<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><!-- generator="wordpress/" --><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>iplosion security</title>
	<link>http://www.iplosion.com</link>
	<description>Discover Security Limits</description>
	<pubDate>Mon, 13 Oct 2008 14:43:43 +0000</pubDate>
	<generator>http://wordpress.org/?v=</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/iplosion-security" type="application/rss+xml" /><item>
		<title>iX Magazine Security Special with DAVIX</title>
		<link>http://feeds.feedburner.com/~r/iplosion-security/~3/419603516/73</link>
		<comments>http://www.iplosion.com/archives/73#comments</comments>
		<pubDate>Mon, 13 Oct 2008 14:41:33 +0000</pubDate>
		<dc:creator>jan.monsch</dc:creator>
		
	<category>News</category>
	<category>DAVIX</category>
	<category>Visualization</category>
		<guid isPermaLink="false">http://www.iplosion.com/archives/73</guid>
		<description><![CDATA[After the DAVIX Visualization Workshop in Las Vegas, Christoph Puppe approached us and asked if we were interested in having DAVIX bundled with the upcoming information security special edition of the iX magazine. Since iX is a very well-established German periodical for IT professionals, we simply could not turn down such a generous offer.
Raffy, Christoph [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" title="Raffy and Jan @ DEFCON 16" id="image74" alt="Raffy and Jan @ DEFCON 16" style="margin-left: 15px; margin-bottom: 5px" src="http://www.iplosion.com/wp-content/uploads/sue_3152_small.jpg" />After the <a title="Blackhat/DEFCON Visualization Retrospective" href="http://www.iplosion.com/archives/69">DAVIX Visualization Workshop</a> in Las Vegas, Christoph Puppe approached us and asked if we were interested in having <a title="DAVA - The Data Analysis and Visualization Linux" href="http://davix.secviz.org">DAVIX</a> bundled with the upcoming information security special edition of the iX magazine. Since iX is a very well-established German periodical for IT professionals, we simply could not turn down such a generous offer.</p>
<p>Raffy, Christoph and I put together our heads and in lightning speed we wrote up an article about DAVIX. The article gives an introduction to the information visualization process, the DAVIX toolset and features a sample analysis of checking network policy compliance using network flows captured with <a title="Argus" href="http://qosient.com/argus/">Argus</a> and visualized with <a title="AfterGlow" href="http://afterglow.sourceforge.net/">AfterGlow</a>.</p>
<p><img align="left" id="image76" alt="iX Special Edition Autumn 2008" title="iX Special Edition Autumn 2008" style="margin-right: 15px; margin-bottom: 5px" src="http://www.iplosion.com/wp-content/uploads/ix_special_edition_autumn_2008.jpg" />The <a title="iX special " href="http://www.heise.de/security/iX-special-Sicher-im-Netz--/news/meldung/117186">special edition</a> due to be released on October 16 comes with a multi-boot DVD with several live CDs. Apart from DAVIX there will be <a title="Avira Rescue" href="http://www.free-av.com/de/tools/12/avira_antivir_rescue_system.html">Avira Rescue</a>, <a title="BackTrack 3" href="http://www.remote-exploit.org/backtrack.html">BackTrack 3</a>, <a title="Damn Vulnerable Linux (DVL)" href="http://www.damnvulnerablelinux.org/">Damn Vulnerable Linux (DVL)</a> and <a title="(R)ecovery (I)s (P)ossible" href="http://www.tux.org/pub/people/kent-robotti/looplinux/rip/">(R)ecovery (I)s (P)ossible</a> on the disk. In particular DVL is a very interesting piece. It is a Linux distro containing as many vulnerable software packages as possible. If you are looking for a playground to train your skills or a simple way to get an environment for teaching security classes, this is it!
</p>

<p><a href="http://feeds.feedburner.com/~a/iplosion-security?a=Zau1mK"><img src="http://feeds.feedburner.com/~a/iplosion-security?i=Zau1mK" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/iplosion-security?a=aav7M"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=aav7M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=wJFCm"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=wJFCm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=V0vdM"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=V0vdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=S2IuM"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=S2IuM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=SdjWm"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=SdjWm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/iplosion-security/~4/419603516" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRSS>http://www.iplosion.com/archives/73/feed/</wfw:commentRSS>
		<feedburner:origLink>http://www.iplosion.com/archives/73</feedburner:origLink></item>
		<item>
		<title>Blackhat/DEFCON Visualization Retrospective</title>
		<link>http://feeds.feedburner.com/~r/iplosion-security/~3/400673643/69</link>
		<comments>http://www.iplosion.com/archives/69#comments</comments>
		<pubDate>Mon, 22 Sep 2008 10:20:58 +0000</pubDate>
		<dc:creator>jan.monsch</dc:creator>
		
	<category>Reports</category>
	<category>Talks</category>
	<category>DAVIX</category>
	<category>Visualization</category>
		<guid isPermaLink="false">http://www.iplosion.com/archives/69</guid>
		<description><![CDATA[From a data mining and visualization perspective the conferences in Las Vegas offered a couple of highlights for me. First of all Raffy&#8217;s book Applied Security Visualization was finally launched and I had the first chance to see and hold the book with the DAVIX CD in my own hands at the bookseller booth. After [...]]]></description>
			<content:encoded><![CDATA[<p><img align="left" title="Las Vegas - Encore, Wynn &#038; Palazzo Towers" id="image70" alt="Las Vegas - Encore, Wynn &#038; Palazzo Towers" style="margin-right: 15px; margin-bottom: 5px" src="http://www.iplosion.com/wp-content/uploads/las_vegas_encore_wynn.jpg" />From a data mining and visualization perspective the conferences in Las Vegas offered a couple of highlights for me. First of all Raffy&#8217;s book <a title="Applied Security Visualization" href="http://www.secviz.org/content/applied-security-visualization">Applied Security Visualization</a> was finally launched and I had the first chance to see and hold the book with the <a title="DAVIX - Data Analysis and Visualization Linux" href="http://davix.secviz.org/">DAVIX CD</a> in my own hands at the bookseller booth. After hours of reviewing the book and building the live CD during the last eight months, it was a great relief that it was finally done.</p>
<p>I very much anticipated Greg Conti&#8217;s and Erik Dean&#8217;s talk on binary visualization (<a title="Visual Forensic Analysis and Reverse Engineering of Binary Data" href="http://www.rumint.org/gregconti/publications/200808_binviz38_dc_final.ppt">PPT Slides</a>). Their newest tools <a title="DanglyBytes" href="http://www.rumint.org/software/danglybytes/db.zip">DanglyBytes</a> allows for interactive analysis of binary data in multiple views. The different views decode data in multiple ways. There is a view that just prints the bit stream in a window while another decodes a series of bytes as RGB value. Their demo of a Windows error dump was a revelation: Using a slider on one of the views they could adjust the column width of the view. While moving the slider Google and Wikipedia images began to appear out of the noise. I am looking forward to play around with it myself.</p>
<p>Another interesting discovery at the Blackhat vendor area was the company <a title="Lookingglass" href="http://www.looking-glass.com/">Lookingglass</a> with their software as a service (SaaS) called <a title="ScoutVision" href="http://www.scout-vision.com/">ScoutVision</a>. They have built an infrastructure that stores Internet meta information in a database and provides its customers a client software to access and visualize this information remotely. For well paying customers they offer a service where clients can tie in their own IT data.</p>
<p><img align="right" title="Main Entrance Caesars Palace" id="image71" alt="Main Entrance Caesars Palace" style="margin-left: 15px; margin-bottom: 5px" src="http://www.iplosion.com/wp-content/uploads/las_vegas_caesars_palace.jpg" />While preparing for the DAVIX Visualization Workshop in the CTF lounge, I saw a dude visualizing network traffic in <a title="Processing" href="http://www.processing.org/">Processing</a>. I approached him and we started chatting about visualization. Interestingly he did neither know about <a title="secviz.org" href="http://www.secviz.org">secviz.org</a> nor <a title="DAVIX" href="http://davix.secviz.org">DAVIX</a>. Over the course of DEFCON I found out that many people are toying around with visualization as well but there is no interaction between these people. This is definitively a thing that we should be working on over the upcoming months. I hope that DAVIX will help to contract people interested in security visualization.</p>
<p>On Sunday our DAVIX Visualization Workshop was on (<a title="DAVIX Visualization Workshop" href="http://www.iplosion.com/papers/defcon16_davix_visualization_workshop.pdf">Slides</a>). During our introductory talk on DAVIX there were about 120 attendees. We were very surprised to see such an interest although many DEFCON participants have already gone home and it was during the last three hours of DEFCON. So there is definitively potential for future activities.
</p>

<p><a href="http://feeds.feedburner.com/~a/iplosion-security?a=kM1r7C"><img src="http://feeds.feedburner.com/~a/iplosion-security?i=kM1r7C" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/iplosion-security?a=hABzL"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=hABzL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=fefjl"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=fefjl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=ljCoL"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=ljCoL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=WzcuL"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=WzcuL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=ijEVl"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=ijEVl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/iplosion-security/~4/400673643" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRSS>http://www.iplosion.com/archives/69/feed/</wfw:commentRSS>
		<feedburner:origLink>http://www.iplosion.com/archives/69</feedburner:origLink></item>
		<item>
		<title>DAVIX 1.0.1 Officially Launched</title>
		<link>http://feeds.feedburner.com/~r/iplosion-security/~3/365187953/67</link>
		<comments>http://www.iplosion.com/archives/67#comments</comments>
		<pubDate>Thu, 14 Aug 2008 22:39:18 +0000</pubDate>
		<dc:creator>jan.monsch</dc:creator>
		
	<category>Reports</category>
	<category>DAVIX</category>
	<category>Visualization</category>
		<guid isPermaLink="false">http://www.iplosion.com/archives/67</guid>
		<description><![CDATA[After months of building and testing, the long anticipated release of DAVIX - The Data Analysis &#038; Visualization Linux® - arrived last week during Blackhat/DEFCON in Las Vegas. It is a very exiting moment for me and I am curious to see how the product is received by audience. So far the ISO image has [...]]]></description>
			<content:encoded><![CDATA[<p>After months of building and testing, the long anticipated release of DAVIX - The Data Analysis &#038; Visualization Linux® - arrived last week during <a title="Blackhat" href="http://www.blackhat.com">Blackhat</a>/<a title="DEFCON" href="http://www.defcon.org">DEFCON </a>in Las Vegas. It is a very exiting moment for me and I am curious to see how the product is received by audience. So far the ISO image has been downloaded at least 600 times from our main distribution server. Downloads from the mirrors are not accounted.</p>
<p><a title="Applied Security Visualization - Rough Cuts Version" href="http://safari.informit.com/9780321585530?tocview=true"><img align="right" style="margin-left: 15px; margin-bottom: 5px" title="Applied Security Visualization" id="image68" alt="Applied Security Visualization" src="http://www.iplosion.com/wp-content/uploads/applied_security_visualization.jpg" /></a>Additionally, Raffael Marty&#8217;s book <em><a title="Applied Security Visualization" href="http://www.informit.com/store/product.aspx?isbn=0321510100">Applied Security Visualization</a></em> is now available in print. DAVIX was built with this particular book in mind. If you are looking for a methodology and not just a workable tool set, then the book is what you are looking for. The book covers all steps from the very basics to complete case studies and contains many hands-on examples. Therefore, the book together with DAVIX 1.0.1 is the perfect match for getting you started with security visualization. For a preview of the book&#8217;s content check out the <a title="Applied Security Visualization - Rough Cuts Version" href="http://safari.informit.com/9780321585530?tocview=true">rough cuts version</a>.</p>
<p>All those eager to get their hands dirty immediately can find a description as well as the download links for the DAVIX ISO image on the <a title="davix.secviz.org" href="http://davix.secviz.org">DAVIX homepage</a>. I wish you happy visualizing!
</p>

<p><a href="http://feeds.feedburner.com/~a/iplosion-security?a=n6tuno"><img src="http://feeds.feedburner.com/~a/iplosion-security?i=n6tuno" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/iplosion-security?a=JNRTNK"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=JNRTNK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=lffKkk"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=lffKkk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=GeVdUK"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=GeVdUK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=AvucEK"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=AvucEK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=jEZ45k"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=jEZ45k" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/iplosion-security/~4/365187953" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRSS>http://www.iplosion.com/archives/67/feed/</wfw:commentRSS>
		<feedburner:origLink>http://www.iplosion.com/archives/67</feedburner:origLink></item>
		<item>
		<title>DAVIX - A Look Behind the Scene</title>
		<link>http://feeds.feedburner.com/~r/iplosion-security/~3/340089351/63</link>
		<comments>http://www.iplosion.com/archives/63#comments</comments>
		<pubDate>Sat, 19 Jul 2008 18:54:33 +0000</pubDate>
		<dc:creator>jan.monsch</dc:creator>
		
	<category>Reports</category>
	<category>Talks</category>
	<category>DAVIX</category>
	<category>Visualization</category>
		<guid isPermaLink="false">http://www.iplosion.com/archives/63</guid>
		<description><![CDATA[Although it has been very quiet on this blog for quite a while, lots of activities in the background have been keeping me busy. During the last six months I have been working on my new pet project DAVIX that relates to my interest in security data mining and visualization. But let me start at [...]]]></description>
			<content:encoded><![CDATA[<p><a title="davix.secviz.org" href="http://davix.secviz.org"><img align="right" title="DAVIX Logo" alt="DAVIX Logo" id="image65" src="http://www.iplosion.com/wp-content/uploads/davix_logo_300c.png" /></a>Although it has been very quiet on this blog for quite a while, lots of activities in the background have been keeping me busy. During the last six months I have been working on my new pet project <a title="DAVIX secviz.org" href="http://davix.secviz.org">DAVIX</a> that relates to my interest in security data mining and visualization. But let me start at the beginning.</p>
<p>While playing around with visualization I found that there are lots of tools on the net but getting them to run can cause quite some headaches. So I thought that it would be cool to have an environment where all those tools are available ready to use. As time went by, the idea of a Linux live CD system materialized in my mind. Between Christmas and New Year, while watching 24C3 live streams in the background, I started playing around with <a title="SLAX - Your Pocket Operating System" href="http://www.slax.org/">SLAX</a>, a modularized Slackware based live CD system. I found it very useful to my purpose and decided to start with it as base for the visualization live CD.</p>
<p>Since I knew that Raffael Marty was writing his book <em><a title="Applied Security Visualization" href="http://www.informit.com/store/product.aspx?isbn=0321510100">Applied Security Visualization</a></em>, I contacted him in January 2008 and told him about my project and asked which tools should be included on the CD. Raffy was hooked by the idea from the get go and he asked me bluntly if I would do the CD for his book. Of course I agreed immediately. To get jump started with adding visualization tools, Raffy provided me with the chapter 9 of his books, which contains a list of visualization tools and instructions on how to get them running. At around the same time I got selected into the technical review board for Raffy&#8217;s book and I alternately reviewed chapters from Raffy&#8217;s awesome book and built the CD.</p>
<p>Since the live CD project was nameless at the time, I thought about an appropriate name for it. After toying with a couple of ideas I came up with the name DAVIX as a short form of Data Analysis and Visualization Linux®. I also liked the reference to the biblical figure David who fought against the giant Goliath. In terms of our project it means that with the &#8220;small&#8221; live system DAVIX you fight the gigantic heaps of log files and network captures.</p>
<p><img align="middle" alt="Las Vegas Skyline" id="image66" title="Las Vegas Skyline" src="http://www.iplosion.com/wp-content/uploads/las_vegas_skyline.jpg" /></p>
<p>DAVIX currently integrates about 180 software packages that contribute to about 40 high level tools for capturing, processing and visualizing data. The project is now in its final rounds of building and testing and will officially release during Greg Conti&#8217;s <a title="Visual Forensic Analysis and Reverse Engineering of Binary Data" href="http://www.blackhat.com/html/bh-usa-08/bh-usa-08-speakers.html#Conti">Blackhat</a> and <a title="Could Googling Take Down a President, a Prime Minister, or an Average Citizen? " href="http://www.defcon.org/html/defcon-16/dc-16-speakers.html#Conti">DEFCON</a> talks. For all of you who want first hand experience with DAVIX, Raffy and I invite you to our <a title="DAVIX Visualization Workshop " href="http://www.defcon.org/html/defcon-16/dc-16-speakers.html#DAVIX">DAVIX Visualization Workshop</a> at DEFCON 16. The session will be held on Sunday, August 10th 2008 at 2 PM to 4 PM.</p>
<p>See you in Las Vegas!
</p>

<p><a href="http://feeds.feedburner.com/~a/iplosion-security?a=iS5OnV"><img src="http://feeds.feedburner.com/~a/iplosion-security?i=iS5OnV" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/iplosion-security?a=ybnMyJ"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=ybnMyJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=TUuRnj"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=TUuRnj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=vcUZcJ"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=vcUZcJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=VV0c0J"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=VV0c0J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=zqeldj"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=zqeldj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/iplosion-security/~4/340089351" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRSS>http://www.iplosion.com/archives/63/feed/</wfw:commentRSS>
		<feedburner:origLink>http://www.iplosion.com/archives/63</feedburner:origLink></item>
		<item>
		<title>A Visit to the Canadian Parliament and Confiscated Items</title>
		<link>http://feeds.feedburner.com/~r/iplosion-security/~3/337391928/59</link>
		<comments>http://www.iplosion.com/archives/59#comments</comments>
		<pubDate>Wed, 16 Jul 2008 19:39:00 +0000</pubDate>
		<dc:creator>jan.monsch</dc:creator>
		
	<category>Observations</category>
		<guid isPermaLink="false">http://www.iplosion.com/archives/59</guid>
		<description><![CDATA[Last year I traveled through Canada. One of my stopovers was in Ottawa. Very nice friends of mine have recommended that I shall pay a visit to the Parliament Hill and take a tour through the Center Block. To my surprise the parliament offers free tours through the buildings. So I decided to participate.
On entering [...]]]></description>
			<content:encoded><![CDATA[<p><img align="left" style="margin-right: 15px; margin-bottom: 5px" title="Canadian Parliament Center Block Peace Tower" id="image61" alt="Canadian Parliament Center Block Peace Tower" src="http://www.iplosion.com/wp-content/uploads/canadian_parliament_center_block.jpg" />Last year I traveled through Canada. One of my stopovers was in Ottawa. Very nice friends of mine have recommended that I shall pay a visit to the Parliament Hill and take a tour through the Center Block. To my surprise the parliament offers free tours through the buildings. So I decided to participate.</p>
<p>On entering the building, everybody got an airport quality security check with x-ray and metal detector and we were asked to shutdown our mobile phones. Then I enjoyed the tour through this magnificent building with stops at the House of Commons and the Senate as well as the newly renovated library.</p>
<p>When the tour came to an end, the guide announced further points of interest. As one of her final sentences she said that stuff, which got confiscated during the security check, can be collect at the desk right next to the exit of the building. I found that pretty wired. What could that be? A magnum, a rifle, a bomb, a lighter, matches? Then I let my thoughts pass&#8230;</p>
<p>When I moved towards the exit I observed a young guy with dreadlocks and his girl friend in the process of collecting their confiscated goods: A secateurs and a handsaw!
</p>

<p><a href="http://feeds.feedburner.com/~a/iplosion-security?a=FEZ8fu"><img src="http://feeds.feedburner.com/~a/iplosion-security?i=FEZ8fu" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/iplosion-security?a=iqOHJJ"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=iqOHJJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=OoQmoj"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=OoQmoj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=wMjkCJ"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=wMjkCJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=HT3EDJ"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=HT3EDJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=aDgiYj"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=aDgiYj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/iplosion-security/~4/337391928" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRSS>http://www.iplosion.com/archives/59/feed/</wfw:commentRSS>
		<feedburner:origLink>http://www.iplosion.com/archives/59</feedburner:origLink></item>
		<item>
		<title>Blog-Tagging or How-To Push Your Blog’s PageRank</title>
		<link>http://feeds.feedburner.com/~r/iplosion-security/~3/86901701/58</link>
		<comments>http://www.iplosion.com/archives/58#comments</comments>
		<pubDate>Mon, 05 Feb 2007 20:54:14 +0000</pubDate>
		<dc:creator>jan.monsch</dc:creator>
		
	<category>Reports</category>
		<guid isPermaLink="false">http://www.iplosion.com/archives/58</guid>
		<description><![CDATA[My dear friend Raffy Marty has Blog-Tagged me.   Well, so far I have not heard about this. So, what is it? When you get Blog-Tagged, you have to write five not commonly known things about yourself to your blog and then you name the next five “victims”. The basic idea is that your [...]]]></description>
			<content:encoded><![CDATA[<p>My dear friend <a title="Raffy's Computer Security Blog" target="_blank" href="http://raffy.ch/blog/">Raffy Marty</a> has <a title="Blog-Tag: A Game for a Virtual Cocktail Party" target="_blank" href="http://pulverblog.pulver.com/archives/006087.html">Blog-Tagged</a> me. <img src='/wp-includes/images/smilies/icon_neutral.gif' alt=':-|' class='wp-smiley' />  Well, so far I have not heard about this. So, what is it? When you get Blog-Tagged, you have to write five not commonly known things about yourself to your blog and then you name the next five “victims”. The basic idea is that your blog readers get to know you a bit better.</p>
<p>So what kind of implications or additional benefits has Blog-Tagging? It is a way to increase your Google <a title="Wikipedia - PageRank" target="_blank" href="http://en.wikipedia.org/wiki/PageRank">PageRank</a>, which is obviously a good thing if you want to grow your audience. Since you most likely refer back to the blog which has Blog-Tagged you the original blog gets an additional backlink. When all your &#8220;victims&#8221; will do the same with your blog, you get an additional five backlinks. Since not everybody knows about Blog-Tagging, additional backlinks to explaining blogs or sites will occur.</p>
<p>Not being a killjoy, I will now give my five “confessions” <img src='/wp-includes/images/smilies/icon_cool.gif' alt='8-)' class='wp-smiley' />  :</p>
<p><a id="more-58"></a></p>
<ul>
<li>I wrote my first computer program when I was about 10 years old. At that time my father has bought a <a title="Wikipedia - Commodore C64" target="_blank" href="http://en.wikipedia.org/wiki/C64">Commodore C64</a> and has taught himself <a title="Wikipedia - BASIC" target="_blank" href="http://en.wikipedia.org/wiki/BASIC">BASIC</a>. I sort of trailed the path and slipped naturally into computer technology. My first program was a series of block character graphics which told a little story about Alex the duck.</li>
<li>You might remember those little albums in primary school days where you drew nice pictures and wrote rhymes and poems to your best friend’s album? There have been some in questionnaire style: &#8220;What is your dream job?&#8221; Well, my answers were: Computer Specialist or Astronaut.</li>
<li>In 1992, when I still was an electronics technician apprentice, I got interested in Linux. A coworker showed me a report in the <a title="c't - Magazin für Computertechnik" target="_blank" href="http://www.heise.de/ct/">c’t magazine</a> about this new operating system. I was hooked right away since I thought Windows sucks and playing on the company’s Ultrix and Solaris workstation was more geeky. Since there were no commercial Linux distros available at the time, we ordered <a title="Wikipedia - Quarter Inch Cartridge" target="_blank" href="http://en.wikipedia.org/wiki/QIC">QIC tapes</a> from the operator of the Swiss academic network (<a title="SWITCH - The Swiss Education &#038; Research Network" href="http://www.switch.ch/">SWITCH</a>) with a copy of the <a title="The Slackware Linux Project" target="_blank" href="http://slackware.com/">Slackware Linux</a> FTP mirror. We then copied the disk images to about forty 5 ¼ inch floppy disks and played disk jockey all night.</li>
<li>I have been a radio amateur since 1993 and my call sign is HB9KOP. I was very active on packet radio and participated in building the local packet radio station <a title="USKA Sektion St. Gallen - HB9CC" target="_blank" href="http://www.hb9cc.ch/">HB9CC</a>. Internet technology fascinated me at the time and I wanted to toy with it. Since Internet was too expensive in those days, the only way to do so was using TCP/IP over <a title="Wikipedia - Packet Radio" target="_blank" href="http://en.wikipedia.org/wiki/Packet_radio">packet radio</a>. That is how I got to know the Internet basics.</li>
<li>I am a science fiction fan. My most favorite TV series are <a title="The Lurker's Guide to Babylon 5" target="_blank" href="http://www.midwinter.com/lurk/">Babylon 5</a>, <a title="Taken" target="_blank" href="http://www.scifi.com/taken/">Taken </a>and <a title="The 4400 TV Series" target="_blank" href="http://www.usanetwork.com/series/the4400/">The 4400</a>. Currently my most favorite science fiction author is <a title="Wikipedia - Michael Cordy" target="_blank" href="http://en.wikipedia.org/wiki/Michael_Cordy">Michael Cordy</a>. He wrote several page-turner thriller novels with biotechnology as the core theme. In his books he tries to envision the course of the world when mankind has reached a sufficient level in playing the genes for better and for worse. In my opinion his best books are <em>Crime Zero</em> and <em>The Miracale Strain</em>.</li>
</ul>
<p>I will now nominate the next round of Blog-Tag “victims”  <img src='/wp-includes/images/smilies/icon_twisted.gif' alt=':twisted:' class='wp-smiley' />  – Drum roll - The winners are:</p>
<ul>
<li><a title="Bytesman - It's a zero it's a one... it's BYTESMAN..." target="_blank" href="http://www.bytesman.com/blogg/">Eric Ernst</a>,</li>
<li><a title="pagetable.com - It's all about Assembly" target="_blank" href="http://www.pagetable.com/">Michael Steil</a>,</li>
<li><a title="DEVTARGET.ORG - Yet another IT security-related site" target="_blank" href="http://www.devtarget.org/">Sebastian Wolfgarten</a>,</li>
<li><a title=" Jeremiah Grossman" target="_blank" href="http://jeremiahgrossman.blogspot.com">Jeremiah Grossman</a>,</li>
<li><a target="_blank" title="ITblog - Polski informatyk w Irlandii" href="http://michal.osmenda.com/">Michal Osmenda</a>.</li>
</ul>

<p><a href="http://feeds.feedburner.com/~a/iplosion-security?a=EGl8f9"><img src="http://feeds.feedburner.com/~a/iplosion-security?i=EGl8f9" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/iplosion-security?a=a2xRTZLz"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=a2xRTZLz" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=xaMTTleU"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=xaMTTleU" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=Iwl7jOaW"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=Iwl7jOaW" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=lm5Guo7L"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=lm5Guo7L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=3vM9aMmb"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=3vM9aMmb" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/iplosion-security/~4/86901701"/>]]></content:encoded>
			<wfw:commentRSS>http://www.iplosion.com/archives/58/feed/</wfw:commentRSS>
		<feedburner:origLink>http://www.iplosion.com/archives/58</feedburner:origLink></item>
		<item>
		<title>Skype Trojan Protection - Disable Skype API and File Transfer</title>
		<link>http://feeds.feedburner.com/~r/iplosion-security/~3/64750643/57</link>
		<comments>http://www.iplosion.com/archives/57#comments</comments>
		<pubDate>Thu, 21 Dec 2006 19:03:50 +0000</pubDate>
		<dc:creator>jan.monsch</dc:creator>
		
	<category>Reports</category>
	<category>Malware</category>
	<category>Skype</category>
		<guid isPermaLink="false">http://www.iplosion.com/archives/57</guid>
		<description><![CDATA[This week Websense reported the first Trojan using the Skype API as part of its evil workings. The currently available information does not tell us what the Trojan uses the Skype API for. As already discussed in the blog article &#8220;Proof-of-Concept Trojan using Skype API&#8221;, such a Trojan can hide its communication in the Skype [...]]]></description>
			<content:encoded><![CDATA[<p>This week <a target="_blank" title="Skype Trojan Horse" href="http://www.websense.com/securitylabs/alerts/alert.php?AlertID=716">Websense</a> reported the first Trojan using the <a title="Skype Public API 2.0 Reference Guide" target="_blank" href="https://developer.skype.com/Docs/ApiDoc">Skype API</a> as part of its evil workings. The currently available information does not tell us what the Trojan uses the Skype API for. As already discussed in the blog article <em><a title="Proof-of-Concept Trojan using Skype API" target="_blank" href="http://www.iplosion.com/archives/44">&#8220;Proof-of-Concept Trojan using Skype API&#8221;</a></em>, such a Trojan can hide its communication in the Skype network and no currently available content inspection technique will be able to cope with such a covert channel. Although the current Trojan will provoke a warning dialog from the Skype client, telling the user that a third party program wants to access the Skype API, it is most likely that adversaries will soon learn to bypass this warning using some Windows low-level API.</p>
<p><a id="more-57"></a></p>
<div style="text-align: center"><img title="Skype API warning dialog when a third party application attaches to the Skype client for the first time" alt="Skype API warning dialog when a third party application attaches to the Skype client for the first time" src="http://www.iplosion.com/reports/skype_api_warning_dialog.png" /></div>
<p align="left">As we can see from the above screenshot the user can permanently enable access for a particular third party application. This prevents the warning dialog to be shown in future. If a user has accidentally permitted access or wants to know which applications have access to the Skype API, he or she can find a link called <em>&#8220;Manage other programs&#8217; access to Skype&#8221;</em> in the section <em>Privacy</em> of the Skype <em>Options </em>dialog.</p>
<p align="center"><img alt="Skype Options" title="Skype Options" src="http://www.iplosion.com/reports/skype_options.png" /></p>
<p align="left">There he or she can view or modify the permissions for each individual third party application.</p>
<p align="center"><img alt="Manage API Access Control" title="Manage API Access Control" src="http://www.iplosion.com/reports/skype_manage_api_access_control.png" /></p>
<p align="left">According to Bill Campbell&#8217;s article <a title="Simple corporate security tip: disable Skype API and File Transfer" target="_blank" href="http://www.skypejournal.com/blog/archives/2005/11/simple_corporate_security_tip_disable_sk_1.php"><span style="font-style: italic">&#8220;Simple corporate security tip: disable Skype API and File Transfer</span><span style="font-style: italic">&#8220;</span></a> there is a way to disable the Skype API using registry settings. The following registry key is officially documented in the Skype knowledgebase article <a target="_blank" title="How can I disable access to the API?" href="http://support.skype.com/index.php?_a=knowledgebase&#038;_j=questiondetails&#038;_i=632">632</a>. The policy prevents that any third party application can attach to the Skype API.</p>
<blockquote><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Skype\Phone]<br />
&#8220;DisableApi&#8221;=dword:00000001</p></blockquote>
<p>In- and outbound file transfers can also be disabled by a registry setting. This is documented in the Skype knowledgebase article <a target="_blank" title="How can I disable File Transfer?" href="http://support.skype.com/index.php?_a=knowledgebase&#038;_j=questiondetails&#038;_i=631">631</a>:</p>
<blockquote><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Skype\Phone]<br />
&#8220;DisableFileTransfer&#8221;=dword:00000001</p></blockquote>
<p>After applying the file transfer policy, an error dialog is shown to the user when he or she wants to send a file from a protected client:</p>
<div style="text-align: center"><img title="Error dialog when a user wants to send a file from a policy protected system." alt="Error dialog when a user wants to send a file from a policy protected system." src="http://www.iplosion.com/reports/skype_filetransfer_from_policy_protected_local_client.png" /></div>
<p>When sending a file to a policy protected Skype client the file transfer immediately aborts and the following error is shown:</p>
<div style="text-align: center"><img title="Error message shown when a file is sent to a policy protected Skype client" alt="Error message shown when a file is sent to a policy protected Skype client" src="http://www.iplosion.com/reports/skype_filetransfer_to_policy_protected_remote_client.png" /></div>
<p>I have verified both registry settings and they both work. In a corporate environment this allows administrators to lockdown Skype. But it requires that the user does not have administrative privileges. Otherwise the Trojan can remove these entries again. Administrators must further ensure that the registry ACL does not permit users to modify these registry keys.</p>
<p>As a preemptive measure I suggest that companies, who do not have Skype deployed, should also deploy the above registry settings to their workstations using Windows Group Policies. This prevents the two most dangerous use cases where employees place the Skype executable onto their system without permission. It should be noted that Skype does not require any special privileges to run. Being an ordinary user is just enough.
</p>

<p><a href="http://feeds.feedburner.com/~a/iplosion-security?a=B8P8R5"><img src="http://feeds.feedburner.com/~a/iplosion-security?i=B8P8R5" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/iplosion-security?a=TOoIMmj2"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=TOoIMmj2" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=3hxq9Y3a"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=3hxq9Y3a" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=QHpUkSwC"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=QHpUkSwC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=l31ZZ0Qm"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=l31ZZ0Qm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=77ybGAvL"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=77ybGAvL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/iplosion-security/~4/64750643"/>]]></content:encoded>
			<wfw:commentRSS>http://www.iplosion.com/archives/57/feed/</wfw:commentRSS>
		<feedburner:origLink>http://www.iplosion.com/archives/57</feedburner:origLink></item>
		<item>
		<title>Ruining Security with java.util.Random</title>
		<link>http://feeds.feedburner.com/~r/iplosion-security/~3/62776236/47</link>
		<comments>http://www.iplosion.com/archives/47#comments</comments>
		<pubDate>Fri, 15 Dec 2006 17:03:01 +0000</pubDate>
		<dc:creator>jan.monsch</dc:creator>
		
	<category>Papers</category>
	<category>Java</category>
	<category>Weblication</category>
		<guid isPermaLink="false">http://www.iplosion.com/archives/47</guid>
		<description><![CDATA[In my review practice I often have to look at Java source code which is used to generate passwords, authentication tokens or session ids. Ever so often this code uses the Java API class java.util.Random to generate random numbers. It is well-established in security industry that this particular random generator is not secure. Since I [...]]]></description>
			<content:encoded><![CDATA[<p>In my review practice I often have to look at Java source code which is used to generate passwords, authentication tokens or session ids. Ever so often this code uses the Java API class <em><a target="_blank" title="Java Documentation java.util.Random" href="http://java.sun.com/j2se/1.4.2/docs/api/java/util/Random.html">java.util.Random</a></em> to generate random numbers. It is well-established in security industry that this particular random generator is not secure. Since I did not know what the reason is for this perception I started to have a closer look.</p>
<p>During the review of the Java API source code I discovered two vulnerabilities which cause the internal state of <em>java.util.Random</em> to be partially exposed or easy guessable. The paper <a title="Ruining Security with java.util.Random" href="http://www.iplosion.com/papers/ruining_security_with_java.util.random_v1.0.pdf"><em>Ruining Security with java.util.Random</em></a> demonstrates two techniques how security mechanisms based on <em>java.util.Random</em> can be attacked and under certain conditions can be broken within seconds. Using these weaknesses an attacker can synchronize into the stream of random numbers and therefore calculate all future random numbers. For security relevant code java.util.Random should never be used. At least the Java class <em>java.security.SecureRandom</em> with the default constructor should be utilized. This provides much better security.</p>
<p>If you know about other vulnerabilities in the design of <em>java.util.Random</em> or you know about vulnerabilities in <a target="_blank" title="Java Documentation of java.security.SecureRandom" href="http://java.sun.com/j2se/1.4.2/docs/api/java/security/SecureRandom.html"><em>java.security.SecureRandom</em></a> I would be happy to hear about it.
</p>

<p><a href="http://feeds.feedburner.com/~a/iplosion-security?a=wqXctL"><img src="http://feeds.feedburner.com/~a/iplosion-security?i=wqXctL" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/iplosion-security?a=aY8pkWgD"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=aY8pkWgD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=2RPd5BQF"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=2RPd5BQF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=7rDAldzk"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=7rDAldzk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=BE031Rc0"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=BE031Rc0" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=OT2LTIX8"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=OT2LTIX8" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/iplosion-security/~4/62776236"/>]]></content:encoded>
			<wfw:commentRSS>http://www.iplosion.com/archives/47/feed/</wfw:commentRSS>
		<feedburner:origLink>http://www.iplosion.com/archives/47</feedburner:origLink></item>
		<item>
		<title>Trends at Black Hat USA 2006 and DEFCON 14</title>
		<link>http://feeds.feedburner.com/~r/iplosion-security/~3/62776237/56</link>
		<comments>http://www.iplosion.com/archives/56#comments</comments>
		<pubDate>Mon, 11 Dec 2006 14:10:48 +0000</pubDate>
		<dc:creator>jan.monsch</dc:creator>
		
	<category>Papers</category>
		<guid isPermaLink="false">http://www.iplosion.com/archives/56</guid>
		<description><![CDATA[Black Hat USA and DEFCON in Las Vegas are amongst the biggest IT security conferences in the world. This year Walter Sprenger and I had the opportunity to attend. Both events have been very interesting on their own merits. Whereas Black Hat is more directed towards the corporate IT users, DEFCON addresses the security geeks. [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal"><a title="Blackhat Homepage" target="_blank" href="http://www.blackhat.com">Black Hat USA</a> and <a title="DEFCON Homepage" target="_blank" href="http://www.defcon.org">DEFCON </a>in Las Vegas are amongst the biggest IT security conferences in the world. This year Walter Sprenger and I had the opportunity to attend. Both events have been very interesting on their own merits. Whereas Black Hat is more directed towards the corporate IT users, DEFCON addresses the security geeks. For me Black Hat had the most interesting presentations and DEFCON proofed to be the better place to network with people.</p>
<p class="MsoNormal">The biggest topics this year at Black Hat were VoIP security, Windows Vista security and all flavors of phishing attacks (Phishing, Vishing, SMiShing). As users grow aware of e-mail based phishing they are likely to fall victim to phishing originating from other communication channels. Although web application security has been top agenda for IT security professionals for years, the situation does not seem to improve but rather worsens: Cross-Site Scripting based worms and Intranet attacks are the new kids on the block. With the large adoption of the <a title="Wikipedia - AJAX (Programming)" target="_blank" href="http://en.wikipedia.org/wiki/Ajax_%28programming%29">AJAX concept</a> new opportunities for attacks will arise. Interesting are the new advances in attacking WLANs and Bluetooth devices. At the DEFCON talks reverse engineering and privacy issues were the main topics. Of course the fun factor with all the contests (CTF, warwalking, lock picking, beverage cooling) has its own charm.</p>
<p class="MsoNormal">Walter and I have put together a <strong><a title="Trends at Blackhat/DEFCON 2006" href="http://www.iplosion.com/papers/trends_at_blackhat_defcon_2006_v2.2.pdf">document with the latest IT security trends (5.2 MB)</a></strong> we have picked up at the conferences. Some pictures have been added to give you an impression of both events. See the <a title="Blackhat USA 2006 Proceedings" target="_blank" href="http://www.blackhat.com/html/bh-media-archives/bh-archives-2006.html#us-2006">Black Hat USA 2006</a> and the <a target="_blank" title="DEFCON 14 Proceedings" href="http://www.defcon.org/html/links/defcon-media-archives.html#dc_14">DEFCON 14 proceedings</a> for further details.</p>

<p><a href="http://feeds.feedburner.com/~a/iplosion-security?a=XqmQId"><img src="http://feeds.feedburner.com/~a/iplosion-security?i=XqmQId" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/iplosion-security?a=Y1Y0pBMC"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=Y1Y0pBMC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=PhaqENQR"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=PhaqENQR" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=tlmE0rf7"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=tlmE0rf7" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=UPLNptxN"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=UPLNptxN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=6eNZgd7L"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=6eNZgd7L" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/iplosion-security/~4/62776237"/>]]></content:encoded>
			<wfw:commentRSS>http://www.iplosion.com/archives/56/feed/</wfw:commentRSS>
		<feedburner:origLink>http://www.iplosion.com/archives/56</feedburner:origLink></item>
		<item>
		<title>Enforcing Java Security Manager in Restricted Windows Environments?</title>
		<link>http://feeds.feedburner.com/~r/iplosion-security/~3/62776238/54</link>
		<comments>http://www.iplosion.com/archives/54#comments</comments>
		<pubDate>Fri, 08 Dec 2006 00:44:00 +0000</pubDate>
		<dc:creator>jan.monsch</dc:creator>
		
	<category>Reports</category>
	<category>Java</category>
	<category>Citrix</category>
	<category>Terminal Server</category>
		<guid isPermaLink="false">http://www.iplosion.com/archives/54</guid>
		<description><![CDATA[Lately I came across several Citrix and Terminal Server projects which provide a restricted set of applications to their users. This is achieved using Windows Software Restriction Policies or AppSense Application Manager to white or black list executables.
One of these permitted binaries is often java.exe. Now the problem arises that once Java is enabled any [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal">Lately I came across several Citrix and Terminal Server projects which provide a restricted set of applications to their users. This is achieved using <a title="Using Software Restriction Policies to Protect Against Unauthorized Software" target="_blank" href="http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/rstrplcy.mspx">Windows Software Restriction Policies</a> or <a title="AppSense Application Manager" target="_blank" href="http://www.appsense.com/content/products/application_manager/application_manager.asp">AppSense Application Manager</a> to white or black list executables.</p>
<p class="MsoNormal">One of these permitted binaries is often <em>java.exe</em>. Now the problem arises that once Java is enabled any Java application can be executed on the system. This allows a malicious user to execute arbitrary Java code, like replacement shells (<a title="JSH - The Open-Source Shell" target="_blank" href="http://gerard.collin3.free.fr/">JSH</a>), RDP clients (<a title="properJavaRDP" target="_blank" href="http://properjavardp.sourceforge.net/">Propero Java RDP</a>) and network port scanners. I could block <em>java.exe</em> but business requires that the company&#8217;s Java application must still work. This lead me into this research on how to white list Java applications in a restricted Windows environment.</p>
<p><a id="more-54"></a></p>
<p class="MsoNormal">First of all Java has a mechanism called Java 2 Security which allows implementing policies based on code location or digital signatures. These policies are configured through the files <a target="_blank" title="Default Policy Implementation and Policy File Syntax" href="http://java.sun.com/j2se/1.4.2/docs/guide/security/PolicyFiles.html"><em>java.policy</em></a> and <a target="_blank" title="The java.security Properties File" href="http://java.sun.com/j2se/1.4.2/docs/guide/security/jce/HowToImplAJCEProvider.html#AppC"><em>java.security</em></a>. When <em>java.exe</em> gets executed these policies are not enforced by default. To enforce the restrictions the Java system property <em>java.security.manager</em> must included at the startup command line:</p>
<blockquote>
<p class="MsoNormal">java.exe -Djava.security.manager MyCode</p>
</blockquote>
<p class="MsoNormal">This property causes Java&#8217;s Security Manager to be installed and the policy to be enforced. So far so good. But how can I pass this parameter without having it to be specified on the command line? Well Java offers the environment variable <em>_JAVA_OPTIONS</em>. So I thought I place the parameter into a Windows system environment variable:</p>
<blockquote>
<p class="MsoNormal">_JAVA_OPTIONS=-Djava.security.manager=</p>
</blockquote>
<p class="MsoNormal">Testing revealed that <em>java.exe</em> can be executed with the Security Manager enabled without passing the parameter on the command line directly. Further testing revealed that when I start a <em>cmd.exe</em> as a low-privileged user I can overwrite this system environment variable and I can bypass the Java Security Manager using following command:</p>
<blockquote>
<p class="MsoNormal">set _JAVA_OPTIONS=</p>
</blockquote>
<p class="MsoNormal">I tried the same from within a Microsoft Word macro. The effect is the same. According to my research and feedback from Microsoft the system environment variables can always be overwritten within the process for the local process. In the paper <a target="_blank" title="Software Restriction Policies in Windows XP" href="http://www.virusbtn.com/files/johnlambert_vb2002.pdf"><em>Software Restriction Policies in Windows XP</em></a> on page 13 in Chapter <em>Analysis of Path Rule</em> John Lambert writes:</p>
<blockquote>
<p class="MsoNormal"><span style="font-style: italic">Environment variables are not secure, and any user who can load a command prompt can temporarily redefine them.</span></p>
</blockquote>
<p class="MsoNormal">So this melts down to my question: <strong>Is there a way to tell <em>java.exe</em> to always use the Java Security Manager without the possibility of manipulation by the user?</strong></p>
<p class="MsoNormal">I would be very interested to learn your ideas. For those of you who want to play yourself I provide a <a href="http://www.iplosion.com/tools/enforce_java_security.zip">ZIP archive</a> with the files I used for testing. Please send your comments by mail to: jan.monsch ät iplosion.com. I will then write-up a post with the discussion results</p>
<p class="MsoNormal">

<p><a href="http://feeds.feedburner.com/~a/iplosion-security?a=Irk54g"><img src="http://feeds.feedburner.com/~a/iplosion-security?i=Irk54g" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/iplosion-security?a=1qNsloJG"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=1qNsloJG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=z72hPhjr"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=z72hPhjr" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=Ydh7ioma"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=Ydh7ioma" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=KWCDsIv8"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=KWCDsIv8" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/iplosion-security?a=K1bzfepL"><img src="http://feeds.feedburner.com/~f/iplosion-security?i=K1bzfepL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/iplosion-security/~4/62776238"/>]]></content:encoded>
			<wfw:commentRSS>http://www.iplosion.com/archives/54/feed/</wfw:commentRSS>
		<feedburner:origLink>http://www.iplosion.com/archives/54</feedburner:origLink></item>
	</channel>
</rss>
