Shared posts

22 Jul 07:35

30C3 Call for Participation (EN)

by fukami

30C3 – 30th Chaos Communication Congress
December 27th–30th 2013, CCH, Hamburg

30C3 is the 2013 edition of the Chaos Communication Congress, the Chaos Computer Club’s international conference and hacker party.
During the four days between Christmas and New Year’s Eve, thousands of technology enthusiasts, tinkerers, artists, utopians and <foo> from Europe and all over the world come together at the Congress Center Hamburg (CCH) to exchange ideas, learn and party together. Participants engage with topics covering information technology, computer security, the make-and-break scene, critically constructive ways of dealing with technology and its effects on our societies.
The lecture programme review and selection process will be put on a new basis this year. Submitted talk proposals will be selected by content teams in charge of one of the following tracks:
  • Art & Beauty
  • Ethics, Society & Politics
  • Hardware & Making
  • Security & Safety
  • Science & Engineering.

Tracks

Art & Beauty

Computers can be used to create art and beauty. This track is for all those lectures and installations dealing with creative approaches to culture, music and art.

Hardware & Making

This track is about all those tools designed to turn the digital into the physical. Included in this track is everything from trendy CAN bus hacks and software defined radio hardware to obscure hardware reverse engineering. We are looking forward to any submissions by those who, when they speak of cloud hacking, actually mean making it rain, who see e-bikes as a transport layer, and who happily forward viruses from their inbox to their dna sequencer. If you design or abuse circuit boards and firmware, mod your 3D printer to reliably barf out non-plastics, and aren’t afraid to get your hands dirty, this is your track.

Ethics, Society & Politics

This track is about ethics, society and politics in the digital age. This includes submissions dealing with the dangers of technology in politics and society as well as the threats that politics pose for the digital society. At the same time, aside from fear and danger, we are interested in examples of happiness and hope for a better world through the interaction of  technology and politics.

Science & Engineering

This track is for all those who don’t think Knuth was a cute polar bear at the Berlin zoo. Submissions containing exoskeletons and “bleeding edge” research – anything cool that comes out of universities – as well as DIY experiments that aren’t about typical making belong in this track. You’ve solved the halting problem? Submit!

Security & Safety

This track gathers people and groups who wish to describe or discuss technical computer related safety and security. We are interested in everything suitable to develop or bypass security mechanisms. This is not limited to software systems,  this year the committee is especially interested in hardware topics. Technical weaknesses, tools, techniques and allied research all belong in this track.

Assemblies

Assemblies are  places where communities of interest can meet in the core of the congress. They are comparable to villages at the various hacker camps. We will have lots of space again, so larger installations will be possible. The assemblies will be organized in the public Wiki.

Self-understanding of the 30C3

The CCC runs the congress with the help of self-organized volunteer teams and on its own funds. We are proud of this and we are looking forward to once again being able to put together a congress with no external influences and no need for self-censorship. We regard this event as one of the few places where a global exchange using the creative-critical approach to technology and society is possible without censorship.
We are not providing a stage to secret services or other state organisations. However, based on our concept and on the fact that work is done on a voluntary basis, a thorough advance screening of participants and speakers is not possible.
It goes without saying that everyone attending the conference should be treated with respect and consideration. A significant proportion of delegates and speakers value their privacy, the integrity of their own data and their photographic likenesses. Those who attach less importance to personal agency in these matters are in a stronger position. We therefore ask them to respect the feelings and wishes of others.

Submission Guidelines

For talks and workshops:

Please send us a description of your suggested talk that is as complete as possible. The description is of particularly importance to the selection, so please ensure it is as clear as possible. Quality takes precedence over quantity. Due to the non-commerical nature of the Congress, presentations which aim to market or promote commerical products or entities will not be entertained.
As it  is likely that  that there will be multiple submissions about the same topic, please show us exactly why your talk should be part of the conference. Please write something about yourself, your environment and your motivation. It does not matter if the talk has been held at another conference, All it has to be is up to date.
Talks should be no longer than 45 minutes plus 15 minutes for question and answers. Longer slots are possible in principle. There are 20-minute slots as well. Please tell us the proposed length of your talk at the time of submission. In addition, there are 5-minute short talks (so-called Lightning Talks) for small ideas, projects or rants. These will only be organised during the event.

For projects, installations and other fun things:

A formal submission is not required. Once again there willl be a Wiki where needs for space and other resources will be collected. Simply start considering now what you would like to make, bring or show, before that Wiki goes online. We have a lot of space and we are open for crazy and surprising stuff.

Language of the presentation:

Although 30C3 is an international conference and a lot of content is being presented in English, this year there will again be a translation team which will simultaneously translate most German talks into English. So if you are not completely comfortable with presenting in English, please feel free to present your lecture in German. Please also use the language of your presentation for its title, so as not to confuse any visitors.

Publication:

Audio and video recordings of the lectures will be published online in various formats under the license CC Attribution 3.0 Germany (CC BY 3.0 DE). This license allows commercial use of excerpts by media institutions as part of their reporting. If you do not wish material of your lecture to be published or streamed, please let us know in your submission. Note: As German law and therefore the license might differ from the law of your country please let us know if you should have any issues or questions regarding the exact implications. Unfortunately we can’t provide a bullet-proof translation.

Travel, costs & visa

Chaos Communication Congress is a non-commercial event, where neither the organisers nor the speakers are being paid. If necessary, we are however able to provide some support regarding travel costs and accomodation.
If you need help applying for a visa,  such as an official invitation to present at the German embassy, please let the content team know well in advance. Please be aware that the visa application procedure may take up to six weeks.

Dates & deadlines:

  • September 15, 2013 (23:59 UTC): Deadline for submissions
  • November 15, 2013: Notification of acceptance
  • December 27–30, 2013: Chaos Communication Congress

Online submissions only:

All submissions of lectures and workshops have to be entered into our conference planning system, which is located at the following URL: https://frab.cccv.de/cfp/30C3.
Please follow the instructions there. If you have any questions regarding the submission, you are welcome to contact us via email at 30c3-content(at)cccv.de.
22 Jul 07:32

NoScript and FlashGot Unsigned

by Giorgio

Notice to mariners: starting with NoScript version 2.6.6.9 (ATM still a RC) and next version of FlashGot (1.5.5.6, most likely) the packages (XPIs) of my Firefox add-ons won’t be signed anymore.

Almost no other Firefox extension gets signed these days (NoScript and FlashGot had been among the earliest and few for a long time), and AMO being the only authorized repository you can install the add-on from by default, there’s little or no point in keeping the relatively expensive and clunky signature machinery in place.

You probably noticed AMO lags quite a lot behind stable versions. That’s because the editorial staff manually checks every line of code published as “stable” for security issues and known performance problems. Therefore, if you’d like to always run the latest and safest (a good idea for a security tool like NoScript), you may want to switch to the fast lane, i.e. the automatically up-to-date beta channel, by installing 2.6.6.9rc1 now.

19 Jul 12:15

The H is closing down

The H is closing its doors four and a half years after heise online UK was redesigned as a open source and security news and features web destination
    


19 Jul 08:39

Study Finds iOS Apps Just As Intrusive As Android Apps

by samzenpus
wiredmikey writes "Despite fevered arguments that iOS is more secure than Android, and that Android offers developers more options than iOS, a study has found that both platforms are equally as invasive and curious when it comes to collecting user data. Security firm BitDefender analyzed more than 522,000 apps over the past year and focused on the 'intrusive behaviors' the app developer may have included in the product, such as tracking location, reading contact lists, and leaking your email address or device ID. According to Catalin Cosi, iOS applications appear to be more focused on harvesting private data than the ones designed for Android. Cosi did acknowledge that Android apps state all the permissions needed at installation time and there is no way to change the settings afterwards, while iOS permissions are requested at run-time, as the specific resource is used, making iOS a little bit more secure in practice."

Share on Google+

Read more of this story at Slashdot.



19 Jul 07:29

Snowden's Dead Man's Switch

by schneier

Edward Snowden has set up a dead man's switch. He's distributed encrypted copies of his document trove to various people, and has set up some sort of automatic system to distribute the key, should something happen to him.

Dead man's switches have a long history, both for safety (the machinery automatically stops if the operator's hand goes slack) and security reasons. WikiLeaks did the same thing with the State Department cables.

"It's not just a matter of, if he dies, things get released, it's more nuanced than that," he said. "It's really just a way to protect himself against extremely rogue behavior on the part of the United States, by which I mean violent actions toward him, designed to end his life, and it's just a way to ensure that nobody feels incentivized to do that."

I'm not sure he's thought this through, though. I would be more worried that someone would kill me in order to get the documents released than I would be that someone would kill me to prevent the documents from being released. Any real-world situation involves multiple adversaries, and it's important to keep all of them in mind when designing a security system.

19 Jul 07:28

PRISM Q&A

by schneier

Mikko Hypponen and I answered questions about PRISM on the TED website.

18 Jul 15:56

July 2013 Critical Patch Update Released

by Eric P. Maurice

Hello, this is Eric Maurice.

Oracle just released the July 2013 Critical Patch Update.  This Critical Patch Update provides 89 new security fixes across a wide range of product families: Oracle Database, Oracle Fusion Middleware, Oracle Hyperion, Oracle Enterprise Manager Grid Control, Oracle E-Business Suite, Oracle PeopleSoft Enterprise, Oracle industry Applications, Oracle Supply Chain Products Suite, Oracle VM, Oracle MySQL, and Oracle and Sun Systems Products Suite.

As a reminder, security fixes for Java SE will continue to be released on a separate Critical Patch Update schedule until October this year.  Starting with the October 2013 Critical Patch Update, Java SE security fixes will be released on the normal Critical Patch Update schedule, along with the security fixes for all other Oracle products, thus likely to increase the total number of security fixes released with each Critical Patch Update.

Out of the 89 new security fixes included with this Critical Patch Update, 6 are for Oracle Database.  One of these database vulnerabilities is remotely exploitable without authentication.  The highest CVSS Base Score for these database vulnerabilities is 9.0.  This score is related to a vulnerability (CVE-2013-3751) which affects the XML Parser on Oracle Database 11.2.0.2 and 11.2.0.3. 

21 of the fixes included in this Critical Patch Update are for Oracle Fusion Middleware.  16 of these vulnerabilities are remotely exploitable without authentication, and the highest CVSS Base Score for these vulnerabilities is 7.5.  This score affects a JRockit vulnerability (CVE-2013-2461), which in fact is related to a series of Java vulnerabilities fixed with the June 2013 Critical Patch Update for Java SE and applicable to JRockit.   With the inclusion of Java in the normal Critical Patch Update schedule starting in October 2013, the release of JRockit and Java security fixes will be integrated.  Note also that with this Critical Patch Update and the previously-released Critical Patch Update, Oracle has been working on addressing a series of known Apache bugs in Oracle HTTP Server.  Finally, note that a number of the Oracle Fusion Middleware vulnerabilities have already been fixed on all supported versions.  The listing of these vulnerabilities in the Oracle Fusion Middleware risk matrix should provide an additional impetus for users of affected versions to update their systems to a more secure release.

The Oracle and Sun Systems Products Suite receive a total of 16 new security fixes.  8 of the vulnerabilities are remotely exploitable without authentication, and the maximum CVSS base Score for these vulnerabilities is 7.8.

Oracle MySQL receives 18 new security fixes.  2 of the MySQL vulnerabilities are remotely exploitable without authentication.  The highest CVSS Base Score for these bugs is 6.8. 

As usual, Oracle recommends that customers apply this Critical Patch Update as soon as possible.  In addition, as previously discussed, Oracle does not test unsupported products, releases and versions for the presence of vulnerabilities addressed by each Critical Patch Update.  However, it is often the case that earlier versions of affected releases are affected by vulnerabilities fixed in recent Critical Patch Updates.  As a result, it is highly desirable that organizations running unsupported versions, for which security fixes are not available under Oracle Premier Support, to update their systems to a current release so as to fully benefit from Oracle’s ongoing security assurance effort (see for example Ovum’s Paper: Avoiding Security Risks with Regular Patching and Support).

 

For More Information:

The July 2013 Critical Patch Update Advisory is located at http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html  

The Oracle Software Security Assurance web site is located at http://www.oracle.com/us/support/assurance/overview/index.html

18 Jul 15:56

[dos] - Microsoft Office PowerPoint 2007 - Crash PoC

Microsoft Office PowerPoint 2007 - Crash PoC
18 Jul 15:54

2013. július 17. – Fogalomtár

A fogalomtár célja, hogy az etikus hackelési projektek során tapasztalható definíciós zavarokat csökkentse, valamint elősegítse egy jól meghatározott, az ügyfél számára megfelelő vizsgálat elvégzését.Fogalomtár letöltése
18 Jul 15:53

Tumblr Tells Users: “Change Passwords Now”

by Lysa Myers
I know we harp on the dangers of Wi-Fi a lot; but, really, there’s a good reason why! The latest example comes from Tumblr, which just provided a great object lesson that we can all learn from. In an official announcement, Tumblr has issued a warning to users of its iOS apps that because their apps [...]
18 Jul 15:52

[local] - Symantec Workspace Virtualization 6.4.1895.0 Local Kernel Mode Privilege Escalation

Symantec Workspace Virtualization 6.4.1895.0 Local Kernel Mode Privilege Escalation
18 Jul 15:52

[dos] - Windows Movie Maker Version 2.1.4026.0 (.wav) - Crash POC

Windows Movie Maker Version 2.1.4026.0 (.wav) - Crash POC
18 Jul 15:52

Igazságot akar a Microsoft Prism-ügyben

Nem tagadják az adatszolgáltatást, de a közvetlen hozzáférést igen, az ügyészhez fordultak.
16 Jul 20:48

EFF Sues NSA, Justice Department, FBI

by Soulskill
New submitter Jawnn writes "The Washington Post reports that the EFF has filed suit against the NSA in Federal Court in San Francisco, on behalf of multiple groups (court filing). Those groups include, 'Rights activists, church leaders and drug and gun rights advocates.' EFF Legal Director Cindy Cohn said, 'The First Amendment protects the freedom to associate and express political views as a group, but the NSA's mass, untargeted collection of Americans' phone records violates that right by giving the government a dramatically detailed picture into our associational ties. Who we call, how often we call them, and how long we speak shows the government what groups we belong to or associate with, which political issues concern us, and our religious affiliation. Exposing this information – especially in a massive, untargeted way over a long period of time – violates the Constitution and the basic First Amendment tests that have been in place for over 50 years.' Apparently, not everyone out there is believing the 'If you have nothing to hide' excuses being offered up from various government quarters."

Share on Google+

Read more of this story at Slashdot.



16 Jul 13:36

Black Hat 2013: NSA director to speak at hacker conference

The organisers of the Black Hat conference have attracted the director of the American NSA, General Keith Alexander, as a keynote speaker. This has caused controversy
    


16 Jul 13:33

A look at Point of Sale RAM scraper malware and how it works

by Numaan Huq
A special kind of malware has been hitting the headlines recently - that which attacks the RAM of Point of Sale (PoS) systems.. In this article, Numaan Huq from SophosLabs takes a step back from the technical details and looks at the evolution of these PoS RAM scrapers.
16 Jul 11:43

Emlékezés a nőre, aki megmentette a sudo-t

by trey

Evi Nemeth az a nő, akire sokan csak a UNIX adminok nagyanyjaként emlékeznek. Az 1940-ben született mérnök, könyvszerző, tanár, megszállott vitorlázó. Volt. Feltehetően csak volt, mert már több mint egy hónapja annak, hogy a Nina nevű hajó, amelynek Evi fedélzetén tartózkodott, eltűnt a Tasman-tengeren. Az új-zélandi hatóságok július 5-én hagytak fel hivatalosan a keresésével.

Nemeth megbecsült tagja volt a rendszeradminisztrátorok közösségének. Vezető szerzője volt a UNIX System Administration Handbook (1989, 1995, 2000), Linux Administration Handbook (2002, 2006) és UNIX and Linux System Administration Handbook (2010) kiadványoknak.

Megbecsült tagja volt a matematikai köröknek, foglalkozott a Diffie-Hellman-problémával, 2-es Erdős-számú volt.

Egy írás olvasható itt arról, hogy Evi Nemeth átvitt értelemben hogyan mentette meg a sudo-t.

16 Jul 09:13

Sony to pay £250,000 fine for PlayStation Network breach

by Lisa Vaas
Sony has thrown in the towel on its appeal of a £250,000 fine ($377,500) imposed after its PlayStation Network was hacked in April 2011, losing data such as names, addresses, email addresses, dates of birth and account passwords of millions of users.
16 Jul 07:38

Problems with MS13-057, (Mon, Jul 15th)

Inforworld is reporting that the WMV codec patch included in MS13-057 causes a number of video ...(more)...

15 Jul 17:39

NSS 3.15.1 brings TLS 1.2 support to Firefox

Network Security Services (NSS), the collection of cryptographic libraries which is used, among others, by Mozilla's Firefox browser, now supports TLS 1.2. This enables the use of TLS with HMAC-SHA256 ciphers
    


15 Jul 15:36

Edward Snowden Nominated For Nobel Peace Prize

by samzenpus
An anonymous reader writes "A Swedish professor of sociology has nominated Snowden for the 2014 Nobel Peace Prize. Giving him the prize would also 'save the Nobel Peace Prize from the disrepute that incurred by the hasty and ill-conceived decision to award U.S. President Barack Obama' the prize, according to professor Stefan Svallfors. He notes ultimately that at great personal cost, 'Edward Snowden has helped to make the world a little bit better and safer.'"

Share on Google+

Read more of this story at Slashdot.



15 Jul 11:50

Maintenance of Apache web server 2.0 discontinued

Version 2.0.65 will be the last update to Apache's HTTP Server 2.0. Those who still use it must act now: a security problem will remain unresolved
    


15 Jul 09:21

NSA's Access To Microsoft's Services Detailed

15 Jul 09:21

New Zero-Day Attack Copies Earlier Flash Exploitation

by Haifei Li

Late on July 10, Microsoft released a blog post disclosing that they were aware of a zero-day attack in the wild. This attack exploits a previously unpatched Internet Explorer vulnerability (CVE-2013-3163). It’s interesting that the vulnerability was just patched in this month’s Patch Tuesday (July 9), which is perhaps only a coincidence. Although we do not know how long ago the attack began, we do have the official solution right now. (Apply the Microsoft patch if you haven’t done so.)

McAfee Labs rapidly responded to the threat. While digging into the exploitation process, we realized that this attack leverages the same exploitation technology that we were first to identify in an Adobe Flash zero-day attack in February. We call the new exploitation technology the Flash Vector exploitation. As highlighted in our blog post from February, we made a fairly accurate prediction:

More important, the technique looks like a common exploitation approach to Flash Player. The vulnerability actually doesn’t help much–just overwriting few bytes that are considered as a field of “element number” for a specific ActionScript object. These traits show that the exploitation technique is not limited to this particular Flash vulnerability; it may apply to other Flash or non-Flash vulnerabilities.

Both of these attacks leverage a weakness inside Flash Player’s custom heap management, especially, for the heap management of ActionScript “Vector.<>” objects. During our analysis, we also found some minor differences between these two attacks:

  • Because the trigger of the previous attack is a Flash vulnerability, the exploitation contains a step that frees the heap block (“leaving the hole”). In the second case, this step is not necessary because the trigger is an IE vulnerability. IE and Flash use different heap managements; thus IE can overwrite the memory bytes managed by Flash.
  • In the earlier exploitation, the zero day leveraged the “Vector.<Number>()” object and corrupted its length field. In the current case, the exploit leverages the “Vector.<uint>()” object (corrupting its length field as well). For example, the following code sprays a lot of “Vector.<uint>()” objects in the memory:

vector_spraying1

McAfee Labs has released a couple of UDS signatures to protect customers of our Network Security Platform against the IE vulnerability as well as the exploitation. Signature “UDS-HTTP: Microsoft Internet Explorer CBlockElement bdo element tag Use After Free Vulnerability I” addresses the vulnerability, and “UDS-HTTP: Microsoft Internet Explorer CVE-2013-3163 Flash Exploitation” handles the exploitation. Also, the generic buffer overflow prevention feature on our HIPS products will stop the related attacks.

The author would like to thank Bing Sun, Chong Xu, and Xiaoning Li (Intel Labs) for their help with the analysis.

15 Jul 09:21

E-Voting Source Code Made Public In Estonia

by Soulskill
New submitter paavo512 writes "Server-side source code used for electronic voting was made fully public by Estonian officials on July 11 (in Estonian). The aim is to encourage more specialists to get involved in the technical analysis of the software. It is hoped that public overview will help to ensure the security of the system. E-voting has been successfully used five times in Estonia since 2007. It facilitates national ID cards which are obligatory for all citizens. In the next municipal elections later this year it is planned to test an experimental feature where the voter can check via a physically separate channel (smart phone) if his or her vote has been registered correctly. The publicized source code is available at GitHub."

Share on Google+

Read more of this story at Slashdot.



15 Jul 09:20

Amazon One-Click Chrome Extension Snoops On SSL Traffic

by Soulskill
An anonymous reader writes "It turns out Amazon has its own sketchy method of snooping on all your browser traffic — even SSL traffic — through their one-click extension for Chrome. As designed, the extension reports every URL you visit, including HTTPS ones, to Amazon. It uses XSS to provide some of its functionality. It also reports contents of some website visits to Alexa. The Amazon extension has also been exploited to allow an attacker to gain access to SSL traffic on browsers that have it installed."

Share on Google+

Read more of this story at Slashdot.



15 Jul 09:20

[webapps] - McAfee ePO 4.6.6 - Multiple Vulnerabilities

McAfee ePO 4.6.6 - Multiple Vulnerabilities
15 Jul 09:20

[local] - Corel PDF Fusion Stack Buffer Overflow

Corel PDF Fusion Stack Buffer Overflow
15 Jul 09:20

Snowden elfogadta Venezuela (és mások) menedékjog felajánlását

by trey

Folytatódik a Snowden ügy, nézzük az elmúlt napok fejleményeit. Richard Stallman és Julian Assange tegnapelőtt találkoztak, hogy egy Edward Snowden & Bradley Manning mellett szóló kampány részleteit megbeszéljék. Akkor készült ez a kép:

Edward Snowden emberi jogi szervezetekhez és magányszemélyekhez juttatott el egy állásfoglalást tegnap, moszkvai idő szerint délután 5 órakor a seremetyjevói repülőtéren. A szervezetek közt megtalálható volt az Amnesty International és a Human Rights Watch is. Snowden állásfoglalása elolvasható itt.

A dokumentumból kiderül, hogy Snowden elfogadta Venezuela (és mások) menedékjog felajánlását, de mivel nem tud biztonságosan eljutni Dél-Amerikába, menedékjogi kérelmet nyújtott be Oroszországhoz is. Snowden álítólag kész eleget tenni annak az orosz feltételnek, hogy csak akkor kaphat menedékjogot, ha nem árt a továbbiakban az USA-nak.

15 Jul 09:19

DuckDuckGo: Illusion of Privacy

by timothy
An anonymous reader writes "With all of the news stories about users moving to DuckDuckGo because of NSA spying, this article discusses why the privacy provided by DuckDuckGo is more the privacy from third-party tracking (advertisers) but may do little, if anything, to prevent the NSA from tracking your searches."

Share on Google+

Read more of this story at Slashdot.