Friday, July 13, 2012

CRAP Internet Computer Security
For The Last 14 Years

--
Today I ran across a fascinating article at the great Ars Technica entitled:

iTunes has "more robust" security than some of our critical infrastructure.
Security researchers have blown the whistle on serious vulnerabilities in an Internet-connected system used by the US military, hospitals, and private industry to control boilers, air-conditioners, security alarms, and other critical industrial equipment.
The defects in the Niagara Framework, which links more than 11 million devices in 52 countries, could allow malicious hackers to seize control of critical infrastructure, an article published by The Washington Post warned. . . . 
"Sadly, we can honestly say that the security of iTunes is more robust than most ICS software."

The full article is well worth a read by anyone interested in the state-of-the-mess we call computer security. We also get to smile that Apple is getting seriously serious about security these days. And you thought iTunes sucked. ;-D

I posted a couple comment responses to the article under my old nick of 'zunipus' (the same name I use for my personal abstraction rants blog). My comments will sound familiar. But I added a paragraph about the recently discovered 'Flame' titan malware for Windows. Enjoy, get all paranoid, or laugh:

"...the most disappointing thing he encountered in his interactions with Tridium was its "eagerness to blame the customer." "
And why not! It's the Spirit Of The Age in biznizz:
Abuse Thy Customer!
This is how business FAILs. This is why we continue to be stuck in our ongoing worldwide economic depression, the second worst in a century.
Until we rid the world of what I call 'Marketing-Morons', those people who insist upon selling products with total disregard for respecting the customer, our system of world business it totally fracked. 
~ ~ ~ 
One historical perspective:
In 1998 the country of China was provided 'Most Favored Nation' status by the Clinton Administration.
At that point, the government of China became involved with Chinese computer hackers and assisted them in forming what became the 'Red Hacker Alliance'. (Please Search for this term for references). [I have a number of articles here at Mac-Security covering my anti-pals from the Red Hacker Alliance].
For the next eight (8) years, the China government-assisted Red Hacker Alliance succeeded in 'PWNing' (OWNing) or botting every single US government Windows-based computer exposed to the Internet. All of them. The infection bots were able to send all data on those computers directly to China. It was not until 2007 that the US government publicly acknowledged the problem.
Last month the 'Flame' malware and its bot network were discovered, exposed and shut down. It has been estimated that Flame had been running on the Internet for at least five (5) years before its discovery. This malware was found to be the most ambitious, best designed and capable malware ever created, to our knowledge (!). Experts have stated that Flame could only be the work of a consortium of malware developers or a major government. Flame took advantage of what was, until its discovery, an extremely old zero-day exploit in Windows. Flame was capable of performing literally any computer task assigned to it by the bot wranglers, whoever they were. It was the perfect multi-functional malware, the ultimate spyware. It could infect and PWN any Windows-based computer by a mere drive-by Internet infection. That means no Windows machine connected to the Internet was immune unless the bot wranglers designed them so. The only data we have regarding its activity and purpose was its proliferation across the Middle East.
That's how CRAP Internet computer security has been, across the world, for the last 14 years.

Of course, it's tempting to add: "Thank Goodness We Use Macs!" But don't be too naive. The fact that the Java drive-by infection version of the FlashBack malware managed to PWN over 600,000 Macs this past spring should keep us all humble and wary.
--

SpamCop.net Goes FUBAR Follow-Up

--
I've heard back from SpamCop regarding its problems.

The SpamCop website is significantly automated. This automation has become, for unspecified reasons, out of control. This ended up being illustrated by the fact that my own SpamCop account was terminated because the automated system decided I had been submitting too many spam reports within too short a period of time. This was in fact an insane conclusion. What I had actually done was attempt to submit the same single spam repeatedly with total failure being the result. These spam report attempts built up in an 'Report' attempt list, which I emptied once I was actually able to access the full SpamCop interface.

The folks at SpamCop were extremely apologetic and cleaned out the automation error within 24 hours after I reported it. Thank you!

Since that time I have found the automation blundering to be somewhat dissipated. But the automation continues to be slow. On two recent occasions I ran into dead end results when attempting to report spam.

This is bad. This is a disincentive to bother reporting spam. I know the SpamCop folks are attempting to gain control. I know their attempts have been ongoing for a full month now.

Happily, I can report that the email submission method of reporting spam is working perfectly. (So bite me, SpamRats!) This is now the method I am using while I snooze waiting for SpamCop's automation system to be cleaned up and reestablished.

If I discover SpamCop's automation to again be working perfectly or I hear further details from the folks at SpamCop, I will report here. Despite this setback, I continue to encourage everyone to use the SpamCop service for wiping SpamRats off the face of the planet.
--

Friday, July 6, 2012

SpamCop.net goes FUBAR

--
If you're an avid SpamCop.net user, as I am, you are not alone if you have found their website to have gone FUBAR. From reading the SpamCop Discussion forum, this problem has been intermittent since June 14, 2012. Apparently I have been lucky logging in and reporting until today. At this point I find it 100% impossible to report spam via the website. A variety of errors are being thrown. I can occasionally log into the main page but cannot log into the forum, which makes no sense.

Thankfully, I verified that the email method of submitting spam is working perfectly at this time. Each verified account has its own email address it can use for submissions.

I'd like to say the problem was being caused by a DDOS attack from some SpamBot network. That's easy to solve. But there is no sign at this point of that being the problem. IMHO they have hosed their server and don't have an adequate backup to restore it again. IOW, IMHO, FGS!, they broke the #1 Rule Of Computing. It doesn't get any worse. I.E. not good.

It is particularly disturbing to me that SpamCop has not publicly acknowledged this problem. There is no official announcement anywhere on the site. That means they're freaked, have no solution, and/or are too embarrassed to admit the situation. I.E. not good.

I'm sure the SpamRats are having a party. SpamCop remains a primary source of free spam blacklist data to the world. Enjoy the party while it lasts little SpamRats. We have other methods of spam reporting up our vigilant sleeves. Darn! :-P

As the SpamCop.net problem evolves, I will be reporting here.
--

Thursday, July 5, 2012

'Find And Call' Trojan horse
Found At iOS App Store
(and removed)

--
The Walled Garden Has Been Breached. 


This was very bad. Thankfully it was over in a hurry.


Find and Call: Leak and Spam



Quoting Denis at Kaspersky:
...a Trojan that uploads a user’s phonebook to remote server. The 'replication' part is done by the server - SMS spam messages with the URL to the application are being sent from the remote server to all the contacts in the user’s address book. 
The application is called ‘Find and Call’ and can be found in both the iOS Apple App Store and Android’s Google Play. We’ve already informed both Apple and Google but we haven’t received an answer yet.
I checked it out via iTunes at the Apple iOS app store. 'Find And Call' had been there as it comes up in the hot help as you type in the name. Thankfully, Apple has pulled the app out of the store.


I hereby declare this iOS malware to be INERT. However:


1) The app is active In-The-Wild on victim's iOS devices.


2) Technically, people could grab it out of their iOS backup or off their iOS device and plant it onto a jailbroken iOS device, which is highly unlikely.


3) The malware writers could fool Apple again and get it back on the iOS app store, which is highly unlikely.


Meanwhile, the Android version of this malware is more likely to remain hanging around at the various Android app stores unless Google, and everyone else running a store, use live running anti-malware to detect it and kill it off their stores.


IMHO: It is of grave concern that Apple did not catch the behavior of this malware before approving it for the iOS App Store. It's another kick in Apple's nuts, hopefully further awakening their security vigilance.


BTW: This is not the first time 'malware' has appeared in the Apple iOS app store. Apple security expert and hacker Dr. Charlie Miller managed to slip one by Apple last year. This IS, however, the first time that deliberately malicious software has been slipped by Apple.


Kill the deceitful messenger, love the results...
---

Tuesday, June 26, 2012

The Fight For Internet User Privacy

--
"Eternal vigilance is the price of liberty."- Thomas Jefferson 
"They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety."- Benjamin Franklin

Today we learned that advertising groups have FAILed to approve full support of the Do Not Track system. They insist upon user surveillance with or without targeted ads. Surprise. :-P

Mike Zaneis of the Interactive Advertising Bureau trade group says his industry will suffer if people can just switch off data collection. [Bolding = mine.]
I say:
THEN SUFFER, MARKETING-MORON BOZONS! User surveillance is NOT your right. Personal privacy is everyone’s right. Deal with it.

Let’s read from the USA Constitution Bill of Rights:
Amendment IV 
The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
As an actual US patriot (as opposed to hypocritical political blowhards) and supporter of all US citizen rights, I hereby present:

The anti-tracking browser tools I use with Apple Safari. 

I'll start with the small stuff and work up to the all-out nuke solutions.

1) Do Not Track Plus, a free Safari extension from Abine. It provides ad sources with the 'Do Not Track' notification. The Plus is that it blocks over 600 tracking cookies and self-updates its tracking cookie list. It is compatible with Mac or PC for the following web browsers: Chrome, Firefox, Safari and IE. I use the Firefox extension version as well. It's not perfect, but it's a nice deal. Install it and forget it.

2) Incognito, a free Safari extension from Orbicule. This is another simple install it and forget it extension. It only blocks tracking cookies from Google Adsense, Google Analytics, embedded YouTube videos, Facebook, Twitter and B kontakte. Orbicule provide regular updates.

3) Ghostery, a free Safari extension. It is also available as a Firefox add-on and works in exactly the same way. Here's where we get more complicated. Ghostery is different in that it focuses specifically on what are called 'web bugs' and scripts, not tracking cookies. Web bugs are used as a more limited but sneaky method of user surveillance by advertisers and spammers. Therefore, use it in addition to a tracking cookie control extension or application. You can read about web bugs HERE.

Once Ghostery is installed, you have to go through an options setup process. I highly advise going through the setup carefully:

A) I prefer checking GhostRank ON. It helps the Ghostery developers to identify web bugs active on the Internet which allows them to be blocked in the future.

B) You will most likely want to UNcheck "Show alert bubble'. It drives me crazy and blocks part of web pages. You'll only want it on if you're getting serious about the surveillance at specific websites.

C) Leave 'Show bug script sources' ON. It's unobtrusive and may be interesting on occasion.

D) Leave 'Enable bug list auto-updating' ON.

E) Next we come to the Blocking Options. This is where Ghostery can cause you nasty troubles. It is possible here to check ON the blocking of something you actually do NOT want to block.

My favorite example of a problem is the web bug that Google forces you to use if you want to be able to use iGoogle, their terrific website where you can set up for RSS feeds, widgets and small games. I use iGoogle constantly. Having Ghostery block Google's forced web bug causes major problems. (Screw you Google for making me gag on your user surveillance! But I do like iGoogle a lot). In this example you will want to make sure you UNcheck 'Google Widgets'.

The best approach is to check ON the top box, which checks ON all the blocking. You'll then have to go down the list of well over 1,000 web bugs to UNcheck the web bugs you're required to use at particular web sites. This can be an obnoxious and tedious process.

My approach is to wait until I run into a problem accesses some aspect of a particular web page. I then go into the Safari (or Firefox) and turn OFF Ghostery. I reload the troubled web page and see if the problem went away. If it did go away, you'll want to go into the Options for Ghostery and figure out what you must now UNcheck. I like keeping a list of the UNchecked items I must use in Ghostery. I do this in a text file I keep with a folder I made for notes about Ghostery. (BTW: If turning off Ghostery didn't solve your web page problem, try turning off ALL your Safari extensions, via the convenient OFF - ON switch, and reloading the page.

Another approach is to use Ghostery to create a list of web URLs where you do NOT want Ghostery to block anything. You simply paste in the URL, hit the 'Add' button and it is added to the list. Clunky, I know. But if you want control, this is the state of the art.

If you'd like to learn more about Ghostery, they have a fairly active blog HERE.

4) Safari Cookies, free Safari extension from SweetPProductions, the makers of the Cookie app, #5 below. You may find the extension version of Safari Cookies to be adequate for your needs. Some people may be concerned that the installation requires SIMBL (aka SIMple Bundle Loader) which essentially adds some useful APIs not supplied by Apple. At one point in the past it caused Mac problems. Thankfully, I have had no problems with SIMBL for years since.

Compared to the full Cookie application, it requires the user to do a lot of manual maintenance of their cookies. Compared to the crap cookie control in every web browser I have ever used, this extension is a  nice godsend. But it does require some work. There are no automatic features apart from automatic updates via Safari. Also, it does not point out actual tracking cookies. That's for you to figure out. Therefore, you end up periodically killing off piles of cookies that you might rather keep.

This extension had a long series of bugs at one point, while the developer was getting a handle on it. I felt like a beta-tester, regularly sending bugs into the developers. But they were responsive and eventually stamped them all out. These days it is well worth using, especially for free.

5) Cookie, the $10 (on sale) application from SweetPProductions. This is the Bells-And-Whistles cookie control application. I like it a lot. I bought it, I use it. It has one silly bug whereby it typically brings up its preferences window when it boots, even when you've checked the box to tell it not to. Otherwise, this thing is well worth the cost if you want total cookie control with the least amount of effort. It has a 14 day trial period. Highly recommended.

When you open the Cookie preferences, the first thing you'll notice is that the thing is thorough: It lists not just plain old website cookies, but Flash cookies, Silverlight cookies and Databases dumped on your computer by various websites. Every one of these methods of placing data on your computer can be used for surveillance. I hate that.

There is a concept called "The Evercookie" that potentially allows user surveillance via any of a number of data sources retrievable from your computer. Plain old web browser cookies are only one of several sources of surveillance data. You can use the Cookie application to wipe out just about all the rest of these surveillance sources. Well, that is until HTML5 becomes standard on the Internet. HTML5 creates a number of new and obnoxious ways for websites to grab surveillance data. I'm expecting Cookie to keep up with all of them with time.

Setting up Cookie:

A) Preferences tab. Initially you do NOT want Cookie to remove any of your cookies. Leave the 'Remove' checkboxes UNchecked. This is recommended specifically during the period when you want to collect cookies in order to sort them as wanted or unwanted in the other four tabs. Read ahead and you'll see what I mean.

Once you have finished the period of time when you sort out the good cookies from bad, I recommend checking ON everything EXCEPT:
- Browser History, if you are the only user on your computer. Otherwise, you might want to periodically dump the history related data.
- 'and Hide Dock Icon'. I like the menubar icon for accessing the Cookie app. Alternatively, you can access it by Command-Tabbing over to it then hitting Command-Comma to bring up its preferences.
- Initially you do NOT want to have cookies removed

Where you may disagree with me is the use of the preferences for 'Remove'. The third checkbox is for remove "Every [ ] minutes while Browser is Open". This can potentially cause some problems with you being logged OUT of certain websites when a tracking cookie is removed. Again, Google has sunk to using this trickery on some of their websites. Therefore, you end up having to log into affected pages again and again. This can get annoying. But I found for my own personal use that setting up regular unwanted cookie removal was preferable. I have Cookie dump tracking cookies every few minutes. Test it and see what works for you.

B) Cookies Tab: Now we get into the initial setup tedium. I found the best approach was to spend some days surfing around the web to my usual places, then set aside a time to comb through the cookies list in order to check ON the cookies I like and leave the rest unchecked. The unchecked cookies will be from sites you've never heard of or from sites where you never log in.

For example, right now I have 41 cookies from google.com that are NOT tracking cookies. I log into the various Google sites for these cookies and want to keep them. Therefore, after hitting the 'Remove All Tracking Cookies' button, I check ON the rest of them via the check box for their directory header. Meanwhile, I see a pile of ad-rat websites that snuck a barrage of crap cookies onto my machine from gawd-know-what website. No way am I checking them on. Once I have checked on all those I want, I hit the button to 'Remove All Non-Favorites' and good riddance.

C) Flash Cookies Tab: I can't imagine ever wanting to keep any Flash cookies. Why isn't Flash dead already? But perhaps you have some very useful Flash game, app or video you use and would like to keep the related cookie. This is the place. It works just like the Cookies tab.

D) Silverlight Tab: If you use NetFlix, you'll want to keep its Silverlight cookie so you won't have to log into the Netflix site every time you visit. Etc.

E) Databases Tab: This list gets as complicated as the Cookies Tab list. It works the same way. Check ON the sites you visit regularly. Remove all the rest. If you don't recognize a listed website, you're most likely safe killing its database. If you figure out that you want that database, check it on later.

Where the Databases tab gets a bit strange is with the databases for Safari extensions. These websites will probably seem obscure to you, but they will keep returning over and over. The 'Type' column can help you as it will tell you when a database is for a "Safari Extension" or "Chromium Extension" etc.

--> For me, the Cookie app is well worth the investment. I want total control over my cookies and over who gets to surveil me on the Internet. I haven't found a better cookie control app. Combining it with Ghostery is as good as it gets at this time.


Other tools with which I am not well acquainted:


Cookie Stumbler from WriteIt! Studios. It has had a spotty reputation. Therefore, I have not worked with it. The 'basic' version is $7.90. It uses a 'heuristics engine' only for tracking cookie detection. The 'standard' version, including a single year 'known tracking cookie' subscription, is $19.90. There is also a free Safari extension version with 'basic protection against most common tracking cookies.' This summer there is also supposed to be an iOS version available. I personally don't see the point of an annual tracking cookie subscription. Any decent cookie analysis can detect a tracking cookie. The standard version is also is not as functional as the Cookie application.

Flush, formerly from MacHacks.tv. This abandonware was a free Flash cookie removal tool. It had good reviews while it lasted. I have no idea whether it still works or where you can download it. The developer's website has been abandoned as well.

If you know of other kewl or new user privacy tools, please let everyone know in the comments!


A good place to watch the progress (if any) of the Do Not Track system is the Electronic Frontier Foundation. Among other things, EFF offer instructions HERE about how you can turn on Do Not Track in various web browsers, including Safari. Just keep in mind that, for the time being, Do Not Track is merely a concept attempting to become reality. That's why the tools listed above, annoying as they may be, are likely to remain important for some time to come.

FIGHT for user privacy! Win it!  \(^_^)/
--

Thursday, May 31, 2012

Download.com Serves Malware To Customers.
It's easier to fall further down a hole
than to crawl back out again.

--
[Updated 2012-05-31 @ 11:45 pm EDT]


The Windows side of Download.com has ruined its credibility in recent months thanks to its General Manager and V.P. Sean Murphy turning the site into a malware rat hole. At least that is the message from an April 24th article at Insecure.org:


Download.com Caught Adding Malware to Nmap & Other Software


Quoting from the article:

In August 2011, Download.com was taken on a new path by their General Manager and V.P. Sean Murphy. They started wrapping legitimate 3rd party software into their own installer which by default installs a wide variety of adware and other questionable software on users machines. It also does things like redirect user search queries and change their Internet home page. At first their installer forced people to accept the malware or close the installer (see screen shot of infected VLC installer in this article). Later they added a non-default "decline" button hidden way on the left side of the panel. Also, the initial installer shown in the previous screen shot claimed the software was “SAFE, TRUSTED, AND SPYWARE FREE”. In an unusual show of honesty, they removed that claim from the rogue installer.
(The bolding is mine in order to point out the apparent culprit-in-charge).

If this report is factual, the self-destructive behavior of CBS's CNET Download.com website is particularly disturbing to me as I have known the guys at VersionTracker for several years. Today I wrote to the creator of VersionTracker for clarification and he replied:
I don't know what they do on the Windows side as I'm not part of that group but I do know nothing gets wrapped or added to files on the Mac side.
I can verify that there is no evidence implicating VersionTracker's Mac software downloads. I am constantly running anti-malware on my Macs as part of my studies of computer security. None of the Mac software I have downloaded daily from VersionTracker has been infected with any form of malware. I am loathe to advise avoiding the VersionTracker aspect of Download.com. 

Nonetheless, anyone concerned about maintaining maximum Mac security might wish to consider using another software download website. Despite its own ethical failures, I can equally recommend MacUpdate.com

(Note: MacUpdate has, IMHO, been a deliberate and persistent marketing pawn of ZeoBIT, the shameful developers of MacKeeper. This problem has been made evident by MacUpdate's tolerance of ZeoBIT paid 4 and 5 star MacKeeper review bombing. I should point out that the VersionTracker has tolerated the same paid positive review bombing. Of course, compromised user reviews are a trivial issue next to infecting customer downloads with malware).

Sigh. 
The Spirit of the Age in business remains: 
Abuse Thy Customer.

No wonder our human world is stuck in an ongoing, long term economic depression. :-P


Thankfully, I continue to have faith in VersionTracker's Mac download sub-site over at Downloads.com.
--

Thursday, May 10, 2012

Chaos In The Field Of Anti-Malware

--
Today I wrote a comment in response to an article at ZDNet by my colleague and anti-malware collaborator Ed Bott.


The subject of Ed's article brought to mind my main discomfort with the field of anti-malware. When I started studying the subject back in 2005, I was expecting something professional, along the lines of my extensive training in science. Instead I found the field to be remarkably chaotic.

Here is the comment I posted in response to Ed's article:

Common Terminology, Scientific Approach
As an amateur in the field of Mac malware and writer about the subject since 2007, I've consistently found that the anti-malware community, particularly the anti-malware business, is unscientific and uncooperative. It's full of contention with people arguing over what means what, who named what first, whose malware naming convention is the best, on and on. The result is a chaotic mess that obviously confuses anyone casually trying to understand what's going on. There is no overview organization for the field. There is no peer review. There are some standards, but breaking those standards is the rule.
Therefore, when casual viewers mess up their terminology or make incorrect emphatic statements, I tend to be forgiving. If the anti-malware community really was scientific by nature, I'd take a stricter view. But it's not. Therefore, casual viewers are going to get things wrong without having any thoroughly reliable source of information from which to gather knowledge or opinions. 
For example, I had a conversation with the owners of a software download site on the net a couple years ago which revealed they had no comprehension of common terminology applied to malware. Every malware was a 'virus' to them. In turn they were sharing this misunderstanding with their users, who in turn repeated the same misinformation within their social circles.
As an example of pointless contention between anti-malware companies, why did Kaspersky have to come up with its own name for a Mac Trojan horse series, 'Flashfake', for what had already been published as 'Flashback' months ahead of time?
In this field, confusion is inevitable.

Maybe with time and experience, the field of anti-malware will mature. Meanwhile, we flounder.
--