error – Jupiter Broadcasting https://www.jupiterbroadcasting.com Open Source Entertainment, on Demand. Sun, 05 Nov 2017 03:48:42 +0000 en-US hourly 1 https://wordpress.org/?v=5.5.3 https://original.jupiterbroadcasting.net/wp-content/uploads/2019/04/cropped-favicon-32x32.png error – Jupiter Broadcasting https://www.jupiterbroadcasting.com 32 32 All Natural Drugs | User Error 33 https://original.jupiterbroadcasting.net/119626/all-natural-drugs-user-error-33/ Sat, 04 Nov 2017 19:48:42 +0000 https://original.jupiterbroadcasting.net/?p=119626 RSS Feeds: MP3 Feed | Video Feed | iTunes Feed Become a supporter on Patreon: Links A phone app that listens to your car and could warn of impending trouble | Ars Technica Rover Log Playlist Buy Now – Nintendo 2DS – Console Bundles

The post All Natural Drugs | User Error 33 first appeared on Jupiter Broadcasting.

]]>

RSS Feeds:

MP3 Feed | Video Feed | iTunes Feed

Become a supporter on Patreon:

Patreon

Links

The post All Natural Drugs | User Error 33 first appeared on Jupiter Broadcasting.

]]>
One Ping Only | TechSNAP 133 https://original.jupiterbroadcasting.net/45222/one-ping-only-techsnap-133/ Thu, 24 Oct 2013 16:54:03 +0000 https://original.jupiterbroadcasting.net/?p=45222 Experian gets caught selling your records to identity thieves, hacking a router with a single UDP Packet, the cloud storage service that deletes your files...

The post One Ping Only | TechSNAP 133 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Experian gets caught selling your records to identity thieves, hacking a router with a single UDP Packet, the cloud storage service that deletes your files…

And a huge batch of your questions, our answers!

Thanks to:


\"GoDaddy\"


\"Ting\"

Direct Download:

HD Video | Mobile Video | MP3 Audio | Ogg Audio | YouTube | HD Torrent | Mobile Torrent

RSS Feeds:

HD Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feeds | Torrent Feed

Experian credit reporting service sold data to identity theft service

  • An identity theft service that sold Social Security and driver\’s license numbers — as well as bank account and credit card data on millions of Americans.
  • Purchased much of its data from Experian, one of the three major credit bureaus, according to a lengthy investigation by KrebsOnSecurity.
  • In November 2011, KrebsOnSecurity ran a story about an underground service called Superget.info, a fraudster-friendly site that marketed the ability to look up full Social Security numbers, birthdays, drivers license records and financial information on millions of Americans.
  • Each SSN search on Superget.info returned consumer records that were marked with a set of varying and mysterious two- and three-letter “sourceid:” identifiers, including “TH,” “MV,” and “NCO,” among others.
  • A KrebsOnSecurity reader said the abbreviations matched data sets produced by Columbus, Ohio-based USInfoSearch.com.
  • Contacted about the reader’s claim, U.S. Info Search CEO Marc Martin said the data sold by the ID theft service was not obtained directly through his company, but rather via Court Ventures, a third-party company with which US Info Search had previously struck an information sharing agreement.
  • Founded in 2001, Court Ventures described itself as a firm that “aggregates, repackages and distributes public record data, obtained from over 1,400 state and county sources.”
  • In March 2012, Court Ventures was purchased by Costa Mesa, Calif.-based Experian, one of the three major consumer credit bureaus. According to Martin, the proprietors of Superget.info had gained access to Experian’s databases by posing as a U.S.-based private investigator. In reality, Martin said, the individuals apparently responsible for running Superget.info were based in Vietnam.
  • Martin said he first learned of the ID theft service after hearing from a U.S. Secret Service agent who called and said the law enforcement agency was investigating Experian and had obtained a grand jury subpoena against the company.
  • While the private investigator ruse may have gotten the fraudsters past Experian and/or CourtVentures’ screening process, according to Martin there were other signs that should have alerted Experian to potential fraud associated with the account. For example, the alleged proprietor of Superget.info had paid Experian for his monthly data access charges using wire transfers sent from Singapore.
  • Experian declined multiple requests for an interview. But in a written statement provided to KrebsOnSecurity, Experian acknowledged the broad outlines of Martin’s story and said it had worked with the Secret Service to bring a Vietnamese national to justice in connection with the online ID theft service.
  • Meanwhile, it’s not clear what — if any — trouble Experian may face as a result of its involvement in the identity theft scheme.

Tenda W302R router can be exploited by sending a single UDP packet

  • The Tenda routers use a modified version of the GoAhead web server, popular for embedded platforms
  • The custom version Tenda uses contains a modification, when the web server starts it creates a UDP socket and bind it to port 7329
  • If a packet is received that starts with the string “w302r_mfg”
  • The next byte of the packet indicates what to do with the rest of the packet:
  • ‘e’ – Responds with a pre-defined string, basically a ping test
  • ’1′ – Intended to allow you to run iwpriv commands
  • ‘x’ – Allows you to run any command, as root
  • This means you can exploit this router and gain remote root privileges with nothing more than the netcat command
  • “the backdoor only listens on the LAN, thus it is not exploitable from the WAN. However, it is exploitable over the wireless network, which has WPS enabled by default with no brute force rate limiting”
  • The device also ship with a default WPA key, which you might want to try first
  • Another Researcher found that this exploit exists in many other versions of the Tenda router firmware

Cloud storage service allows strangers to delete your data

  • Box.com is a cloud storage service like Dropbox and others
  • A reporter had an account that he used from time to time to share images with his Editors
  • His wife also used the account, and at one point had invited an employee from a large PR firm to upload a file
  • That PR firm later signed up for a corporate account with box.com
  • Box.com has a feature, called account roll-in, which allows companies to slurp up all of their employees accounts and grant those users the additional capacity and features of the corporate account
  • This feature can also slurp in accounts that have “deep collaborative relationships” with the company
  • So in this case, the reporters account was sucked into the corporate account of the PR firm, even though the relationship was only a single file
  • Later on, the Administrators of the PR firm saw the account they did not recognize, and deleted it
  • Box.com destroyed the account rather than just unrelating it to the PR firm
  • Eventually, Box.com managed to find the Reporters files and return them to him
  • This just goes to show the risk involved with trusting your files to a cloud storage provider

Feedback:

— Allan’s new router unboxing —

[asa]B005FYNSZA[/asa]

Amazon.com: SanDisk Cruzer Fit 16 GB USB Flash Drive SDCZ33-016G-B35: Electronics


Round Up:


The post One Ping Only | TechSNAP 133 first appeared on Jupiter Broadcasting.

]]>
Don’t Copy That Floppy | TechSNAP 79 https://original.jupiterbroadcasting.net/25876/dont-copy-that-floppy-techsnap-79/ Thu, 11 Oct 2012 16:04:46 +0000 https://original.jupiterbroadcasting.net/?p=25876 How a Russian Spy ring used floppies to pass sensitive information, how Backblaze made it through the great hard drive shortage. Plus GPG explained!

The post Don't Copy That Floppy | TechSNAP 79 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

How a Russian Spy ring used floppies to pass sensitive information, how Backblaze made it through the great hard drive shortage, and why the US congress is saying no to Chinese Telco manufactures.

Plus a big batch of your questions, and our answers.

All that and much more, on this week’s TechSNAP!

Thanks to:

Use our codes TechSNAP10 to save 10% at checkout, or TechSNAP20 to save 20% on hosting!

BONOUS ROUND PROMO:

Get your .COMs just $5.99 per year up to 3 domains! Additional .COMs just $7.99 per year!
CODE: 599tech

Expires 10/31/12

SPECIAL OFFER! Save 20% off your order!
Code: go20off5

Pick your code and save:
techsnap7: $7.49 .com
techsnap10: 10% off
techsnap11: $1.99 hosting for the first 3 months
techsnap20: 20% off 1, 2, 3 year hosting plans
techsnap40: $10 off $40
techsnap25: 25% off new Virtual DataCenter plans
techsnapx: 20% off .xxx domains

 

Direct Download:

HD Video | Mobile Video | MP3 Audio | Ogg Audio | YouTube | HD Torrent | Mobile Torrent

RSS Feeds:

HD Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feeds | Torrent Feed

 

Support the Show:

   

Show Notes:

Get TechSNAP on your Android:

Browser Affiliate Extension:

  • Jupiter Broadcasting Affiliate Extensions for Chrome and Firefox
  • How Backblaze dealt with the hard drive shortage

    • During the hard drive shortage that started a year ago, Backblaze found itself in a rather tight spot, in order to continue offering unlimited storage for $5/month, they needed more drives
    • The price of a 3TB internal drive shot up from $129 to $349 overnight
    • However external drives, were prices around $169, at least $100 cheaper than their internal counterparts (mostly because HP, Dell and Apple had bought up most of the supply of internal drives)
    • BackBlaze fills about 50TB worth of drives per day, so they need a continuous supply of new drives
    • Between November 2011 and February 2012, Backblaze farmed 5.5 Petabytes worth of hard drives from retailers, mostly consisting of external drives that needed to be removed from their enclosures
    • The external drives incurred other costs, shucking the drives out of the enclosures, and recycling the leftover shells afterwards
    • Many stores had ‘limit 2 per customer’ (I remember this well with my own drive buying), and BackBlaze employees employed many devious tactics to try to squeeze more out of each store, including pretending to be a grandmother buying drives for each of her grandchildren for Christmas
    • Backblaze employees were banned from a number of CostCo and BestBuy stores, or asked to leave empty handed
    • On Christmas Eve, the CEO of BackBlaze stopped at a friend’s house to pick up 80x 3TB drives his friend had acquired from an online site that forgot to limit the quantity he could order. It had taken the FedEx driver more than 30 minutes to unload all of the drives into the apartment. While loading them into his car, the BackBlaze CEO reflected that the drives he was loading into his car, were worth more than the car
    • Backblaze still buys external drives when the price is right, ~$30 cheaper than internal drives, to cover the additional cost of preparing the drives
    • The ‘shucked’ drives can usually not be returned for warranty replacement
    • Additional Coverage
    • Additional Coverage
    • The backblaze storage pod 2.0

    Russian spy ring relied on notepad and floppy disks

    • Sub-Lt. Jeffrey Delisle pled guilty today on charges of breach of trust and two counts of communicating safeguarded information to a foreign entity
    • The maximum sentence for ‘communicating safeguarded information to a foreign entity’ is life in prison
    • Delisle was an Analyst at HMCS Trinity, an intelligence facility that tracks vessels entering and exiting Canadian waters via satellites, drones and underwater devices, it is located at the naval base in Halifax, Nova Scotia
    • He would search for and copy sensitive materials from a secure computer at the base
    • Copy/pasting the data into notepad, it would then save it to a floppy disk
    • The floppy was then moved to a regular non-secure computer, where the data was transferred to a USB drive
    • After taking the USB home, he would access a webmail account, and draft an email, but never send it
    • His Russian handlers had the username and password to the email account, and would access it, and retrieve the stolen intelligence
    • The emails were never sent, lessening the chance that they might be intercepted
    • Delisle walked into the Russian Embassy in Ottawa in 2007 and asked to speak to someone from the GRU (Russian Military Intelligence), offering to sell the secrets he had access to
    • He was paid $3000/month in prepaid credit cards
    • the RCMP (Royal Canadian Mounted Police, Equivalent to the FBI in Canada) started investigating him after CBSA (Canada Border Services Acency) Officers alerted the Military when Delisle returned from a short trip to Brazil with a large amount of cash
    • Additional CBC Coverage

    SEC hands out first ever fine for ‘failure to protect customer data’

    • In the spring of 2005, network traffic at the Florida officers of GunnAllen Financial had slowed to a crawl
    • The company had outsourced its entire IT department to The Revere Group
    • GunnAllen’s acting CIO, a partner at Revere Group, asked the manager of the IT team to investigate
    • A senior network engineer had disabled the WatchGuard firewalls and routed all of the broker-dealer’s IP traffic–including trades and VoIP calls–through his home cable modem
    • As a result, none of the company’s trades, emails, or phone calls were being archived, in violation of Securities and Exchange Commission regulation
    • However, this did not appear in the final report from the SEC about the settlement with GunnAllen Financial, which was actually about other breaches of security and policy
    • Some of the data that was routed through the engineering some connection include: bank routing information, account balances, account numbers, social security numbers, customers’ home addresses and driver’s license numbers
    • “He’d purposefully break things, then come in in the morning and be the hero, I ended up key-logging all the servers, and I logged him logging in from home at 2:30 in the morning, logging on to BlackBerry servers and breaking them."
    • Although required by the SEC to keep copies of all emails for 7 years, “There was a point in time for probably two months where no one’s email was logged. I brought it up in a meeting once and was told to shut up [by the acting CIO]”
    • In 2008 FINRA (Financial Industry Regulatory Authority) fined GunnAllen $750,000 for a “trade allocation scheme” conducted by former head trader, in which profitable stock trades were allocated to his wife’s personal account instead of to the accounts of firm customers
    • Employees at The Revere Group were afraid to report issues because other employees had been fired

    Bug in facebook mobile app could expose your phone number

    • A feature of the facebook mobile app allows you to compare your mobile contacts list against facebook, and find any people you have in your phone, but not on facebook
    • A researcher exploited this feature by adding random phone numbers to his phone’s contact list and was able to determine many users’ mobile phone numbers, despite their privacy settings
    • Facebook originally denied that this was an issue when he reported it to them, they claimed that rate limiting and privacy settings prevented the exploit
    • The researcher posted proof , in the form of 100s of phone numbers (random digits blocked out to protect the innocent) with the corresponding person’s name
    • Facebook has since tightened up the rate limiting
    • TheNextWeb has an article on how to protect your phone number on facebook

    TechSNAP viewer discovers IE flaw

    • IE8 and IE9 in compatibility mode will sometimes mistakenly render plain text content as HTML
    • This means that the ‘raw’ view of a pastebin of some javascript source code, could cause the browser to execute it, rather than display it
    • A proof of concept is providers for you to test your browser

    US congressional report says Huawei and ZTE are a security threat

    • A draft of a report by the House Intelligence Committee said Huawei and another Chinese telecom, ZTE, “cannot be trusted” to be free of influence from Beijing and could be used to undermine US security
    • The report recommends that the chinese hardware manufacturers should be barred from US contracts and acquisitions, due to the security implications of chinese controlled devices in sensitive US installations
    • US set to reject UN ITU proposals for changes to Global Telecom systems, citing danger of increased foreign espionage
    • The US fears nations like China and Russia will gain too much control and impose tracking and monitoring, and assert control over content and user information
    • US says that ITU regulations are “not an appropriate or useful venue to address cybersecurity,”

    Feedback

    • More Info on digi-pass
    • Could provide some insight to GPG Keys?
      • Packages are signed by the GPG key of the person or group who created them
      • Your package manager maintains a list of the GPG keys you trust (the default is usually to trust official packages from your distro)
      • If you use 3rd party packages, you will get a warning
      • You must decide if you trust the 3rd party that signed the package, not to include an exploit in the package
      • If you trust the 3rd party, you can add their key to your allow list, and you will not receive the warning
      • It is unsafe to ignore the warning if you do not trust the source of the packages, especially if you are trying to install an official package
    • Switching to Publicly Signed SSL?
      • Wildcard SSL certificates cover *.domain.com (something.domain.com, otherthing.domain.com)
      • This does not include *.something.domain.com
      • Covers future sub domains that you might create
      • There are also ‘UCC’ (Unified Communications Certificates) certificates, that allow you to enumerate many domains to be covered by a single certificate. Adding or removing a domain to the certificate requires it to be reissued
      • UCC certificates are expensive, but are popular for Exchange servers that must cover multiple domains
    • Securing Cookies
    • Darwin writes in with a note that in addition to limiting the length of your password, ‘Microsoft Account’ also prevents you using some special characters, including ‘space’

    Round-Up

    The post Don't Copy That Floppy | TechSNAP 79 first appeared on Jupiter Broadcasting.

    ]]>