FBI – Jupiter Broadcasting https://www.jupiterbroadcasting.com Open Source Entertainment, on Demand. Mon, 31 May 2021 17:56:29 +0000 en-US hourly 1 https://wordpress.org/?v=5.5.3 https://original.jupiterbroadcasting.net/wp-content/uploads/2019/04/cropped-favicon-32x32.png FBI – Jupiter Broadcasting https://www.jupiterbroadcasting.com 32 32 Linux Action News 191 https://original.jupiterbroadcasting.net/145177/linux-action-news-191/ Mon, 31 May 2021 10:00:00 +0000 https://original.jupiterbroadcasting.net/?p=145177 Show Notes: linuxactionnews.com/191

The post Linux Action News 191 first appeared on Jupiter Broadcasting.

]]>

Show Notes: linuxactionnews.com/191

The post Linux Action News 191 first appeared on Jupiter Broadcasting.

]]>
Mutually Assured Manipulation | Unfilter 280 https://original.jupiterbroadcasting.net/124941/mutually-assured-manipulation-unfilter-280/ Wed, 16 May 2018 17:10:59 +0000 https://original.jupiterbroadcasting.net/?p=124941 Show Notes: unfilter.show/280

The post Mutually Assured Manipulation | Unfilter 280 first appeared on Jupiter Broadcasting.

]]>

Show Notes: unfilter.show/280

The post Mutually Assured Manipulation | Unfilter 280 first appeared on Jupiter Broadcasting.

]]>
This Guy Hates Encryption | Ask Noah 61 https://original.jupiterbroadcasting.net/124387/this-guy-hates-encryption-ask-noah-61/ Wed, 25 Apr 2018 13:15:04 +0000 https://original.jupiterbroadcasting.net/?p=124387 Show Notes: podcast.asknoahshow.com/61

The post This Guy Hates Encryption | Ask Noah 61 first appeared on Jupiter Broadcasting.

]]>

Show Notes: podcast.asknoahshow.com/61

The post This Guy Hates Encryption | Ask Noah 61 first appeared on Jupiter Broadcasting.

]]>
Secret Society of Corruption | Unfilter 266 https://original.jupiterbroadcasting.net/121897/secret-society-of-corruption-unfilter-266/ Thu, 25 Jan 2018 23:15:29 +0000 https://original.jupiterbroadcasting.net/?p=121897 RSS Feeds: Video Feed | MP3 Feed | HD Torrent | iTunes Become an Unfilter supporter on Patreon: — Show Notes — Links: Mattis: US national security focus no longer terrorism – BBC News House Republicans demand release of classified FISA abuses memo – Axios House Republicans clash over secret memo – POLITICO Week 35: […]

The post Secret Society of Corruption | Unfilter 266 first appeared on Jupiter Broadcasting.

]]>

RSS Feeds:

Video Feed | MP3 Feed | HD Torrent | iTunes

Become an Unfilter supporter on Patreon:

Patreon

— Show Notes —

Links:

The post Secret Society of Corruption | Unfilter 266 first appeared on Jupiter Broadcasting.

]]>
Manafort Meltdown | Unfilter 257 https://original.jupiterbroadcasting.net/119591/manafort-meltdown-unfilter-257/ Wed, 01 Nov 2017 20:23:48 +0000 https://original.jupiterbroadcasting.net/?p=119591 RSS Feeds: Video Feed | MP3 Feed | HD Torrent | iTunes Become an Unfilter supporter on Patreon: — Show Notes — Links: NSA Concealed Records on JFK Assassination for Decades FBI informant in Obama-era Russian nuclear bribery cleared to testify before Congress | TheHill J.F.K. Files, Though Incomplete, Are a Treasure Trove for Answer […]

The post Manafort Meltdown | Unfilter 257 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

Video Feed | MP3 Feed | HD Torrent | iTunes

Become an Unfilter supporter on Patreon:

Patreon

— Show Notes —

Links:

The post Manafort Meltdown | Unfilter 257 first appeared on Jupiter Broadcasting.

]]>
Spy Tapes | TechSNAP 340 https://original.jupiterbroadcasting.net/119041/spy-tapes-techsnap-340/ Thu, 12 Oct 2017 16:33:13 +0000 https://original.jupiterbroadcasting.net/?p=119041 RSS Feeds: HD Video Feed | MP3 Audio Feed | iTunes Feed | Torrent Feed Become a supporter on Patreon: Show Notes: The Ethics of Running a Data Breach Search Service HIBP – have i been pwned? Is the NSA Doing More Harm Than Good in Not Disclosing Exploits? Post a boarding pass on Facebook, […]

The post Spy Tapes | TechSNAP 340 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

HD Video Feed | MP3 Audio Feed | iTunes Feed | Torrent Feed

Become a supporter on Patreon:

Patreon

Show Notes:

The Ethics of Running a Data Breach Search Service

Is the NSA Doing More Harm Than Good in Not Disclosing Exploits?

Post a boarding pass on Facebook, get your account stolen

How Israel Caught Russian Hackers Scouring the World for U.S. Secrets


Feedback


Round Up:

The post Spy Tapes | TechSNAP 340 first appeared on Jupiter Broadcasting.

]]>
2016 Review | Unfilter 219 https://original.jupiterbroadcasting.net/105766/2016-review-unfilter-219/ Wed, 28 Dec 2016 16:17:35 +0000 https://original.jupiterbroadcasting.net/?p=105766 RSS Feeds: Video Feed | MP3 Feed | OGG Feed | HD Torrent | Mobile Torrent | iTunes Become an Unfilter supporter on Patreon: — Show Notes — Links Gun’s N Ruses | Unfilter 171 Make Flint Unleaded | Unfilter 173 Hillary’s Bern Notice | Unfilter 174 CIA Rewrites History | Unfilter 189 DNC_Secret_Documents.zip | […]

The post 2016 Review | Unfilter 219 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

Video Feed | MP3 Feed | OGG Feed | HD Torrent | Mobile Torrent | iTunes

Become an Unfilter supporter on Patreon:

Patreon

— Show Notes —

Links

The post 2016 Review | Unfilter 219 first appeared on Jupiter Broadcasting.

]]>
Weiner’s Explosive Leak | Unfilter 211 https://original.jupiterbroadcasting.net/104411/weiners-explosive-leak-unfilter-211/ Thu, 03 Nov 2016 00:29:43 +0000 https://original.jupiterbroadcasting.net/?p=104411 RSS Feeds: Video Feed | MP3 Feed | OGG Feed | HD Torrent | Mobile Torrent | iTunes Become an Unfilter supporter on Patreon: — Show Notes — Links: Federal Probe of Anthony Weiner Prompted Review of Clinton Email Investigation, Sources Say – ABC News Sean Spicer on Twitter: “#BREAKING VIDEO @GOP releases signed @HumaAbedin […]

The post Weiner's Explosive Leak | Unfilter 211 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

Video Feed | MP3 Feed | OGG Feed | HD Torrent | Mobile Torrent | iTunes

Become an Unfilter supporter on Patreon:

Patreon

— Show Notes —

Links:

The post Weiner's Explosive Leak | Unfilter 211 first appeared on Jupiter Broadcasting.

]]>
Wikileaks Melts the Media | Unfilter 210 https://original.jupiterbroadcasting.net/104226/wikileaks-melts-the-media-unfilter-210/ Wed, 26 Oct 2016 22:10:48 +0000 https://original.jupiterbroadcasting.net/?p=104226 RSS Feeds: Video Feed | MP3 Feed | OGG Feed | HD Torrent | Mobile Torrent | iTunes Become an Unfilter supporter on Patreon: — Show Notes — Links: White House clarifies President Obama did know Hillary Clinton’s personal email | Daily Mail Online CIA Prepping for Possible Cyber Strike Against Russia – NBC News […]

The post Wikileaks Melts the Media | Unfilter 210 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

Video Feed | MP3 Feed | OGG Feed | HD Torrent | Mobile Torrent | iTunes

Become an Unfilter supporter on Patreon:

Patreon

— Show Notes —

Links:

The post Wikileaks Melts the Media | Unfilter 210 first appeared on Jupiter Broadcasting.

]]>
Assange’s October Dud | Unfilter 207 https://original.jupiterbroadcasting.net/103601/assanges-october-dud-unfilter-207/ Tue, 04 Oct 2016 21:35:20 +0000 https://original.jupiterbroadcasting.net/?p=103601 RSS Feeds: Video Feed | MP3 Feed | OGG Feed | HD Torrent | Mobile Torrent | iTunes Become an Unfilter supporter on Patreon: — Show Notes — Links: NBC Donated $5.6 Million To Dems | The Daily Caller WikiLeaks CONFIRMS Hillary Sold Weapons to ISIS… Then Drops Another BOMBSHELL! – Daily Politics Russia says […]

The post Assange's October Dud | Unfilter 207 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

Video Feed | MP3 Feed | OGG Feed | HD Torrent | Mobile Torrent | iTunes

Become an Unfilter supporter on Patreon:

Patreon

— Show Notes —

Links:

The post Assange's October Dud | Unfilter 207 first appeared on Jupiter Broadcasting.

]]>
Your Personal Google Stalker | TTT 260 https://original.jupiterbroadcasting.net/103241/your-personal-google-stalker-ttt-260/ Mon, 19 Sep 2016 15:55:42 +0000 https://original.jupiterbroadcasting.net/?p=103241 RSS Feeds: MP3 Feed | OGG Feed | iTunes Feed | Video Feed | Video Feed | Torrent Feed Become a supporter on Patreon Show Notes: Links Samsung Note 7 explodes in Florida man’s pocket, sues Samsung – YouTube iPhone 7 Beat The Galaxy Note 7 By Being Boring The Mystery of the Hissing iPhone […]

The post Your Personal Google Stalker | TTT 260 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

MP3 Feed | OGG Feed | iTunes Feed | Video Feed | Video Feed | Torrent Feed

Become a supporter on Patreon

Patreon

Show Notes:

Links

The post Your Personal Google Stalker | TTT 260 first appeared on Jupiter Broadcasting.

]]>
DNC Frenzy | Unfilter 197 https://original.jupiterbroadcasting.net/101481/dnc-frenzy-unfilter-197/ Wed, 27 Jul 2016 20:31:48 +0000 https://original.jupiterbroadcasting.net/?p=101481 Leaks of DNC emails lead to total chaos at Hillary’s big event. We cover the content of those leaks, the fallout & debunk the spin from the Clinton campaign. Plus some important world news updates, the FBI restarting the encryption debate & our coverage of the 2016 Democratic National Convention. Direct Download: Video | MP3 […]

The post DNC Frenzy | Unfilter 197 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Leaks of DNC emails lead to total chaos at Hillary’s big event. We cover the content of those leaks, the fallout & debunk the spin from the Clinton campaign.

Plus some important world news updates, the FBI restarting the encryption debate & our coverage of the 2016 Democratic National Convention.

Direct Download:

Video | MP3 Audio | OGG Audio | Torrent | YouTube

RSS Feeds:

Video Feed | MP3 Feed | OGG Feed | HD Torrent | Mobile Torrent | iTunes

Become an Unfilter supporter on Patreon:

Patreon

— Show Notes —

Episode Links:

The post DNC Frenzy | Unfilter 197 first appeared on Jupiter Broadcasting.

]]>
Careless but Not Criminal | Unfilter 195 https://original.jupiterbroadcasting.net/101131/careless-but-not-criminal-unfilter-195/ Wed, 13 Jul 2016 21:02:11 +0000 https://original.jupiterbroadcasting.net/?p=101131 By our estimate Hillary Clinton won the 2016 election since our last episode, we’ll run down the last two amazing weeks for her. Why NATO’s military moves are creating a ticking time bomb & the latest cyber threat powered by encryption. Direct Download: Video | MP3 Audio | OGG Audio | Torrent | YouTube RSS […]

The post Careless but Not Criminal | Unfilter 195 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

By our estimate Hillary Clinton won the 2016 election since our last episode, we’ll run down the last two amazing weeks for her. Why NATO’s military moves are creating a ticking time bomb & the latest cyber threat powered by encryption.

Direct Download:

Video | MP3 Audio | OGG Audio | Torrent | YouTube

RSS Feeds:

Video Feed | MP3 Feed | OGG Feed | HD Torrent | Mobile Torrent | iTunes

Become an Unfilter supporter on Patreon:

Patreon

— Show Notes —

Episode Links

The post Careless but Not Criminal | Unfilter 195 first appeared on Jupiter Broadcasting.

]]>
Queso the Mondays | TTT 243 https://original.jupiterbroadcasting.net/99596/queso-the-mondays-ttt-243/ Mon, 09 May 2016 17:06:48 +0000 https://original.jupiterbroadcasting.net/?p=99596 Drones dropping blood, HTC’s dropping profits & Microsoft’s dropping ASUS rigs. Plus the end to the latest Bitcoin saga, the FBI labeling TOR users & a Kickstarter you won’t believe! Direct Download: MP3 Audio | OGG Audio | Video | HD Video | Torrent | YouTube RSS Feeds: MP3 Feed | OGG Feed | iTunes […]

The post Queso the Mondays | TTT 243 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Drones dropping blood, HTC’s dropping profits & Microsoft’s dropping ASUS rigs.

Plus the end to the latest Bitcoin saga, the FBI labeling TOR users & a Kickstarter you won’t believe!

Direct Download:

MP3 Audio | OGG Audio | Video | HD Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | OGG Feed | iTunes Feed | Video Feed | Video Feed | Torrent Feed

Become a supporter on Patreon

Patreon

Show Notes:

KICKSTARTER OF THE WEEEAAAAK:

The post Queso the Mondays | TTT 243 first appeared on Jupiter Broadcasting.

]]>
The Saudi Connection | Unfilter 185 https://original.jupiterbroadcasting.net/99131/the-saudi-connection-unfilter-185/ Thu, 28 Apr 2016 01:28:01 +0000 https://original.jupiterbroadcasting.net/?p=99131 The “28 Pages” of the 9/11 report the media never talked about… Until they did. What’s in the 28 pages? Why is it getting so much attention now? We’ll reveal how the Obama administration is using vital information about 9/11 as leverage with the Saudis & why these 28 pages are getting so much attention […]

The post The Saudi Connection | Unfilter 185 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

The “28 Pages” of the 9/11 report the media never talked about… Until they did. What’s in the 28 pages? Why is it getting so much attention now? We’ll reveal how the Obama administration is using vital information about 9/11 as leverage with the Saudis & why these 28 pages are getting so much attention now.

Plus details on how the FBI hacked the iPhone 5c, the Bern starts to fade & Trump takes the lead on the right.

Then we end it all on a high note & an epic Overtime segment!

Direct Download:

Video | MP3 Audio | OGG Audio | Torrent | YouTube

RSS Feeds:

Video Feed | MP3 Feed | OGG Feed | HD Torrent | Mobile Torrent | iTunes

Become an Unfilter supporter on Patreon:

Patreon

— Show Notes —

Episode Links

The post The Saudi Connection | Unfilter 185 first appeared on Jupiter Broadcasting.

]]>
Encryption gets the Clap | TTT 241 https://original.jupiterbroadcasting.net/99091/encryption-gets-the-clap-ttt-241/ Tue, 26 Apr 2016 10:54:50 +0000 https://original.jupiterbroadcasting.net/?p=99091 Has Spotify been hacked? And our different approaches for preparing to reload an important personal computer. Plus piracy skyrockets, hacks go for a premium & one of our coolest Kickstarters of the week yet! Direct Download: MP3 Audio | OGG Audio | Video | HD Video | Torrent | YouTube RSS Feeds: MP3 Feed | […]

The post Encryption gets the Clap | TTT 241 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Has Spotify been hacked? And our different approaches for preparing to reload an important personal computer. Plus piracy skyrockets, hacks go for a premium & one of our coolest Kickstarters of the week yet!

Direct Download:

MP3 Audio | OGG Audio | Video | HD Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | OGG Feed | iTunes Feed | Video Feed | Video Feed | Torrent Feed

Become a supporter on Patreon

Patreon

Show Notes:

The post Encryption gets the Clap | TTT 241 first appeared on Jupiter Broadcasting.

]]>
One Key to Rule Them All | TechSNAP 263 https://original.jupiterbroadcasting.net/98991/one-key-to-rule-them-all-techsnap-263/ Thu, 21 Apr 2016 10:41:52 +0000 https://original.jupiterbroadcasting.net/?p=98991 This week, the FBI says APT6 has pawned the government for the last 5 years, Unaoil: a company that’s bribing the world & Researchers find a flaw in the visa database. All that plus a packed feedback, roundup & more! Thanks to: Get Paid to Write for DigitalOcean Direct Download: HD Video | Mobile Video […]

The post One Key to Rule Them All | TechSNAP 263 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

This week, the FBI says APT6 has pawned the government for the last 5 years, Unaoil: a company that’s bribing the world & Researchers find a flaw in the visa database.

All that plus a packed feedback, roundup & more!

Thanks to:


DigitalOcean


Ting


iXsystems

Direct Download:

HD Video | Mobile Video | MP3 Audio | OGG Audio | YouTube | HD Torrent | Mobile Torrent

RSS Feeds:

HD Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed

Become a supporter on Patreon:

Patreon

Show Notes:

FBI says APT6 has pwning the government for the last 5 years

  • The feds warned that “a group of malicious cyber actors,” whom security experts believe to be the government-sponsored hacking group known as APT6, “have compromised and stolen sensitive information from various government and commercial networks” since at least 2011, according to an FBI alert obtained by Motherboard
  • The official advisory is available on the Open Threat Exchange website
  • The alert, which is also available online, shows that foreign government hackers are still successfully hacking and stealing data from US government’s servers, their activities going unnoticed for years. This comes months after the US government revealed that a group of hackers, widely believed to be working for the Chinese government, had for more than a year infiltrated the computer systems of the Office of Personnel Management, or OPM. In the process, they stole highly sensitive data about several millions of government workers and even spies.
  • In the alert, the FBI lists a long series of websites used as command and control servers to launch phishing attacks “in furtherance of computer network exploitation (CNE) activities [read: hacking] in the United States and abroad since at least 2011.” Domains controlled by the hackers were “suspended” as of late December 2015, according to the alert, but it’s unclear if the hackers have been pushed out or they are still inside the hacked networks.
  • Looks like they were in for years before they were caught, god knows where they are,” Michael Adams, an information security expert who served more than two decades in the US Special Operations Command, and who has reviewed the alert, told Motherboard. “Anybody who’s been in that network all this long, they could be anywhere and everywhere.
  • “This is one of the earlier APTs, they definitely go back further than 2011 or whatever—more like 2008 I believe,” Kurt Baumgartner, a researcher at the Russian security firm Kaspersky Lab, told me. (Baumgartner declined to say whether the group was Chinese or not, but said its targets align with the interest of a state-sponsored attacker.)
  • Kyrk Storer, a spokesperson with FireEye, confirmed that the domains listed in the alert “were associated with APT6 and one of their malware backdoors,” and that the hackers “targeted the US and UK defense industrial base.” APT6 is ”likely a nation-state sponsored group based in China,” according to FireEye, which ”has been dormant for the past several years.”
  • Another researcher at a different security company, who spoke on condition of anonymity because he wasn’t authorized to speak publicly about the hacker’s activities, said this was the “current campaign of an older group,” and said there “likely” was an FBI investigation ongoing. (Several other security companies declined to comment for this story.) At this point, it’s unclear whether the FBI’s investigation will lead to any concrete result. But two years after the US government charged five Chinese military members for hacking US companies, it’s clear hackers haven’t given up attacking US targets.

Unaoil: the company that bribed the world

  • After a six-month investigation across two continents, Fairfax Media and The Huffington Post are revealing that billions of dollars of government contracts were awarded as the direct result of bribes paid on behalf of firms including British icon Rolls-Royce, US giant Halliburton, Australia’s Leighton Holdings and Korean heavyweights Samsung and Hyundai.
  • A massive leak of confidential documents, and a large email, has for the first time exposed the true extent of corruption within the oil industry, implicating dozens of leading companies, bureaucrats and politicians in a sophisticated global web of bribery.
  • The investigation centres on a Monaco company called Unaoil.
  • Following a coded ad in a French newspaper, a series of clandestine meetings and midnight phone calls led to our reporters obtaining hundreds of thousands of the Ahsanis’ leaked emails and documents.
  • The leaked files expose as corrupt two Iraqi oil ministers, a fixer linked to Syrian dictator Bashar al-Assad, senior officials from Libya’s Gaddafi regime, Iranian oil figures, powerful officials in the United Arab Emirates and a Kuwaiti operator known as “the big cheese”.
  • Western firms involved in Unaoil’s Middle East operation include some of the world’s wealthiest and most respected companies: Rolls-Royce and Petrofac from Britain; US companies FMC Technologies, Cameron and Weatherford; Italian giants Eni and Saipem; German companies MAN Turbo (now know as MAN Diesal & Turbo) and Siemens; Dutch firm SBM Offshore; and Indian giant Larsen & Toubro. They also show the offshore arm of Australian company Leighton Holdings was involved in serious, calculated corruption.
  • The leaked files reveal that some people in these firms believed they were hiring a genuine lobbyist, and others who knew or suspected they were funding bribery simply turned a blind eye.
  • The files expose the betrayal of ordinary people in the Middle East. After Saddam Hussein was toppled, the US declared Iraq’s oil would be managed to benefit the Iraqi people. Today, in part one of the ‘Global Bribe Factory’ expose, that claim is demolished.
  • It is the Monaco company that almost perfected the art of corruption.
  • It is called Unaoil and it is run by members of the Ahsani family – Monaco millionaires who rub shoulders with princes, sheikhs and Europe’s and America’s elite business crowd.
  • How they make their money is simple. Oil-rich countries often suffer poor governance and high levels of corruption. Unaoil’s business plan is to play on the fears of large Western companies that they cannot win contracts without its help.
  • Its operatives then bribe officials in oil-producing nations to help these clients win government-funded projects. The corrupt officials might rig a tender committee. Or leak inside information. Or ensure a contract is awarded without a competitive tender.
  • On a semi-related note, another big story for you to go read:
  • How to hack an Election from someone who has done it, more than once

Researchers find flaw in Visa database

  • No, not that kind of Visa, the other one.
  • Systems run by the US State Department, that issue Travel Visas that are required for visitors from most countries to be admitted to the US
  • This has very important security considerations, as the application process for getting a visa is when most security checks are done
  • Cyber-defense experts found security gaps in a State Department system that could have allowed hackers to doctor visa applications or pilfer sensitive data from the half-billion records on file, according to several sources familiar with the matter –- though defenders of the agency downplayed the threat and said the vulnerabilities would be difficult to exploit.
  • Briefed to high-level officials across government, the discovery that visa-related records were potentially vulnerable to illicit changes sparked concern because foreign nations are relentlessly looking for ways to plant spies inside the United States, and terrorist groups like ISIS have expressed their desire to exploit the U.S. visa system, sources added
  • After commissioning an internal review of its cyber-defenses several months ago, the State Department learned its Consular Consolidated Database –- the government’s so-called “backbone” for vetting travelers to and from the United States –- was at risk of being compromised, though no breach had been detected, according to sources in the State Department, on Capitol Hill and elsewhere.
  • As one of the world’s largest biometric databases –- covering almost anyone who has applied for a U.S. passport or visa in the past two decades -– the “CCD” holds such personal information as applicants’ photographs, fingerprints, Social Security or other identification numbers and even children’s schools.
  • “Every visa decision we make is a national security decision,” a top State Department official, Michele Thoren Bond, told a recent House panel.
  • Despite repeated requests for official responses by ABC News, Kirby and others were unwilling to say whether the vulnerabilities have been resolved or offer any further information about where efforts to patch them now stand.
  • State Department documents describe CCD as an “unclassified but sensitive system.” Connected to other federal agencies like the FBI, Department of Homeland Security and Defense Department, the database contains more than 290 million passport-related records, 184 million visa records and 25 million records on U.S. citizens overseas.
  • “Because of the CCD’s importance to national security, ensuring its data integrity, availability, and confidentiality is vital,” the State Department’s inspector general warned in 2011.

Feedback:


Round Up:


The post One Key to Rule Them All | TechSNAP 263 first appeared on Jupiter Broadcasting.

]]>
rm -rf $ALLTHETHINGS/ | TechSNAP 262 https://original.jupiterbroadcasting.net/98886/rm-rf-allthethings-techsnap-262/ Thu, 14 Apr 2016 18:34:12 +0000 https://original.jupiterbroadcasting.net/?p=98886 Find out why everyone’s just a little disappointed in Badlock, the bad security that could be connected to the Panama Papers leak & the story of a simple delete command that took out an entire hosting provider. Plus your batch of networking questions, our answers & a packed round up! Thanks to: Get Paid to […]

The post rm -rf $ALLTHETHINGS/ | TechSNAP 262 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Find out why everyone’s just a little disappointed in Badlock, the bad security that could be connected to the Panama Papers leak & the story of a simple delete command that took out an entire hosting provider.

Plus your batch of networking questions, our answers & a packed round up!

Thanks to:


DigitalOcean


Ting


iXsystems

Direct Download:

HD Video | Mobile Video | MP3 Audio | OGG Audio | YouTube | HD Torrent | Mobile Torrent

RSS Feeds:

HD Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed

Become a supporter on Patreon:

Patreon

Show Notes:

Badlock vulnerability disclosed

  • The badlock vulnerability was finally disclosed on Tuesday after 3 weeks of hype
  • It turns out to not have been as big a deal as we were lead to believe
  • The flaw was not in the SMB protocol itself, but in the related SAM and LSAD protocols
  • The flaw itself is identified as https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2118
  • It affects all versions of Samba clear back to 3.0
  • “Samba 4.4.2, 4.3.8 and 4.2.11 Security Releases are available”
  • “Please be aware that Samba 4.1 and below are therefore out of support, even for security fixes. There will be no official security releases for Samba 4.1 and below published by the Samba Team or SerNet (for EnterpriseSAMBA). We strongly advise users to upgrade to a supported release.”
  • See the Samba Release Planning page for more details about support lifetime for each branch
  • Microsoft releases MS16-047 but rated it only “Important”, not “Critical”
  • The patch fixes an “elevation of privilege bug in both SAM and LSAD that could be exploited in a man-in-the-middle attack, forcing a downgrade of the authentication level of both channels. An attacker could then impersonate an authenticated user”
  • Microsoft was also careful to note: “Only applications and products that use the SAM or LSAD remote protocols are affected by this issue. The SMB protocol is not vulnerable.”
  • It seems most of the “badlock” bugs were actually in Samba itself, rather than the protocol as we were lead to believe
  • “There are several MITM attacks that can be performed against a variety of protocols used by Samba. These would permit execution of arbitrary Samba network calls using the context of the intercepted user. Impact examples of intercepting administrator network traffic:”
  • Samba AD server – view or modify secrets within an AD database, including user password hashes, or shutdown critical services.
  • standard Samba server – modify user permissions on files or directories.
  • There were also a number of related CVEs that are also fixed:
    • CVE-2015-5370 3.6.0 to 4.4.0: Errors in Samba DCE-RPC code can lead to denial of service (crashes and high cpu consumption) and man in the middle attacks. It is unlikely but not impossible to trigger remote code execution, which may result in an impersonation on the client side.
    • CVE-2016-2110 3.0.0 to 4.4.0: The feature negotiation of NTLMSSP is not downgrade protected. A man in the middle is able to clear even required flags, especially NTLMSSP_NEGOTIATE_SIGN and NTLMSSP_NEGOTIATE_SEAL. Which has implications on encrypted LDAP traffic.
    • CVE-2016-2111 3.0.0 to 4.4.0: When Samba is configured as Domain Controller it allows remote attackers to spoof the computer name of a secure channel’s endpoints, and obtain sensitive session information, by running a crafted application and leveraging the ability to sniff network traffic.
    • CVE-2016-2112 3.0.0 to 4.4.0: A man in the middle is able to downgrade LDAP connections to no integrity protection. It’s possible to attack client and server with this.
    • CVE-2016-2113 4.0.0 to 4.4.0: Man in the middle attacks are possible for client triggered LDAP connections (with ldaps://) and ncacn_http connections (with https://).
    • CVE-2016-2114 4.0.0 to 4.4.0: Due to a bug Samba doesn’t enforce required smb signing, even if explicitly configured. In addition the default for the active directory domain controller case was wrong.
    • CVE-2016-2115 3.0.0 to 4.4.0: The protection of DCERPC communication over ncacn_np (which is the default for most the file server related protocols) is inherited from the underlying SMB connection. Samba doesn’t enforce SMB signing for this kind of SMB connections by default, which makes man in the middle attacks possible.
  • Additional Coverage: Threadpost – Badlock vulnerability falls flat against its type
  • “As it turns out, Badlock was hardly the remote code execution monster many anticipated. Instead, it’s a man-in-the-middle and denial-of-service bug, allowing an attacker to elevate privileges or crash a Windows machine running Samba services.”
  • “Red Hat security strategist Josh Bressers said Badlock could have been much worse, especially if it had turned out to be a memory corruption issue in SMB as some had surmised. Such a scenario would have cleared a path for remote code execution, for example.”
  • Additional Coverage: sadlock.org

Panama Papers: Mossack Fonseca

  • Eleven million documents were leaked from one of the world’s most secretive companies, Panamanian law firm Mossack Fonseca.
  • They show how Mossack Fonseca has helped clients launder money, dodge sanctions and avoid tax.
  • The documents show 12 current or former heads of state and at least 60 people linked to current or former world leaders in the data.
  • Eleven million documents held by the Panama-based law firm Mossack Fonseca have been passed to German newspaper Sueddeutsche Zeitung, which then shared them with the International Consortium of Investigative Journalists. BBC Panorama is among 107 media organisations – including UK newspaper the Guardian – in 76 countries which have been analysing the documents.
  • There are many conspiracy theories about the source of the Panama Papers leak. One of the more prominent theories today blames the CIA.
  • Bradley Birkenfeld is “the most significant financial whistleblower of all time,” and he has opinions about who’s responsible for leaking the Panama Papers rattling financial and political power centers around the world.
  • Wikileaks is also getting attention today for blaming USAID and George Soros for the leaks.
  • What little is known about the source of the leak comes from details published by German newspaper Suddeutsche Zeitung. Communicating via encrypted chat in late 2014, the source warned his or her life was “in danger” but that they had data from law firm Mossack Fonseca that they wanted to share. When asked how much data they had, the source replied “more than you have ever seen,” according to the newspaper.
  • Regardless, the front-end computer systems of Mossack Fonseca are outdated and riddled with security flaws, analysis has revealed.
  • Mossack Fonseca’s client portal is also vulnerable to the DROWN attack, a security exploit that targets servers supporting the obsolete and insecure SSL v2 protocol. The portal, which runs on the Drupal open source CMS, was last updated in August 2013, according to the site’s changelog.
  • On its main website Mossack Fonseca claims its Client Information Portal provides a “secure online account” allowing customers to access “corporate information anywhere and everywhere”. The version of Drupal used by the portal has at least 25 vulnerabilities, including a high-risk SQL injection vulnerability that allows anyone to remotely execute arbitrary commands. Areas of the portal’s backend can also be accessed by guessing the URL structure, a security researcher noted.
  • Mossack Fonseca’s webmail system, which runs on Microsoft’s Outlook Web Access, was last updated in 2009, while its main site runs a version of WordPress that is three months out of date. A further vulnerability makes it possible to easily access files uploaded to the backend of Mossack Fonseca’s site simply by guessing the URL.
  • Mossack Fonseca’s emails were also not transport encrypted, according to privacy expert Christopher Soghoian who noted the company did not use the TLS security protocol.
  • Who leaked the Panama Papers? A famous financial whistleblower says: CIA. / Boing Boing
  • Wikileaks Accuses US Of Funding Panama Papers Putin Expose | The Daily Caller
  • Panama Papers: The security flaws at the heart of Mossack Fonseca (Wired UK)
  • Additional Coverage: The Register – Mossack Fonseca website found vulnerable to SQL injection
  • Additional Coverage: Forbes
  • Additional Coverage: WordFence
  • Additional Coverage: Slashdot
  • In general, it seems there were so many flaws in the website we may never know which one was used to compromise the server

I accidently rm -rf /’d, and destroyed my entire company

  • “I run a small hosting provider with more or less 1535 customers and I use Ansible to automate some operations to be run on all servers. Last night I accidentally ran, on all servers, a Bash script with a rm -rf {foo}/{bar} with those variables undefined due to a bug in the code above this line.”
  • “All servers got deleted and the offsite backups too because the remote storage was mounted just before by the same script (that is a backup maintenance script).
    How I can recover from a rm -rf / now in a timely manner?”
  • There is not usually any easy way to recover from something like this
  • That is why you need backups. Backups are not just a single copy of your files in another location, you need time series data, in case you need to go back more than the most recent backup
  • It is usually best to not have your backups mounted directly, for exactly this reason
  • Even if you will never rm -rf /, an attacker might run rm -rf /backup/*
  • While cleaning up after an attacker attempted to use a Linux kernel exploit against my FreeBSD machine in 2003, I accidently rm -rf /’d in a roundabout way, Trying to remove a symlink to / that had a very funky name (part of the exploit iirc), i used tab complete, and instead of: rm -rf badname, it did rm -rf badname/, which deletes the target of the symlink, which was /.
  • Obviously this was my fault for using -r for a symlink, since I only wanted to delete one thing
  • When the command took too long, I got worried, and when I saw ‘can’t delete /sbin/init’, I panicked and aborted it with control+c
  • Luckily, I had twice daily backups with bacula, to another server. 30 minutes later, everything was restored, and the server didn’t even require a reboot. The 100+ customers on the machine never noticed, since I stopped the rm before it hit /usr/home
  • There are plenty of other examples of this same problem though
  • Steam accidently deletes ALL of your files
  • Bryan Cantrill tells a similiar story from the old SunOS days
  • Discussion continues and talks about why rm -rf / is blocked by on SunOS and FreeBSD
  • Additional Coverage: ServerFault
  • When told to dd the drive to a file, to use testdisk to try to recover files, the user reports accidentally swapping if= and of=, which likely would just error out if the input file didn’t exist, but it might also mean that this entire thing is just a troll. Further evidence: rm -rf / usually doesn’t work on modern linux, without the –no-preserve-root flag

Feedback:


Round Up:


The post rm -rf $ALLTHETHINGS/ | TechSNAP 262 first appeared on Jupiter Broadcasting.

]]>
Clearly Rigged | Unfilter 184 https://original.jupiterbroadcasting.net/98841/clearly-rigged-unfilter-184/ Wed, 13 Apr 2016 21:35:25 +0000 https://original.jupiterbroadcasting.net/?p=98841 More fallout from the Panama Papers gets picked up in this week’s episode, plus we discuss the mounting pressure against the rigged 2016 elections system, Russia buzz’s our planes & CNN has some hot propaganda. Plus we reveal our secret plans & pack our Overtime full of news you should know! Direct Download: Video | […]

The post Clearly Rigged | Unfilter 184 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

More fallout from the Panama Papers gets picked up in this week’s episode, plus we discuss the mounting pressure against the rigged 2016 elections system, Russia buzz’s our planes & CNN has some hot propaganda.

Plus we reveal our secret plans & pack our Overtime full of news you should know!

Direct Download:

Video | MP3 Audio | OGG Audio | Torrent | YouTube

RSS Feeds:

Video Feed | MP3 Feed | OGG Feed | HD Torrent | Mobile Torrent | iTunes

Become an Unfilter supporter on Patreon:

Patreon

— Show Notes —

Episode Links

The post Clearly Rigged | Unfilter 184 first appeared on Jupiter Broadcasting.

]]>
Internet of Wine | TTT 239 https://original.jupiterbroadcasting.net/98771/internet-of-wine-ttt-239/ Tue, 12 Apr 2016 09:48:06 +0000 https://original.jupiterbroadcasting.net/?p=98771 Ransomware unlocked, NASA rescues Kepler, the FBI still wants Apple’s help & Telegram wants to be your Jarvis. Plus our “Kickstarter” of the week might be the craziest IoT device yet! Direct Download: MP3 Audio | OGG Audio | Video | HD Video | Torrent | YouTube RSS Feeds: MP3 Feed | OGG Feed | […]

The post Internet of Wine | TTT 239 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Ransomware unlocked, NASA rescues Kepler, the FBI still wants Apple’s help & Telegram wants to be your Jarvis.

Plus our “Kickstarter” of the week might be the craziest IoT device yet!

Direct Download:

MP3 Audio | OGG Audio | Video | HD Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | OGG Feed | iTunes Feed | Video Feed | Video Feed | Torrent Feed

Become a supporter on Patreon

Patreon

Show Notes:

The post Internet of Wine | TTT 239 first appeared on Jupiter Broadcasting.

]]>