Blog posts

  1. CharmSec

    Ben is dropping this invite in various places:

    CharmSec

    What
    An informal meetup of infosec folks

    When
    Wednesday May 14th, 7:00pm

    Where
    The Wharf Rat @ Camden Yards
    Bar side – look for geeky looking folks in black shirts

    Why
    Talk security with people who aren’t there just to get 3 CPE points!

    I’ll be attending, and we already have a few committed guests so that it won’t just be Ben and I enjoying Oliver Ales. We spend all day in front of four or five monitors in small rooms with no windows interacting with the folks in the cubes around us over instant messenger. It’ll be like that only with beer, and a much much better screen.

    I stopped using a (quake) handle years ago, but we don’t expect everyone there to talk openly about where they work or what they do. For future meetups, check the official CharmSec page.

    Join us!

  2. SANS GIAC GCFA

    I am a “Certified IT Professional”, as of this morning. Just like you hear about on the radio advertisements! Yikes.

    I’m on on the list and they published my 83% score on the test to become a SANS Certified Forensics Analyst.

    I took the class six months ago and procrastinated on taking the test. I shouldn’t have because the test was a new version and covered new information not in my books – I got a 90% on the last practice test I took. =/

    Do certifications matter?

    Well it depends, and because it depends, the entire debate is not that interesting to me. But, I’m certified now, so I have to confront it.

    Does my certification matter? I dig that it validates that I can pass an open book, multiple-choice four hour exam in about an hour and forty minutes. I also dig that potential future people looking at my qualifications might give it some value.

    Does it mean anything else? Will I add it to my e-mail signature and business cards?

    Not really, and no.

  3. Hans Reiser: Guilty

    The Wired article concludes…

    From his seat at the defense table, Reiser seemed to offer supporting evidence for that so-called “geek defense” in the form of his own actions, frequently quarreling with his attorney, and interrupting DuBois’ cross-examination. In January, Judge Goodman threatened to bar Reiser from his own trial. “I’m not sure whether you’re doing this on purpose to screw up the process or it’s just part of your nature,” the judge said outside the presence of the jury. “I’m tired of you disrupting the courtroom.”

    DuBois made little effort to hide his frustration with his client. The biggest bone of contention was Reiser’s insistence on taking the stand himself — a move that may have been Reiser’s undoing.

    On many of Reiser’s 11 days on the stand, jurors were seen shaking their heads in disbelief, laughing to themselves and wearing skeptical looks.

    Ok, I’m not one to hold a grudge but quoting myself from six years ago:

    Welp, reiserfs has officially decieved me.

     Kernel Panic: Unable to mount root filesystem on 03:07
    
    reiserfsck —rebuild-tree /dev/hda7
    [UNCORRECTABLE ERROR] SECTOR 110!
    [UNCORRECTABLE ERROR] SECTOR 111!
    [UNCORRECTABLE ERROR] SECTOR 112!
    [UNCORRECTABLE ERROR] SECTOR 113!
    [UNCORRECTABLE ERROR] SECTOR 114!   `

    It then makes it to about 133 before aborting and dying. Good times indeed.

    For those not in the know, that means, I just lost my / linux partition with all of my data on it. Suck suck suck.

    Edit: No seriously—this fucking sucks. hard. =/

    Six Months Later

    advice: Do not use reiserfs.

    ben: told you cough

  4. Logging incident handler activity on the console

    During incident handling, time is precious. I try to make myself take notes and communicate about the incident over logged channels like e-mail and IM - to the point that I think some team members have rules specifically for e-mail from me.

    The detailed timelines that can be reconstructed from these notes are crucial when preparing post-mortem documents!

    I have a simple philosophy: Fill what’s empty. Empty what’s full. Scratch where it itches Script the process wherever possible.

    — Alice Roosevelt Longworth (and Grant Stavely)

    Initially, I thought bash history could help.

    # Bash settings
    export HISTTIMEFORMAT="%s "
    export HISTCONTROL=ignoredups
    export HISTFILESIZE="9999999"

    But what about the command output? There is a better way:

    Firstly, and this is something that took getting used to, set up a fancy shell prompt to provide the log with context and time stamping:

    --(grant@sensor)-(1/pts/1)-(17:32:33-UTC/28-Apr-08)--
    --($:/nsm/)-

    Gross! A two-line shell prompt! Trust me, it’s useful.

    Then just add to your shell start-up:

    # start script to log everything now!
    exec /usr/bin/script -f /nsm/var/handlerlog/$USER.shell_log.` date +'%Y-%m-%d:%H:%M:%S' `.$$

    Script will then log everything that prints to the console with the prompt providing context.

  5. Business Meetings

    Frustrated by distracted workers so plugged in that they tune out in the middle of business meetings, a growing number of companies are going “topless,” as in no laptops allowed. Also banned from some conference rooms: BlackBerrys, iPhones and other personal devices on which so many have come to depend…

    But as laptops have gotten lighter and smart-phones even smarter, people have discovered a handy diversion, making more eye contact these days with their screens than one another. The practice became so pervasive that Todd Wilkens turned to his company blog to wage his “personal war against CrackBerry…”

    His San Francisco design firm, Adaptive Path, now strongly encourages everyone to leave their laptops at their desks. His colleague, Dan Saffer, coined the term “topless” as in “laptop-less.” Also booted are mobile and smart-phones, which must be stowed on a counter or in a box during meetings. It took some convincing, but soon people began connecting with one another rather than with their computers, Wilkens said.

    “All of our meetings got a lot more productive,” he said.

    Merlin Mann likes the idea.

    It stinks. It of course is not being proffered as the sole solution to ‘the meeting problem’, but I don’t even consider it a close runner-up.

    My Straw Man

    cue birds shining, sun chirping

    The meeting lead or a delegate has arrived before anyone else and prepared the room, ensuring there is appropriate seating, refreshments, and a printed agenda. The attendees all arrive on time, having had beautiful stress and distraction free mornings leading up to the meeting. All attendees have been preparing for the meeting in the shower or during the commute and are ready to brainstorm, compromise, and provide insights from their unique perspectives. The meeting lead or a delegate has a history of taking excellent notes and can be counted on to send next-actions to all attendees.

    The actual meeting happens and is hugely successful! The meeting strays once or twice from the established goal when a few ideas are discussed that provide unintended benefits to support personnel or secondary goals. Everyone compromises, gives permission, understands, is motivated, is ready to kick off, or buy, or whatever the goal of the meeting was. The meeting ends before its established hard stop.

    Reality

    The people that are usually early to meetings show up early and wait the five minutes they are accustomed to waiting for everyone else to arrive. A percentage of attendees are late due to random things more important to them than the meeting. A percentage of the attendees have little more than token interest in the goal of the meeting. A few people will take bad notes, a few will take no notes, a few will take down what they think are their own next actions, a few will accept more than they have bandwidth to actually finish in time, and so on. No one knows who scheduled the meeting for 3:30PM on a Friday but everyone agrees silently to murder that person if their identity is revealed.

    The meeting will not start on time because the early folks will be chatting about their personal lives or other work related stuff and the late folks will be explaining why they are late. The people that think they avoided any of the above pitfalls will silently begrudge the attendees that didn’t. The actual meeting begins and is rife with communication problems. One attendee spaces out due to family problems, another due to biological problems, a third because it is more fun than the meeting. One attendee keeps grinding the same axe, tangents fail to get redirected. One of the two people that conferenced into the meeting fills the room with barking dogs every time he unmutes, the other keeps saying “what”? when asked questions. Some people fiddle with their laptops and smartphones. The meeting will stop at the hard stop because people absolutely can’t stay later, or it will run late.

    …and after the meeting

    The people that were on time will blame the lack of progress partly on the late folks (and they’ll be right). The late folks will blame the lack of progress on their distractions (and they’ll be right). The percentage of attendees with no more than token interest in the meeting goals will forget they wasted their time (and they’ll be right to do so). The note takers will be amazed anyone does anything without taking such great notes, the non-note takers will wait for someone to ask them for a deliverable so that they can handle it, and the overloaded folks will do whatever they do that isn’t learning to be less overloaded.

    Obviously the doodling is the problem. And the chairs in the room that allowed people to be so slouchy and doodly. And the cell phones and laptops. And the fidgeting. Why, I can see you now, skimming this and IM’ing someone else, and fidgeting with your left foot at that thing under your desk. Why in my day, meetings were productive and engaging!

  6. Shmoocon 2008

    I’m just returning to work after Shmoocon 2008 – I took Monday off to recover and catch up on sleep.

    It seemed like the presenters this year were asked for only overview level subject matter. The talks were relaxed from past year’s research findings – they were more open ended brainstorms and predictions on the implications of known concepts. I’m still glad I went and will be back next year, maybe it was just a slow year for research.

    Friday

    David Smith’s password analysis talk was really neat. Rss subscribed!

    Deviant returned to lock picking after last years gun-nut panel (sorry, not my bag) masked as a physical security panel, and it appealed to everyone I was with. I would have skipped it if it wasn’t a main track talk even though Deviant is a great presenter.

    The Gringo Challenge was a great idea that didn’t seem to be given enough attention. I would have preferred vendors in the room where the lock picking stuff was and Deviant’s booth in the main hall with an announcer lining up folks to run through the challenge, all recorded on video. The bloopers would have been great!

    Saturday

    I underestimated the hotel black-out curtains and missed the morning talk I wanted to see Saturday.

    G. Mark‘s A Hacker Looks Past 50 wasn’t a talk I’d planned to attend after really enjoying his talk last year and expecting a repeat as the title hadn’t changed. I obviously don’t know G. Mark. I was in the room for Aaron Higbee and Jaime Fuentes talk on ISP filtering – a brainstorm and what-if session that I did enjoy, and stuck around to see if G. Mark would be telling the same stories again. I couldn’t detect any repeats that weren’t framing a new anecdote. G. Mark has a brilliant literary knack for relating life’s anecdotes to a greater theme, but not without a bit of tangential confusion. Also, someone needs to help him re-do his website! I’d gladly assist – the main nav has two blank pages and a 404, and it is all outdated and full of spacer gifs.

    I have to call out the heckler he had. G. Mark was giving away a lot of crap as he usually does, by ticket number. He read a ticket number for an NSA shot glass and a woman behind me was the winner. She didn’t seem too excited that she’d won the shot glass so G. Mark asked “Do you drink?”.

    The crazy lady two seats over from me annoyed.

    “Did you ask her that because she’s female or because she’s asian?”

    Silence.

    “I asked her that because she didn’t seem to want the shot glass.”

    Anyway…

    After a long lunch I checked out Simple Nomad’s crypto chat. A lot of slide-reading, but the content was excellent, if somewhat tinfoil. I expected no less.

    While looking back, I really enjoyed these talks, I was bummed overall and pining for previous years. I was with a large group and there was always someone to skip an hour with, so I didn’t force myself to sit through any less interesting titled presentations. My loss, I’m sure. Every time I was in heading to skip a talk and get a beer it seemed like Shmoo guys were doing the same. Laurels?

    Sunday

    I missed the E-discovery talk that I wanted to see Sunday morning for the only Windows Vista focused talk; Dan Griffin’s Hacking Windows Vista Security. Too many infosec folks stand behind Unix superiority like it is 1999 still (myself included) while Microsoft has really gotten their act together. When I found myself arguing bash over Powershell a few months back having only been exposed to a Monad Ars Technica article I realized I had my head in the sand about Vista. Dan’s talk was great and I would have loved more like it! What is Server 2008 bringing that I can’t do now? What is Vista and Powershell bringing to forensics? Pwning? Nobody at ShmooCon was talking about it.

    Atlas’s Vtrace talk was over my head but I mostly stuck it out. I didn’t have to keep up with the debugging techniques to keep up with the vulnerability research implications!

    I went to RenderMan‘s talk before the closing and he enumerated the how each of us are vulnerable every day because of our RFID, bluetooth, 802.11, and IR wireless devices. The talk was a nice overview but pretty snarky. A generic salesman isn’t an idiot for leaving his bluetooth and 802.11 on and killing his own batteries when the vendors make that the default or easy path. Hackers blaming the victim again?

    Toby Kohlenberg, after years of being the annoying pedant, had great timing at the closing panel discussion. After 20 minutes of Bruce Potter, Simple Nomad, Johnny Long, Rick Dakan, and one mystery person (the website isn’t updated yet) rapping about what the word Hacker means, I was starting to feel like we were in my sophomore Art classes having the “What Is Art?” talk. The closing thoughts were a plea to all of us to do good with our infosec skills, in some way. On our way home, Ben and I talked about this as a diversion to me complaining about the con (and to help stay awake!). More later when we think of anything to actually do.

    Now I just need to go submit all this feedback to the Shmoo folks. I agree with Ben’s submitted feeback. 2006 was my favorite ShmooCon. It isn’t fair to complain and not submit feedback!

  7. Syn Phishus

    I have nice things to say about the rest of the con.

    Baked not Fired: Performing an Unauthorized Phishing Awareness Exercise
    Syn Phishus

    This talk will illustrate how, without getting fired, to perform an unauthorized internal phishing exercise within a large corporation to raise security awareness and demonstrate why processes need to change. The phishing attack was orchestrated to allow incidence response to quickly determine the author and support the forensic investigation that followed. Phishing is easy; this is how to stand up and rock the boat hard while remaining on board.

    Phishing is easy to do. An insider Anyone can perfect the timing, presentation, and content enough to fool the people in the cubes on either side of you. But that doesn’t prove anything. It is a basic violation of the simple trust we all place in e-mail and the only things keeping you smart folks from falling for it is how poorly it is usually done, and your tinfoil hats.

    Public research suggests that it is hard to pin down the percentage of recipients that will download and execute malware delivered to look like corporate communications but it is somewhere between 5% and 30%. If I was in corporate communications I would be disheartened – that is the same cohort that actually skims corporate communications.

    That this threat has been around long enough to earn it’s own cutesy-hacker-name when it is just standard fraud is a great bullet point in the why-column for the usual controls (antivirus, nac, filtering, etc…), comprehensive network security monitoring, and logging absolutely everything.

    Presenting these findings to management might require some writing and maybe the patience to dump the data into a power point slide. A rogue drill of the incident response team isn’t a bad idea either. A planned drill of other business units with management buy-in and CSIRT awareness might even be nice validation of corporate communication plans asking users to report attacks (note: not to determine the threat / risk).

    A rogue drill of other business units is a terrible idea. A poorly executed rogue drill of other business units (Syn accidentally cc’d a large distribution list) due to poor planning is inexcusable.

    Syn Phishus got a formal reprimand for it.

    He then recommended that corporate communications in the future be digitally signed. He didn’t go on to explain how the infrastructure and training required to implement a signed communications initiative actually aligns with the poorly demonstrated unquantified risk. And, he didn’t review other existing controls that help mitigate it. And he didn’t discuss what would happen if his fix actually worked and the threat morphed to social websites, IM, continuing to use e-mail phishing but spoofing vendors instead of the company, and so on. Syn acknowledged that the company had a corporate communications initiative to spread awareness of the threat, but didn’t attempt to quantify its effectiveness. So back to pgp’ing everything.

    What percentage of recipients of an incorrectly-digitally signed message would still download and execute malware? HTTPS is such a great success that no one would ever ignore a poorly signed certificate, so he had no reason to discuss it. Right?

    I have too much respect for Shmoocon to heckle a presenter but had I gotten a microphone, I would have asked:

    “Where are your brains? In your ass!”

  8. Weekend Convention

    I’ll be at the annual nerd convention all weekend. I’ve already made dinner plans for Friday. I don’t know what is up Saturday night for dinner, nor do I know if the Shmoo group has a Saturday night open bar planned like last year’s (which kicked ass). Sunday afternoon lunch is also already planned.

    Anyone else going?

  9. Johnny Winter

    I just bought two general admission tickets to see Johnny Winter
    at The State Theatre in Virginia March 22nd.

    I haven’t really listened to any recent Johnny Winter – I have Second Winter and it’s great, but what really motivated me to grab tickets isn’t specifically his stuff (or that he played at Woodstock). Johnny brought Muddy Waters out of retirement to re-record using a mix of his band and Johnny’s band and the result, Hard Again, is the quintessential blues record of the 20th century.

    What an opportunity!

  10. Tufte on the iPhone

    Edward Tufte has posted a video and essay reviewing successes and failures of presentation and design in Apple’s iPhone. It is an especially easy to digest block of Tufte’s long running attention to information density.

    1. Keep information on a single surface
    2. Small multiples are great
    3. High resolution is nice
    4. Computer administrative junk obstructs information
    5. Images are superior to cartoons of images

    This is mostly common sense stuff, unfortunately when we play desktop publisher we are left with tools that do not have common sense. A graph in excel plotting three numbers over 12 weeks should have the same resolution as the table of data it is meant to augment or replace, and preferably the resolution should be much higher than that.

    Sadly, this is never the case.

    We should be able to easily place graphics, charts, tables, and text into a document in our editors. How did Microsoft Word beat the Quark’s and inDesign’s and Acrobats to failing at this? Why do we write with an editor that is a typewriter dressed up as a Publisher?

    Design is then dictated by the medium.

    Typewritten materials

    • spacing indented first line and double spaced paragraphs
    • two spaces after full stops ending sentences
    • no images
    • no graphics
    • minimal tables
    • Single font size

    Powerpoint slide decks

    • minimal tables due to import / export complexity
    • Graphics that were acceptable on 13” to 17” screens projected to 70” diagonals
    • Clip Art
    • Sliding Animations
    • Wipes
    • Screen reading

    Most unfortunate.

Pizza Slow (high quality)

© 2026 gravely