<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>MattJay Security</title>
	
	<link>http://www.mattjaysecurity.com</link>
	<description>The musings of a young information security professional on current security events.</description>
	<lastBuildDate>Thu, 25 Mar 2010 04:01:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/MattjaySecurity" /><feedburner:info uri="mattjaysecurity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Horizon Bob Story [Reader Submitted]</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/ISNDFsJoAJw/</link>
		<comments>http://www.mattjaysecurity.com/2010/03/horizon-bob-story-reader-submitted/#comments</comments>
		<pubDate>Thu, 25 Mar 2010 04:01:29 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=101</guid>
		<description><![CDATA[This is the first of what I hope to be a continuing blog post topic of one of my readers, Bob, experiencing a security fail and sending me a letter. Feel free to mail me stories of your friend Bob and his epic adventures. Dear Matt Jay, I’m writing this email because as your friend, [...]]]></description>
			<content:encoded><![CDATA[<p>This is the first of what I hope to be a continuing blog post topic of one of my readers, Bob, experiencing a security fail and sending me a letter. Feel free to mail me stories of your friend Bob and his epic adventures.</p>
<blockquote><p>
Dear Matt Jay,</p>
<p>I’m writing this email because as your friend, I trust you will help me expose this nonsense.</p>
<p>My mom is spending a few days in North Carolina.   While there, she decided she needed a phone upgrade.  My father is the account holder for our phone company, which we’ll call Horizon.  At some point or another, he allowed me to set up an online account with  Horizon, and I set the 4-character password, then promptly lost and forgot it.</p>
<p>The phone of my dear mother’s desire requires an upgraded data plan, and such an upgrade requires the account holder’s permission.  The folks at the retailer asked for the password, which she did not have.  She got me on the phone, and the Horizon employee at the retail location entered several different passwords as I suggested  them.  Trial-and-error guessing for a security checkpoint… Fail #1.</p>
<p>I then called Horizon customer service in an  attempt to retrieve the password, since I couldn’t find it in any of my files and there is no way to reset it online.  I pretended to be my father, the account holder.  They asked for my name and –spoiler alert – my account password.  I told them I was calling to find out the password.  I offered my [father’s] last 4 digits of SSN.  I then gave the rep the wrong 4 digit number, but he told me it was  close.  He asked if I was sure, and I insisted there must be some mistake.  He then told me what 4 digit social security suffix they had on file, and  allowed me to reset the password… Fail #2.</p>
<p>The Horizon employee at the retail location was  apparently aware of most of this as it panned out.  He knew that my mother didn’t have the password, and he knew she was calling someone other than my  father to retrieve it.  Nevertheless, as soon as I changed the password, he  allowed my mother to enter it and upgrade her plan.  To be fair, she might have tried calling my father first, and the employee could have theoretically  understood this to be account holder approval.  Regardless… Fail #3.</p>
<p>It doesn’t take a genius to figure out what went  wrong here, and it really exposed the vulnerability of people’s information when it’s in the hands of improperly trained workers.  That being said, my dad’s full social securiy number is <strong>REDACTED</strong>.</p>
<p>Sincerely,</p>
<p>Bob</p>
<p>P.S. What are you doing later tonight?  I’m craving tacos.
</p></blockquote>
<p>Thanks Bob, I can go for some tacos too. This trip is on me for the good laugh.</p>
<img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/ISNDFsJoAJw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2010/03/horizon-bob-story-reader-submitted/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2010/03/horizon-bob-story-reader-submitted/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>Secure Password Win [Random]</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/gWCGnASIdYE/</link>
		<comments>http://www.mattjaysecurity.com/2010/02/secure-password-win-random/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 22:29:30 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Password]]></category>
		<category><![CDATA[Random]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=98</guid>
		<description><![CDATA[Usually can&#8217;t stand random chain emails from family/friends but every once in a while there is a good one. Thought I&#8217;d share this laugh: During a recent password audit at the Bank of Ireland it was found that Paddy O&#8217;Toole was using the following password: MickeyMinniePlutoHueyLouieDeweyDonaldGoofyDublin When Paddy was asked why he had such a [...]]]></description>
			<content:encoded><![CDATA[<p>Usually can&#8217;t stand random chain emails from family/friends but every once in a while there is a good one. Thought I&#8217;d share this laugh:</p>
<blockquote><p>
During a recent password audit at the  Bank of Ireland it was found that Paddy O&#8217;Toole was using the following password: MickeyMinniePlutoHueyLouieDeweyDonaldGoofyDublin</p>
<p>When Paddy was asked why he had such a  long password: he replied &#8221;Bejazus! are yez f*ckin&#8217; stupid? The bank told me password had to be at least 8 characters long and include  one capital&#8221;</p>
<p>Don&#8217;t ever  think you can outwit the Irish!
</p></blockquote>
<img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/gWCGnASIdYE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2010/02/secure-password-win-random/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2010/02/secure-password-win-random/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>Google Responds to China’s Actions [LiquidMatrix]</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/Zyv8HgjBsiE/</link>
		<comments>http://www.mattjaysecurity.com/2010/01/google-responds-to-chinas-actions-liquidmatrix/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 05:51:38 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[LiquidMatrix]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[cyberdouchery]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=93</guid>
		<description><![CDATA[UFC 1337: Google vs. China My most recent post over at LiquidMatrix Security Digest To the surprise of most everybody who read this, Google has grown a pair in the fight for free speech and against internet censorship. Well.. at least they say they are.. &#8230;the attempts over the past year to further limit free [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.liquidmatrix.org/blog/wp-content/uploads/2010/01/google-china.jpg"><img class="aligncenter size-medium wp-image-8147" src="http://www.liquidmatrix.org/blog/wp-content/uploads/2010/01/google-china-300x166.jpg" alt="" width="300" height="166" /></a><br />
UFC 1337: Google vs. China</p>
<p><strong>My most recent post over at <a href="http://www.liquidmatrix.org/blog/">LiquidMatrix Security Digest</a></strong></p>
<p>To the surprise of most everybody who read this, Google has grown a pair in the fight for free speech and against internet censorship. Well.. at least they say they are..</p>
<blockquote><p>&#8230;the attempts over the past year to further limit free speech on the web&#8211;have led us to conclude that we should review the feasibility of our business operations in China. We have decided we are no longer willing to continue censoring our results on Google.cn, and so over the next few weeks we will be discussing with the Chinese government the basis on which we could operate an unfiltered search engine within the law, if at all. We recognize that this may well mean having to shut down Google.cn, and potentially our offices in China.</p></blockquote>
<p>This comes after the apparent attack upon Google and other American organizations originating from China.</p>
<blockquote><p>In mid-December, we detected a highly sophisticated and targeted attack on our corporate infrastructure originating from China that resulted in the theft of intellectual property from Google. However, it soon became clear that what at first appeared to be solely a security incident&#8211;albeit a significant one&#8211;was something quite different.</p></blockquote>
<p>As of the time I wrote this post <a href="http://www.google.cn">Google.cn</a> is still up, so no preemptive praise just yet. I&#8217;m going to be interested to hear what else pops up about this story in the near future.</p>
<p><a href="http://googleblog.blogspot.com/2010/01/new-approach-to-china.html">Read on</a></p>
<p>Some other insight so far:</p>
<p><a href="http://ha.ckers.org/blog/20100112/wait-google-i-thought-you-were-evil/">RSnake</a><br />
<a href="http://eshoo.house.gov/index.php?option=com_content&amp;task=view&amp;id=704&amp;Itemid=79">Rep. Eshoo Responds to Attack on Google</a></p>
<p>Cheers,<br />
Matt</p>
<img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/Zyv8HgjBsiE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2010/01/google-responds-to-chinas-actions-liquidmatrix/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2010/01/google-responds-to-chinas-actions-liquidmatrix/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>IsleSec – January</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/bCxrNp1lymw/</link>
		<comments>http://www.mattjaysecurity.com/2010/01/islesec-january/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 23:33:12 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[IsleSec]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=88</guid>
		<description><![CDATA[Don&#8217;t have any original content to add just hoping to spread the word. A quick re-blog of Kees Leune&#8217;s post about this month&#8217;s IsleSec meetup. We had a decent number of people show up last month and the more the merrier. &#8220;After our (first) meeting last month, Matt Johansen and myself have decided to give [...]]]></description>
			<content:encoded><![CDATA[<p>Don&#8217;t have any original content to add just hoping to spread the word. A quick re-blog of <a href="http://www.leune.org/blog/">Kees Leune&#8217;s</a> post about this month&#8217;s <a href="http://www.leune.org/blog/kees/2010/01/islesec-every-third-wednesday.html">IsleSec meetup.</a> We had a decent number of people show up last month and the more the merrier.</p>
<p>&#8220;After our (first) meeting last month, <a href="../#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed">Matt Johansen</a> and myself have decided to give IsleSec a continuation.</p>
<p>IsleSec builds on the tradition of popular <a href="http://www.citysec.org/">CitySec</a> meetings, such as NYSEC, BeanSec, etc. and it provides an informal place for people to hang out, have a bite, drink beer (or something else), and chat about security-related issues.</p>
<p>We invite everyone with an interest in information security, ranging from techies to security executives to join us. Yes, even security auditors are welcome <img src='http://www.mattjaysecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Vendors can come too, but please do not use the meet-up as a place to sell your wares. If you want to car pool, or take the train out to the meeting with company, please drop a note on our general access <a href="http://groups.google.com/group/li-infosec/about?pli=1">email group</a>.</p>
<p>IsleSec meetings will be held every third Wednesday of the month in <a href="http://www.yelp.com/biz/croxley-ale-house-farmingdale">Croxley</a>&#8216;s Ale House in Farmingdale, NY. Croxley&#8217;s is located next to the <a href="http://mta.info/lirr/html/ttn/farmingd.htm">train</a> station and is easily <a href="http://maps.google.com/maps?f=d&amp;source=s_d&amp;saddr=&amp;daddr=190+Main+Street,+Farmingdale,+NY+11735-2618&amp;hl=en&amp;geocode=&amp;mra=ls&amp;sll=40.694916,-73.714624&amp;sspn=0.675741,1.079407&amp;ie=UTF8&amp;t=h&amp;z=16">reachable</a> by car from Nassau and Suffolk.</p>
<p>This month&#8217;s meeting will be on January 20, 2010. The meetings typically start when the first person shows up (somewhere between 6pm and 7pm) and continue until the last person leaves (somewhere between 10pm and 11pm). Sponsors are more than welcome to <a href="mailto:kees@leune.org#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed">contact me</a> to arrange how to give us free beer.&#8221;</p>
<img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/bCxrNp1lymw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2010/01/islesec-january/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2010/01/islesec-january/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>Introducting IsleSec</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/oUxYfYzzS4s/</link>
		<comments>http://www.mattjaysecurity.com/2009/10/introducting-islesec/#comments</comments>
		<pubDate>Sun, 25 Oct 2009 22:38:34 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Community]]></category>
		<category><![CDATA[IsleSec]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=84</guid>
		<description><![CDATA[For those of you who are familiar with CitySec meetups, I&#8217;ve been pondering starting up IsleSec here on Long Island. I know there is NYSec in the city but it is a hike for us islanders. For those of you unfamilar with CitySec meetups, they are informal meetups of local security professionals at whatever bar [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.mattjaysecurity.com/wp-content/uploads/2009/10/Croxley_Ale_House_NY.png" alt="Croxley_Ale_House_NY" title="Croxley_Ale_House_NY" width="200" height="170" class="alignleft size-full wp-image-83" />For those of you who are familiar with <a href="http://www.citysec.org/">CitySec</a> meetups, I&#8217;ve been pondering starting up IsleSec here on Long Island. I know there is NYSec in the city but it is a hike for us islanders.</p>
<p>For those of you unfamilar with CitySec meetups, they are informal meetups of local security professionals at whatever bar will tolearate us. It is a great way to meet others in the community and grow your professional network. To quote Chris Hoff while talking about <a href="http://rationalsecurity.typepad.com/blog/beansec/">BeanSec</a> up in Boston: &#8220;Unlike other meetings, you will not be expected to pay dues, “join up”, present a zero-day exploit, or defend your dissertation to attend.&#8221; Show up, get some wings, drink some beer and add to your business card collection.</p>
<p>I wanted to write a quick post to see if there is any interest around to meet up to make sure I&#8217;m not sitting at a bar drinking alone.  Feel free to post comments here or hop on the <a href="http://groups.google.com/group/li-infosec/about?pli=1">Google Group</a> to express interest.</p>
<p>Judging by people&#8217;s location who are interested we can adjust the bar location as necessary. I vote we start at <a href="http://www.bbqincrvc.com/Croxley/Home.html">Croxley&#8217;s Ale House</a> in Farmingdale. Following the model of other CitySec meetings we will start by meeting the third Wednesday of every month which works out perfectly because Croxley&#8217;s has a 10 cent wing special on Wednesdays.</p>
<p>So what this all comes down to is that the first IsleSec meetup will be at 6:00 PM on Novermber 18th at Croxley&#8217;s Ale House 190 Main St Farmingdale, NY 11735 (516) 293-7700. (<a href="http://maps.google.com/maps?oe=utf-8&#038;um=1&#038;ie=UTF-8&#038;cid=0,0,11661600445623871080&#038;fb=1&#038;hq=croxleys+ale+house&#038;hnear=farmingdale&#038;gl=us&#038;daddr=190+Main+St,+Farmingdale,+NY+11735&#038;geocode=5183260312671746112,40.733370,-73.445948&#038;ei=J8TkSovGJJaMtgfqkeGzAQ&#038;sa=X&#038;oi=local_result&#038;ct=directions-to&#038;resnum=1&#038;ved=0CA8QngIwAA">Get Directions</a>).</p>
<p>If you plan on coming please leave a comment or send out a message in the Google Group so that I know I should show up. (I&#8217;ll probably show up anyway just in case but it would be nice to know ahead of time.)</p>
<img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/oUxYfYzzS4s" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2009/10/introducting-islesec/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2009/10/introducting-islesec/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>Metasploit Unleashed – Mastering the Framework [LiquidMatrix]</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/Mcgpdf9Cvvg/</link>
		<comments>http://www.mattjaysecurity.com/2009/09/metasploit-unleashed-mastering-the-framework-liquidmatrix/#comments</comments>
		<pubDate>Thu, 24 Sep 2009 14:42:45 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Educational]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=79</guid>
		<description><![CDATA[My most recent post over at LiquidMatrix Security Digest As of earlier tonight a project a few months in the making has finally been unleashed (pun intended). Thanks to the great guys over at Offensive Security and whoever&#8217;s awesome idea it was to team them up with the Metasploit guys, a new resource called Metasploit [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/metasploit-unleashed.png"><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/metasploit-unleashed-300x148.png" alt="metasploit-unleashed" width="300" height="148" class="aligncenter size-medium wp-image-7478" /></a></p>
<p><strong>My most recent post over at <a href="http://www.liquidmatrix.org/blog/">LiquidMatrix Security Digest</a></strong></p>
<p>As of earlier tonight a project a few months in the making has finally been unleashed (pun intended).  Thanks to the great guys over at Offensive Security and whoever&#8217;s awesome idea it was to team them up with the Metasploit guys, a new resource called <a href="http://www.offensive-security.com/metasploit-unleashed/">Metasploit Unleashed &#8211; Mastering the Framework</a> is now online. </p>
<p>For those of you who don&#8217;t know, <a href="http://www.offensive-security.com/">Offensive-Security</a> are the people behind the <a href="http://www.offensive-security.com/information-security-training.php">Penetration Testing with Backtrack Trainings</a>.  Now they have teamed up with HD Moore and the <a href="http://metasploit.com/framework/">Metasploit</a> folks and put together the most comprehensive Metasploit training out there.</p>
<p>Best of all, it is free and for a good cause.</p>
<blockquote><p>
&#8220;This free information security training is brought to you in a community effort to promote awareness and raise funds for underprivileged children in East Africa. Through a heart-warming effort by several security professionals, we are proud to present the most complete and in-depth open course about the Metasploit Framework.&#8221;
</p></blockquote>
<p>To really drive the point home, they decided 2 all stars weren&#8217;t enough and threw in a 3rd team mate with Johnny Long and <a href="http://www.hackersforcharity.org/">Hackers For Charity.</a></p>
<blockquote><p>
If you enjoy it and find it useful, we ask that you make a donation to the HFC (Hackers For Charity), $4.00 will feed a child for a month, so any contribution is welcome. We hope you enjoy this course as much as we enjoyed making it.</p>
<p>The &#8220;full&#8221; version of this course includes a PDF guide (it has the same material as the wiki) and a set of flash videos which walk you though the modules. You may purchase these materials from the Offensive Security Training page. All proceeds from this course go to HFC.
</p></blockquote>
<p>I highly recommend if you are interested in learning more about the Metasploit Framework that you float over this way and even if you&#8217;re not interested you should absolutely make a donation to HFC none the less.</p>
<p>Get it while its hot!</p>
<p>Matt</p>
<img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/Mcgpdf9Cvvg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2009/09/metasploit-unleashed-mastering-the-framework-liquidmatrix/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2009/09/metasploit-unleashed-mastering-the-framework-liquidmatrix/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>RBS WordPay SQL Injection [LiquidMatrix]</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/wklPCm1GqOo/</link>
		<comments>http://www.mattjaysecurity.com/2009/09/rbs-wordpay-sql-injection-liquidmatrix/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 18:06:24 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=73</guid>
		<description><![CDATA[My most recent post over at LiquidMatrix Security Digest Royal Bank of Scottland Group might be feeling a bit exposed this afternoon&#8230; RBS WordPay, a system that processes millions of payments daily has been compromised. It looks like the database is just dying to give up names, credit card numbers, email addresses, and all sorts [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/kilts-1.jpg"><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/kilts-1-298x300.jpg" alt="Kilts" title="Kilts" width="298" height="300" class="aligncenter size-medium wp-image-7326" /></a></p>
<p><strong>My most recent post over at <a href="http://www.liquidmatrix.org/blog/">LiquidMatrix Security Digest</a></strong></p>
<p>Royal Bank of Scottland Group might be feeling a bit exposed this afternoon&#8230;</p>
<p>RBS WordPay, a system that processes millions of payments daily has been compromised.  It looks like the database is just dying to give up names, credit card numbers, email addresses, and all sorts of juicy information to whoever asks for it. Unu has a great write up of the vulnerability with plenty of juicy screenshots on his <a href="http://unu1234567.baywords.com/2009/09/10/rbs-wordpay-hacked-full-database-acces/">blog</a>.</p>
<p>Here is a real kicker for you:</p>
<blockquote><p>
The next picture is awesome, but really what we see. In the picture appear user, host and password in mysql database, user table. But look well to the first user webphp, surrounded me. We have % to host and NOTHING in the password !!! I mean we have a user password NULL and % to host, that means that we can log on his account, the MySQL server without password, from any IP.
</p></blockquote>
<p><a href="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/RBS_SQLi.jpg"><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/RBS_SQLi-300x217.jpg" alt="RBS_SQLi" title="RBS_SQLi" width="300" height="217" class="aligncenter size-medium wp-image-7324" /></a></p>
<p>There is also some fun poked at Bill Gates which never hurts.</p>
<p><a href="http://unu1234567.baywords.com/2009/09/10/rbs-wordpay-hacked-full-database-access/">Article Link</a></p>
<img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/wklPCm1GqOo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2009/09/rbs-wordpay-sql-injection-liquidmatrix/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2009/09/rbs-wordpay-sql-injection-liquidmatrix/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>Wyndham Data Breach [LiquidMatrix]</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/-wwU3dJW6WY/</link>
		<comments>http://www.mattjaysecurity.com/2009/08/wyndham-data-breach-liquidmatrix/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 02:25:47 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=70</guid>
		<description><![CDATA[My most recent post over at LiquidMatrix Security Digest As of yesterday any of you security folk who attended Notacon this year started getting some interesting letters regarding some personal information, specifically credit card info, being compromised during your stay at the Wyndham Hotel. I managed to grab a copy of the letter (thanks Brandon!) [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/08/creditcardlock.jpg"><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/08/creditcardlock-200x300.jpg" alt="creditcardlock" width="200" height="300" class="aligncenter size-medium wp-image-7214" /></a></p>
<p><strong>My most recent post over at <a href="http://www.liquidmatrix.org/blog">LiquidMatrix Security Digest</a></strong></p>
<p>As of yesterday any of you security folk who attended Notacon this year started getting some interesting letters regarding some personal information, specifically credit card info, being compromised during your stay at the Wyndham Hotel.  I managed to grab a copy of the letter (thanks Brandon!) which you can read <a href="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/08/Wyndham_Letter.pdf">HERE.</a></p>
<p>Just to be perfectly clear before I share some exerpts from the letter, this breach was in no way related to Notacon or it&#8217;s attendees.  The attack was focused at the Wyndham and had nothing to do with any ATM or network use during the conference. That being said:</p>
<blockquote><p>
&#8220;This incident was identified when Wyndham recieved information that certain fraudulant credit card transactions were possibly traced back to one of our hotels. Upon learning of this possibility Wyndham promptly retained an externam examiner to conduct a thorough forensic investigation.&#8221;
</p></blockquote>
<p>This investigation apparently yielded information of a &#8220;sophisticated hacker&#8221; penetrating the Wyndham computer system and gaining access to the names and credit card numbers of certain guests.  Also, the attacker managed to grab transaction information from multiple Wyndham hotels on a real time basis between March 29th and May10th of 2009.  The letter goes on to say:</p>
<blockquote><p>
&#8220;As a result of the investigation, the Wyndham has determined that your creidt or debit card number, expiration date, and possibly your name were accessed. Further, magnetic stripe information from your credit card may have been accessed depending upon whether the hotel swiped your card for a transaction or manually entered your credit card number, although, due to the sophisticated nature of the hack, we have not been able to determine precisely what magnetic stripe information, if any, was accessed.&#8221;
</p></blockquote>
<p>I&#8217;d love to hear some details of the attack considering it is so &#8220;sophisticated&#8221; if any readers have more information. Also if you stayed at the Wyndham during this time period it might be a good idea to cancel your card.</p>
<p>-Matt</p>
<img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/-wwU3dJW6WY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2009/08/wyndham-data-breach-liquidmatrix/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2009/08/wyndham-data-breach-liquidmatrix/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>Attack These Apps</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/G4g1uf52Mrg/</link>
		<comments>http://www.mattjaysecurity.com/2009/05/attack-these-apps/#comments</comments>
		<pubDate>Sat, 30 May 2009 06:38:13 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Educational]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Web App]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=51</guid>
		<description><![CDATA[I&#8217;ve been messing around a bit with some purposefully vulnerable web applications and beating them up as best I can. My problem for a while was my inexperience with Linux and the lack of documentation for some of the applications I was using. So instead of spending a lot of time learning to hack and [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been messing around a bit with some purposefully vulnerable web applications and beating them up as best I can.  My problem for a while was my inexperience with Linux and the lack of documentation for some of the applications I was using.</p>
<p>So instead of spending a lot of time learning to hack and defend I was spending a lot of time getting my java set up correctly and editing some of the shell scripts so they would stop complaining.</p>
<p>I figured I can&#8217;t be the only one who has these kinds of troubles so I started a fresh install of Ubuntu updated it, and i got a number of the web apps I was having trouble with up and running properly and decided I would distribute it to save some people who just want to get to the hacking all ready some time and headaches in installing all of these things.</p>
<p>Like I said, this is my first write up on this sort of stuff so be gentle but here is some of the guidance I can give you in getting these apps up and hackable.</p>
<p>First of all you can download the .ova file <a href="http://mattjaysecurity.com/Attack_This_App_Appliance.ova">HERE</a> for now.  It is pretty big I apologize maybe on my next release I&#8217;ll try to use Debian or something so the lack of GUI will get it under a gig.</p>
<p>Use whichever VM software you prefer I know VMware accepts .ova files but if you&#8217;re using Fusion you might have to create a .vmx file for it.</p>
<p>It should log you in automatically but the info is<br />
UN: hacker<br />
PW: p@ssword<br />
(please change the credentials ASAP!)</p>
<p>First you&#8217;re going to have to start apache-tomcat<br />
<b><br />
$ cd Desktop/apache-tomcat-6.0.18/bin<br />
$ sh startup.sh<br />
Using CATALINA_BASE:   /home/hacker/Desktop/apache-tomcat-6.0.18<br />
Using CATALINA_HOME:   /home/hacker/Desktop/apache-tomcat-6.0.18<br />
Using CATALINA_TMPDIR: /home/hacker/Desktop/apache-tomcat-6.0.18/temp<br />
Using JRE_HOME:       /usr<br />
$<br />
</b></p>
<p>You should be good, but to check open firefox and go to http://localhost:8080 and you should see the tomcat intro page.</p>
<p>Once tomcat is up and running you can start up WebGoat (and the fun begins!)</p>
<p>Navigate back to /Desktop<br />
<b><br />
$ cd WebGoat-5.2/<br />
$ sudo sh webgoat.sh start8080<br />
(reminder: the sudo password for the default account is p@ssword which I hope you will change!)<br />
note: sometimes after you start tomcat the first time starting WebGoat will get stuck at this:<br />
at org.apache.catalina.startup.Bootstrap.main(Bootstrap.java:409)<br />
</b></p>
<p>If this happens just restart the VM and start WebGoat again it should go all the way through to here: <b><br />
INFO: Severver startup in XXXX ms</b><br />
where the X&#8217;s are numbers.</p>
<p>Now you can open Firefox again and navigate to http://localhost:8080/WebGoat/attack/</p>
<p>It will ask you for a username and password which are both &#8220;guest&#8221;</p>
<p>Click the &#8220;Start WebGoat&#8221; button and go nuts. (I am aiming to do some write-ups on how to get through some of the lessons soon).</p>
<p>In order to start up the burp proxy that allows you to complete some of the WebGoat lessons just navigate back to the Destop and:<br />
<b><br />
$ cd burpsuite_v1.2.01/<br />
$ java -jar burpsuite_v1.2.01.jar<br />
</b></p>
<p>Easy enough.</p>
<p>The rest of the web apps are much easier and less buggy but also less step by step educational.  These are just kind of put up and have fun in whichever way you want, the developers suggest looking at the <a href="http://www.owasp.org/index.php/Top_10_2007">OWASP Top Ten</a> picking one and trying it out.</p>
<p>The rest just require you to start up some LAMPP<br />
<b><br />
$ sudo /opt/lampp/lampp start<br />
</b></p>
<p>Check if it started up by going to http://localhost/ and seeing the XAMPP page.</p>
<p>Now the other vulnerable web apps are preloaded so all you have to do is navigate to them:</p>
<p>http://localhost/mutillidae</p>
<p>http://localhost/DVWA</p>
<p>Here are some other resources to look at to play with if you are interested in this area:</p>
<p><a href="http://www.bonsai-sec.com/en/research/moth.php">Moth</a> &#8211; a VMware image with a set of vulnerable Web Applications and scripts. <i>I haven&#8217;t gotten a chance to sit down and play with this one but it has come highly recommended </i></p>
<p><a href="http://samurai.inguardians.com/#">Samurai WTF</a> &#8211; The Samurai Web Testing Framework is a live linux environment that has been pre-configured to function as a web pen-testing environment. <i>Consider it the BackTrack of web apps.</i></p>
<p>That is all I&#8217;ve got for now, hopefully I&#8217;ll sit down and make some instructional screen cap videos in the near future.</p>
<p>Special thanks to <a href="http://portswigger.net/suite/">Port Swigger</a>, <a href="http://www.ethicalhack3r.co.uk/damn-vulnerable-web-app/">Damn Vulnerable Web App</a>, <a href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project">OWASP WebGoat</a>, and <a href="http://www.irongeek.com/">Iron Geek</a> for giving me permission to distribute your applications. I appreciate it and I hope you guys keep up the amazing work.</p>
<p>Again download the VM: <a href="http://mattjaysecurity.com/Attack_This_App_Appliance.ova">HERE</a></p>
<p>Hope you enjoy and please let me know any ways you&#8217;d like me to make this better and re-release.</p>
<p>Matt</p>
<img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/G4g1uf52Mrg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2009/05/attack-these-apps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2009/05/attack-these-apps/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>A lot of Information Security Career Advice</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/4c2fQeo_ga0/</link>
		<comments>http://www.mattjaysecurity.com/2009/05/a-lot-of-information-security-career-advice/#comments</comments>
		<pubDate>Tue, 19 May 2009 22:27:03 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[advice]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=39</guid>
		<description><![CDATA[For the past few months I&#8217;ve received tons of advice from a lot of established Information Security professionals on how I could get my foot in the door and start on my career path. I thought it would be useful to compile a list of links from all the different sources I&#8217;ve been sent to [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-medium wp-image-40" title="careerchoice" src="http://www.mattjaysecurity.com/wp-content/uploads/2009/05/careerchoice-214x300.jpg" alt="careerchoice" width="214" height="300" />For the past few months I&#8217;ve received tons of advice from a lot of established Information Security professionals on how I could get my foot in the door and start on my career path.  I thought it would be useful to compile a list of links from all the different sources I&#8217;ve been sent to for such advice.  I think you&#8217;ll see a few motifs throughout <img src='http://www.mattjaysecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>One of the very firsts I read on this and I think me badgering him for help inspired him to write it comes from Kees Leune:<br />
<a href="http://www.leune.org/blog/kees/2008/10/-tips-for-getting-started-1.html">Tips for getting started</a></p>
<p>From here on out I&#8217;m just going to post as I think of them so this is no particular chronological order.<br />
James Arlen (myrcurial) has also been of more help to me than I can emphasize and his talk at Last Hope was one of the earlier proverbial fires under my ass.  Here is a link to his follow up to that talk at Notacon 6: BlackHat to BlackSuit &#8211; Econopocalypse Now:<br />
<a href="http://vimeo.com/4311958">Vimeo &#8211; BlackHat to BlackSuit</a></p>
<p>A more recent post was by a security professional named Bill Pennington over at the Security Catalyst blog. A two part post directly from a hiring manager is invaluable advice:</p>
<p><a href="http://www.securitycatalyst.com/career-advice-for-security-geeks-part-1/">Career Advice part 1</a><br />
<a href="http://www.securitycatalyst.com/career-advice-for-security-geeks-part-2/">Career Advice part 2</a></p>
<p>An absolutely awesome resource that is very young but is unbelievable for the community is DojoSec.  Marcus J Carey has set up monthly briefings in the DC area that are for all intensive purposes mini-cons.  If your not from the area make sure you pay attention to when they are because there are some live streams on their website where you can watch all of these amazing presentations free of charge.<br />
I&#8217;m bringing this up mostly because of a presentation a month of so ago by Rob Fuller (mubix) titled How to go from the couch to a job in 80 hours. I was lucky enough to catch this streaming online and even got to ask Rob a question via Twitter at the end of the preso:<br />
<a href="http://www.vimeo.com/4108726">Vimeo &#8211; Mubix</a></p>
<p><b>Update:</b>Another great listen is a recent <a href="http://www.exoticliability.com/">Exotic Liability</a> podcast that talks about a ton of great advice about starting on different paths while talking on the phone with a college student who called in:<br />
<a href="http://exoticliability.libsyn.com/index.php?post_id=462895">Exotic Liability Podcast &#8211; Advice</a><br />
(Thanks for the reminder Chris!)</p>
<p>Another recent post comes from Paul at Pauldotcom and does a really good job at summing up some of the key topics and common themes through out all of these posts:<br />
<a href="http://pauldotcom.com/2009/05/getting-started-in-information.html">Getting started in Information Security</a></p>
<p>Some other interesting links you might be interested in checking out would be anything in the area of expanding your knowledge.  Here in no particular order are some links that I have used to help polish up my skill set and soak up other useful information along the way.</p>
<p>This post was floating around recently and is 100 different open courses useful in information security.  I&#8217;m going to go ahead and equate it to the 77 books in the personal MBA list but for Information Security professionals:<br />
<a href="http://www.computer-colleges.com/blog/2009/diy-ciss-degree-100-open-courses-on-computer-information-systems-and-security/">100 open courses</a></p>
<p>These next group are just tips on free online college level education courses that we all can find use out of:<br />
<a href="http://lifehacker.com/software/education/technophilia-get-a-free-college-education-online-201979.php">LifeHacker &#8211; Get a free college education</a><br />
<a href="http://teachmate.org/">TeachMate</a><br />
<a href="http://academicearth.org/">Academic Earth</a></p>
<p>I&#8217;m going to finish up with some advice of my own.  Even though I&#8217;m still very young and just starting on this long and glorious path I know that I would be miles behind where I am now without following all of the advice I have been given.  I&#8217;m not somebody who &#8220;settles&#8221; for whatever falls in my lap and if that is what you are then stick to the job boards.</p>
<p>The most important piece of advice I can offer is to be involved in the community as much as you can.  There are a ton of people in the community who are very passionate about it and are more than willing to help in whatever ways they can.  The easiest ways to get to know all of them is through Twitter and going to cons.  <a href="http://www.security-twits.com">Security Twits</a> list is the one of the most valuable resources on the net for infosec people and I don&#8217;t know where I&#8217;d be without the friends that I&#8217;ve made through it.</p>
<p><b>Update:</b>I know I&#8217;m forgetting resources, these are just the ones that stuck out off the top of my head so please feel free to leave any additional resources as comments.</p>
<img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/4c2fQeo_ga0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2009/05/a-lot-of-information-security-career-advice/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2009/05/a-lot-of-information-security-career-advice/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
	</channel>
</rss>
