Sunday, 24 April 2016

The Foray into Digital Forensics

As part of  my tertiary studies I'm now working on Digital Forensics. Our latest assignment includes some steganography, some bit shifting and writing a forensic report on a made-up or actual scenario that we find or invent.

I thought it might of use to write a bit about the experience I'm having getting into this. From the course we are supplied a variety of different tools with a variety of different capabilities. Being a Linux chap, I thought it would be cool to go into the open source tools. Running ElementaryOS on laptop has made this difficult and more than a little frustrating. Perhaps because I'm not big on what the best tools are, or the install methods - but I'm experiencing annoyance. I'm currently downloading Ubuntu 14.04 Desktop to put the SANS Investigative Forensic Toolkit (SIFT) version 3 on it. Details on SIFT can be found at http://digital-forensics.sans.org/community/downloads. I'll work this later - I'm still waiting on Ubuntu to download. It doesn't help living out in the bush.

The Windows tools I have played with thus far include:

  • ProDiscover Basic
  • Hex Workshop
  • OSForensics
  • WinHEX
I've also found Notepad++ to be quite useful. It's a very powerful notepad replacement I find useful for many applications of work - find it here: https://notepad-plus-plus.org

The textbook also seems pretty good - "Guide to Computer Forensics and Investigations" Nelson, Phillips and Steuart are the authors. Lots of good examples and methods for working through things. Annoyingly, but this is to be expected, it all has a US slant on it, including laws and rights. Translating them into Australian can be tricky at times. There are a lot of good resources on the Net - SANS as I've already mentioned, CERT and AusCERT aren't bad. Google is, as always, your friend.

I've spoken with some friends about this and they immediately assume its like CSI-Cyber and we use cyber to describe everything - it's a cybercrime, it's a cyberstalking, its a cyberpen I'm writing on this cyberpaper with etc. Of course it's not like that at all. Lots of painstaking attention to detail and writing a *lot* of notes. You can't blow through this stuff on a hunch - stupid TV shows seem to make it a lot easier than it is and people jump around with ideas and stuff all the time. What a bag of pish! At any rate it's fascinating stuff if you have the patience and technical background for it.

I'll update and add a post as I play with SIFT and with the particular case I'm investigating.

I have spent some time on the digital forensic reddit https://www.reddit.com/r/computerforensics/ which has some great info and great help for people. I thank the contributors for their time and effort. Was looking through a bit list of blogs and stuff about forensics. Sad that so many of them have fallen away. There's some gold in amongst it though. On to the SIFT install!

Saturday, 16 April 2016

The rise of ransomware and the devil that is Cryptolocker

Over time, with advancements in anti-virus and anti-spyware, the ne'er do wells would eventually evolve. Their cunning and understanding of human behaviour has resulted in the devil that is ransomware. An innocent email from Australia Post arrives or a letter from the Australian Federal Police turns up in your inbox - most people are curious, even excited by an unexpected package, or concerned about a letter from the AFP and so they click the link. Boom! All their data starts to be infected - encrypted with heavy encryption and a lovely letter to say pay us or never get your stuff back.

We've seen it live and in the field on at least 5 occasions and had one or two clients actually pay the ransom - buying their Bitcoins and getting their decryption key back. Sadly, we've had people try this only to find out the website they need to talk to has been closed down by the authorities and their data irretrievably lost - until we restore it from backups that is... but sometimes even this doesn't work if people haven't moved data to the servers for backup. It's not good.

It seems like it was inevitable that a new mode of making money from people would have to emerge. Stealing credit card details and personal information - while profitable - is also fraught with danger of being identified when you try to use them. An anonymous ransom - helpfully supported by an anonymous currency - means a relatively straightforward exchange - a key for your own data back. It's kind of elegant in a way. This doesn't mean I don't think these people should be prosecuted - I've seen and experienced the stress and pain of business owners as their data becomes inaccessible and I'd love to pass that back to the perpetrators.

There are ways and means of protecting yourself from this, but it comes down to being systematic about it - just like these thieving bastards have been. Consider your vectors of risk:

  • external influences
    • email
    • websites
  • physical influences
    • users
    • dodgy USB keys
  • active attacks
    • hack attempts
    • social engineering
There could be more.

Defending against these requires defence in depth. Some of these things are passive - they do the job all the time, with managed updates and some are active - people actually need to think about what's happening. Here are a few examples:-
  • email scanning (externally if possible)
  • strong firewall
  • internet scanning (if possible)
  • anti-virus and anti-spyware on the machines
  • Chrome instead of good old IE (or awful Edge)
  • user education - the single best form of protection and typically the one with the least amount of time and resources put into it. Honestly, it makes me experience sadness that people aren't trying to get their staff skilled up a bit on the computer. It doesn't take all that much!
  • backups
  • backups of backups offsite
  • restorable backups
Of course, this kind of systematic approach doesn't just cover the awfulness of ransomware, but could be helpful against many other risks - attacks, environmental (fire / flood / famine / Justin Bieber), malicious employee activity (still identified as the Number #1 risk by many security dudes) and other "out of the box" issues.

I haven't mentioned patching or updating your system although I know this is critical. Updates are a beast of a thing, and anyone caught with a SharePoint update that means a database rebuild will feel where I'm coming from with this - security updates can cause more pain than if the damn thing was hacked or compromised in some way. Understanding the impact of an update on key infrastructure is very important and it isn't a passive security mechanism like some of the other things I've mentioned.

Reporting is also a tricky thing - yes it's great to have all this stuff going on, but who wants to plough through 20 or 30 system generated emails in a morning? I have for the last 12 years and it's bollocks. I don't care for it at all, and to be honest - it becomes so rote and routine that I miss things (sometimes very important things) because I'm just skimming. I urge you to consider some sort of consolidation report or webpage with information colour coded according to rules so that things going wrong are immediately obvious. We only have a limited attention time (and I think I've written about this elsewhere) and so we need to make sure that time is being carefully put to use and not wasted on stuff that's all OK and we don't care about. Likewise, with Nagios or other monitoring software I'm using, the thresholds for things going wrong is quite high - i.e. tell me when something is really going to be in trouble, not that it's just experiencing some sadness now. 

This post has diverged somewhat from cryptolocker, but the principles in keeping that piece of garbage out of your network are similar across a wide range of threats. 

Thursday, 7 April 2016

XenServer 6.5 and Windows Server 2012 Slowness

Recently at more than one site we've been experiencing slowness with file transfers, and general 2012 behaviour. It's maddening because task manager, the performance monitor and XenCentre show very little to no load across the servers. Having reviewed it more thoroughly and turned off Windows file security and made no progress, we've started looking into the hardware that makes up our XenServers.

It's a bit of a mis-mash of gear - an IBM x3650 and a generic sort of a server make up the two physical hosts. They don't have a huge amount of power under the hood, but run a couple of VMs quite well. The 2012 server runs appalling though and I think I've figure it out.

The x3650 has a Broadcom chipset on the network cards and this doesn't play well with others. The other generic beast of a machine has an Intel chipset on it's network cards and it runs fine. Yesterday I installed an Intel network adaptor into the x3650 and lo and behold, it's running better than it has been - significantly better. A click on the start button could take 20 - 30 seconds to get the menu to pop up in 2012 server, now it's almost instantaneous. My guys using this server for stuff are much happier.

In earlier iterations of XenServer I haven't noticed this so much, but in this most recent one I certainly have. XenServer 6.2 didn't seem to have this issue, so I wonder what has changed in the driver management to have caused this issue.

If you have servers running with odd slowness, definitely check this out - we have a much larger site with 2012 servers running on hardware with Broadcom chipsets and we are about to install new Intel cards to see if that fixes the problem. Stay tuned - this could be a real head scratcher if you come across it, and if the fix is a couple of $500 NICs then it could save you a huge amount of time and effort.

Saturday, 5 March 2016

Cloud Computing Challenges in Regional Australia

Out here in the bush we have a fundamental problem with Cloud Computing. We can’t get to it! Our internet access is 3rd world at best and generally that’s being charitable. Recently I was at one of the incredibly rare Microsoft road shows in this area - we generally do not see any big companies come through here. Our regional population is around the 100,000 mark so we’re a small fish in a big ocean.

The key message being delivered by the Microsoft chaps was Cloud, cloud and more cloud. So the outlook for the presentation was cloudy. Azure, Office365 - all that good stuff. Great for Microsoft - everyone moves to a subscription model, doesn’t need onsite hardware and you pay - continuously - for ever! Some of the stats were interesting. 

Of those taking up a hosted Exchange, very few had taken up Office365. The presenter was surprised by this, but I don’t know why. We have a lot of clients using Office2010 or 2013 who have either purchased it very recently (in the case of 2013) or have specific applications or processes built around the way that Office works. They are not likely to change any time soon - the ROI on their purchase has not yet been achieved. And amazingly, some of these clients don’t want to pay for the software every month.

We have some clients, quite a few sadly, that have sub 10Mbps ADSL2+ connections who are absolutely staying away from cloud anything. All well and good to have their data in someone else’s server, but they can’t get to it! With such a crap internet connection, it’s almost impossible to upload data, let alone pull it back down. The pain for having to move to a different cloud provider - especially if the data has to come back to site first before leaving to the new hosting is going to be considerable. 

The question I didn’t get to ask the Microsoft lads was: “What is Microsoft doing to promote better internet connectivity so we can sell all your cloud stuff?” Such a large company, with fingers in so many pies - get us better internet! 

While it’s true we are Google Apps resellers, and Microsoft Partners and we do have quite a few hundred Office 365 and hosted Exchange subscribers out there, we are severely limited by the ability to provision these services.

Access is not the only challenge we have. Data sovereignty is a major issue for our clients too. They don’t believe that they maintain full control over data sitting on someone else’s servers and, quite understandably, some of our clients are not big fans of that. Truth be told, it’s a fair jump to make for someone. “Let’s put all our gold in someone else’s chest! Screw that!” - this was a message given to me by one of my clients. He viewed his data as gold and didn’t want anyone else to have control and to be fair, it’s the result of his life’s work. 

There have been lots of issues around someone else maintaining and holding client data - privacy, security, accessibility being the big three. Who is held accountable etc are all the questions we are asked many times. Microsoft have not helped their own cause with some of the stuff they’ve done over the years - anticompetitiveness and their major hate on for Linux to name two. Being a massive company that doesn’t pay it’s taxes in Australia and is US owned are more strikes against them for the purposes of this argument and in the minds of many rural business owners. These are hard things to overcome, especially when I’m asked about my own cloud usage.

I live on a farm. Can you guess how great my internet connection is? The pigeon delivering my USB of data each day is pretty fast, but nothing compared to an urban fibre connection. So by necessity my cloud interactions are controlled and largely minimal. There are plenty of business - who are in rural cities - that do not have internet connectivity as reliable or “fast” (I sniggered when I wrote that because its a 3.5Mbps connection on the best of days) as I do. No cloud for them!


Before you go hell for leather selling cloud services to clients, stop for just a moment and consider all the variables beyond what Microsoft is telling you. They want very much for you to be locked in with their model, using their servers and services for ever because then you have to pay for them every month for the rest of eternity. There are other ways and its important to keep those options alive for people. Onsite servers are not dead - not by a long shot. Let me reiterate the main point of this article - we have to provide data to our clients in a secure, reliable and accessible way. Doing so is the important part. How we deliver it is the challenge.

Saturday, 20 February 2016

Breaking the iPhone's encryption

For the last few days the internetz has been in an uproar. If you haven't heard then have a look at this:
Apple ordered to help the US government. For the TL;DR folks out there:

  • some terrorist killers in the USA used an iPhone 5C
  • the FBI want to know what was on the phone
  • the phone has that lock where 10 incorrect pins wipes it
  • a judge has ordered our old mates at Apple to disable the wipe function so the FBI can break in
  • Apple have told them to go away and refused to do it
So, gentle reader, why do we care about this? A bit of backstory might be useful...

The iPhone has quite solid built in encryption. Check out the Apple Privacy policy here for all the goods (PDF download) https://www.apple.com/business/docs/iOS_Security_Guide.pdf - lots of goodies in there. From iOS 8 onwards, the basic iPhone data was heavily encrypted, and Apple have always claimed they don't access passcodes or data. Here is their privacy policy if you'd like to have a read: Apple's Privacy Policy

Bottom line: Apple have long claimed that without the passcode an iPhone is basically inaccessible and now the FBI have a judge ordered Apple to disable this protection. This is a pretty full on hack. In his open letter, Tim Cook, the Apple CEO basically said we'll have to rewrite the code, install it on this iPhone and then let the FBI in. Oh and now that's out in the open, welcome thieves, pirates and governments who want access to iPhones! Prior to iOS 8, Apple had assisted law enforcement with access to iPhones in the past, but now they're saying we can't do this anymore. Tim Cook's letter is here: Apple Letter to our Customers and all the details are here. 

My analysis of what this means for us, the consumer, is that once again law enforcement and government have requested the capabilities to break through our privacy. At the moment, Apple users are reasonably confident of the privacy of their devices. If you lose it then best of luck to anyone try to break into it. Different to an Android device with an SD card in it - where you could pinch the SD card and get whatever you want, unless it's encrypted. The iPhone does this already. I was looking the other day at the security of Apple Notes. It's encrypted on the device, in iCloud (if you use it) and in transit between the two. I'm not sure it's encrypted on your Mac though - something to check. My point is that the security is pretty good out of the box. Not being a chap involved in dodgy behaviour I've never had a real need to have heavy protection on my iPhone but I was certainly pleased to see that I had decent encryption on the device. 

I think there's a parallel here between Pandora's Box and introducing a back door into iOS. When Pandora opened the box and let evil into the world the big corporations were born (yes I have a hate for them and yes I'm aware of the inherent irony of using Blogger to write this - a part of the biggest corporation Google!), in this instance, once the iPhone's security is broken to allow law enforcement  a backdoor in, that's a genie that doesn't go back into the bottle. From there, it's relatively easy to see how the police or feds get compromised and that backdoor gets into the wild. Voila! No security any more for people's devices and anything you put on them might as well be in the public domain. Apple have said they won't comply with the order and that it's technically very difficult. I believe them. Encryption is tricky at the best of times and getting it right is hard. Breaking back into it, once you've worked so hard to establish it isn't easy. 

This story has garnered a lot of press in the last few days and there are plenty of people talking about it which is important. The right to privacy, which I think is closely linked to the core desire for security of oneself is critical. I hope that Apple fight this one hard and/or make it incredibly difficult for the hack to be repeated. I understand law enforcement need access to stuff to prosecute etc. I do understand that. But with so much warrantless invasion of privacy I'm not inclined to be a huge supporter. In a small scale this probably seems callous - those poor people murdered by the crazies and I don't want to know the truth about it all! Shame on you ryv! But in the broader scope, this affects all iPhone user's security and I'm concerned about that too. 

I'll be keeping an eye on this issue as it develops - if you're an iPhone user, you should too.

Thursday, 18 February 2016

Lenovo E540 won't start or boot - solved

Recently a client called saying their fairly new E540 wouldn't turn on or respond at all. The red light that makes up the "i" in ThinkPad would light up but that was the extent of the functionality.

I tried removing the battery and booting off but no dice. The computer was totally unresponsive. It turns out there is an issue with Lenovo for Small Business software that causes this.

To fix it, remove the BIOS battery - this is located under the compartment to the left in this photo:

Stick the battery back in and give it the berries. The laptop should boot and complain about the time and date. Set those and start the laptop. Log in, go to Uninstall Programs and ditch the Lenovo for Small Business. Once that's done, it's probably a good idea to update the BIOS. Try not to screw that up by killing power or anything mid upgrade. The recovery process is incredibly annoying and not guaranteed to work.

A reboot and you should be right to go. Enjoy.

Tuesday, 16 February 2016

How ethical is it to download movies and TV using torrents?

I have just completed a Cyberethics course and I was forced to consider this question in depth as part of an assignment. Given that I had to answer a specific question, I couldn't really put forward what I truly feel, so that's what this post is all about.

I have long considered that paying a fair and reasonable price for content delivered in a timely and reasonable manner to be of no issue whatsoever. Let me put that out there for y'all. If I have access to a wide catalogue of TV shows or movies, they're priced reasonably and the available in a timely fashion I see no reason to have take other measures to get the product I want. In researching the essay for this course, I had to read a whole bunch of journal articles and I won't bore you to death with those, nor will I bore you with proper citations.... From this research, the core matters that affect a person's decision to download or pirate digital content appear to be:

  • price
  • availability
  • time to market
  • quality
  • perceived unreasonable behaviour by content producers
and in some cases a simple unwillingness to have to pay for everything (for whatever reason). I'm sure that if you are an Australian, gentle reader, that you will know all too well the Australia Tax. If you aren't an Aussie, then this is a new thing to you. The Australia Tax affects us all down here, particularly back in the day when it was expensive to transport things to our island continent. Nowadays though, it costs very little to transport digital media under the sea and into the country. The tax is applied to Apple and Microsoft software, to hardware, cars, digital content. APC Mag has a list here: http://apcmag.com/overcharge.htm/ It's a bit old, but you can see the overcharge. 

This article started it all: Downloading movies and TV is not a crime from the Sydney Morning Herald. The writer makes some great points and I will echo them here. According to Australian law it's not a crime to download movies or TV per se. It is instead a breach of copyright. The crime of theft can only occur if the owner of a piece of property is permanently deprived of it - and that doesn't work when applied to digital media. The owner still has it, and can still market and sell it. Applying copyright law to try to enforce the preservation of copyright as been spectacularly unsuccessful. I remember as a young chap watching while Napster was sued and the MPAA, RIAA and ARIA started going after downloaders. Universities protected their students, and now even ISPs are protecting their clients, refusing to give data up about the end users. I remember while still at Uni hearing about the people that were being chased and the recording and movie industry wailing at their loss in profits - think of the poor actors! Only getting $10 million a movie when they could get $20 million! Think of our profit margins - oh woe is us! And then seeing them record the largest profits ever. Those poor souls. I really felt for them as I contemplated getting that latest new release from the internets. 

Down under we get a limited catalogue of content available. Netflix, iTunes, etc all only release a subset of their products to us. Why? Some licensing bullshit. Clearly to do with maximising profit margins. What these idiots are failing to recognise is the market in Australia is hungry for content. So hungry we were allegedly the largest downloaders of Game of Thrones last year. While the media morons all shook their heads and bemoaned those evil downloading Australians, they failed to recognised why we were engaged in this behaviour. The reasons above a directly responsible for this. Game of Thrones, as an example, is available only on Pay TV. I personally do not have Pay TV. Why pay $70 a month for something when I hardly have a chance to use it? I would literally only be getting it for GoT. Also, in this attention economy, I resent paying for a service and then having to pay my attention to ads. That's double dipping. More thieving bastardy on the parts of the media moguls. This year, GoT will air completely on Pay TV before it is available on Free to Air. I understand how Free to Air works - I pay with my attention to the ads. That's OK. I'm cool with that. I'm not cool with having to wait those extra months to see my shows though. Can I buy them off iTunes in a timely manner? Can I see it on Netflix? I'm not sure. What I do know, from a mate, is that I could download in high definition a copy of each GoT episode an hour after it airs from torrents. That's how you meet audience demand. Supply the content that's wanted and do it in a timely manner. No geographical restrictions on what you can get to watch or listen to! It's supposed to be a free market and yet it clearly is not. 

I should also note, that the stuff we can occasionally get is up to 400% more expensive than what might be paid for it in USD. Now, not only do we have an increase in price because the Australian Dollar isn't worth a pinch of goat shit, but the bastards gouge the arse out of us anyway. Are we honestly supposed to be happy with that? Do they expect us to toe the line and simply get on with bending over and allowing the media content producers to have their way with us? I don't think so. And the evidence is clear that Australians aren't doing it vis a vis the top downloaders of Game of Thrones. Imagine for one stunning moment there is an executive in these content houses with a semi-functional brain, beyond just wanting enormous profits. This relative genius could see a massive market that is being undersupplied and misunderstood. If GoT was available in a timely manner, reasonably priced - maybe a couple of dollars per episode or something, then imagine the profit difference! I'll just do some maths for you now.

So currently, for arguments sake, 3 million Australians are downloading GoT. That's 3,000,000 times $0 in profit.... which is... just using my calculator here... $0 dollars of profit. Bravo content producers. But here's an amazing thing! If that product was available via iTunes or Netflix or <insert other gouging content provider> for even just $1, then the profit would be... more calculations.... $3,000,000! Holy shitballs Batman! And that's per episode! What an amazing thing! I just fell off my chair! (much of this is sarcasm - I have not literally fallen off my chair, nor do I own a calculator). I would think for a quality TV show like Game of Thrones, I would happily pay up to $5 an episode. But it has to be delivered at the same time as it airs, it has to be in high def and the catalogue I'm choosing from has to be broad. On iTunes, Game of Thrones is $3.49 / episode (10 episodes) or $32.99 for the season. But according to this article http://exstreamist.com/game-of-thrones-season-5-will-be-on-itunes-after-it-airs/ Game of Thrones won't be available on Australian iTunes until after the season finishes. Guess what thieving bastards - you're not getting my money then and I'm not waiting that fucking long to see a TV I really like. I'll get it by other means. I'd pay $3.49 an episode if it came day of each episode airing but if think I'm going to wait and then still pay then I suggest you see a neurosurgeon because half your brain is non-functional. It's shit like this that makes an average, happy to pay person like myself say: "Right, time to learn how to use this torrent thing!" and then set up a VPN to another country, wrap it all in encrypted tunnels and show the big middle finger to the establishment. Screw you thieving bastards!

You can probably tell I get a bit cranky about this. Equality for all I say. The only people "suffering" and I use that term in it's most loosely possible way are the execs watching their profits only reach stratospheric heights instead of astronomical heights. 




So is it ethical? Well that's up to you isn't it? 

AppleTV and Jellyfin

 I like the AppleTV - what a great little bit of kit. The sad thing is, the application that connects to my Jellyfin server has been very hi...