I can't believe that came from your mouth!
Cyber
All-things related to Cyber Security
College Humor’s WebSite Story
Jul 1st
This is a great spoof on West Side Story, but updated for the Internet age. Enjoy.
All my thanks goes to Marco Mo.
Like This Post? Rate it and tell your friends! Click the Share button below.
Get IE8 B4 OMGIGP
Jul 1st
Dean Kane explains why it is so important to use the InPrivate mode of IE8. UPDATE! Not anymore. Microsoft seems to have taken down this epic video because it featured a chick puking through her nose in disgust at her husband’s porn surfing habits. So instead, this is a video on sharing, which is also kinda funny.
On a related note, I saw this picture today on FARK and I LOL’d.

Like This Post? Rate it and tell your friends! Click the Share button below.
Build Your Own Cube Farm
Jun 30th
When I was on vacation I made a rare impulse buy. I picked up set 1 of The Cubes, Bob. This is Bob below.

He comes with awesome motivational posters, his own computer, filing cabinet and deskphone. You can buy other Cubes too and build your own tiny cubefarm of despair. You can also get Ann.

Or maybe the IT guy:

Check out the whole set at CubeFigures.com here.
Like This Post? Rate it and tell your friends! Click the Share button below.
Steve Jobs Used iAnesthic to Get iSurgery and Received iLiver
Jun 20th
Steve Jobs has been out of work to receive his own upgrade. Lets hope his bio-developers are as good as the ones at Apple.

From the WSJ here:
Steve Jobs, who has been on medical leave from Apple Inc. since January to treat an undisclosed medical condition, received a liver transplant in Tennessee about two months ago. The chief executive has been recovering well and is expected to return to work on schedule later this month, though he may work part-time initially.
So I think we can rule out alcohol as the cause of the failed liver, which leaves autoimmune or hepatitus as the culprit.

Remember, as House would say, it’s Not Lupus.
Like This Post? Rate it and tell your friends! Click the Share button below.
Oldest Computer PII Data Loss Uncovered
Jun 17th
The guys at DataLossDB.Org ran a user contest looking for the oldest reported instances of personally identifiable information that was stolen or lost by an organization that would, under today’s standards, have to be disclosed according to law. As it turns out, the oldest instance was that of patient records disappearing from a Los Angeles hospital for the insane in 1903. But the oldest computer incident found relates to a hospital that suffered a breach via a phone line by hackers from Milwaukee in 1983. It involves a VAX 11-780 by Digital Machine corp.
![]()
That article is online courtesy of Time Magazine here:
One Friday morning last June, Chen Chui, systems manager of the hospital’s medical physics computer service, discovered to his great astonishment that a Digital VAX 11/780 computer, which monitors the radiation treatment for 250 patients, had inexplicably failed during the night. Looking into the machine’s log, he found that a file of billing records worth about $1,500 was missing and that passwords had been issued to five unauthorized accounts. Chui deleted the new names and took the extra precaution of replacing all the passwords for those authorized to change patient records.
Chui hoped that that would be the last of it. It was not. After the weekend he discovered that someone had made contact with the computer through a telephone hookup and introduced a new program: whenever a legitimate user typed in his password, the code name was immediately sent to the intruder. “It was panic,” says Dr. Radhe Mohan, director of the computer service. “Someone was up to big mischief that could have conceivably caused harm.”
Sloan-Kettering officials called the New York City police, the FBI and New York Telephone security, which tapped the phone lines connected to the machine. Then Chui tried to reach the intruders by leaving messages in their computer terminals. “You have done some harm to the system,” read one plea. “Please call us and help us repair the damage.” About an hour after the message went out, someone called back. “He said he was sorry,” recalls Chui. “But when we asked how he got into the system he refused to answer.”
Over the next two months there were about 20 other calls to the computer; the most recent took place on Aug. 11. In July the hospital received a tip identifying two young men in the Milwaukee area as the source of the trouble. The two were innocent, but the Milwaukee connection turned out to be the break that police needed. For months, FBI agents had been tracking the activities of a loosely organized gang of computer enthusiasts in and around Milwaukee who call themselves “the 414s” after that city’s telephone area code. Using home computers connected to ordinary telephone lines, they had been breaking into computers across the U.S. and Canada, including one at a bank in Los Angeles, another at a cement company in Montreal and, ominously, an unclassified computer at a nuclear weapons laboratory in Los Alamos, N. Mex.
What a shock that the Los Alamos labs had such crappy cyber security back then too. Check out the rest of the contest results over at DatalossDB here.
Like This Post? Rate it and tell your friends! Click the Share button below.
1 AM Music: Weird Al Yankovic – “Craigslist”
Jun 17th
My previous post was on Craigslist, and I would be remiss if I didn’t post this awesome new song and video by the Geek Rock God, Weird Al. And the keyboardist in this video which is an homage to the Doors is the legendary keyboardist of the Doors, Ray Manzarek. Enjoy.
Like This Post? Rate it and tell your friends! Click the Share button below.
MySpace to Fire 400
Jun 16th
Facebook likes this. The firing of 400 MySpace employees is supposed to help the company stay lean and run more efficiently. Maybe now they can hire someone to make the site look better and less like an HTML coding horror.

From Reuters here:
MySpace, the social network owned by Rupert Murdoch’s News Corp, said it will cut 30 percent of its staff to lower costs as it struggles to stay popular in the face of rising competition.
MySpace will be left with about 1,000 employees, it said in a statement released on Tuesday. The company declined to say how many people work at the service, but the percentage suggests that about 400 people will lose their jobs.
The cuts are the biggest move so far by new management at the social network and an attempt, it said, to return the service to a “start-up culture.”
I think MySpace has lost so much marketshare to FaceBook that it may never recover. I think the only way they can capture the market back is to clean up the site. Standardize on just a few clean templates, get rid of annoying ads, or better yet, allow users to get a cut of the ad revenue, and tighten security.
Like This Post? Rate it and tell your friends! Click the Share button below.
Does Your Corporate Phone System Have a Password?
Jun 15th
Just about every corporate office uses a telephone routing system or a PBX to handle their incoming calls and route calls both internally and externally back to their carrier. I was once the administrator of my office’s PBX, and would often configure the system for new employees, reset voicemail passwords and perform other tasks for the office. Unfortunately, the password of such systems, typically a 6-digit code, are all too often are left as default.

People familiar with such systems can dial into your office after hours, request the voicemail box of the administrator and program the PBX remotely. Then the attacker will sell access to your system to overseas exchanges who will route calls through your system for their customers at a deeply discounted price. And if you are criminal or terrorist organizations, you can avoid wiretaps this way. Brian Krebs has a great story here on an Italian case that deals with 2,500 US corporations that left their PBX with a default password. Check it out.
I’m back on travel again this week. This time its Shreveport, Louisiana, home of mosquitoes and alligators. Oh, and maybe some cajun food too. Blogging will be erratic when possible, so browse through some of my archives.
Like This Post? Rate it and tell your friends! Click the Share button below.
World’s Dumbest Hacker Threatens Suicide if He’s Extradited
Jun 9th
The world’s stupidest hacker, gary McKinnon, who is self-diagnosed as having Assburgers syndrome, a made-up disease to explain why stupid people do stupid things, is now saying he will kill himself if he has to fly to the US to stand trial for damaging DoD systems after September 11th.

From the BBC here:
Hacker ‘too fragile’ to extradite
A British computer hacker who targeted Nasa should be tried in the UK not the US because his mental state is so fragile, the High Court has heard. Lawyers for Gary McKinnon say there is “clear, uncontradicted expert evidence” that the stress of extradition could result in psychosis and suicide.
He has Asperger’s syndrome and claims he was looking for details of UFOs.
Mr McKinnon hacked into 97 government computers belonging to organisations including the US Navy and Nasa during 2001 and 2002. The US government says this caused damage costing $800,000 (£500,000) at a time of heightened security in the wake of the 11 September 2001 attacks.
But he disputes the amount of damage the US alleges he caused to its computer systems and says he did not employ any complicated techniques. He said: “I’m not, you know, a master hacker. I didn’t write my own programmes or anything. I used commercially off-the-shelf available software.”
Mr McKinnon’s lawyer told the High Court on Tuesday that the home secretary had “underestimated the gravity” of the threat to his client’s mental health. He said Mr McKinnon was “an eccentric person who has passionate views about UFOs” – not a malicious hacker – and extradition was “unnecessary, avoidable and disproportionate”.
Mr McKinnon earlier told the BBC that the last seven years since his arrest had taken a considerable toll on him, both personally and financially, as he is unable to work in IT.
His solicitor Karen Todner said being sent to the US would be very difficult for Mr McKinnon. She said: “One of the problems with Asperger’s is that you need to have your family and support network around you and Gary would be completely denied that.”
This asshat is unable to work in IT because he can’t be trusted not to hack into the systems, not because of stress due to prosecution. And to better understand Assburgers, you should click here. I have been writing about this idiot almost since my blog has been online. To find all stories, click here.
Like This Post? Rate it and tell your friends! Click the Share button below.
FTC Shuts Down 3FN Webhosting Company
Jun 4th
One webhosting company responsible for hosting hundreds of criminal operations, including spammers and child pornographers has been shut down by the FTC. The court order simply turned off the router. This company is now gone black.

From Brian Krebs at WaPo here:
In an unprecedented move, the Federal Trade Commission has taken legal steps to shut down a Web hosting provider in Northern California that the agency says was directly involved in managing massive global spam operations.
Sometime on Tuesday, more than 15,000 Web sites connected to San Jose, Calif., based Triple Fiber Network (3FN.net) went dark. 3FN’s sites were disconnected after a Northern California district court judge approved an FTC request to have the company’s upstream Internet providers stop routing traffic for the provider.
In its civil complaint, the FTC names 3FN and its various monikers, including Pricewert LLC — the business entity named on the 3fn.net Web site registration records. The FTC alleges that Pricewert/3FN operates as a “‘rogue’ or ‘black hat’ Internet service provider that recruits, knowingly hosts, and actively participates in the distribution of illegal, malicious, and harmful content,” including botnet control servers, child pornography and rogue antivirus products.
The FTC chairman confirmed that this was the first time the agency had sought and been granted an order to shut down an Internet service provider.
“Pricewert hosts very little legitimate content and vast quantities of illegal, malicious, and harmful content, including child pornography, botnet command and control servers, spyware, viruses, trojans, phishing related sites, illegal online pharmacies, investment and other Web-based scams, and pornography featuring violence, bestiality, and incest,” the FTC said.
I am happy to see the criminal operations taken down, but it is surprising that it was the FTC who did this instead of a law enforcement agency. Lets hope that LE is involved in actually trying to apprehend the people behind the malware and illegal content. Otherwise, these jokers will just move somewhere else.
Like This Post? Rate it and tell your friends! Click the Share button below.
Seeing Bing in My Weblogs
Jun 4th
I have been seeing hits on my website originating from Bing Searches. No, not this Bing:

The evolved Microsoft Live Websearch engine, which has been renamed as Bing. The search page is prettier, more informative, and can help you search better by using categories. If you haven’t checked it out yet, you should.
Like This Post? Rate it and tell your friends! Click the Share button below.
Wikipedia Bans Church of Scientology
May 29th
In a true LOL move, Wikipedia admins had a big powwow and decided that, effective immediately, everyone from the Church of Scientology should be crushed by the ban hammer. This is the first time that the do-it-yourself-encyclopedia has ever banished an entire IP range for abuse, proselytizing and pushing its own agenda.

Battlefield Wikipedia soon to be next Co$ novel?
From the Register here:
In an unprecedented effort to crack down on self-serving edits, the Wikipedia supreme court has banned contributions from all IP addresses owned or operated by the Church of Scientology and its associates.
Closing out the longest-running court case in Wikiland history, the site’s Arbitration Committee voted 10 to 0 (with one abstention) in favor of the move, which takes effect immediately.
The eighth most popular site on the web, Wikipedia bills itself as “the free encyclopedia anyone can edit.” Administrators frequently ban individual Wikifiddlers for their individual Wikisins. And the site’s UK press officer/resident goth once silenced an entire Utah mountain in a bizarre attempt to protect a sockpuppeting ex-BusinessWeek reporter. But according to multiple administrators speaking with The Reg, the muzzling of Scientology IPs marks the first time Wikipedia has officially barred edits from such a high-profile organization for allegedly pushing its own agenda on the site.
According to evidence turned up by admins in this long-running Wikiland court case, multiple editors have been “openly editing [Scientology-related articles] from Church of Scientology equipment and apparently coordinating their activities.”
So the Co$ is now out of the wiki-editing business, at least from certain IP ranges. So now I suppose the steps to becoming a Scientologist involves purging thetans with an e-meter, coughing up all your dough and finally, promoting Scientology on Wikipedia. Dumbest religion ever. Thanks to Robb for the story!
Like This Post? Rate it and tell your friends! Click the Share button below.
Wow! A Chinese Citizen Wins a Censorship Case
May 28th
A critic of the Chinese government and blogger, Hu Xingdou, sued his Internet Service Provider because they shut down his website because they claimed he was hosting illegal content. The judge in Beijing said Hu should have been given the chance to censor himself and awarded him 200 bucks in damages.

From the FT here by way of Threat Chaos:
A Beijing judge has ruled that an internet hosting company was wrong to close a prominent government critic’s website over illegal content, in the first case won by a victim of internet censorship in a Chinese court. Hu Xingdou, an economics professor who regularly discusses topics ranging from corruption to police brutality on his webpage, sued Beijing Xin Net in April after the hosting company sent him an e-mail saying the site contained “illegal” content and had been shut down.
In a verdict issued on May 20, the Daxing district court said the company had failed to provide proof for its claim and to prove that it asked Mr Hu to change the incriminated content before closing the site, as required in their contract.
As demanded by Mr Hu, the court ordered Xin Net to return the $201 fee he had paid for two years of services. The verdict did not discuss the issue of free speech.
The verdict raises the pressure on internet service providers as they get stuck between the authority of the censors and the law.
In China, various bodies including the Communist party’s propaganda department, the police and different ministries and other government institutions on all administrative levels monitor and censor online content. However, they rarely block websites or blogs themselves but rather make hosts do this for them. This is sometimes done through outright orders, and in other cases through self-censorship by internet companies.
Steinnon takes this opportunity to call on Yahoo! and Google to stop helping China censor its citizens. I don’t think the verdict will reach quite that far, but I also hope that the search providers will stop providing logfiles to Chinese authorities without first trying to contact its users. Yahoo! put one blogger in jail for 10 years by blindly cooperating with the Communist overlords there. See a previous article here where Microsoft shut down a blog. Rather than beat up high tech companies for kowtowing to the Chinese, I view their entrance into the Chinese market as something that will eventually help them win their freedom.
Like This Post? Rate it and tell your friends! Click the Share button below.
Intel Rockstars Make Geeks Swoon
May 28th
Behold this goofy video of an actor portraying Ajay Bhatt getting a cup of coffee and all of the geeky people at Intel swooning. I’m not sure why they couldn’t use the real Ajay. I’m guessing its because the actor had more hair. And how hilarious is it that the freeze-frame YouTube uses as the background image for the video shows a chick touching another woman’s breast? (Boobies!)
Like This Post? Rate it and tell your friends! Click the Share button below.
Hottest T-Shirt on Amazon
May 22nd
My wife made the very keen observation to me the other day while watching Cops on TV that everyone who wears a wolf T-Shirt or Sweatshirt is a complete moron, drug-addled simpleton or general loser. But judging by the glowing reviews at Amazon, this T-Shirt below bestows upon the wearer superhuman strength, irresistible charisma and charm and the ability to sexually arouse others!
And its no wonder it is so powerful a totem to its believers. Check out how its manufactured! From the forums discussing the shirt:
Three Wolf Moon (3WM) shirts are born in one day’s time. The cotton from our shirts is grown in the US and harvested by dragonflies who fly it south to be sewn in Mexico by the finest of craftswomyn zombies during Dia de los Muertos . The woven shirts are delivered to us saddled to the backs of Pegacorns (Unicorn-Pegasus Hybrids). After each shirt is hand dyed by monks using sixteenth century blackberry merlot (which gives the shirts their unique red-black tint) eagles come and whisk them into the sky, then fly them to the ocean and drag them through the waves giving each shirt it’s unique salt-mottled look. Drying while flying back to our tree top shop in South Western, NH they are dropped into the full moonlit woods.
Then the magic happens…. The forest goes silent and wolves from every corner of the earth descend at once in harmonious joy upon Mount Monadnock, NH. The magnificent Mother Moon brightens to the point of blinding any human that looks upon her and imprints herself on each shirt, next 3 wolves choose which shirt they wish to merge their likeness with. A deafening howling cacophony roar of wolves which would instantly kill any human caught in the sound waves occurs, after which the transference is complete. When dawn breaks we send the monks to collect the shirts one by one wrapping each in the shroud of turin blessing each with a turin kiss from Jesus. After which they are hand rolled in a U.S. Flag and set upon our shelves waiting to be ordered.
Thanks to the Technically Incorrect blog for finding this along with the awesome customer reviews.
Like This Post? Rate it and tell your friends! Click the Share button below.
IRS Doesn’t Shred Documents
May 21st
I usually write more about cyber security, but physical security has been in the new a bunch lately. Earlier this week a hard disk from the Clinton Administration walked out of the national archives. Now we find out that the contractors who carry away the trash from the IRS offices don’t bother to actually burn the sensitive tax return information or shred them. Anyone can fish this information out of the trash.

Brian Krebs has the story at the WaPo here:
The Internal Revenue Service has long advised consumers to shred old tax returns and other documents that contain sensitive data, as a way to thwart identity thieves who sometimes root through trash bins in search of identity information. But it seems the IRS doesn’t take its own advice: a recent investigation of more than a dozen IRS document disposal facilities found that — at each location — old taxpayer records were being tossed out in regular waste containers and dumpsters.
It also turns out that no one at the IRS knew who was actually in charge of the burn-bag operations nor did anyone at the IRS bother to do background checks on the contractors that drove off with the trash to make sure it was burned or shredded.
If you ever wonder how on earth the government ever manages to get things done properly, you can thank the Inspector’s General Offices at the agencies for keeping people in line with policies and regulations.
Like This Post? Rate it and tell your friends! Click the Share button below.
McAfee’s H*Commerce Web Series
May 21st
Yes, there is an underground business of buying and selling stolen credentials and identities. It is a huge business that really does wreck peoples’ lives and credit histories. But I’m not quite sure it is as scary as McAfee is making it out to be. This is the first video in a six-part series at their new site, StopHCommerce.Com. Kudos for raising awareness, but jeers on the parade of idiot victims, fear, uncertainty and doubt. Enjoy.
Like This Post? Rate it and tell your friends! Click the Share button below.
Someone Swiped a 1 TB Disk From Clinton White House Archives
May 20th
It has been reported that some dumbass working at the National Archives in College Park, MD left a 1 TB drive he was working on lying around and someone swiped it. The drive was from the Clinton White House and contained sensitive information, including social security numbers, operations procedures for the White House and probably a couple hundred gigs of porn of naked cheerleaders and interns.

From the AP here:
The National Archives lost a computer hard drive containing massive amounts of sensitive data from the Clinton administration, including Social Security numbers, addresses, and Secret Service and White House operating procedures. One of former Vice President Al Gore’s three daughters is among those whose Social Security numbers were on the drive. Other information includes logs of events, social gatherings and political records.
The FBI is conducting a criminal investigation of the matter. The drive is missing from the Archives facility in College Park, Md., a Washington suburb. The drive was lost between October 2008 and March 2009 and contained 1 terabyte of data. The hard drive was moved from a “secure” storage area to a workspace while it was in use. At least 100 badge-holders had access to the area where the hard drive was left unsecured.
Besides those with official access to sensitive material, janitors, visitors, interns and others passed through the area. Further, the workspace is in an area that Archives workers pass through on their way to the bathroom and the door often is left open for ventilation.
I got this story from FARK where the headline stated that construction was going on at the time, but this fact is not mentioned in the article. This could be insider information which could better explain the loss.
The drive is probably a collection of other drives, as 1 TB drives weren’t in wide use 10 years ago. Every federal facility records the social security numbers of official visitors, so that’s probably how Gore’s daughter’s PII ended up on the disk. And if it is a collection of other drives, then sure, operations information on secret service duty rosters and other operational information that may be sensitive or even classified might be on the disk. Also note that the door is “left open for ventilation?” Contrary to what you see on television, just about all government buildings are crappy, broken down places to work. Its no surprise to me that the AC would be broken.
Hey, maybe someone should check Sandy Berger’s pants. He is fond of stealing documents from the Clinton era. Michelle Malkin also suspects Berger is up to his old tricks.
Like This Post? Rate it and tell your friends! Click the Share button below.
The Lori Drew Sentence Delayed
May 18th
I had predicted that Lori Drew wouldn’t do a day in jail. This case was about lying to someone over email, and if the Federal Government wants to start prosecuting that, they need to build a whole lot of new jails.
But Lori Drew, aka, “the most hated person on the Internet” did use someone else’s profile on MySpace, which is a misdemeanor, and she was convicted of that. She was due to be sentenced today but the judge postponed the sentencing until July saying that he found the prosecution’s case “troublesome.” He may end up dismissing the entire case, possibly for jurisdictional reasons.

Megan Meiers, the 13 year old victim of cyber bullying
From the LATimes here:
When federal prosecutors in Los Angeles indicted a Missouri mother last year for committing an Internet hoax that apparently led to the suicide of a 13-year-old girl, they touted the novel legal approach that allowed them to file the case halfway across the country. On Monday, a U.S. district judge indicated they may have gone too far.
“Using this particular statute in this particular situation is so weird,” Judge George H. Wu said, calling some of the prosecution’s argument “troublesome.”
Wu’s comments came Monday afternoon at a hearing where Lori Drew, 50, was to have been sentenced. Wu delayed the sentencing until July, saying he wanted to consider a defense motion to dismiss the entire case.
At Monday’s hearing, Wu grilled Assistant U.S. Atty. Mark Krause at length about whether the government had prosecuted Drew under the appropriate laws when they accused her of unauthorized access in violation of MySpace’s “terms of service.”
“Is a misdemeanor committed by the conduct which is done every single day by millions and millions of people?” Wu asked. “If these people do read [the "terms of service"] and still say they’re 40 when they are 45, is that a misdemeanor?”
What Lori Drew did was despicable, and she is going to have to live with the horror she has visited on the Meier’s family for the remainder of her days. But prosecuting someone for a “terms of service” violation is preposterous and would set a dangerous precedent that could infringe on the freedom of speech of all Americans. Besides, didn’t Megan Meiers also violate the Terms of Service for being on MySpace when she was underage? I’m not blaming the victim, just pointing out that the violation Drew is charged under is inconsistent with this case.
Like This Post? Rate it and tell your friends! Click the Share button below.
Yeah, You CAN Judge a Book By Its Cover
May 13th
Check out Dennis Garthus. Just look at him. Seriously, you wouldn’t let this freak bag your groceries. If you were driving down the street and he stepped off the curb you probably wouldn’t stop. If he sat down next to you on the subway, you not only would switch seats, but you would probably try to switch cars.

His claim to fame is that he spent time in jail for molesting a 14 year old kid about 10 years ago. Now that he is out of jail after a short 7 year sentence, he was busted by the FBI for distributing kiddie porn featuring forcible rape of toddlers.
From WBBM here:
A 42-year-old southwest suburban man is jailed for possessing and sharing child pornography, some depicting children who appeared to be as young as 1 or 2.
An undercover FBI agent in February signed onto a file-sharing network on which users “befriend” each other in order to share files. The agent accessed the file folders for a user who went by the name of “Pantielover” and downloaded 53 files, some of which contained child pornography.
There were at least a half dozen images depicting sexual activity involving young girls between the ages of 2-8. In March, the agent shared some adult porn with “Pantielover,” who it was determined lived at 2620 E. Cass St. in Joliet. In return, he allegedly got more child porn from the user, including videos involving what appeared to be forced sexual contact with girls as young as 1 or 2.
Agents found there were multiple people at the Cass Street address, but a search of the state’s sex offender registry showed that one resident, Dennis Lee Garthus, was a registered sex offender.
If you are all googley-eyed, how do you know what kind of porn you are looking at? I suspect he got that way from spending too much time “spanking it.” Hey Illinois, this time don’t let this bastard back out on the streets, okay?
Like This Post? Rate it and tell your friends! Click the Share button below.



