Friday, August 19, 2011

JadedSecurity DailyDDoSe™ TargetED @ELyssaD™ 6:59am

JadedSecurity

jadedsecurity.net | Jul 6th 2011

It appears that this may be a homepage or an index page with non-article content. To accurately view it, you may want to switch to the Full Web Page view.

If you know there should be an article here, help improve the article parser by reporting this page. Thanks!

Much Ado about nothing but Information Security

MP3

JADED EXPOSURE PODCAST TOPICS
JULY 06, 2011      #1 LIGATT just tweeted he is going to hack someone tonightLooking into if his account was hacked again…

#2 FOX NEWS
#3 Lulzsec interview
#4 SKYPE & MICROSOFT & FACEBOOK
#5 ABHAXAS
#6 Sam Bowne   (tool bag)

RANT

ISC2

CASEY ANTHONY IS A BIATCH AND NOBODY CARES ABOUT THE WHORE

Tweet

My password is “password” plus the year I’m safe right? Why no Timmy, no you are not. While passwords are just a small piece of what we need to know about access controls, they are sort of important. Passwords and PINs are the utmost basic access controls. Every modern operating system has the capability to enforce strong passwords.

A strong password is at least 15 characters long consists of at least three of the following:

  • Upper Case
  • Lower Case
  • Number
  • Special Character

While ISC2 will want you to learn things like information entropy and formulas that include some random base 10 calculations, you only need to know the following things in the real world. Passwords, using current hashing methods are becoming more and more easily cracked due to Graphic Processors; people much smarter than I (@purehate_ ) have developed methods to crack SHA1 hashed passwords at ridiculous speeds. According to his site  can crack a password up to 7 characters using all 95 characters on a keyboard (a total of 69,833,729,609,375 trillion matches) in around 4 days.  about 10-12 hours according to @purehate_

So how do we protect ourselves? Enforce passwords that are at the very least 15 characters. The 8 characters that were once thought of as “best practices” followed the LanMan Hash mechanism that only required the cracking of the first 7 characters. This was years ago and irrelevant by any means. Password attacks are the very common and getting more and more prevalent considering all the hashes being pasted to Pastebin these days.

A dedicated attacker will not scour pastebin to get your password, although “inurl: password” used to be a common attack vector J. More common amongst the dedicated attacker is getting as much background information as possible on his or her target. Humans are for the most part predictable, and as an attacker builds the dossier on their target they also build a customized dictionary that can be very successful for password guessing. People tend to use things that are easy to remember such as:

  • Kids names
  • Spouse names
  • Birthdays
  • Anniversaries
  • Favorite Teams
  • Home towns
  • Etc.

When I go on physical pen tests, I typically look around the office for things would be easy for me to remember as a user. You’d be surprised how successful that has been.

So how do we block password based attacks? Simple; Implement lockout procedures, require strong passwords (15 characters+), train your users on the importance of picking passwords that are random. I’d like to say use one time passwords or dual factor authentication, but we all know usability always trumps security. Also, since your development staff sucks at preventing SQL injections, you might want to not just hash your passwords but use state encryption as well.

Strong Authentication Mechanisms should be two-factor:

  • Something you have (Smart Card, Key Fob)
  • Something you know (Password, Pin)
  • Something you are (Fingerprint, Retina, Signature) I’m not going to go into any of the privacy concerns associated with this one)

Now that we have covered passwords, lets discuss Access Controls. Access controls come in multiple forms.

  • Physical (Security Guards, Cameras, Card Readers, Locks, etc.)
  • Technical (Firewalls, Roles, ACLS, DMZs, etc.)
  • Administrative (Policy, “Honor System”)

Most organizations do not include physical security as part of their information security program. As security professionals we know that attackers, don’t care how they get in. Your Internet posture may be bulletproof, but how does that help if your front door is wide open?  Why put a lock on the door, if you have a hung ceiling above it? Attackers think outside the box and so must you.

A skilled cat burglar will first case the place before they try to break in. Take a walk through your lobby entrance and look at it as an outsider what do you see? The typical setup is a camera, a locked door, card reader, maybe an alarm panel and if they were really diligent a motion detector. What good are these if you can just climb over the wall? Or better yet cut through the drywall? Get where am I’m going? Lock picking is a hobby most of us hold, so unlocking a door is easy.

When you design your physical controls, keep that in mind. Shared areas should be blocked off with concrete. Do not use Drywall or penetrable materials. The casual adversary doesn’t care if he is caught. The dedicated attacker does not want to be detected. Cameras are great at detection, but if no one is actively watching them that is all that they are detective controls. A Camera with a blind spot can be easily circumvented, as such should never be in a shared area. Anyone can use a blind spot to their advantage and create an obstructed view.

RFID cards for physical access have become more of a security through obscurity mechanism. Card Reader/Writers are extensively available for purchase and the old bump and steal will pretty much get you through the door. Forget the movies, this is real life and these technologies exist and are in use by attackers. Physical access controls should take on the same authentication mechanisms that we use in the logical world. Two Factor authentications should be used for all physical access methods. This is essentially the only way to ensure that the casual attacker stays out of the front door.

Access controls are a broad subject, so I will be breaking this up into subsections. The next section will address Logical controls.

Tweet

“We Wish @JoeBiden the best of luck as our new President of the United States. In such a time of madness, there is light at the end of the tunnel”

You gotta love the internets, @foxnewspolitics twitter account has been compromised and news of Obamas Death circulates. This isn’t the first time someone has been pronounced dead on Twitter and it has gone viral. Late last year Bill Cosby died twice apparently. It seems funny to me, that minutes after the Twitter account claims that “They have regained control”, the news hits.  While this is all fun and games to the #AntiSec operation, this directly speaks to my point. Fox News is a huge conglomerate with a lot at stake. This is the type of attack that should of been considered as part of their threat model, and somehow it went overlooked.

This is a huge problem, when it comes to social media and the whole concept of Information Risk Management. If you are a media firm, you must damn well include a threat model that revolves around a compromise to your reputation. Can Fox ever be taken seriously again as a media outlet? Will you believe that the world has just ended if you read it on their twitter stream?

I could just bet that this account has a shared password, that has been written down so many times that all probably know it at this point. Would a media conglomerate consider Twitter a critical function? Twitter is a public service, that does not assure any of the things we have come to expect from critical functions. We trust a third party with what essentially could be our livelihood, depending on our industry. Maybe, Fox should revisit their Risk Management Process. Just a thought.

Thanks to @brew_ninja for pointing this out, it shows up on their webpage. 

Tweet

Update: 1:00AM

Not too sure, what this is.. Looks like some credit Card numbers too me… Someone should of bought him some beer.. Pastebin

So for anyone who thought that the voting machines in Florida aren’t rigged, well you were wrong. @Abhaxas has just posted a pastebindetailing the accounts and much much more .

Follow me @Abhaxas

So, this is a little ironic. Here is inside details of florida voting systems. Now.. who still believes voting isn’t rigged? If the United States Government can’t even keep their ballot systems secure, why trust them at all? FAIL!

##############
# voterstats #
##############

####################
# pollworker_users #
####################

##################
# pollworker_log #
##################

####################
# pollworker_links #
####################

#########
# races #
#########

#############
# elections #
#############

##############
# candidates #
##############

Tweet

In order to celebrate Google Search results linking JadedSecurity to ISC2, I figured we must celebrate

How do we celebrate at JadedSecurity??? Well we shout out to our friends! ISC2, Proudly killing kittens since 1988

Tweet

Hey we have SSL we are good! Uhm No you are not. Network basics for “security guys”

If you have been following me, you might notice I tend to use “ACK” a lot when I respond. If you don’t know what this is, then we have a lot to learn. The CISSP study guide focuses on the OSI model, as they should for foundation. I’m just going to go over the basics that I feel every security professional must know. I suggest you go out and read Wileys Understanding TCP/IP  & Gene Spaffords Building Internet Firewalls. The books are fairly old, but will teach you all you need to know about networking for our profession with the exception of IPV6 (I’m still learning).

With that said, why do we need to know networking as Security Professionals? Well, if you don’t understand how systems talk to each other, how can you do the whole GRC thing? You won’t be able to inject security into the SDLC, nor will you be able to identify fluff. While I firmly agree that the term “IT Security” must go away, I also believe you must have a deep understanding of technology to be security professional.

Let’s start with the very basics…

Layer 1. The Physical Layer

The physical connection is one commonly overlooked when designing security. I don’t need to go into Cat5/6, Fiber, Coax, etc. to a great length, but you do need to understand the differences. Virtualization, has added additional complexity, as now some feel comfortable using a single ESX Server and traversing networks of different security levels. In the past this was unheard of, as all it took was an overworked IT guy who moves a cable and now your core was exposed. Fun stuff The security professional needs to be aware of the risks associated with each physical medium. The easiest and cheapest to physically attack is Cat6, there are several devices available that allow you to splice the connection while keeping it active. Keep in mind that any unencrypted traffic can be picked up on the wire with this attack.

You need to ensure that physical connections are limited to known nodes. You can have a bulletproof firewall, but a physical drop in a shared area can be an attackers best friend. I have conducted several pen tests, where the client was so sure they couldn’t be breached because they didn’t have an Internet presence.  The way in was almost always the same. A network drop in a shared area is extremely common. You will have card readers, cameras and telephone drops. A small autosensing dumb hub is an easy quick solution. In most cases Port Security will not be enabled, and with any luck you will be plugged directly into the core. Start your discovery here…

How do we protect against this you ask??? Use dedicated VLANs for your physical security. A VLAN will is layer 2 technology which provides a separate collision domain. What this means is, an attacker will only be able to sniff the traffic on the segment that he has plugged into. Additionally you need to ensure that systems on that network are not allowed to initiate connections. The attacker could potentially initiate a layer 2 attack to capture credentials, however that would end up in a race condition so more than likely might fail.

Layer 2 The Data Link Layer

This layer focuses on the delivery of frames between devices in the same collision domain. It doesn’t provide any routing functionality, but what it does do it maps the MAC address of the device to the port, which it is plugged in to. Hubs run on Layer 1 as they send packets to every system that will listen for it, switches run on layer 2. They provide the store and forward functionality. Packets are only sent to the port that the switch has mapped the end device too. When you try to establish an outgoing connection, the first thing your system does is send and ARP request to every port asking if this machine is on the local network, if it is not the packets are forwarded onto the gateway address which the system will also request.

Layer 2 provides the functionality to logically separate network segments by creating VLANS. A VLAN allows you to segregate by floor, function, etc. It creates a separate collision domain, which in the old days provided a false sense of security against eavesdropping of data. Don’t get me wrong, VLANS are our friends, but use them wisely not just because they are cool. Combined with Layer 4 ACLS, you can at least potentially weed out the casual attacker.

The Demilitarized zone (DMZ) you keep hearing about, is just a VLAN that is hopefully separated by a layer 4 device and not just an access list. DMZs come in all forms, but the most common is an Internet Services DMZ (web servers, mail servers, dns, etc) and a Partner DMZ (Market Data, Vendors, partners, etc.) Don’t broadcast routing to these guys. Make sure that you don’t allow funky connections initiating from these segments.. just saying

Multicast is another fun layer two protocol you should be aware off. It pretty much forwards packets to every port. Market data applications typically use multicast to reduce latency. You could just plug in and listen Fun Fact.. some older IP CCTV implementations will broadcast to pretty much anyone listening. UPnP is a form of a layer 2 protocol.

Old school security guys still are of the mindset that “hey you can’t sniff our network, we run a switched environment”.  That is a sad delusion for anyone that still believes this is the case. An attacker can start an ARP spoof attack where his node will start flooding the segment with ARP Response packets claiming to be the gateway. Now whenever a node requests the gateway address, before the legitimate gateway has a chance to respond, it will have already received the forged response.  Now all the attacker has to do is forward your packets on their merry way to the final destination and you’d have no idea. A malicious attacker can make things even more fun for you by not forwarding packets. Can you say DoS? You need to ensure you use strong encryption, and keep in mind that SSL is not the end all be all. Your users are stupid, and will not always be cognizant of the fact that the little lock is broken.

How do we protect ourselves??? You can implement a Network access control solution, which authenticates nodes prior to letting them on to the network. This will deter a casual attacker, however it is false hope if you bridge your VOIP phones to the same port as the machine. In most instances the VOIP devices are added to the bypass list. You should use a layered security model. Port Security should be enabled; IDS Response rules should trigger a port shutdown on multiple ARP responses past a certain threshold.

Are you seeing yet how attackers think?? The CISSP will not teach you to think outside the box.

Layer3 The Network Layer

Now we get into some of the Sexy I had talked about earlier.  Routing is handled by this sexy layer, it answers the How do the hell do I get there question. IP, RIP, BGP, ICMP, IGMP and more run at this layer.

IP is connectionless, it doesn’t care if you packet got to it’s final destination, it just tells it how to get there, and sometimes it throws a big “You can’t get there from here” (also known as FU No in technical terms).  The biggest threats against these protocols in the past have been the ability to inject false routing information thereby allowing data leakage or Denial of service. I’m not going to get into each one of these, as this is not a network tutorial. All I will say is FUCK RIP! RIP is the easiest routing protocol to implement as it pretty much just broadcasts its routes all over the place. The latest version has authentication built, but sadly it can still be breached.  Some organizations still like to do the whole static route thing, however this leads to administrative nightmares.

Network address translation (NAT) also happens at Layer 3. NAT is the process of mapping one IP address to another. I would hope that most organizations use private address schemes, but I know better. You implement NAT as a way to allow your internal addresses to access public networks. This is where you can be of help and kill the 10 class C’s your boss bought for absolutely no reason back in the day. Most companies do not need that many external connections.

Finally most encryption happens at higher layers, while IPSec runs at Layer 3. It essentially tunnels all of the above layers through an encrypted channel established at layer 3.

Security professionals tasked with looking at options to mitigate the whole DDoS thing should know that BGP is the NEW black. What it essentially does is provide a route to your systems using multiple ISPs as opposed to load balancing with round robin DNS records. Of course, you should also build load balancing into your infrastructure, but we’ll talk about that later

Threats??  IP Spoofing is always fun. Also, attackers are really crafty at using ICMP to tunnel traffic. Most organizations allow ICMP for testing connectivity, attackers love to use ICMP to map out your network and locate active filtering devices. You can make their lives more difficult by turning it off.

Layer4 The Transport Layer

Does Port 23 sound fun to you??? Do you get excited when 3128 responds? You do? Then you will know what I’m rambling about. TCP and UDP both run on the transport protocol. They map services to sockets.

Ports 1-1024 are privileged and used by known applications. IANA keeps a list of all registered port numbers, but keep in mind with root access you can run anything you want on any port. TCP provides a connection-oriented experience, which guarantees that the recipient will always receive the message based on acknowledgment of receipt.

A Three-way handshake is how a connection is established. You send a SYN(hello you there) to a destination port, the end node responds with an SYN/ACK from a random source port(Yeh, I’m here what do you want), and then the ACK (ok let’s chat). It is a connection oriented, so you can set up most firewalls (outside of the pix) to only allow outbound, without requiring a return rule. The firewall knows that the SYN is waiting for a response and listens for a response from a random source port.

TCP and UDP both have sequence numbers in the header. Attacks against TCP have included sequence injection where an attacker sitting on the wire can take over the connection by sending an Reset packet to the originating source. TCP hijacking has been around for years, and for clear text protocols is still valid.  USE STRONG ENCRYPTION at lower layers!

In order to bypass certain IDS implementations, an attacker as part of his network mapping activities will typically initiate a SYN scan which will leave the connection half open. This isn’t as reliable as a full scan, but it can cover the whole 65K ports fairly quickly and provide a refined target port list for later.  Our world essentially revolves around Layer 4. Learn everything about it!  You will find that most firewalls operate at Layer 4. This is tons of fun for your average attacker, because once he exploits a vulnerability in an exposed system, he can use the connection to traverse your protected segments. If layer 7 filtering is not feasible than implement proxy solution. Your proxies should be configured to rewrite, not ROUTE! Remember the difference, you don’t want any direct connections in or out of a private segment.

Disable services that you don’t use… Period. A listening socket is a open path. Don’t be dumb. Men in the middle attacks are commonplace these days. Connection hijacking is all the rage. SSL will not protect you from this.

I’m going to go over layers 5-7 later, as I think they should be covered more in depth within the Application Security piece.  (Part 4 maybe)..

If you enjoyed this stay tuned for more.. All I ask if you can buy a shirt (still looking for sponsors as well) and please submit

“What The CISSP won’t teach you, by JadedSecurity” for CPEs

So where does Lulz fit into this picture???? Huh ISC2?

Tweet

ISC2 outlines information security within their “10 domains of the (ISC)² CISSP CBK®

  1. Access Control
  2. Application Security
  3. Business Continuity and Disaster Recovery Planning
  4. Cryptography
  5. Information Security and Risk Management
  6. Legal, Regulations, Compliance and Investigations
  7. Operations Security
  8. Physical (Environmental) Security
  9. Security Architecture and Design
  10. Telecommunications and Network Security

While the 10 domains are interesting in theory, they only cover information security in the pie in the sky context. I have been receiving numerous questions on how do I break into information security, without the CISSP. ISC2 has had a very successful marketing campaign, which has had over a decade to saturate the industry. As such, unfortunately you probably will have to take the exam, for now anyway.

This series will focus on what I believe you need to know as an information security professional starting with the basics. We will eventually get to “sexy”, but for now we need to get back to basics. The key to being a successful security professional is the ability to think outside the box. The most successful law enforcement officials were once the most successful juvenile offenders. Why is that so??? Well, they think like the bad guys…  Taking an exam, regardless who is offering the accreditation will never teach you how to change your mindset. That is something at least I believe is a combination of nature and nurturing.

With that said, what the hell is this security thing? Why do we do it? What are we trying to accomplish? If you can’t answer that, then all the book knowledge in the world isn’t going to help you. Every organization will be different, there is no one size fits all solution.  You need to be able to understand every aspect of your business. How do we do that? Information Security will always be an uphill battle. You are embarking on a career that will have very unique challenges. You need to be able to come to a realization that there is no such thing as 100% secure. This is a myth…

So lets talk security. What do I need to know? How do I break into the field? Well little Johnny, you must have a passion for it first. Yes, the field is lucrative and it will not be going away anytime soon, but if you don’t have a thirst for knowledge you wont be successful.  Information security unlike other industries does not sleep; I personally spend 3+ hours a day just learning what I can. Technology, regulations and attack methods change every day. If you don’t stay ahead of it, you will end up with pie on your face when you get hit with the latest “New Thing”

The CBK looks at everything from passwords to my pipe, I mean dry pipe. My exam was 80% BCP & DR, so needless to say if you don’t pass the exam more than likely you are too technical for it. The problem is they want you to learn concepts that are almost defunct in some ways. If you just want to pass the test and not learn about security than go buy the latest Shon Harris book and call it a day. If you want to learn how to be an effective security professional, keep up with this series. I promise it will not disappoint.

Step #1 What the are we trying to accomplish?

Every organization has assets that are critical to their business. This will be different in every industry from the mom & pop bodega to the fortune 100. In order to establish your security plan, you need to perform some type of asset valuation. There are tons of formulas available, but unless you understand what your business does you won’t get any practical results.

Assets come in two forms:

  • Tangible – Hardware, software, facilities, etc…  Easy to valuate
  • Intangible – Intellectual property, client data, employee information, strategy plans, books & records and much much more…

How do you value the intangibles??? And that is where the whole qualitative/quantitative blah blah formulas kick in.. They are useless for the most part. The business can assign values based on what-if scenarios. An example where an intangible asset could be valued properly would be if a client record was exposed you would If we lose 1 piece of client day we could be fined X. Ok. So we know we have to spend at least X-(enter profit margin here) to protect this piece of data. What about our reputation? Can we put a number on that? NO. There are some way out formulas that claim you can use historic analysis. The problem is most companies do not share reputational impact. It isn’t in their interest to release any of that information. You can damn well bet that they do some type of analysis on bottom line impact, but even that would have to be based on statistical analysis which isn’t possible. Sounds confusing don’t it?

Ok.  We lose 1 client record on June 1st. We are fined $100 dollars. We know last year our stock price was $1, we made .10eps in the 2nd quarter last year. If this year we make .08 or even .11eps, there is no way to link the 2. It just isn’t possible. So regardless of everything the book says, your main goal is to limit your reputational risk.  Keep the pie off your face. How do we accomplish that? This is what I will go through during the rest of this series.

In the mean time, on your way to that security profession, pick up a book on networking. The next episode will focus on what you need to know at Layer 1. We’ll get to Sexy.. Stay tuned.

Tweet

Update: 8:01pm EST @UBerleaks hits PBS yet again PasteBin

Hacked website http://www.wyomingpbs.org/ http://www.PBS.org Date: 6/25/2011 I’ll miss you Lulzsec
mailinglist     program member  email   zipcode city_state      address name

I get the fact that some organizations are behind the times in security. @LulzSec, Anonymous and all of the members of #AntiSec have been demonstrating the lack of security in some of these organizations. I just want to say, Really PBS? WTF is wrong with you? You already had a major incident a few days ago, and SQLi isn’t something that requires a shit load of work remedying on your part.

A new name has popped up in the name of #AntiSec , and it is @Abhaxas.

To date he had said that he found 9 SQLi vulnerabilities of which he had tweeted 3 within the PBS Realm.

The latest is against http://www.azpbs.org/ with supposedly 30K 300K records,which are currently being dumped. The following comes from the PasteBin posting

@Abhaxas
This one will take a while to dump guys..

http://www.azpbs.org/

Table = “members”
“email”,”varchar(100)”
“phone”,”varchar(13)”
“state”,”varchar(2)”
“city”,”varchar(50)”
“address”,”varchar(255)”
“mailingName”,”varchar(255)”
“lastName”,”varchar(50)”
“firstName”,”varchar(50)”
“src”,”int(11)”
“status”,”varchar(1)”
“nameNum”,”int(11)”
“memberNum”,”int(11)”
“id”,”int(10) unsigned”

fetching entries for table ‘members’ on database ‘azpbs_org’
the SQL query used returns 298639 entries

In an leak today he had released almost 400 records, asking PBS to “Fix your Shit”.

Hey PBS, fix your shit. What security?
Follow me @Abhaxas

address,city_state,email,mailinglist,member,name,program,zipcode

While not associated with LulzSec, he uses lulz in jest while calling out PBS in an earlier Tweet to them

He had posted the following to PasteBin earlier today

Here’s some lulz.. PBS doesn’t like these words
Follow me @Abhaxas

id,word
“21″,”Butt”
“74″,”Knuckle draggin”
“91″,”Peckerwood”
“184″,”fuck”
“103″,”Ream”
“63″,”Hillbilly”
“100″,”Putz”
“93″,”Piss”
“72″,”Jungle bunny”
“34″,”Cunt”
“135″,”White trash”
“125″,”Swirl”
Continued.

Tweet

In my search for a replacement to the battery killing powers of TweetDeck, I had stumbled upon this article by Tech Radar titled “17 Best Twitter Apps for 2011”. I thought I might as well go through the motions and test them out. As most of you know from reading the site, I am kind of anal when it comes to security. So when an application requires access to “all of the data on websites I visit”, I tend to get curious.

I’m not a developer, but from my perspective the Twitter API seems pretty straightforward in terms of implementation. It should not require any type of access to any data outside of twitter.com. It should be able to authenticate my account and allow me to read and post over standard SSL transport.  I should be able to install it as a sandboxed application, so what is wrong with this picture?

“permissions”: [   "tabs",    "http://*/*",    "https://*/*" ],

Huh?? WTF??? Really? The developer in question (which I’ll get to in a second) put’s out the following rationale
“There’s nothing to worry about in this fact. Silver Bird is committed to never grab any personal information from you. It doesn’t even have access to your Twitter’s password. All these permissions are only required because it’s the only way to implement all these cool features.”

We know you don’t have access to the Twitter password, because the API handles the authentication. I don’t need any of your “Cool” features.

With that said let’s take a look at the OSX and browser based applications listed in the Tech Radar Piece.

#1 SilverBird Chrome Extension

Fun Security Fact= See the Example above.. That’s the permission you give them when installing the extension. They invite you to review the source code, but at this point I’d be done. Next

#2. DestroyTwitter (Windows, OS X, Linux) – Free

Fun Security Fact= Built on Adobe Air.  Although it stores the password is some form of hash It saves a lot of cool things for Forensic purposes in a file called.. Anybody?? databases.db

#3 Mixero (Windows, OS X, Linux) – Free

Fun Security Fact= Well it’s built on Adobe Air, Oh wait, they have this cool disclaimer on installation..  Publisher:Unknown System Access:unrestricted. You go ahead and install

#4 BufferApp (OSX/FireFox Extension) Free with some paid services. “Be Awesome on Twitter, whatever)

Fun Security Fact= Requires sign on and authorization on twitter to use the web application prior to allowing you to install the extension.  Same Excessive permissions as SilverBird. Next.

#5 Echofon

Interesting EULA (Which it doesn’t let you copy): We can install whatever software we want within our application. Hmm


Transmission information: Hmm they don’t have to notify you if they transmit data to a third party. Ok.. Wait, “and other Twitter information needed to provide you the Service” I’m not a lawyer nor do pretend to be one on TV, but I have done of share of contract reviews. Password will be considered in this context.

It’s a native OSX application, No customization bleh

Fun Security Fact= Requires authorization on twitter to use the web application prior to allowing use. Make sure to enable SSL under preferences advanced.  Make sure to have full disk encryption on because all private messages are stored as .sql  in /Users/sureI’llTellyou/Library/Application Support/Echofon

#6 TweetDeck

Chrome: These guys actually kind of did it right. Unfortunately they do want to read all of your social media sites. The Extension automatically uses SSL

tcp4       0      0  xxx.xxx.xxx.xxx.53122    199.59.148.139.443     ESTABLISHED

AdobeAir: Also by default uses SSL
Fun Security Fact= Stores Auth in Keychain, requests access. Data seems to be held encrypted in /Users/sureI’llTellyou/Library/Application Support/Adobe/Air/ELS/Tweetdeck*

#7 Seesmic

Fun Security Facts=
Web: Seems to just be just a web front end over SSL. Requires you to authorize the app on Twitter.com

Silverlight: Well first problem is it’s based on Silverlight J  Runs in it’s own container without an installation. Uses SSL for Transport. Requires Twitter Autorization

Configurations are in /Users/yeah0k/Library/Application Support/Microsoft/Silverlight username is in the clear, but can’t find any tweets

#8 Twitterific

Fun Security Fact: Saves account info a .plist file /Users/blahblah/Library/Application Support/Twitterrific also keeps private messages in clear within a .db file within the same directory.  Uses SSL by default for Transport

So these are the main applications. So far, I kind of like twitter Chrome extension. Will use it for a few days to see if I don’t end up hating it. Now what will you install, based on the above?

Tweet Tweet
  • Support The Site

Original Page: https://jadedsecurity.net/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

No comments:

Post a Comment