14 Ocak 2013 Pazartesi

29c3 Hamburg / DE

The last week of 2012 marked the 29th installment of the Chaos Communication Congress. Organized by the Chaos Computer Club (CCC), the congress is an annual conference on technology and its impact on society. Although the scope may look quite loose, both lectures and workshops typically revolve around privacy, freedom of information, data security and other hacking issues. Needless to say, it has always been a great success; huge, considering that black-hat sized events here in Europe are not that common. Take, for instance, the fact that this year the congress had to be held in Hamburg, as Berlin could not offer a congress center fit enough to host more than 6000 attendees. Trust me, this number was not an exaggeration at all!

Congress Center Hamburg by night. Congress Center Hamburg by night.

I admit my expectations were quite high: after four long years of scientific symposia going back to more technical venues was indeed putting my brain in hunger-mode. However, having experienced what it means organizing events for medium sized scientific conferences, I was honestly puzzled about turning a huge building such as the Congress Center of Hamburg in a functional place ready to host lectures, workshops, and hack spaces. Boy I was wrong to be worried about it. The event lasted 4 whole days (from the 27th to the 30th) with an impeccable organization: not only were all lectures and workshops flawlessly organized, streamed, and chaired; but also all open spaces were collectivized and used for all kind of hacking purposes, from playing CTF to entry-level courses on the Arduino platform.

The speakers on the other hand could take advantage of extremely well-sized rooms, with the most important talks having available an auditorium able to host more than 2000 people. Nevertheless, I have to say I was forced to learn one thing pretty fast: if you are interested in a topic, and that topic happens to be quite a hot one, well, be ready to get to the room at least 15 minutes before show-time; seriously, being on time never worked; any room, regardless of the capacity, was liable to get full. Believe me, I was really thankful for the flawless streaming infrastructure (watching a talk on my laptop that was taking place just few meters away was indeed paradoxical :) ).

Jacob Appelbaum on stage. Jacob Appelbaum on stage.

The first day's line up was respectable. The keynote was given by Jacob Appelbaum, known for his contributions to "The Tor Project", and also former spokesperson for WikiLeaks. After the usual introductions, he explained the reasons of this year's congress' zeitgeist "Not My Department". We all have heard this sentence at least once in our lives; usually uttered to belittle other people's arguments, it has always been used as an example of a closed mindset at work. Jacob's point was that this attitude is even more detrimental in an inter-connected world. What is the use of a privacy-preserving bill if our data flows through the routers of oppressive governments potentially assembling huge data sets about our lives? A new level of awareness is therefore suggested.

nod32 full indir nod32 full download full nod32 download est nod32 serial

Using TS RemoteApp as an attack vector

So in today's session at SMBNation that I spoke at, I showed how to use TS RemoteApp with TS Gateway on SBS2008 to deliver remote applications through Remote Web Workplace. It is one of the most cool features in the Windows Server 2008 operating system. But we have to remember what its doing.

Part of the conversation we had was on the difference between local desktop display in TS RemoteApp vs just having a full desktop to the Terminal Server. One issue that came up was that as a RemoteApp, you can't run other applications.

Well, that is not actually true. If you think that, then a TS RemoteApp has the ability to be an attack vector for you. What do I mean? Well below is a screen shot of what happens if you hit CTRL-ALT-ENTER with the cursor focused on the RemoteApp window (in this case MS Paint running remotely):

At this point, you can run Task Manager.... then hit File->Run and run something else. In my case, I showed a few people afterwards how to start cmd and start exploring the network. Now, you will only have the privileges of the user account logged in as, but it is still something you have to be careful about. If you think a RemoteApp bundle prevents access to other application sor the network... you are wrong.

So is this bad? No. Is it really an attack vector? No. You just need to understand that when allowing ANY type of Terminal Services based access, you have to restrict the policies and access accordingly. No matter if its local or remote. Running a TS RemoteApp bundle of Office will display on the local desktop, but is STILL running on the Terminal Server. So it will be browsing the network the Terminal Server is connected to as the local net. It will also browse your own drives mapped via tsclient. So you have to remember that.

Hope thats useful. A TS RemoteApp bundle does NOT mean you won't have access to the TS desktop when displaying remotely on your personal desktop. And that's not a bad thing. TS Remote App is a convenient way to extend the workspace to your local machine, anywhere in the world. No pun intended. That's its power... and the benefit. Great remote productivity enhancement in Windows Server 2008. Use it. (Safely of course)

full nod32 download est nod32 serial 64 bit nod32 esed nod32 4

Celebrate Packt Publishing's 1000th Title

nod32 guncel key eset nod32 guncel key eset nod32 güncel key indir com nod32

Aaron Swartz, charged with hacking MIT archive system, commits suicide

http://en.wikipedia.org/wiki/Aaron_Swartz

Web entrepreneur and political activist Aaron Swartz, who made headlines in 2011 when he was charged with hacking into MIT?s network and mass downloading millions of documents from a subscription-based archive, took his life in Brooklyn Friday, according to a statement from his family and partner.

Swartz, 26, hanged himself in his Brooklyn apartment Friday, according to the statement and the New York Medical �Examiner?s Office.

full nod32 download est nod32 serial 64 bit nod32

Trojan-Dropper:OSX/Revir.C

Trojan-Dropper:OSX/Revir.C silently drops other malicious programs onto the machine; on execution, Revir.C displays a titillating image to distract the user from the program's malicious activities.

nod32 turkce nod32 full indir nod32 full download full nod32 download

TCS adds clients to beat profit forecast

Logos of TCS are displayed at the venue of the annual general meeting of the software services provider in MumbaiMUMBAI/BANGALORE (Reuters) - Tata Consultancy Services Ltd, India's No.1 software services exporter, topped expectations with a 23 percent rise in quarterly profit and reiterated it should beat a closely watched industry growth forecast. India's $100 billion IT services sector is under pressure to sustain growth as clients in key markets, including Europe and the United States, have been keeping a tight grip on tech spending because of global economic uncertainty. ...


nod32 key esed nod32 download nod32 serialleri esed nod32 indir

CA issues first-in-U.S. mobile privacy guidelines

California continues to toughen its stance on mobile privacy as the state's attorney general issues privacy protection guidance.

nod32 güncel key nod32 guncel key eset nod32 guncel key eset nod32 güncel key