<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2408579978663158415</id><updated>2011-11-27T17:17:56.729-06:00</updated><category term='unam-cert'/><category term='pharming'/><category term='&quot;privacy&quot; &quot;social networks&quot;'/><category term='off-topic'/><category term='pharming security'/><category term='security'/><category term='humor'/><title type='text'>Eduardo Espina's blog</title><subtitle type='html'>Blog about computer security related stuff. 
Keywords: UNAM-CERT, computer security, Mexico.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>35</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-8992475703174000638</id><published>2009-11-16T13:33:00.001-06:00</published><updated>2009-11-16T13:34:26.433-06:00</updated><title type='text'>Día Internacional de la Seguridad en Cómputo</title><content type='html'>El DISC 2009 México será celebrado el 30 de noviembre de 2009 teniendo como sede el Instituto de Investigaciones en Materiales, localizado dentro de las instalaciones de Ciudad Universitaria.&lt;br /&gt;&lt;br /&gt;El DISC es el Día Internacional de la Seguridad en Cómputo. Es una celebración convocada por la Association for Computing Machinery (ACM) en el año de 1988 con el propósito de incrementar el nivel de conciencia en relación a los problemas de la seguridad en cómputo. Con el paso de los años ha ido aumentando a nivel mundial el interés por este día. El Departamento de Seguridad en Cómputo/UNAM-CERT de la Dirección General de Servicios de Cómputo Académico es el organismo oficial en México encargado de celebrar el DISC desde 1994.&lt;br /&gt;&lt;br /&gt;En esta emisión, el tema principal del DISC será "La primera defensa eres tú".&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.disc.unam.mx/2009/"&gt;Link&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-8992475703174000638?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/8992475703174000638/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=8992475703174000638' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/8992475703174000638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/8992475703174000638'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2009/11/dia-internacional-de-la-seguridad-en.html' title='Día Internacional de la Seguridad en Cómputo'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-9001243452651813255</id><published>2009-11-16T13:22:00.001-06:00</published><updated>2009-11-16T13:24:50.350-06:00</updated><title type='text'>CAPTCHA Security: A Case Study</title><content type='html'>"CAPTCHAs have been widely used across the Internet to defend against undesirable or malicious bot programs. In this article, the authors describe the security of a CAPTCHA reported in a recent peer-reviewed paper and deployed on the Internet. They show that although this scheme was effectively resistant to one of the best optical character recognition programs on the market, they could break it with a success rate of higher than 90 percent by using a simple but novel attack. In contrast to early work that relied on sophisticated computer vision or machine learning algorithms, they used simple pattern recognition algorithms that exploited fatal design errors. The main contribution of their work is that simply counting the pixels in a CAPTCHA's characters can be a very powerful attack."&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.computer.org/portal/web/csdl/magazines/security#4"&gt;Link to e-article.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-9001243452651813255?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/9001243452651813255/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=9001243452651813255' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/9001243452651813255'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/9001243452651813255'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2009/11/captcha-security-case-study.html' title='CAPTCHA Security: A Case Study'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-4540156768875205861</id><published>2009-10-23T13:55:00.000-05:00</published><updated>2009-10-23T13:56:29.331-05:00</updated><title type='text'>H D Moore sells Metasploit</title><content type='html'>H D Moore sells Metasploit: &lt;a href="http://www.metasploit.com"&gt;http://www.metasploit.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-4540156768875205861?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/4540156768875205861/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=4540156768875205861' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/4540156768875205861'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/4540156768875205861'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2009/10/h-d-moore-sells-metasploit.html' title='H D Moore sells Metasploit'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-8553644486943116002</id><published>2009-10-16T17:42:00.001-05:00</published><updated>2009-10-16T17:42:56.060-05:00</updated><title type='text'>Evolt</title><content type='html'>One of the founding members of evolt.org, Adrian Roselli, has provided the archive as well as its support through his company, Algonquin Studios.&lt;br /&gt;Lots of &lt;a href="http://browsers.evolt.org"&gt;legacy browsers&lt;/a&gt;...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-8553644486943116002?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/8553644486943116002/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=8553644486943116002' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/8553644486943116002'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/8553644486943116002'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2009/10/evolt.html' title='Evolt'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-5911344776638166744</id><published>2009-08-19T22:29:00.000-05:00</published><updated>2009-08-19T22:30:06.928-05:00</updated><title type='text'>Seminario de seguridad en la UNAM</title><content type='html'>La Facultad de Ingeniería a través de la División de Ingeniería Eléctrica hace una atenta invitación a:&lt;br /&gt;&lt;br /&gt;Seminarios impartidos por:&lt;br /&gt;&lt;br /&gt;Ing. Pavel Ocenasek, graduating PhD candidate&lt;br /&gt;Brno University of Technology, Czech Republic&lt;br /&gt;http://pavel.ocenasek.com/&lt;br /&gt;&lt;br /&gt;Sala de videoconferencia del Centro de Docencia, Anexo de la Facultad de Ingeniería&lt;br /&gt;&lt;br /&gt;21, 24 y 25 de Agosto 2009, de 12:00 a 14:00&lt;br /&gt;&lt;br /&gt;Seminarios sobre los tópicos:&lt;br /&gt;&lt;br /&gt;- Security Protocols and Authentication/Key Distribution Schemes&lt;br /&gt;- Evolutionary Computation in Network Communication &lt;br /&gt;- Evolutionary Algorithms in Security Design &lt;br /&gt;- Computer Networks and Security &lt;br /&gt;- CISCO Networking technologies (routers, switches, LAN, WAN, ...) &lt;br /&gt;- Web Technologies and Security &lt;br /&gt;- Web Accessibility &lt;br /&gt; - Electronic Commerce, Payment Systems and Payment Protocols&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-5911344776638166744?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/5911344776638166744/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=5911344776638166744' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/5911344776638166744'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/5911344776638166744'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2009/08/seminario-de-seguridad-en-la-unam.html' title='Seminario de seguridad en la UNAM'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-5013445154688474047</id><published>2009-08-12T12:30:00.004-05:00</published><updated>2009-08-12T12:40:30.190-05:00</updated><title type='text'>New semester</title><content type='html'>Today is the third day of a new semester at UNAM (both Bs and Ms). I have 6 students at "selected topics of security", we will be working with OSSTMM and vulnerability analysis, as well as fuzzing and other cool topics. The first challenge we met as teachers is to learn the names of the students, I only have 6 now, but used to be 40 when teaching other classes, I found a link with useful steps to remember most of the names, &lt;a href="http://honolulu.hawaii.edu/intranet/committees/FacDevCom/guidebk/teachtip/remnames.htm"&gt;it's here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-5013445154688474047?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/5013445154688474047/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=5013445154688474047' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/5013445154688474047'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/5013445154688474047'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2009/08/new-semester.html' title='New semester'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-8044423319210112339</id><published>2009-06-11T08:19:00.003-05:00</published><updated>2009-06-11T08:28:02.805-05:00</updated><title type='text'>Security Flaw Hits VAserv; Head of LxLabs Found Hanged</title><content type='html'>"The discovery of 24 security vulnerabilities may have contributed to the death of the chief of LxLabs. A flaw in the company's HyperVM software allowed data on 100,000 sites, all hosted by VAserv, to be destroyed. The HyperVM solution is popular with cheap web hosting services and the attacks are easy to reproduce, which could lead to further incidents." &lt;a href="http://www.theregister.co.uk/2009/06/09/lxlabs_funder_death/"&gt;&lt;br /&gt;&lt;br /&gt;Link to the news&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-8044423319210112339?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/8044423319210112339/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=8044423319210112339' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/8044423319210112339'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/8044423319210112339'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2009/06/security-flaw-hits-vaserv-head-of.html' title='Security Flaw Hits VAserv; Head of LxLabs Found Hanged'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-1407879262093216030</id><published>2009-04-28T13:03:00.010-05:00</published><updated>2009-05-05T00:34:52.202-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='off-topic'/><title type='text'>Off-topic: Summit @ Pico de Orizaba</title><content type='html'>This is totally an off-topic but it represents a personal achievement for me. Last sunday, April 26th I climbed Citlaltépetl to the summit (5630 msnm/masl), highest point in Mexico at 6:45 am local time. &lt;br /&gt;&lt;br /&gt;Thanks to the brave and professional fellows at Grupo Universitario de Alta Montaña (&lt;a href="http://www.montanismounam.org"&gt;UNAM&lt;/a&gt;) Here's the link to the &lt;a href="http://www.espina.info/fotos/Pico_Orizaba/"&gt;pictures&lt;/a&gt;. Mens sana in corpore sano.&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/JJAugCq5Ias&amp;hl=es&amp;fs=1"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/JJAugCq5Ias&amp;hl=es&amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-1407879262093216030?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/1407879262093216030/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=1407879262093216030' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/1407879262093216030'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/1407879262093216030'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2009/04/off-topic-summit-pico-de-orizaba.html' title='Off-topic: Summit @ Pico de Orizaba'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-1054180296074747296</id><published>2009-04-23T12:54:00.004-05:00</published><updated>2009-04-23T13:25:34.355-05:00</updated><title type='text'>New token from Banamex</title><content type='html'>A month ago I got an e-mail from Banamex (but hadn't had time to write down a blog entry) notifying of a new scheme to access to online bank system. (It's not a coincidence that Banamex is one of the main targets in Mexico for online fraud, they have a &lt;a href="http://eduardomx.blogspot.com/2007/09/pharming-and-one-time-passwords-otp.html"&gt;very weak system&lt;/a&gt; to authenticate users through an event-based token). It's good news to know that finally they're moving to a more effective system (although not fool-proof, there's still a scenario with &lt;a href="http://en.wikipedia.org/wiki/Man-in-the-middle_attack"&gt;MITM&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;I haven't received the new token, so I don't have a first-hand experience yet, BUT... I hope the challenge-response scheme they're announcing implements TIME-BASED numbers and not only EVENT-BASED like they do now.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-1054180296074747296?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/1054180296074747296/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=1054180296074747296' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/1054180296074747296'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/1054180296074747296'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2009/04/new-token-for-banamex.html' title='New token from Banamex'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-5088863877585252533</id><published>2009-01-06T19:42:00.013-06:00</published><updated>2009-01-07T18:13:51.241-06:00</updated><title type='text'>Captcha circumvention</title><content type='html'>Last week I was trying to bypass a captcha implementation (&lt;a href="http://jcaptcha.sourceforge.net/"&gt;JCAPTCHA&lt;/a&gt;) on a website I was hired to pentest. Although captchas can get very difficult to bypass I found a "weak link" through the WAP portion of the portal in question and I could extract a significant portion of data abusing the nonexistent distortion of the letters shown in the image.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_A7jpZtDdX-8/SWT-C-JZibI/AAAAAAAAADc/qYZE7N8Nf44/s1600-h/jcaptcha.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 100px; height: 50px;" src="http://3.bp.blogspot.com/_A7jpZtDdX-8/SWT-C-JZibI/AAAAAAAAADc/qYZE7N8Nf44/s320/jcaptcha.jpg" alt="" id="BLOGGER_PHOTO_ID_5288631189435419058" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;You'll see, there is an OCR (optical character recognition softare) in Linux (&lt;a href="http://code.google.com/p/tesseract-ocr/"&gt;tesseract&lt;/a&gt;) capable of "reading" the image given to the user, then this tool will write the characters to a text-file.&lt;br /&gt;Using &lt;a href="http://www.gnu.org/software/wget/"&gt;wget&lt;/a&gt; we can start http queries to a website, save and load cookies and write data to the filesystem. Putting it all together, we got a shellscript that will circumvent the captcha protection and extract the data in an automatic fashion (it's effective around 60%).&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-family:courier new;"&gt;#!/bin/sh&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;wget http://www.somesite.com/jcaptcha --save-cookies cookies.txt --keep-session-cookies -O /tmp/captcha.jpg 2&gt; /dev/null&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;djpeg -grayscale /tmp/captcha.jpg | convert - /tmp/captcha.tiff&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;tesseract /tmp/captcha.tiff jcaptcha&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;cap=`cat jcaptcha.txt`&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;wget "http://www.somesite.com/servlet?niv=&amp;amp;nrpv=&amp;amp;query=$somevalue&amp;amp;captcha=$cap" --load-cookies cookies.txt -O salida.txt 2&gt; /dev/null&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;tam=`wc -c salida.txt| cut -c1-3`&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;echo $tam&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;if   [ $tam -ne 701 ]; then&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; mv salida.txt $query.txt&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;fi&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;You may wonder why the script uses a length of 701 bytes to detect if the captcha has been defeated, well, it's just assuming the default "error" page has a length of 701 bytes, any other length it's assumed as info extracted from the database (ok, it's not the best approach, but it's just a PoC).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-5088863877585252533?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/5088863877585252533/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=5088863877585252533' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/5088863877585252533'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/5088863877585252533'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2009/01/captcha-circumvention.html' title='Captcha circumvention'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_A7jpZtDdX-8/SWT-C-JZibI/AAAAAAAAADc/qYZE7N8Nf44/s72-c/jcaptcha.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-5751316621622020729</id><published>2008-11-07T14:03:00.002-06:00</published><updated>2008-11-07T14:06:09.478-06:00</updated><title type='text'>WPA partially broken</title><content type='html'>"Security researchers say they've developed a way to partially crack the Wi-Fi Protected Access (WPA) encryption standard used to protect data on many wireless networks.&lt;br /&gt;&lt;p&gt;The attack, described as the first practical attack on WPA, will be discussed at the &lt;a href="http://pacsec.jp/"&gt;PacSec conference&lt;/a&gt; in Tokyo next week. There, researcher &lt;a title="Erik Tews" href="http://www.computerworld.com/action/inform.do?command=search&amp;amp;searchTerms=Erik+Tews"&gt;Erik Tews&lt;/a&gt; will show how he was able to crack WPA encryption and read data being sent from a router to a laptop computer. The attack could also be used to send bogus information to a client connected to the router."&lt;/p&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9119258"&gt;Link&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-5751316621622020729?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/5751316621622020729/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=5751316621622020729' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/5751316621622020729'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/5751316621622020729'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2008/11/wpa-partially-broken.html' title='WPA partially broken'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-7473906027787125465</id><published>2008-10-22T18:57:00.002-05:00</published><updated>2008-10-22T20:01:08.319-05:00</updated><title type='text'>Skype-in numbers for Mexico city</title><content type='html'>It's been hard for me to keep the blog up-to-date due to, among others, excess of work, my class at UNAM, mountaineering on weekends.&lt;br /&gt;&lt;br /&gt;Anyway, yesterday I've just paid a 3 month subscription to Skype-in service, meaning I can receive calls in my computer that have been generated, mostly, from local phones, I know this is old news for other countries, but in Mexico it's a new service. You can even choose your number (sort of, just the last 4 digits). I can think of many illegal scenarios for scams, and I think it won't take much time to attract the attention of criminals in Mexico, so bad.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-7473906027787125465?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/7473906027787125465/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=7473906027787125465' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/7473906027787125465'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/7473906027787125465'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2008/10/skype-in-numbers-for-mexico-city.html' title='Skype-in numbers for Mexico city'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-1709662849908746990</id><published>2008-09-12T13:40:00.008-05:00</published><updated>2008-09-12T14:06:14.363-05:00</updated><title type='text'>UNAM's Computer security conference</title><content type='html'>The UNAM's computer security conference will be held on September 25th-26th in Mexico city, the line-up includes (among others):&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Eugene Schultz&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Kimberly Zenz&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Dr. Tom Holt&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Peter Casidy&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Lance Spitzner&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Jess Vincent&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;br /&gt;&lt;a href="http://congreso.seguridad.unam.mx"&gt;Registration &lt;/a&gt;is now open for this 2-day event. The fee is $100 per person for both days.&lt;br /&gt;Where: Palacio de Minería, downtown.&lt;br /&gt;See you there two weeks from now.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-1709662849908746990?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/1709662849908746990/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=1709662849908746990' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/1709662849908746990'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/1709662849908746990'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2008/09/unams-computer-security-conference.html' title='UNAM&apos;s Computer security conference'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-5271849094904635027</id><published>2008-08-25T09:48:00.003-05:00</published><updated>2008-08-25T09:51:48.645-05:00</updated><title type='text'>New blog from my class</title><content type='html'>I've just added a &lt;a href="http://temas-seguridad-unam.blogspot.com"&gt;link&lt;/a&gt; to a blog related to computer security topics from my class at UNAM. We'll be discussing fresh news and other info. Sorry, only spanish.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-5271849094904635027?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/5271849094904635027/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=5271849094904635027' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/5271849094904635027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/5271849094904635027'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2008/08/ive-just-added-link-to-blog-related-to.html' title='New blog from my class'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-4715235157716424259</id><published>2008-07-28T12:40:00.003-05:00</published><updated>2008-07-28T12:49:27.976-05:00</updated><title type='text'>Heart defibrillators &amp; security</title><content type='html'>A couple of weeks ago I received the printed version of "The Institute" newspaper from IEEE. Although not fresh news (I found some headlines dated March 13, 2008), there is an interesting article titled &lt;a href="http://www.theinstitute.ieee.org/portal/site/tionline/index.jsp?pageID=institute_level1_article&amp;TheCat=2201&amp;article=tionline/legacy/inst2008/jul08/featurehackers.xml"&gt;"hacking hearts"&lt;/a&gt; about the "hackability" of the human heart defibrillators.&lt;br /&gt;&lt;br /&gt;Back in May the IEEE held a Symposium about privacy &amp;amp; security, and the topic of security of defibrillators was deeply discussed, "The researchers tricked the defibrillator into responding to their signals by recording a real device programmer talking electronically to a defibrillator, then replaying the signals wirelessly back to the defibrillator."&lt;br /&gt;&lt;br /&gt;Were you concerned about your car's bluetooth connectivity?, what about this?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-4715235157716424259?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/4715235157716424259/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=4715235157716424259' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/4715235157716424259'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/4715235157716424259'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2008/07/heart-defibrillators.html' title='Heart defibrillators &amp; security'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-8207712103875809530</id><published>2008-06-27T13:39:00.003-05:00</published><updated>2008-06-27T13:50:27.643-05:00</updated><title type='text'>802.11n and vulnerabilities</title><content type='html'>With the upcoming release of IEEE's 802.11n standard, I've been looking for already known vulnerabilities with the draft-based (2.0) products that have been sold for a while.&lt;br /&gt;&lt;br /&gt;There are some interesting URLs where you can dig, like &lt;a href="http://www.wirelessve.org/"&gt;WVE&lt;/a&gt; and Joshua Wright's &lt;a href="http://www.willhackforsushi.com/Home/Home.html"&gt;website&lt;/a&gt;. The standard is planned to be released on November 2008, and so the "certified" products, so we expect to find exploits, vulnerabilities shortly after.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-8207712103875809530?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/8207712103875809530/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=8207712103875809530' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/8207712103875809530'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/8207712103875809530'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2008/06/with-upcoming-release-of-ieees-802.html' title='802.11n and vulnerabilities'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-9073543425074642378</id><published>2008-05-09T17:41:00.004-05:00</published><updated>2008-05-09T17:51:32.217-05:00</updated><title type='text'>Mexican Senate's site hacked</title><content type='html'>Today the Mexican &lt;a href="http://www.senado.gob.mx/"&gt;Senate's&lt;/a&gt; website &lt;a href="http://www.eluniversal.com.mx/notas/505626.html"&gt;has been hacked&lt;/a&gt; by a southamerican hacker group. It's been almost 10 years since that website was hacked by the X-ploit group. The people responsible for the Senate's website still have many lessons to learn.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-9073543425074642378?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/9073543425074642378/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=9073543425074642378' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/9073543425074642378'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/9073543425074642378'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2008/05/mexican-senates-site-hacked.html' title='Mexican Senate&apos;s site hacked'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-1527998936365590775</id><published>2008-05-09T16:01:00.003-05:00</published><updated>2008-05-09T17:41:25.532-05:00</updated><title type='text'>Back to the roots</title><content type='html'>I'm back at the &lt;a href="http://www.cert.org.mx"&gt;UNAM-CERT&lt;/a&gt; after spending 3 months at NextiraOne. And it's a good returning for me because I've been told I'll be teaching at the engineering school at &lt;a href="http://www.unam.mx"&gt;UNAM&lt;/a&gt;, a course of selected topics on network security.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-1527998936365590775?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/1527998936365590775/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=1527998936365590775' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/1527998936365590775'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/1527998936365590775'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2008/05/back-to-roots.html' title='Back to the roots'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-334335118530914713</id><published>2008-02-05T10:40:00.000-06:00</published><updated>2008-02-05T11:07:29.947-06:00</updated><title type='text'>Security patch for the "2wire authentication vulnerability"</title><content type='html'>Today the &lt;a href="http://www.cert.org.mx"&gt;UNAM-CERT&lt;/a&gt; has released an update to the security note published back in December 2007 that warned about an authentication vulnerability in the &lt;a href="http://www.2wire.com"&gt;2wire &lt;/a&gt;modems.&lt;br /&gt;&lt;br /&gt;Last week the UNAM-CERT tested the new firmware that is scheduled to be released to the &lt;a href="http://www.telmex.com"&gt;TELMEX &lt;/a&gt;users (prodigy Infinitum) later this month. The new firmware version is 5.29.135.5 and will be deployed in the next weeks. It is important to say that the update is automatic.&lt;br /&gt;&lt;br /&gt;The complete information is here: &lt;a href="http://www.cert.org.mx/boletin/?vulne=5534"&gt;http://www.cert.org.mx/nota/?vulne=5534&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-334335118530914713?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/334335118530914713/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=334335118530914713' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/334335118530914713'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/334335118530914713'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2008/02/security-patch-for-2wire-authentication.html' title='Security patch for the &quot;2wire authentication vulnerability&quot;'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-639992669254225626</id><published>2008-01-27T13:07:00.000-06:00</published><updated>2008-01-27T15:57:43.361-06:00</updated><title type='text'>2wire authentication vulnerability reaches the mainstream</title><content type='html'>It's been 50 days since the UNAM-CERT &lt;a href="http://www.seguridad.unam.mx/doc/?ap=articulo&amp;amp;id=196"&gt;first warned&lt;/a&gt; about the 2wire authentication vulnerability we found through an 0-day exploit.&lt;br /&gt;&lt;br /&gt;Many people and security-related companies have claimed that "that was old news" referring to the "cross site request forgery (XSRF)" vulnerability &lt;a href="http://www.securityfocus.com/archive/1/archive/1/476595/100/0/threaded"&gt;reported by a mexican hacker&lt;/a&gt; group back in August 2007, BUT our security note announced a brand-new-authentication-vulnerability that put in high risk more than 1 million users (at least) in Mexico.&lt;br /&gt;&lt;br /&gt;Back in December 2007 we got in touch with 2wire and Telmex before releasing the security note, we were the first team to discover and to report the issue while some companies were buying their gifts for christmas day and cooking the turkey.&lt;br /&gt;&lt;br /&gt;For those companies, the issue remained unnoticed for some weeks (even when we made public the vulnerability and when some blogs had been discussing the topic for a while). But two weeks ago a company (one of those cooking the turkey for the christmas back in 2007, TrendMicro)  made a statement about  the issue, 1 month after our security note was released (just in time) . It's funny TrendMicro is warning about a "&lt;a href="http://www.netmedia.info/articulo-31-7578-1.html"&gt;massive attack to hit&lt;/a&gt;&lt;a href="http://www.netmedia.info/articulo-31-7578-1.html"&gt; the mexican users&lt;/a&gt;" when this issue has been exploited for a long time.&lt;br /&gt;&lt;br /&gt;It seems that TrendMicro Labs are only able to "predict attacks" when they have enough newspapers to "read the future".&lt;br /&gt;&lt;br /&gt;Then appeared Symantec, some days ago, with the article "&lt;a href="http://www.networkworld.com/news/2008/012208-drive-by-pharming.html"&gt;first case of drive-by-pharming in the wild&lt;/a&gt;", based on the Trendmicro statement (I guess).&lt;br /&gt;&lt;br /&gt;But aside the flames, the important thing here is: antivirus and security-related companies based in the USA or other countries doesn't put enough efforts to detect the current threats in LatinAmerica or at least not in Mexico. And that's odd, because they sell a lot of licenses here, I think they should start working instead of warning of "(already) upcoming threats".&lt;br /&gt;&lt;br /&gt;Shame on them!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-639992669254225626?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/639992669254225626/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=639992669254225626' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/639992669254225626'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/639992669254225626'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2008/01/2wire-vulnerability-reaches-mainstream.html' title='2wire authentication vulnerability reaches the mainstream'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-1627561784917335626</id><published>2007-12-11T13:30:00.000-06:00</published><updated>2007-12-11T13:33:24.580-06:00</updated><title type='text'>Vulnerability in 2Wire routers</title><content type='html'>We've just released a security advisory for a vulnerability in 2Wire routers that is being actively exploited through phishing.&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://www.seguridad.unam.mx/vulnerabilidadesDB/?vulne=5534"&gt;advisory is located here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-1627561784917335626?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/1627561784917335626/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=1627561784917335626' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/1627561784917335626'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/1627561784917335626'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/12/vulnerability-in-2wire-routers.html' title='Vulnerability in 2Wire routers'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-9074057083008250204</id><published>2007-12-03T21:08:00.000-06:00</published><updated>2007-12-03T21:53:43.912-06:00</updated><title type='text'>Win a car!, just click here</title><content type='html'>I don't know if this scam really qualifies as "phishing" because it seems odd at first sight.&lt;br /&gt;&lt;br /&gt;I don't know even if it really represents a threat to anyone. Let me explain, the e-mail asks the user to click on the attachment and answer a trivia to win a car, so what's this all about?&lt;br /&gt;&lt;br /&gt;The picture of the "prize" is of a &lt;a href="http://en.wikipedia.org/wiki/Volkswagen_Golf"&gt;Volkswagen Golf&lt;/a&gt; (by the way, the name of the file is misspelled as "Wolsvagen") but not the brand new model, not even the previous one, the car is something around Mark 3 or Mark 4 (newest is Mark 5), I'm not sure because I'm not a VW fan nor expert, but certainly it isn't a Mark 5 VW Golf, you can take a look at the &lt;a href="http://www.volkswagen.com/vwcms_publish/vwcms/master_public/virtualmaster/es_mx/models/gti_mx.html"&gt;VW Mexico&lt;/a&gt; website.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_A7jpZtDdX-8/R1TLRi4BbiI/AAAAAAAAABs/Yf5UrZUuofk/s1600-R/golf.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_A7jpZtDdX-8/R1TLRi4BbiI/AAAAAAAAABs/wQdhOXH3z2U/s320/golf.jpg" alt="" id="BLOGGER_PHOTO_ID_5139956577016573474" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;So, my first thought was "this e-mail must be a joke", but when I analized the binary I realized that the threat was very real, the .exe file modifies the hosts file in Windows and, guess what, add some entries to replace the BANAMEX domain name.&lt;br /&gt;&lt;br /&gt;I don't know if this is intentional, but in any case the phishers put little effort to deceive the user, finally, there's always a user who will try to "win the car" even if the car was dropped from production in Mexico many years ago.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Md5sum: 70d0a93d0001288ad057f41c7fd8a397&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Filename: Wolsvagen-Sorteo.exe&lt;br /&gt;IP: 65.23.158.58&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Ps. I did some research and found that the car is indeed offered as a &lt;a href="http://www.canalmail.com/sorteos/golf3/"&gt;prize in Spain&lt;/a&gt;, so my guess is that this phishing scam originates in the &lt;a href="http://en.wikipedia.org/wiki/Motherland"&gt;Motherland&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-9074057083008250204?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/9074057083008250204/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=9074057083008250204' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/9074057083008250204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/9074057083008250204'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/12/win-car-just-click-here.html' title='Win a car!, just click here'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_A7jpZtDdX-8/R1TLRi4BbiI/AAAAAAAAABs/wQdhOXH3z2U/s72-c/golf.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-7722863846787385228</id><published>2007-10-23T13:41:00.000-05:00</published><updated>2007-11-09T13:08:46.974-06:00</updated><title type='text'>iPhone targeted for hacking</title><content type='html'>HDMoore has &lt;a href="http://blog.metasploit.com/2007/09/root-shell-in-my-pocket-and-maybe-yours.html"&gt;announced&lt;/a&gt; very good stuff to hack the iPhone (like adding an openssh to the phone and getting a rootshell). The entry has been added to the &lt;a href="http://www.metasploit.com/"&gt;Metasploit&lt;/a&gt; blog.&lt;br /&gt;&lt;br /&gt;I know it will be a long time before the iPhone make its debut in Mexico, but it seems like  the delay will be worth it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-7722863846787385228?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/7722863846787385228/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=7722863846787385228' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/7722863846787385228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/7722863846787385228'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/10/iphone-targeted-for-hacking.html' title='iPhone targeted for hacking'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-1122897185766807103</id><published>2007-10-12T12:32:00.000-05:00</published><updated>2007-10-12T12:40:31.160-05:00</updated><title type='text'>Malware speech</title><content type='html'>Next monday I'm giving a speech at Facultad de Ingeniería, UNAM. Here is the &lt;a href="http://cms.lidsol.net"&gt;complete information&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-1122897185766807103?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/1122897185766807103/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=1122897185766807103' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/1122897185766807103'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/1122897185766807103'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/10/malware-speech.html' title='Malware speech'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-535959458666859435</id><published>2007-09-02T18:39:00.000-05:00</published><updated>2007-09-02T20:07:49.394-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pharming security'/><title type='text'>Pharming and One Time Passwords (OTP)</title><content type='html'>Sadly, the pharming is increasing in Mexico, with local "look &amp; feel" and targeting online banks, mainly &lt;a href="http://www.banamex.com/"&gt;Banamex&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Banamex (Citigroup in Mexico) is one of the largest banks in Mexico, so it is natural for phishers to target the users of this bank. But it isn't just related to the number of users but to the fact that Banamex uses &lt;a href="http://www.securecomputing.com/"&gt;NETKEY token&lt;/a&gt; to give online access. So, you may wonder why criminals are targeting Banamex if two-factor authentication is used?&lt;br /&gt;&lt;br /&gt;The reason is, NETKEY is a "sequence-based token", this means a new pseudo-random number will be given to the user each time he/she pushes a key on the token, but won't expire after some time (like &lt;a href="http://en.wikipedia.org/wiki/Strong_authentication"&gt;time-based tokens&lt;/a&gt; do).&lt;br /&gt;&lt;br /&gt;Criminals will fool the user into thinking that he/she has reached the bank website, then the phisher will steal the login, the password and the OTP and show the user a message like &lt;span style="font-style: italic;"&gt;"we're under maintenance, please come back in a few hours"&lt;/span&gt;; finally the phisher will get access to the online bank and steal the money (as long as the user doesn't log in to the genuine website before the e-robbery takes place).&lt;br /&gt;&lt;br /&gt;The problem here is the OTP doesn't expire (I've tried with my NETKEY and I could log in two hours after reading the OTP at NETKEY's display), so the phisher has more time to steal the money. Other banks use time-based tokens so the phisher would need to log in with the stolen credentials within sixty seconds or less. Banamex &lt;span style="font-weight: bold;"&gt;should adopt the time-based solution, &lt;/span&gt;in the meantime its users are in risk.&lt;br /&gt;&lt;br /&gt;Now, for the attack-vector part, the message says "a finnish kid was condemned because of a youtube video", and at the end of the text it prompts the user to download the supposed video.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_A7jpZtDdX-8/RttYsZUs0aI/AAAAAAAAABk/dXLM-IU2VZU/s1600-h/youtube-pharming.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_A7jpZtDdX-8/RttYsZUs0aI/AAAAAAAAABk/dXLM-IU2VZU/s320/youtube-pharming.JPG" alt="" id="BLOGGER_PHOTO_ID_5105772122289787298" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The file is a .rar that contains an executable file that modifies the &lt;span style="font-style: italic;"&gt;hosts &lt;/span&gt;file and it also opens a browser window  with a &lt;a href="http://es.youtube.com/watch?v=rooDxralE3s"&gt;video&lt;/a&gt; from youtube (in fact the video is in spanish).&lt;br /&gt;The md5 of this file is: &lt;span style="font-style: italic;"&gt;b845cbb13117a9776852bc86a802b51a&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-535959458666859435?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/535959458666859435/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=535959458666859435' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/535959458666859435'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/535959458666859435'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/09/pharming-and-one-time-passwords-otp.html' title='Pharming and One Time Passwords (OTP)'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_A7jpZtDdX-8/RttYsZUs0aI/AAAAAAAAABk/dXLM-IU2VZU/s72-c/youtube-pharming.JPG' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-4413139263844095288</id><published>2007-08-29T22:12:00.000-05:00</published><updated>2007-08-30T10:49:47.532-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='humor'/><title type='text'>"Anti-fraud dipping birds" Unit</title><content type='html'>At UNAM-CERT, we think that any help is good help. After the pharming attack we faced yesterday, we called the special forces unit.&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="350"&gt;&lt;param name="movie" value="http://www.youtube.com/v/JvrU97rY-Mw"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/JvrU97rY-Mw" type="application/x-shockwave-flash" width="425" height="350"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;With one hundred of these workers we could take the anti-fraud fight to a new level.&lt;br /&gt;&lt;br /&gt;For information about"drinking birds": &lt;a href="http://en.wikipedia.org/wiki/Drinking_bird"&gt;wikipedia&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-4413139263844095288?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/4413139263844095288/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=4413139263844095288' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/4413139263844095288'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/4413139263844095288'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/08/happy-drinking-birds-unit.html' title='&quot;Anti-fraud dipping birds&quot; Unit'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-2408739945967263048</id><published>2007-08-28T11:46:00.000-05:00</published><updated>2007-08-28T19:17:50.221-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pharming'/><title type='text'>Pharming attacks are on the rise, this time: UNAM-CERT</title><content type='html'>Today's early morning we started receiving phone calls from people asking us about an e-mail they received last night. This e-mail included links to UNAM-CERT, a supposed "guide" to secure the PC and the UNAM-CERT's phone number.&lt;br /&gt;&lt;br /&gt;Some user submitted to me a copy of the e-mail that supposedly came from UNAM-CERT, this e-mail included a text asking the recipients to download a supposed "guide" to secure their PCs (&lt;span style="font-style: italic;"&gt;Manual.exe&lt;/span&gt;).&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_A7jpZtDdX-8/RtRfyJUs0ZI/AAAAAAAAABc/jtlH9LRw608/s1600-h/phish-unam.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_A7jpZtDdX-8/RtRfyJUs0ZI/AAAAAAAAABc/jtlH9LRw608/s320/phish-unam.jpg" alt="" id="BLOGGER_PHOTO_ID_5103809592818454930" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The md5 checksum of the malware is: &lt;span style="font-style: italic;"&gt;fcfc77d1786572812aac1319e5ad5fde&lt;/span&gt;&lt;br /&gt;This malware modifies the hosts file in Windows, redirecting www.banamex.com to an IP address under the control of the phisher.&lt;br /&gt;&lt;br /&gt;What is really interesting in this attack is the fact that phishers are using well-known organizations as vector for infection, even when the final target is another website, like &lt;a href="http://www.banamex.com/"&gt;Banamex&lt;/a&gt; in this case.&lt;br /&gt;&lt;br /&gt;For more information regarding recommendations and related info you should go to the &lt;a href="http://www.seguridad.unam.mx/"&gt;UNAM-CERT official site&lt;/a&gt;.&lt;br /&gt;For an in-depth analysis check the UNAM-CERT's &lt;a href="http://www.malware.unam.mx/blog.dsc"&gt;malware blog&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-2408739945967263048?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/2408739945967263048/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=2408739945967263048' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/2408739945967263048'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/2408739945967263048'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/08/pharming-on-raise.html' title='Pharming attacks are on the rise, this time: UNAM-CERT'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_A7jpZtDdX-8/RtRfyJUs0ZI/AAAAAAAAABc/jtlH9LRw608/s72-c/phish-unam.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-8966921205714673730</id><published>2007-07-30T14:53:00.000-05:00</published><updated>2007-07-30T17:12:40.776-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='&quot;privacy&quot; &quot;social networks&quot;'/><title type='text'>The Privacy Risks of Social Networking Sites</title><content type='html'>For those concerned about &lt;span style="font-weight: bold;"&gt;privacy&lt;/span&gt; on the Net and &lt;span style="font-weight: bold;"&gt;social networks&lt;/span&gt; like &lt;a href="http://www.facebook.com/"&gt;Facebook&lt;/a&gt;, &lt;a href="http://www.hi5.com/"&gt;Hi5&lt;/a&gt;, &lt;a href="http://www.myspace.com/"&gt;Myspace&lt;/a&gt;, etc., there is a good article in the last issue (&lt;a href="http://ieeexplore.ieee.org/iel5/8013/4218538/04218550.pdf?isnumber=4218538&amp;prod=JNL&amp;amp;arnumber=4218550&amp;arSt=40&amp;amp;ared=49&amp;arAuthor=Rosenblum%2C+David"&gt;May-June 2007&lt;/a&gt;) of IEEE's &lt;span style="font-style: italic;"&gt;Security &amp; Privacy&lt;/span&gt; magazine by David Rosenblum.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_A7jpZtDdX-8/Rq5IKjKNYvI/AAAAAAAAABU/ptUcpmJ7jrU/s1600-h/secprivac2007a.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_A7jpZtDdX-8/Rq5IKjKNYvI/AAAAAAAAABU/ptUcpmJ7jrU/s320/secprivac2007a.jpg" alt="" id="BLOGGER_PHOTO_ID_5093087574676562674" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;"For the Net generation, social networking sites have become the preferred forum for social interactions, from posturing and role playing to simply sounding off. However, because such forums are relatively easy to access, posted content can be reviewed by anyone with an interest in the users' personal information."&lt;/span&gt;  &lt;span style="font-style: italic;"&gt;"It is possible to glean personal information even without accessing a home page on these sites because many people use the public wall as a private message board to post intimate details of their lives, schedules, or recent sexual conquests. But what would motivate people to broadcast&lt;/span&gt; &lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-size:85%;"&gt;their private lives? As one user explained it: 'Like many of my generation, I consistently trade actual human contact for the more reliable high of smiles on MySpace, winks on Match.com, and pokes on Facebook. I live for Friendster views, profile comments, and the Dodgeball messages that clog my cell phone every night.”&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-size:100%;"&gt;Many websites ask its users to enter a "secret question/answer" in case they forget the password, so the user can recover/reset it. Many of the secret answers could be found at myspace or hi5, i.e.: name of the primary school, name of the pet, city of birth, favorite team.&lt;br /&gt;&lt;br /&gt;Worst, many of these questions are used as authentication method at phone services offered by many banks, so when you call for the very first time you will be asked for your mother's maiden name and even if you didn't publish this info, it isn't hard for an attacker to directly ask this question at your myspace/hi5/facebook site(using social engineering). &lt;a href="http://ieeexplore.ieee.org/iel5/8013/4218538/04218550.pdf?isnumber=4218538&amp;prod=JNL&amp;amp;arnumber=4218550&amp;arSt=40&amp;amp;amp;amp;ared=49&amp;amp;arAuthor=Rosenblum%2C+David"&gt;Worth a look&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-8966921205714673730?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/8966921205714673730/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=8966921205714673730' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/8966921205714673730'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/8966921205714673730'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/07/privacy-risks-of-social-networking.html' title='The Privacy Risks of Social Networking Sites'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_A7jpZtDdX-8/Rq5IKjKNYvI/AAAAAAAAABU/ptUcpmJ7jrU/s72-c/secprivac2007a.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-6059230774388813736</id><published>2007-07-27T15:37:00.000-05:00</published><updated>2007-07-29T13:12:53.525-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pharming'/><category scheme='http://www.blogger.com/atom/ns#' term='unam-cert'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Pharming in the wild</title><content type='html'>My SPAM folder is an unbeatable source of malware, I think better than the &lt;a href="http://www.honeynet.org/"&gt;honeynet project&lt;/a&gt; (JK); last week I found an e-mail with an interesting subject "Combate al robo de combustible" loosely translated "Fighting the gas rip-off", let me explain, in Mexico there are some gas station pumps that dispense less fuel than what you're paying for, you pay for 1 L but you get, let's say 900 ml (or less). Well, there is a study on this topic and a &lt;a href="http://webapps.profeco.gob.mx/verificacion/gasolina/"&gt;list of gas stations&lt;/a&gt; that rip you off.&lt;br /&gt;&lt;br /&gt;Back to the e-mail stuff, it was supposedly sent by the "&lt;a href="http://www.itesm.edu.mx/"&gt;Tec de Monterrey&lt;/a&gt;" (private university in Mexico), it seems to be fake.&lt;br /&gt;And it includes a link to a file that pretends to be the list of gas stations (Gasolinera.rar); inside this rar is contained a "gasolineras.exe" file with md5 hash:  &lt;span style="font-style: italic;"&gt;f5e9203e2d799cc98016db11a1832880&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_A7jpZtDdX-8/RqpZNzKNYuI/AAAAAAAAABM/ULvRAT9qNi4/s1600-h/malwareprofeco.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_A7jpZtDdX-8/RqpZNzKNYuI/AAAAAAAAABM/ULvRAT9qNi4/s320/malwareprofeco.jpg" alt="" id="BLOGGER_PHOTO_ID_5091980422301967074" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;It was evident this file was malware, but I always upload suspicious files to &lt;a href="http://www.virustotal.com/"&gt;virustotal&lt;/a&gt; before start a deeper analysis (to save efforts in case of an existing malware), but reported nothing. Then I sent a copy of the file to the &lt;a href="http://www.malware.unam.mx/"&gt;malware team at UNAM-CERT&lt;/a&gt; for analysis, at the same time I was trying to reverse-engineer the code to highlight the main activities of this malware.&lt;br /&gt;&lt;br /&gt;The file has interesting strings:&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Gasolineraxc&lt;br /&gt;SeguridadBanamex&lt;br /&gt;Gasolineras&lt;br /&gt;ProductName&lt;br /&gt;SeguridadBanamex&lt;br /&gt;FileVersion&lt;br /&gt;1.00&lt;br /&gt;ProductVersion&lt;br /&gt;1.00&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This malware add entries to the "&lt;span style="font-style: italic;"&gt;C:\WINDOWS\system32\drivers\etc\hosts&lt;/span&gt;" file, specifically:&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;209.40.195.154   banamex.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;209.40.195.154    www.banamex.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;209.40.195.154    banamex.com.mx&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;209.40.195.154    www.banamex.com.mx&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;72.249.77.180    www.bancanetempresarial.banamex.com.mx&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;209.40.195.154    bancanetempresarial.banamex.com.mx&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;209.40.195.154    boveda.banamex.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;209.40.195.154    www.boveda.banamex.com&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This kind of attack is known as "PHARMING" and will fool the browser and other applications into resolving to fake internet portals, mainly online banks. This means, that when I type &lt;span style="font-style: italic;"&gt;www.banamex.com&lt;/span&gt; at the browser, the system will go to check the hosts file, the malware previosly added the entry, so the &lt;span style="font-style: italic;"&gt;www.banamex.com&lt;/span&gt; domain now belongs to the IP: &lt;span style="font-style: italic;"&gt;209.40.195.154&lt;/span&gt;, and of course the attacker has control over this IP.&lt;br /&gt;&lt;br /&gt;The antivirus fails to detect this malware as potentially unwanted because doesn't open TCP ports, doesn't add entries to the windows registry and doesn't spy hardware interruptions (among other hacking activities), needless to say it's a very NASTY attack.&lt;br /&gt;&lt;br /&gt;The details maybe quite technical for some people, but let's make an analogy: An attacker overwrites the yellowpages book, so when you try to reach Domino's pizza by phone you get in fact the number of Pizza hut.&lt;br /&gt;&lt;br /&gt;So, &lt;span style="font-weight: bold;"&gt;how can I protect myself?&lt;/span&gt;, ALWAYS check the SSL certificate when browsing online banks, no matter you type directly the URL in the browser, and NEVER execute files received as attachment, even if antivirus says it's ok.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-6059230774388813736?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/6059230774388813736/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=6059230774388813736' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/6059230774388813736'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/6059230774388813736'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/07/pharming-in-wild.html' title='Pharming in the wild'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_A7jpZtDdX-8/RqpZNzKNYuI/AAAAAAAAABM/ULvRAT9qNi4/s72-c/malwareprofeco.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-7951067258490716293</id><published>2007-07-05T13:19:00.000-05:00</published><updated>2007-07-09T14:51:51.526-05:00</updated><title type='text'>New celebrity phishing</title><content type='html'>Today I found an interesting brand new (at least for me) vector of infection; usually when you are being phished the attackers send you e-mails with the look &amp; feel of some bank's website trying to convince you of the authenticity of the site. But now it's being obvious and people do know how phishing e-mails look like.&lt;br /&gt;&lt;br /&gt;This time I got a supposed video from a well-known magazine with the headline "Luis Miguel cheating on his wife", some pictures and three links to the "video". The video is a tvnotas.exe file.&lt;br /&gt;&lt;br /&gt;You may wonder why would a victim click on that link, well &lt;a href="http://en.wikipedia.org/wiki/Luis_Miguel_Gallego_Basteri"&gt;Luis Miguel&lt;/a&gt; is a famous singer in Mexico, one of the richest, and all the magazines and TV programs are always following his career and personal life (far beyond of his public life). Maybe I'm not the target for this phishing, but I know a lot of people (mostly women) who would click before they finish reading "luis miguel"; you know, his wife is another beautiful woman "&lt;a href="http://en.wikipedia.org/wiki/Aracely_Ar%C3%A1mbula"&gt;Araceli Arámbula&lt;/a&gt;", and it would be embarrasing to him to be caught "on action".&lt;br /&gt;&lt;br /&gt;If you are curious about who was luis miguel supossedly kissing, it was "Jessica de Alba" (&lt;span style="font-style: italic;"&gt;sic&lt;/span&gt;), I guess phisher was referring to "Jessica Alba" the chick from Dark Angel and Fantastic four.&lt;br /&gt;&lt;br /&gt;After all this "background", I downloaded the tvnotas.exe troyan from www.nocleh.cz and uploaded to virus total (&lt;a href="http://www.virustotal.com/"&gt;www.virustotal.com&lt;/a&gt;) to scan it. Virus total is a public free service in Spain, you can upload any file you like to get scanned for virus and malware.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_A7jpZtDdX-8/Ro1DTy0YMjI/AAAAAAAAABE/VwWcKBJYVXY/s1600-h/virustotal.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_A7jpZtDdX-8/Ro1DTy0YMjI/AAAAAAAAABE/VwWcKBJYVXY/s320/virustotal.jpg" alt="" id="BLOGGER_PHOTO_ID_5083793561709195826" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;From all the 30+ engines used at virus total, just 6 reported from "suspicious file" to "Trojan/Delphi.Downloader.Gen", Symantec and Mcafee reported nothing.&lt;br /&gt;&lt;br /&gt;What we can learn from this is not to blindly trust the Antivirus. Everyday hackers are trying to fool you into clicking an image or link and have freshly programmed code that intercepts your request. You might get convinced with a headline and download a file, run the antivirus and as long as there isn't any alerts you double click the file and you are gone.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-7951067258490716293?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/7951067258490716293/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=7951067258490716293' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/7951067258490716293'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/7951067258490716293'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/07/today-i-found-interesting-brand-new-at.html' title='New celebrity phishing'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_A7jpZtDdX-8/Ro1DTy0YMjI/AAAAAAAAABE/VwWcKBJYVXY/s72-c/virustotal.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-232077908340904066</id><published>2007-06-30T16:08:00.000-05:00</published><updated>2007-06-30T16:18:59.914-05:00</updated><title type='text'>American Express phishing</title><content type='html'>Yesterday I received a promotional flyer from American Express Mexico to speed up the collecting of membership rewards. Either I call by phone and ask for the promotion or sign up myself at Internet.&lt;br /&gt;&lt;br /&gt;The problem is, when you access the URL you're asked for your credit card number, no problem. I would give my number after checked the SSL certificate and double-check I'm at the correct American Express site; but wait a moment... I opened the source code at Firefox browser to get myself assured about the destination of my credit card data:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;font-size:85%;" &gt;form name="forma1" action="http://extranet.ogilvy.com.mx/amexoptin/default.asp"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Am I wrong or is there a missing "s" after the "http"?&lt;br /&gt;&lt;br /&gt;It's not the first time I got promotionals from American Express asking for my account number without encryption layer over the Internet. Last time I was supposed to send my credit card number via e-mail (no encryption at all) and I would get 500 membership rewards.&lt;br /&gt;&lt;br /&gt;Last time I wrote down "It seems that American Express is phishing... their clients", now I'm pretty sure they are.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-232077908340904066?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/232077908340904066/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=232077908340904066' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/232077908340904066'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/232077908340904066'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/06/american-express-phishing.html' title='American Express phishing'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-6540047250021959368</id><published>2007-06-29T13:37:00.000-05:00</published><updated>2007-06-29T18:49:51.369-05:00</updated><title type='text'>Wardriving</title><content type='html'>&lt;div style="text-align: justify;"&gt;Like a month ago I was wardriving south of the city for a project at UNAM-CERT. I found a lot more networks than six months ago that I did a Wi-Fi reconnaissance; most of the networks were totally open like hotspots.&lt;br /&gt;&lt;br /&gt;This is a growing problem in Mexico because wireless technology it's being recently widely adopted (with some years of delay respect to other countries). Everytime we do pentest we found the weakest link to be the wireless network, so bad.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;Here some pictures of the kit for wardriving.  &lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;(click for bigger image)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt; &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.espina.info/fotos/blogspot/gps.jpg"&gt;&lt;img style="cursor: pointer;" src="http://bp0.blogger.com/_A7jpZtDdX-8/RoVVCS0YMgI/AAAAAAAAAAs/2Da4NyTIagE/s320/gps_thmb.jpg" alt="" id="BLOGGER_PHOTO_ID_5081561252457099778" border="0" /&gt;&lt;/a&gt;                           &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.espina.info/fotos/blogspot/laptop.jpg"&gt;&lt;img style="cursor: pointer;" src="http://bp0.blogger.com/_A7jpZtDdX-8/RoVVCS0YMhI/AAAAAAAAAA0/ylAFE_PexmM/s320/laptop_thmb.jpg" alt="" id="BLOGGER_PHOTO_ID_5081561252457099794" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-6540047250021959368?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/6540047250021959368/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=6540047250021959368' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/6540047250021959368'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/6540047250021959368'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/06/wardriving.html' title='Wardriving'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_A7jpZtDdX-8/RoVVCS0YMgI/AAAAAAAAAAs/2Da4NyTIagE/s72-c/gps_thmb.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-1528708492421611210</id><published>2007-06-16T21:58:00.001-05:00</published><updated>2007-07-02T11:46:31.245-05:00</updated><title type='text'>Online fraud in Mexico</title><content type='html'>Last week, the UNAM's Computer Security Conference was held at the Palacio de Mineria in Mexico city. One of the sponsors was Bancomer and there was a discussion panel between Bancomer and Banamex.&lt;br /&gt;&lt;br /&gt;The banks were trying to convince people that they do everything to protect your money online, the truth is, they just do the necessary to keep their business working and make profit of it.&lt;br /&gt;&lt;br /&gt;One guy at the audience asked them, about an internet portal dedicated to online frauds of Bancomer, Banamex and many other banks with mexican clients (like HSBC, Santander, etc.)&lt;br /&gt;I wrote down the URL (&lt;a href="http://www.robosbancarios.com/"&gt;http://www.robosbancarios.com&lt;/a&gt;), and today I visited the site; I've been reading some of the affairs, needless to say, banks in Mexico SUCK BIG TIME.&lt;br /&gt;&lt;br /&gt;I realized that I should asked to the bank guys why the hell they don't give details of the transactions to the affected clients, but I was busy with the conference organization. The banks justify saying they're following the "banking secret", the truth is they're just protecting criminals.&lt;br /&gt;&lt;br /&gt;Another form of fraud in Mexico, and very common, is the social engineering. It would be interesting to hear why the banks call to your home/office offering new credit cards and ask for personal data that any criminal can gather to steal your identity, and it's perfectly legal. It's a form of phishing and banks do nothing to stop the modus operandi, they should adopt an anti-phishing policy for phone calls.&lt;br /&gt;&lt;br /&gt;"Bancomer won't ask for personal information: Be suspicious of any unsolicited phone calls asking for your personal information", that would help a lot, but after all they are BANKS, they're more interested on getting new clients rather than protecting them.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-1528708492421611210?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/1528708492421611210/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=1528708492421611210' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/1528708492421611210'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/1528708492421611210'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/06/last-week-as-some-of-you-already-know.html' title='Online fraud in Mexico'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-3190475966263917675</id><published>2007-06-15T18:28:00.001-05:00</published><updated>2007-06-15T19:13:57.170-05:00</updated><title type='text'>Biometrics at UNAM-CERT</title><content type='html'>Finally, today the access control mechanism were setup at UNAM-CERT, consisting of proximity card and biometric (fingerprint).&lt;br /&gt;&lt;br /&gt;This mechanism is part of the new policy for SOC (Security Operations Center) at UNAM-CERT, DGSCA. The proximity card device has been the de-facto standard for a while, but the biometric gives added security to the scheme.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-3190475966263917675?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/3190475966263917675/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=3190475966263917675' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/3190475966263917675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/3190475966263917675'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/06/biometrics-at-unam-cert.html' title='Biometrics at UNAM-CERT'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2408579978663158415.post-4024249427886625417</id><published>2007-06-15T17:42:00.000-05:00</published><updated>2007-06-15T19:40:05.072-05:00</updated><title type='text'>Switching to blogger</title><content type='html'>This is an important day to this blog:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;first&lt;/span&gt;, because I'm moving from my home-made blogging tool to blogger, and&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;second &lt;/span&gt;because I'm switching from spanish to english language.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2408579978663158415-4024249427886625417?l=eduardomx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eduardomx.blogspot.com/feeds/4024249427886625417/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2408579978663158415&amp;postID=4024249427886625417' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/4024249427886625417'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2408579978663158415/posts/default/4024249427886625417'/><link rel='alternate' type='text/html' href='http://eduardomx.blogspot.com/2007/06/switching-to-blogger.html' title='Switching to blogger'/><author><name>Eduardo</name><uri>http://www.blogger.com/profile/04095708627771614159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_A7jpZtDdX-8/SfCpGGVIF4I/AAAAAAAAAEA/bQzBQBGUK2c/S220/yo-formal2.jpg'/></author><thr:total>0</thr:total></entry></feed>
