Archive for February, 2010

28
Feb

Koobface Proxies SUCK

Although I’ve been collecting and reporting on them ever since they first showed up last year, I had never tried to use a Koobface (port 8085) proxy until a few days ago.  The reason being, I tend to avoid using US, UK, and Canadian proxies out of pure legal paranoia.  I like to keep my ass covered.

So when a French Koobface proxy showed up on The List last week I thought I’d give it a shot.

It sucked out loud.

No matter what URL I punched in, it would only take me to the top level of the site, which makes me wonder how the Hell it ever passed a proxy judge, since none of them are top-level URLs.  After a dozen or so clicks, it just stopped working.  I couldn’t even connect.

Once it died I had to think twice about the wisdom of using a Koober proxy for anything, even “educational” purposes. A connection to port 8085 could be a Big Red Flag to anyone with half a lick of security sense monitoring the line here or in France or anywhere in between. And don’t kid yourself, “they” are watching.

That’s why port 80 proxies are probably best (or maybe third, with SSL at number one followed closely by a SOCKS proxy on an oddball port). Hiding in plain site is a good way to go.

23
Feb

2.5 MILLION PROXIES!!!

Actually, 2,499,909 at this very moment but we should hit the magic milestone by midnight.

Business has been picking up.  After the last proxy purge I didn’t even have to run a resurrection to get a decent number of pages up.

Koobface has been making a comeback, if the number of U.S.A. proxies running on port 8085 is any indication (and it usually is).

Even the Cameroonians should be happy, given the number of UK proxies that have been popping up in the last few weeks.  Push those puppies, boys!

This surge in new proxies reaffirms my opinion that this is a seasonal business.  The exact same thing happened last year and we should continue to see more and more fresh proxies until November, when the whole thing will come crashing down once again.

We should hit the three million mark by August.

11
Feb

Security DICKs & ASSCLOWNs

I never really wanted to be a Hot Shot IT Security Guru.  It just sort of happened that way.  Ten years ago I was working as a Web master’s apprentice at a dot-com and mentioned something about a patch Microsoft had just released.

Next thing I knew I was responsible for security of the Web site.

Lucky for me, I got out before everyone was laid off (although I should have stayed just to get the severance pay).  When my new employer learned that I was the Old Security Guy at a dot-com (me and my Big Mouth) I immediately became the New Security Guy.

That was ten years ago.  I am really beginning to hate this job.  Not only is the entire Security Industry a Total Utter Failure, but the people in it are all dicks and assclowns.

Every man Jack of them.

Take, for instance, this recent thread at Full Disclosure.  It didn’t start at Full Disclosure.  It started out in a Security Wannabee mailing list.  Some newb was wondering out loud about how to program a “secure” SMS banking program.

I’m designing an SMS baking application but i need to research on the security risks involved first. I’m thinking of subscribing mobile phone number along with a pin…

Little did he know he was starting an Epic Troll.  First, he attracted a number of security dicks, who basically poo-pooed his approach and warned of the insecurities of SMS.

Then, the assclown showed up.

I have been aware of this OCD whack-job for several years.  Back in the early days of GMail (when you could still get away with it) I used to mark all of his messages to the security lists I subscribe to as SPAM.  He is just that annoying.

If you ever want to pull/troll this guy out of the woodwork and watch him froth, just join the wannabees list and post something about “security by obscurity”.

Most “Security Pros” despise security by obscurity simply because it rhymes.  Or maybe it just makes it easier for them to remember that they hate it.  Many have lost track of what it actually means and as a result it’s a great security list troll topic, right up there with automotive industry analogies (which are almost universally despised in security mailing lists these days – try it sometime).

So this man, A Legend In His Own Mind, shows up and the thread instantly becomes a pissing match.  After 16 messages the head dick drags the argument out of Wannabees and into Full Disclosure and the real fun begins.

Normally I tend to ignore these things.  One of the benefits of reading security mailing lists in GMail is you can construct a filter to instantly delete annoying threads like these (I have dozens and dozens of them).

It’s not my point to give a blow by blow synopsis of the Full Disclosure thread.  If you’re really interested, read it.  It’s still going on as I write this.

But it is the finest example of why I hate this industry and the people in it.

10
Feb

Two Days In A Row

I suppose the power company had to test our new smart grid meter by forcing an outage.

Everything died again.  At about the same time, too.  Even though, unlike the last two times, it wasn’t snowing at all.

And it’s very evident that the UPS that powers my lifeline to the Web must be toast, because it didn’t start back up when the power came on.

I have a lot of catching up to do on other projects. But enough of my problems.  Things will be back to normal at 8PM EST.  Maybe we’ll make it all the way through Thursday.

09
Feb

Stupid Smart Grid

My electric company decided to upgrade our house and installed a “smart grid” meter early this morning.

Of course, it killed the proxy project for most of the day.

Things are back on schedule now.

08
Feb

Former Proxy “Supplier” In The News

It seems one of my former Russian “suppliers” (in quotes because he didn’t actually know he was a supplier) has made some news.

And it’s not good news.

It turns out he’s a Very Bad Man (I keep telling you kids that proxies are evil but you never listen).  He’s allegedly been running a Zeus botnet and recently sent some (very good) targeted SPAM to .gov and .mil domains.  I know it’s good because I’ve seen it first hand (and you can conclude whatever you want from that information).

So anyway, for what it’s worth, the story is here.

There’s also some security clown on BlogSpot who has written some nasty stuff about him, but I won’t give him a link.  He’s not a “major player” in the security field, but he’s quite a number of notches up from Yours Truly.  He is the kind of security dude who gets all worked up about “criminals” and if I give him a link, it would be instant guilt by association and the next thing you know he’d be calling me all sorts of bad names, too.

In fact I’m not all that crazy about giving that douchebag Krebs a link, either.

The Russian supplier got taken down some time in the Fall of 2008.  I remember it well because his site disappeared about the same time the Security Industry (and Mutual Masturbation Society) was giving themselves a huge pat on the back for taking down Estdomains.

I briefly mentioned it here, sixth paragraph down.

But, dammit, he was a good supplier.  He ran a “for pay” proxy site but his security was bad enough to leak out his subscribers’ private URLs (thanks, Google).  When he disappeared I put his name and the site name in a pair of Google News Alerts, waiting for the day when he’d put his proxy site back up.

And now this shows up.

At least we know he’s still alive.

06
Feb

Blizzard of ’10 Strikes!

The power went out for five hours last night. It killed the 4AM run and everything else.

Hopefully, the next update will be at 8:00AM EST.

10AM UPDATE

The fucking netfilter ftp modules didn’t load.

In fact, nothing in rc.local ran on the firewall box.