Showing posts with label Sam Bowne. Show all posts
Showing posts with label Sam Bowne. Show all posts

Wednesday, May 21, 2014

Pacific IT Professionals TechDays, June 5-6 in San Francisco

Excited to let everyone know that Pacific IT Professionals TechDays is happening June 5-6 in San Francisco. Only $200 this year for two days of awesome content, details below and please register right away we are down to only 50 spots left.


TECHDAYS-SF IS JUNE 5-6

Please register now for TechDays-SF which will be happening June 5-6 (so no June user group meeting). We have a great list of presentations and speakers. Please help us spread the word about the event and better yet, register at http://techdays.org/2014/04/register-for-3nd-annual-techdays-it-professional-conference/ This year we have lowered the price to $200, you really can't beat that. Details on sessions at http://techdays.org and the schedule is up on Eventboard.
Some great topics being covered: PowerShell, Microsoft System Center, Hyper-V, Lync plus many more.
Presented by folks such as: Jason Helmick, Darren Mar-Elia, Symon Perriman, Aleksandar Nikolic, Steve Evans and many more.
Please help us get the word out about the event. Twitter hashtag: #TechDaysSF

Some sample tweets:
  • Get what you need to know about Desired State Configuration with @jasonhelmick #TechDaysSF June 5-6 http://techdays.org
  • Don't miss @scevans talk on #DevOps, what is different and why you need to understand it #TechDaysSF June 5-6 http://techdays.org
  • Learn from @grouppolicyguy about Windows 8.1 Group Policy Features at #TechDaysSF June 5-6 http://techdays.org
  • If you want to learn the skinny on Lync then come hear @alexlewis at #TechDaysSF June 5-6 http://techdays.org
  • Time to learn Azure IaaS Automation with PowerShell w/ @alexandair at #TechDaysSF June 5-6 http://techdays.org
  • Windows Server 2012 R2: Preparing the Datacenter for a Private Cloud w/ @SymonPerriman at #TechDaysSF June 5-6 http://techdays.org


Location:
Microsoft, San Francisco Office
835 Market Street, Suite 700
San Francisco, CA 94103
Sessions summary: For session details, see EventBoard.
Name
Session Title
1
Sven Aelterman
Getting Started with MDT 2013 to Deploy Windows 8.1
2
Sven Aelterman
Application Deployment Tips and Tricks for MDT
3
Sam Bowne
Violent Python & The AV Scam
4
Eric Courville
Extending your reach with Powershells Custom Objects
5
Jennelle Crothers
Azure IaaS Hands On Lab – ½ day session
6
Jessica Deen
You’re not as important as you think you are
7
Jessica DeVita
Planning and building your first virtual machines in Azure
8
Daniel Egan
How to work with Developers
9
Matt Egen
App Deployment session of some kind?
10
Steve Evans
DevOps, What is Different and Why You Need to Understand IT
11
Steve Evans
Hyper-V Q&A
12
Cliff Galiher
Grappling with Hyper-V Networking in 2012 R2
13
Cliff Galiher
Confused About Clustering in Hyper-V?
14
Nick Hawkins
Microsoft Azure – Hyper-V Recovery Manager – How and why to use it
15
Jason Helmick
Manage, deploy and prevent drift with Desired State Configuration
16
Jason Helmick
Anywhere, Anytime, Any Device Management with PowerShell Web Access
17
Richard Hicks
Access Everywhere! Secure Remote Access to Public Cloud and On-Premises Resources with Windows Server 2012 R2
18
Laura Hunter
How MSIT does…” spiel on any number of Identity topics – How Microsoft IT Has Adopted O365 & Azure?
19
Laura Hunter
How MSIT does…” spiel on any number of Identity topics – Azure ADFS best practices?
20
Alex Lewis
How to Make Your Lync Deployment a Killer Success
21
Alex Lewis
Lync 2013 and Beyond
22
Alex Lewis
Lync – Integrating Communications into your Business
23
Darren Mar-Elia
Understanding & Leveraging new Group Policy Features in Windows 8.1
24
Sai Mukundan
StorSimple: Enabling Azure cloud storage for enterprise workloads
25
Kirk Munro
PowerShell Modules: Best Practices to Follow When Creating and Sharing PowerShell Modules with Colleagues and the Community At Large
26
Kirk Munro
Debugging PowerShell, Defensive Scripting Techniques and How to Cope With Red Error Text
27
Aleksandar Nikolic
Azure IaaS Automation with PowerShell
28
Aleksandar Nikolic
Getting Started with Windows PowerShell Workflow
29
Symon Perriman
Hybrid Cloud Capabilities with System Center 2012 R2 & Windows Azure
30
Symon Perriman
Windows Server 2012 R2: Introduction to Failover Clustering Fundamentals
31
Symon Perriman
Windows Server 2012 R2: Preparing the Datacenter for a Private Cloud
32
Symon Perriman
Introduction to System Center Application Management & DevOps for DevelopersorSystem Center 2012 R2: Virtual Machine Manager Overview
33
Isaac Roybal
Splunk for Microsoft Applications
34
Doug Spindler
Your privacy online – What your Like clicks tell the world about you
Remember that we have everything up on Eventboard and the application is available for every major mobile handset OS (yes, even Windows Phone 8!) so make sure to download and use that as it also allows you to fill out the survey questions per session.
We look forward to seeing you June 5th and 6th, 2014 in San Francisco, CA!!!



Monday, May 21, 2012

Free ICT Faculty Development Week Events


So far, 118 instructors have signed up for these free events,  
 75 for the northern California event, and 43 for the southern California event.

In northern California, the Web track 1 is now full and being wait-listed.  The Intermediate GIS track 2 is being cancelled due to low enrollment.

In southern California, the VMware track 3 is now full and being wait-listed.  Some other tracks are at risk for cancellation due to low enrollment.

Please spread the word with your peers about these outstanding faculty development opportunities.  Information and Communications Technologies advance quickly.  Programs and faculty that do not keep current with technologies and practices in ICT can quickly become outdated.  

These great opportunities to keep up are not only free, but you may also be eligible for stipend or expense reimbursements to attend.  

This is a rare and valuable opportunity to improve your knowledge, skills and programs, and network with your peers, thanks to the National Science Foundation and the California Community College Chancellor's office.

You are invited to attend either or both of these events.

2012 Summer Faculty Development Week
2012 Summer Faculty Development Week
















This summer, MPICT and the California Community College ICT Collaborative are co-hosting two very high quality, 4.5 day Faculty Development Week events:

SoCal FDW 
 Ohlone Photo


Click on the individual event links above to see the exceptional, updated multiple track offerings at each event.

Faculty Development Week is an opportunity to go deep and learn new technical content or teaching and learning skills.

Both of these events will be FREE for qualified community college instructors in ICT related programs, who may be eligible for stipendsor travel expense reimbursements to attend either or both events.  The Cisco Academy track in northern California is also covering high school teachers.

Check it out!

Register free at:


(It is possible these agendas will change some.  There is a lot going on at these events.  This is the best information we have for now.)

If after reviewing these agendas you still have questions, you can contact us at info@mpict.org or (415) 239-3600.

Tuesday, February 7, 2012

Hacker Group Anonymous Intercepted U.S. Call Over Investigation

"The U.S. government said the online hacker group Anonymous intercepted a telephone call between FBI agents and U.K. authorities involving a joint investigation of the group.

"Members of the hacker-activist group obtained details on a Jan. 17 conference call, including dial-in information, and posted a recording of it on Google Inc.’s YouTube website and other Internet sites, according to messages posted on Twitter accounts associated with Anonymous members..."

Bloomberg

Friday, July 1, 2011

Check Out MPICT's Q2 Newsletter!

Please check out MPICT's Q2 2011 newsletter!

It includes:

* Information about Faculty Development Week Earlier This Month
* Information on Building ICT Pathways From K-12 to College
* A Story About an International ICT Capstone Pilot Project with Paris, France
* A Call for a New MPICT Regional Partner!
* Information About the HI-TEC Conference in San Francisco in July

MPICT may be able to scramble up a few main conference passes if that would make it possible for you to attend. We cannot cover travel or pre-conference. If interested, please let us know.

Thursday, June 2, 2011

Legal Issues in the PBS Hack

LulzSec, a splinter group of Anomous, hacked PBS television this week. Here are a couple articles about it:


http://blogs.forbes.com/parmyolson/2011/05/31/interview-with-pbs-hackers-we-did-it-for-lulz-and-justice/



http://www.sfgate.com/cgi-bin/blogs/abraham/detail?entry_id=89990


Obviously, hacking in and stealing the data was wrong, but then things get less clear. Here's what I saw and did:

1. LULzsec posted the stolen data on Pastebin where anyone could find it
2. LULZSec tweeted links to the Pastebin dumps
3. I retweeted the LULZSec tweets

A couple people told me I was wrong in step 3, but I am confident my actions were legal and ethical.  But items 1 and 2 are less clear to me.

i asked Alex Muentz for a legal opinion, and here's what he sent me:

--------------------------------------

Re: legalities of LulzSec's PBS hack

Moral and ethical considerations aside, let's look to the law. Since PBS' web servers are engaged in interstate and international communications, they're protected under U.S. Federal law. By my limited understanding of what LulzSec actually did, they have committed at least three separate crimes, violating the Computer Fraud and Abuse Act and the Stored Communications Act.

I'm assuming the following for this analysis:
LulzSec is more than one person working together to a common goal.
LulzSec did not have permission to obtain or divulge PBS' secrets.
You (and other re-tweeters) are not members of or acting to further LulzSec's actions.

LulzSec's actions were as follows:
1. Accessed PBS servers without permission
2. Changed PBS' web page
3. Obtained information stored within, including logins and stored emails.
4. Divulged the obtained information by posting on Pastebin
5. Tweeted the links to Pastebin containing the PBS documents.

Other people, commenting on LulzSec's actions have re-tweeted the Pastebin links.

So, what laws did LulzSec violate?

Accessing non-public files on PBS servers-  The Computer Fraud and Abuse Act (codified at 18 USC 1030)  prohibits unauthorized access of computers of Federal interest, including computers used in interstate communication. By obtaining any information stored on PBS servers, LulzSec has violated 18 USC 1030(a)(2)(C), which reads as follows:

“intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains...information from any protected computer”.

LulzSec claims to have targeted PBS, so their actions (and access) were intentional. I am assuming that PBS did not grant LulzSec access to the private sections of their servers or their information. Since PBS' servers were Internet accessible and intended to facilitate communication between PBS and affiliate employees, they were used in interstate communication, thus making them a 'protected computer' under 18 USC 1030(e)(2)(B).

LulzSec's second violation of the CFAA would be the modification of PBS webpage. Section (a)(5)(A) of the CFAA bars the knowing transmission of a program, information, code or command that results in the intentional, unauthorized damage to a protected computer.

Presumably, once LulzSec obtained user rights on the PBS server, they had to tell it to change the web page served from that server.  While non-lawyers may disagree with the idea that merely modifying another's web page is 'damage', there is case law that supports this theory. Damages under the CFAA include costs of cleanup, securing a compromised server, identifying the attacker or performing a forensic examination.

Now, let's look to LulzSec's posting of PBS' information. The Stored Communications Act protects electronic communications held in storage. Unauthorized access to an 'electronic communications facility' and obtaining, altering or preventing the transmission of an electronic communication is a crime. By downloading any emails, forum posts to their or other computers, LulzSec has broken yet another Federal law.

Ok. Great. We know LulzSec has been naughty. So they obtained and posted private material. What about the re-tweeters?

All the re-tweeters are doing is pointing out the actions of another. If they're working with LulzSec to further their aims, perhaps an accessory or conspiracy theory could be used to find them liable. I'm assuming that you're not supporting LulzSec , but instead trying to comment on the actions of a criminal group.

Wednesday, April 20, 2011

Video of the IPv6 RA Attack

A student recorded this video, which makes it easier for people to quickly see the importance of the Windows IPv6 Router Advertisement vulnerability, without bothering with the technical details.



If you want a complete explanation of the attack, and recommended defenses, see:

http://samsclass.info/ipv6/proj/flood-router6a.htm

Monday, April 18, 2011

Why the Jester and Anonymous are Both Wrong

The opinions expressed below are mine, and not official positions of MPICT, CCSF, or any of my other employers.

I am writing this because it's too long to explain on Twitter, and the responses I get there make it clear that an explanation is needed.

In the USA, we have the legal system and the Bill of Rights for good reasons. If someone says something unpopular, you cannot silence them with force. But you are free to state your own opinion, too. That way we live in a noisy, chaotic culture, with many people saying things that are often wrong and offensive, and you have to win by saying better things, not by silencing your enemies.

Right now the Jester (@th3j35t3r) and Anonymous are taking down many Web sites with DoS and DDoS attacks. Several Anonymous participants have been arrested, but so far the Jester has escaped capture, probably because his cyber-weapons are more advanced and he works alone.

Both the Jester and Anonymous are wrong. They are breaking the law, and denying others their Constitutional rights. And since their targets are often political and religious, they damage our most fundamental freedoms. It is essential to let people with religious or political messages speak freely, so people can make informed decisions about them.

At first, the Jester took down sites he called Jihadist, saying they were participating in terrorism. It is possible that some of those were not in the USA, or perhaps even legitimate military targets; but it is obvious that the Jester did not have legal authority to attack them. But then he took down Wikileaks and the Westboro Baptist Church (WBC). While Wikileaks was hosted on American servers, it should have enjoyed the protections of the American legal system, and the WBC certainly should. The WBC is a religous and political organization, and in America, so they are very strongly protected. Their protests and Web sites are outrageous and offensive, of course, but silencing them by force is illegal.

The Jester's campaign is self-destructive. If he continues on his current path, he will be stopped by external forces, and probably end up in prison. People who cheer for him and encourage him are not his friends. I'd like to see him stop before it comes to that.

People are saying I am unpatriotic and disrespectful towards the Jester, but I don't see it that way. I support the Constitution, and I say the Jester needs to stop his crimes. That's what he needs to hear, not what he wants to hear.

EDIT: I changed 'projections' to 'protections' in the 3rd-to-last paragraph at 5:04 pm April 22, 2011 (ty @attritionorg)

Friday, April 15, 2011

Teaching Networking with scapy

The Python package "scapy" is a wonderful teaching and research tool. It provides a simple interactive environment you can use to build network packets in, and you can use it in scripts as well to make simple scanners, attack tools, Intrusion Detection Systems, etc.

It's really good for students to craft packets directly, so they understand how IP, ICMP, TCP, and UDP really work at a low level.

For example, here is "yesman"--a script that answers every SYN with a SYN/ACK.



When an attacker runs a port scan on a network protected by yesman, every port on every machine appears to be open, making the scan slow and useless.



I have assigned my students a series of projects learning scapy, and here they are so you can use them too:

Intro to scapy

TCP Handshake with scapy

IPv6 with scapy

Router Advertisements with scapy

Slow Loris Attack with scapy

yesman--Scanner Honeypot with scapy

As always, everyone is free to use these materials for teaching, research, or any other legal purpose. If you break the law, you may get into trouble, and I won't be able to save you.

Tuesday, April 12, 2011

Serious Windows Flaw

A few weeks ago, I was testing some tools in Backtrack Linux. I started flood_router6, which sends hundreds of IPv6 Router Advertisement packets onto the network each second. I had planned to view the result on a Windows 7 machine, but it was frozen. The mouse had no effect, and I had to completely turn off the power to revive it. I posted a tweet about it, and tried again, this time cancelling the attack after just one or two seconds. The machine was not totally frozen, so I ran IPCONFIG and saw this--hundreds of IPv6 addresses (click image to make it bigger):



This will not be a good homework assignment, I decided, because students will just crash the machines before they can examine them. But wait--Router Advertisements are not unicast traffic! They are sent to ff02::1, the "all-nodes multicast address", so this single Linux machine will stop every Windows machine on a whole network. And all the Windows servers too!

This was too hot to handle, so I sent out some frantic tweets, asking for a security contact inside Microsoft, ASAP. And my friends came through--within a few hours I had reached the right people, and within two days I had Microsoft's response. Here's what they said:

1. This was not news to them. As I later found out, Microsoft had been alerted to this in July of 2010.

2. They don't care. Microsoft has no intention of patching this at all.

Whoever made those decisions at Microsoft has simply not thought it through. What will they say when a whole financial company goes down, or a government office, or industrial machinery, or a hospital, because of this attack? How can they escape liability when it is a matter of public record that a serious defect exists in their products and they do nothing?

This is a common situation in the field of network security: you find something AWFUL, and management ignores you. I often discuss this with my students. Common responses are to get drunk, start insulting your bosses, sabotage your own network, send secrets to Wikileaks, etc. Those are the self-destructive, counterrproductive responses which I don't recommend. The right thing to do is inform and protect people in a reasonable manner.

So here's what I did. I wrote a weaker, slower form of the attack so it could be used as homework without crashing the target machine, and also ported it to Windows, so I can easily use it in classes and demonstrations. And I wrote a talk proposal for Black Hat, the most important security conference in the world for CSO-level executives. If my talk is accepted, I will go there and kill a network of Windows machines on stage. And I will tell them how to protect their machines. So they will be safer, and perhaps they will go suggest to Microsoft that they think again about just leaving this hole unplugged.

If you want more information, and several projects ready to use in classes, see this page:
http://samsclass.info/ipv6/proj/flood-router6a.htm. I have also listed ways to protect yourself there.

Friday, February 4, 2011

Ethical Hacking and LIGATT Security

Legal Note:  The opinions stated here are my own, and do not necessarily
represent the positions of MPICT, CCSF, or any of my other employers.  (Sam
Bowne)

It's frustrating to deal with criminals, online or otherwise.  The process
of collecting evidence legally, preparing documents, trials, etc. is slow,
and frequently bad guys escape punishment.  And the temptation to cut
corners and go outside the system is always there.  I saw this whole thing
happen this week in a case I am personally involved in, and I am documenting
it as a case study.


Gregory Evans runs a company named LIGATT security, which has been notorious
in the information security community for years.  He has been accused of
plagiarism, falsifying his credentials, threatening researchers, and many
other misdeeds, as detailed on Attrition.org;


http://attrition.org/errata/charlatan/gregory_evans/


A lot of security professionals have been resisting Evans' activities,
including me.  It is particularly galling that he is a media celebrity,
appearing as a security expert on CNN, Fox News, Bloomberg, and Time
magazine.  So we complain about his actions to media companies, conference
organizers, accrediting bodies, and potential victims.  And many lawsuits
are being prepared and filed on both sides.  It all takes time and energy,
and has very little immediate effect.  But as security professionals, we all
should understand the process.  We face the same frustration convincing
corporate and government administrations to change poor practices, and
patience is an essential job skill.  Entrenched bad habits can only be fixed
by slow erosion, like water digging through stone.


This week, someone ran out of patience with Evans.  He got hacked.  Two of
his sites went down completely, and his entire email database was stolen and
released onto the torrents.  These emails reportedly include personal
information about Evans, his contacts and his victims. The thief couldn't
even be bothered to use a search-and-replace function to remove Social
Security numbers, bank account routing numbers, etc.  Details are posted
here:


http://www.thetechherald.com/article.php/201105/6775/Ligatt-Security-breached-company-emails-hijacked-and-sent-to-public


I cannot condemn all this strongly enough.  Allowing criminals to drag you
down to their level and become a criminal too is a terrible mistake.  The
difference between ethical security professionals and criminal hackers is
that we have the maturity and patience to proceed slowly and carefully
within the system.


I disapprove of Gregory Evans and his harmful actions strongly, and I have
been working to stop them.  But this is not a personal fistfight with the
goal of bringing him down by any means necessary.  My goal is to help make
the Internet safer for everyone, and protect innocent people.  I cannot see
how adding lawless vigilantes to the ecosystem helps that process.


We have laws, courts, police, and governments for good reasons.  I am bound
by the (ISC)^2 code of ethics, and so are my students:


https://www.isc2.org/uploadedFiles/(ISC)2_Public_Content/Code_of_Ethics/ISC2-Code-of-Ethics.pdf


I want to remind my students and all other aspiring security professionals
to stay out of criminal schemes.  Don't help Anonymous take down websites,
don't steal copyrighted materials, and don't hack into other people's
systems, even if you dislike what they are doing.  Becoming a criminal
yourself does not stop crime--it increases it.  Comic books are escapist
fantasies--in the real world, vigilantes are no better than the people they
oppose.