<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT-security &#8211; Tomorrow in retrospect</title>
	<atom:link href="https://erik.zalitis.se/category/it-security/feed/" rel="self" type="application/rss+xml" />
	<link>https://erik.zalitis.se</link>
	<description>- My thoughts but no prayers</description>
	<lastBuildDate>Sat, 23 May 2026 15:08:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://erik.zalitis.se/wp-content/uploads/2020/05/cropped-ezs-1024x659-1-32x32.png</url>
	<title>IT-security &#8211; Tomorrow in retrospect</title>
	<link>https://erik.zalitis.se</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">178113661</site>	<item>
		<title>The inventor</title>
		<link>https://erik.zalitis.se/personal-thoughts/the-inventor/</link>
					<comments>https://erik.zalitis.se/personal-thoughts/the-inventor/#respond</comments>
		
		<dc:creator><![CDATA[Erik Zalitis]]></dc:creator>
		<pubDate>Wed, 19 Nov 2025 18:29:28 +0000</pubDate>
				<category><![CDATA[IT-security]]></category>
		<category><![CDATA[Personal thoughts]]></category>
		<guid isPermaLink="false">https://erik.zalitis.se/?p=1916</guid>

					<description><![CDATA[This is a story about a podcast I and a friend run and the strangest interview I have ever been part of. It turned out to be a great learning experience, but I must start the story in 2013, before the podcast even existed.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">This is a story about a podcast I and a friend run and the strangest interview I have ever been part of. It turned out to be a great learning experience, but I must start the story in 2013, before the podcast even existed.</p>



<p class="wp-block-paragraph">I was a new employee in a company, working as a security specialist. My first assignment was a brand-new encryption solution that I was asked to evaluate. My manager wanted me to tell him if this product was worth investigating further or not. I was given a production presentation pamphlet. It was something you don&#8217;t hear every day: a Swedish company offering a totally new encryption solution. It was one of those startups that had gotten a healthy injection of cash from a &#8220;corporate angel&#8221;. In short, they were given money to realize a new solution. It was presented as something brand new and never seen before. It didn&#8217;t need any keys, passphrases or other information that could give away the secrecy of the data. Also, it was based on a security protocol that the inventor of the solution had invented herself. And it also boosted that it was patented and the patent registration number was printed in the pamphlet.</p>



<p class="wp-block-paragraph">It was easy for me to get the patent document from the patent office. It read as the same &#8220;marketing fluff&#8221; that the pamphlet did with the addition of a generic diagram and some text talking about quantum encryption. Most of the statements raised red flags for me. I will explain shortly why. Then I thought that &#8220;maybe there is something to download to test it?&#8221;. No download links and no instructions on who to contact at sales to get a trial version. Checking their website and other sources gave me no further information. I started doubting that they had some sort of software solution ready. This was weird. The company was at the time a few years old. &#8220;They got to have some sort of beta&#8221;, I thought. But nothing came up anywhere. I noted to my manager that I didn&#8217;t recommend going any further with this solution. My manager wasn&#8217;t a bit surprised. He had read the marketing text and didn&#8217;t think it was interesting to pursue further. Fair enough, not all things on the market are worth the effort. There&#8217;s nothing strange about that.</p>



<p class="wp-block-paragraph">A few years later I read a popular Swedish magazine where a reviewer had gone through the solution. The most interesting part of the article was when he commented on the claim about &#8220;quantum properties&#8221;. The marketing text stated that the solution through quantum properties could detect if someone was eavesdropping the encrypted data. Not hacking or trying to decrypt it. Just watching the packet stream would set off an alert. This was claimed to work on any kind of connection. The reviewer noted that an ethernet connection as opposed to a fiber optic connection doesn&#8217;t have quantum properties. The claim was wrong as this feature could not work. It was physically impossible.</p>



<p class="wp-block-paragraph">Years passed and in 2018 me and a friend decided to start a podcast together. We both worked at the same company at the time and in the IT security industry. So, it was clear we would cover the IT-security field. That&#8217;s a story for another day, though. A few months later we were offered a sponsorship by a large security organization in Sweden. This included that they sent interesting IT-security and info security lecturers for us to interview. We started doing regular interviews during the spring and it continued.</p>



<p class="wp-block-paragraph">In the summer the other host went on vacation, and I decided to take the reins of the podcast myself during his vacation. I ran the show, covering the events in the IT-security field during each week. One of the last podcasts I made before he came back was about the inventor and her company. I was careful not to mention her name or the name of the company. But I talked about the claim that she had invented an encryption protocol herself. This is generally a very bad thing to do. Especially if you don&#8217;t make the solution open. Her encryption, if it existed at all, was closed source. Microsoft made this mistake in the 90s when they released Windows 95. It had the passwords of the users stored in passwordlist-files. Those encrypted .pwl-files were built so no one got to know how they worked and that was supposed to be secure. It was not. Not by a long shot. Hackers had a field day with the solution and what little security Windows 95 could offer was lost. The .pwl files were properly hacked and became useless. A new encryption format must go through years of vetting and attacks before getting trusted for implementation in standards. Some encryption standards that were considered secure, have been broken over the years and then stopped being used. This is the harsh reality and the reason why this was a red flag for me. I noted this on the podcast.</p>



<p class="wp-block-paragraph">This is where it got interesting. What happened next was something I would never have seen coming. Our contact in the organization suggested another guest for our podcast. He said she was a bit controversial but may be interesting. We had to decide ourselves if she fit the podcast. She had invented her own encryption. You guessed it, it was her and it was the very same solution that I had evaluated previously. Who would have thought? What was the likelihood of our paths crossing? Me and the other host agreed to allow her on. It was a bit of risk taking, but a self-made inventor could be interesting to have on. I silently wondered if we knew what we had gotten ourselves into. We had no idea…</p>



<p class="wp-block-paragraph">It was a nice day in autumn when she arrived at our work office. We led her to a conference room we had been allowed to use. She told us she had just come back from a large company nearby. She had been presenting her product to them, and she seemed to be very hopeful of it leading to some business for her company.</p>



<p class="wp-block-paragraph">&nbsp;The recording went off to a bad start. It wasn&#8217;t her fault. It was mine. She spoke about prime numbers, and I explained what that was. Got the explanation right but also suggested a few numbers that were prime numbers. Among them was 9, which is not a prime number at all. It&#8217;s divisible by 3. I got to hear that a number (haha!) of times from listeners and thought there was no end of it. What happened next was worse. She claimed that her cryptography did not use mathematics and pointed to a matrix with binary numbers she drew on the whiteboard. Listeners could not see that, but if they had, they would probably have drawn the conclusion I did: a matrix, a mathematical thing. At least I learned to use them in math class in school way back when. Either way, I have never heard about cryptography not using math. I tried a conversation starter by telling her that her solution reminded me of the Kerberos protocol. That did not sit well with her. I started worrying that she might stand up and walk out on us if we asked the wrong questions. It was probably not what we should have done. She was kind of worked up from my question. We really didn&#8217;t know how to challenge her different views on how encryption was to be done. In the end, she told us her point of view without much intervention. We thanked her for her time and then stopped recording.</p>



<p class="wp-block-paragraph">What she said later totally should have gone into the recording but didn&#8217;t. It was interesting and unexpected. The first thing was that she was going to teach herself Microsoft C#, a popular programming language, to be able to build the software solution. I could hardly believe that I heard her right. At this time, her company was 10 years old. It confirmed what I suspected from the beginning: there was no functioning solution. They basically had an unrealized idea that yet had to materialize. This is kind of the most long-standing &#8220;vapor ware&#8221; I have ever heard of. What could she really sell to an interested customer if she had no solution ready? Then came the next thing she said. She told us of her quantum computer that she had in her cellar. Some background: quantum computing is bleeding edge research technology. Companies like Microsoft, IBM and Google pour loads of money into their projects to create the first quantum computer capable of reaching the goal of being powerful enough to bring massive parallel computing to this world. This technology advances but is many years away from being done. Back when this interview was conducted there were just a handful of quantum computers in the world. Somehow, she had one in her cellar. Such statements are impossible to verify unless you look in her cellar, I guess. This left me wondering exactly why she said something like that.</p>



<p class="wp-block-paragraph">We went home to our respective homes, and the episode was uploaded and spread though the podcast services on time and to a waiting community. The response came a few days later.</p>



<p class="wp-block-paragraph">Someone posted a message in a Swedish Facebook group specializing in IT-security. This message was about the interview, and it was surprisingly respectful for an angry take on our podcast. The people posting in the thread called us out and wondered why we had put her on the show. They also wondered if we knew anything about cryptography, given that we didn&#8217;t question anything she said. And few days later someone posted a new post without knowing about the first one. There were the same critical questions about the interview. We responded the best we could.</p>



<p class="wp-block-paragraph">Something good came out of it. A man working with cryptography in a Swedish university offered himself as a guest on our show. We let him on, and it became a good introduction to cryptography and quantum computing. The calmness began to come back to our world. This is the end of the story, right. Nooooo… Not by any stretch of imagination.</p>



<p class="wp-block-paragraph">Time passed and we continued producing podcast episodes. Months passed, but one day I got an email from a listener. It was addressed to me and asked me if I believed in her solution. At this time, I had to be careful what to respond. I didn&#8217;t want to be too negative about it. I noted that all I had to do was to say it like it was. I responded something like &#8220;there is no product to test in order to evaluate its capabilities. Until such a solution exists and can be tested, I do not believe it works. If I ever get to test it, it&#8217;s unlikely I will believe in it. But let me at least try&#8221;. I felt pretty good about that answer.</p>



<p class="wp-block-paragraph">20 minutes later, I stood outside the building I work in, so I could get some fresh air. Then the phone rang. It was her and she wanted to talk to my manager. It was a moment of &#8220;ouch, dammit!&#8221;. It wasn&#8217;t just my direct manager she wanted to talk to. Not even the CEO of my company. Nope, she wanted to talk to the CEO of the company group. I thought I was going to get into some hot water. But she was nice and polite. I gave her his number. Then I went back to the office and sent him a message. I asked him to be a bit on the skeptical side with her. I got no response from either of them. It later struck me that it was probably just a coincidence she called me at the time she did. She most likely wanted to do a sales pitch. It was not her with a fake name I had mailed back to. A sigh of relief later it was all forgotten.</p>



<p class="wp-block-paragraph">More time went on. Months later I got a message from her. She wanted to come again as a guest of our show. I didn&#8217;t have the heart to tell her no. I asked her to come back to her later. Time passed and I didn&#8217;t hear from her at all and forgot about it.</p>



<p class="wp-block-paragraph">This story has a sad ending. One day I saw a message from her daughter on social media telling us that the inventor, her mother, had passed away recently.</p>



<p class="wp-block-paragraph">There is an old saying: &#8220;Don’t speak ill of the dead&#8221;. I really don&#8217;t want to do that either. Remember that my first experience with their security product was before I even met her. My whole point is to tell a story about working in the IT industry. We must be hard on security companies, because so much of our society will be entrusted to their protection. It&#8217;s nothing personal really.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://erik.zalitis.se/personal-thoughts/the-inventor/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1916</post-id>	</item>
		<item>
		<title>Netizenship needs to come back!</title>
		<link>https://erik.zalitis.se/personal-thoughts/netizenship-needs-to-come-back/</link>
					<comments>https://erik.zalitis.se/personal-thoughts/netizenship-needs-to-come-back/#respond</comments>
		
		<dc:creator><![CDATA[Erik Zalitis]]></dc:creator>
		<pubDate>Sat, 21 May 2022 10:18:33 +0000</pubDate>
				<category><![CDATA[Computing]]></category>
		<category><![CDATA[IT-security]]></category>
		<category><![CDATA[Personal thoughts]]></category>
		<guid isPermaLink="false">https://erik.zalitis.se/?p=1499</guid>

					<description><![CDATA[Back in the 90s, I learned about the term "Netizenship". I learned it from Usenet, as Internet wasn't a thing (at least for me) back then. It is a portmanteau of the words "Citizenship" and "Net". If you access a local- or global network with more users on it, you’re a Netizen. As in “you live as a member of a village”. Yes, it harkens back to the days of the "Global village" discussion, and its come back in the 90s. I won’t bother you with the details. Suffice to say this: netizenship was important. It's the computer equivalent of "Above all, cause no harm". In short: as a network user you must not become a problem for others.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>All right. The connection between this graph and Netizen may feel weak. But remember that the idea of netizenship started years before the whole play field changed. It may be what can push it back into feeling much, but thinking more, instead of feelings out of control and little thinking. Am I right?</em></p>



<p class="wp-block-paragraph">Back in the 90s, I learned about the term &#8220;Netizenship&#8221;. I learned it from Usenet, as Internet wasn&#8217;t a thing (at least for me) back then. It is a portmanteau of the words &#8220;Citizenship&#8221; and &#8220;Net&#8221;. If you access a local- or global network with more users on it, you’re a Netizen. As in “you live as a member of a village”. Yes, it harkens back to the days of the &#8220;Global village&#8221; discussion, and its come back in the 90s. I won’t bother you with the details. Suffice to say this: netizenship was important. It&#8217;s the computer equivalent of &#8220;Above all, cause no harm&#8221;. In short: as a network user you must not become a problem for others.</p>



<p class="wp-block-paragraph">A true netizen (not that Scotsman fallacy!) must act in a proper, non-aggressive and secure manner. I found out that there is an old, but oddly useful RFC called RFC1855, describing among other things how to &#8220;Be conservative in what you send and liberal in what you receive.&#8221;. That&#8217;s not a political statement, but a rule that truly fits today. In short don&#8217;t blow a fuse when people write stuff that is dumb or hateful and choose your own words well. Just imagine everyone applying that on Twitter, and I don&#8217;t think Elon Musk would have bought the company. Yes, I wrote that! Twitter is what it is DUE to the raging wars, no despite it. And social media builds on this divide. &#8220;Digital divide&#8221; used to mean those with access to Internet vs those without. Today, it&#8217;s a false dichotomy of &#8220;angry left&#8221; vs &#8220;raging right&#8221; or &#8220;whatever&#8221; vs &#8220;whatever else&#8221;. We don&#8217;t need that. It&#8217;s like going to a bar, meeting some drinking buddies, and then starting a fight over soccer teams or political parties. Please don&#8217;t. It was nice when it was just drinking beer and talking about everything and everyone.</p>



<p class="wp-block-paragraph">But my main intent of this text is not just social issues and proper behavior. IT-security must now be in the driver seat. A modern netizen MUST consider his or her presence when online and offline. A good netizen should always know that lax security on their part, can, and probably WILL constitute an emergency on someone else side of the net. I mean, if your work or private account gets hacked, because you have bad password discipline, that account can be used in your good name to send malicious email to others. That&#8217;s just an example. There are many ways this can play out against you and others. Back in the naughties, we had the &#8220;security triad&#8221; of &#8220;Firewall, patching and antivirus&#8221;. It was a mantra, that we were told. Was it a bad idea? No, absolutely not. That was a part of netizenship even when the term was long gone. But it&#8217;s 2022 today, and the list of obligations to stay secure is growing and changing fast.</p>



<p class="wp-block-paragraph">I think, as the headline said, that we should take the term back. Internet has been libertarian since its popularization in the 90s. But it never was meant as an anarchy. Self-governing and making ourselves and others into informed users was what it was meant to be. If we want that to be true now, we&#8217;re probably out of luck. But Internet is still somewhat free. In some parts of the world. And this puts the responsibility on YOU and me! We must keep your equipment safe, our manners at least somewhat decent and educate ourselves in being observant. A citizen should &#8220;trust but verify&#8221; and so must a netizen. In short, we must understand better than to Google for what we already believe in, stop helping in spreading unverified rumours, cease and desist connecting insecure stuff directly to the Internet because &#8220;who cares?&#8221; and remember where we came from. I saw texts from 1979 on one of the first Swedish bulletin board systems and it had a lot of disagreements. And, yes, drama and nasty comments. This has not changed a bit. BUT. The SCALE of things has. Everyone and their dog are a netizen (ever heard about electronic dog collars?) today.</p>



<p class="wp-block-paragraph">If we intend the Internet to be more of a positive than a negative force in this world, we must bring netizenship back! Not regulate it &#8211; foster it! Inspire it &#8211; not force it. Talk about consequences for others when you&#8217;re not acting properly rather than forbidding certain words, views, and ideas. Laws still apply, that will not change. The Internet does not give you the right to do illegal stuff (which jurisdiction, btw?) or to harm others. But if we cannot get our act together, a lot of things that are acceptable today, may be illegal tomorrow.</p>



<p class="wp-block-paragraph">How to become a netizen, summed up in a few points, that will not form a complete list:</p>



<ul class="wp-block-list"><li>“We hold these truths to be self-evident” does not mean “Hey, it does not specifically forbid that dumb thing I want to do, so I will”.</li><li>“Free speech” means that the government (if you’re lucky to live under such a government) cannot censure you. You still cannot spew racist comments on a cat pedigree forum if the admins don’t want you to (they won’t!).</li><li>You may have a right to speak, but I have no obligation to listen. Same is true in reverse.</li><li>Writing dumb and incendiary stuff is probably legal – but you will face a backlash if you make that a habit. A Swedish proverb: “Angry cats get their skin torn”.</li><li>Fox Mulder “wanted to believe”. A netizen needs to get in the know.</li><li>Learn to observe and place your naivete outside the Internet connection.</li><li>Netizens inform others when needed, try to understand who they’re communicating with when doing so and say something when they see something.</li><li>It’s not mandatory to be a netizen, but it may be what keeps the Internet from becoming a controlled zone where you cannot voice some opinions.</li><li>If your opinions are always controversial to large groups of other people, nurture the thought that those people may not be the problem.</li><li>If it feels wrong or bad in a conversation, disconnect! Pull the plug or the better yet, the mains circuit breaker.</li><li>Trustno1 is a poor password, but a decent way of navigating the Internet until you have unlooked the “Trust but verify” skill in your netizen skill tree.</li><li>Microsoft once wrote something like “If someone controls your computer, it’s no longer yours”. Given their track record when it comes to IT-security, that is hilarious. It’s also very true.</li><li>Unique passwords and multi-factor authentication. That’s where it’s at today. I’m not selling running shoes but must still say this: “Just do it”.</li><li>It’s advisable not to be an arse. That is the beginning of the road to true enlightenment, netizenship and maybe one day getting married.</li><li>Open your mind a bit and close the firewall a lot.</li><li>The internet is not the Twilight zone. That would be the dark net.</li><li>OSSINT is a word you MUST understand and consider when on the Internet. Google for it if you don’t know what it means. Just don’t Bing for it, then you will never find it.</li><li>Authentication is meant to make sure that you know who you’re really talking to. It does not work. Always been that way.</li><li>If you try to be anonymous, you will shine like a beacon. Try to be like everyone else, it works better.</li><li>Make sure your brain is connected, before checking the keyboard cable.</li><li>If keyboard is not found, please press ‘F1’ to proceed. If brain is not working, don’t press any key.</li><li>”Cool app. I can age my face 40 years. I gotta check it out”. Great, soon you will wonder why the airport security in the banana republic you travel to immediately recognize you.</li><li>Looking at cat videos on YouTube for a whole day every now and then, causes no harm. Cats are cool and you won’t have time to vent your frustration about some dumb stuff some celebrity did, when you are on Twitter. Dogs are also nice.</li><li>Create stuff because you love to. Not because you want to be famous. That place is already taken. And not by you or me.</li><li>If you write tweets, short posts on Facebook or show your lunch on Instagram all the time, you’re draining your creativity pool. This way, you are content enough not to write the great novel, the scary radio drama, the great software, mixing up that strange new mint-flavored Whiskey or maybe writing a new secure communication protocol. Some of that would be sad if not ever created.</li><li>Don’t get angry. Don’t get even. Go somewhere else.</li><li>Being agreeable leads to Netizenship. Want to learn more?</li></ul>



<h2 class="wp-block-heading">Links:</h2>



<p class="wp-block-paragraph"><a href="http://cybra.p.lodz.pl/Content/1081/issues/issue3_7/preface/index.html">http://cybra.p.lodz.pl/Content/1081/issues/issue3_7/preface/index.html</a></p>



<p class="wp-block-paragraph"><a href="https://datatracker.ietf.org/doc/html/rfc1855">https://datatracker.ietf.org/doc/html/rfc1855</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://erik.zalitis.se/personal-thoughts/netizenship-needs-to-come-back/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1499</post-id>	</item>
		<item>
		<title>What a real buffer overwrite may look like</title>
		<link>https://erik.zalitis.se/tin-foil-hattery/what-a-real-buffer-overwrite-may-look-like/</link>
					<comments>https://erik.zalitis.se/tin-foil-hattery/what-a-real-buffer-overwrite-may-look-like/#respond</comments>
		
		<dc:creator><![CDATA[Erik Zalitis]]></dc:creator>
		<pubDate>Tue, 16 Nov 2021 17:42:40 +0000</pubDate>
				<category><![CDATA[IT-security]]></category>
		<category><![CDATA[Tin foil hattery]]></category>
		<guid isPermaLink="false">https://erik.zalitis.se/?p=1280</guid>

					<description><![CDATA[What little remains of the charred corpse of the firefox...]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">In 2018 I got my Firefox hacked! It was over as fast as it was done. First Firefox crashed. It was fully patched and I had an Apparmor profile on Ubuntu in full enforcemode. Here are the log entries:</p>



<p class="wp-block-paragraph">May 25 20:17:06 molly kernel: [&nbsp; 372.984627] audit: type=1400 audit(1527272226.649:102): apparmor=&#8221;DENIED&#8221; operation=&#8221;capable&#8221; profile=&#8221;/usr/lib/firefox/firefox{,*[^s][^h]}&#8221; pid=7437 comm=&#8221;firefox&#8221; capability=21&nbsp; capname=&#8221;sys_admin&#8221;</p>



<p class="wp-block-paragraph">May 25 20:17:06 molly dbus-daemon[2062]: apparmor=&#8221;DENIED&#8221; operation=&#8221;dbus_method_call&#8221;&nbsp; bus=&#8221;session&#8221; path=&#8221;/org/gtk/vfs/Daemon&#8221; interface=&#8221;org.gtk.vfs.Daemon&#8221; member=&#8221;ListMonitorImplementations&#8221; mask=&#8221;send&#8221; name=&#8221;:1.7&#8243; pid=7437 label=&#8221;/usr/lib/firefox/firefox{,*[^s][^h]}&#8221; peer_pid=2161 peer_label=&#8221;unconfined&#8221;</p>



<p class="wp-block-paragraph">May 25 20:17:07 molly kernel: [&nbsp; 373.458709] audit: type=1400 audit(1527272227.121:103): apparmor=&#8221;DENIED&#8221; operation=&#8221;file_lock&#8221; profile=&#8221;/usr/lib/firefox/firefox{,*[^s][^h]}&#8221; name=&#8221;/home/erza/.cache/fontconfig/a41116dafaf8b233ac2c61cb73f2ea5f-le64.cache-7&#8243; pid=7437 comm=&#8221;firefox&#8221; requested_mask=&#8221;k&#8221; denied_mask=&#8221;k&#8221; fsuid=1001 ouid=1001</p>



<p class="wp-block-paragraph">May 25 20:17:07 molly dbus-daemon[2062]: apparmor=&#8221;DENIED&#8221; operation=&#8221;dbus_method_call&#8221;&nbsp; bus=&#8221;session&#8221; path=&#8221;/org/freedesktop/DBus&#8221; interface=&#8221;org.freedesktop.DBus&#8221; member=&#8221;RequestName&#8221; mask=&#8221;send&#8221; name=&#8221;org.freedesktop.DBus&#8221; pid=7437 label=&#8221;/usr/lib/firefox/firefox{,*[^s][^h]}&#8221; peer_label=&#8221;unconfined&#8221;</p>



<p class="wp-block-paragraph">May 25 20:17:07 molly dbus-daemon[2062]: apparmor=&#8221;DENIED&#8221; operation=&#8221;dbus_method_call&#8221;&nbsp; bus=&#8221;session&#8221; path=&#8221;/org/gtk/vfs/Daemon&#8221; interface=&#8221;org.gtk.vfs.Daemon&#8221; member=&#8221;ListMonitorImplementations&#8221; mask=&#8221;send&#8221; name=&#8221;:1.7&#8243; pid=7505 label=&#8221;/usr/lib/firefox/firefox{,*[^s][^h]}&#8221; peer_pid=2161 peer_label=&#8221;unconfined&#8221;</p>



<p class="wp-block-paragraph">May 25 20:17:08 molly dbus-daemon[2062]: apparmor=&#8221;DENIED&#8221; operation=&#8221;dbus_method_call&#8221;&nbsp; bus=&#8221;session&#8221; path=&#8221;/org/gtk/vfs/Daemon&#8221; interface=&#8221;org.gtk.vfs.Daemon&#8221; member=&#8221;ListMonitorImplementations&#8221; mask=&#8221;send&#8221; name=&#8221;:1.7&#8243; pid=7567 label=&#8221;/usr/lib/firefox/firefox{,*[^s][^h]}&#8221; peer_pid=2161 peer_label=&#8221;unconfined&#8221;</p>



<p class="wp-block-paragraph">May 25 20:17:24 molly dbus-daemon[2062]: [session uid=1001 pid=2062] Activating via systemd: service name=&#8217;org.gnome.Terminal&#8217; unit=&#8217;gnome-terminal-server.service&#8217; requested by &#8216;:1.77&#8217; (uid=1001 pid=7611 comm=&#8221;/usr/bin/gnome-terminal.real &#8221; label=&#8221;unconfined&#8221;)</p>



<p class="wp-block-paragraph">May 25 20:17:24 molly systemd[2035]: Starting GNOME Terminal Server&#8230;</p>



<p class="wp-block-paragraph">May 25 20:17:24 molly dbus-daemon[2062]: [session uid=1001 pid=2062] Successfully activated service &#8216;org.gnome.Terminal&#8217;</p>



<p class="wp-block-paragraph">May 25 20:17:24 molly systemd[2035]: Started GNOME Terminal Server.</p>



<p class="wp-block-paragraph">When I searched through the logs 30 seconds later, almost everything above was gone, leaving only the inconspicious entries. Now, that&#8217;s a very professional hacker group at work.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://erik.zalitis.se/tin-foil-hattery/what-a-real-buffer-overwrite-may-look-like/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1280</post-id>	</item>
		<item>
		<title>The IT-security maverick scoring system (IMSS)</title>
		<link>https://erik.zalitis.se/it-security/the-it-security-maverick-scoring-system-imss/</link>
					<comments>https://erik.zalitis.se/it-security/the-it-security-maverick-scoring-system-imss/#respond</comments>
		
		<dc:creator><![CDATA[Erik Zalitis]]></dc:creator>
		<pubDate>Fri, 06 Aug 2021 10:12:00 +0000</pubDate>
				<category><![CDATA[IT-security]]></category>
		<guid isPermaLink="false">https://erik.zalitis.se/?p=1146</guid>

					<description><![CDATA[(2021-08-06 &#8211; Just started this page. Will add more lines, shortly!) Inspired by John Baez &#8220;The Crackpot index&#8220;. Right, we can all screw up or say stuff that is wrong. But we learn and we strive to correct ourselves. But among us walks the IT-security mavericks that don&#8217;t abide by common rules such as making [&#8230;]]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="490" height="429" src="https://erik.zalitis.se/wp-content/uploads/2021/08/image.png" alt="" class="wp-image-1183" srcset="https://erik.zalitis.se/wp-content/uploads/2021/08/image.png 490w, https://erik.zalitis.se/wp-content/uploads/2021/08/image-300x263.png 300w, https://erik.zalitis.se/wp-content/uploads/2021/08/image-150x131.png 150w, https://erik.zalitis.se/wp-content/uploads/2021/08/image-480x420.png 480w" sizes="(max-width: 490px) 100vw, 490px" /><figcaption>attrition.org&#8217;s mean squirrel. The site has been an amusing source of laughter for me a number of times. And some of their stories has been inspiration for this list as well.</figcaption></figure>



<p class="wp-block-paragraph">(2021-08-06 &#8211; Just started this page. Will add more lines, shortly!)</p>



<p class="wp-block-paragraph">Inspired by John Baez &#8220;<a rel="noreferrer noopener" href="https://math.ucr.edu/home/baez/crackpot.html" target="_blank">The Crackpot index</a>&#8220;. </p>



<p class="wp-block-paragraph">Right, we can all screw up or say stuff that is wrong. But we learn and we strive to correct ourselves. But among us walks the IT-security mavericks that don&#8217;t abide by common rules such as making their statements possible to test or that you actually must accept critisism without calling the other person names.</p>



<p class="wp-block-paragraph">They commonly sell stuff, software and ideas that may or may not work, actually exist, improve security at all or just plain do anything at all. So, no, they&#8217;re not necessary incompetent. They may be snake-oil salesmen or just have a pompous ego and no idea as to the mind set and spirit of the IT-security field.</p>



<p class="wp-block-paragraph">Score someone you want to understand and remember: racking up points is not a good thing. Above all, enjoy!</p>



<ol class="wp-block-list"><li>They start at -5 points for calling themselves an &#8220;IT-security expert&#8221; or something like that. We&#8217;re currently cautiously optimistic as we need more people in this field. Then add:</li><li>1 point for every statement that&#8217;s widely believed to be false.</li><li>1 point for every time a statement is wrong, that should have had been easy to actually verify before stating it.</li><li>1 point for every statement that sounds about right until actually someone checks it up.</li><li>2 points for every &#8220;as everyone knows&#8221; that actually is something that no one really believes or that is incorrect.</li><li>5 points for complaining about this list and feeling it attacks them personally or refers to something they wrote or said (Most likely it did not).</li><li>5 points for calling everyone who disagrees with them &#8220;Orthodox thinkers&#8221;, &#8220;Troglodytes&#8221;, &#8220;Unimaginative&#8221;, &#8220;Sheeple&#8221; or just plain &#8220;idiots&#8221;.</li><li>10 points for writing articles/books/posts that are basically stolen from others and then badly rewritten to obscure this fact.</li><li>10 points for spraying the speech/articles with every abbreviation, initialism and acronym known to mankind as long as they (may) relate to the IT-security field.</li><li>10 point for taking a pride in inventing new language as a selling point. &#8220;armor clad security shielding&#8221;, &#8220;cloaking mode&#8221;, &#8220;security arbitration&#8221; and &#8220;synergi-based security tracking&#8221;. (Ok, I made those up. Or did I?)</li><li>10 points for getting &#8220;original research&#8221; stamped on contributions on Wikipedia.</li><li>20 points for whole Wikipedia-articles written getting removed.</li><li>&#8230; an additional point for every &#8220;WTF&#8221; comment on their articles in the &#8220;Talk&#8221; section.</li><li>10 points for taunting their &#8220;exceptionally high IQ&#8221;, &#8220;extreme skills&#8221;, &#8220;Hacked the global liberation army&#8221;, &#8220;being trusted by NSA/CIA/MUST/GRU/Whatever&#8221; or anything else you have no way of actually verifying.</li><li>10 points per work experience they state that is not possible to check or that is purposefully vaguely written. E.g., &#8220;20 years of experience with IT-security research in the intelligence community&#8221;.</li><li>20 points for pointing to other experts &#8220;supporting&#8221; what they&#8217;re stating/selling/proposing, when said expert&#8217;s statements are taken out of context or is not applicable.</li><li>20 points for adding buzz words and claiming to use/support/provide/understand &#8220;Artificial intelligence&#8221;, &#8220;Heuristic analysis&#8221;, &#8220;Data lakes&#8221; when it isn&#8217;t clear that those technologies even would make sense in that context. E.g., &#8220;Our firewall features artificial intelligence based search engine optimization to provide synergy between the total cost of ownership and the customer experience&#8221;.</li><li>20 points for claiming to have big companies as customers, while ignoring to mention that they just got them to accept a sales pitch and then never called back.</li><li>20 points for ridiculous statements that makes you wonder how much they actually understand. &#8220;It was a command-driven movement on the Internet&#8221;, &#8220;Plugged the hard disk into the Internet&#8221;, &#8220;Our firewalls cannot be hacked&#8221;, &#8220;Since this cannot happen, it really didn&#8217;t&#8221;.</li><li>20 points for suggesting &#8220;Security by obscurity&#8221; as a main security design. (E.g., setting a service to listen to an uncommon port)</li><li>20 points for every year passing after the promised solution&#8217;s/product&#8217;s initial release date.</li><li>20 points for predictions that a vulnerability they found &#8220;will bring down the Internet&#8221;.</li><li>20 points for using sales lingo to pitch their research like &#8220;It&#8217;s beautiful and perfect&#8221; or &#8220;It will change the whole world&#8221;.</li><li>20 points for invoking Godwin&#8217;s on anyone opposing them.</li><li>40 points for comparing themselves to any historically or currently oppressed people and thus losing all contact with reality.</li><li>40 points for inventing their own cryptography without disclosing how it works.</li><li>30 more points for stating that &#8220;it can&#8217;t be expressed as an algorithm&#8221;, &#8220;doesn&#8217;t use common mathematical rules&#8221; or &#8220;is based on quantum physics&#8221;.</li><li>40 points for going full mad scientist &#8220;YOU WILL ALL SEE WHEN THE INTERNET CRASHES! You will regret not listening to me! And not buying my super-perfect software!&#8221;</li><li>50 points for vaguely suggesting you invented/were instrumental in the development of a famous protocol/software/system. Points will not be &#8220;awarded&#8221; if it&#8217;s actually true (It never is!).</li></ol>



<p class="wp-block-paragraph">Note</p>



<p class="wp-block-paragraph">The list is a mix of things I&#8217;ve heard a number of people say, commonly said stuff that boggles my mind, proof of a mind set that totally misses the target and a few I&#8217;ve done myself over the years (not telling you which!).</p>



<p class="wp-block-paragraph">The original &#8220;crackpot-list&#8221; does not tell you what score you need to be seen as a crackpot. I don&#8217;t know when you become an &#8220;IT-security Maverick&#8221; either. It&#8217;s more a list for some laughs than anything. </p>
]]></content:encoded>
					
					<wfw:commentRss>https://erik.zalitis.se/it-security/the-it-security-maverick-scoring-system-imss/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1146</post-id>	</item>
		<item>
		<title>A pox on all your Amigas!</title>
		<link>https://erik.zalitis.se/retrocomputing/a-pox-on-all-your-amigas/</link>
					<comments>https://erik.zalitis.se/retrocomputing/a-pox-on-all-your-amigas/#respond</comments>
		
		<dc:creator><![CDATA[Erik Zalitis]]></dc:creator>
		<pubDate>Sun, 04 Apr 2021 20:00:38 +0000</pubDate>
				<category><![CDATA[Amiga]]></category>
		<category><![CDATA[IT-security]]></category>
		<category><![CDATA[Retrocomputing]]></category>
		<guid isPermaLink="false">https://erik.zalitis.se/?p=962</guid>

					<description><![CDATA[As I&#8217;m into the areas of IT-security and retro computing&#8230; Here&#8217;s a podcast with me talking about old viruses from the 80s and 90s. It features cool music from the Amiga. Viruses are no fun, but we have had to contend with them since the 70s. The Amiga had its share of them like SCA, [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">As I&#8217;m into the areas of IT-security and retro computing&#8230; Here&#8217;s a podcast with me talking about old viruses from the 80s and 90s. It features cool music from the Amiga.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe title="Amiga Flashback #27 – a pox on all your Amigas" width="696" height="522" src="https://www.youtube.com/embed/bf4Xz3l2S1w?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe>
</div></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Viruses are no fun, but we have had to contend with them since the 70s. The Amiga had its share of them like SCA, Bytebandit, Saddam Hussein, Lamer exterminator and some others. Some just wrote cute messages, whereas others deliberately or by mistake destroyed your data. Let DJ Daemon take you back to the 80s and guide you through the less popular parts of Amiga history.</p>



<p class="wp-block-paragraph">00:00​ Amiga Flashback &#8211; show intro<br>00:13​ DJ Daemon &#8211; introduces the episode<br>00:35​ Firage &#8211; Buns and Guns<br>02:40​ DJ Daemon &#8211; speaks about Amiga computer viruses<br>03:32​ Radix &#8211; * CoLoUrS *<br>08:45​ DJ Daemon &#8211; speaks about the SCA virus<br>10:06​ Reed Richards &#8211; Devoted<br>14:56​ DJ Daemon &#8211; speaks about the ByteBandit virus<br>15:58​ CRD &#8211; Chordian remix<br>17:51​ DJ Daemon &#8211; speaks about the Saddam virus<br>19:20​ Finwave &#8211; Just Do It (F/U)<br>23:47​ DJ Daemon &#8211; concludes by saying it&#8217;s not an Amiga-thing<br>25:10​ FearofDark &#8211; SurfingOnASineWave<br>30:01​ DJ Daemon &#8211; discusses viruses destroying hardware<br>31:42​ Elwood &#8211; After Hours<br>35:07​ DJ Daemon speaks 29s<br>35:36​ Maikel Yeremy &#8211; The Wayfarers Arrive<br>38:34​ DJ Daemon speaks 34s<br>39:07​ JaseChong &#8211; Kingdom Skies<br>43:41​ DJ Daemon speaks 37s<br>44:17​ Maikel Yeremy &#8211; Teller 1<br>46:30​ DJ Daemon speaks 39s<br>47:09​ Nescio &#8211; Dreaming of you<br>49:36​ DJ Daemon speaks 33s<br>50:08​ AceMan &#8211; Vintage Groove<br>53:57​ DJ Daemon speaks 28s<br>54:24​ Velvet of Amb and Tdr &#8211; Sternzeit<br>56:41​ DJ Daemon speaks 11s</p>
]]></content:encoded>
					
					<wfw:commentRss>https://erik.zalitis.se/retrocomputing/a-pox-on-all-your-amigas/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">962</post-id>	</item>
		<item>
		<title>Caveat emptor: PastBook &#8211; giving your pictures away</title>
		<link>https://erik.zalitis.se/it-security/caveat-emptor-pastbook-giving-your-pictures-away/</link>
					<comments>https://erik.zalitis.se/it-security/caveat-emptor-pastbook-giving-your-pictures-away/#respond</comments>
		
		<dc:creator><![CDATA[Erik Zalitis]]></dc:creator>
		<pubDate>Mon, 11 Jan 2021 23:01:17 +0000</pubDate>
				<category><![CDATA[IT-security]]></category>
		<guid isPermaLink="false">https://erik.zalitis.se/?p=864</guid>

					<description><![CDATA[TLDR; Don&#8217;t log in to Pastbook or use it in anyway! They steal pretty much all of your data and will sell it to god knows who. If you do: get ready to be bombarded with mail telling you to buy the photoalbum from them&#8230; Or else&#8230; Really nasty site. As I was idly surfing [&#8230;]]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image"><img decoding="async" src="https://i.imgflip.com/32o083.jpg" alt="mark zuckerberg - Imgflip"/><figcaption>As does Google, I guess&#8230;</figcaption></figure>



<p class="wp-block-paragraph">TLDR; Don&#8217;t log in to Pastbook or use it in anyway! They steal pretty much all of your data and will sell it to god knows who. If you do: get ready to be bombarded with mail telling you to buy the photoalbum from them&#8230; Or else&#8230; Really nasty site.</p>



<p class="wp-block-paragraph">As I was idly surfing on Facebook, a post told me that my 10 year photobook was ready. I should have known better (with a site like you) and NOT clicked on it. I thought it was one of those Facebook memory slide shows where you&#8217;re shown pictures with a random friend on Facebook. </p>



<p class="wp-block-paragraph">When I clicked on it, an authorization dialog came up and told me to login with my Facebook account. This is a clear warning that it wasn&#8217;t Facebook I was going to. Being tired and unfocused I stupidly logged in by clicking the link. Terror struck me when I realized what I had done five seconds later. My photos were already spreading accross their site. I unauthorized them, but it was too late.</p>



<p class="wp-block-paragraph">Their name (too live forever in infamy): www.pastbook.com.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="642" height="545" src="https://erik.zalitis.se/wp-content/uploads/2021/01/image.png" alt="" class="wp-image-865" srcset="https://erik.zalitis.se/wp-content/uploads/2021/01/image.png 642w, https://erik.zalitis.se/wp-content/uploads/2021/01/image-300x255.png 300w, https://erik.zalitis.se/wp-content/uploads/2021/01/image-150x127.png 150w, https://erik.zalitis.se/wp-content/uploads/2021/01/image-495x420.png 495w" sizes="(max-width: 642px) 100vw, 642px" /><figcaption>That&#8217;s it&#8230; I&#8217;m boned&#8230; Yeah, I need help, to get rid of charlatans like you!</figcaption></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">So as to what they want from your Facebook account? Pretty much everything.. No surprises there&#8230; And Mark O&#8217;ZuckerIsBorn doesn&#8217;t care.</p>



<figure class="wp-block-image size-large is-resized"><a href="https://erik.zalitis.se/wp-content/uploads/2021/01/image-3-1024x869.png"><img loading="lazy" decoding="async" src="https://erik.zalitis.se/wp-content/uploads/2021/01/image-3-1024x869.png" alt="" class="wp-image-881" width="1025" height="870" srcset="https://erik.zalitis.se/wp-content/uploads/2021/01/image-3-1024x869.png 1024w, https://erik.zalitis.se/wp-content/uploads/2021/01/image-3-300x255.png 300w, https://erik.zalitis.se/wp-content/uploads/2021/01/image-3-768x652.png 768w, https://erik.zalitis.se/wp-content/uploads/2021/01/image-3-150x127.png 150w, https://erik.zalitis.se/wp-content/uploads/2021/01/image-3-696x591.png 696w, https://erik.zalitis.se/wp-content/uploads/2021/01/image-3-1068x906.png 1068w, https://erik.zalitis.se/wp-content/uploads/2021/01/image-3-495x420.png 495w, https://erik.zalitis.se/wp-content/uploads/2021/01/image-3.png 1124w" sizes="auto, (max-width: 1025px) 100vw, 1025px" /></a><figcaption>It&#8217;s easier to list what they DON&#8217;T take from you. Click this picture if you&#8217;re not already dead inside&#8230;</figcaption></figure>



<p class="wp-block-paragraph">SCREW FACEBOOK! PIECE OF GARBAGE SITE! MENTAL BLOODY DOPAMIN-RELEASE DRUG!!!</p>



<p class="wp-block-paragraph">&#8230; And just when you thought it was safe to pop out of your bunker&#8230;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="670" height="476" src="https://erik.zalitis.se/wp-content/uploads/2021/01/image-1.png" alt="" class="wp-image-872" srcset="https://erik.zalitis.se/wp-content/uploads/2021/01/image-1.png 670w, https://erik.zalitis.se/wp-content/uploads/2021/01/image-1-300x213.png 300w, https://erik.zalitis.se/wp-content/uploads/2021/01/image-1-150x107.png 150w, https://erik.zalitis.se/wp-content/uploads/2021/01/image-1-591x420.png 591w, https://erik.zalitis.se/wp-content/uploads/2021/01/image-1-100x70.png 100w" sizes="auto, (max-width: 670px) 100vw, 670px" /><figcaption>&#8230; Jay, another psychopath entrepeneur ready to sell your stuff&#8230;</figcaption></figure>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://erik.zalitis.se/it-security/caveat-emptor-pastbook-giving-your-pictures-away/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">864</post-id>	</item>
		<item>
		<title>Hacking it up!</title>
		<link>https://erik.zalitis.se/it-security/hacking-it-up/</link>
					<comments>https://erik.zalitis.se/it-security/hacking-it-up/#respond</comments>
		
		<dc:creator><![CDATA[Erik Zalitis]]></dc:creator>
		<pubDate>Mon, 28 Sep 2020 09:17:44 +0000</pubDate>
				<category><![CDATA[IT-security]]></category>
		<guid isPermaLink="false">https://erik.zalitis.se/?p=556</guid>

					<description><![CDATA[I was working from home one Friday as Dnov sent me an email asking for my participation in the FOI 20/20 CTF. I thought about it, and decided to join him and his crack (haha!) squad of elite haxx0rs. A &#8220;capture the flag&#8221; or CTF is simply a hacking competition, where you work as a [&#8230;]]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-large"><a href="https://erik.zalitis.se/wp-content/uploads/2020/09/FiveScreens-1024x429.jpg"><img loading="lazy" decoding="async" width="1024" height="429" src="https://erik.zalitis.se/wp-content/uploads/2020/09/FiveScreens-1024x429.jpg" alt="" class="wp-image-557" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/FiveScreens-1024x429.jpg 1024w, https://erik.zalitis.se/wp-content/uploads/2020/09/FiveScreens-300x126.jpg 300w, https://erik.zalitis.se/wp-content/uploads/2020/09/FiveScreens-768x322.jpg 768w, https://erik.zalitis.se/wp-content/uploads/2020/09/FiveScreens-1536x644.jpg 1536w, https://erik.zalitis.se/wp-content/uploads/2020/09/FiveScreens-2048x858.jpg 2048w, https://erik.zalitis.se/wp-content/uploads/2020/09/FiveScreens-150x63.jpg 150w, https://erik.zalitis.se/wp-content/uploads/2020/09/FiveScreens-696x292.jpg 696w, https://erik.zalitis.se/wp-content/uploads/2020/09/FiveScreens-1068x447.jpg 1068w, https://erik.zalitis.se/wp-content/uploads/2020/09/FiveScreens-1920x804.jpg 1920w, https://erik.zalitis.se/wp-content/uploads/2020/09/FiveScreens-1002x420.jpg 1002w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a><figcaption>Five screens trained on the problem of getting all the flags. A snapshop in the middle of the process that lead us to 17th place among 152 competing teams.</figcaption></figure>



<p class="wp-block-paragraph">I was working from home one Friday as Dnov sent me an email asking for my participation in the FOI 20/20 CTF. I thought about it, and decided to join him and his crack (haha!) squad of elite haxx0rs. A &#8220;capture the flag&#8221; or CTF is simply a hacking competition, where you work as a team to solve tasks that require you to &#8220;hack&#8221; something. It does not necessary mean rooting a system, but you have to subvert a service, program or system in order to prove your skills in breaking its security.</p>



<h2 class="wp-block-heading">FOI &#8211; Totalförsvarets forskningsinstitut</h2>



<p class="wp-block-paragraph">FOI is a Swedish governmental organisation tasked with aiding the Swedish armed defence with technology research and support things like disarmamernt and international security. In a typical Swedish manner, doing a lot of things that looks like they&#8217;re contradictionary. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f642.png" alt="🙂" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>



<p class="wp-block-paragraph">On the 26th of September the 20/20 CTF started with a bang as the virtual doors flung open at 2 pm and we worked until 10 pm that same evening.</p>



<h2 class="wp-block-heading">Meet 0xDEADBEEF</h2>



<p class="wp-block-paragraph">In the Atrocity archives, supernatural hacker/sysadmin/government agent Bob Howard destroys the content of a hard drive by writing the hexdecimal string DEADBEEF over and over again on all the tracks. This is as far as I know an old hacker joke and it fits. 0xDEADBEEF is also the name of our team. We&#8217;re at this moment five guys employed in the IT-security field. So let&#8217;s talk about us.</p>



<figure class="wp-block-image"><img decoding="async" src="https://i.guim.co.uk/img/media/7fcc94d9e1154d957f2cf461c61cb2b881b78ae5/0_301_3000_1800/master/3000.jpg?width=700&amp;quality=85&amp;auto=format&amp;fit=max&amp;s=4656af45976a44cc39979311f0db9955" alt=""/><figcaption>Really not sure who is who here among us, but it amuses me to try to figure it out.</figcaption></figure>



<p class="wp-block-paragraph">dnov<br>The principal leader of the team. <a rel="noreferrer noopener" href="https://en.wikipedia.org/wiki/John_%22Hannibal%22_Smith" target="_blank">He&#8217;s like that white haired old man who likes a good plan coming together</a> in the A-team TV-series. With a broad knowledge in infosecurity, it-security and working with our Swedish defense effort, he is really the right man for the job.</p>



<p class="wp-block-paragraph">CrashOverride<br>Ok, so we&#8217;re doing A-team references here? This is clearly Mr T. The heavy hitter, who managed to come up with solutions to many different tasks and worked all over the board mostly with cryptograhy and reversing. He has an academic background &#8220;in something cyber&#8221;. That&#8217;s his story, and I&#8217;m sticking with it. So there&#8230;</p>



<p class="wp-block-paragraph">StripeCAT<br>Enough references to the old TV-series, as I really don&#8217;t remember it all that well. But StripeCAT is my nome de guerre and I&#8217;m a good supporting role, with plenty of experience with web hacking and network (in)security. Know my way around Kali Linux and Burp suite and Metasploit.</p>



<p class="wp-block-paragraph">FX<br>Working in the same company as dnov and specializing in webhacking and security analysis.</p>



<p class="wp-block-paragraph">Zaffner<br>General profile with experience in a number of different areas.</p>



<h2 class="wp-block-heading">A journal of sorts&#8230; Because, why not?</h2>



<h3 class="wp-block-heading">Saturday, the 26 th of September</h3>



<p class="wp-block-paragraph">10:00 woke up late and spoke to my mother over the phone. Got on an uber to a music store in Järfälla to get my new mixing console. An errant soldering job had swiftly killed the one I had.</p>



<p class="wp-block-paragraph">12:00 connected the new mixing console and patched the compressor into it. This made it possible to get sound to my rig. A good thing when you&#8217;re in a teleconference. Due to Corona, I decided not to go to the location where the others were gathering.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="768" src="https://erik.zalitis.se/wp-content/uploads/2020/09/mixer.jpg" alt="" class="wp-image-582" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/mixer.jpg 1024w, https://erik.zalitis.se/wp-content/uploads/2020/09/mixer-300x225.jpg 300w, https://erik.zalitis.se/wp-content/uploads/2020/09/mixer-768x576.jpg 768w, https://erik.zalitis.se/wp-content/uploads/2020/09/mixer-150x113.jpg 150w, https://erik.zalitis.se/wp-content/uploads/2020/09/mixer-696x522.jpg 696w, https://erik.zalitis.se/wp-content/uploads/2020/09/mixer-560x420.jpg 560w, https://erik.zalitis.se/wp-content/uploads/2020/09/mixer-80x60.jpg 80w, https://erik.zalitis.se/wp-content/uploads/2020/09/mixer-265x198.jpg 265w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption>Look at it! It has blinkly lights!!!</figcaption></figure>



<p class="wp-block-paragraph">Made contact with the team on Slack. CrashOverride offered to come and get me into the building, until I pointed out I&#8217;m working from my home.</p>



<figure class="wp-block-image size-large"><a href="https://erik.zalitis.se/wp-content/uploads/2020/09/hackstation-1024x768.jpg"><img loading="lazy" decoding="async" width="1024" height="768" src="https://erik.zalitis.se/wp-content/uploads/2020/09/hackstation-1024x768.jpg" alt="" class="wp-image-569" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/hackstation-1024x768.jpg 1024w, https://erik.zalitis.se/wp-content/uploads/2020/09/hackstation-300x225.jpg 300w, https://erik.zalitis.se/wp-content/uploads/2020/09/hackstation-768x576.jpg 768w, https://erik.zalitis.se/wp-content/uploads/2020/09/hackstation-1536x1152.jpg 1536w, https://erik.zalitis.se/wp-content/uploads/2020/09/hackstation-150x113.jpg 150w, https://erik.zalitis.se/wp-content/uploads/2020/09/hackstation-696x522.jpg 696w, https://erik.zalitis.se/wp-content/uploads/2020/09/hackstation-1068x801.jpg 1068w, https://erik.zalitis.se/wp-content/uploads/2020/09/hackstation-1920x1440.jpg 1920w, https://erik.zalitis.se/wp-content/uploads/2020/09/hackstation-560x420.jpg 560w, https://erik.zalitis.se/wp-content/uploads/2020/09/hackstation-80x60.jpg 80w, https://erik.zalitis.se/wp-content/uploads/2020/09/hackstation-265x198.jpg 265w, https://erik.zalitis.se/wp-content/uploads/2020/09/hackstation.jpg 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a><figcaption>Thunderbirds are go!</figcaption></figure>



<p class="wp-block-paragraph">12:30 updated Kali Linux on my main PC as a virtual machine. Also had a real laptop with Kali on standby. &#8220;All events random favor the prepared&#8221; and all that.</p>



<p class="wp-block-paragraph">13:00 ordered some food and made sure everything worked. At this time everyone in the team had arrived, with FX being the last to enter the room.</p>



<p class="wp-block-paragraph">14:00 dnov was frantically smashing the &#8220;F5&#8221;-key to reload the CTF website, waiting for it to start. And sure enough, the challenges appeared on time.</p>



<p class="wp-block-paragraph">We all started working. Zaffner took the first flag. Just a few seconds before I did. This is not a good thing, as it meant he missed that I was working on it. But dnov soon started coordinating the challenges so we would not work on the same ones unless cooperating. Doing so would otherwise make us lose valuable time.</p>



<p class="wp-block-paragraph">The first tasks went down easy.</p>



<figure class="wp-block-image size-large"><a href="https://erik.zalitis.se/wp-content/uploads/2020/09/doggie-768x709.jpg"><img loading="lazy" decoding="async" width="842" height="777" src="https://erik.zalitis.se/wp-content/uploads/2020/09/doggie.jpg" alt="" class="wp-image-595" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/doggie.jpg 842w, https://erik.zalitis.se/wp-content/uploads/2020/09/doggie-300x277.jpg 300w, https://erik.zalitis.se/wp-content/uploads/2020/09/doggie-768x709.jpg 768w, https://erik.zalitis.se/wp-content/uploads/2020/09/doggie-150x138.jpg 150w, https://erik.zalitis.se/wp-content/uploads/2020/09/doggie-696x642.jpg 696w, https://erik.zalitis.se/wp-content/uploads/2020/09/doggie-455x420.jpg 455w" sizes="auto, (max-width: 842px) 100vw, 842px" /></a><figcaption>Who is a good doggie? You are! Yes, you are! (kinda used that joke already in this blog)</figcaption></figure>



<p class="wp-block-paragraph">I fed a total list of all existing breeds of dogs into Burp suite and solved a very weird flag involving trying to figure out how to get a web app to give out information to some kind of dog collar that a normal user should not be able to get. It worked and I got a good laugh out of it.</p>



<p class="wp-block-paragraph">The others worked through cryptography and reversing. One task spewed out simple aritmetic questions that had to be solved with in a few seconds. CrashOverride and Dnov quickly wrote a script to do so and the flag was caught.</p>



<p class="wp-block-paragraph">FX and Zaffner looked into the arguably convoluted mess of a Javascript that held the secret to one of the flags.</p>



<p class="wp-block-paragraph">I wrote a script to recursivly open encrypted ziparchives, but CrashOverride mistakenly solved it before I was done. Having lost two flags because of the others failed to note that I was on them made me a bit irritated, so I told them in no unclear terms to start keeping track on who is doing what. No more incidents after that, but my outburst probably rendered this choice of emoji representing me on Twitter from dnov:</p>



<figure class="wp-block-image size-large"><a href="https://erik.zalitis.se/wp-content/uploads/2020/09/soursc-1024x603.jpg"><img loading="lazy" decoding="async" width="1024" height="603" src="https://erik.zalitis.se/wp-content/uploads/2020/09/soursc-1024x603.jpg" alt="" class="wp-image-573" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/soursc-1024x603.jpg 1024w, https://erik.zalitis.se/wp-content/uploads/2020/09/soursc-300x177.jpg 300w, https://erik.zalitis.se/wp-content/uploads/2020/09/soursc-768x452.jpg 768w, https://erik.zalitis.se/wp-content/uploads/2020/09/soursc-1536x905.jpg 1536w, https://erik.zalitis.se/wp-content/uploads/2020/09/soursc-2048x1206.jpg 2048w, https://erik.zalitis.se/wp-content/uploads/2020/09/soursc-150x88.jpg 150w, https://erik.zalitis.se/wp-content/uploads/2020/09/soursc-696x410.jpg 696w, https://erik.zalitis.se/wp-content/uploads/2020/09/soursc-1068x629.jpg 1068w, https://erik.zalitis.se/wp-content/uploads/2020/09/soursc-1920x1131.jpg 1920w, https://erik.zalitis.se/wp-content/uploads/2020/09/soursc-713x420.jpg 713w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a><figcaption>Hacking while annoyed.. That&#8217;s not illegal, is it?</figcaption></figure>



<p class="wp-block-paragraph">&#8230; I find that highly amusing&#8230; <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f642.png" alt="🙂" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>



<p class="wp-block-paragraph">The afternoon went on and we steadily captured the flags. At one point we were ranked as number nine among the 152 competing teams and this energized us even further.</p>



<figure class="wp-block-image size-large"><a href="https://erik.zalitis.se/wp-content/uploads/2020/09/a-team-1024x728.jpg"><img loading="lazy" decoding="async" width="1024" height="728" src="https://erik.zalitis.se/wp-content/uploads/2020/09/a-team-1024x728.jpg" alt="" class="wp-image-576" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/a-team-1024x728.jpg 1024w, https://erik.zalitis.se/wp-content/uploads/2020/09/a-team-300x213.jpg 300w, https://erik.zalitis.se/wp-content/uploads/2020/09/a-team-768x546.jpg 768w, https://erik.zalitis.se/wp-content/uploads/2020/09/a-team-1536x1092.jpg 1536w, https://erik.zalitis.se/wp-content/uploads/2020/09/a-team-2048x1456.jpg 2048w, https://erik.zalitis.se/wp-content/uploads/2020/09/a-team-150x107.jpg 150w, https://erik.zalitis.se/wp-content/uploads/2020/09/a-team-696x495.jpg 696w, https://erik.zalitis.se/wp-content/uploads/2020/09/a-team-1068x759.jpg 1068w, https://erik.zalitis.se/wp-content/uploads/2020/09/a-team-1920x1365.jpg 1920w, https://erik.zalitis.se/wp-content/uploads/2020/09/a-team-591x420.jpg 591w, https://erik.zalitis.se/wp-content/uploads/2020/09/a-team-100x70.jpg 100w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a><figcaption>The 90s rave culture never really died. Aciiiiiiiid! I&#8217;m still trying to figure out if Dnov choose the emojis on random or if he is trying to tell us something.</figcaption></figure>



<p class="wp-block-paragraph">The remaining tasks were harder and it was pretty clear that the tasks on the right side of the list were the really hard ones. Each flag gives the team and the member points. The points decrease over time as others solve them as well. So looking on tasks that still have the full score you will see that no one else have been able to solve them either&#8230;</p>



<figure class="wp-block-image size-large"><a href="https://erik.zalitis.se/wp-content/uploads/2020/09/wtf-1024x233.jpg"><img loading="lazy" decoding="async" width="1024" height="233" src="https://erik.zalitis.se/wp-content/uploads/2020/09/wtf-1024x233.jpg" alt="" class="wp-image-578" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/wtf-1024x233.jpg 1024w, https://erik.zalitis.se/wp-content/uploads/2020/09/wtf-300x68.jpg 300w, https://erik.zalitis.se/wp-content/uploads/2020/09/wtf-768x175.jpg 768w, https://erik.zalitis.se/wp-content/uploads/2020/09/wtf-150x34.jpg 150w, https://erik.zalitis.se/wp-content/uploads/2020/09/wtf-696x159.jpg 696w, https://erik.zalitis.se/wp-content/uploads/2020/09/wtf.jpg 1066w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a><figcaption><em>What the Sam Hill am I l</em>ooking at here? Does this require a degree in SCADA protocol analysis? Yes, actually, I does! Who said things should be easy?</figcaption></figure>



<p class="wp-block-paragraph">In the evening we ordered pizza and the team took a short break.</p>



<p class="wp-block-paragraph">9 pm The night was looming and we were frantically trying to solve the last challenges. The final minutes had me and CrashOverride fighting with a very obfuscated javascript mess to find a flag.</p>



<p class="wp-block-paragraph">10 pm All is over and the final score is in. We did quite well, but no prizes coming our way. 17th place, that rocks!</p>



<h2 class="wp-block-heading">The aftermath</h2>



<figure class="wp-block-image size-large"><a href="https://erik.zalitis.se/wp-content/uploads/2020/09/werenumber17-1.jpg"><img loading="lazy" decoding="async" width="943" height="530" src="https://erik.zalitis.se/wp-content/uploads/2020/09/werenumber17-1.jpg" alt="" class="wp-image-600" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/werenumber17-1.jpg 943w, https://erik.zalitis.se/wp-content/uploads/2020/09/werenumber17-1-300x169.jpg 300w, https://erik.zalitis.se/wp-content/uploads/2020/09/werenumber17-1-768x432.jpg 768w, https://erik.zalitis.se/wp-content/uploads/2020/09/werenumber17-1-150x84.jpg 150w, https://erik.zalitis.se/wp-content/uploads/2020/09/werenumber17-1-696x391.jpg 696w, https://erik.zalitis.se/wp-content/uploads/2020/09/werenumber17-1-747x420.jpg 747w" sizes="auto, (max-width: 943px) 100vw, 943px" /></a><figcaption><em>CrashOverride&#8217;s graph over all teams. Not bad, not bad at all. But next time, lets go for gold!</em></figcaption></figure>



<p class="wp-block-paragraph">So&#8230; Did we do it well? Heck, yeah! But we also had fun and learnt a lot along the way. Much obliged.</p>



<p class="wp-block-paragraph"><strong>The good</strong></p>



<ul class="wp-block-list"><li>A brand new team that had no problems getting into high gear.</li><li>We hit the ground running.</li><li>No real technical problems on our side. Except maybe with Zoom.</li></ul>



<p class="wp-block-paragraph"><strong>The bad</strong></p>



<ul class="wp-block-list"><li>Took a while before we started helping each other on a regular basis. At first everyone was focused on their tasks.</li></ul>



<p class="wp-block-paragraph"><strong>The ugly</strong></p>



<ul class="wp-block-list"><li>The test environment provided by FOI was a bit flaky at times.</li></ul>



<h2 class="wp-block-heading">The links</h2>



<p class="wp-block-paragraph">CrashOverride&#8217;s own write-up (In Swedish):<br><a href="https://github.com/dansarie/FOI2020CTF/blob/master/README.md">https://github.com/dansarie/FOI2020CTF/blob/master/README.md</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://erik.zalitis.se/it-security/hacking-it-up/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">556</post-id>	</item>
		<item>
		<title>The anatomy of an attack</title>
		<link>https://erik.zalitis.se/it-security/the-anatomy-of-an-attack/</link>
					<comments>https://erik.zalitis.se/it-security/the-anatomy-of-an-attack/#comments</comments>
		
		<dc:creator><![CDATA[Erik Zalitis]]></dc:creator>
		<pubDate>Sat, 12 Sep 2020 11:26:41 +0000</pubDate>
				<category><![CDATA[IT-security]]></category>
		<guid isPermaLink="false">https://erik.zalitis.se/?p=297</guid>

					<description><![CDATA[(Updated at 2020-09-19 19:13) &#8211; Good news, everyone. bxsmail.com is not responding anymore. Could one hope Telia booted mr Spammer off the net? Probably just a minor setback until he finds a news place to send his crap from. Pyrobee.com is, alas, still up and running. Why, oh why&#8230;? How the journey begun&#8230;. On Friday [&#8230;]]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-large"><a href="https://erik.zalitis.se/wp-content/uploads/2020/09/Intromail-1024x349.jpg"><img loading="lazy" decoding="async" width="1024" height="349" src="https://erik.zalitis.se/wp-content/uploads/2020/09/Intromail-1024x349.jpg" alt="" class="wp-image-298" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/Intromail-1024x349.jpg 1024w, https://erik.zalitis.se/wp-content/uploads/2020/09/Intromail-300x102.jpg 300w, https://erik.zalitis.se/wp-content/uploads/2020/09/Intromail-768x262.jpg 768w, https://erik.zalitis.se/wp-content/uploads/2020/09/Intromail-1536x524.jpg 1536w, https://erik.zalitis.se/wp-content/uploads/2020/09/Intromail-2048x699.jpg 2048w, https://erik.zalitis.se/wp-content/uploads/2020/09/Intromail-1200x409.jpg 1200w, https://erik.zalitis.se/wp-content/uploads/2020/09/Intromail-1980x675.jpg 1980w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a><figcaption>The email that started it all. Sounds very legit, but clearly isn&#8217;t Hint: hover over the link if you get this mail!</figcaption></figure>



<p class="wp-block-paragraph">(Updated at 2020-09-19 19:13) &#8211; Good news, everyone. bxsmail.com is not responding anymore. Could one hope Telia booted mr Spammer off the net? Probably just a minor setback until he finds a news place to send his crap from. Pyrobee.com is, alas, still up and running. Why, oh why&#8230;?</p>



<h2 class="wp-block-heading">How the journey begun&#8230;.</h2>



<p class="wp-block-paragraph">On Friday the 11th of September I found an email in my junk mail folder. That in itself is nothing special, but this particular spam stood out. It was in Swedish, without the usual auto-translated mess that those are wellknown for. It simply said (translated from Swedish):</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p>Hi</p><p>Thanks for the last time, here are the statistics you wanted. I hope you&#8217;ll receive this mail before going home for the day.<br>&lt;Link to what looks like tillvaxtverket.se, but really sends you to a malicious site&gt;</p><p>[I] believe it rather clearly shows what we though from the start and that is that there is a large lack of available talent in the rural communes. The quiestion is what could be done about it on a regional level.</p></blockquote>



<p class="wp-block-paragraph">The Swedish original:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p>From: Magnus <a href="mailto:notification@bxsmail.com">notification@bxsmail.com</a><br>Sent: den 11 september 2020 21:35<br>To: Erik Zalitis <a href="mailto:erik@zalitis.se">erik@zalitis.se</a><br>Subject: Jag tror det var detta du ville ha</p><p>Hej</p><p>Hoppas du hinner få mailet innan du går hem idag.</p><p>hxxps://tillvaxtverket.se/statistik/vara-undersokningar/kompetensforsorjning/2020-04-24-kompetensforsorjning-i-landsbygder.html</p><p>Tror den visar ganska klart det vi trodde från början att det är stor brist på kompetens i de större landsbygdskommunerna.<br>Frågan är vad man skulle kunna göra åt det regionalt.<br><br>/Magnus</p></blockquote>



<p class="wp-block-paragraph">I racked my brains trying to remember ever having spoke to someone on Tillväxtverket about something that would warrant this response and came up empty handed. I quickly Googled and what I found made me suspect it was some kind of fraud or spam. I posted my preliminary findings on &#8220;Säkerhetsbubblan&#8221;, a Facebook group dedicated to IT-security discussions.</p>



<p class="wp-block-paragraph">At this time I was quite curious about what was going on and started tracing the sending system down. The mailheaders were clear on the matter.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="805" height="631" src="https://erik.zalitis.se/wp-content/uploads/2020/09/mpath.png" alt="" class="wp-image-303" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/mpath.png 805w, https://erik.zalitis.se/wp-content/uploads/2020/09/mpath-300x235.png 300w, https://erik.zalitis.se/wp-content/uploads/2020/09/mpath-768x602.png 768w" sizes="auto, (max-width: 805px) 100vw, 805px" /><figcaption>Ok, got it&#8230; server.bxsmail.com</figcaption></figure>



<p class="wp-block-paragraph">The IP was recognized almost immediately by me, as I used to work at Swedish telecom provider Telia back in the day, and sure enough, it was them.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="398" height="467" src="https://erik.zalitis.se/wp-content/uploads/2020/09/IP-lookup-1.png" alt="" class="wp-image-307" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/IP-lookup-1.png 398w, https://erik.zalitis.se/wp-content/uploads/2020/09/IP-lookup-1-256x300.png 256w" sizes="auto, (max-width: 398px) 100vw, 398px" /><figcaption>Hallsberg does not sound as a center of cybercriminal activity, especially when&#8230;</figcaption></figure>



<p class="wp-block-paragraph">The post code is easy to put on a map:</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="873" height="967" src="https://erik.zalitis.se/wp-content/uploads/2020/09/map.jpg" alt="" class="wp-image-308" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/map.jpg 873w, https://erik.zalitis.se/wp-content/uploads/2020/09/map-271x300.jpg 271w, https://erik.zalitis.se/wp-content/uploads/2020/09/map-768x851.jpg 768w" sizes="auto, (max-width: 873px) 100vw, 873px" /></figure>



<p class="wp-block-paragraph">A typcial war zone in Sweden. A few day care centers for children and small suburban housing. This is where the hacker roams freely&#8230;. or maybe not.  Seriously though, it&#8217;s probably located on someones home network, directly connected to a consumer Internet broadband connection operated by Telia.</p>



<h2 class="wp-block-heading">One click on this link and you&#8217;re toast&#8230;</h2>



<p class="wp-block-paragraph">Let&#8217;s take a look on the seemingly innocent email (you should know better now, though):</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="716" height="158" src="https://erik.zalitis.se/wp-content/uploads/2020/09/malin.jpg" alt="" class="wp-image-328" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/malin.jpg 716w, https://erik.zalitis.se/wp-content/uploads/2020/09/malin-300x66.jpg 300w" sizes="auto, (max-width: 716px) 100vw, 716px" /><figcaption>One-click selling of your identity&#8230; Ain&#8217;t life grand?</figcaption></figure>



<p class="wp-block-paragraph">Hovering over the link in the email, shows you where it really goes. The link leading to the Tillväxtverket-site uses an old trick, where the displayed link does not correspond to the one you&#8217;re actually are clicking on (Se picture above!). </p>



<p class="wp-block-paragraph">Weirdly named proxy &#8220;Burp suite&#8221;, shows exactly what happens over the wire when you click the evil link like there was no tomorrow.</p>



<figure class="wp-block-image size-large"><a href="https://erik.zalitis.se/wp-content/uploads/2020/09/breq.png"><img loading="lazy" decoding="async" width="911" height="320" src="https://erik.zalitis.se/wp-content/uploads/2020/09/breq.png" alt="" class="wp-image-337" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/breq.png 911w, https://erik.zalitis.se/wp-content/uploads/2020/09/breq-300x105.png 300w, https://erik.zalitis.se/wp-content/uploads/2020/09/breq-768x270.png 768w" sizes="auto, (max-width: 911px) 100vw, 911px" /></a><figcaption>As you ask&#8230;</figcaption></figure>



<figure class="wp-block-image size-large"><a href="https://erik.zalitis.se/wp-content/uploads/2020/09/bresp.png"><img loading="lazy" decoding="async" width="739" height="349" src="https://erik.zalitis.se/wp-content/uploads/2020/09/bresp.png" alt="" class="wp-image-338" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/bresp.png 739w, https://erik.zalitis.se/wp-content/uploads/2020/09/bresp-300x142.png 300w" sizes="auto, (max-width: 739px) 100vw, 739px" /></a><figcaption>&#8230; ye shall receive&#8230;</figcaption></figure>



<p class="wp-block-paragraph">This fake link instead leads to a server for the domain pyrobee.com which is located in Germany. The reply-to address in the mail also points to info@pyrobee.com. The ip-information for this site is as follows.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="433" height="693" src="https://erik.zalitis.se/wp-content/uploads/2020/09/image.png" alt="Details for 78.46.65.196 
Decimal: 
1311654340 
Hostname: host2.sitedns_se 
ASU 24940 
ISP: 
Hetzner Online GmbH 
Organization: Hetzner Online GmbH 
Services None detected 
Assignment Likely Static IP 
Blacklist 
Click to Check Blacklist Status 
Continent Europe 
Country: Germany 
Latitude 51.2993 (51' 17' 57.48&quot; N) 
Longitude: 9.491 (9' 29' 27.60&quot; E) 
Geolocation Map 
Sch 
Nederland 
Belgié :BeIÉ que 
an tadt 
Niedersac 5 en 
tschland 
hijFi 
B ande b 
Belgien 
•de-Éra bourg 
icardie 
woje &quot;6dztwo 
z achodniopomo' 
dztWO kg 
ztwo dolnog« 
tesko " class="wp-image-312" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/image.png 433w, https://erik.zalitis.se/wp-content/uploads/2020/09/image-187x300.png 187w" sizes="auto, (max-width: 433px) 100vw, 433px" /></figure>



<p class="wp-block-paragraph">If you somehow doubt they are malicious, note the abuse-link provided in the mail:</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="747" height="324" src="https://erik.zalitis.se/wp-content/uploads/2020/09/image-4.png" alt="" class="wp-image-381" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/image-4.png 747w, https://erik.zalitis.se/wp-content/uploads/2020/09/image-4-300x130.png 300w" sizes="auto, (max-width: 747px) 100vw, 747px" /><figcaption>Ah.. Mr Bond, that was a bad move, now we know you&#8217;re trying to thwart our nefarious plans.</figcaption></figure>



<p class="wp-block-paragraph">OH!! They have a Facebook presence too&#8230; How &#8220;I&#8217;m just a serious business owner&#8221; of you.</p>



<figure class="wp-block-image size-large"><a href="https://erik.zalitis.se/wp-content/uploads/2020/09/image-5-1024x730.png"><img loading="lazy" decoding="async" width="1024" height="730" src="https://erik.zalitis.se/wp-content/uploads/2020/09/image-5-1024x730.png" alt="" class="wp-image-383" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/image-5-1024x730.png 1024w, https://erik.zalitis.se/wp-content/uploads/2020/09/image-5-300x214.png 300w, https://erik.zalitis.se/wp-content/uploads/2020/09/image-5-768x547.png 768w, https://erik.zalitis.se/wp-content/uploads/2020/09/image-5.png 1190w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a><figcaption>Aint nuthing but us chikkuns in here&#8230; Sez the fox&#8230; The farmer is not amused&#8230;</figcaption></figure>



<p class="wp-block-paragraph">And for my final trick, I going to pull a rabbit out of my hat. Or rather, disclose the identity of the spammer. He seriously has his REAL name on the FaceBook-group above. A fast check shows that he lives in the exact same area and in the same Zipcode as the bxsmail.com-server is located.</p>



<p class="wp-block-paragraph">This links him to the Pyrobee.com-server AND the bxsmail.com-server. So it&#8217;s a wrap then? We&#8217;ll see.</p>



<h2 class="wp-block-heading">What about them servers?</h2>



<p class="wp-block-paragraph">So, back to the server in Sweden, server.bxsmail.com. What is it running? Quite a lot actually.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="470" height="287" src="https://erik.zalitis.se/wp-content/uploads/2020/09/image-1.png" alt="o 
O 
O 
O 
O 
o 
O 
O 
P ort 
22 
53 
80 
465 
587 
2020 
2525 
3306 
8083 
Protocol 
tcp 
tcp 
tcp 
tcp 
tcp 
tcp 
tcp 
tcp 
tcp 
State 
open 
open 
open 
open 
open 
open 
open 
open 
open 
open 
open 
Service 
ftp 
smtp 
domain 
http 
smtp 
smtp 
x Inupageserver 
smtp 
mysql 
http 
Version 
vsftpd 3.02 
OpenSSH 7.4 (protocol 2.0) 
Ex im smtpd 4.93 
(unknown banner: get lost) 
ngvnx 
Ex im smtpd 4.93 
Ex im smtpd 4.93 
cbdev cmail smtpd 
MySQL 5.5.65-MariaD8 
ngvnx " class="wp-image-315" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/image-1.png 470w, https://erik.zalitis.se/wp-content/uploads/2020/09/image-1-300x183.png 300w" sizes="auto, (max-width: 470px) 100vw, 470px" /><figcaption>An open Mysql-port, a nasty DNS that tells me to get lost and god knows what port 2020 is about. The webserver has little to say:</figcaption></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="447" src="https://erik.zalitis.se/wp-content/uploads/2020/09/image-2-1024x447.png" alt="" class="wp-image-318" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/image-2-1024x447.png 1024w, https://erik.zalitis.se/wp-content/uploads/2020/09/image-2-300x131.png 300w, https://erik.zalitis.se/wp-content/uploads/2020/09/image-2-768x336.png 768w, https://erik.zalitis.se/wp-content/uploads/2020/09/image-2.png 1151w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption>Did you forget to remove the shrink wrap?</figcaption></figure>



<p class="wp-block-paragraph">We can go no further as this would constitute an intrusion, and I&#8217;m strictly a  white hat.</p>



<h2 class="wp-block-heading">Analysis</h2>



<p class="wp-block-paragraph">Given what we know:</p>



<ul class="wp-block-list"><li>The link in the email takes the user clicking on it on a detour to pyrobee.com, a server in Germany, and then automatically bouces the unwary user to Tillväxtverket. This way, it will look legit. This link has, what looks to be a identifier, that is most likely connected to the email-adress the mail was sent to. Thus the Pyrobee.com-server will know who clicked on the link.</li><li>Most likely this gives the hacker a list of people that clicked on the link and who can now be further investigated and targetted for phishing attacks in the future. Caveat emptor: don&#8217;t click the link! (Unless you&#8217;re like me, curious and want to see what happens..)</li><li>It&#8217;s impossible to say if this attack was aiming to target Tillväxtverket in any way or capacity, or if they were selected to give the attack itself a semblance of credibility.</li><li>The server sending the email is barely configured at all and only the services needed to send the emails seem have anything more than just minimal &#8220;dial tone&#8221;-setup.</li><li>It&#8217;s likely not to be secured in any meaningful matter. I cannot, as I stated, investigate this any further</li><li>The server in Germany uses a template that teases with stuff like podcasts and a blog, but in reality does not exist. It&#8217;s kinda a good thing to remove services featured on the template by default, if you don&#8217;t intend to offer them. Looks more serious like that.</li><li>Real advertising campaigns often work exactly like this, but they generally don&#8217;t use badly built servers running on someones home broadband connection and then redirect you to another, barely setup server in Germany.  Also, they DO NOT SEND spam that tries to fool you that the message is an answer to a previous discussion with the sender that obviously did not happen.</li></ul>



<h2 class="wp-block-heading">Time line</h2>



<p class="wp-block-paragraph">2020-08-07 &#8211; The domain bxsmail.com was registered. It&#8217;s probably around this time the mails started appearing.</p>



<p class="wp-block-paragraph">2020-09-11 &#8211; I noticed the mail, that was sent to my private email address, in my junk folder and started to investigate the matter. Had to stop due to needing to sleep.</p>



<p class="wp-block-paragraph">2020-09-11 &#8211; Asked Telia to shut the server in Sweden (bxsmail) down.</p>



<p class="wp-block-paragraph">2020-09-12 &#8211; Sporadic work in spare time during a trip to another city in Sweden.</p>



<p class="wp-block-paragraph">2020-09-12 16:12 &#8211; completed the report after some questions were asked and then added new stuff I found.</p>



<p class="wp-block-paragraph">2020-09-12 16:23 &#8211; reported Pyrobee.com to their upstream provider&#8217;s abuse department.</p>



<p class="wp-block-paragraph">2020-09-12 17:xx &#8211; reported spam to spamcop.</p>



<p class="wp-block-paragraph">2020-09-13 19:xx &#8211; They have now created more domains with servers: ettmoln.com and merkurex.com. Probably not a complete list, but I will update as soon as I learn more&#8230; Their weak point is pyrobee.com. Take that down and they will have nothing going on.</p>



<p class="wp-block-paragraph">2020-09-12 22:31 &#8211; The identity of the owner of all the servers has been found. He wrote it on Pyrobee&#8217;s FaceBook-page. The name is Magnus, but I will not write his whole name here as to stay within the Swedish law. He lives exactly in the same postal code (zip code) area where the bxsmail.com server is located. I have a hard time believing this&#8230; Really takes the cake.</p>



<p class="wp-block-paragraph">2020-09-14 &#8211; Right, I was told by the German abuse-department that they will not process the report unless they can tell the owner about it. That will effectivly send this link to the guy behind all this. Who said life should not be interesting?</p>



<h2 class="wp-block-heading">Evidence and other material</h2>



<p class="wp-block-paragraph">The spam mail, complete with all headers:<br><a href="https://erik.zalitis.se/files/spam.txt">https://erik.zalitis.se/files/spam.txt</a></p>



<h2 class="wp-block-heading">Thanks</h2>



<p class="wp-block-paragraph">Malin Ekström for spotting a thing I missed.<br>The rest of the &#8220;<a href="https://www.facebook.com/groups/sakerhetsbubblan/">Säkerhetsbubblan</a>&#8220;-Facebook group for aiding me in my research&#8230; You guys and gals rock.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://erik.zalitis.se/it-security/the-anatomy-of-an-attack/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">297</post-id>	</item>
		<item>
		<title>My burp just barfed</title>
		<link>https://erik.zalitis.se/it-security/my-burp-just-barfed/</link>
					<comments>https://erik.zalitis.se/it-security/my-burp-just-barfed/#comments</comments>
		
		<dc:creator><![CDATA[Erik Zalitis]]></dc:creator>
		<pubDate>Wed, 02 Sep 2020 07:48:31 +0000</pubDate>
				<category><![CDATA[IT-security]]></category>
		<category><![CDATA[Pentesting]]></category>
		<guid isPermaLink="false">https://erik.zalitis.se/?p=286</guid>

					<description><![CDATA[Update 2020-09-28: Answer from Burp suite support: Screen redraw issues have appeared on various Windows versions when custom scaling has been adjusted in the display settings. Have you adjusted the default scaling behavior at all? If so, can you try returning that to the default setting? Additionally, can you try adding the following options to [&#8230;]]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" src="https://erik.zalitis.se/wp-content/uploads/2020/09/Burp-broken.png" alt="" class="wp-image-287" width="1553" height="837" srcset="https://erik.zalitis.se/wp-content/uploads/2020/09/Burp-broken.png 1553w, https://erik.zalitis.se/wp-content/uploads/2020/09/Burp-broken-300x162.png 300w, https://erik.zalitis.se/wp-content/uploads/2020/09/Burp-broken-1024x552.png 1024w, https://erik.zalitis.se/wp-content/uploads/2020/09/Burp-broken-768x414.png 768w, https://erik.zalitis.se/wp-content/uploads/2020/09/Burp-broken-1536x828.png 1536w, https://erik.zalitis.se/wp-content/uploads/2020/09/Burp-broken-1200x647.png 1200w" sizes="auto, (max-width: 1553px) 100vw, 1553px" /><figcaption>Burp suite, as painted by Picasso. Not rare at all amazingly enough and not valued for its intrinsic artistic skills.</figcaption></figure>



<p class="wp-block-paragraph">Update 2020-09-28: Answer from Burp suite support:</p>



<figure class="wp-block-pullquote"><blockquote><p>Screen redraw issues have appeared on various Windows versions when custom scaling has been adjusted in the display settings. Have you adjusted the default scaling behavior at all? If so, can you try returning that to the default setting? Additionally, can you try adding the following options to your VMOPTIONS file? This can be found in the installation directory. </p><p>1: -Dsun.java2d.noddraw=true <br>2: -Dsun.java2d.d3d=false <br>3: -Dswing.useflipBufferStrategy=True <br>4: -Dsun.java2d.ddforcevram=true <br>5: -Dsun.java2d.ddblit=false </p><p>You can add them in order until the issue disappears or add all of them at once.</p><cite><a href="https://forum.portswigger.net/thread/gui-graphics-corruption-at-random-intervals-14765ccb">https://forum.portswigger.net/thread/gui-graphics-corruption-at-random-intervals-14765ccb</a></cite></blockquote></figure>



<p class="wp-block-paragraph">Is it just me, or is this a common thing? It kinda makes my pentesting experience quite dull. The only resolution is to restart the program if you can find out how and then you lose a lot of your progress. Thanks a bunch&#8230;</p>



<p class="wp-block-paragraph">What&#8217;s happening here? Well, this problem occurs after a few minutes or hours. The window seems to &#8220;break apart&#8221; and the different pieces move around as you move your mouse or &#8230;. worse&#8230; click around.</p>



<p class="wp-block-paragraph">When you stop the program, it sometimes seems to corrupt the saved file and you could easily lose days of work.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://erik.zalitis.se/it-security/my-burp-just-barfed/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">286</post-id>	</item>
	</channel>
</rss>
