Belägring över i Tripoli SvD Utrikes(cached at May 11, 2013, 11:32 pm)

Libyska milismän som belägrat två departementsbyggnader i huvudstaden Tripoli i snart två veckor har dragit sig tillbaka.
Minst 40 döda i flera samtidiga bilbomber SvD Utrikes(cached at May 11, 2013, 11:32 pm)

I Reyhanli nära gränsen mot Syrien.
Ask Slashdot: How Do You Deal With Programmers Who Have Not Stayed Current? Slashdotby Soulskill on business at January 1, 1970, 1:00 am (cached at May 11, 2013, 11:32 pm)

skaffen42 writes "The recent Ask Slashdot about becoming a programmer later in life got me thinking about a related question. How do you deal with programmers who have not stayed current with new technologies? In the hiring process, this is easy; you simply don't hire them. However, at most companies where I've worked, there are usually a few programmers who have been employed long enough that the skill-set they were originally hired for has become irrelevant. At the same time, they have not bothered to stay current with newer technologies. They usually have enough business knowledge that they provide some value to the company, but from a technical perspective they are a slowly-increasing liability. As an example: I work with a developer who is 10 years my senior, but still doesn't understand how to write concurrent code and cannot be trusted to use a revision control system without causing a mess that somebody else will have to clean up. On top of that, he is really resistant to the idea of code reviews; I suspect he dislikes people he considers junior to him making suggestions about how to improve his code. So, how do my fellow Slashdotters handle situations like this? How do you help somebody like this to improve their skill-sets? And, most importantly, how do you do so without stepping on anybody's feelings?"

Read more of this story at Slashdot.



Cuba government holds anti-homophobia parade AL JAZEERA ENGLISH (AJE)(cached at May 11, 2013, 11:30 pm)

La Rampa was danced through the streets of Havana in a march against homophobia led by the president's daughter.
Israelis march against austerity budget AL JAZEERA ENGLISH (AJE)(cached at May 11, 2013, 11:30 pm)

Police say 2,000 people marched in Tel Aviv against new finance minister's proposed tax rises and spending cuts.
Global network of hackers steals $45M from ATMs (Yahoo Security) SANS ISC SecNewsFeed(cached at May 11, 2013, 11:30 pm)

”Tacka Allah som har gett oss en ny chans” SvD Utrikes(cached at May 11, 2013, 11:02 pm)

Sharif har utropat sig till valvinnare.
HIPAA Risk Analysis Tips - Open Appeal to Risk Thought Leaders (IT Toolbox Blogs) SANS ISC SecNewsFeed(cached at May 11, 2013, 11:00 pm)

Extracting Digital Signatures from Signed Malware, (Sat, May 11th) SANS Internet Storm Center, InfoCON: green(cached at May 11, 2013, 11:00 pm)

Sometimes attackers digitally sign their malicious software. Examining properties of the signature helps malware analysts understand the context of the incident. Moreover, analysts could use the signature as an indicator of compromise. Here are some tips and tools for determining whether a suspicious Windows executable has been signed and for extracting the embedded signature in a Linux environment. We'll look at Pyew, Disitool and get a bit of help from OpenSSL.

Microsoft's Windows Authenticode Portable Executable Signature Format document explains that the signatures can be embedded "in a Windows PE file, in a location specified by the Certificate Table entry in Optional Header Data Directories." The location of the signature is stored within the PE header's OptionalHeader structure's Security field.

One way to determine whether the file contains an embedded signature is to use Pyew, which is a command-line hex editor/disassembler for malware analysis. After loading the sample into Pyew, you can look at the size of the IMAGE_DIRECTORY_ENTRY_SECURITY field. A non-zero value indicates that the file probably includes an embedded signature.To do this, load the PE file into Pyew and enter the command "pyew.pe.OPTIONAL_HEADER.DATA_DIRECTORY". Then look at the size of IMAGE_DIRECTORY_ENTRY_SECURITY as shown below:

Pyew Signature Header

In the Pyew output above, we see that the size of IMAGE_DIRECTORY_ENTRY_SECURITY is non-zero. This indicates that kiwi.exe probably includes an embedded signature.

Disitool provides another way of determining whether a PE file includes a signature. This tool, created by Didier Stevens, can delete, copy, extract and add signatures. If you attempt to extract a signature from a non-signed file, Disitool will tell you "source file not signed."

In the example below, we see that the file has been signed. The author of this malicious file seems to have used a stolen certificate to sign the specimen. Disitool's "extract" command pulled out the signature, so we can examine it.

Disitool Extract Signature

Disitool saves the extracted certificate in the binary DER format. You can look at the strings embedded in the DER file to examine its contents. Even better, you can use the following OpenSSL command to convert the DER file into a more informative text file:

openssl pkcs7 -inform DER -print_certs -text -in INPUT_FILE > OUT_FILE

Knowing how to spot signed files and extract signature details can be helpful for malware and forensic analysts. On Windows, you can gather some of these details by right-clicking on the PE file and looking at its properties, as well as with the help of Microsoft's Sign Tool and Sigcheck tools. On Linux, you can accomplish this with the help of Pyew, Disitool and OpenSSL, which are installed on REMnux for your convenience.

 

-- Lenny Zeltser

Lenny Zeltser focuses on safeguarding customers' IT operations at NCR Corp. He also teaches how to analyze malware at SANS Institute. Lenny is active on Twitter and writes a security blog.

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Astronauts Fix Phantom Space Station Ammonia Leak Slashdotby Soulskill on iss at January 1, 1970, 1:00 am (cached at May 11, 2013, 10:32 pm)

astroengine writes "During an unscheduled spacewalk on the space station's exterior on Saturday morning, NASA astronauts Tom Marshburn and Chris Cassidy carried out the mother of all plumbing jobs: They detached a suspect ammonia pump, replaced it with a spare and watched for any further ammonia leakage. The emergency spacewalk was carried out in response to a troubling ammonia coolant leak that was discovered on Thursday. The coolant is used to maintain the temperature of the vast solar arrays the space station uses to generate electricity for its systems. 'It will take some diagnostics, still, over the course of the next several days by the thermal systems specialists to fully determine that we have solved the problem of the ammonia leak," said NASA commentator Rob Navias during the live NASA TV spacewalk broadcast. 'But so far, so "good."'"

Read more of this story at Slashdot.



The great ATM heist: How thieves brazenly stole $45 million in a few hours (Yahoo Se SANS ISC SecNewsFeed(cached at May 11, 2013, 10:30 pm)

Weather-WWO-0.05 search.cpan.orgby Mateu X. Hunter at January 1, 1970, 1:00 am (cached at May 11, 2013, 10:02 pm)

World Weather Online Data
NASA emergency mission successful AL JAZEERA ENGLISH (AJE)(cached at May 11, 2013, 10:00 pm)

Astronaut tweets that repairing of pump during an emergency space walk at the International Space Station a success.
Elva döda i attacker mot valet i Pakistan SvD Utrikes(cached at May 11, 2013, 9:32 pm)

Väntas ovanligt högt valdeltagande.
Barn kan ligga bakom förskolebrand SvD Inrikes(cached at May 11, 2013, 9:32 pm)

Polisen utesluter inte att branden som ödelade förskolan Igelkotten i Krylbo under fredagskvällen och natten mot i dag var anlagd.