Många dödade i attacker i Irak SvD Utrikes(cached at July 12, 2013, 11:33 pm)

Minst 18 personer har dödats och 28 skadats i en självmordsattack mot ett kafé i Kirkuk, rapporterar AFP.
Flera döda i tågolycka nära Paris SvD Utrikes(cached at July 12, 2013, 11:33 pm)

Dödstalet befarades i kväll stiga efter det att ett intercitytåg med 370 personer ombord spårat ur söder om Paris.
Amazon One-Click Chrome Extension Snoops On SSL Traffic Slashdotby Soulskill on chrome at January 1, 1970, 1:00 am (cached at July 12, 2013, 11:33 pm)

An anonymous reader writes "It turns out Amazon has its own sketchy method of snooping on all your browser traffic — even SSL traffic — through their one-click extension for Chrome. As designed, the extension reports every URL you visit, including HTTPS ones, to Amazon. It uses XSS to provide some of its functionality. It also reports contents of some website visits to Alexa. The Amazon extension has also been exploited to allow an attacker to gain access to SSL traffic on browsers that have it installed."

Read more of this story at Slashdot.



Hmm - where did I save those files?, (Fri, Jul 12th) SANS Internet Storm Center, InfoCON: green(cached at July 12, 2013, 11:30 pm)

A client recently called me with some bad news.  "Our CFO's laptop was just stolen!" he told me - "What should we do?".  My immediate response (and out-loud I'm afraid) was "Fire up the Delorean, go back in time and encrypt the drive".  Needless to say, he wasn't keen on my response, even though I offered up a spare flux capacitor - maybe his Delorean was in the shop.

His response actually suprised me "We're actually in the middle of a WDE (WHole Disk Encryption) project.  The CFO's laptop was scheduled for next week (delayed at his request)".  But no matter how good that project is, it wasn't helping us today.
This client is under both NERC and PCI regulation, so I asked the obvious "did he have any financial data on his machine?  Do you need to disclose the theft as a breach?".  The response was an immediate "he says not".  Since the answer wasn't a definite "no", I asked the obvious - "Do you believe him?"  The answering pause really said it all.

Having just taken SANS FOR408, I know for a fact that even if he didn't save anything to the laptop, the presense of files and either parts of or full files are strewn across the file structure, registry and a kazzilion other locations on the machine.

So the scenario and a fun forensics question to end your week is:
A Windows 7 laptop, fully patched with Office 2010 installed
The corporate browser is IE10, but Firefox is also installed

Using our comment form
, share where you would look for sensitive files, fragments of files or indicators of the presence of files.
Passwords, links and other sensitive information are all in play.

Let's assume that the user didn't download anything to the "downloads" directory, and didn't have "I don't know where I saved that file" files strewn across his local profile and drive (even though that's extremely likely)

I'll update this story in a week or so with how the story played out, and how we made the point to the CFO.

Happy forensicating everyone!
 

===============
Rob VandenBrink
Metafore

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Skickade räkning till avliden SvD Inrikes(cached at July 12, 2013, 11:03 pm)

En kvinna i Ronneby fick en räkning för mat som hennes far skulle ha ätit på ett äldreboende under sommaren, rapporterar SVT:s Blekingenytt.
Man tafsade på Lisebergskanin SvD Inrikes(cached at July 12, 2013, 11:03 pm)

Anställd iklädd en kanindräkt ofredad.
Japanese Gov't Accidentally Shares Internal Email Over Google Groups Slashdotby Soulskill on japan at January 1, 1970, 1:00 am (cached at July 12, 2013, 11:03 pm)

itwbennett writes "An official at Japan's Ministry of the Environment created a Google Group to share email and documents related to Japan's negotiations during a meeting held in Geneva in January, but used the default privacy settings, which left the exchanges wide open. According to Japan's Yomiuri Shimbun newspaper, over 6,000 items, including private contact information of government officials, was publicly accessible. Michihiru Oi, a ministry official, said the ministry has its own system for creating groups and sharing documents, but it doesn't always function well outside of Japan, sometimes leading to 'poor connections' and a 'bad working environment.'"

Read more of this story at Slashdot.



Israeli group decries juvenile's detention AL JAZEERA ENGLISH (AJE)(cached at July 12, 2013, 11:00 pm)

Rights group urges Israeli military to "change tactics" when dealing with Palestinian youth in occupied West Bank.
Women In Technology: Overcoming Obstacles to STEM Careers (Network Computing Securit SANS ISC SecNewsFeed(cached at July 12, 2013, 11:00 pm)

Man försökte röva bort barn SvD Inrikes(cached at July 12, 2013, 10:33 pm)

En man har gripits misstänkt för olaga frihetsberövande efter att han försökte röva bort ett tioårigt barn på Liseberg i Göteborg.
The Savvy Tech Strategy Behind Obamacare Slashdotby Soulskill on government at January 1, 1970, 1:00 am (cached at July 12, 2013, 10:33 pm)

snydeq writes "The U.S. health care industry is undergoing several massive transformations, not the least of which is the shift to interoperable EHR (electronic health records) systems. The ONC's Doug Fridsma discusses the various issues that many health care IT and medical providers have raised regarding use of these systems, which are mandated for 2014 under the HITECH Act of 2004, and are all the more important in light of the 2010 Patient Protection and Affordable Care Act, aka Obamacare. Key to the transition, says Fridsma, is transforming health IT for EHRs into something more akin to the Internet, and less like traditional ERP and IT systems. 'I think what we're trying to do is the equivalent of what you've got in the Internet, which is horizontal integration rather than vertical integration,' Fridsma says. 'We've done a lot of work looking at what other countries have done, and we've tried to learn from those experiences. Rather than trying to build this top down and create restrictions, we're really trying to ask, "What's the path of least regret in what we need to do?"'"

Read more of this story at Slashdot.



Bomber hits peacekeeping convoy in Somalia AL JAZEERA ENGLISH (AJE)(cached at July 12, 2013, 10:30 pm)

Two civilians killed in suicide bomb attack targeting African Union peacekeeping forces in capital Mogadishu.
Dropbox, WordPress used in cyberespionage campaign (NetworkWorld Security) SANS ISC SecNewsFeed(cached at July 12, 2013, 10:30 pm)

TA13-193A: Exploit Tool Targets Vulnerabilities in McAfee ePolicy Orchestrator (ePO) SANS ISC SecNewsFeed(cached at July 12, 2013, 10:30 pm)

"Layer 4-7 Service Chain problem statement" - Linda Dunbar, Donald SANS ISC SecNewsFeed(cached at July 12, 2013, 10:30 pm)