Ref: http://www.ti.com/tool/cc2531usb-rd
Friday, April 24, 2015
Friday, April 17, 2015
Redirect To SMB vulnerability
Ref: http://www.makeuseof.com/tag/every-version-windows-vulnerability/
Every Version of Windows Is Affected By This Vulnerability – What You Can Do About It.
By Christian Cawley on 16th April, 2015 | Security Matters,Windows | 2 Comments
What would you say if we told you that your version ofWindows is affected by a vulnerability that dates back to 1997? You’d laugh, right? Surely, after all, Microsoft would have patched the fault prior to releasing Windows 98, or at the latest, Windows 2000?
Well, not quite.
This Redirect to SMB vulnerability has its roots in the identically-named attack discovered by Aaron Spangler 18 years ago. And it’s a problem that you need to do something about, because it doesn’t only affect Windows, but also programs from Adobe, Apple, Symantec and even the Windows 10 preview.
Redirect to SMB: What Does it Do?
Affecting Windows PCs, tablets and servers, Redirect to SMB – discovered by Cylance’s Brian Wallace – is a development of the original vulnerability.
In 1997, Spangler found that introducing URLS beginning “file” would cause Windows to attempt authentication with an SMB server at the given IP address (for example, file://1.1.1.1), which could then be used to record login credentials. These URLs could be introduced as images, iframes, or any other media displayed by the browser.
SMB is the Server Message Block protocol, mostly used for sharing files, printers, and serial ports on a network. Various versions have been released over the years, (Samba is an open source implementation, although there is no suggestion that the vulnerability exists there) and it has long been a target, with real-time scanning demonstrating that SMB is one of the most popular attack vectors for online intruders. It was reported in December that the Sony Pictures hack wasperformed using an SMB vulnerability.
Redirect to SMB was uncovered by the Cylance team as they investigated ways to abuse a chat client.
“When a URL to an image was received, the client attempted to show a preview of the image. Inspired by Aaron’s research some 18 years ago, we promptly sent another user a URL starting with file:// which pointed to a malicious SMB server. Surely enough, the chat client tried to load the image, and the Windows user at the other end attempted to authenticate with our SMB server.
“We created an HTTP server in Python that answered every request with a simple HTTP 302 status code to redirect clients to a file:// URL, and using that we were able to confirm that an http:// URL could lead to an authentication attempt from the OS.”
It doesn’t take much to prompt someone to enter their credentials, after all – just a legitimate-looking dialogue box.
How Redirect to SMB Might Be Used Against You
Four Windows API functions can be used to redirect a HTTP or HTTPS connection to an SMB connection, where a malicious server may await to siphon away user credentials, and reuse them for nefarious purposes.
Brian Wallace explains that for Redirect to SMB to be successful, the attacker must be reasonably advanced as there is a requirement to “control… some component of a victim’s network traffic.”
He also points out that the threats can come in the shape of malicious adverts forcing authentication attempts, and Redirect to SMB can also be used in a drive by hack on public Wi-Fi networks (dangerous at the best of times), launched from a portable computer, and even an Android smartphone.
Potentially one of the most dangerous attack vectors unleashed by Redirect to SMB is via Apple’s iTunes Software Updater. In this scenario, a compromisedDNS record could lead to redirect updates being directed to an SMB server, again with the result that credentials are farmed via a classic Man-In-The-Middle attack.
Put simply, this is a vulnerability that should have been closed 18 years ago. While Microsoft offered ways to mitigate it then, the opposition – the black hats – have become far more sophisticated in their attacks, with more and more Internet users representing a big pay day. Now would seem to be the time for Microsoft to get its act together on SMB security.
Software Affected by Re-Direct to SMB
Okay, it’s deep breath time. As well as every version of Windows the mid-1990s, Redirect to SMB also affects a wide selection of applications and system utilities (at least 31) from some of the biggest names in the industry. To begin, Microsoft and Apple.
Microsoft:
Internet Explorer 11Windows Media PlayerExcel 2010Microsoft Baseline Security Analyzer
Apple:
QuickTimeApple iTunes Software Update
Frustratingly for a vulnerability of this kind, security software is also affected.
Symantec Norton Security ScanAVG FreeBitDefender FreeComodo Antivirus
Productivity apps that are known to be vulnerable to Redirect to SMB:
Adobe ReaderBox Sync (the Box.net cloud client app)TeamView
These utilities and installers are also affected:
.NET ReflectorMaltego CEGitHub for WindowsPyCharmIntelliJ IDEAPHP StormOracle JDK 8u31’s installer
As you can see, this is quite a list, with every application a potential gateway to your credentials for an attacker. But what can you do about it?
Workaround, or Wait for a Patch?
Microsoft is said to be working on a patch to fix the Redirect to SMB vulnerability. But until that happens, what can you do?
As reported by cybersecurity experts Cylance, the best fix is to block traffic sent outbound from your computer through your software firewall or through your router, on TCP 139 and TCP 445. This will block SMB communication between your network and the Internet, and if the change is made on the network firewall, you will still be able to use SMB between devices on your local network. Our guide to the Windows Firewall explains how to create these rules in just a few seconds; for your router, you’ll need to check the device documentation.
Given the breadth of operating systems and applications affected by this vulnerability, and with the impending arrival of Windows 10, isn’t it about time Microsoft did something about it?
Image Credits: Password via Shutterstock
Thursday, April 16, 2015
How to split a very large text or CSV file by a specific number of lines/rows
How to split a very large text or CSV file by a specific number of lines/rows
- Background: I am going to describe an example whereby I split a file called “chunk.csv” into several pieces that are a maximum of 10,000 rows each. This same process will work on any type of text file (for example TXT, INI, LOG, BAT, DIZ, BAK, and QUE) and you can customize this process to exactly the number of rows you require for your use.
- Download and install Gsplit. This is the program that will perform the operation and it is 100% freeware, even for commercial use.
- Run Gsplit.
- Click “Original file” in the left sidebar. Click on the “browse” button under “file to split”. Browse to and click on the file you want to split.
- Click “Destination folder” in the left sidebar. Click on the “browse” button under “destination path” on the right. Browse to the folder where you would like your output files to be saved.
- Click “Type and Size” in the left sidebar. This is where all the interesting stuff will take place. Click on “Blocked Pieces” icon. Next, from the dropdown select “I want to split after the nth occurrence of a specified pattern”; and from the dropdown under that “Split after the occurrence number”. Enter the number of lines you want to split underneath (10,000 in this case, but you can enter the value that you need). Lastly, make sure that the pattern to use for splitting is “0x0D0x0A” (without quotes). This value is the hex code for a carriage return, and it should be displayed by default.
- Click “Filenames” in the left sidebar. In the “piece name mask” field enter “{ofw}_{num}{ore}”(without quotes). This will generate pieces with the original file extension and the original file names that look like “filename_1.csv”. Alternately, you could leave this alone altogether, go with the default generated names, and simply rename the extension to “.csv” (or whatever your original extension is) in Windows explorer.
- Click “Other Properties” in the left sidebar. check “do not add tags to piece files”, This will ensure that no additional information will be added to your original data.
You’re now ready to split. Click on the “Split” button in the upper toolbar. Your file should be split within seconds. Once the splitting process is finished you will see the “Splitting log” screen. Click on the “Open the folder in Windows Explorer” link to instantly jump to the output folder.
Optional: save your splitting profile. If you are going to repeat this splitting process in the future you might consider saving these settings as a “profile” that can be loaded when you need it so that you do not have to go through these process again. To do so select “Save a Profile As” from the “File” Menu.
Tuesday, April 14, 2015
Monday, April 13, 2015
Path Manipulation in a Batch File
Path Manipulation in a Batch File
%~I - expands %I removing any surrounding quotes (")
%~fI - expands %I to a fully qualified path name
%~dI - expands %I to a drive letter only
%~pI - expands %I to a path only
%~nI - expands %I to a file name only
%~xI - expands %I to a file extension only
%~sI - expanded path contains short names only
%~aI - expands %I to file attributes of file
%~tI - expands %I to date/time of file
%~zI - expands %I to size of file
%~$PATH:I - searches the directories listed in the PATH environment variable and expands %I to the fully qualified name of the first one found. If the environment variable name is not
defined or the file is not found by the search, then this modifier expands to the empty string
The modifiers can be combined to get compound results:
%~dpI - expands %I to a drive letter and path only
%~nxI - expands %I to a file name and extension only
%~fsI - expands %I to a full path name with short names only
%~dp$PATH:I - searches the directories listed in the PATH environment variable for %I and expands to the drive letter and path of the first one found.
%~ftzaI - expands %I to a DIR like output line