<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Computer Solutions Blog &#187; Thoughts</title>
	<atom:link href="http://www.computersolutions.cn/blog/tag/thoughts/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.computersolutions.cn/blog</link>
	<description>Whats happening at Computer Solutions</description>
	<lastBuildDate>Thu, 02 Sep 2010 08:07:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Random! (semi) Interesting! Thing!</title>
		<link>http://www.computersolutions.cn/blog/2009/04/random-semi-interesting-thing/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=random-semi-interesting-thing</link>
		<comments>http://www.computersolutions.cn/blog/2009/04/random-semi-interesting-thing/#comments</comments>
		<pubDate>Tue, 21 Apr 2009 20:36:03 +0000</pubDate>
		<dc:creator>Lawrence Sheed</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[eclectic]]></category>
		<category><![CDATA[Kitto]]></category>
		<category><![CDATA[projects]]></category>
		<category><![CDATA[random crap]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[waffle]]></category>

		<guid isPermaLink="false">http://www.computersolutions.cn/blog/?p=222</guid>
		<description><![CDATA[Apparently the new thing in blogging in China is to be eclectic. While I have been blogging/writing in China for a good few years longer than most of even the longest China blogs out there (I started in 95, beat that haha!), I haven&#8217;t really thrown it all into one spot. Plus mostly it all [...]]]></description>
			<content:encoded><![CDATA[<p>Apparently the new thing in blogging in China is to be eclectic.</p>
<p>While I have been blogging/writing in China for a good few years longer than most of even the longest China blogs out there (I started in 95, beat that haha!), I haven&#8217;t really thrown it all into one spot.</p>
<p>Plus mostly it all went into forum postings on long lost sites that I should revive at some point (<a href="http://www.ddsclub.com">D.D&#8217;s Club</a> and <a href="http://www.shanghaiguide.com">Shanghaiguide</a> I&#8217;m looking at you), so there is a vague chance I may get to revive some of it from the depths of bit rot hell, and post select bits in one place.</p>
<p>Too be honest, this is probably going to turn into a rant or pure SEO spammy keyword promo post to get more hits for the blog anyway but&#8230;</p>
<p>Apparently I should also mention Puppies, Kittens, that cool dude I totally hung out with last night and partied till dawn with, and the 15 chicks we hooked up with that night, plus god isn&#8217;t China a total pit, I mean they don&#8217;t even speak English here, what the F!*</p>
<p>*This is an in-joke that no-one else will get but <a href="http://fashion-and-gossip.com/2009/04/want-to-diss-my-blog-thats-shanghai-miss-helen-ok-cool-it-is-then-on.html">the Jojo</a>, and readers of <a href="http://www.urbanatomy.com">That&#8217;s not Kitto</a>.</p>
<p>Back to being eclectic, shall we, and less of the &#8220;in&#8221; jokes.</p>
<p>The honest truth is that I&#8217;m eclectic enough apparently, although that might also be a slightly schizophrenic way of looking at my diverse random project ideas.</p>
<p>Over the last few months, we&#8217;ve done the following interesting projects, some for love, some for money, and some for the hell of it.</p>
<p>Figure out which is which, and see which of them you like.</p>
<p>No.1 on our list is:  <a href="http://LiURL.cn">LiURL.cn</a></p>
<p>Lets face it, once a geek, always a geek.<br />
I discovered twitter, and for a few days was happy playing in a new medium.<br />
I did note that twitter had a limited character span (140 chars) for messages, and it truncated URL&#8217;s to save space.<br />
Taking a quick look around I saw plenty of clones oversea&#8217;s, but nothing local, so I grabbed my trusty keyboard, and a few hours later and a quick search of what was left in .cn domain space I invented LiURL.cn, the first Chinese TinyURL clone.</p>
<p>Its even got its own <a href="http://blog.liurl.cn">blog</a>, and <a href="http://www.twitter.com/liurl">twitter</a> feed.</p>
<p>Use is slowly growing, and we&#8217;re starting to see an increase in use and awareness of LiURL.cn in China and oversea&#8217;s.</p>
<p><a href="http://www.smartshanghai.com">SmartShanghai.com</a> has also started using it for their venue twitter links (5000+ urls).</p>
<p>No. 2 is &#8211; <a href="http://www.iWantOne.cn">iWantOne.cn</a></p>
<p>iWantOne started out as an outlet for our badges.</p>
<p>The badges themselves started out from a post on <a href="http://lpcoverlover.com/2008/09/09/moa-sounds">LPCoverLover</a> via a sighting on <a href="http://www.boingboing.net">BoingBoing</a>.</p>
<p>A quick trip to <a href="http://www.taobao.com">taobao</a>, and we had a badge machine, and lots of idea&#8217;s.</p>
<p>These quickly culminated in my staff going nuts over snoopy badges, and my prompting them for cool stuff for foriegners (we&#8217;re suckers for cultural revolution related artwork).</p>
<p>We quickly got bored doing that, and moved onto cool phrases.</p>
<p>Coffee at Moganshan lu led to a brainstorming session about cool ways to promote Shanghainese (an under promoted language imho), and a whole set of cool phrases.</p>
<p>Some publicity shots, and some talk about it over <a href="http://56minus1.com/2009/03/things-done-well-badges/">here</a> at <a href="http://56minus1.com">56minus1.com</a>.<br />
(Note that I am also occasionally a contributor to the 56minus1 blog, although I completely avoid talking about stuff we do ourselves).</p>
<p>No 3.    Fridge Magnets &#8211; is a rather cool unique idea, and something that led on from the badges.</p>
<p>One of our clients asked me why we didn&#8217;t put an English translation on the badges as well.  Which, to be honest,  I&#8217;d thought about, but as I&#8217;m a pretentious I can speak Chinese better than you so nya nya kind of foreigner, didn&#8217;t want to do.  Plus it also meant remaking a bunch of badges, and I&#8217;m lazy.<br />
*Pick one of the above for the correct answer.  </p>
<p>It did lead me to think, well hey, why don&#8217;t I make some magnet word sets like you used to see a few years back when Magnet Poetry was all the craze.</p>
<p>An idea was born&#8230;</p>
<p>A few days later, we had our first rough draft of the first magnet set we wanted to make &#8220;Talking to your Ayi&#8221;, and a few agonizing days later teaching my art team how to use illustrator correctly so I didn&#8217;t have to spend over 12 hours redoing their alleged &#8220;good&#8221; version *again*, we had something we could play around with.  This also involved some running with scissors, and lots of small pieces of sharp paper, to put the danger, and comic tragedy of it all into perspective.</p>
<p>A quick round or two with friends, roman&#8217;s and countrymen, and we had most of the mistakes corrected also.<br />
Interesting factoid &#8211; I could point out more mistakes than the native speakers could.</p>
<p>Even more weeks passed and we had a sample set.  Even more weeks x2 later,  lots of shouting, changes, and scowling  (followed by light rain), we actually had a box design that I liked, and all was good.</p>
<p>This was closely followed by lots of my own money changing hands with dodgy factories in outer godknowswhere, a minor whoops at the factory meaning a reprint, and finally a rather large kuaidi delivery to our office later, I actually had a product in my hands, yay!</p>
<p>We&#8217;re currently pimping the sets out to anyone that stands still long enough &#8211; <a href="http://SmartShanghai.com">Smart Shanghai</a> is the first to publish something about us, and expect to have some more publicity and some sales soon.<br />
Plus, its been rather fun making something that people can buy (or I can throw at the kuaidi guy), instead of our usual intangible products &#8211; websites, websites, and more websites.</p>
<p>Our Fridge Lingo Magnet sets are available now at select venues around town, or via the <a href="http://iwantone.cn">iWantOne.cn</a> website.</p>
<p>Direct link to the <a href="http://liurl.cn/eu">Magnet sets here</a>.<br />
They are honestly quite cool, and I&#8217;m extremely happy to be a father to my first live baby project.</p>
<p>Anyway, I&#8217;ve rambled on enough, and to be honest, I&#8217;m a lot more eclectic on <a href="http://www.twitter.com/compsolutions">Twitter</a>.</p>
<p>This is Lawrence signing out, and I hope you enjoyed the ride.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.computersolutions.cn/blog/2009/04/random-semi-interesting-thing/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Spyware Wars</title>
		<link>http://www.computersolutions.cn/blog/2009/03/the-spyware-wars/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=the-spyware-wars</link>
		<comments>http://www.computersolutions.cn/blog/2009/03/the-spyware-wars/#comments</comments>
		<pubDate>Sun, 29 Mar 2009 18:17:08 +0000</pubDate>
		<dc:creator>Lawrence Sheed</dc:creator>
				<category><![CDATA[General Talk]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Thoughts]]></category>

		<guid isPermaLink="false">http://www.computersolutions.cn/blog/?p=147</guid>
		<description><![CDATA[(This is a rough draft, so excuse the lack of editing and / or coherence at points) The news this week is full of alleged government interference with a certain exiled government leaders computers. While there is sufficient evidence of  targeting by state sponsored actors, I don&#8217;t necessarily agree with  everything they wrote in the [...]]]></description>
			<content:encoded><![CDATA[<p><em>(This is a rough draft, so excuse the lack of editing and / or coherence at points)</em></p>
<p>The news this week is full of alleged government interference with a certain exiled government leaders computers.</p>
<p>While there is sufficient evidence of  targeting by state sponsored actors, I don&#8217;t necessarily agree with  everything they wrote in the report, or all their findings.  While there is merit to discussion about that, its probably safer to avoid the topic, and examine how the attacks worked, and what we can do to avoid or mitigate events like that.</p>
<p>The actual report can be read here in PDF format &#8211; <a href="http://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-746.html">http://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-746.html</a></p>
<p><span id="more-147"></span>As the attack was through multiple vectors I thought it would be interesting to do a little actual research, on current techniques.</p>
<p>The report showed that there were a myriad of ways the attackers obtained access.</p>
<p>The first (and most likely to actually have been used) was via simple password cracking.<br />
The targeted mail servers were hosted in the USA, and passwords were obtained using either sniffing or dictionary attack methods.</p>
<p>Once access was obtained,  emails were monitored simply by logging into the mail server and downloading mails.</p>
<p>What can be done to mitigate against that?</p>
<p>The first option, is to use decent passwords for your email, and use encrypted communication between points.<br />
It also helps to actually read the logs on the servers and check for failed logins.</p>
<p>On our email servers here, I get a daily report on failed logins, and can quickly tell if someone is attempting to break in.<br />
We also block further login attempts for a short period of time after a certain number of failures.</p>
<p>This stops dictionary attacks, but won&#8217;t stop a concerted attacker, who can spread attacks over a longer period of time.</p>
<p>In the above case, it would have been fairly easy for officialdom to tell the local ISP up in the Autonomous province to put a filter in the network to search for connections to the target mail server, and log communications.  As communications were going over the network in the clear (encryption wasn&#8217;t in use), the user names and passwords were available to anyone sitting in the right place in the network.  That that wasn&#8217;t done, and different vectors of attack were used is more telling.</p>
<p>Encryption would solve that kind of monitoring though.</p>
<p>There are 2 types of encryption that can be used.  Network encryption, or service encryption.<br />
Mail is usually encrypted using TLS or SSL, we support both styles in our email systems.</p>
<p>If you&#8217;ve setup mail on a Mac using Leopard, you&#8217;ll find that Leopard will automatically detect and set this up for you on our systems.</p>
<p>Encrypted mail would still be visible on the network as headed to the target server though, and given enough time and money, could be decrypted.</p>
<p>One thing to note though is that service encryption only works if the service is encrypted (obviously!).  If you offer multiple ways to access a service, then you are only as secure as the weakest link.</p>
<p>In our setup we offer webmail over unsecured http access.  This means that user name and passwords go over plain text over the internet to our server.    We also offer unencrypted access to POP / SMTP ports, which again travel in plain text over the internet.</p>
<p>I will be taking a look at using SSL encryption for webmail in the near future, although there are a number of issues with that also, mainly to do with the way a handful of companies have sown up the SSL key market (thats a whole other story), making it cost prohibitive.</p>
<p>A better way to communicate would be to use network encryption &#8211; or as its more commonly known &#8211; VPN.</p>
<p>If a VPN was used, all communication from point A -&gt; B would be encrypted.  This is still not infallible though, a VPN wouldn&#8217;t be much use if they used a point to point VPN to a known target, as more advanced techniques could be used to gain access to the VPN (man the middle, replay attacks etc).    VPN&#8217;s are more often used in China to allow access to sites otherwise blocked.</p>
<p>All this talk of encryption though is moot when people have access to one of the computers in the equation.</p>
<p>I&#8217;ll digress for a moment, and take a quick look at the case of banks.</p>
<p>With internet banking, you have a situation where you have an untrusted computer attempting to access a secure system.<br />
Encryption stops people in the middle from snooping, but it doesn&#8217;t prevent someone who has already hacked into a computer from access.  So, how do banks solve this issue?</p>
<p>The solution to unauthorized access lies in the use of multiple access tokens.   The smarter banks are using keyfob random number generators which are used in conjunction with a transaction to verify that its true.  Having multiple contributory authentication mechanisms (google two factor authentication) solves the issue of password theft, as transactions or logins also need to be verified by the random number generator.  Its a shame more banks don&#8217;t use this.</p>
<p>Its interesting to see that Chinese banks (although big fans of ActiveX technology) are ahead of the curve here regarding this, compared to their Western equivalents.</p>
<p>Chinese banks will also send you SMS&#8217;s on transaction completion, and payments, so you get an immediate notification if something is amiss.</p>
<p>More talk about that <a href="http://www.infoage.idg.com.au/index.php/id;1175856000;fp;4;fpid;866209206">here</a> for the interested</p>
<p>If we head back to our original topic again, you&#8217;ll see I mention attack via access to one of the computers.</p>
<p>How do people get access to computers these days?</p>
<p>Spyware / Malware</p>
<p>The prevalence of insecure computers and a lack of security has led to people taking advantage of this fact.  While most infected computers are running Windows, there are a surprising number of servers that are compromised, assisting with the infections.</p>
<p>If we look toward the report regarding the attacks, there is mention of compromised computers being used from Hong Kong, California, and China. (Not so) Strangely enough, this ties in nicely with a large service provider.<br />
<a href="http://blog.fireeye.com/research/2009/02/bad-actors-part-4---hostfresh.html">http://blog.fireeye.com/research/2009/02/bad-actors-part-4&#8212;hostfresh.html</a></p>
<p>China unfortunately has a huge number of compromised servers and desktops used by spammers.  Last time I did some calculations I guesstimated something like 10-20% of all international network traffic in China was spyware related.</p>
<p>For some hard figures on infected <strong>servers</strong> see here &#8211; <a href="http://www.scribd.com/doc/5244100/Atrivo-white-paper-082808ac">http://www.scribd.com/doc/5244100/Atrivo-white-paper-082808ac</a></p>
<p>(figures are on Pages 17 and 18)</p>
<p>Infected computers (not servers) in China number in the<strong> millions</strong>.</p>
<p>If we take a look at the hostfresh report above on the rather good <a href="http://blog.fireeye.com">FireEye</a> blog, you&#8217;ll see mention of a number of different attack mechanisms.</p>
<p>PDF vulnerabilities.<br />
Social Engineering (Mac&#8217;s are starting to see Malware via people installing Trojans masquerading as legit software)<br />
The standard IE vulnerabilities (sad state of affairs really&#8230;)<br />
Javascript exploits.</p>
<p>Worryingly, Mac&#8217;s are starting to be targetted for spyware.   Network monitoring appears to be the easiest method of detection at this point.  See Little Snitch et al.</p>
<p>Control of multiple computers requires a botnet server.   While there was talk about a server in Sichuan which was retrieving documents this in the article and the PDF, there was no real talk of Botnet&#8217;s, when clearly &gt;1200 computers under control implies use of a botnet.</p>
<p>While it would be interesting to explain more about those points in detail, I&#8217;ll skip over that for now (if there is interest, let me know and I&#8217;ll probably write something about it).</p>
<p>This is where I disagree with the report however &#8211; they say that use of Chinese computers proves government involvement.  This is not necessarily the case.   There was a similar report last year about China&#8217;s alleged <a href="http://www.computing.co.uk/computing/news/2204756/people-liberation-army-spying">hacking of UK companies</a>, and yet another one claiming attempts at <a href="http://www.news.com.au/story/0,23599,22403224-2,00.html">Australian computers</a>.  And yet another one about the <a href="http://www.foxnews.com/story/0,2933,435681,00.html">World Bank here</a>.</p>
<p>It is a whole lot more likely, that hacked Chinese computers were used by Malware / Botnet&#8217;s to infect other computers.</p>
<p>Therein lies the crux of the matter, or as we say <a href="http://en.wikipedia.org/wiki/Correlation_causation" target="_blank">Correlation does not <em>imply causation</em></a></p>
<p>Location <strong>does not</strong> imply involvement.   What it <strong>does</strong> imply, sadly, is a systemic lack of system monitoring and security updates at most Chinese hosting providers, which effectively means most attacks will come from Chinese computers.</p>
<p>That said, there is overwhelming evidence of targeted attacks from interested parties in the report.</p>
<p>We&#8217;ve seen a resurgence of attacks again our own servers recently against common applications.  While we can monitor things relatively closely due to our relatively small server base (&lt; 6 machines on 2 continents), its an ongoing threat that isn&#8217;t getting any easier to protect against.<br />
Most of the attacks we see against us are web based scanning of vulnerabilities, or SSH dictionary attacks.   We are seeing a substantial increase in SQL injection attacks though in the last month.</p>
<p>Most of the attacks appear to be from compromised machines in China.   While we try to contact the compromised servers admins, we&#8217;re not always successful.  I usually have to end up using iptables to blacklist their servers from continually trying to scan ours.</p>
<p>An example of this would kind of attack would something like be scan attempts from this ip address 202.108.212.39 (owned by the Institute of Theoretical Physics), which is uh-oh &#8211; a government agency.    We have been seeing a low level of sustained scans from that ip address on one of our servers for at least a year.  Sadly though, the attacker doesn&#8217;t appear know the difference between Windows and Unix, and continually scans for ASP / IIS related holes.<br />
While I&#8217;ve tried to contact the owners of the ip space, their email bounces.</p>
<p>In another fairly recent case an attacking computer was in the same data center as ours, and was causing a denial of service attack to one of our servers with a flood of ARP requests to anything on the same subnet.  We were seeing  up to 10M/sec ARP traffic, which was saturating our bandwith link for that machine.  I was sorely tempted to unplug it to stop it from DDOS&#8217;ing ours as I had physical access to it.  In the end our upstream provider agreed with me, and unplugged it before I got frustrated enough to do that!</p>
<p>Other random thoughts -</p>
<p>I&#8217;m also thinking about an article regarding chinese name registrations.  As a good number of spam / malware sites use Chinese domain names, due to ease of registration  (US based registrars are invalidating domains with incorrect registration details) it would be interesting to see if there is any correlation between spammers and registrars, and see if there is a preferred registrar.</p>
<p>Eg registrars for 2 recent malware domains mentioned at FireEye (one appears to be russian registered, the other american)</p>
<p>whois givemelog.cn<br />
Domain Name: givemelog.cn<br />
Sponsoring Registrar: 厦门华融盛世网络有限公司<br />
Registration Date: 2009-01-15 03:08<br />
Expiration Date: 2010-01-15 03:08</p>
<p>whois bulletproofmonk.cn<br />
Domain Name: bulletproofmonk.cn<br />
Sponsoring Registrar: 广东时代互联科技有限公司<br />
Registration Date: 2009-02-16 17:59<br />
Expiration Date: 2010-02-16 17:59<br />
Some additional domains here &#8211; <a href="http://www.bluetack.co.uk/forums/index.php?s=3d12699cd5acbc5eabf0b7bd40c585e3&amp;showtopic=18064&amp;pid=91545&amp;st=240&amp;#entry91545">http://www.bluetack.co.uk/forums/index.php?s=3d12699cd5acbc5eabf0b7bd40c585e3&amp;showtopic=18064&amp;pid=91545&amp;st=240&amp;#entry91545</a></p>
<p>Would be interesting for someone over at 广东时代互联科技有限公司 ( now.cn ) to do a search for RoderickKiewiet@gmail.com, and see just how many domains they&#8217;ve bought, considering the majority are being used for spam / malware purposes.  Sufficient evidence for someone at Google to cancel that email account anyway..</p>
<p>Another registrar to look at is BizCN.com, they have a substantial amount of malware site registrations.</p>
<p>Things to think about -</p>
<p>Why are so many of China&#8217;s computers vulnerable?<br />
Should the be government involvement in cleaning it up?<br />
What can we do to prevent malware?<br />
Should companies be responsible for their inaction when it causes issue for others?</p>
<p>I welcome comments.</p>
<p>Further reading:</p>
<p><a href="http://realsecurity.wordpress.com/2008/11/26/finding-the-unknown-on-your-network/">http://realsecurity.wordpress.com/2008/11/26/finding-the-unknown-on-your-network/</a></p>
<p><a href="http://www.contentverification.com/man-in-the-middle/index.html">http://www.contentverification.com/man-in-the-middle/index.html</a></p>
<p><a href="http://www.sans.org/newsletters/newsbites/newsbites.php?vol=11&amp;issue=24&amp;rss=Y#sID202">http://www.sans.org/newsletters/newsbites/newsbites.php?vol=11&amp;issue=24&amp;rss=Y#sID202</a></p>
<p><a href="http://www.itpro.co.uk/610182/should-the-bbc-botnet-have-hijacked-22-000-computers">http://www.itpro.co.uk/610182/should-the-bbc-botnet-have-hijacked-22-000-computers</a></p>
<p><a href="http://garwarner.blogspot.com/">http://garwarner.blogspot.com/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.computersolutions.cn/blog/2009/03/the-spyware-wars/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
