Category Archives: Security

Yokosuka Sailor Sought for Attempted Murder in Yokohama Hit ‘N Run.

A couple days ago I wrote that the Stars & Stripes had a story about a hit-and-run accident in Yokohama, that possibly involved a US Sailor. I received some follow up information in my e-mail this morning, and it looks like a really bad situation involving two E4’s from local Yokosuka shore commands.
UPDATE: Stars [...]

Japanese Radical Group Claims Rocket Attack on US Navy Base in Yokosuka, Japan.

Since many people still don’t realize there was an attempted rocket attack directed at the US Navy base in Yokosuka, I figured it was because authorities thought it to be just some idiots playing with pipe bombs, and not a suspected terrorist attack attempt. It’s now being reported by Japan’s AsahiTV that it was in [...]

Secure Your Personal Thumb-drive with Encryption.

I know most of my blogging deals with stuff that goes on around the FDNF, but I thought I’d share some of my techy side with everyone.
Working as an Information Assurance Manager, I routinely come across personal thumb-drives that have been mistakenly left in workstations or lost. When these thumb-drives are turned in, we perform [...]

USS George Washington’s CO and XO Fired!

And now from the we-all-saw-that-coming department, the USS George Washington’s Commanding Officer (CO) and Executive Officer (XO) have been relieved of their duties following the shipboard fire they had in May. The firing came at the direction of Admiral Willard, Commander Pacific Fleet, who cited the typical nondescript “lack of confidence” with an additional “failure [...]

Stars & Stripes Hacked! China Involved?

Visiting the Stars & Stripes website this morning, I was surprised to see the following:
Stripes.com hacked; users’ computers may be affected
The Stars and Stripes Web site appears to have been struck by a hacker early Saturday. Indications are that this may have been related to an automated cyber-attack launched last month that [...]

Chinese Hackers Are Overrated.

CNN is running a story on Chinese hackers who openly boast about pwning pentagon and other DoD computers, with financial compensation from the Chinese government. From the article:
They operate from a bare apartment on a Chinese island. They are intelligent 20-somethings who seem harmless. But they are hard-core hackers who claim to have gained access [...]

Printers a Threat to Classified .MIL Networks.

A few months go I received a PayPal phishing scam on my ship e-mail account. We get these periodically because spam bots grab the e-mail addresses we have published on our ship’s website, or by use common e-mail addresses found on most networks, e.g., webmaster, administrator, etc. I give every one of these a [...]

The Battle for my AOL Account!

I’m using a new AIM screen name, so if you’d like to know it and be added to the new buddy list, email me at Jim(at)Fewl.net.
Nearly a decade ago I hit a low point in my life. I became an AOL hacker. I’m sure there are plenty of chuckles from security types, but there were [...]

PayPal Sucks at Stopping Fraud.

I was watching some YouTube videos when my mail email program popped up to let me know I had new mail. To my dismay it was just another PayPal scam. It let me know that my account information needed to be updated by tomorrow, otherwise my account would be terminated. Being that I had nothing [...]

US Navy Blocks Instant Messenger Sites.

First it was web mail, then MySpace and dating sites. Now it’s various instant messaging (IM) sites that are the latest targets to be added to the list of stuff the people who defend this country can’t do. I know a lot of people on board who used various chat sites, like Meebo.com and eMessenger.net, [...]

U.S. Army to Use Trusted Computing

According to SecurityFocus, the US Army is making the move to convert it’s current networks to a Trusted Computing model. Trusted Computing is a process in which hardware encryption systems, known as the Trusted Platform Module (TPM), prevent files and other data from being viewed or manipulated on any computer other than the one it [...]

Navy, Nasa, Other DoD Sites Hacked.

In what seems to be a cyber protest on the Israel-Hizbollah conflict, hackers have defaced various Department of Defense, military, and NASA websites. Among those hit was that Navy’s Personnel Command website, replaced with a wanted poster boasting the hacker’s accomplishment. I remember a lot of government and military sites being defaced in the late [...]

Wordpress Vulnerable to Injection Attack?

This might be a slight follow up to Dr. Dave’s Followup on Wordpress Security Issue. I just woke up after a long flight from Virginia to Tokyo and got to this link via Jem’s site. Details on the vulnerability are sketchy so I thought I’d take a look for myself. The followup post said that [...]

AOL Hackers Charged with LexisNexis Hack.

At least 6 years ago I used to be involved in what some would call the AOL scene. I’m sure I’m hearing snickers from any true geek that happens to stumble across this post, but I assure you while the motives were lame, the techniques were many times very ingenious. I was one of the [...]

Subdomain Snooping.

I’m a very nosey person. I’m so nosey, that sometimes I like to see what “hidden” subdomains of big web companies are open to the public. The quickest way to do this is to use nmap. Nmap stands for Network MAPper, and is an extremely powerful command-line tool for conducting enumeration on different networks/computers. [...]

A Wikipedia Worm?

This isn’t a long post. I was just sitting here thinking about how easily, assuming they don’t already have preventions in place, it would be for someone to write a worm that edited random articles in Wikipedia. Sure, they have a lot of volunteers, but what if thousands of machines were infected and editing thousands [...]

The Poor State of CodeGrrl.com

Before anyone assumes I’m being sexist here, I’m not. While most techy guys would prefer to have techy girls being gaming graphic designers who just wear cool Linux t-shirts, I don’t. I tend to like working with women in the IT field more than most men, because there’s usually less of a pissing contest. A [...]

US Navy Blocks MySpace and Other “Dating Sites”

At least in Japan, Sailors who use MySpace, Yahoo! Personals, BlackPlanet, etc., are no longer able to get to the sites on government computers. Instead they’re greeted with a restricted message, and a link to the instruction of appropriate uses for DoN computer systems.
The Navy blows my mind with their policies sometimes. Not to [...]

Microsoft Releases WMF Patch Early

I guess the pressure was too much for Redmond. They’ve released an official patch to the WMF exploit, well ahead of their original proposed date.
Update your ish now…

Unofficial WMF Exploit Patch!

Microsoft isn’t expected to have an official patch for this vulnerability until Janurary 9th. In the meantime, hackers have created variants of the WMF exploit, including a new IM worm, that are not detected or stopped by traditional means. This means your antivirus, firewall, IDS, snort rules, etc., are all basically useless. In a first, [...]

Images enhanced with WordPress Lightbox 2 by Zeo