<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>philosecurity &#187; john_strand</title>
	<atom:link href="http://philosecurity.org/author/john_strand/feed" rel="self" type="application/rss+xml" />
	<link>http://philosecurity.org</link>
	<description></description>
	<lastBuildDate>Tue, 23 Feb 2010 22:42:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>&#8220;Verizon&#8221; Store Security Update</title>
		<link>http://philosecurity.org/2009/06/29/verizon-store-security-update</link>
		<comments>http://philosecurity.org/2009/06/29/verizon-store-security-update#comments</comments>
		<pubDate>Mon, 29 Jun 2009 19:38:26 +0000</pubDate>
		<dc:creator>john_strand</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1846</guid>
		<description><![CDATA[The illustrious John Strand has an update for us regarding Verizon&#8217;s demo EVDO system security. This summer John is launching his new SANS class, Security Architecture for Systems Administrators. Shortly after we posted the article about the openness of the Verizon EVDO demonstration terminals, we were contacted by Verizon. After discussing the issue at length [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-06-30 --><em>The illustrious John Strand has an update for us regarding Verizon&#8217;s demo EVDO system security. This summer John is launching his new SANS class, <a href="http://www.sans.org/training/description.php?mid=1312">Security Architecture for Systems Administrators.</a><br />
</em><br />
Shortly after we posted the article about the <a href="http://philosecurity.org/2009/06/10/verizon-stores-pre-p0wned">openness of the Verizon EVDO demonstration terminals</a>, we were contacted by Verizon.  After discussing the issue at length they requested that we post the following comment:</p>
<blockquote><p>“The demo laptops in question are located in an independently owned/operated reseller location, and are not configured or maintained by Verizon Wireless. Verizon Wireless is committed to the security of its customers and is working with the reseller to resolve this issue.&#8221;
</p></blockquote>
<p>Usually when working with vendors, the company&#8217;s lawyers immediately respond to any potential problems with security systems.  Verizon did not respond this way. Instead, they began by asking a bunch of questions about the store locations and what security breaches were compromised.   Further, they said that they could understand the confusion because the third party resellers have huge Verizon signs on their store.  In short, they acknowledge that it can be very difficult to distinguish between the real Verizon stores and the resellers.</p>
<p>I was also very happy to see that they were interested in solving the issue. You see, even though the stores are not theirs, there is still damage that can be done if something hideous was to happen on one of the terminals. </p>
<p>I will keep you all posted on how the fix goes.   I am planning on hitting a few of the stores later today just to see.<br />
&nbsp;</p>
<table style="float: right">
<tr>
<td align=right><em>Philosecurity contributor John Strand</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/verizon-store-security-update-2009-06-30.asc">PGP-signed text: 2009-06-30 (current)</a></td>
</tr>
</table>
</td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F29%2Fverizon-store-security-update&amp;title=%22Verizon%22%20Store%20Security%20Update" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F29%2Fverizon-store-security-update&amp;title=%22Verizon%22%20Store%20Security%20Update" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F29%2Fverizon-store-security-update&amp;title=%22Verizon%22%20Store%20Security%20Update" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=%22Verizon%22%20Store%20Security%20Update&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F29%2Fverizon-store-security-update" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://technorati.com/faves?add=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F29%2Fverizon-store-security-update" title="Technorati"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F29%2Fverizon-store-security-update" title="TwitThis"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/twitter.gif" title="TwitThis" alt="TwitThis" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/06/29/verizon-store-security-update/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verizon Stores Pre-p0wned</title>
		<link>http://philosecurity.org/2009/06/10/verizon-stores-pre-p0wned</link>
		<comments>http://philosecurity.org/2009/06/10/verizon-stores-pre-p0wned#comments</comments>
		<pubDate>Wed, 10 Jun 2009 08:56:55 +0000</pubDate>
		<dc:creator>john_strand</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1823</guid>
		<description><![CDATA[John Strand is the author of this week&#8217;s article. John is the owner of Black Hills Information Security and a member of PaulDotCom Security Weekly. He is also a SANS Instructor and a regular presenter at various security conferences. Last week I was plucking around at my local Verizon Wireless store looking for a power [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-06-10 --><em>John Strand is the author of this week&#8217;s article. John is the owner of Black Hills Information Security and a  member of <a href="www.pauldotcom.com">PaulDotCom Security Weekly</a>. He is also a SANS Instructor and a regular presenter at various security conferences.</em></p>
<p>Last week I was plucking around at my  local Verizon Wireless store looking for a power adapter for my i760. Apparently, this task is far harder then I thought it would be. The gentleman behind the counter said, &#8220;Whoa! That is a very old phone.&#8221;</p>
<p>I bought it last year.</p>
<p>Anyway, he disappeared into the back like he was hunting for the store&#8217;s last mogwai and left me, alone, in the store with their demo EVDO computer terminal.</p>
<p>So I started playing around with the Windows XP system they allow their customers to test the EVDO speed.   Which I think is a great idea.  However, there was a sign that said, &#8220;Please, check your email here!!&#8221;  I don&#8217;t think so.</p>
<p>So I got curious as to what kind of security they put on these systems.  I was hoping for at least a partially locked down terminal. At the very least, I was sure they would not leave an open system logged in with Administrator privileges for the whole world to use.</p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/06/verizon-smaller.jpg"><img src="http://philosecurity.org/wp-content/uploads/2009/06/verizon-smaller-300x189.jpg" alt="verizon-smaller" title="verizon-smaller" width="300" height="189" class="right size-medium wp-image-1829" /></a>I was wrong.</p>
<p>As you can see the system is logged in with an account that has Administrator Privileges.  There is no &#8220;hacking&#8221; this box&#8230;. You just walk up to it.</p>
<p>&nbsp;<br />When he returned, without the adapter I needed, he noticed that I had the command prompt up.  He asked me the basic questions like, &#8220;What the hell are you doing?&#8221;  Which I answered truthfully with the necessary mitigation steps.  You see, I am a pathetic, hopeless white hat.  I spent a few seconds re-explaining the problem to him while his eyes glassed over.  When I was done he said that he would need to take my name and a copy of my drivers license so he could run this &#8220;incident&#8221; by the management and possibly the police. It was my turn for my eyes to glass over and quickly leave the store. The irate store clerk was shocked that I would just walk away without complying with a perfectly sound and logical request to hand over my PII to a store that cannot secure a simple terminal.</p>
<p>To my horror, all of the Verizon stores in my area were set up the exact same way.</p>
<p>There are two issues here.  First, these terminals are insecure by design and replicated. Second, they encourage their potential customers to use these insecure systems to do potentially sensitive activities.</p>
<p>Why should Verizon care?  The single biggest thing I can think of is liability.  If you&#8217;re an attacker why would you keep your illegal files on your system?  It seems so much better to store them on a random Verizon demo system. Next, think about the consistency.   It is trivial to dump the password hashes from a system when you have Administrator access to the box.  Where else are those passwords used?</p>
<p>The point is that we need to start securing things even if you don&#8217;t think there is a need.  There are liability issues that come with having open systems so insecure. Further, it is just these types of things that can be catastrophic for an organization.  The sad part is many organizations would say they never saw it coming.</p>
<p>We can say it again and again, organizations need to be a bit more protective of their customers data.  Also, I think it would be a step in the right direction to not openly suggest that customers should check their email.</p>
<p>Until then&#8230; Buyer beware.</p>
<table style="float: right">
<tr>
<td align=right><em>Philosecurity contributor John Strand</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/verizon-stores-pre-p0wned-2009-06-10.asc">PGP-signed text: 2009-06-10 (current)</a></td>
</tr>
</table>
</td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F10%2Fverizon-stores-pre-p0wned&amp;title=Verizon%20Stores%20Pre-p0wned" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F10%2Fverizon-stores-pre-p0wned&amp;title=Verizon%20Stores%20Pre-p0wned" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F10%2Fverizon-stores-pre-p0wned&amp;title=Verizon%20Stores%20Pre-p0wned" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=Verizon%20Stores%20Pre-p0wned&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F10%2Fverizon-stores-pre-p0wned" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://technorati.com/faves?add=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F10%2Fverizon-stores-pre-p0wned" title="Technorati"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F10%2Fverizon-stores-pre-p0wned" title="TwitThis"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/twitter.gif" title="TwitThis" alt="TwitThis" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/06/10/verizon-stores-pre-p0wned/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
