A look at our security related traffic

Filed under:Uncategorized — posted by Consultant on April 27, 2008 @ 4:36 pm

Hey, so today I wanted to take a look at the traffic both the blog and the pentest directory project are receiving and, as you may have already noticed, since I’m using Google Analytics for keeping track of traffic stats I found some interesting data that I wanted to share with you.

I’m analyzing 7,167 unique surfers, ranging from January 1st 2008 to yesterday, April 26th 2008.

Most of them, 2.687 connected using IPs from the US. 623 came from the UK and in third place is India, with 417. We then have several more different countries.

From the ~7100 surfers, the 63.61% (4559) used FireFox as a browser, and in second place with 29.15% comes Internet Explorer. 245 used Opera, 114 Safari, 109 Mozilla, 18 Konqueror, 9 Camino, 7 Mozilla compatible Agent, 9 Avant Go.

So most of them use Firefox, that’s nice. And take a look at the following:

82.41% used Microsoft Windows, that’s 5,906 users! Then comes Linux with 831, Macintosh with 370. We have 18 iPhone users! 3 used the iPod, and a couple more.

And moving on to the Adobe/Macromedia Flash plugin version installed:

28.92% (2,073) had 9.0.r115  - 26.58% had 9.0 - and so on with decreasing versions.. we get to a point where:

76 users had version 6.0 installed! and several different old versions of 9.0 including r28, r45, r47, etc.

I would say - interesting. Nothing new yeah but interesting. Let’s update the Flash plugin.

And then you wonder why google analytics takes so much time to load.. 

Cheers

Wireless keyboard security

Filed under:Hardware — posted by Consultant on April 1, 2008 @ 1:07 pm

Recently a new thread in the pentest mailing list (pen-test@securityfocus.com) related to wireless keyboard security was started. Quite interesting given that several different responses included a wide range of resources. So I thought I would grab them all and store them somewhere (here) for the future in case I ever need it.

The thread can be found online here:

http://www.securityfocus.com/archive/101/490080/30/0/threaded 

The links include:

http://www.wartyping.com/  and http://www.wartyping.com/?page=links

WarTyping is the act of location, and interception of radio signals transmitted by wireless keyboards onto the public airwaves by driving / walking around with the appropriate equipment.”

http://www.symantec.com/enterprise/security_response/weblog/2007/12/why_did_my_nextdoor_neighbor_e.html Why Did My Next Door Neighbor Erect a 50-Foot Radio Antenna? Wireless keyboards have been around for several years. After developing the first series of infrared devices, vendors have developed radio-based keyboards that run at 27 MHz.

http://seclists.org/basics/2005/Mar/0420.html

Security Basics: Wireless Keyboard Security

http://seclists.org/fulldisclosure/2008/Mar/0162.html

Full Disclosure thread: Wireless keyboard insecurity - any secure one available?

http://www.zdnet.com.au/news/security/soa/Microsoft-wireless-keyboard-hacked-from-50-metres/0,130061744,339284328,00.htm

Microsoft wireless keyboard hacked from 50 metres

http://www.dreamlab.net/download/articles/27_Mhz_keyboard_insecurities.pdf

27 MHz Keyboard Insecurities

http://www.remote-exploit.org/advisories/27Mhz_Analyzing.pdf

Analyzing 27 MHz keyboards

Later,



image: detail of installation by Bronwyn Lace