Skip to main content

Whiskey Tango Foxtrot

Today is one of those Whiskey Tango Foxtrot kind of days. I've been tracking a real November Sierra since December, and even reported it. I figured it was a bug, so I submitted it to the security folks. Their response? "We're not the team for this problem." ok.

Now today I see two data points, one weird-o one-timer kind of probe. Yup, for real, a solo IP in the gigabytes of logs that my splunk eats. Yet this IP correlates with another IP that has been on my radar.

So I get out my splunk and pull a "deny" query on this IP. Not only does it generate IPS hits from my desktop, outbound to destination, but I see inbound activity from this IP (also denied, of course).

(2017-03-29T17:56:44) firewall: msg_id="3000-0150" Deny 1-Trusted 0-External 9840 tcp 20 64 [desktop_ip] 184.86.92.71 12766 80 offset 5 A 2936268642 win 342 signature_name="WEB-CLIENT WScript.Shell Remote Code Execution -1 (Ransomware A" signature_cat="Access Control" signature_id="1110895" severity="5" geo_dst="USA" msg="IPS detected" (HTTP-proxy-00)

(2017-03-23T08:35:36) firewall: msg_id="3000-0148" Deny 0-External Firebox 936 tcp 20 56 184.86.92.71 [office-ip] 80 1847 offset 5 A 2554649786 win 913 msg="tcp syn checking failed (expecting SYN packet for new TCP connection, but received ACK, FIN, or RST instead).

That IP (184.86.92.71) is owned by non-other than Microsoft. They host the OfficeCat update content on Akamai:

(2017-03-29T17:56:45) http-proxy[2026]: msg_id="1AFF-0021" Allow 1-Trusted 0-External tcp [desktop_ip] 184.86.92.71 12768 80 msg="ProxyAllow: HTTP Request categories" proxy_act="HTTP-Client.1" cats="Information Technology" op="GET" dstname="www.microsoft.com" arg="/office/offcat/2.5/en/offcat.nextversion.xml" geo_dst="USA" (HTTP-proxy-00)

I sent email to security at microsoft.com explaining how this first showed up in December during a Visio update (2AM kind of MSFT update). They responded with the "yeah, not our problem," kind of email.

The other November-Sierra involves a fast tripwire that implicated Microsoft again. That one won't go up on the blog until after I get a response from BigSoft's contact.

Fun times.

Popular posts from this blog

DNS Custom Logs and selinux

If you google "named custom logs selinux" you will find quite a bit of chatter about setting up custom logs outside of /var/log for DNS (named). These posts are interesting, but they tend to be run on posts about learning selinux and becoming an expert on named. What you need to know? If you have setup custom logging locations in your /etc/named.conf file, such as:     channel default_file {         file "/var/log/named/default.log" versions 3 size 5m;         severity dynamic;         print-time yes;     }; Then you will likely see errors like this in /var/log/messages: Oct 26 11:41:13 namedsvr setroubleshoot: SELinux is preventing /usr/sbin/named from write access on the directory /var/named/chroot/var/log/named. For complete SELinux messages. run sealert -l 6eab4aaf-e615-4ade-9e88-4efdc789eaf2 Then you run the sealert command as suggested by the very friendly selinux audit log and you are told: #============= named_t ============== #!

THE RISE OF FASCIST SOCIAL MEDIA

The Merriam-Webster dictionary defines fascism as: a tendency toward or actual exercise of strong autocratic or dictatorial control .  The phrase "dictatorial control" is important for the case that I am going to make about fascism in social media. The word "dictatorial" means "of or relating to a dictator," and a dictator is "one ruling in an absolute and often oppressive way." In 2020, social media has seen a rise in the number of autocratic events of censorship. The two social media outlets that I am going to focus on are Facebook and Twitter.  Background Facebook is a semi-private curated blogging platform where you, the user, share information at your leisure. The public part of Facebook is in Facebook Groups. With a group, outside people who are not privy to your "Facebook Wall" will join your group and establish a communal discourse. This can be private, by invitation only, or public. The Facebook is auth-walled so that you must

A Mask Protocol

The SARS-COV-2 [1] virus pandemic that started in late 2019 and took over the planet in 2020 has been the big news of late. I don't think there is anyone on the planet who does not know about the virus and its impact on the world. XPrize [2] held a competition in 2020 called the XPrize Pandemic Response Challenge [3]. I competed in this challenge and made it to the final. The competition concerned itself with creating two kinds of models, one to predict mortality and morbidity, and another to predict intervention policy. The first round was the prediction portion where my model performed quite well. The model I wrote used some anecdotal knowledge about prevention and risk as well as some research topics that were emerging in 2020.  Out of this competition there were some interesting anecdotal observations about virus transmission. Masks could be ineffective . When you respirate through a mask in an area that has elevated concentrations of the Covid-19 virus, the particles hosting t