Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, March 11, 2011

Handling Y-Cam Security Camera files on my FTP server

The y-cam is generating hundreds of files a day. The files are very small (about 65K) but they become a mess to keep organized. To handle this I have developed a solution. It's still a work in progress and is not fully implemented, but here is what it does:

Every night at midnight my Ubuntu server will:
  • Clear a temp folder
  • Move all the pictures to the temp folder
  • Renumber the pictures in sequential order
  • Convert the pictures to an MP4 time lapse video
  • Email the video to my gmail account

I have two cameras so this process will happen for each camera. It takes less than a minute to complete the process. This gets the videos off site (gmail), and keeps the surveillance organized.

As I said, this is a work in progress. I don't actually have the script running automatically. Right now it does everything from end to end, except renumber the pictures. The Y-Cam has an option to automatically number the images sequentially, but it doesn't start over. I had hoped that the y-cam would start over once the folder was cleared.

Tuesday, March 8, 2011

Security Camera Follow-up

I purchased a y-cam knight. It's just like the y-cam black except it is white. The knight offers Wifi and Cat5 connectivity, night vision with IR leds, web based interface and management, motion detection, automatic sending of pictures to email, ftp, etc, and more. The Y-cam costs about $260 and has an optional outdoor enclosure for $100 more. You can not simply aim this through a window because once the night vision turns on, the camera is blinded by glare.

I created an account on my FTP server which the knight logs into to upload pictures any time it detects movement. This has been working well and it gives me something to look back on.

I also purchased the Axis M101 to do a comparison. In general the axis cameras are more expensive, but they are supposed to be good cameras. However after some testing I have determined the axis is harder to tune as far as motion detection goes and has a worse picture. For the most part, it sends to the FTP server just the same.

Y-cam has also released a new Y-Cam bullet model which is supposedly even better at night, and comes in an outdoor weather proof enclosure. The bullet itself is smaller than the y-cam knight in the outdoor enclosure, but it has a rather thick bundle of cables which you will have a hard time getting through a wall. I have installed one of these at my parents house and it is working well.

What I like most about having cameras is I can check the status of my house at a moments notice via my iphone. I can see if my wife is home, or if the handy man has arrived. I can also sleep easier knowing that if anything happens I have a picture of it.

Next time I will discuss some of the home grown solutions I am putting in place on my FTP server to handle the hundreds of files I am generating daily.

Saturday, March 5, 2011

Schlage Link iphone controlled door locks with z-wave

I purchased the Schlage Link locks from Amazon so I can have better control of people with access to the house. Normally I would give the neighbor a key, my sister a key, my mom a key, the repairman, etc. All of these keys and no control of who copies them, who looses them, etc. In addition, even with all of these keys floating around, I still lock myself out.

Schlage makes a few doorlocks with number pads. I originally bought the model from home depot which handles all the situations above. It costs about $100 and you can assign up to 19 four digit codes. Thats about all it will do. The other benefit of this type of lock is once the door is shut, it's locked. There is no forgetting to lock the door or risk of someone trying to follow you in the house.

However I decided if I'm going to spend $100, I may as well go all the way and get better features. Schlage Link Locks operate identically to the lock above. However, the added feature is the locks can join a home automation network using Z-Wave. Schlage trys to sell you their automation solution but it has a $12 monthly cost and it's actually not compatable with all the neat z-wave products available. The product I have found is called Vera by Mi Casa Verde. It's more of an open solution which promises to not force a vendor lock in. You can use the locks without the Vera. Schlage doesn't include the stand-alone programming instructions, but I had a copy of them from the original locks. All the manual programming worked just fine. Then when you get the Vera you can use the automation.

Some of the great features which are possible:
  • Adding and removing codes remotely
  • Unlocking, locking, and checking the status of the doors remotely (The Schlage deadbolt isn't motorized)
  • Getting (email, sms) alerts when certain codes are used.
  • Seeing a history of lock usage (who came in and when)

The Vera supports macros so I have the Vera turn on lights when the code is entered and turn off the lights when I leave or go to bed.

Tuesday, March 1, 2011

Verizon FIOS default keys are terribly unsecure.

I've suspected for a while that the Verizon FIOS WEP keys and SSID were correlated. The SSID is the ID your wireless router broadcasts out to any device with a Wifi chip. WEP itself is not very secure and can be cracked faster than I can write this, but it does keep the neighbors out and it's something you're not going to typically do on an Iphone.

However, Kyle Anderson took the time to publish the solution to figuring out the default WEP password on every Verizon FIOS router. WhatIsMyIP.org provides a free tool to automatically do the calculation too. However after reading Kyle's blog about it, the scary thing about the password is it's not some weak cryptography or scrambling which hides this key, its just in another base. So with a base converter app on your Iphone, you can get access to any FIOS internet your Iphone can see.

I tried Base Converter and Calculator Pro for just 99 cents and it worked like a champ. I can convert the SSID into a WEP key in seconds without any specialized tools and access a FIOS default WIFI.

Here is how: (Note, the steps I'm showing are simply a clarification on the sites referenced above. This should only be used to test or demonstrate the weakness in the default configuration of FIOS routers to encourage users to change their security)
  1. Run Base Pro on your iPhone (Click the link above with your iPhone)
  2. Change Base Pro to Base 36 by dragging the slider to the right.
  3. Type in the SSID backwards. ex. “E3X12″ gets typed in as "21X3E"
  4. Click the button at the top that says Hex (Don't drag the slider to Base 16, there is a small bug) ex. 21X3E becomes 349FCA
  5. Append one of these two prefixes to the result: 1801 or 1F90. ex Try 1801349FCA or 1F90349FCA.
  6. Try both keys to see which one works. (You can determine which key to use with more work, but its easier to just try them.)


That's it. A few easy steps with nothing more than a Base Calculator and you can determine the default FIOS WEP key with your phone.

Tuesday, March 9, 2010

1024bit RSA cracked in 100 hours. What is coming next?

Here is a very technical read on the attack used on RSA http://www.eecs.umich.edu/~valeria/research/publications/DATE10RSA.pdf. I made it about half way though, see how far you can go... lol. Anyways the summary is by messing with the voltage supply they are able to introduce single bit errors into the RSA algorithm, then they can take these bad outputs and analyze them to reveal the secret key.

They are able to do this without modifying or accessing the internal system components. So in effect the attack leaves no signs of tampering. They performed this particular attack against linux and OpenSSL.

WOW. Just remember security isn't about how strong your front door is.

Monday, March 1, 2010

Two ways to find out who is selling your info.

Gmail has two features which will allow you to monitor who is selling your information. Nearly everyday I find a site that requires registration and it gets annoying. More annoying is revealing my email address to these sites. I used to use multiple addresses but it became annoying to check all of them. So here are two tips for giving out multiple email addresses via Gmail. These addresses can be later filtered if they become too spammy.

Plus Addressing
I've seen this one mentioned alot. Plus addressing allows you to append anything you want to your email address by using a plus sign. So if my name is john@gmail.com, I can sign up to a site with john+somesite@gmail.com. The plus sign is a valid email character. Unfortunately many site registration forms don't allow it. However this is the first thing I try to do every time. If I start getting spam from other companys to john+somesite@gmail.com, then I know who sold me and I can filter that address from going to my inbox.

Dot Addressing
Not as flexible as plus addressing and harder to know which site sold you. However this can be a great way to filter spam. Gmail ignores periods (.) in email addresses. You can't start or end your address with a period and you can't have two in a row, but you can have as many as you want. The best part about this method is I have yet to find a site that won't accept a period in an address. So jo.hn@gmail.com is valid, jo.h.n@gmail.com is valid as well. Obviously longer email addresses have more choice. You are limited here but I would suggest grouping sites by level of trust. So some site you randomly visit that you feel you must sign up for to post a comment and you know you will never be back, put the period in the first position, j.ohn@gmail.com. A site you plan to use all the time would perhaps get a period in the last position. Or whatever you decide. If you have a 6 character email address you have 31 alternates available. An 8 character email address has 256, but then with so many choices you will need a way to keep track. I would just use three or four at a time and change them as they start getting abused.

Both of these schemes work out of the box with gmail, though the dot technique does not work for gmail for your domain addresses. There is no pre-registering the addresses you plan to use. Go ahead, mail something to yourself at some random plus address. Keep in mind there is a maximum length to an email address, so don't go crazy. Other email providers allow plus addressing or other choices as well. You can get more specifics here: http://en.wikipedia.org/wiki/E-mail_address

Monday, February 15, 2010

How to clean up Google Chrome on Ubuntu 9.10

If you saw my post yesterday you will know I wasn't happy about the 39 new packages Google Chrome decided to install. I have a command that will clean the mess up for most ubuntu desktop systems.


sudo apt-get autoremove bsd-mailx g++-4.4 dpkg-dev

  • dpkg-dev gets rid of the bulk (30+ packages) including alien, rpm and QT.
  • bsd-mailx gets rid of the mail server stuff like postfix
  • g++-4.4 cleans up one or two odds and ends. 

Make sure you don't actually use any of these packages. If you do, adjust the command to just get rid of what you don't need.


I went through all the packages that were installed and this command takes them all out plus Google Chrome itself.

No more open ports for my desktop system. Just the way I like it.

Sunday, February 14, 2010

No thank you google! Chrome automatically installs a mail server.

I just updated my Ubuntu desktop system and I didn't read the list of updates first. I swear this is the first time I didn't read the list and boy has it bitten me. I currently have the Google Chrome repo (http://dl.google.com/linux/deb/ stable main) on my system and it has really done it now.

Chrome has installed the following new packages on my system:
  • alien (8.78)
    bsd-mailx (8.1.2-0.20081101cvs-2ubuntu1)
    build-essential (11.4)
    cvs (1:1.12.13-12ubuntu1)
    debhelper (7.3.15ubuntu3)
    dpkg-dev (1.15.4ubuntu2)
    g++ (4:4.4.1-1ubuntu2)
    g++-4.4 (4.4.1-4ubuntu9)
    gettext (0.17-8ubuntu2)
    html2text (1.3.2a-14)
    intltool-debian (0.35.0+20060710.1)
    libmail-sendmail-perl (0.79.16-1)
    libqt4-assistant (4.5.3really4.5.2-0ubuntu1)
    libqt4-dbus (4.5.3really4.5.2-0ubuntu1)
    libqt4-designer (4.5.3really4.5.2-0ubuntu1)
    libqt4-gui (4.5.3really4.5.2-0ubuntu1)
    libqt4-opengl (4.5.3really4.5.2-0ubuntu1)
    libqt4-script (4.5.3really4.5.2-0ubuntu1)
    libqt4-sql (4.5.3really4.5.2-0ubuntu1)
    libqt4-sql-sqlite (4.5.3really4.5.2-0ubuntu1)
    libqt4-svg (4.5.3really4.5.2-0ubuntu1)
    libqt4-xml (4.5.3really4.5.2-0ubuntu1)
    librpm0 (4.7.0-9)
    librpmbuild0 (4.7.0-9)
    librpmio0 (4.7.0-9)
    libstdc++6-4.4-dev (4.4.1-4ubuntu9)
    libsys-hostname-long-perl (1.4-2)
    lsb (4.0-0ubuntu5)
    lsb-core (4.0-0ubuntu5)
    lsb-cxx (4.0-0ubuntu5)
    lsb-desktop (4.0-0ubuntu5)
    lsb-graphics (4.0-0ubuntu5)
    m4 (1.4.13-2)
    mailx (1:20081101-2ubuntu1)
    ncurses-term (5.7+20090803-2ubuntu2)
    pax (1:20090728-1)
    po-debconf (1.0.16)
    postfix (2.6.5-3)
    rpm (4.7.0-9)


WOW that is a lot of junk I didn't want. The most concerning to me is the unwelcomed mail server. Yes. anyone who updated their desktop system and is using the Chrome repo is now running a mail server. Complete with port 25 open.

Arggg. Now I have to rip this stuff out of my system, hope I don't break anything and say good-bye to Chrome.

Monday, February 1, 2010

Ten Tips for Keeping Windows Fast and Secure (Part 3 of 3)

If you missed the first two parts, please go read them now.

8. Use an active virus scanner and spyware blocker.
    There isn't much of an explanation for needed this. In the windows world this is required. On Ubuntu, virus scanners and spyware scanners are not needed due to other measures in place to help prevent infections. However, for Windows, ensure the definitions are updated daily and don't let your scanners expire. You need to stay up to date.

9. Don't click links in emails even if you know the source.
    This is true for any OS, but even more so with Windows. In every OS, links in emails can trick you to reveal your passwords and other private data to bad guys. In windows, they can also infect your computer easily. Also watch out for attachments. If you get a file from someone you know, it can still be bad. If it's a video, or a picture ask them to put it on a popular site like youtube, flikr, or facebook. Then go view it there. All it takes is a new virus which infects that type of file to get in their system, then it will be in your system. Using a known third party doesn't eliminate the risk completely, but it reduces the risk.

10. Don't be an administrator.
    Many of us share a computer with family. It can be a pain in the butt, but to help keep the bad guys out of the computer give each family member their own account. Make sure your family member is not also an administrator. In fact, it's better if you create a separate account for yourself too which isn't an administrator. When you need to install a new application, switch to the administrator account and run the install. Some applications won't play nicely with this and expect administrator privileges. Really if they can't get these security requirements right, do you expect them to get it right in other ways?

If you enjoy this blog, please click the follow button!

Sunday, January 31, 2010

Ten Tips for Keeping Windows Fast and Secure (Part 2 of 3)

5. Don't install free or cheap applications unless it's open source.
    There are some exceptions to this too such as AVG Virus Scanner. However most free or cheap closed source applications want something in return for that low price. Perhaps they give you spyware, or they will start harassing you to buy a license. Even if this is not the case the coder can unintentionally create a vulnerability or fail to patch a vulnerability. Adobe Acrobat Reader is a free application supported by a major software company and even that has introduced vulnerabilities. Open source applications are exceptions because they can be maintained and critiqued by others. With all software though you have to justify the risk with the rewards. These applications also have to be updated, windows will not do it for you. Ubuntu will keep all your applications up to date which is a huge plus for linux security.

6. Don't install extra applications.
    When installing any application, use advanced install and un-check any offer to install additional applications. Even applications from Adobe and Apple ask to install something else, always say NO. If you are installing iTunes, don't accept Safari too. Don't install any software if you aren't going to use it.

7. Turn off nearly every program that is running near the clock.
    Programs running in the background are a huge risk because they can be listening for or communicating with the internet without you knowing. Each one also takes a little speed away from the computer. While turning all all unneeded background tasks can require a degree in computers, most of us can get the tasks near the clock to stop running. Of course there are windows provided icons and your virus scanner that must remain. But you don't need that office toolbar, Adobe updater, etc.

Saturday, January 30, 2010

Ten Tips for Keeping Windows Fast and Secure (Part 1 of 3)

1. Use Firefox for internet browsing.
    Internet Explorer has been one of the weakest points in windows security. Using Firefox eliminates a huge portion of risk and supports web standards better than internet explorer. Did you know most websites run special compatibility code just for internet explorer?

2. Turn on automatic updates. Ensure it runs daily.
    Many people don't even turn on automatic updates. And if you aren't updating because your Microsoft Windows is an illegal copy, you are even more vulnerable. If you need a legal copy and have more than one computer in the family you can save money by getting a family pack. If you can not afford it, switch to Ubuntu for free.

3. Ensure you choose shutdown and install updates before turning off your computer.
    Every night you should choose to shutdown and install updates. This ensures updates are getting installed, it also reduces the number of lockups and slowdowns you can have from running windows too long. Also you are helping to stay green by not keeping the computer on all night.

4. Don't install browser toolbars or plugins.
    There are some exceptions but toolbars and plugins in general are another point of vulnerabilities and web speed issues. They just aren't worth the risk no matter how cute they are. Plugin exceptions are flash and ad blockers.

Thursday, January 28, 2010

Security Camera Recommendations

There have been some break-ins in a few neighborhoods around my house. Mostly just smash and grabs with stuff left in cars. My Wife had her ipod stolen and a dvd player two years ago, so I have been personally affected.

Since then I have been on the look out for outdoor security cameras which have a decent image at night and don't cost a fortune. I've not been happy with many of the options I have found but after quite a bit of research I have narrowed it down to two cameras.

Both cameras are capable for outdoors. Both can perform at night. Though the Panasonic may need SOME light from a porch light.

Panasonic bb-hcm531
Offers Pan/Tilt controls.
Power Over Ethernet (PoE)
Must buy a PoE adapter or switch
Sample Images: http://www.amazon.com/gp/customer-media/product-gallery/B000P7X438/ref=cm_ciu_pdp_images_1?ie=UTF8&index=1


Y-Cam Black - $269 or $999 for 4
http://www.y-cam.com/y-cam-black
Wireless networking, just need power.
No Pan/Tilt. Its fixed
IR LED for night illumination
Must buy outdoor housing for $99 more per camera.
Sample Live Camera here: http://ycam3.dtdns.net:8150/en/login.asp
Login is guest Password guest


At this point I don't see the need for pan tilt because once it's set there should be little reason to move it. I've looked for other options but with the low light requirement and outdoor mounting you can't get much better image wise without spending at least $1200.

The cameras can serve the video themselves over the internet, but I'm going to try to use ZoneMinder. A free security application which can control multiple cameras.

As of now, I'm going to buy the Y-Cam Black because it seems to be easier to install and has a true night vision mode. The pan and tilt just isn't that important for what I need. To install the Y-Cam properly you should run the power cable through the soffet(sp) and in the attic run an outlet from the nearest junction box. I'm thinking of avoiding ladders and just mounting it outside a window and run the power through the window. We'll see.

Friday, January 22, 2010

Watch Out! You are getting ripped off.

If you aren't aware, or you have believed these devices to be obvious, please look at some of these photos of ATM Skimmers. ATM Skimmers are devices built to look like they are a part of the ATM machine, but they are made and attached by theives. They record your card and have a camera which 'sees' what pin you type. Some skimmers even have a cell phone hidden away so they can send the data remotely.

Here are links to some articles with pictures, and below I will suggest a partial solution.
http://www.boingboing.net/2010/01/16/atm-skimmer----could.html

Here is a pic of a slot with a skimmer in place: http://twitpic.com/4pkn3
Here is a pic of a panel mounted to the top of the ATM which captures your pin and transmits via cell phone: http://twitpic.com/4pknu

A google search leads to many other pictures:
http://images.google.com/images?q=ATM+skimming

TIPS:
  • Avoid ATMs placed in secluded areas.
  • Be wary of anything that looks suspicious about the ATM slot (extra seams, different color plastic, etc)
  • Try to cover your hand while typing your pin.
  • Fake type numbers with your pin. Meaning between actual key presses make it look like you are pushing other keys.
  • If possible only use your bank ATMs and learn what they really look like.