ExamNotes.net  -  IT certification portal

ForumsCertResearchTop sitesNewslettersFree email
HomeRegister
Exams Notes
Practice exams
Exam games
Questions by email
Online training
Training videos
College degrees
Boot camps
Book store
Links directory
Tell a friend
For webmasters

CompTIA Exam Vouchers
Save money on CompTIA exams
Question of the day
Sign up to receive
interactive practice questions
for MCSE, CompTIA
Cisco and other exams
TestKing
Get MCSE, MCSD, CCNA, CCNP,A+, N+ and many more

* ExamSheets *
Guide for Success!
Actual Questions & Answers
MCSE, MCSD, A+ ,CCNA, CCNP
Oracle 8i, Oracle 9i

Online practice tests

Certification sites

Online university

Online college

Online education

Distance learning

Software forum

Server administration forum

Programming resources






This is interesting: Free IT Magazines | Databases help forum



CompTIA > Security+ > Can Anyone Here Add To This

Show a Printable Version
Email This Page to Someone!
Receive updates to this thread


www.ExamVouchers.com - Get Instant $60 OFF Security+ exam and a free practice test!

Featured site: Online Security+ practice exams from Cert21.com



Author Can Anyone Here Add To This
sinaps
Senior Member
M




Registered: Sep 2001
Location: Vancouver
Country: Canada
State:
Certifications: A+
Working on: Network+

Total Posts: 136
Can Anyone Here Add To This

http://www.voxnyc.com/archives/00000059.htm

How NSA access was built into Windows

Duncan Campbell
Careless mistake reveals subversion of Windows by NSA.
A CARELESS mistake by Microsoft programmers has revealed that special access codes prepared by the US National Security Agency have been secretly built into Windows. The NSA access system is built into every version of the Windows operating system now in use, except early releases of Windows 95 (and its predecessors). The discovery comes close on the heels of the revelations earlier this year that another US software giant, Lotus, had built an NSA "help information"
trapdoor into its Notes system, and that security functions on other software systems had been deliberately crippled.

The first discovery of the new NSA access system was made two years ago by British researcher Dr Nicko van Someren. But it was only a few weeks ago when a second researcher rediscovered the access system. With it, he found the evidence linking it to NSA.
Computer security specialists have been aware for two years that unusual features are contained inside a standard Windows software "driver" used for security and encryption functions. The driver, called ADVAPI.DLL, enables and controls a range of security functions. If you use Windows, you will find it in the C:\Windows\system directory of your computer.

ADVAPI.DLL works closely with Microsoft Internet Explorer, but will only run crypographic functions that the US governments allows Microsoft to export. That information is bad enough news, from a European point of view. Now, it turns out that ADVAPI will run special programmes inserted and controlled by NSA. As yet, no-one knows what these programmes are, or what they do.

Dr Nicko van Someren reported at last year's Crypto 98 conference that he had disassembled the ADVADPI driver. He found it contained two different keys. One was used by Microsoft to control the cryptographic functions enabled in Windows, in compliance with US export regulations. But the reason for building in a second key, or who owned it, remained a mystery.

A second key

Two weeks ago, a US security company came up with conclusive evidence that the second key belongs to NSA. Like Dr van Someren, Andrew Fernandez, chief scientist with Cryptonym of Morrisville, North Carolina, had been probing the presence and significance of the two keys. Then he checked the latest Service Pack release for Windows NT4,
Service Pack 5. He found that Microsoft's developers had failed to remove or "strip" the debugging symbols used to test this software before they released it. Inside the code were the labels for the two keys. One was called "KEY". The other was called "NSAKEY".
Fernandes reported his re-discovery of the two CAPI keys, and their secret meaning, to "Advances in Cryptology, Crypto'99" conference held in Santa Barbara. According to those present at the conference, Windows developers attending the conference did not deny that the "NSA" key was built into their software. But they refused to talk about what the key did, or why it had been put there without users' knowledge.

A third key?!

But according to two witnesses attending the conference, even Microsoft's top crypto programmers were astonished to learn that the version of ADVAPI.DLL shipping with Windows 2000 contains not two, but three keys. Brian LaMachia, head of CAPI development at Microsoft was "stunned" to learn of these discoveries, by outsiders. The latest discovery by Dr van Someren is based on advanced search methods which test and report on the "entropy" of programming code.

Within the Microsoft organisation, access to Windows source code is said to be highly compartmentalized, making it easy for modifications to be inserted without the knowledge of even the respective product managers.

Researchers are divided about whether the NSA key could be intended to let US government users of Windows run classified cryptosystems on their machines or whether it is intended to open up anyone's and everyone's Windows computer to intelligence gathering techniques deployed by NSA's burgeoning corps of "information warriors".

According to Fernandez of Cryptonym, the result of having the secret key inside your Windows operating system "is that it is tremendously easier for the NSA to load unauthorized security services on all copies of Microsoft Windows, and once these security services are loaded, they can effectively compromise your entire operating system". The NSA key is contained inside all versions of Windows from Windows 95 OSR2 onwards.

"For non-American IT managers relying on Windows NT to operate highly secure data centres, this find is worrying", he added. "The US government is currently making it as difficult as possible for "strong" crypto to be used outside of the US. That they have also installed a cryptographic back-door in the world's most abundant operating system should send a strong message to foreign IT managers".

"How is an IT manager to feel when they learn that in every copy of Windows sold, Microsoft has a 'back door' for NSA - making it orders of magnitude easier for the US government to access your computer?" he asked.

Can the loophole be turned round against the snoopers?

Dr van Someren feels that the primary purpose of the NSA key inside Windows may be for legitimate US government use. But he says that there cannot be a legitimate explanation for the third key in Windows 2000 CAPI. "It looks more fishy", he said.

Fernandez believes that NSA's built-in loophole can be turned round against the snoopers. The NSA key inside CAPI can be replaced by your own key, and used to sign cryptographic security modules from overseas or unauthorised third parties, unapproved by Microsoft or the NSA. This is exactly what the US government has been trying to prevent. A demonstration "how to do it" program that replaces the NSA key can be found on Cryptonym's
website.

According to one leading US cryptographer, the IT world should be thankful that the subversion of Windows by NSA has come to light before the arrival of CPUs that handles encrypted instruction sets. These would make the type of discoveries made this month impossible. "Had the next-generation CPU's with encrypted instruction sets already been deployed, we would have never found out about NSAKEY."
_________________

__________________
You Can Do Whatever You Set Your Mind To !

Report this post to a moderator

Old Post 12-14-02 03:26 AM
sinaps is offline Click Here to See the Profile for sinaps Click here to Send sinaps a Private Message Add sinaps to your buddy list Find more posts by sinaps Reply w/Quote Edit/Delete Message IP: Logged
mikop
Supa SUPA MAN!




Registered: Mar 2002
Location: Gimpville
Country: United States
State:
Certifications: USDA Certified Worthless Organic Matter
Working on: USDA Certified Grade A SPAM

Total Posts: 2250

what's there to talk about?

just more crap from conspiracy theoriest...

your energy is better serve to read security vulnearbility from legit sites than to worry about ppl writing about everything they don't know about and claim it is some spy mechanism...

Report this post to a moderator

Old Post 12-14-02 04:00 AM
mikop is offline Click Here to See the Profile for mikop Click here to Send mikop a Private Message Add mikop to your buddy list Find more posts by mikop Reply w/Quote Edit/Delete Message IP: Logged
chodan
Senior Member
M




Registered: Mar 2000
Location: Kentucky
Country: United States
State:
Certifications: CCNA/CCNP CCDA /CCDP MCSE NT4/Win2000 MCP+I Network+ Security+
Working on: CCIE Routing & Switching

Total Posts: 1582

quote:
Originally posted by mikop
what's there to talk about?

just more crap from conspiracy theoriest...

your energy is better serve to read security vulnearbility from legit sites than to worry about ppl writing about everything they don't know about and claim it is some spy mechanism...


here here!!
what a load
Were this the case then the media would be shouting it from the rooftops.
Unless.....
THEY got to them first.

__________________
Check out my music at
www.chodan.com
Rural Development in Eastern Ky.
www.centertech.com
"It is our decisions that show us what we truly are in life, not our abilities."

Report this post to a moderator

Old Post 12-15-02 02:49 AM
chodan is offline Click Here to See the Profile for chodan Click here to Send chodan a Private Message Visit chodan's homepage! Add chodan to your buddy list Find more posts by chodan Reply w/Quote Edit/Delete Message IP: Logged
mikop
Supa SUPA MAN!




Registered: Mar 2002
Location: Gimpville
Country: United States
State:
Certifications: USDA Certified Worthless Organic Matter
Working on: USDA Certified Grade A SPAM

Total Posts: 2250

I am surprise this *news* isn't coupled with the *trial* of microsoft... how NSA and various government agency convinced the judicial system to let microsoft go and prevent hte release of microsoft source codes to protect its own interest... hmmmpf!!!....

if this is true, follow the guideline listed HERE to secure your computer and network to prevent unauthorized access from the government or every day hacker... and if you are a linux user, please use this VERSION to for enchanced security.





Report this post to a moderator

Old Post 12-15-02 03:23 AM
mikop is offline Click Here to See the Profile for mikop Click here to Send mikop a Private Message Add mikop to your buddy list Find more posts by mikop Reply w/Quote Edit/Delete Message IP: Logged
Boulware5
Moderator
M




Registered: Mar 2001
Location:
Country: USA
State:
Certifications: A+, Network+, Linux+, CST, A.A.S degree in CIS LAN concentration
Working on: BS degree, CCNA, Security+

Total Posts: 3283

If you don't want to use the NSA's Linux hardening, take a look at this:
http://www.bastille-linux.org/

It's not supported for every distro., but it has a nice GUI that walks you throw all the security settings - a nice way to learn about Linux kernel security settings.

__________________
"They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety."
-- Ben Franklin

http://www.stopfcc.com/

Report this post to a moderator

Old Post 12-15-02 03:47 AM
Boulware5 is offline Click Here to See the Profile for Boulware5 Click here to Send Boulware5 a Private Message Visit Boulware5's homepage! Add Boulware5 to your buddy list Find more posts by Boulware5 Reply w/Quote Edit/Delete Message IP: Logged
BlokWatch
Couterfeit Engineer
M




Registered: Oct 2002
Location: Columbia, SC
Country: United States
State: SC
Certifications: A+ Net+ MCP
Working on:

Total Posts: 799

Interesing enough none of my systems contain this "backdoor .DLL". Neither 98SE or any version of 2000.

Report this post to a moderator

Old Post 12-23-02 01:30 AM
BlokWatch is offline Click Here to See the Profile for BlokWatch Click here to Send BlokWatch a Private Message Add BlokWatch to your buddy list Find more posts by BlokWatch Reply w/Quote Edit/Delete Message IP: Logged
chodan
Senior Member
M




Registered: Mar 2000
Location: Kentucky
Country: United States
State:
Certifications: CCNA/CCNP CCDA /CCDP MCSE NT4/Win2000 MCP+I Network+ Security+
Working on: CCIE Routing & Switching

Total Posts: 1582

or ADVAPI.DLL either

__________________
Check out my music at
www.chodan.com
Rural Development in Eastern Ky.
www.centertech.com
"It is our decisions that show us what we truly are in life, not our abilities."

Report this post to a moderator

Old Post 12-23-02 01:47 AM
chodan is offline Click Here to See the Profile for chodan Click here to Send chodan a Private Message Visit chodan's homepage! Add chodan to your buddy list Find more posts by chodan Reply w/Quote Edit/Delete Message IP: Logged
All times are GMT.
Post new thread   Post reply

Click here for list of Security+ study guides and order yours now!

CompTIA exam notes

Security+ exam details



Forum Jump:
Rate This Thread:
Forum Rules:
Who Can Read The Forum? Any registered user or guest.
Who Can Post New Topics? Any registered user.
Who Can Post Replies? Any registered user.
Changes: Messages can be edited by their author.
Posts: HTML code is OFF. Smilies are ON. vB code is ON. [IMG] code is OFF.
 

ExamNotes forum archive


Powered by: vBulletin 2.2.8
Copyright ©2000, Jelsoft Enterprises Limited.

  Free Braindumps | mcse braindumps