<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Stratum Security Blog</title>
	<atom:link href="http://www.stratumsecurity.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.stratumsecurity.com/blog</link>
	<description>Innovative Risk Solutions</description>
	<lastBuildDate>Tue, 17 Apr 2012 11:29:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Stratum is hiring!</title>
		<link>http://www.stratumsecurity.com/blog/2012/04/17/stratum-is-hiring/</link>
		<comments>http://www.stratumsecurity.com/blog/2012/04/17/stratum-is-hiring/#comments</comments>
		<pubDate>Tue, 17 Apr 2012 11:29:28 +0000</pubDate>
		<dc:creator>Trevor</dc:creator>
				<category><![CDATA[Stratum Announcements]]></category>

		<guid isPermaLink="false">http://www.stratumsecurity.com/blog/?p=541</guid>
		<description><![CDATA[We are hiring experienced security consultants. Full details here: http://www.stratumsecurity.com/careers Perks include: pick your own laptop, utilization bonuses, business development commissions, cell phone reimbursement, work from home, and paid conferences. We&#8217;re a small but quickly growing security services company full of seasoned veterans with a strong technical core. It&#8217;s a great environment for security geeks. We [...]]]></description>
			<content:encoded><![CDATA[<p>We are hiring experienced security consultants. Full details here:</p>
<p><a href="http://www.stratumsecurity.com/careers">http://www.stratumsecurity.com/careers</a></p>
<p>Perks include: pick your own laptop, utilization bonuses, business development commissions, cell phone reimbursement, work from home, and paid conferences.</p>
<p>We&#8217;re a small but quickly growing security services company full of seasoned veterans with a strong technical core. It&#8217;s a great environment for security geeks. We speak at conferences, co-chair OWASP DC, and built <a href="http://www.threatsim.com/">www.threatsim.com</a>. We want you to be our next great hire.</p>
<p>Introduce yourself at <a href="mailto:careers@stratumsecurity.com">careers@stratumsecurity.com</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stratumsecurity.com/blog/2012/04/17/stratum-is-hiring/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fighting The Advanced Attacker: 9 Security Controls You Should Add To Your Network Right Now</title>
		<link>http://www.stratumsecurity.com/blog/2011/12/19/fighting-the-advanced-attacker-9-security-controls-you-should-add-to-your-network-right-now/</link>
		<comments>http://www.stratumsecurity.com/blog/2011/12/19/fighting-the-advanced-attacker-9-security-controls-you-should-add-to-your-network-right-now/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 14:42:13 +0000</pubDate>
		<dc:creator>Trevor</dc:creator>
				<category><![CDATA[APT]]></category>
		<category><![CDATA[Exfiltration]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[spear phishing]]></category>
		<category><![CDATA[ThreatSim]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.stratumsecurity.com/blog/?p=506</guid>
		<description><![CDATA[ We have a new post over at the ThreatSim Blog &#8220;Fighting The Advanced Attacker: 9 Security Controls You Should Add To Your Network Right Now&#8220;. It is a list of 9 things that everyone should be doing with their existing devices, infrastructure and network. Other than a lot of hard drive space (heh) the recommendations [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.stratumsecurity.com/blog/2011/12/19/fighting-the-advanced-attacker-9-security-controls-you-should-add-to-your-network-right-now/fiber_wires/" rel="attachment wp-att-507"><img class="alignnone size-full wp-image-507" title="fiber_wires" src="http://www.stratumsecurity.com/blog/wp-content/uploads/2011/12/fiber_wires.jpg" alt="" width="360" height="270" /></a> We have a <a href="http://threatsim.com/blog/2011/12/19/fighting-advanced-attacker-9-security-controls-add-network/">new post</a> over at the ThreatSim Blog &#8220;<a href="http://threatsim.com/blog/2011/12/19/fighting-advanced-attacker-9-security-controls-add-network/">Fighting The Advanced Attacker: 9 Security Controls You Should Add To Your Network Right Now</a>&#8220;. It is a list of 9 things that everyone should be doing with their existing devices, infrastructure and network. Other than a lot of hard drive space (heh) the recommendations don&#8217;t cost much. Of course you can test these security controls with our very own <a href="http://threatsim.com">ThreatSim</a> data exfiltration testing service.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stratumsecurity.com/blog/2011/12/19/fighting-the-advanced-attacker-9-security-controls-you-should-add-to-your-network-right-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Egress Network Security Poll</title>
		<link>http://www.stratumsecurity.com/blog/2011/12/07/egress-network-security-poll/</link>
		<comments>http://www.stratumsecurity.com/blog/2011/12/07/egress-network-security-poll/#comments</comments>
		<pubDate>Wed, 07 Dec 2011 13:18:27 +0000</pubDate>
		<dc:creator>Trevor</dc:creator>
				<category><![CDATA[APT]]></category>
		<category><![CDATA[Exfiltration]]></category>
		<category><![CDATA[ThreatSim]]></category>

		<guid isPermaLink="false">http://www.stratumsecurity.com/blog/?p=499</guid>
		<description><![CDATA[Stratum is conducting an anonymous survey to see what kinds of egress network security controls are in use within the enterprise. These are controls that would detect or prevent the exfiltration of sensitive data. We have already compiled a significant data set from our own customers. Please take a moment to complete the poll below. [...]]]></description>
			<content:encoded><![CDATA[<p>Stratum is conducting an anonymous survey to see what kinds of egress network security controls are in use within the enterprise. These are controls that would detect or prevent the <a href="http://threatsim.com">exfiltration</a> of sensitive data. We have already compiled a significant data set from our own customers. Please take a moment to complete the poll below. The results will be presented at this month&#8217;s <a href="http://tampabay.issa.org/">ISSA Meeting</a> in Tampa Bay, FL as well as here on our blog. Thanks!</p>
<p><iframe src="http://polls.linkedin.com/vote/159129/vvnho" frameborder="0" marginwidth="0" marginheight="0" scrolling="no" width="300" height="250"></iframe></p>
]]></content:encoded>
			<wfw:commentRss>http://www.stratumsecurity.com/blog/2011/12/07/egress-network-security-poll/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stratum Sponsoring First OWASP Tampa Day</title>
		<link>http://www.stratumsecurity.com/blog/2011/06/17/stratum-sponsoring-first-owasp-tampa-day/</link>
		<comments>http://www.stratumsecurity.com/blog/2011/06/17/stratum-sponsoring-first-owasp-tampa-day/#comments</comments>
		<pubDate>Fri, 17 Jun 2011 20:09:50 +0000</pubDate>
		<dc:creator>Nate</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[stratum]]></category>

		<guid isPermaLink="false">http://www.stratumsecurity.com/blog/?p=482</guid>
		<description><![CDATA[Stratum is proud to be sponsoring the first OWASP Tampa Day this Monday, June 20th. The free event will feature presentations aimed at providing developers and Information Security professionals with an introduction to application security. The event features 4 presentations from application security experts and &#8216;sold-out&#8217; in less than 48 hours with 76 registered attendees. [...]]]></description>
			<content:encoded><![CDATA[<p>Stratum is proud to be sponsoring the first OWASP Tampa Day this Monday, June 20th. The free event will feature presentations aimed at providing developers and Information Security professionals with an introduction to application security. The event features 4 presentations from application security experts and &#8216;sold-out&#8217; in less than 48 hours with 76 registered attendees. You can visit the event&#8217;s <a title="Eventbrite" href="http://owasptampaday2011.eventbrite.com/" target="_blank">Eventbrite page</a> for more information.</p>
<p>Stratum&#8217;s own Trevor Hawthorn will be presenting <em><em><em><em><em>PCI for Developers: Lessons from the Real World</em></em></em></em></em>,</p>
<blockquote><p>Any organization that stores, processes, or transmits credit card data must comply with the Payment Card Industry&#8217;s (PCI) Data Security Standards (DSS). PCI can be daunting even for compliance and security experts. If you are a developer, it can be a major headache. Sooner or later the day will come when you (or your developers) will need to integrate PCI into your Software Development Lifecycle (SDLC). During this talk Trevor will discuss what is required to meet PCI compliance, and examine how a wide variety of organizations tackle their compliance obligations.</p></blockquote>
<p>Stratum is also a sponsor of the <a title="OWASP Tampa" href="https://www.owasp.org/index.php/Tampa" target="_blank">OWASP Tampa</a> chapter.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stratumsecurity.com/blog/2011/06/17/stratum-sponsoring-first-owasp-tampa-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Announcing ThreatSim &#8211; Stratum&#8217;s Spear Phishing and Data Exfiltration SaaS Offering</title>
		<link>http://www.stratumsecurity.com/blog/2011/06/15/announcing-threatsim-stratums-spear-phishing-and-data-exfiltration-saas-offering/</link>
		<comments>http://www.stratumsecurity.com/blog/2011/06/15/announcing-threatsim-stratums-spear-phishing-and-data-exfiltration-saas-offering/#comments</comments>
		<pubDate>Wed, 15 Jun 2011 12:16:45 +0000</pubDate>
		<dc:creator>Trevor</dc:creator>
				<category><![CDATA[APT]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[spear phishing]]></category>
		<category><![CDATA[Stratum Announcements]]></category>
		<category><![CDATA[ThreatSim]]></category>
		<category><![CDATA[Advanced Persistent Threat]]></category>
		<category><![CDATA[apt]]></category>

		<guid isPermaLink="false">http://www.stratumsecurity.com/blog/?p=460</guid>
		<description><![CDATA[We are finally able to share something exciting that Stratum has been working on for the past several months. If you look at recent data breaches&#8211; the kind where the attackers are inside the network hanging out and shipping sensitive data out of the network&#8211; you will find two things in common: spear phishing is [...]]]></description>
			<content:encoded><![CDATA[<p>We are finally able to share something exciting that Stratum has been working on for the past several months.</p>
<p>If you look at recent data breaches&#8211; the kind where the attackers are inside the network hanging out and shipping sensitive data out of the network&#8211; you will find two things in common: spear phishing is how they got in and some form of data exfiltration is how they got out. Read Mandiant&#8217;s M-Trends report or the Verizon Data Breach Reports; it&#8217;s all discussed in-depth. Attackers are exploiting user endpoints to get right to the heart of the network. Why mess around with finding a perimeter vulnerability (sure they still exist) when you can own something in the soft chewy center of a network with access to almost everything? While this represents a major, actively exploited attack vector, the industry does not have a comprehensive, repeatable and scaleable solution to test organizations&#8217; susceptibility to these attacks. Until now.</p>
<p>Today we are announcing our new Security-as-a-Service (SaaS) offering:</p>
<p>&nbsp;</p>
<p style="text-align: center;"><a href="http://www.stratumsecurity.com/blog/wp-content/uploads/2011/06/logo_web.jpg"><img class="size-full wp-image-461 aligncenter" title="logo_web" src="http://www.stratumsecurity.com/blog/wp-content/uploads/2011/06/logo_web.jpg" alt="" width="261" height="178" /></a></p>
<p>&nbsp;</p>
<p>ThreatSim allows customers to easily run their own advanced attacker simulation campaigns that tests users, user end point devices, network security controls, 3rd party security solutions and incident response plans. ThreatSim answers three critical questions that all organizations should be asking right now:</p>
<ol>
<li>How can attackers get in?</li>
<li>How do attackers get my data out?</li>
<li>What can we do to prevent it?</li>
</ol>
<p>The ThreatSim website, <a href="http://www.threatsim.com">www.threatsim.com</a>, has more details on our new service, including how to sign up to be a beta customer. We will provide more updates here on our blog and via our ThreatSim twitter account, <a href="http://twitter.com/threatsim">@threatsim</a>. For inquires please email us at <a href="mailto:info@stratumsecurity.com">info@stratumsecurity.com</a> or fill out the <a title="Request A Demo" href="http://www.threatsim.com/demo/">Request A Demo</a> page on the ThreatSim website.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stratumsecurity.com/blog/2011/06/15/announcing-threatsim-stratums-spear-phishing-and-data-exfiltration-saas-offering/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Solving the PCI Level Puzzle with What Level am I?</title>
		<link>http://www.stratumsecurity.com/blog/2011/02/28/solving-the-pci-level-puzzle-with-what-level-am-i/</link>
		<comments>http://www.stratumsecurity.com/blog/2011/02/28/solving-the-pci-level-puzzle-with-what-level-am-i/#comments</comments>
		<pubDate>Mon, 28 Feb 2011 20:48:14 +0000</pubDate>
		<dc:creator>Trevor</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[pci]]></category>

		<guid isPermaLink="false">http://www.stratumsecurity.com/blog/?p=444</guid>
		<description><![CDATA[Starting with my first ever foray into PCI compliance, I have consistently encountered many clients (and even more potential clients) who have struggled with understanding their PCI requirements. While this may seem like a relatively easy task based on the information provided by the card brands, it is my experience that to those who&#8217;ve never [...]]]></description>
			<content:encoded><![CDATA[<p>Starting with my first ever foray into PCI compliance, I have consistently encountered many clients (and even more potential clients) who have struggled with understanding their PCI requirements. While this may seem like a relatively easy task based on the information provided by the card brands, it is my experience that to those who&#8217;ve never dealt with PCI before (and even those who deal with it on a casual basis), it can be a daunting task.</p>
<p>Flashback to a couple of months back: Trevor and I were discussing a prospective client with this exact issue when we came up with the idea of developing a website that asked simple questions and provided clear answers. Many discussions followed, a majority of which were with current and prospective PCI clients. We found that even seasoned PCI compliance professionals thought this was a &#8220;no-brainer.&#8221;</p>
<p><a href="http://www.whatlevelami.com" target="_blank"><img class="size-medium wp-image-446 alignright" title="What Level am I?" src="http://www.stratumsecurity.com/blog/wp-content/uploads/2011/02/WLAI-294x300.png" alt="What Level am I?" width="294" height="300" align="right" /></a>Today Stratum is happy to announce the culmination of all of our talking, skype-ing, and coding with the launch of <a href="http://www.whatlevelami.com/" target="_blank">www.whatlevelami.com</a> &#8211; a site that aims to be a quick online tool aimed at helping visitors easily and quickly identify their PCI requirements. While the site doesn&#8217;t cover every potential entity involved in PCI, it covers PCI Merchants and Service Providers. We&#8217;ve tried to make the site as simple as possible, using JavaScript and CSS to do most of the work. We&#8217;ve even gone as far as providing definitions for terms unfamiliar to those outside PCI (they&#8217;re underlined&#8230;simply mouse-over them and the definition will appear).</p>
<p>We would love to hear your feedback on the site, and would of course appreciate you spreading the word about its existence. Enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stratumsecurity.com/blog/2011/02/28/solving-the-pci-level-puzzle-with-what-level-am-i/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ABC Action News Smartphone Security Video Posted (with an additional Android exploit demo video)</title>
		<link>http://www.stratumsecurity.com/blog/2011/01/11/abc-action-news-smartphone-security-video-posted-with-an-additional-android-exploit-demo-video/</link>
		<comments>http://www.stratumsecurity.com/blog/2011/01/11/abc-action-news-smartphone-security-video-posted-with-an-additional-android-exploit-demo-video/#comments</comments>
		<pubDate>Tue, 11 Jan 2011 20:16:37 +0000</pubDate>
		<dc:creator>Trevor</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Android Security]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPhone Security]]></category>
		<category><![CDATA[Smartphone]]></category>
		<category><![CDATA[wireless]]></category>
		<category><![CDATA[BlackBerry]]></category>
		<category><![CDATA[jailbreak]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[smartphone]]></category>
		<category><![CDATA[videos]]></category>

		<guid isPermaLink="false">http://www.stratumsecurity.com/blog/?p=423</guid>
		<description><![CDATA[Watch the segment on Smartphone Security that aired on Monday, January 10, 2011 on WFTS (ABC Action News). Also included in the blog post is a full length demonstration video of how to exploit an Android phone running Eclair (2.1) using the CVE-2010-1807 vulnerability.]]></description>
			<content:encoded><![CDATA[<p>WFTS posted the video of the Smartphone Security piece that aired last night. You can watch the video below.</p>
<p><object id="video" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="320" height="280" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="data" value="http://www.abcactionnews.com/video/videoplayer.swf?dppversion=7151" /><param name="FlashVars" value="&amp;skin=MP1ExternalAll-MFL.swf&amp;embed=true&amp;adSizeArray=1x1000,320x40,3x1000&amp;adSrc=http%3A%2F%2Fad%2Edoubleclick%2Enet%2Fpfadx%2Fssp%2Ewfts%2Fnews%2Flocal%5Fnews%2Finvestigations%2Fdetail%3Bdcmt%3Dtext%2Fxml%3Bsz%3D%25size%25%3Bpos%3D%25pos%25%3Bloc%3D%25loc%25%3Bcomp%3D%25adid%25%3Btile%3D3%3Bfname%3Dhackers%2Dlearning%2Dnew%2Dways%2Dto%2D%2522hijack%2522%2Dsmartphones%3Bord%3D762544543249532500%3Frand%3D%25rand%25&amp;flv=http%3A%2F%2Fwww%2Eabcactionnews%2Ecom%2Ffeeds%2FoutboundFeed%3FobfType%3DVIDEO%5FPLAYER%5FSMIL%5FFEED%26componentId%3D187252427&amp;img=http%3A%2F%2Fmedia2%2Eabcactionnews%2Ecom%2F%2Fphoto%2F2011%2F01%2F10%2FHackers%5Flearning%5Fnew%5Fwcddfe97d%2Da804%2D44ff%2D878f%2Dbcb4ae1aaadb0000%5F20110110232853%5F640%5F480%2EJPG&amp;story=http%3A%2F%2Fwww%2Eabcactionnews%2Ecom%2Fdpp%2Fnews%2Flocal%5Fnews%2Finvestigations%2Fhackers%2Dlearning%2Dnew%2Dways%2Dto%2D%2522hijack%2522%2Dsmartphones&amp;category=&amp;title=&amp;oacct=&amp;ovns=" /><param name="allowNetworking" value="all" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://www.abcactionnews.com/video/videoplayer.swf?dppversion=7151" /><param name="flashvars" value="&amp;skin=MP1ExternalAll-MFL.swf&amp;embed=true&amp;adSizeArray=1x1000,320x40,3x1000&amp;adSrc=http%3A%2F%2Fad%2Edoubleclick%2Enet%2Fpfadx%2Fssp%2Ewfts%2Fnews%2Flocal%5Fnews%2Finvestigations%2Fdetail%3Bdcmt%3Dtext%2Fxml%3Bsz%3D%25size%25%3Bpos%3D%25pos%25%3Bloc%3D%25loc%25%3Bcomp%3D%25adid%25%3Btile%3D3%3Bfname%3Dhackers%2Dlearning%2Dnew%2Dways%2Dto%2D%2522hijack%2522%2Dsmartphones%3Bord%3D762544543249532500%3Frand%3D%25rand%25&amp;flv=http%3A%2F%2Fwww%2Eabcactionnews%2Ecom%2Ffeeds%2FoutboundFeed%3FobfType%3DVIDEO%5FPLAYER%5FSMIL%5FFEED%26componentId%3D187252427&amp;img=http%3A%2F%2Fmedia2%2Eabcactionnews%2Ecom%2F%2Fphoto%2F2011%2F01%2F10%2FHackers%5Flearning%5Fnew%5Fwcddfe97d%2Da804%2D44ff%2D878f%2Dbcb4ae1aaadb0000%5F20110110232853%5F640%5F480%2EJPG&amp;story=http%3A%2F%2Fwww%2Eabcactionnews%2Ecom%2Fdpp%2Fnews%2Flocal%5Fnews%2Finvestigations%2Fhackers%2Dlearning%2Dnew%2Dways%2Dto%2D%2522hijack%2522%2Dsmartphones&amp;category=&amp;title=&amp;oacct=&amp;ovns=" /><embed id="video" type="application/x-shockwave-flash" width="320" height="280" src="http://www.abcactionnews.com/video/videoplayer.swf?dppversion=7151" allowscriptaccess="always" allownetworking="all" flashvars="&amp;skin=MP1ExternalAll-MFL.swf&amp;embed=true&amp;adSizeArray=1x1000,320x40,3x1000&amp;adSrc=http%3A%2F%2Fad%2Edoubleclick%2Enet%2Fpfadx%2Fssp%2Ewfts%2Fnews%2Flocal%5Fnews%2Finvestigations%2Fdetail%3Bdcmt%3Dtext%2Fxml%3Bsz%3D%25size%25%3Bpos%3D%25pos%25%3Bloc%3D%25loc%25%3Bcomp%3D%25adid%25%3Btile%3D3%3Bfname%3Dhackers%2Dlearning%2Dnew%2Dways%2Dto%2D%2522hijack%2522%2Dsmartphones%3Bord%3D762544543249532500%3Frand%3D%25rand%25&amp;flv=http%3A%2F%2Fwww%2Eabcactionnews%2Ecom%2Ffeeds%2FoutboundFeed%3FobfType%3DVIDEO%5FPLAYER%5FSMIL%5FFEED%26componentId%3D187252427&amp;img=http%3A%2F%2Fmedia2%2Eabcactionnews%2Ecom%2F%2Fphoto%2F2011%2F01%2F10%2FHackers%5Flearning%5Fnew%5Fwcddfe97d%2Da804%2D44ff%2D878f%2Dbcb4ae1aaadb0000%5F20110110232853%5F640%5F480%2EJPG&amp;story=http%3A%2F%2Fwww%2Eabcactionnews%2Ecom%2Fdpp%2Fnews%2Flocal%5Fnews%2Finvestigations%2Fhackers%2Dlearning%2Dnew%2Dways%2Dto%2D%2522hijack%2522%2Dsmartphones&amp;category=&amp;title=&amp;oacct=&amp;ovns=" data="http://www.abcactionnews.com/video/videoplayer.swf?dppversion=7151"></embed></object></p>
<p>Yes, that was my wife sending me the rigged SMS message. Thanks Honey!</p>
<p>In all seriousness, the exploit used in the video utilized the Webkit Floating Point Datatype Remote Code Execution Vulnerability (<a title="CVE-2010-1807" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1807" target="_blank">CVE-2010-1807</a>). I used <a title="Exploit Code" href="http://downloads.securityfocus.com/vulnerabilities/exploits/43047.html" target="_blank">MJ&#8217;s exploit code</a> to compromise a stock Verizon Motorola Droid (A855) running Android Eclair (2.1). The exploit code was about 33% reliable, but I found running it against an Eclair Emulator to be far more reliable (~80%).</p>
<p>You can watch a full length video of the exploit demo below. I had put this together to show Michael George of WFTS how an attack might work. This was against an emulated Motorola Droid (A855) running Eclair (2.1).</p>
<p><iframe src="http://player.vimeo.com/video/18668105" width="400" height="300" frameborder="0"></iframe></p>
<p>If you have any questions about either of the videos, or smartphone security, please post them in the comments below. Also, make sure you read the previous posts on our blog regarding smartphone security:</p>
<ul>
<li><a title="WFTS ABC Action News Smartphone Security Piece" href="http://www.stratumsecurity.com/blog/2011/01/07/wfts-abc-action-news-smartphone-security-piece/" target="_self">WFTS ABC Action News Smartphone Security Piece</a></li>
<li><a title="The New World of SmartPhone Security" href="http://www.stratumsecurity.com/blog/2010/02/12/shmoocon-2010-video-online-the-new-world-of-smartphone-security/" target="_self">The New World of SmartPhone Security</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.stratumsecurity.com/blog/2011/01/11/abc-action-news-smartphone-security-video-posted-with-an-additional-android-exploit-demo-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WFTS ABC Action News Smartphone Security Piece</title>
		<link>http://www.stratumsecurity.com/blog/2011/01/07/wfts-abc-action-news-smartphone-security-piece/</link>
		<comments>http://www.stratumsecurity.com/blog/2011/01/07/wfts-abc-action-news-smartphone-security-piece/#comments</comments>
		<pubDate>Fri, 07 Jan 2011 13:39:27 +0000</pubDate>
		<dc:creator>Trevor</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Android Security]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPhone Security]]></category>
		<category><![CDATA[Smartphone]]></category>
		<category><![CDATA[BlackBerry]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[smartphone]]></category>

		<guid isPermaLink="false">http://www.stratumsecurity.com/blog/?p=395</guid>
		<description><![CDATA[Want to know more about smartphone security? This blog post highlights the talking points I discussed with reporter Michael George from WFTS ABC News in Tampa. Learn why people should care about smartphone security, the risks associated with using a smartphone, how smartphones are attacked, and what you can do to better secure your own smartphone.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.wfts.com"><img class="alignright size-full wp-image-414" title="ABC Action News" src="http://www.stratumsecurity.com/blog/wp-content/uploads/2011/01/abc.jpg" alt="ABC Action News" width="132" height="99" /></a>Today I was interviewed by Michael George of Tampa&#8217;s WFTS ABC Action News. He was interested in doing a piece on smartphone security; specifically what are the threats, how attacks occur, and what (if anything) users can do to protect themselves. Michael had a very good understanding of the current state of smartphone security: &#8220;Don&#8217;t run for the hills yet, but soon it will be just as messy as your home computer.&#8221;</p>
<p>I figured it was appropriate to cover my talking points on this blog post, so that others can reference the materials, and hopefully we can start a great dialogue in the comments on how to best tackle smartphone security. I will post an update with a link to the story once it airs (Anticipated 11PM on 1/7/11).</p>
<p><!-- p.p1 {margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Arial} p.p2 {margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Arial; min-height: 15.0px} span.s1 {color: #333333} --><strong>Why should people care about smartphone security?</strong></p>
<p>The mobile phone is arguably the most personal technology device that we own. People have a real relationship with the phone, the data it holds and what they do with it. There are three primary reasons why people should care about smartphone security:</p>
<ol>
<li>Protecting the integrity of the device so that you continue doing what you want to do on your phone (texting, surfing, shopping, calling, etc.) without the threat of information being made public.</li>
<li>Securing the data on the device so that if it is lost, someone else cannot retrieve all of your data, such as passwords, emails, pictures, etc.</li>
<li>Safeguarding the device itself so that you don&#8217;t have to buy a new one if you lose it.</li>
</ol>
<p><strong>What are the risks associated with using a smartphone?</strong></p>
<p>Generally speaking, the risks of using a smartphone are similar to those of using your home computer. Specifically, the following personal data may be compromised by poor smartphone security:</p>
<ul>
<li>Personal data (phone #s, email addresses, photos, etc.)</li>
<li>Account credentials (Facebook, Twitter, Bank of America)</li>
<li>Ability to use your device</li>
</ul>
<p>GPS location data is unique to smartphones when compared to desktops and most laptops. This data can also be at risk if your phone was to be compromised by an attacker or rogue application.</p>
<p><strong>How are smartphones attacked?</strong></p>
<p>Much like how the risks of using a smartphone are similar to those of using your home computer, so are the ways in which smartphones are attacked. The following are examples of how smartphones are targeted by attackers:</p>
<ol>
<li>Trojans such as Gemini, which emerged in China, sends personal data from a user&#8217;s smartphone to remote servers. It can also potentially turn your phone into a zombie controlled by the attacker. Trojans are traditionally attacked to legitimate software (sometimes unknowingly) and are equitable to computer viruses.</li>
<li>Rogue applications are applications that are supposed to be one thing, such as a game, but also include code that performs other actions. The TapSnake android game not only entertained its users, but also tracked their GPS locations every 15 minutes and allowed other people to pay to view this information.<img class="alignright size-full wp-image-402" title="iPhone" src="http://www.stratumsecurity.com/blog/wp-content/uploads/2011/01/pirate_iphone.jpg" alt="Jail-Broken iPhone" width="273" height="336" /></li>
<li>By &#8220;hacking&#8221; your own phone, you can actually make it less secure. &#8220;Jail-breaking&#8221; or &#8220;rooting&#8221; your phone can leave you exposed to hackers. For example, rooting the iPhone enables remote access via SSH and the default root password is commonly known. The iBontNet.A worm used this insecure configuration to steal online banking credentials from ING Direct account holders. Also a Dutch hacker in 2009 held &#8220;jailbroken&#8221; iPhones for ransom by charging €5 to provide instructions on how to secure the affected phones and remove the &#8220;hacked&#8221; wallpaper</li>
</ol>
<p><strong>What can you do to help secure your smartphone?</strong></p>
<p>Following the checklist below will go a long way in helping to secure your smartphone. However, realize that no smartphone is 100% secure, and always practice caution when installing applications, visiting websites, or clicking on links.</p>
<ul>
<li>Only install applications from trusted sources, like Apple&#8217;s AppStore or Google&#8217;s Android Market</li>
<li>Review the permissions that applications ask for, and when they don&#8217;t seem right, do some research online before installing</li>
<li><a href="http://www.mylookout.com"><img class="size-full wp-image-407 alignright" title="Lookout Mobile Security" src="http://www.stratumsecurity.com/blog/wp-content/uploads/2011/01/lookout.png" alt="Lookout Mobile Security" width="238" height="55" /></a>Install a security suite such as <a title="Lookout Mobile" href="http://www.mylookout.com" target="_blank">Lookout Mobile</a> (Android, BlackBerry, Win7) or <a title="Trend Micro" href="http://itunes.apple.com/app/smart-surfing/id306657316?mt=8" target="_blank">Trend Micro</a> for iPhone that looks for malicious applications and/or websites</li>
<li>Install updates for applications and firmware</li>
<li>Don&#8217;t click on links from unsolicited emails or text messages</li>
<li>Set a strong password for your phone</li>
<li>Install a remote location identification application like <a title="Lookout Mobile" href="http://www.mylookout.com" target="_blank">Lookout Mobile</a> or <a title="MobileMe" href="http://www.apple.com/mobileme/" target="_blank">MobileMe</a> so that you can locate and/or wipe your lost phone</li>
</ul>
<p><strong>More Information</strong></p>
<p>For more information on smartphone security, you can watch Trevor&#8217;s ShmooCon 2010 presentation entitled, <a title="The New World of SmartPhone Security" href="http://www.stratumsecurity.com/blog/2010/02/12/shmoocon-2010-video-online-the-new-world-of-smartphone-security/" target="_self">The New World of SmartPhone Security</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stratumsecurity.com/blog/2011/01/07/wfts-abc-action-news-smartphone-security-piece/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Lights-out Football in New York</title>
		<link>http://www.stratumsecurity.com/blog/2010/12/13/lights-out-football-in-new-york/</link>
		<comments>http://www.stratumsecurity.com/blog/2010/12/13/lights-out-football-in-new-york/#comments</comments>
		<pubDate>Mon, 13 Dec 2010 16:01:36 +0000</pubDate>
		<dc:creator>Trevor</dc:creator>
				<category><![CDATA[Smart Grid]]></category>
		<category><![CDATA[Availability]]></category>
		<category><![CDATA[Terrorism]]></category>

		<guid isPermaLink="false">http://www.stratumsecurity.com/blog/?p=365</guid>
		<description><![CDATA[For those of you who don't know, the New Meadowlands stadium, filled with 80,851 fans, completely lost power during the 3rd quarter of the November 14th game between the Giants and Cowboys. The complete outage lasted only 5-6 seconds, but for someone with a Smart Grid security background, the first thing I thought was <em>terrorism</em>.]]></description>
			<content:encoded><![CDATA[<p>On Sunday, November 14, 2010 the Dallas Cowboys defeated the New York Giants 33-20. Fans of the NFL had a number of reasons to watch this game; a historically bitter NFC East rivalry, the Cowboys&#8217; new coach Jason Garrett testing his coaching prowess against a strong opponent, or simply wanting to catch a glimpse of the Giants&#8217; new $1.6 billion New Meadowlands stadium. I personally was watching the game, or at least as much that was covered by the NFL&#8217;s RedZone channel.</p>
<p>You might be asking yourself why I am talking about a sports event on an Information Security blog. Well for those of you who don&#8217;t know, the New Meadowlands stadium, filled with 80,851 fans, completely lost power during the 3rd quarter of the game. The complete outage lasted only 5-6 seconds, but for someone with a Smart Grid security background, the first thing I thought was <em>terrorism</em>. Thankfully this was not the case, and there are no indications of such; rather a New Jersey Sports and Exposition Authority transformer failure caused the outage.</p>
<div id="attachment_366" class="wp-caption aligncenter" style="width: 390px"><a href="http://www.stratumsecurity.com/blog/wp-content/uploads/2010/12/NewMeadowlands.jpg"><img class="size-full wp-image-366" title="NewMeadowlands" src="http://www.stratumsecurity.com/blog/wp-content/uploads/2010/12/NewMeadowlands.jpg" alt="Power Outage at the New Meadowlands" width="380" height="255" /></a><p class="wp-caption-text">Power Outage at the New Meadowlands</p></div>
<p>What concerns me is that while the stadium was able to restore power from the total blackout in a timely manner, the outage itself may have provided terrorists with a previously unidentified target: large stadiums filled with Americans. I have read about sporting events being the target of terrorist attacks before, but not when the power (or lack their of) was the target. Imagine the chaos that would have ensued if the stadium was without power for several minutes or hours. Several of the NFL players that night voiced similar concerns.</p>
<ul>
<li>The Giant&#8217;s star Justin Tuck commented that, &#8220;You start worrying about is your family all right.&#8221;</li>
</ul>
<p>As I was watching the situation unfold on the RedZone channel, Fox&#8217;s Joe Buck, Troy Aikman, and Pam Oliver (who were covering the game) made the following observations:</p>
<ul>
<li>Troy Aikman &#8211; &#8220;They didn&#8217;t know what was going on nor did anyone else. But they hit the ground. A number of those guys did.&#8221;</li>
<li>Pam Oliver &#8211; Described the scene as &#8220;organized chaos&#8221; and &#8220;extremely scary&#8221; when the lights went out.</li>
</ul>
<p>Interestingly, when Buck and Aikman were describing the scene at the New Meadowlands, they failed to mention that during the blackout, fire alarms also sounded. They did mention that an announcement came over the PA system telling fans to remain in their seats and to stay tuned for evacuation instructions, if necessary.</p>
<p>Fortunately, no major incidents occurred as a result of the power outage. However, I hope that those responsible for securing the New Meadowlands, and all public venues, use this as an opportunity to better understand their own weaknesses and how they may now have an additional threat from terrorists; power outages.</p>
<p><img class="size-full wp-image-378 alignright" title="Securing The Smart Grid" src="http://www.stratumsecurity.com/blog/wp-content/uploads/2010/12/SmartGrid.jpg" alt="Securing The Smart Grid" width="120" height="148" align="Right" /></p>
<p>Attacks like this are covered in my book, <a href="http://www.amazon.com/Securing-Smart-Grid-Generation-Security/dp/1597495700" target="_blank">Securing the Smart Grid</a>. <a href="http://www.syngress.com/" target="_blank">Syngress</a> has made part of the chapter covering threats like these, entitled &#8220;Threats and Impacts: Utility Companies and Beyond,&#8221; available <a href="http://www.stratumsecurity.com/blog/Securing_the_Smart_Grid_Sample.pdf" target="_blank">here</a>. It is unfortunate that situations like these are sometimes necessary to identify &#8220;unknown, unknowns&#8221; to our national security.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stratumsecurity.com/blog/2010/12/13/lights-out-football-in-new-york/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Shearing FireSheep with the Cloud</title>
		<link>http://www.stratumsecurity.com/blog/2010/12/03/shearing-firesheep-with-the-cloud/</link>
		<comments>http://www.stratumsecurity.com/blog/2010/12/03/shearing-firesheep-with-the-cloud/#comments</comments>
		<pubDate>Fri, 03 Dec 2010 13:56:28 +0000</pubDate>
		<dc:creator>Trevor</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[EC2]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[wireless]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[FireSheep]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Proxy]]></category>

		<guid isPermaLink="false">http://www.stratumsecurity.com/blog/?p=276</guid>
		<description><![CDATA[If your laptop ever connects to a network behind enemy lines (e.g. hhonors, attwifi, panera), this post is for you. The step-by-step directions below allow you to stand up a portable, cloud-based private VPN that you can use from anywhere - for around $0.50 a month. Once you get everything setup, you can feel good connecting to a hotspot and laugh at the guy running FireSheep.]]></description>
			<content:encoded><![CDATA[<div id="_mcePaste">If your laptop ever connects to a network behind enemy lines (e.g. hhonors, attwifi, panera), this post is for you. The step-by-step directions below allow you to stand up a portable, cloud-based private VPN that you can use from anywhere &#8211; for around $0.50 a month. Once you get everything setup, you can feel good connecting to a hotspot and laugh at the guy running <a title="FireSheep" href="http://codebutler.com/firesheep" target="_blank">FireSheep</a>.</div>
<p>&nbsp;</p>
<div>Speaking of Firesheep, I&#8217;ve actually had some people close to me (including my wife) ask how they can prevent these types of attacks from happening. There are some nice &#8220;off-the-shelf&#8221; solutions like <a title="HTTPS Everywhere" href="http://www.eff.org/https-everywhere" target="_blank">HTTPS Everywhere</a> and <a title="BlackSheep" href="http://www.zscaler.com/blacksheep.html" target="_blank">BlackSheep</a> but as a security professional I wanted to give a recommendation that would provide broader coverage than these solutions.</div>
<p>&nbsp;</p>
<div id="_mcePaste">Enter Amazon&#8217;s recently introduced <a title="Free Tier" href="http://aws.amazon.com/free/" target="_blank">Free Tier</a> for EC2. I&#8217;ll save my thoughts and comments on &#8220;The Cloud&#8221; and security for a later date (and after a couple of beers), but for the purposes of this solution, it works great to help you increase your security while using open wireless networks. Quite simply, the solution I came up with was to create an EC2 instance with Ubuntu 10.04 LTS server and setup OpenVPN and SideStep. This allows me to route all of my traffic over an SSL or SSH VPN to my EC2 instance and then out to the Internet.</div>
<p>&nbsp;</p>
<div>To graphically represent what this solution offers, below is a picture of your laptop while surfing on an Open Wi-Fi network such as those at Starbucks.</div>
<p><a href="http://www.stratumsecurity.com/blog/wp-content/uploads/2010/12/Laptop.jpg"><img class="aligncenter size-medium wp-image-328" title="Your Laptop @ Starbucks" src="http://www.stratumsecurity.com/blog/wp-content/uploads/2010/12/Laptop-300x223.jpg" alt="Your Laptop @ Starbucks" width="300" height="223" /></a></p>
<div>The second image is the guy running Firesheep at Starbucks.</div>
<p><img class="aligncenter size-full wp-image-330" title="The Guy @ Starbucks Running FireSheep" src="http://www.stratumsecurity.com/blog/wp-content/uploads/2010/12/FireSheep.jpg" alt="The Guy @ Starbucks Running FireSheep" width="268" height="400" /></p>
<div>The last image depicts your laptop running OpenVPN or SideStep at Starbucks.</div>
<p><a href="http://www.stratumsecurity.com/blog/wp-content/uploads/2010/12/OpenVPN.jpg"><img class="aligncenter size-medium wp-image-333" title="Your Laptop Armed with OpenVPN or SideStep @ Starbucks" src="http://www.stratumsecurity.com/blog/wp-content/uploads/2010/12/OpenVPN-300x198.jpg" alt="Your Laptop Armed with OpenVPN or SideStep @ Starbucks" width="300" height="198" /></a></p>
<div>Enough with the &#8216;Behind Enemy Lines&#8217; comparisons&#8230;I swear. I installed other services on my EC2 instance, like <a title="Privoxy" href="http://www.privoxy.org/" target="_blank">Privoxy</a> and iodine (<a title="iodine" href="http://www.stratumsecurity.com/blog/2010/10/18/data-exfiltration-with-iodine/" target="_blank">see my post on tunneling traffic via iodine</a>), but for the purpose of this post, I will limit the scope to creating an EC2 instance, installing and configuring OpenVPN, and installing and configuring SideStep.</div>
<p>&nbsp;</p>
<div>A couple of notes before we get started. While the instructions that follow utilize Amazon&#8217;s Free Tier,<em> this setup will cost you roughly $.50 per month</em>. <del datetime="2011-02-22T16:33:40+00:00">There are ways to shrink your EC2 ami to fit within the Free Tier&#8217;s EBS limit of 10GB, but I will pay around $.50 a month to have this service available to me (the Ubuntu AMI we will use utilizes 15GB of EBS).</del> <em>Thanks to Martin&#8217;s post in the comments below, I have updated this post to utilize an 8GB ami, which is less than the 10GB allotted in the free tier for EBS storage.</em></div>
<p>&nbsp;</p>
<div id="_mcePaste">Also, thanks to <a title="Chetan Surpur" href="http://chetansurpur.com/" target="_blank">Chetan Surpur</a>, <a title="TaoSecurity" href="http://taosecurity.blogspot.com/2010/11/trying-ubuntu-1010-in-aws-free-usage.html" target="_blank">TaoSecurity</a>, <a title="Alestic" href="http://alestic.com/" target="_blank">Alestic</a>, and <a title="Ivan Kristianto" href="http://www.ivankristianto.com/os/ubuntu/howto-install-configure-openvpn-on-ubuntu/1462/" target="_blank">Ivan Kristianto</a>.</div>
<p>&nbsp;</p>
<div>So let&#8217;s get started…</div>
<p>&nbsp;</p>
<div>1. If you haven&#8217;t already, head over to <a title="Amazon EC2" href="http://aws.amazon.com/ec2/" target="_blank">Amazon EC2</a> and create an Amazon EC2 account.</div>
<p>&nbsp;</p>
<div>2. Once you have created an account, visit the <a title="AWS Management Console" href="https://console.aws.amazon.com/ec2/home" target="_blank">AWS Management Console</a> and click on the &#8216;Key Pairs&#8217; link on the left side of the screen. Here you will create a Key Pair that will allow you to login to your EC2 instances. Click on the &#8216;Create Key Pair&#8217; button and name the Key Pair something unique. I chose &#8216;JustinsAllEC2Key&#8217;. Save the file in your ~/Download folders and move it to your ~/.ssh/ folder by issuing the following commands:</div>
<p>&nbsp;</p>
<div style="padding-left: 30px;"><strong>Your Mac</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>jmorehouse@Old-Trafford:~$ cd Downloads</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>jmorehouse@Old-Trafford:Downloads$ mv JustinsAllEC2Key.pem ~/.ssh/</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>jmorehouse@Old-Trafford:Downloads$ chmod 400 ~/.ssh/JustinsAllEC2Key.pem</code></div>
<p>&nbsp;</p>
<div id="_mcePaste">3. Now that you have a key pair, it is time to create and launch an instance. Click on the &#8216;AMIs&#8217; link on the left side. Then select All Images from the &#8216;Viewing&#8217; drop-down (it takes a minute to load all of the available instances), and search for <del datetime="2011-02-22T16:33:40+00:00">ami-4a0df923</del> <em>&#8216;ami-3e02f257&#8242;</em>. This is an EBS instance of Ubuntu 10.04 LTS Server <del datetime="2011-02-22T16:33:40+00:00">64-bit</del> 32-bit from <a title="Alestic" href="http://alestic.com/" target="_blank">Alestic</a>. EBS allows for persistent storage, so that your setting will remain even when you power-cycle your instance.</div>
<p>&nbsp;</p>
<div>4. Select the AMI and then click the &#8216;Launch&#8217; button at the top. You will be prompted with a number of options, and I recommend using the following:</div>
<div id="_mcePaste">
<ul>
<li>
<div id="_mcePaste">Number of Instances: 1</div>
</li>
<li>
<div id="_mcePaste">Availability Zone: No Preference</div>
</li>
<li>
<div id="_mcePaste">Instance Type: Micro</div>
</li>
<li>
<div id="_mcePaste">Launch Instances</div>
</li>
<li>
<div id="_mcePaste">Click &#8216;Continue&#8217;</div>
</li>
</ul>
</div>
<p>&nbsp;</p>
<div id="_mcePaste">
<ul>
<li>
<div id="_mcePaste">Kernel ID: Default</div>
</li>
<li>
<div id="_mcePaste">RAM Disk ID: Default</div>
</li>
<li>
<div id="_mcePaste">No Monitoring</div>
</li>
<li>
<div id="_mcePaste">No User Data</div>
</li>
<li>
<div id="_mcePaste">Click &#8216;Continue&#8217;</div>
</li>
</ul>
</div>
<p>&nbsp;</p>
<div>
<ul>
<li>
<div id="_mcePaste">Key = &#8216;Name&#8217;</div>
</li>
<li>
<div id="_mcePaste">Value = &#8216;Free Tier EC2 Ubuntu 10.04 Instance&#8217;</div>
</li>
<li>
<div id="_mcePaste">Click &#8216;Continue&#8217;</div>
</li>
</ul>
</div>
<p>&nbsp;</p>
<div>
<ul>
<li>
<div id="_mcePaste">Choose from your existing Key Pairs &#8211; &#8216;JustinsAllEC2Key&#8217; -&gt; This is the key you previously created in Step 2 and moved to your ~/.ssh/ folder.</div>
</li>
<li>
<div id="_mcePaste">Create a new Security Group &#8211; &#8216;InternetAccessible&#8217; -&gt; This akin to a firewall ruleset group. I created a new once called &#8216;InternetAccessible&#8217;, but you can just as simply use and edit the &#8216;Default&#8217; group.</div>
</li>
<li>
<div id="_mcePaste">Describe your security group &#8211; &#8216;Services allowed from the Internet&#8217;</div>
</li>
<li>
<div id="_mcePaste">Select &#8216;SSH&#8217; from the drop-down &#8216;Applications&#8217; menu -&gt; I left &#8216;All Internet&#8217; as we want to access this instance from wherever we are on the Internet.</div>
</li>
<li>
<div id="_mcePaste">Click &#8216;Add Rule&#8217;</div>
</li>
<li>
<div id="_mcePaste">Select &#8216;HTTPS&#8217; from the drop-down &#8216;Applications&#8217; menu -&gt; This will give us access to our OpenVPN server. I also left this open to &#8216;All Internet&#8217; for the same reason we configured SSH this way.</div>
</li>
<li>
<div id="_mcePaste">Click &#8216;Add Rule&#8217;</div>
</li>
<li>
<div id="_mcePaste">Click &#8216;Continue&#8217;</div>
</li>
</ul>
</div>
<p>&nbsp;</p>
<div id="_mcePaste">5. You are then be presented with a confirmation page where you should confirm your setting and make any necessary changes. If everything looks good, go ahead and launch your instance.</div>
<p>&nbsp;</p>
<div>6. Your instance is now launching. Click on the &#8216;View your instances on the Instances page&#8217; link to access information about your instance.</div>
<p>&nbsp;</p>
<div>7. Now we will assign a static IP address to your instance as Amazon makes this feature available for free (what IPv4 shortage?). Click on the &#8216;Elastic IPs&#8217; link on the left side. Then click on the &#8216;Allocate New Address&#8217; button in the center of the page. Click the &#8216;Yes, Allocate&#8217; button, and then click the checkbox infront of the newly added IP address. We want to associate this IP with your newly created instance. You can do this by now clicking on the &#8216;Associate&#8217; button at the top. Select the &#8216;Instance ID&#8217; for the instance you just created (there should be only one Instance ID in the drop-down) and click &#8216;Associate&#8217;. Copy the IP address somewhere handy as we will need it in a couple of minutes.</div>
<p>&nbsp;</p>
<div id="_mcePaste">8. Once you have done this, it&#8217;s time to login to your EC2 instance! You can perform this from Terminal using the following:</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><strong>Your Mac</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>jmorehouse@Old-Trafford:Downloads$ cd ~</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>jmorehouse@Old-Trafford:~$ ssh -i ~/.ssh/&lt;filename&gt;.pem ubuntu@IPAddress</code></div>
<p>&nbsp;</p>
<div id="_mcePaste">9. Type &#8216;yes&#8217; to accept the RSA key fingerprint and you should see something akin to the following:</div>
<blockquote><p>Linux ec2 2.6.32-309-ec2 #18-Ubuntu SMP Mon Oct 18 21:00:50 UTC 2010 x86_64 GNU/Linux<br />
Ubuntu 10.04.1 LTS</p>
<p>Welcome to Ubuntu!<br />
* Documentation:  https://help.ubuntu.com/</p>
<p>System information as of Fri Dec  3 00:40:20 UTC 2010</p>
<p>System load:  0.0               Processes:           60<br />
Usage of /:   6.2% of 14.76GB   Users logged in:     1<br />
Memory usage: 6%                IP address for eth0: 10.XX.XX.XX<br />
Swap usage:   0%                IP address for tun0: 10.X.XX.X</p>
<p>Graph this data and manage this system at https://landscape.canonical.com/<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
At the moment, only the core of the system is installed. To tune the<br />
system to your needs, you can choose to install one or more<br />
predefined collections of software by running the following<br />
command:</p>
<p>sudo tasksel &#8211;section server<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>14 packages can be updated.<br />
4 updates are security updates.</p>
<p>Last login: Thu Dec  2 23:22:38 2010 from pool-XX-XX-XX-X.domain.net</p></blockquote>
<div id="_mcePaste">10. At this point you want to perform some hardening and maintenance on the box.</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><em>Update passwords</em></div>
<div id="_mcePaste" style="padding-left: 30px;"><strong>EC2 Instance</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~$ sudo su -</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~$ passwd ubuntu</code> <span style="color: #3366ff;">(Enter in a new password for the &#8216;ubuntu&#8217; account. This is the default account on your EC2 instance. I recommend storing these passwords in <a title="KeePassX" href="http://www.keepassx.org/downloads" target="_blank">KeePassX</a>)</span></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~$ passwd</code> <span style="color: #3366ff;">(Enter in a new password for the &#8216;root&#8217; account. This account should be need no explanation.)</span></div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><em>Update packages</em></div>
<div id="_mcePaste" style="padding-left: 30px;"><strong>EC2 Instance</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~$ exit</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~$ sudo apt-get update </code> <span style="color: #3366ff;">(This updates the list of known packages.)</span></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~$ sudo apt-get upgrade -y</code> <span style="color: #3366ff;">(This upgrades the installed packages to their latest version.)</span></div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;">If you are prompted for grub-pc config update, just hit enter. Also select &#8216;Yes&#8217; at the next Grub message window.</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><em>Time Zone</em></div>
<div id="_mcePaste" style="padding-left: 30px;"><strong>EC2 Instance</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~$ sudo dpkg-reconfigure tzdata</code></div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;">Follow the instructions to setup the proper timezone information for your EC2 instance.</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~$ sudo reboot now</code> <span style="color: #3366ff;">(This will reboot the sytem. Wait about 2 minutes before you try and reconnect to the EC2 instance via Terminal using the above ssh command.)</span></div>
<p>&nbsp;</p>
<div id="_mcePaste">11. At this point I setup a host record for my EC2 instance so that I could use DNS to access it. I also configured the hostname on the system to match the DNS record. This is an optional step, and if you aren&#8217;t sure what I am talking about or aren&#8217;t sure how to do it, don&#8217;t worry about it.</div>
<p>&nbsp;</p>
<div id="_mcePaste">12. Now that we have our EC2 instance configured and ready to go, it is time to install and configure OpenVPN. To install OpenVPN on your EC2 instance, simply type the following from within your SSH session:</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><strong>EC2 Instance</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~$ sudo apt-get -y install openvpn libssl-dev openssl</code></div>
<p>&nbsp;</p>
<div id="_mcePaste">13. Now we need to create the certificates to use with OpenVPN. First let&#8217;s copy the easy-rsa tool to the OpenVPN folder.</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><strong>EC2 Instance</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~$ cd /etc/openvpn/</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn$ sudo mkdir easy-rsa</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn$ sudo cp -r /usr/share/doc/openvpn/examples/easy-rsa/2.0/* /etc/openvpn/easy-rsa/</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn$ sudo chown -R $USER /etc/openvpn/easy-rsa/</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn$ cd /etc/openvpn/easy-rsa/</code></div>
<p>&nbsp;</p>
<div id="_mcePaste">14. We now need to edit the &#8216;vars&#8217; file to provide some information for our SSL certificates. You will need to know how to use the &#8216;vi&#8217; text editor. If you don&#8217;t know how to use it, I recommend this <a title="tutorial" href="http://heather.cs.ucdavis.edu/~matloff/UnixAndC/Editors/ViIntro.html" target="_blank">tutorial</a>.</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><strong>EC2 Instance</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa$ sudo vi vars</code></div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;">Change export &#8216;KEY_SIZE=1024&#8242; to &#8216;export KEY_SIZE=2048&#8242;</div>
<div id="_mcePaste" style="padding-left: 30px;">Change export KEY_COUNTRY=&#8221;US&#8221; to your country.</div>
<div id="_mcePaste" style="padding-left: 30px;">Change export KEY_PROVINCE=&#8221;CA&#8221; to your state. I.e. &#8216;KEY_PROVINCE=&#8221;FL&#8221;&#8216;</div>
<div id="_mcePaste" style="padding-left: 30px;">Change export KEY_CITY=&#8221;SanFrancisco&#8221; to your city. I.e. &#8216;KEY_CITY=&#8221;Tampa&#8221;&#8216;</div>
<div id="_mcePaste" style="padding-left: 30px;">Change export KEY_ORG=&#8221;Fort-Funston&#8221; to your organization or something else. I did my family (&#8216;KEY_ORG:&#8221;Morehouse-Family&#8221;&#8216;)</div>
<div id="_mcePaste" style="padding-left: 30px;">Change export KEY_EMAIL=&#8221;me@myhost.mydomain&#8221; to your email address.</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;">Save the file by hitting the &#8216;ESC&#8217; key and then typing &#8216;:wq&#8217; and press enter.</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa$ source vars</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa$ ./clean-all</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa$ source vars</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa$ ./build-ca</code></div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;">You should be prompted for the following. You can hit &#8216;enter&#8217; to keep the default value you already setup by editing the &#8216;vars&#8217; file.</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;">Country Name (2 letter code) [US]:</div>
<div id="_mcePaste" style="padding-left: 30px;">State or Province Name (full name) [FL]:</div>
<div id="_mcePaste" style="padding-left: 30px;">Locality Name (eg, city) [Tampa]:</div>
<div id="_mcePaste" style="padding-left: 30px;">Organization Name (eg, company) [Morehouse-Family]:</div>
<div id="_mcePaste" style="padding-left: 30px;">Organizational Unit Name (eg, section) []:Personal</div>
<div id="_mcePaste" style="padding-left: 30px;">Common Name (eg, your name or your server&#8217;s hostname) [justin.domain.org]: -&gt; Enter your hostname here if you created a DNS record. Otherwise enter your EC2&#8242;s Elastic IP address from Step 7.</div>
<div id="_mcePaste" style="padding-left: 30px;">Name []:Justin Morehouse</div>
<div id="_mcePaste" style="padding-left: 30px;">Email Address [justin@mydomain.com]:</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;">Now execute the following commands:</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa$ ./build-dh</code> <span style="color: #3366ff;">(This takes some time. Like 2 minutes.)</span></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa$ source vars</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa$ ./pkitool --server server</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa$ cd keys</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa/keys$ openvpn --genkey --secret ta.key</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa/keys$ sudo cp server.crt server.key ca.crt dh2048.pem ta.key /etc/openvpn/</code></div>
<p>&nbsp;</p>
<div id="_mcePaste">15. Now we have created the CA and Server certificates. Now we need to create keys for our users. For the purpose of this blog, we will create one key for one user. You can repeat this step for each additional user you wish to allow to access your OpenVPN server.</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><strong>EC2 Instance</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa/keys$ cd..</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa$ source vars</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa$ ./pkitool &lt;yourname&gt;</code> <span style="color: #3366ff;">(I typed &#8216;./pkitool justin&#8217;)</span></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn/easy-rsa$ cd ..</code></div>
<p>&nbsp;</p>
<div id="_mcePaste">16. Now we need to create an archive to download all of the necessary files from the server to the system you want to configure to use OpenVPN (Your laptop). I recommend using <a title="Cyberduck" href="http://cyberduck.ch/" target="_blank">Cyberduck</a> to access the .tar file we create. Remember to use your EC2 key to login with Cyberduck. It is the key we created in Step 2 and stored in your ~/.ssh/ folder (JustinsAllEC2Key.pem). Remember, the keys.tar file will be located in the /etc/openvpn/ directory. Download the keys.tar file to your Downloads directory.</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><em>EC2 Instance</em></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn$ sudo tar czf keys.tgz ca.crt ta.key easy-rsa/keys/<em>yourname.crt</em> easy-rsa/keys/<em>yourname.key</em></code></div>
<p>&nbsp;</p>
<div id="_mcePaste">17. Now it&#8217;s time to configure your OpenVPN server. You can most likely use the pre-configured template I posted online. It uses the IP address scheme of 10.8.80.0/24 for VPN clients, so unless you are using that network somewhere else, you don&#8217;t need to change a thing in the configuration. If you do need to edit the network, you can download the server.conf file <a title="server.conf" href="http://www.stratumsecurity.com/sites/default/files/server.conf" target="_blank">here</a> or issue the commands below and use vi to edit it as you would like. Use the commands below to download the server.conf file to the /etc/openvpn folder on your EC2 instance.</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><strong>EC2 Instance</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:/etc/openvpn$ sudo wget http://www.stratumsecurity.com/sites/default/files/server.conf</code></div>
<p>&nbsp;</p>
<div id="_mcePaste">18. Now we have to setup ip forwarding on your EC2 instance. We&#8217;ll use sudo to perform these commands.</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><strong>EC2 Instance</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~$ sudo su -</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>root@ec2:~$ modprobe iptable_nat</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>root@ec2:~$ echo 1 &gt; /proc/sys/net/ipv4/ip_forward</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>root@ec2:~$ iptables -t nat -A POSTROUTING -s 10.8.80.0/24 -o eth0 -j MASQUERADE</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>root@ec2:~$ iptables-save &gt; /etc/iptables.conf</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>root@ec2:~$ echo '#!/bin/sh' &gt; /etc/network/if-up.d/iptables</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>root@ec2:~$ echo "iptables-restore &lt; /etc/iptables.conf" &gt;&gt; /etc/network/if-up.d/iptables</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>root@ec2:~$ chmod +x /etc/network/if-up.d/iptables</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>root@ec2:~$ echo "net.ipv4.ip_forward=1" &gt;&gt; /etc/sysctl.conf</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>root@ec2:~$ reboot now</code></div>
<p>&nbsp;</p>
<div id="_mcePaste">19. Back on your Mac, download and install Tunnelblick. It is is a free, open source Graphic User Interface (GUI) for OpenVPN on Mac OS X. You can download the latest stable version from <a title="here" href="http://code.google.com/p/tunnelblick/downloads/detail?name=Tunnelblick_3.0.dmg" target="_blank">here</a>.</div>
<p>&nbsp;</p>
<div id="_mcePaste">20. Once you have installed Tunnel blick, go do your &#8216;Downloads&#8217; folder and extract your keys.tar files. Copy the ca.crt, ta.key, &lt;yourname&gt;.crt, and &lt;yourname.key&gt; files from the extracted .tar file to the Tunnelblick directory located at &#8216;<em>~/Library/Application\ Support/Tunnelblick/Configurations/</em>&#8216;. (&lt;yourname&gt;.crt and &lt;yourname.key&gt; will be in the &#8216;easy-rsa/keys&#8217; folder. Make sure all of the extracted files are in the &#8216;<em>~/Library/Application\ Support/Tunnelblick/Configurations/</em>&#8216; folder!)</div>
<p>&nbsp;</p>
<div id="_mcePaste">21. You will now need to edit the client template that I have posted <span style="color: #000000;"><a title="ec2.conf" href="http://www.stratumsecurity.com/sites/default/files/ec2.conf" target="_blank">here</a></span>. Download the file to &#8216;<em>~/Library/Application\ Support/Tunnelblick/Configurations/</em>&#8216; and edit the following three items:</div>
<div id="_mcePaste" style="padding-left: 30px;">
<ul>
<li>
<div id="_mcePaste">Line 42: Change &#8216;&lt;IP or hostname&gt;&#8217; to your EC2 instance&#8217;s IP address, from Step 7, or the DNS name you gave it.</div>
</li>
<li>
<div id="_mcePaste">Lines 89 &amp; 90: Change cert &lt;yourname&gt;.crt &amp; key &lt;yourname&gt;.key to the names of the .crt and .key files you extracted from the keys.tar file. This the client certificate you created for yourself in Step 15.</div>
</li>
</ul>
</div>
<div id="_mcePaste">22. Once this is done, open up a web browser and go to <a title="IP Chicken" href="http://www.ipchicken.com" target="_blank">IP Chicken</a>. Obesrve your current source IP address. Then open Tunnelblick and from the menu bar at the top, select <em>Connect &#8216;ec2&#8242;</em>. Reload your browser and notice that you now have a source IP address of your EC2 instance! Congratulations on getting OpenVPN on an EC2 instance setup. Now let&#8217;s setup SideStep.</div>
<p>&nbsp;</p>
<div id="_mcePaste">23. While Tunnelblick allows you to create an on-demand SSL tunnel to proxy all of your network traffic through your EC2 instance (for both wired and wireless) networks, SideStep takes the guess work out of when to use a proxy to secure your network when you are on an open wireless network (it currently only works on wireless networks, but Chetan is going add the capability to use it on an wired network as well). First download and install <a title="SideStep" href="http://chetansurpur.com/projects/sidestep/" target="_blank">SideStep</a>.</div>
<p>&nbsp;</p>
<div id="_mcePaste">24. SideStep uses passwords or keys to create an on-demand SSH tunnel that proxies your traffic. As our EC2 instance doesn&#8217;t allow for password logins via SSH, we need to create a new keypair to use with SideStep. Using Terminal on your Mac, issue the following commands:</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><strong>Your Mac</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>jmorehouse@Old-Trafford:~$ cd ~</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>jmorehouse@Old-Trafford:~$ ssh-keygen -t rsa -f ~/.ssh/id_ec2</code></div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;">Enter in a passphrase twice, and store it some place safe (KeePassX) because you will need it later.</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><code>jmorehouse@Old-Trafford:~$ scp -i .ssh/JustinsAllEC2Key.pem .ssh/id_ec2.pub ubuntu@IP:~/.ssh/</code> <span style="color: #3366ff;">(Key created in Step 2 and IP address from Step 7.)</span></div>
<p>&nbsp;</p>
<div id="_mcePaste">25. Still within Terminal, log back into your EC2 instance and append the public key to your authorized_keys file.</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><strong>Your Mac</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>jmorehouse@Old-Trafford:~$ cd ~</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>jmorehouse@Old-Trafford:~$ ssh -i ~/.ssh/&lt;filename&gt;.pem ubuntu@IPAddress </code><span style="color: #3366ff;">(Key created in Step 2 and IP address from Step 7.)</span></div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><strong>EC2 Instance</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~$ cd .ssh/</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~/.ssh/$ cat &gt;&gt; authorized_keys id_ec2.pub</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~/.ssh/$ chmod 640 authorized_keys</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>ubuntu@ec2:~/.ssh/$ exit</code></div>
<p>&nbsp;</p>
<div id="_mcePaste">26. Now we need OSX to prompt us for the passphrase for the id_ec2 key, so from Terminal, enter the following:</div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;"><strong>Your Mac</strong></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>jmorehouse@Old-Trafford:~$ cd ~</code></div>
<div id="_mcePaste" style="padding-left: 30px;"><code>jmorehouse@Old-Trafford:~$ ssh -i .ssh/id_ec2 ubuntu@IP</code></div>
<p>&nbsp;</p>
<div id="_mcePaste" style="padding-left: 30px;">You should be prompted for a password. Check the save the password to your Key Chain and hit ok. You should now have an SSH session to your EC2 box using your new key. You can go ahead and exit from your SSH session and close out all of your Terminal sessions and quit the Terminal application.</div>
<p>&nbsp;</p>
<div id="_mcePaste">27. Now fire up SideStep and click the &#8216;Next&#8217; button. Under &#8216;I already have one&#8217; enter &#8216;ubuntu&#8217; as the Username, your IP address from Step 7 as the hostname, and press &#8216;Test Connection to Server.&#8217; You should receive a &#8216;Connection to server succeeded!&#8217; message. Now click the &#8216;Next&#8217; button. Read the notes and check the box that reads &#8216;Run SideStep on login.&#8217; Click &#8216;Finish.&#8217;</div>
<p>&nbsp;</p>
<div id="_mcePaste">28. SideStep is now on the menu bar next to Tunnelblick. I added Tunnelblick to my login items so that it is launched when I boot. Understand the differences between these two tools (Tunnelblick and SideStep) and when to use each.</div>
<p>&nbsp;</p>
<div id="_mcePaste">Congratulations! If you made it this far, pat yourself on the back. This was a long tutorial, but it should work if you followed each step. If you have any problems, hit me up on Twitter (<a title="@Mascasa" href="http://twitter.com/#!/mascasa" target="_blank">@Mascasa</a>).</div>
<p>&nbsp;</p>
<div id="_mcePaste">Enjoy surfing open wireless networks or hostile wired network securely!</div>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stratumsecurity.com/blog/2010/12/03/shearing-firesheep-with-the-cloud/feed/</wfw:commentRss>
		<slash:comments>134</slash:comments>
		</item>
	</channel>
</rss>

