4/18/2008

Addendum to :"Letter to the community"

After my recent post on this blog about the ethical dilemma that pushed me to think if I should stay or leave WSL, followed by the motivations about my decision to continue to support the project, the international press has republished excerpts of my words in the articles that followed.
Those excerpts have been in most cases interpreted correctly, I am referring to that part in my post in which I tried to describe the outlines of the big case that brought me troubles.
Specifically, with the words:

"The case for which I was arrested it's actually a huge case and believe me, no single news agency was able to picture it completely right. Probably, nobody will ever be able to picture it completely right as it's a case involving a hundred of arrested people, the Italian Secret Services, the US Secret Services, some Italian corrupted police and financial police officers, some Italian and US investigation companies, a multi-billionaire struggle between Telecom Italia and Brasil Telecom, an extraordinary rendition (kidnapping) of a presumed Islamic terrorist, and last but not least, the suicide (but many say murder) of a Telecom Italia Security top manager. Aside this, the various attempts of the Italian government to take over the control of the Italian main telecommunication carrier."

I didn't report facts known to me personally, but a short recap of the case as it was reported by the Italian press. In fact, my personal case is loosely connected to the whole, big Telecom Italia case that appeared, for nearly two years on Italian newspapers, as a case which borders are not easily identifiable.

In one specific case though, an Italian columnist of the "Il Sole 24 Ore" newspaper has interpreted my words, in the typical way of the Italian scandalistic journalism, raising suspects on the possibility that I could be the guardian of who-knows-what secrets related to the case.

No, I am not the guardian of any secret. If a was, I would have not written those words. I just reported what the Italian newspapers wrote, following the Italian investigators' findings. Within my drawers there are no secrets, on the contrary, I wish I'll be able to forget this case, which greatly damaged my personal life and professional career.

4/10/2008

Roberto Preatoni - Letter to the community

One year has already passed, since the moment the WSL crew started to work on the marketplace project, as it went public on July '07, but a lot of preparation work has been done since several months before.
As you well know, the marketplace gained immediately a quite impressive press coverage, splitting (as we were expecting) the security world in two: those who praised the project and those who hated it.

Generally speaking, whenever you succeed to split the world in two, it's a sign you are doing the right thing. Absolute positiveness it's usually an indication that a sort of monopoly or dictatorship is ruling the game, brainwashing the thinkers.
I already know, even this post will split the world in two.
Honestly, WSL was expecting even more criticism, at least in the beginning, thus we can't deny we are quite satisfied by what the project achieved in the last months.

But eventually WSL had a problem.
Sorry, I had a problem.

The news of my arrest broke through the press titles causing havoc among WSL and the people who started to put some trust in it.
Right, trust. That's the word without which, no project such ours could ever take off.

The case for which I was arrested it's actually a huge case and believe me, no single news agency was able to picture it completely right. Probably, nobody will ever be able to picture it completely right as it's a case involving a hundred of arrested people, the Italian Secret Services, the US Secret Services, some Italian corrupted police and financial police officers, some Italian and US investigation companies, a multi-billionaire struggle between Telecom Italia and Brasil Telecom, an extraordinary rendition (kidnapping) of a presumed Islamic terrorist, and last but not least, the suicide (but many say murder) of a Telecom Italia Security top manager. Aside this, the various attempts of the Italian government to take over the control of the Italian main telecommunication carrier.

Well, right after my arrest, I clarified my position and the Court of Freedom ruled for my release a few days after. Of course, no press coverage in this case but hey, that's the way it works. At least, next time I'll meet Kevin Mitnick at TJI Friday's I'll have something to say and not only to ask.

But the damage to WSL was done and there was nothing I could do to repair the cracks. The questions I kept asking myself in the last months were: What will happen to WSL if I will stay? Will my private life and troubles effect negatively the project? Should I keep representing publicly the project?
Several people, including security researchers mailed me addressing the same questions (thanks, Jesper) forcing me finally to take a decision.

I will stay.
I will stay and continue to put pressure to security lobbies. Things must change, researchers and their discoveries should be considered beneficial to the whole security cycle.

I'll represent WSL once again, in the next planned security conference (6-7-8 May 2008, Johannesburg - South Africa). I'll be there, you are welcome to come and kick in harsh questions related to the project, I'll try to do my best to answer to you.

One more thing. We worked hard on a partnership that we will announce soon. It'll be a surprise and it'll effect positively the marklet-place and the cash the researchers might be able to get.

Yours faithfully,

Roberto Preatoni

12/19/2007

Focus On: MySQL remote code execution

Christmas is coming and Santa brought us a new interesting vulnerability about another database system: today it's the turn of one of the most spread and used RDBMS, MySQL.

MySQL 5 is in fact prone to a remote command execution vulnerability.

This vulnerability has been tested on Linux, with MySQL versions 5.0.45 and 5.0.51, the latest one.

This is a pre-authentication vulnerability so you won't even need a valid username and password but a GRANT from your IP on the database, to let the connection start.

Like all the database softwares, you won't find so many MySQL's exposed on the internet, while it can be very common in a Local Area Network.

Also, MySQL is often used in web application development, so most (all?) of the web hosting providers sell access to the MySQL server together with the web space.

By exploiting this vulnerability you will be able to access the content of all the databases present on the DBMS without needing a local privilege escalation since the files on the filesystem containing the database data are owned by the same user running MySQL.

If you buy this vulnerability you will receive a fully working PoC and all the technical details.

Of course, for further information don't hesitate to contact us via e-mail, and if you want to make a bid on the vulnerability, do it here.