Veti-Gel Stops Bleeding Immediately

New York University student Joe Landolina has come out with an amazing product. It is called Veti-Gel. It stops bleeding immediately when applied. We are talking about 10 seconds or less here. You apply it to the wound. It holds its own pressure. You don't need to press down on it.

The gel uses plant polymers to get the job done. Joe calls this platform technology. It also helps to start the healing process. It allegedly can stop the bleeding from punctured organs. Orignally this was called Medi-Gel. That name matches the one from the Mass Effect video game.

This obviously has military applications. Joe is trying to get a grant from the Department of Defense. The Army already has a similar product calls QuickClot that it uses. Hospitals use another product that is similar.

Right now Joe is trying to get approval from the Food and Drug Administration. They will start doing tests on animals next. Joe has filed a patent for this breakthrough tech. Obviously this need to go through a lot of trials. Others call this in the early stages. But damn. This is exciting stuff if it is for real.

Software License


I needed some software for a class I am taking. Thought I could just download the free version. Nope. The company took that version off the market. Okay. Let's price the commercial version. It costs $1000. WTF? That does not even include documentation or install media. They do have a lite version for $500. Also a fail. That's about how much my whole college course for the semester costs. What's a starving student to do?

My initial instinct was to head to the Windows registry. I had signed up for a free 30 day trial. Maybe I could hack that somehow. It was not obvious how to do that. Then I searched around for some license codes on the net. They were easy to find, and surprisingly, they worked. If that had failed, I would maybe have to resort to running a keygen. I always fear it would also leave some malware on my system though.

I told my instructor about the fail. He said that as an instructor, he might be able to get 1 copy of the software for free. But he was going to keep that for himself. He did share some ideas on how to extend the trial. He thought we could just keep resetting the system clock on our PCs. Our he thought the key might be stored in a browser cookie. That seemed weird since this is not a web app.

There was one piece of good news to go the legit route. My instructor said the company does provide a 30% discount to students. So the lite version costing $500, with a 30% discount, would be $350. That is still way too much money for the piece of software I needed. Sure it was good software. But it did not do that much. As a last ditch legit effort, I could talk my company into buying me a copy of the software. They have big bucks in their budget. And I am learning this stuff for work.

Pwn2Own Happening Now

I just heard about the Pwn2Own competition going on in Vancouver right now. It is taking place at the CanSecWest conference. The conference specializes in digital security. Hewlett Packard and Google are backing the contest with some sweet prizes. Prizes for pwning the latest version of browsers top out at $100k. Bamm.

This is not a new competition. It has been held in previous years. But Pwn2Own had previously focused on browser vulnerabilities. Now the goal has been broadened to include browser plugins. You got to break the latest version of the browsers running on the latest operating systems. And they got all the current patches installed.

You cannot work for HP or Google to enter. And yeah you got to be 18 years old at a minimum. You must be registered for the CanSecWest conference to qualify. Bad news is that it costs $2200++ USD to get into the conference at this late date. I guess this only makes sense if you were already planning to attend the conf. Then again, the high cost of entry might minimize the competition.

One cool thing about the compeition is that you get drawn at random to attack the machine and browser. Then you go to work to hack an exploit. You got 30 minutes to break in. Then you got to hand over all your details to collect your prize. Of course HP will pass the info on so the holes can be plugged. This is a legit opportunity.

The Case of Aaron Swartz

Aaron Swartz was 26 when he hung himself last Friday. He was a co-author of the RSS 1.0 specification at the young age of 14. He was also a cofounder of Reddit, from where he was later fired. Aaron dropped out of Stanford. He created web.py, a Python web framework.

Swartz broke into a network closet at MIT. He placed a computer in the closet to run scripts to download articles from JSTOR, which is a journal storage system. Swartz had downloaded almost 5 million articles. JSTOR did not pursue a case against Swartz.

The Massachusetts attorney picked up the case against Swartz. The trial was to start in the spring. Swartz was pleading not guilty. He was charged with wire and computer fraud under the Computer Fraud and Abuse Act. If found guilty, he could have served up to 35 years in jail. He also may have been liable for $1M in fines.

Swartz initially had access to JSTOR at MIT. Then they detected his massive downloads. At first, his IP address was blocked. He changed his IP address. Then his MAC address was banned. He changed his MAC address. Finally he got another laptop, broke into a network closet at MIT, and jacked into the network to download the files.

McAfee Surveillance

Previously I had heard about John McAfee going on the run from Belize police. That sounded a bit odd. He was allegedly a person of interest in the murder of his neighbor in Belize. This caused McAfee to go into hiding, claiming that the police were trying to silence him.

Recently I read that McAfee launched a surveillance campaign against police and government officials in Belize. He said that he got a bunch of new laptops. Then he installed some keyloggers on all the PCs. Finally he distributed the laptops free of charge to people of importance in Belize.

McAfee also hired a team of people to monitor the rogue laptops. He then allegedly recorded all kinds of wrongdoing from the subjects of his espionage. Perhaps that is why the law is gunning after him in Belize. If that is true, he better hope that they don't extradite him back to Belize. He might not last long in that scenario.

I do love the premise that McAfee used to put the laptops in the hands of high ranking Belize officials. Part of the draw was that the cost was free. The other vector he used was to have some hotties deliver the PCs to the dudes in charge. Smart. Apparently it worked.

Elcomsoft Forensic Disk Decryptor

I recently read an article about a product called Forensic Disk Decryptor from Elcomsoft. This thing can access Bitlocker, PGP, and TrueCrypt volumes. It does this by grabbing the keys required to decrypt the data. There are three main ways the software can grab the key: from RAM, a hibernation file, or through a FireWire attack.

Note that you need to use some other third party tools for some of these attacks. For exampl, you need to use a separate tool to get a RAM memory dump for the program to scan. Also you need some extra software to mount a Firewire attack.

The fun part of this is that once you get the key, this software will mount the encrypted volume as a drive letter in unencrypted format. It will also not modify the encrypted volume it is cracking. This is access without a trail. The software looks like it costs a couple hundred bucks. There has been some discussion about this release. Most of the talk hinges around the fact that they are really just mining the keys. Once you have those keys, accessing the encrypted data is really not much of a hack.

Bureau of Prisons

Recently I went to the bookstore to do a little Christmas shopping. In the corner of the magazine section I spotted a stack of 2600 magazines. Ahh I remember reading those diligently in the past. They have such a good feel to them. I bought a copy and am half way through the thing. I need to actively pace myself so I don't read it cover to cover in one sitting.

So far the most interesting article was on the Federal Bureau of Prisons. The author describes the hoops inmates need to jump through to get computer access. They need to pay for it. Pay for the time. Pay for each page printed. You cannot email anyone directly in prison. You must go through a proxy where your correspondence is monitored and approved on an email by email basis.

Of course the author described some of the details of the systems used to provide net access to prisoners. LOL. Looks like he found a few holes to avoid payment and/or censoring. He had better be careful. I think he gets released soon. No need to further delay his release for something small such as hacking the printer.

This perspective helps me realize how lucky we have it. I often grumble about having to change the printer paper or toner. Or I need to occasionally reboot the wireless router to get back on the Internet. If you are in prison, you got to do a lot to be able to get even restricted access to the net.