Friday, May 1, 2020

IETF Tool

IETF Tools

IETF Tools

IETF-related tools, standalone or hosted on tools.ietf.org.
(Tools hosted by the secretariat are listed at http://www.ietf.org/tools).

Which license? See Preferred License

author Prepare documents
RFC dependency checker
Joe Touch
A script to check the references in Internet Drafts for dependencies and updates.
Bibtex Citation Converter
Yaron Sheffer
This tools converts bibtex-formatted citations into the bibxml format used in xml2rfc. Many (if not most) academic papers have bibtex citations available online, and the tool makes it easier to reference them in Internet Drafts.
Draft HTML and PDF from XML source
Julian Reschke
A set of XSLT transformations that can be used to transform RFC2629-compliant XML (see RFC 2629) to various output formats, such as HTML and PDF
Templates for xml2rfc work
Elwyn Davies
Elwyn Davies has produced a template as a starting point for writing drafts using xml2rfc. You can find a copy of the schema v3 version of the XML template at tools.ietf.org.
Draft Submission API
Henrik Levkowetz
A simplified draft submission interface, intended for automation, is available at https://datatracker.ietf.org/api/submit".
The interface accepts only xml uploads which can be processed on the server, and requires the user to have a datatracker account. A successful submit still requires the same email confirmation roundtrip as submissions done through the regular submission tool.

BibXML to Markdown Converter
Yaron Sheffer
This simple script, bibxml2md, converts bibxml references extracted from xml2rfc files into markdown, for use in kramdown-rfc2629 Internet Drafts.
License File for Open Source Repositories
IESG
Many working groups work with open source repositories, even for their work on specifications. The IESG has made a boilerplate text available for inclusion in repositories, available at the URL above.
Write RFCs using wiki-style markup ('markdown')
Miek Gieben
Pandoc2rfc (see RFC 7328) uses Markdown in combination with Make and XSLT scripting to produce internet-drafts in XML format from plain text input. The plain text only needs a few formatting conventions, more or less like wiki markup. See also these OSX installation tips.
Draft Submission
Henrik Levkowetz
The New Internet Draft Submission Tool replaces the older Draft Submission Tool and the even older email submission workflow, and lets an author submit a new or updated draft through a webpage, and have it appear in the archives immediately.
Writing Internet-Drafts using Microsoft Word
Joe Touch
Use Microsoft Word or .doc-compatible editors to edit Internet Drafts. Word is a WYSIWYG editor that runs on Windows and Mac OSes, with an open-source variant (OpenOffice) that runs on Linux. This method is documented in RFC 5385 based on a template , using a post-processing Perl script.
Convert nroff for drafts and RFCs to RFC2629 format XML
This is a first release of nroff2xml. The tool is able to get nroff source and generate xml based on it. The output XML has well formed sections, paragraphs, and external references. The output can be successfully processed with xml2rfc. The author is not going to develop this further, as it's served its initial purpose in converting the .nroff source for RFC3315 to xml; other people are however very welcome to pick this up and refine it.
A configuration for editing xml2rfc-format documents in XXE
Bill Fenner , Warren Kumari

This is a WYSIKN (What You See Is Kinda Neat) addon for the very configurable XMLMind XML Editor ("xxe"). The personal version of xxe is free and very capable.

The addon is capable of graphical editing of sections, anchors, lists, cross-references, etc. and allows word processor-like behavior of "enter" to create a new paragraph or list item. More info in the README.


Draft TXT and HTML from XML source (xml2rfc)
Henrik Levkowetz

xml2rfc will allow you to take your XML source (using the format defined in RFC 2629 and its unofficial successor) and generate well-formatted text and html versions of drafts from it.

Version 2 of xml2rfc is a complete rewrite in Python. It is available for installation from the Python Package Index (PyPi): https://pypi.python.org/pypi/xml2rfc/
There's a tutorial available on how to install from PyPi, or if you're impatient you can try the following commands on the command line:
  pip install xml2rfc
if that fails:
  easy_install pip
  pip install xml2rfc
if that fails, go to the tutorial above.


Edit IDs in .nroff with wysiwyg display
Stefan Santesson
NroffEdit is a Java application for writing and editing Internet Draft files using the nroff format. This application lets you load any I-D nroff file, which will be shown processed in the right-hand window, and can be edited in the left-hand window.
Write Internet-Drafts using the LyX Editor.
Nico Williams , Yaron Sheffer
Use lyx2rfc togeter with LyX to edit Internet-Drafts. LyX is an open source WYSIWYM GUI editor that runs on all major operating systems. Currently lyx2rfc outputs XML, text, and HTML, but only runs on Linux.
Write RFCs using asciidoc markup
Ronald Tse
Asciidoctor-rfc is a tool that allows writing Internet-Drafts using AsciiDoc as an alternative to Kramdown / MMark or manual RFC XML. AsciiDoc is a widely-adopted textual format. Similar to Markdown, it is simple to write and easy to understand, but its major benefit is for being a structured format that directly converts into DocBook XML.
Fix document spacing.
Henrik Levkowetz
Fix up the spacing between sentences to use two spaces. (This is a small script written in awk).
Check internet-drafts for submission nits
Henrik Levkowetz
Use idnits to check that your draft has the desired formatting, boilerplate, references consistency and more.
Run a spelling-check on your internet-draft
Henrik Levkowetz
Idspell uses an IETF-specific wordlist built from the last 2 years' published RFCs, surnames of recent I-D authors and some manually added words.
Draft HTML and PDF from XML source
Julian Reschke
A set of XSLT transformations that can be used to transform RFC2629-compliant XML (see RFC 2629) to various output formats, such as HTML and PDF. For more information, see the documentation.
Draft Diff Tool
Henrik Levkowetz
When looking at updated drafts, you want a diff with the previous draft which ignores changing page layout and moved page headers and footers. Online version is at http://tools.ietf.org/rfcdiff and source at http://tools.ietf.org/tools/rfcdiff/rfcdiff
Add bcp14 markup to XML draft source
Joe Touch

Run this script in order to add <bcp14> elements around BCP 14 key words (MUST, SHOULD, etc.) in the XML source for an Internet-Draft.

Usage: simple-bcp-fix.pl file1.xml > file2.xml

Known defect: there may be stray elements in comments, sourcecode, and artwork.


Templates for MIB Documents
David B. Harrington
The MIB Doctors have produced three templates specifically aimed at drafts containing MIB modules:
• The first is an XML template for editors that use XML2RFC. Some advice echoing guidelines from RFC4181 is embedded in comments.
• A second template is a text template for MIB documents with advice embedded in the document.
• A third template is a plain text template with no advice included.

Validate XML input for XML2RFC
Bill Fenner
Performs many checks on an XML input document, verifying both XML welformedness and many other issues specific to document processing through xml2rfc. Alternative URL: https://tools.ietf.org/tools/xml2rfc-valid
old author tools page ...

meeting Follow an IETF meeting
Download Agenda draft tarballs
Henrik Levkowetz
On the IETF meeting agenda provided on https://tools.ietf.org/agenda, there are links provided to tarballs of all drafts mentioned on each WG agenda. If a tarball exists, there is an archive symbol between the WG acronym and the WG name.
IETF Meeting App for iPhone
Tom Pusateri
A Conference App for the iPhone, letting you track meeting slot times, agendas, rooms and their location.
Download WG drafts
Eric Rescorla
Download and optionally print WG drafts for a specific IETF meeting, as listed in the meeting agenda for the WG(s).
stats Statistics - Overview and Trivia
Document Statistics
Jari Arkko
Which companies are the most active contributors? How has the situation changed over the years? Who has published most RFCs? What percentage of drafts use ABNF or PDF? And more ...
chair Manage Working Groups and Documents
Template for Chairs' Document Writeup
IESG
This is the current version of the document shepherd writeup template introduced by RFC 4858.
admin Server admin tools
Update
Henrik Levkowetz
Copy over a new version of a file only if there are changes.
display Search, show and print documents
Download the latest documents
Rsync access to various document archives:
• Unpurged IETF drafts repository:
To list the content, do:
  rsync rsync.tools.ietf.org::tools.id
To sync the content, do:
  rsync -avz rsync.tools.ietf.org::tools.id ./id
• Currently available htmlized drafts and RFCs:
To list the content, do:
  rsync rsync.tools.ietf.org::tools.html
To sync the content, do:
  rsync -avz rsync.tools.ietf.org::tools.html ./html
• For a full list of the various rsync sources at tools.ietf.org, do:
 rsync rsync.tools.ietf.org::

Access IETF-related files from the command line
Paul Hoffman
The "ietf" program lets you access IETF-related files from the command line. It creates a local copy of these files on your computer using rsync, and gives a friendly way to access them. You can give commands from your normal shell, or you can run an interactive shell that is part of the program.
Chrome: Rewrite IETF ID URLs to the Tools or Datatracker versions
Warren Kumari
This will rewrite the "official" IETF Internet Draft URLs (https://www.ietf.org/id/foo-42.txt) to the Tools (https://tools.ietf.org/html/foo-42) or Datatracker (https://datatracker.ietf.org/docs/foo) versions instead.
Retrieve IETF Documents from the search bar
Sean Leonard
This adds an IETF document retrieval search provider to the Firefox (v2+) or IE (v7+)
Print an Internet Draft (ID) or RFC as PDF.
Warren Kumari
Because of the difference between the number of lines on laser printers and line / dot-matrix printers, each "page" of the draft actually takes up 2 pages and you end up with lots of pages with just a one line footer. This script tries to fix that by downloading the draft, converting it to a PDF and then printing it.
Downloading RFCs & I-Ds eBooks
Tero Kivinen
There is weekly generated ebooks in .epub and .mobi (kindle) format for RFCs and Internet-Drafts. The rfc.mobi and rfc.epub files contains all RFCs in one big file. For I-Ds there is files for each separate working group (i-d.*) and one file per area containing all WGs in the area (area.*). In addition to the active WG drafts those files also contain the published RFCs and related I-Ds.
PDF Conversions of drafts and RFCs
Henrik Levkowetz
This repository provides PDF conversions of drafts and RFCs, which can be very helpful in order to print these documents.
Internet-drafts archive.
Henrik Levkowetz
Find old and current drafts by full or partial name. If a complete draft name without version indication is used, the latest revision of the draft is provided.
Browse and search IETF documents
Henrik Levkowetz
RFCs and drafts with hyperlink markup for easier reading and browsing, with a Google search interface.
Rfcindex
Simon Leinen
A script which creates a compact HTML index to the RFCs.
Rfcmarkup
Henrik Levkowetz
Add HTML markup to a plain text draft or RFC
more display tools ...

share Share and communicate
Public IMAP Access to List Archives
Alexey Melnikov
An IMAP server with all IETF email list archives is available for IMAP access at imap.ietf.org:993.

For authenticated access, use your datatracker login and password.

For anonymous access, use username="anonymous", and provide your email address as a password.

BOF Wiki
A Wiki which lists all intended BOFs, per IETF meeting
Comprehensive Mailing List Search
Lars Eggert
Searches the mailing list archives of the working groups of the Internet Engineering Task Force (IETF) and the research groups of the Internet Research Task Force (IRTF), as well as several related lists.
WG Chairs' Wiki
WG Chairs' Guide - Everything a WG Chair Needs to Know but Was Afraid to Ask
WG Issue Trackers
Henrik Levkowetz
All IETF Working Groups have issue trackers set up to facilitate tracking of document issues. The wiki for each WG is at https://trac.ietf.org/trac/<ACRONYM>, and you can see tickets at https://trac.ietf.org/trac/<ACRONYM>/report/1. The issue tracker is automatically updated with ticket (issue) component names matching the WG drafts. New tickets can be added (login with your datatracker login is needed) at https://trac.ietf.org/trac/<ACRONYM>/newticket. The WG page in the datatracker has link to the group wiki and issue tracker under the 'About' tab.
IESG Wiki
IESG Guide - Everything an AD Needs to Know
WG Subversion Repositories
Henrik Levkowetz
Some IETF Working Groups have subversion repositories set up, to facilitate cooperative editing and change tracking. To find the repository of a WG, please go to the WG status page and follow the link which says 'Svn' in the top horizontal menubar. If there is no such link, the WG doesn't have a registered issue tracker. In order to check out a document from the repository, find the svn url to it, then use:
 svn co <document-url>

Email aliases to draft authors and chairs
Henrik Levkowetz
ietf.org provides email aliases to WG chairs and draft authors, to make it easier to reach them without having the individual addresses available. To reach the authors of a draft, send an email to:
 <DRAFTNAME>@ietf.org
[See the complete draft alias file]

In a similar manner, to reach a WG's Chairs or ADs, send an email to:
 <WG>-chairs@ietf.org or
 <WG>-ads@ietf.org, respecitvely.
On each WG page in the datatracker, there's a tab that shows the list of aliases for that WG; see for example the complete DHC WG alias list]


validation Verify compliance
Fetch, extract and validate YANG models
Fetch, extract and validate YANG modules by RFC number, by IETF draft name, or by uploading IETF drafts or YANG files.
BNF Parser²
Václav Vacek
BNF Parser² is an online syntax verification utility. It is capable of checking whether a string conforms to a syntax specification written in a Backus-Naur Form (BNF) dialect.
Generate ABNF Parsers (with extensions)
Munjo Yu
Generates complete c language code for decoding/encoding messages from an ABNF definition file with extension rules. Examples and automated test suite are provided for a quick start.
YANG data model catalog
YANG module search, validation, dependencies visualization, and API generation.
Bap
Bill Fenner
An ABNF parser, focusing on human-friendly error messages.
Validate the signature for an Internet-Draft
Russ Housley
RFC 5485 specifies a mechanism to provide a cryptographic signature for valid internet drafts. The Cryptographic Message Syntax (CMS) is used to create a detached signature, which is stored in a separate companion file so that no existing utilities are impacted by the addition of the digital signature. This scripts provides a way to verify these signatures.
Msglint
Chris Newman
Check Email Headers for RFC Compliance
more validation tools ...

extract Extract info from documents
Extract code from RFCs and drafts
Martin Bjorklund
Extracts code components, YANG modules and SMIv2 modules from RFCs and Internet Drafts
Sean's SUPER Regular Expression-Based ABNF Extractor
Sean Leonard
This Regular Expression-Based ABNF Extractor will read the given input and output the ABNF that is found therein. The ABNF must conform to RFC 2234, RFC 4234, or RFC 5234 (as amended, e.g., by RFC 7405).

The program accepts XML (xml2rfc v2 and v3) and plain text (traditional RFC format ca. 2016) input formats. Optionally, the program can emit location (line number, page, anchor) and caption information in ABNF comments.


Extract ABNF from a document
Bill Fenner
Shows the ABNF contained in a draft or RFC, as extracted by 'aex' from Bill Fenner's 'bap' toolsuite (https://github.com/fenner/bap)
support Get support
IETF Database
The IETF Database holds information related to documents, authors, positions and messages within the IETF.
Set up or update tools server login and password
Henrik Levkowetz
loginmgr provides scripts used to generate and verify keyed-hash URLs in order to confirm that email addresses are reachable and owned by the person requesting a password, and also a web frontend and a backend to set the password in an apache digest file.
Nomcomsel
Suresh Krishnan
Do nomcom selection from volunteers according to RFC 3797
news Stay updated
Get your daily dose of IETF news
Pasi Eronen
A summary of the progress and events of the last 24 hours in all parts of the IETF world.
review Review documents
Idcomments
Henrik Levkowetz



/ed70

Saturday, April 11, 2020

Construction Workers Embrace the Robots That Do Their Jobs | WIRED

Construction Workers Embrace the Robots That Do Their Jobs | WIRED

Construction Workers Embrace the Robots That Do Their Jobs

A robotic excavator can dig a pipeline trench without a human in the cab. An engineers' union is partnering with the company that makes the tech.

A man looking up at an excavator
Startup Built modifies excavators and bulldozers into autonomous robots that can perform some work, like digging trenches, with an empty cab.Courtesy of Built Robotics

The International Union of Operating Engineers has plenty of big toys at its training center in Crosby, Texas, but one that began rolling across the 265-acre campus last week is an oddity. The modified Caterpillar 336 excavator can use onboard computers and sensors to perform by itself some of the work the center trains human operators to do, such as digging trenches for gas pipelines or wind turbine foundations.

The IUOE's new robotic excavator is the result of an unusual partnership with Built Robotics, a San Francisco startup that sells a box that can enable a backhoe or bulldozer to pilot itself for some tasks. It contains a high-powered computer, motion and angle sensors, and a laser scanner called a lidar commonly used in self-driving cars.

Although Built's product is designed to remove workers from the cab of construction equipment, IUOE's director of construction training, Chris Treml, says the union wants to train its members to work with the technology. "Operating engineers are always on the cutting edge of technology," he says.

People at a computer screen

After construction workers describe an excavation using GPS coordinates, the vehicle can drive itself across a site to its starting point and go to work.

Courtesy of Built Robotics

The IUOE was founded in 1896 and its logo features a steam gauge with the needle at 420 pounds per square inch, the operating pressure of some steam engines. Its training center teaches members to use remotely operated robotic equipment such as drones and mini-cranes, as well as fine-grade GPS equipment to guide construction vehicles to grade dirt at precise angles.

Treml says members now need to get familiar with autonomous construction equipment, because it too is set to become a standard part of the industry. "The last thing I want to see is people losing their jobs," he says. "But this is something that's out there and it's going to be part of our industry, and so we want to be a part of it." Built plans to help IUOE expand its fleet of autonomous vehicles over the coming year.

An autonomous excavator digging a pile of dirt

While a vehicle is in autonomous mode, a single worker needs to stay on hand in case of problems.

Courtesy of Built Robotics

Another reason for construction workers to be collegial toward robots is that there's plenty of work to go around amid an industry-wide shortage of workers. The nonprofit National Center for Construction Education and Research says heavy equipment operators are among the most sought after. Many current operators are close to retirement age, and the Bureau of Labor Statistics estimates that such jobs will grow 10 percent between 2018 and 2028, twice the rate for all occupations.

Other unions have not welcomed automation. In 2017 the Teamsters helped convince the Senate to exclude autonomous trucks from draft legislation on self-driving vehicles. That was a setback for companies working on the technology, such as Alphabet, because a regulatory vacuum would delay commercial deployment. The legislation ultimately foundered; a new draft, yet to be introduced, also excludes large trucks.

Keep Reading

The latest on artificial intelligence, from machine learning to computer vision and more

Vehicles with Built's equipment don't need regulatory approval if they work off public roads. They're already at work in the US, primarily on energy projects, digging foundations for wind turbines or oil and gas pipeline trenches.

After workers specify the GPS coordinates of the ends of a pipeline trench, they can leave the rest to the excavator, which will drive itself to the starting point and dig thousands of feet in a day. One worker—not necessarily an excavation specialist—needs to stay on hand in case of problems.

Built's CEO and founder Noah Ready-Campbell said unions were wary when his company's tech first appeared at construction sites. "We got a lot of questions early on about whether these robots are here to steal jobs," he says. "The answer is no. The computers are not smart enough, but they can free up operators to do the more challenging and valuable work," such as more complex excavations. Suspicions typically evaporate fast once workers see how the technology can help make sites more efficient, he says.

Treml of IUOE says although the technology is improving, it can help only with certain tasks, not the most valuable and complex work and planning. "You still need to have that human touch," he says.


More Great WIRED Stories

 Shout out to Malcolm and Robotic Demolitions 🚧

/ed70

Sunday, March 8, 2020

REPOST: hbgary wanted to suppress stuxnet research |

REPOST: hbgary wanted to suppress stuxnet research |

REPOST: hbgary wanted to suppress stuxnet research

This is a repost for historical purposes as the original site is gone.

Cheryl D Peace was at the time an employee at the NSA.

https://web.archive.org/web/20120227170532/http://crowdleaks.org/hbgary-wanted-to-suppress-stuxnet-research/

It is no secret that in recent days, Anonymous Operatives have released a cache of HBGary Federal internal emails to the public. Crowdleaks has discovered that within these communications, Aaron Barr received a copy of Stuxnet (a computer worm that targets the types of industrial control systems (ICS) that are commonly used in infrastructure supporting facilities) from McAfee on July 28, 2010.

HBGary wanted to suppress Stuxnet research

In an effort to confirm this was in fact Stuxnet, Crowdleaks has decompiled some of the source code, which can be found here.

Throughout the following emails it is revealed that HBGary Federal may have been planning to use Stuxnet for their own purposes.

Throughout the following emails it is revealed that HBGary Federal may have been planning to useStuxnet for their own purposes.

In a message sent to all email account holders at HBGary.com, Charles Copeland (Lead Support Engineer at HBGary, Inc.) writes:

from: Charles Copeland
to: all@hbgary.com
date: Sat, Sep 25, 2010 at 9:54 PM
subject: Stuxnet Worm Mailing List
Filter messages from this mailing list. mailed-byhbgary.com
hide details 9/25/10
Computerworld – Officials in Iran have confirmed that the Stuxnet worm infected at least
30,000 Windows PCs in the country, multiple Iranian news services reported on Saturday.

http://www.computerworld.com/s/article/9188018/Iran_confirms_massive_Stuxnet_infection_of_industrial_systems

I've already got a email asking about stuxnet, this came out late Friday. Does anyone have a dropper I have been unable to find it.

In another email sent directly to Aaron Barr, David D. Merritt writes:

from: David D. Merritt
to: Aaron Barr
date: Sun, Oct 3, 2010 at 9:35 PM
subject: Re: Hunter Killer Insanity 285mailed-bygmail.com
hide details 10/3/10
contacts over at TSA say that everybody has a copy…combine that with US CERTs vulnerability status and their own systems not meeting the spec….
i'm seeing TSA becoming a malware testbed…

Aaron Barr responds:

On Oct 3, 2010, at 10:13 PM, Aaron Barr wrote:
> Dave,
>
> We haven't but I would be interested to talk to you some about the tie. I do have a decent amount of information on Stuxnet and would be interested to hear about the tie. Some of what I know about Stuxnet might be of interest. I think it would be best to discuss in a more closed space though.
>
> In doing a little research:
> http://diocyde.wordpress.com/2010/03/12/ringy-ringy-beacon-callbacks-why-dont-you-just-tell-them-their-pwned/
>
> While this guy can be a bit of a crackpot at times his post has more validity than fiction. Greg and I have brainstormed a bit in the past on how to conduct such an attack that would be very difficult to detect. Autonomous, single purpose malware with no C&C. As we have said the battle is on the edges either source of destination, everything else is or will become somewhat irrelevant or diminished in value.
>
> Aaron Barr
> CEO
> HBGary Federal, LLC
> 719.510.8478

In another message sent to all email account holders at HBGary.com by
Greg Hoglund,
 it's made clear that HBGary wanted to hide their work onStuxnet.

from: Greg Hoglund
to: all@hbgary.com
date: Sun, Sep 26, 2010 at 10:26 PM
subject: stuxnet mailing list
Filter messages from this mailing listmailed-byhbgary.com
hide details 9/26/10
All,
HBGary has no official position on Stuxnet. Please do not comment to the press on Stuxnet. We know nothing about Stuxnet.
-Greg Hoglund
CEO, HBGary, Inc.

In the most chilling strand of emails, we find that whatever HBGary was working on, it was in conjunction with the NSA.

Aaron Barr writes:

Hi Cheryl,
719.510.8478
Aaron
Sent from my iPad

Aaron Barr writes:

> From: Aaron Barr
> To: Peace, Cheryl D
> Sent: Mon Aug 09 13:54:23 2010
> Subject: Re: Number
>
> Hi Cheryl,
>
> It does. I haven't met him personally. Our sister company does work
> in a few different pockets on the bldg. And i am on the extended NANA
> team. I recently joined to stand up HBGary federal, a related but
> separate company. We manage all the work that requires clearances.
> We exchange some technologies, but we have some separate developments
> as well. Mostly around threat intelligence and CNO/social media.
>
> I think there are some enabling tech to your mission but really need
> that qualified.
>
> Interested to run some of the stuxnet stuff by u as well.
>
> Aaron
>
>
> Sent from my iPhone

Cheryl Peace writes:

On Aug 9, 2010, at 9:27 AM, "Peace, Cheryl D" wrote:
>
>> Aaron
>> Did a little checking and we already do busy with you guys. Does the name
>> Tony Seager ring a bell?

Aaron Barr writes:

>> —–Original Message—–
>> From: Aaron Barr [mailto:aaron@hbgary.com]
>> Sent: Friday, August 06, 2010 10:56 AM
>> To: Peace, Cheryl D
>> Subject: Re: Number
>>
>> OK. If interested do you have some time to get together when you get back?
>> either next Friday or early the following week?
>> Aaron

Cheryl Peace writes:

>> On Aug 6, 2010, at 10:44 AM, Peace, Cheryl D wrote:
>>
>>> I am in Europe till mid next week

Aaron Barr writes:

>>> —–Original Message—–
>>> From: Aaron Barr [mailto:aaron@hbgary.com]
>>> Sent: Thursday, August 05, 2010 10:57 PM
>>> To: Peace, Cheryl D
>>> Subject: Re: Number
>>>
>>> Hi Cheryl,
>>>
>>> Can I schedule an appointment with you to come by and chat for a few
>>> minutes?
>>>
>>> Aaron

Cheryl Peace writes:

>>> On Jul 30, 2010, at 10:41 PM, Peace, Cheryl D wrote:
>>>
>>>> I am at Rao at the bar if you want to come by for a few. Meeting friends
>>> for a cocktail in a few
>>>> ————————–
>>>> Sent using BlackBerry

Arron Barr writes:

>>>> —– Original Message —–
>>>> From: Aaron Barr
>>>> To: Peace, Cheryl D
>>>> Sent: Fri Jul 30 20:02:44 2010
>>>> Subject: Number
>>>>
>>>> Cheryl,
>>>>
>>>> Sorry to bother you but do you have a minute to talk. I don't have
>>>> your number handy. It will only take moment, but I have some
>>>> information for you.
>>>>
>>>> Aaron Barr
>>>> CEO
>>>> HBGary Federal
>>>> 7195108478

In a related internal email sent to Rich Cummings (CTO of HBGary, Inc.)Greg Hoglund writes:

from: Greg Hoglund
to: Rich Cummings
date: Mon, Nov 16, 2009 at 9:30 PM
subject: Govt dropper in this word DOC, zipped up for youmailed-byhbgary.com
hide details 11/16/09

Phil, Rich,

I got this word doc linked off a dangler site for Al Qaeda peeps. I think it has a US govvy payload buried inside. Would be neat to REcon it and see what it's about. DONT open it unless in a VM obviously. password is meatflower. Remove the .txt extension too. DONT let it FONE HOME unless you want black suits landing on your front acre. 🙂

-Greg

Crowdleaks.org had a software engineer (whose name has been withheld) look at the Stuxnet binaries inside of a debugger and offer some insight on the worm. She informed us that most of the worms' sources were using code similar to what is already publically available. She noted that the only remarkable thing about it was the 4 windows 0 days and the stolen certificates.

She says:

"A hacker did not write this, it appears to be something that would be produced by a team using a process, all of the components were created using code similar to what is already publically available. That is to say it's 'unremarkable'. This was created by a software development team and while the coders were professional level I am really not impressed with the end product, it looks like a picture a child painted with finger paints."

When asked what type of organization likely wrote it, she stated:

"Probably a corporation by request of a government, it was clearly tested and put together by pro's. It really looks like outsourced work."  – See more at: http://webcache.googleusercontent.com/search?q=cache:ld1YZvZkTFUJ:thehackernews.com/2011/02/exposed-hbgary-wanted-to-suppress.html+&cd=1&hl=en&ct=clnk&gl=us#sthash.39BcBvxo.dpuf



Elyssa Durant