SF Health Inspectors Charged with Fraud

Two San Francisco health inspectors have been charged with taking payments to falsify results.

Both Sanders and Stewart are former employees of the city Public Health Department. Each took hundreds of bribes of $100 to $200 apiece from restaurant managers and owners in 2007 and 2008 in exchange for allowing them to pass their food safety manager exams, District Attorney George Gascón said.

[…]

Gascón said the managers and owners who allegedly bribed Stewart and Sanders would not be prosecuted because many of them thought the payments were legitimate fees. For many of the managers and owners, English was their second language, the district attorney said.

“We believe that the greater culpability goes to the public employees,” Gascón said.

That policy, of course, encourages the managers and owners to turn in corrupt inspectors.

Metasploit update and DNS fuzz challenge

Two new challenges are mentioned in today’s update to the Metasploit framework. One is based on the fuzz module for DNS

Metasploit contributor pello brings us a new auxiliary module, dns_fuzzer.rb. As part of testing, I threw this module against three different DNS resolvers to just watch the traffic, and promptly crashed one of targets. Clearly, grown-up DNS servers shouldn’t fall over in the face of malformed traffic delivered at regular Internet speeds, so if you’re feeling like hunting for remote 0-day for fame and fortune, you could do worse than starting with this module.

Whatevz. Fame and fortune from testing quality with a fuzzer is so 2000-and-late. Let’s see some destroy_foreign_cyberarmy.rb module action.

The other is to create and submit resource scripts

There’s exactly one rc script in there right now (thanks Mubix!), but if you have a resource script that you’d like to share, please feel free to submit it via a pull request to our GitHub repository — especially if your favorite resource script does something novel and interesting with modules, targets, or something we haven’t thought of yet.

SF Police Shootout, Larkin and Bush

San Francisco police pulled over a car this afternoon around 1:30 pm near the intersection of Larkin and Bush, as reported by local news stations KTVU and KRON.

The stories are not yet identical but essentially the driver left the car and started firing a gun at the police. Police returned fire. A passenger in the car escaped.

The KTVU witness account says officers fired a single shot.

Hamood Albadani, 52, who was visiting San Francisco from Michigan, said he witnessed the shooting while walking on Sutter Street.

He said that he was at the intersection of Sutter and Larkin streets when he saw a man fire five or six shots toward a parked car, but couldn’t see if he was shooting at anything in particular.

He said the shooter was in the street, and that a police officer approached him from the sidewalk and fired one shot to the man’s head, taking him down.

KRON says it was multiple shots.

Witnesses say the driver fired two shots at the officer who was not hit. The police officer returned fire hitting the fleeing man several times including at least once in the chest.

The man is now in hospital. The officers were not injured.