Blog

  • Windows Password Recovery: ONTPRE

    Offline NT Password & Registry Editor (ONTP&RE)

    Did you lock yourself out of your Windows system?  Forgot your Windows password?  What is the best Windows password recovery?

    The best way is to have a Windows Recovery disc ready.  But this is something you must do BEFORE you get locked out.

    reset-password
    reset-password

    There are tools you can use to get into your system, but the first think you should try is to use “Administrator” as the user with no password.  “Administrator” is a default account on Windows systems.  On Windows 7 it is disabled by default but if someone has used the account you may be able to use it as backdoor into the system.

    If their is not Administrator account and no Windows Recovery disc you will have to use a Windows password recovery tool.  ONTP&RE is a password recovery tool that allows quick access to windows systems.

    Reset Password : Windows 7

    1.  Download ONTP&E: First, download the Windows password recovery software from pogostick.net . pogostick.net/~pnh/ntpasswd/cd110511.zip

    2.  Unzip ONTP&E:  Files are compressed into 1 folder named ( cd110511.zip).  Unzip the file.

    3.  Create CD with ISO:  Set the cd disc creator into ‘image to  disc’’. Burn the image to the cd.  Each CD burner software is different, so you will have to figure out how to create a CD from the ISO.  Sometimes its as easy as double clicking the ISO but it depends on the type of software.

    4.  Reboot & Insert:  Actually, you need to make sure your Windows system is able to boot from the CD.  Once its done , insert the cd back to the CD ROM  and reboot your computer.

    5.   Computer Boot from CD:  As your computer reboots, keep hitting F2 to go through the BIOS.  Select “Boot Options”.  Some versions of BIOS call this “Boot”.  But the idea is the same.  Go into the BIOS and make sure CDROM is on the top of the list for boot options.  This means that the computer first looks at the CD before going to the Hard Drive.  Instructions on modifying BIOS settings will be listed on the page.

    6.  Boot into ONTRE:  Once the BIOS boot option is set, save and exit.  Your system will boot into your ONTRE disc.  Software will start running. Just follow the steps.  “Press enter” to boot into the “Offline NT Password & Registry Editor” CD.

    windows password recovery
    screen shot of Offline NT Password & Registry Editor

    7.  Select an Account:  It will ask you to select an account.  If you hit “Enter” it will automatically boot into the [Administrator] account.

    *note: Anything in [brackets] is the default value, so if you hit “Enter” it will auto-magically choose that [bracket] value.. its a linux thing.. you wouldn’t understand.

    If you choose the “Administrator” account, you may need to Enable the account since the built-in Administrator account is  disabled by default in certain versions of Windows.

    8.  Enable Built-in Administrator Account:  The Windows account  needs to be enabled.  Select 4  and enter ‘to Unlock and enable user Account’.

    windows ontpre menu enable
    windows ontpre menu

    9.  Clear (blank) User Password:  After selecting 4-Unlock and Enable user account, you will be sent back to the User Edit Menu. If you want to clear the Administrator password (if it has one) then hit enter or type Administrator and Select 1 and “Enter” – to clear the user password.

    10.  Save Changes:  Once you have made all the changes you want (enabled the Administrator account & cleared any passwords), you are ready for the next step.  Hit  ‘!’ and enter.

    Windows Password save changes
    Windows ONTP&RE password save change

    On the screen it asks ‘What to do’?  hit q to quit. You will see:

    Step FOUR:  Writing back changes

    “About to write file(s) back.  Do it ?’’

    Hit   Y  and enter to save changes.

    11.  Last Step:  Hit “Ctrl-Alt-Del” to reboot and eject the cd quickly.  This will allow the system to boot into Windows on the Hard drive.

    You can now login as “Administrator” with NO password.

    Once you are in as Administrator you can change passwords of any local accounts in Control Panel | Users.

  • ISC2 CAP Domain Changes

    Got this message today on CAP domain changes.. Not much changed:

    On September 1, 2013, (ISC)²® will implement certain domain-related changes for the Certified Authorization Professional (CAP®) credential exam.  These will be the new domains you will need to select when submitting CPE credits for your CAP certification.

    These domain changes are being implemented based on the outcome of the Job Task Analysis (JTA) completed in late 2012. The JTA provides the essential foundation for all of (ISC)²’s credential exams. Under general circumstances, changes due to a new JTA study are incremental, so addition or deletion of Domains does not occur normally.

    isc2-cap-domain-changes
    courtesy of gabfirethemes

    Current CAP Domains:

    1.      Understand the Security Authorization of Information Systems

    2.      Categorize Information Systems

    3.      Establish the Security Control Baseline

    4.      Apply Security Controls

    5.      Assess Security Controls

    6.      Authorize Information System

    7.      Monitor Security Controls

    Effective September 1, 2013 CAP Domains:

    1.      Risk Management Framework (RMF)

    2.      Categorization of Information Systems

    3.      Selection of Security Controls

    4.      Security Control Implementation

    5.      Security Control Assessment

    6.      Information System Authorization

    7.      Monitoring of Security Controls

  • Snowden-Manning Heros?

    DISCLAIMER: I have no first hand knowledge of the NSA PRISM program.  This is just my personal opinion of Edward Swowden’s release of classified information and the impacts.

    What is PRISM:

    PRISM is the code name for the data collection program which was born out of the Protect America Act.

    Recently Mr. Edward Snowden released classified information to the international media and fled the U.S.  He was working on the PRISM program and felt that the right thing to do was to tell U.S. citizens about their loss of privacy.

     snowden-manning-heros

    snowden-manning-heros

    SHH!! Don’t tell anybody this.. but privacy has BEEN gone if you are on Facebook, Google or any other social network.  These organization are storing our private data.  But what do these organizations do with that data?

    • Do they try to protect your data?
    • Do they sometime release it to third parties?
    • Can certain data you store on their system be used against you in a court of law?
    • All of the Above 🙂

    Encrypt your data.  That is the only real way to have privacy to a trusted party.   Don’t use FB or Google for stuff you want hidden.

    The Need for Some Sort of PRISM:

    Spies get a very very bad rap lately.  Analysts are unsung heros.   It that world nothing is what it seems.  The media presents one side of everything.  You have to dig and cross reference to get facts.  Intelligence provides a proactive answer to security.  I am speaking from the perspective of someone who has done security defensively.  There is a need for gathering data within the U.S. infrastructure.  Once data is gathered, it can be correlated to detect patterns of potential threats.

    So I think we MUST have something like PRISM (especially in the US) due to the exposure of our assets and the subsequent likelihood of attack. We have a high risk.  And the greatest risk is from INSIDERS (ironically enough PRISM cannot protect itself).

    There are three main issues with the programs current setup:

    1.  Lack of Oversight & Transparency: There seems to be very little transparency and  oversight that represents US citizens regarding privacy and controlling how far the government can go.  US Senators are led away from what is really going on.

    2.  Total Information Awareness:  This system may be too DAMN powerful as far as what it is capable of.  In fact, it seems to be like using GOD Mode 24/7 to gather information.  Snowden mentioned that it can track ANY email.. is this on a whim?  does there need to be some sort of probable cause or “reason to believe” or is this left to the discretion of the guy with his finger on the button.. this leads to the next issue..

    3. The Patriot Act II + Protect America Act =  Its too DAMN politically powerful.  This program has the legal backing to do anything with NO checks and balances.

    Is SNOWDEN A HERO?

    Would I call Snowden/Manning heros/martyrs?  I would not group Snowden with Manning.  The information that Snowden released (so far) is showing a the capability of NSA spying (something that was done by whistle blower William Binney in 2002).  PVT First Class Bradley Manning leaked a lot of war material that risked a lot of people’s lives:

    videos of the July 12, 2007 Baghdad airstrike and the 2009 Granai airstrike in Afghanistan; 250,000 United States diplomatic cables; and 500,000 army reports that came to be known as the Iraq War logs and Afghan War logs. It was the largest set of restricted documents ever leaked to the public. – http://en.wikipedia.org/wiki/Bradley_Manning

    The problem with this is that it actually endangered the lives of informants, and some people that were on the ground in Afghan/Iraq.  Manning fucked up big time.  Snowden is a hacktivist who will have to spend sometime in prison or in Iceland evading the US government unless the American public rallies to sway the politicians.

    Whistleblower Protection:

    My hope is that there is due care taken on this issue.  Because there is a real concern regarding the Constitution, Privacy and uncheck powers of the government.  If not, perhaps the next administration will take up the call of the people.  SarbanesOxley Act of 2002 has a Whistleblower Protection Act that would be helpful if such a law could apply to Snowden.  I am not so sure about that.

    Transparency & Accountability

    I know their needs to be transparency and accountability. But I think its naive to think that we should release all information on all classified data to the world as the Wikileaks crowd believes.  

    Why?

    Organizations & States have an obligation to maintain Confidentiality of critical data.

    That means databases with witness protection programs must be kept Confidential, bank transactions must be protected..

    Nations have some serious enemies (ESPECIALLY the US).  The US governments duty is to protect its people from those enemies (foreign or domestic).

    Consider this:  Certain information on the physical/logical locations of weapons systems, pattens on lethal biochemicals, information on the capabilities of a nation are very effective tools in the hands of really bad people.

    Its naive to think that opening up all classified data is going to set the world free.  I wish humanity was in a kinder, gentler situation.. but the reality is some crazy people want to kill as many people as possible.

    Yes!  I agree that governments with unrestricted power can be MUCH more dangerous.  Some transparency with check and balances are necessary.

     

    WAR OF INFORMATION

    The post modern war conflict is a fight over ideology. Its less about my nation versus your nation and more and more about belief systems.  

    RIGHT NOW there is someone with the intent to kill as many people as possible.  With the capability and opportunity they would strike.  There IS an enemy and they are anywhere and everywhere.  You can no longer point at a map and say “All these people are my enemy.”

    Now there is an enemy willing to kill you over what you believe, what you represent and what they think you are.  And more than likely, THEY are living in your city.   Who are “THEY”?

    Figuring out who THEY are.. is where data mining and correlation comes in.

    The threat-source can be from ANY country, race, creed, or religious faction. They are more and more likely to have a citizenship in your country for the sake of having free reign to make the most damage on the most people that represent what they seek to destroy.

    Its sounds crazy until a bomb goes off in the middle of a Boston Marathon with the attackers on their way to Time Square.  Luckily, there was surveillance to help deter further killings.

    How do we fight against these threats?
    Threats can be detected via patterns within information.

    Solution:  The government should allow the program manager of the system to explain why its necessary, provide proof of its usefulness.  Limit the use and extent of PRISMs power.

    I hope the president will listen to the Internet community on this.  I hope that some political party will hear the cries of thousands of potential constituents then take an intelligent look at the public’s concerns.  Realistically, the American public voted on the reps that backed the laws that created this system.  They accepted it by proxy.  But the shock is from the alleged reach of this program.  Its too bad it took Snowden is risking years away from home and possibly prison for the US to wake up and start talking about something that was leaked years ago.

  • uninstall avg

    The AVG secure search toolbar seems to appear out of nowhere and its annoying.  Its annoying because you probably did not want it.  AVG is a legitimate anti-virus software, but its search/homepage hijack is a bit pushy.  I prefer a search engine without AVG on my Chrome browser.

    Luckily, AVG allows you to get rid of it in a few clicks.

    uninstall avg

    Select “Restore default new tab” in the far right-hand corner.

    Uninstall avg search
    Uninstall avg search

    Upon selecting “Restore default new tab” you will be led to “AVG security toolbar settings”.  Deselect “Show AVG Secure Search Box on new tabs in the browser” then select “OK”.

    After that, you will need to close the application and reopen it.

     

     

  • payphone in hong kong

    payphone hong kong

    a pay phone in hong kong

     

  • tech & coffee: vietnamese coffee

    Vietnamese Coffee
    Vietnamese Coffee

    First taste of Vietnamese Coffee.  It was good.


    View Larger Map

  • Interface Techno-Phil Inc. Keppel Cebu Office Scam Bust

    Interface-Techno-Phil-Inc
    Interface-Techno-Phil-Inc

    ”Im one of the employees onthat company…its true our or sss and other benefits is not updated…this company sucks…if you are new here onthis company they pay 5o pesos for 7 days my god…where doin or best to have sale everyday and they pay us back 5o pesos and if we dont have sale at the end of the day some officers blackmail us if your working here its like heal everyday…i hope this company will close and the owner will put on jail… makati

    Interface, Techno-Phil Inc., had been shut down for its online scam mostly to US clients  and 400 computers had been confiscated on the Anti- Cyber Group (ACG) at Keppel Building, Cebu Business Park, Cebu City on May 16, 2013.

    120 call center center agents were brought to the police station for further investigations about the Interface Techno-Phil company.They said they didn’t have the idea that the company they’re working for is a scam.

    According to the ACG, the agents job are to convince clients to sign up an electronic form exchange for $2.99 as registration and other processing fees. In return, they offer gift cards worth 50$ upon enrolling for a credit card and $100 worth of gift card vouchers of all gasoline station in the United States  .They will also recieve an email from ‘’ Silva Norton ‘’ who claimed to be the owner of a company based in Florida using the website “wakanetworksavings”.

    All payments are made through credit cards. After the account enrollment, Interface techno-phil inc. gets the information and access from the clients’  and start stealing the money from their personal accounts.

    A day after the place had been raided, the company’s representative tried to bribe Senior Insp. Michael Vertudazo, chief of the Anti-Cybercrime Group (ACG) in Central Visayas  in the amount of  P 300,000.00 to withdraw the case against Techno-Phil Inc. and also to return the computers that were taken during the operation.

    http://cebudailynews.ph/news/story/10049

  • military scam: MAJOR KELLY COLLINS

    This is a scam targeting American citizens and/or US military.
    How do I know its a scam?
    –> US Military don’t usually use hong kong email – also that is not the real email source.
    –> Search done on content Three Kings Scam
    –> email originates from threat source [caritasmc.org – 202.168.238.226]

    –> based on its neutral standing, this source has had other threats.

    military-scam
    military-scam

    Hi,
    My name is MAJOR KELLY COLLINS,

    serving the World and my country in the

    most honorable way I know I can, in AFGHANISTAN right now, in a nutshell With a very desperate need for assistance, I found your contact
    particulars during my email search and picked up courage to contact you for your assistance.

    Some money in various currencies were discovered in a room at a farm
    house near one of Osama Bin Laden’s old house in Kabul-Afghanistan during
    a rescue operation, I happened to be one of the soldiers that lead that
    operation that day, so it was agreed by Col. William E. Cole the head of
    our battalion that some part of this money will be shared among both of
    us before informing anybody about it since both of us saw the money
    first. This was quite an illegal thing to do, but I tell you what? No
    compensation can make up for the risk we have taken with our lives in
    this hell hole, my brother in-law was killed by a road side bomb just few
    months ago.

    Now i found a very reliable way of sending a trunk metallic box
    containing the amount of United States Dollars worth ($20,000,000) as
    you must agree with me it has been hell on earth trying to keep this
    money safe from people’s eyes for all these while and with this
    opportunity all I need is just someone capable I can trust 100% I can
    send the box to. So if you can assure me of your honesty I will go ahead
    and send the box to you for safe keeping till I am back home and I will
    gladly give you 30% of the money. If this okay with you please get back
    to me with the following so i can get the box across to you.

    1. Your full name: …………………………. 2. Contact
    address………………………..
    3. Telephone number: ……………………… 4. Occupation: ………………………….

    Contact me on my private email address:(collinskelly307@

    yahoo.com.hk)
    Waiting for your replyMAJOR KELLY COLLINS

     

  • Child Exploitation Online

    Written by CME, 2013

    Short article about Child Exploitation Online: why it happens, how and why to report it.

    cnn story about child exploitation

    child online exploitation

    Spiral of Poverty One Cause of Child Exploitation Online

    27.9% of Filipino citizens make less than 16,841 pesos (412USD) a year according to data from National Statistics Coordination Board (2012).  16,841 peso/year is considered below the poverty line by Philippine standards.  The Philippines is still a third world country with a  poor quality of life and a poor quality of education that enhances the suffering of many children.

    Unfortunately, the strong influence of the Catholic church does more to hurt than heal with its political push to  block laws that  favor of family planning issues such as birth control and prochoice.  Schools do not teach sex education so children grows up without the knowledge of safe sex. They grow up to become very young parents with even less knowledge about family or birth control causing an endless cycle of poverty.

    In a family with 5 kids or more, an only one breadwinner, with a job of a minimum salary of less than 300 pesos daily.  It takes a lot of budgeting.  The families diet consists ofporridge, noodles and sardines. 300 pesos is not enough to supply the family’s needs. In order to survive the parents are forced to make their children work for a living. Due to lack of parenting they implant in children’s mind that they must be responsible of taking care of the family specially the eldest daughter or son. Mostly it is the eldest daughter that is obliged to work for the entire family.

    Poor Parents Make it worse

    In worst case (yet common) scenario parents talk their daughter into prostitution. Some sells their kids for slavery or sent to beg for money on the streets.. Some children are exploited in cities  Luzon Area such as Angeles Pampangga, Cavite and Metro Manila to work as cam girls on the Internet to show their young bodies to the foreigners.  The authorities do investigate and catch the international and domestic sexual predators however the underground market for this activity still goes on even though “cam girl” activity is actually against the law (Cybercrime Prevention Act of 2012).

    The exploitation of minors is also happening in other poor countries such as Thailand and Cambodia where those in a position to alert the police turn a blind eye for money or participate in what will lead to the scaring of a child that will grow up into life-long self destruction.  Raped of their innocence without the benefit of a childhood and not given the chance to choose for themselves what life they wanted all to satisfy the perverse appetite of people that know better but don’t care.

    The parents of these kids are certainly at fault, but if there was no one giving money for these acts, without pedofiles and predator customers paying for the activity there would be no reason to do it.

    Only We can Fight against Child Exploitation Online

     There is a that says:  “It takes a village to raise a child.”

     Its our responsibility to report these acts, confront the parents and raise awareness where we can.  These children deserve a bright future and guidance instead of being abused and damned to a life of being used and exploited.  The real disease is poverty this is only one of the symptoms.

    Ways to Stop Online Child Exploitation:

    If you know of an offender that is doing this report them.  The only way to help kids from being exploited online is the stop the people that give money for the act.  If we don’t help these children, no one else will.

     Europe – http://ceop.police.uk/ – email…enquiries@ceop.gsi.gov.uk

     US

    http://stoponlineexploitation.org/

    https://www.childwelfare.gov/responding/exploitation.cfm

     Canada:

    www.redcross.ca

     Australia:

    The AFP investigates online child exploitation which occurs using a telecommunications service, such as computers with internet connectivity or mobile phones. —  www.afp.gov.au

    MORE:  https://www.google.com/search?q=online+exploitation&ie=utf-8&oe=utf-8&aq=t&rls=org.mozilla:en-US:official&client=firefox-a

     

    www.unicef.org/infobycountry/philippines_46852.html

     

    References:

    Leland Joseph R. Dela Cruz, 2009 Philippine Poverty, 9 February 2011, http://www.slideshare.net/ldelacruz/poverty-situationer-2011-8294418 (accessed February 15, 2012).

    farivar, cyrus, 2012 New Philippine Law, Sept, 2012, http://arstechnica.com/tech-policy/2012/09/new-philippine-law-outlaws-cybersex/