Category: hacking

  • Why Linux Wont Replace Windows

    A well written article using the motorcycle/car metaphor on why linux will never need to replace windows.

    This is a great article for those interested in the Linux vs Windows debate.

    Linux is an alternative to
    Windows, but not a replacement. It will never be a replacement, because
    it has incompatible goals. Microsoft's goal is to get their software
    onto as many PCs as posible, as their priority is profit. Linux has no
    such goal, because Linux is free. It has a different priority.

    Free & Open Source Software (FOSS) is the exact opposite of
    proprietary software like Windows: FOSS is all about the
    software
    . It's not
    about the number of end users. Software that works well but has only a
    few users is considers a failure by comemrcial software standards, but
    a success by FOSS ones.

    Lots of great, great points for those wanting to switch from Windows to Linux, A MUST READ for LINUX N00bs.

    I use Linux for the security things that I can't do with Windows (or at
    least I don't know how to do easily with Windows).  Like carrying
    an OS in my pocket loading it on a system in another country and *hacking a network.

    * Hacking
    Disclaimer: (All is done legally, with consent of network owners… Do
    not try this at home.  Hacking networks is done by and in the
    presence of trained professionals.  No animals are harmed in my
    hacking events). 

    Thanks linux.oneandoneis2.org, I really learned something.

    read more | digg story

  • Decyphering…and cyphering…driver's licenses

    Site explains and provides tools to determine someone's DL#, and the reverse process as well.

    Before you consider creating fake ID's consider first that you could be charged with second-degree possession of a forged instrumentit is a Class D FELONY.

    Depending on how many count you get against you (or how many times you break the law) you could win a signifigant amount of time in PRISON. 

    Is getting into a club and have a few drinks worth the risk of being RAPED by a person of the same sex and being a Felon for the rest of your life?

    If you are willing to take that risk than go have fun but don't say you weren't warned when your in the prison shower debating on whether you should pick up your soap.

    read more | digg story

  • RIAA Sued for Hacking

    A 41-year old disabled single mother has counter-sued the RIAA for
    Oregon RICO violations, fraud, invasion of privacy, abuse of process,
    electronic trespass, violation of the Computer Fraud and Abuse Act, and
    negligent misrepresentation.

    read more | digg story

  • Computer Security 101: Proactive Security

    Another university accepted ethical hacking.  Lately it seems every other month educational institutions are teaching security hacking.  I think this is good.  It is important to learn many kinds of Wire-Fu. 

    Oct. 3–NEW HAVEN, Conn. — The computer lab tucked into a corridor at Jennings Hall at Southern Connecticut State University may not look it, but it's sick.

    Viruses run rampant. Firewalls are frowned on. Here, hacking is not only encouraged, it's a course requirement.

    “Last week, I went onto a computer in the back room. Their homework was to figure out what I did and log into my fake account,” said Lisa Lancor, an associate professor of computer science.

     

    University of Calgary hacker course 

    University of Glamorgan – Certified security Testing Associate and Professional and Certified Forensic Investigation Analyst

     Internation Counsel of e-Commerce Consultants – Certified Ethical Hacker CEH – Certification

  • Sony cracks down on PSP hacks

    O.k. I don't get it, Sony:

    Sony is engaged in a tug-of-war with
    hackers who keep cracking its PlayStation Portable software to unlock
    the device and run their own applications on it.

    The company is preparing another update to the PSP firmware to fix a
    recently disclosed bug that lets hackers downgrade the PSP system
    software, a Sony representative said Thursday.

    Hacking is the coolest thing you can do with a device!  Sure it
    voids the warantee but isn't that worth moding that bad boy to your
    specifications? 

    I don't know, it I spend $200 dollars on a device I should be able to
    mod it, chuck it off a three story building, or wipe my ass with
    it!  As long as I'm not breaking any laws, or taking money out of
    companies pocket.  

    You are telling me that AVERY can enforce the intended use of the paper
    they sell!?  Common now.   Once you buy it you can put
    it on the side of your toilet and make Rorschach Inkblot Test
    after cleaning yourself.  Now if you buy the paper and re-wrap it
    and call it SAVERY's, and under cut AVERY, then that is not right.

    read more | digg story

  • http://www.shmoocon.org ?

    An annual East coast hacker
    convention hell-bent on offering an interesting atmosphere for
    demonstrating technology exploitation, inventive software &
    hardware solutions, as well as open discussion of critical information
    security issues.  ShmooCon 2006 will be January 13-15, 2006, in
    Washington, D.C.

    I first heard about this convention from Derad.  I was beating my drum about Defcon and she asked me if I'd ever been to ShmooCon.
    To which I replied, “No.”

    Aparently it is the east coast version of Defcon.  Sounds a bit
    different though.  We can gauge how affective it is by seeing how
    many FEDs show up.  Does anyone know that answer?

    I'd love to go but I can only go if I get the company I work for to
    spring for the ticket and lately they have been really cheap. 

  • Wardriving Tools

    Great site that lists the best software for finding and decrypting wireless AP's.

    Morality of Wardriving tools.
    I do not personally wardrive but I think it is a great way to do an
    assessment of the security of your area.  I know some people
    wardrive just to find a free spot to surf.  This is the equivalent
    to walking up to every door in your neigborhood and twisting the knob
    to see if the door is unlocked.  Then walking in and watching
    cable on their couch and eating popcorn.  It is not right. 
    And I can not pretend that it is.

    Privacy of Publically dispensed Wireless Data
    But at the sametime, having a wireless service and NO security is like
    having a house with no walls.  How can there be a crime or theft
    of data and service when the data and service is spilling out freely
    into the air like a public water fountain. 

    Paying for Service and then serving it to the Public
    I pay for the water service at my house so if anyone else walks into my
    yard to use my water hose they are wrong.  But if I put that same
    hose into a nearby public park and turn it on, how guilty is anyone
    going to feel about taking a sip or splashing their face with it?

    So if you feel strongly about people NOT wardriving and not stealing
    service than do something about it.  I think that wardriving will
    dry up when the masses finally get wind of wireless security, until
    then “Surfs up.”

    read more | digg story

  • Hackers Step Up Attacks on IM Networks

    This is an interesting article on eWeek penned by Gene Koprowski
    adressing the virus portal known as Internet Message chat (AIM, MS
    messenger, ICQ etc).  

    “One security research outfit on
    Wednesday reported the highest monthly total ever of new IM viruses…
    some 25 viruses were reported on IM networks during September alone.”

    Great point but the article speaks as if IM is some sort of NEW
    target.  IM is one of the biggest holes in home computer
    systems.  There are MANY hacker tools that exploit these swiss
    cheese, foolishly trusting apps.  Do a scan on your ISP's Network
    and you will see scores of ports open on AIM and ICQ and others. 

    “We started doing this report about four months ago. What we're
    seeing is that there could be a new phase of IM viruses emerging. In
    the past, IM viruses were variants of e-mail-borne viruses. That's not
    exclusively the case anymore.”

    Jaros said that his company's research demonstrates that there
    is an average of at least one IM virus attack being conducted every day
    now.

    One of the most popular techniques that truly dark hackers use is to
    connect an “owned” box to an IRC (Internet Relay Chat) room from which
    many unholy acts can be done.

    read more | digg story

  • Mobile viruses could get nasty fast

    Dan Nystedt's article on PCWorld tells of the good, the bad and the
    ugly about connecting mobile systems to home system to the Internet:

    “The dream of a connected world where
    PCs and mobile phones can communicate with the digital home and other
    devices is supposed to make life easier. But it could instead make life
    far more dangerous if malware developers have their way.”

    And my favorite part:

    “For example, mobile phone services in some countries let people see
    what's going on inside their house via a Web cam connected to motion
    sensors, snapping a picture and sending to the homeowner if anything
    seems awry. But a hacker could use that same Web cam to see if anyone's
    home, and perhaps break in. Or invade people's privacy by taking
    pictures of what's going on in the house. And could a marauder hack
    into a driver's mobile phone use it to shut down certain automobile
    systems, like the brakes?”

    The article goes on to mention something very interesting, 3G phones
    are online all the time.  This feature make them HIGHLY
    vulnerable to attacks.  I won't be surprise if one day soon these
    phones will have to have little built in mobile firewalls.

    “F-Secure, another vendor of antivirus tools,
    says the current total count of known mobile malware stands at 87, up
    from less than 10 early last year. A total of 82 of those viruses were
    written to run on the Symbian series 60 operating system.”

    Symbian is a very popular mobile phone operating system.  Much
    like the Microsoft OSes and apps, Symbians popularity makes it a huge,
    juicy target to mobile phone black hats.

    read more | digg story

  • 40 Million Credit Card Numbers Stolen – CardSystem Solutions Incompetence

    CardSystems Solutions moronic security efforts have resulted in the potential theft of information for 40 million credit cards. Hackers were able to install a rogue program, probably a Trojan, in the CardSystems security network. This program captured credit card information including the cardholder’s name, account number and verification code.

    CardSystems Solutions is an Atlanta-based company. Prior to this incident, it processed approximately $15 billion dollars in credit card transactions each year. Small businesses were the primary users of the system.

    The FBI and MasterCard International have launched investigations into the hack. It has become apparent CardSystems Solutions should be charged with gross negligence. The company failed to comply with MasterCard security regulations and failed to destroy the information of cardholders after prescribed time periods.

    In a matter of gross incompetence, CardSystems failed to encrypt any of the credit card data for users. This is the equivalent of your bank sending monthly account statements will all the information printed on the outside of the envelope. It is simply inexcusable and has led to potentially the biggest theft of financial information in history.

    Which Credit Cards?

    The incompetence of CardSystems Solutions will have an impact on every major credit card group. Estimated numbers range from about 20 million Visa cards exposed to 14 million MasterCard credit cards. As many as 4 million American Express and Discover accounts were also put on the sacrificial altar by CardSystems.

    What You Should Do

    You should review all charges on credit card statements over the next 12 months. Contrary to popular belief, hackers typically will not go out and charge up thousands of dollars on the card. Instead, you should look for small charges of $10 to $20 from companies with bland names. Hackers know that many people will not call to reverse a small charge. Don’t be lazy! Closely inspect your statement and contest any charges that aren’t familiar.

    Closing

    How big is this hack? There are approximately 300 million people in the United States. 40 million accounts equates to 1 in every 7.5 people. Yes, people carry multiple credit cards, but it is still a huge number. CardSystems Solutions should pay a heavy price for its incompetence. Frankly, it should be liquidated. There is little doubt the major credit card companies will take action.

    Richard Chapo, Esq., is a business lawyer with http://www.sandiegobusinesslawfirm.com – offering legal advice to San Diego businesses. This article is for general education purposes and does not address every facet of the subject matter. Nothing in this article creates an attorney-client relationship