Category: Howto

  • Why Social Bookmarking and Service Links: Social Market Optimization

    Why Service  Links?
    Service links are the little buttons you see on blogs that allow the user to submit your article to your online bookmarking account.
          Consider  Social Marketing Optimization (SMO)The best  thing about these service links is social marketing optimization. Social        marketing  optimization is where you allow your readers some control of the ranking,  content or look of your site.  Service Links allows your readers to show their  approval of your content by bookmarking it or saving it in their own accounts  across the web.  These accounts, such as Del.icio.us, actually publish all        user content to the web for all to see. The reader also chooses the labels  associated with your content and exposes that same content to like minded  readers who may have been previously unaware of your presence.  SMO is allowing  your readers to syndicate your content, that is what service link do.  This is the current direction of the World Wide Web (Pakii/SMO).

    For more information on Social Marketing Optimization check out Mr. T.L. Pakii's site on the subject: Blogging for Fun and Profit/SMO!

  • How to get Malware/Virus/Trojans on your Home Windows computer:

    1) Use Window 9x/2000/XP out of the box DO NOT bother to reconfigure it
      

    Don't create any login accounts with strong passwords
    Do all work from the adminstrator account (Windows does this out automatically  so   don't do anything)
    Do not bother with patches no matter how critical (Windows will prompt you to update, just ignore it)
    Don't disable the guest account
    Don't change the name of default administrator account
    Enable as many network protocols as you can

     

    2) Use Internet Explorer

    If you want your system to get infected with all kinds of malware DO NOT use Firefox or anytype of pop up blockers
    When you use IE, don't increase the security under: Tools | Internet Options | Security tab, just leave it as is
    Ensure all Java and ASP scripting languages are enabled, allowing other computers to load software on your computer remotely
    Never patch Internet Explorer

    3) Connect directly to the Internet

    Do not use any kind of firewall 
    Do not use Network Adress Translation (which will hide your IP adress)
    Do not load SP2 for Window XP
      

    4) Surf the deadliest sites with no protection

    Surf Serial/Crack/Warez sites and always completely trust their sites
    Porn sites with no protection
    Screen Saver sites
    “hacker sites”  not all hackers sites just “black hats” and script kiddie type sites
    Find dark IRCs
      

    5) Behavior that will help you get your system infected.

    Download Screen Savers from site you are not sure about
    Open emails from people you don't know
    If you get a Security Warning that says “Do you want to download XXXXPROCUT NAMEXXX..” Don't even bother reading the rest just click yes.
      

    6) Software that is more than likely infected

    Tools bars that automatically download without your permission
    Kazaa and some other free P2P tools

     

    List of Tools for faster Infection:

    Internet Explorer  (Firefox can affectively block malware)
    Broadband/DSL (use of a firewall using Network Adress Translation will hide you system)
    Windows 9.x/2k/XP (open source OSes such as Linux are less likely to be hacked)

     

  • How to get rid of SpySheriff:

    “I have a malware infection on my laptop, i go into safe mode and look into
    the files and the virus file comes up as spysheriff with an icon.”

    How do i get rid of it?
    Is it easy to get rid of?
    How did i come accross it?

    *******************************************************

    How to get rid of it?

    Check out my site:

    http://elamb.blogharbor.com/hacked/removespysheriff.htm

    If you have already, try this:

    http://www.bleepingcomputer.com/forums/How_to_remove_SpySheriff_Winstallexe_Spysheriffexe-t22402.html

    The Easiest Way to get rid of it:
    Another way you may be able to remove it is to do a system restore:

    http://www.elamb.org/hacked/systemerror384.htm

    This is what I had to do because I had stuff going on even in Safe Mode.

    How did I get it?
    I was surfing some serial/crack/warez sites.  They are absolutely
    INFESTED with malware. Some porn sites are bad, but warez sites seem to
    be the worst.

    On way to Prevent it is to use FireFox:
    See top of this blog.


  • Detected Spyware! System error #384

    detected spyware system error #384

    This is a bogus error screen that replaces your browser's home page. The message Reads:

    Detected Spyware! System error #384

    Your IP address is XX.XXX.XX.XX. Using this address a remote computer has gained access to your computer and probably is collecting the information about the sites you've visited and the files contained in the folder Temporary Internet Files. Attention! Ask for help of install the software for deleting secret information about the sites you visited.

    You computer is full of evidences!

    More than likely, this message is just the tip of the iceberg. Using simple intrusion detection tools you will see that your system has scores of viruses, trojans, worms and other malware installed on it. The message is trying to get you to purchase some scamware.

     

    How to remove the “Detected Spyware! System error #384” message and all the malware on your system?

    There are actually a few relatively easy ways for removing this malware:

    USE FREE (LEGITIMATE) ANTI-SPYWARE

    PERFORM A SYSTEM RESTORE

    COMPLETELY RE-INSTALL WINDOWS (self explanatory, and complete overkill unless you have rootkit on your system or something crazy like that.)

    READ MORE HERE…

  • Spy Sheriff Removal

    I was doing some testing on my Windows XP system surfing about some
    sites of “ill repute” with IE6 and got hit with something called Spy
    Sheriff
    .

    Spy Sheriff is like a watered down version of PS Guard or Smithfaud.  Like PS
    Guard
    , Spy Sheriff claims to want to remove all the malware it infects
    you system with.  Both of these horrible bits of malicious code
    are what I like to call scareware.  The get loaded on to your
    system along with about 100 other viruses, worms and trojans and take
    over you desktop with a message like “Spyware Infection”.  The
    application then “scans” your system.  And tells you that you must
    activate the Spy Sheriff or PS Guard in order to clean your
    system.  When attempt to remove Spy Sheriff using Add/Remove programs, it simply adds itself again once you reboot.

    In the background, all the malware they loaded on your system are
    collecting data and send status report to a parts of the world. 
    The scareware will usually make sure you know this to convince you to
    buy their product.  DO NOT GIVE THEM YOUR CREDIT CARD INFO!

    Here is how to remove Spy Sheriff.

  • Whax ver. 3 on Vmware Version 4.0.2 build 5592

    This article assumes you are familiar with Vmware.

    Until I find something better, Whax is my favorite White Hat
    tool.  It is a Swiss army knife with built in Swiss army knives
    for computer security testing.  What is even cooler about
    Whax is that you can make it a virtual OS with Vmware. 

    This means you can use Whax to test a whole network of
    virtual Operating Systems on a single PC.  With enough RAM and
    hardrive space, you can have a few different versions of
    Windows and a few versions of Solaris on a
    single computer being tested by Whax.

    Here is how I loaded a virtual version of Whax on a Dell Latitude D600 laptop. 

    First of all, you'll need:

    A Dell Latitude D600 (x86 system with at least 128Ram, 8 Gig HD, 1GHZ… need more RAM & HD for more OSes) See basic system requirements HERE.

    Vmware 4.0.2 build-5592 (may work with other versions such as the FREE Vmware player)

    Whax version 3 (should work with any version of Whax.  Download free version of Whax HERE.) 

     

    Loading Whax on Vmware with the Vmware 4.0 Wizard:

    Select File | New | choose “Custom”

    Guest Operating System: Select “Linux” as the Guest Operating System

    Virtual Machine Name: Whax (optional, I usually name this something to make it stand out from the other OSes) 

    Location: I chose the default location

    Network Connection: This depends on what you are
    trying to do and your network set up.  It you have a
    internetworking device that you want Whax to interface with with it own
    IP address you will want to choose Network Address Translation. 

    Disk: Select “Create a new vitural disk”

    Disk Capacity: As low as 1GB

    Disk File: I usually rename the Disk file “Whax” so it can be distinguishable from other OSes you have loaded.

     

    Edit Virtual Machine Settings:

    I haven't been able to get the RAM below 128Megs, but maybe you'll have better luck than me.

    The hard disk can be brought down to 1Gig perhaps even lower.

     

    Whax can be run on VMware from an ISO on the desktop.

    With this setting, Whax will run on VMware directly from the disk. 

    The elusive setting that initially stopped this Whax from working on
    VMware was the “acceleration” feature that is turned on by default on
    some versions of VMware.  To modify this feature, click
    on “Edit virtual machine settings” once your Whax Guest Operating
    System is set up.  From the “Virtual Machine Control Panel”
    select the “Options” tab and select “Disable Acceleration” in the
    Advanced options box.  

    On my Dell Latitude d600 the load time is very slow (as in takes a
    total of about 5-10 minutes total to see the dragon), but I sure this
    will be faster on a betters system.  Good Luck.

    Another Cool trick with VMWare can be found at  baeke.info

  • Beer Can Padlock Shim aka "Masterlock Master Key"

    How to build a better padlock shim using a very special hacker tool… A beer can.

    This was picked from Deviant Ollam at Defcon 13.  This is yet
    another reason I love Defcon.   I've heard the arguement that
    we [security professionals] should NOT “promote” hacking or do anything to suggest that it is cool.

    But I think that is a pretty stupid thing to say… because hacking IS
    cool.  Its not always bad and definitely not always good.  As
    far as going to events like Defcon… The IT and Security Industry are
    so slow and firewalled with corporate BS that they will actually hide
    things the consumners need to know.  Just look at CiscoGate
    Or, do like a typical government, know that there is a problems but be
    so filled with overhead and beauracracy that they can not do any thing
    about it even if they cared enough to.

    You don't have that kind of big brother crap at the Defcon.  If
    its broke you fix it and if it is fixed you break it to see if its
    possible. 

    If
    the locks on the doors into your house are no good don't you want to
    know about it ASAP?

    Ollams Site:
    http://deviating.net/

    read more | digg story

  • Good Password Tips and Password Management

    These days a single computer user may have dozens of passwords. If you use computers at your job you may need to access secured databases, local workstations and numerous accounts online and each is supposed to have its own unique password. Though many people don't require a logon for their home PC, they will definitely have one for email or websites that they manage. Here is a guide to assist you in strengthening your passwords and password techniques.

    After reading this article you will know the following:
    -How to make good passwords
    -Good password practices
    -Techniques to manage all of your passwords

    How to Make Good Passwords

    Choose a password with the following criteria:
    -At least 8 characters in length
    -At least 1 number
    -At least 1 special character
    -Upper and lowercase.

    Passwords with difficult combinations make it harder for tools like L0phtcrack, Brutus, John the Ripper, Cain and Able and other password crackers to decipher your password.

    When creating a password, don't use personal information such as birthdays, children names, or first and last names. Avoid using words or phrases that can be easily guess or cracked with a “dictionary attack.” Do not use the same password on the different systems. If you work in a classified environment, passwords should be treated at the same level of classification as the systems they protect.

    Good password practices

    Never share your password with ANYONE including your Administrators, Help Desk personnel or System Administrators. IT professionals at your job or Internet Service Provider (ISP) will not normally ask you for your password. If they do need it then you should give it to them in person and ensure you change it as soon as they are done with their task. A common “Social Engineering” tactic used by malicious hackers consists of calling up unsuspecting users and pretending to be from the computer support staff. Another tactic is to have trusting users email the password or type it into what looks like a legitimate site; this is known as “phishing.”

    Be aware of your surrounding when you are typing your password. Watch for “shoulder Surfing” or people watching what you type as you are entering your password. If you use the web to access critical information (such as online banking, or medical information) ensure that the site uses some type of secured method of encryption. You will know this if the site's URL begins with an “https.” SSL and Secure HTTP are sometimes indicated by a tiny lock in a corner of the page. If there is no encryption then it maybe possible for unauthorized users to view and/or capture the data you enter and later access the account using a “sniffer.” A sniffer is a tool that captures all “clear text” or unencrypted data. SSL and Secure HTTP encrypts data so that it looks like gibberish to tools like sniffers.

    Techniques to manage all of your passwords

    It is best to memorize your passwords however if you have literally scores of passwords from work, home, online business ventures and the bank and you do not have a photographic memory, you may want to write them down and put it in your wallet. This simple and practical task is what author of Beyond Fear, and system security phenomenon, Bruce Schneier, recommends as does Senior Programmer for Security Policy at Microsoft, Jesper Johannson.

    Using Password Management applications such as Password Safe, a free Microsoft application for storing passwords, and Password Vault (also free) can help you to effectively manage your passwords.

    Another management technique is to allow Windows (and other Operating Systems) to automatically fill in the data. This is great for trusted SECURE environments such as home systems in which you don not need to hide any account information from anyone, but not such a good idea for the work environment. It should also be noted that systems without a high level of Internet security (protected with firewalls, updated patches, NAT enabled, etc) should not use the auto fill features as the passwords are many times stored on the system in clear text making it easy for malicious code such as spyware, trojans and worms to steal your passwords and account information.

    The greatest thing you can do to protect your password is to be aware that at every moment someone somewhere would love to access some or all of your accounts. It is not always cyber criminals looking for you banking information, sometimes it is just curious people who happen upon your username & password. It may even be someone you know. Be aware.

     

    Other ways to protect your passwords:

    .htaccess

    PasswordSafe

    Online Password Generators:

    http://www.winguides.com/security/password.php

    http://www.goodpassword.com/

     

     

  • How to pick a lock

    ever wondered how to pick a lock…well now you can know. i have tried
    the pin column lock explanation they gave and it was open with no
    problem

    read more | digg story

  • Use Google To Find Passwords

    Google hackers have been doing this for a while now. Here is a tutorial on finding passwords using google. This could be used to secure your own web server.

    Security Professionals charged with protecting IT infrastrutures would do well to become the most aggressive hacker of their own networks. This would help them to proactively seek out new exploits on their network, webserver, or IS they protect.

    read more | digg story