Category: I got hacked

  • 17-year-old accused of hacking into school computers

    JEFFERSON COUNTY – A 17-year-old student at Golden High School has been arrested after police say he hacked into the school’s computer system and changed grades.

    Police say charges could include forgery, computer crime and use of forged academic records.

    Police believe the student hacked into the campus portal system, which is meant to give parents access to grades, schedules and attendance records.”

    Everytime I hear about a kid trying to hack the school records I am reminded of Ferris Bueller’s Day off. 

    read more | digg story

  • Archive of Defaced Websites Defaced by Saudi Arabian Hackers!

    Possibly the most ironic defacement ever. Zone-H.org, “the largest website defacement archive and IT security resource on the planet” has been hacked and defaced by Saudi Arabian hackers “Devil Hacker & Unix Web”.

    read more | digg story

  • Prevent Computer Viruses

    In the last three years or so I haven’t had a single computer virus on my main system unless I put it there on purpose.  I use a very simple method to prevent computer viruses and malware from ever getting on my system. 

    check it out here: http://elamb.org/hacked/how-to-prevent-computer-virus.htm

     

  • There is no such thing as Security

    I’ve noticed that there are two types of security people: anal “type A personalities” who live every moment by the rules, and those that realize that there is no real security.  Please understand that these two mindset don’t seem to have anything to do with talent.  I’ve met talented people with both mindset.  A talented security professional is mindful, aware, and always pays attention to detail.  The very best seem almost psychic in their ability to spot wrong doing, security breaches and even malicious intent.

    Type A security people seem to thrive on “catching bad guys”.  Its like they are kids playing cops & robbers.  These people thrive on structure, order and regulations.  In information security they know how important it is to have lots of centralized control and a stardard configuration for all systems.  In the Meyers-Brigg’s personality test, these people are ESTJ’s (Extraverted Sensing Thinking Judging).  The thought of any getting away with breaking the law (ANY LAW) is unacceptable.  These guys make great Directors of Security, CSO’s and other policy creators as long as they don’t micromanage their people.  Their employees will either love them as a great mentor or hate them with every fiber of their being.

    Those who realize that there is no such thing as security are hackers.  They are many times INFP’s (Introverted iNtuitive Feeling Perceptive).  Unlike the ESTJ’s they don’t care about structure and rules because the realize that rules are only suggestion to keep an acceptable level or order.  For them the most important rules are in a persons heart.  ESTJs will usually see these people as lazy and don’t really care but these people are just trying to find an easier way to do things.  If they don’t enforce certain rules or cut corners, it because the sincerely believe that the rule or enforcement (in that particular situation) is not needed.  Employees will usually love INFP’s unless they happen to be ESTJ’s.

    I am a bit biased because I am in the second camp, INFP.  I don’t believe there is a such thing as “security”.  No one is ever completely safe.  All a malicious intending person needs is the element of surprise, time, and pressure an they can get away with anything they want.  Further, anyone at anytime can have malicious intent: employees, kids, bosses, friends, family not just random strangers.

    Security is just an illusion.  The one good thing security does is ensure you are faster than the slowest person, organization, network or whatever on the block.  Those with malicious intent will typically go for the easiest target. 

    Since many crime happen from people that the victims know all we can really do is not worry about it.  Life is too short to waste too much time fretting about every possible thing that can happen to you.     

    I guess that is what Ben Franklin meant when he said:

    “Those Who Sacrifice Liberty For Security Deserve Neither”  

    If you worry so much about security that you can’t enjoy the fruits of your labor, then what is the point of the living and if you can’t enjoy living whats the point of protecting ANYTHING. – elamb

  • Black Hat Spammers (NIST Hacked)

    NIST.gov, heidelberg university and others have been hacked by black hat spammers.

    Lately I’ve been getting some spam that I consider a special treat.  These are websites that have been exploited and used to promote spammy pharmacy products such as viagra and cialis. 

    I am not happy that victims are being used, I’m intriqued on how the spammers managed to get away with it.

    This one comes from NIST.gov: 

    SPAM Hack of NIST.gov
    viagra
    http://www.nist.gov/HyperNews/atp/get/collaboration/285/1.html
    viagra
    [URL=”http://www.nist.gov/HyperNews/atp/get/collaboration/285/1.html”]viagra[/URL]
    tramadol
    http://www.nist.gov/HyperNews/atp/get/collaboration/288.html
    tramadol

    I’ve been working with the U.S. Govt for a long time so I am familiar with the NIST.  It is the National Institue of Standards and Technology: “Founded in 1901, NIST is a non-regulatory federal agency within the U.S. Commerce Department’s Technology Administration.” 

    When I thought that they might have been hacked, I immediately sent and email to the webmaster.  But unfortunately they rejected my email.
    Here is another hack attempt (this one unsuccessful):

    UTA.edu
    viagra
    http://www.uta.edu/HyperNews/get/delgua/158.html
    viagra
    [URL=”http://www.uta.edu/HyperNews/get/delgua/158.html”]viagra[/URL]
    phentermine
    http://www.uta.edu/HyperNews/get/delgua/160.html
    phentermine

    Here is one is what looks like a division of Heidelberg University:

    physi.uni-Heidelberg.de
    cheap xanax
    http://www.physi.uni-heidelberg.de/HyperNewsFachschaft/get/discussion/862.html
    cheap xanax
    [URL=”http://www.physi.uni-heidelberg.de/HyperNewsFachschaft/get/discussion/862.html”]cheap xanax[/URL]
    generic viagra
    http://www.physi.uni-heidelberg.de/HyperNewsFachschaft/get/discussion/860.html
    generic viagra

    email I sent to Heidelberg Universtiy (translated with babelfish):

    Hallo,
    Ihr Aufstellungsort kann ausgenutzt worden sein:
    http://www.physi.uni-heidelberg.de/HyperNewsFachschaft/get/discussion/862.html
    Die Person, die dies getan hat, benutzt Ihren Aufstellungsort zu Spam andere Internet-Aufstellungsorte. Traurig über meinen Deutschen. Ich verwende babelfish.altavista.com, um zu übersetzen. Auf Wiedersehen

    Here is another attempt on Kryten.murdoch.edu.au 

    pacific poker
    http://kryten.murdoch.edu.au/HyperNews/get/forums/thal/300.html
    pacific poker
    [URL=”http://kryten.murdoch.edu.au/HyperNews/get/forums/thal/300.html”]pacific poker[/URL]
    cialis
    http://kryten.murdoch.edu.au/HyperNews/get/forums/thal/297.html
    cialis

    As with any exploit, the spammers used a flaw in the webpage to post the data on victims webpages.  The sad thing is that it can happen to anyone.  Security Awareness is really the only defense one can have.
     

    I have been getting a lot.  I’ll update this when I get some good one.

  • Want to outwit hackers? Hire an ethical one

    Some of my colleagues in the information security profession think that hacking is evil.  They strongly rebuke any information security professionals for condoning hacking. 

    I think that is a ridiculous position to take.  How can we be any good at our job (particulary the more technical information security professionals) if we ignore the skills that malicious hackers use to exploit the very systems we protect?  Why would we bind our own hands from finding vulnerabilities before our enemys? 

    Not knowing the darker side of security is like a Drug Enforcement Agent who can't recognize drugs because he or she has never had any exposure to controlled substances.  It is not my position that cops should rob a bank or abuse crack to REALLY know the criminal mind.  I'm just saying that security is not just about implementing secuirty practice, it is about knowing the exploits, vulnerabilities and threats and knowing them well.

    Hacking is cool.  It is not all evil or criminal.  Sometimes I have to hack my system after locking myself out.  I've attempted to hack my own network to find vulnerabilities. 

    I think hacking is about mastering systems, finding easier ways to do things in life, being clever.  The dangerous thing about hacking is that sometimes individuals are smarter than the systems that they interface with (or control them).  It is the mutant strain that changes everything, the revolution that forces change, the rebel refuses to submit and any of those can be very good or very bad.

    Unfortunately, it is easier to destroy than to create, so some weak, ignorant, sociopaths give in to the darkside.  This is true of any method, skill, talent, profession ect.  It is a part of human nature to have users and abusers in our ranks.  You may even have some in your family!  It is my personal belief that what you reap is what you sow (karma); those who do bad will get theirs.  I choose to hack ethically lest I incur the wrath of the universe.

    The first ethical-hacking course was started six years ago. Today, there are some half-dozen organizations offering similar instruction around the world

    read more | digg story

  • Re:INVESTMENT MANAGEMENT – SCAM?

    I'm so pissed off lately about scammers that I've been considering baiting them even though
    That is not my style. 

    Instead, I'll do some thing kind and sign them up for special offers!

    Here is a scam I got today.

    SCAM SCAM SCAM SCAM
    tomkinson consult <tomkinson_consult7@virgilio.it>

    Reply-To: tomkinson@excite.com
    Date: Jun 15, 2006 7:04 PM
    Subject: From:Mr.TomKinson

    From:Mr.TomKinson

    Dear Sir/Madam,

    Re:INVESTMENT MANAGEMENT

    I
    represent a client who has interest to
    do business relative and invest
    in your country in any area related
    to Real Estate, Properties,
    Shares, Bonds,Agriculture, Construction,
    Supply, or any business of
    your choice in order to initiate a proper
    and structured relationship.
    I request your Trust to jointly invest and
    solicit an Honorable
    partnership to assist us invest and manage the
    funds in long term
    profitable businessventures.Please let me know what
    your response will
    be to this offer, to receive investment funds in
    cash or cash/bank
    account.

    The amounts is Eighteen Million Five
    hundred Thousand
    United States Dollars,you will assist in the
    transfer/receive of the
    above amount in cash or your designated liable
    bank or personal claim
    .

    Invest and manage the funds. Advise on
    lucrative areas for
    investment with good turn-over profit Assist us in
    the purchase of
    properties,shares, bonds or and we intend to invest
    through you or
    your agency in the purchase of assets in your country.

    The
    transaction will result in you being paid a commission of 10% of
    the
    investment capital and extra additional percentage in every
    subsequent
    venture under your pervision and the transaction desires
    absolute
    confidentiality and professionalism in the handling of this
    matter.

    Your swift response will be appreciated .

    Sincerely.

    Mr .Tomkinson

    “,0]
    );
    //–>From:Mr.TomKinson

    Dear Sir/Madam,

    Re:INVESTMENT MANAGEMENT

    I represent a client who has interest to do business relative and invest
    in your country in any area related to Real Estate, Properties,
    Shares, Bonds,Agriculture, Construction, Supply, or any business of
    your choice in order to initiate a proper and structured relationship.
    I request your Trust to jointly invest and solicit an Honorable
    partnership to assist us invest and manage the funds in long term
    profitable businessventures.Please let me know what your response will
    be to this offer, to receive investment funds in cash or cash/bank
    account.

    The amounts is Eighteen Million Five
    hundred Thousand United States Dollars,you will assist in the
    transfer/receive of the above amount in cash or your designated liable
    bank or personal claim.

    Invest and manage the funds. Advise on lucrative areas for
    investment with good turn-over profit Assist us in the purchase of
    properties,shares, bonds or and we intend to invest through you or
    your agency in the purchase of assets in your country.

    The transaction will result in you being paid a commission of 10% of
    the investment capital and extra additional percentage in every
    subsequent venture under your pervision and the transaction desires
    absolute confidentiality and professionalism in the handling of this
    matter.

    Your swit response will be appreciated .

    Sincerely.

  • Social Engineering, the USB Way

    I made my way to the credit union at about 6 a.m. to make sure no employees saw us. I then proceeded to scatter the drives in the parking lot, smoking areas, and other areas employees frequented.

    I knew a professor who did something similar to this.  He and his class wanted to prove how unsecure the computer stores are so they went to CompUSA/Fry's type computer store and loaded up the display computers with malware.  But they weren't evil malware.. they were “happy malware”.  They notified the manager of what they'd done in order to give them a heads up on the lack of security.  Needless to say the store was pissed.  Gray Hats get no respect.

    read more | digg story

  • Delete Search Results: Cover your tracks

    Ever search for something questionable on someone else system and go into a hyperventilation panic when you notice that their computer is retaining the keywords you typed into their search engine?  

     

    You typed in “boobies” on your mom's computer and now the word pops up everytime you type a “B”!!

     

    Perhaps it was your spouses system and your were searching for evidence of pornography.

    Maybe it was your kids computer and you want to make sure they are o.k. mentally.

    Maybe your Internet connection has been down for a while and you’ve had to use your friends system or a public system.

    Whatever the case maybe it is none of my business.  And you don’t want it to be the business of the other who will use the system after you.

     

    Here are two simple techniques to get rid of those bad keywords.

     

    For Window XP “Recently Opened Documents”:

    To delete “my Recent Documents”

    Right – Click on the “Start” button

    Select “Properties”

    On the Start Menu Tab, Select “Customize”

    Select the “Advance Tab”

    Select the “Clear List” button at the bottom.  Don’t worry, it will NOT delete the files.  (Deselect the checkbox if you don’t want the system to track previously opened files)

     

     

    For Windows XP, Internet Explorer:

    In IE, Select “Tools”

    Go to “Internet Option” at the bottom of the Tools list

    Under Temporary Internet Files select “Delete Cookies” and “Delete Files”

    To delete the history of the websites you searched select “Clear History”

  • 18 Days of Reckless Computing

    Someone over at wired gives tests his new Dell to see how many viruses and how much malware it takes to get the Geek Squad to call it a total loss.

    read more | digg story