Category: I got hacked

  • Computer Viruses Monitored via Dynamic Worldmap

    You'll be able to view Previous Hour, Previous Day, Previous Month, This Year, and Previous Year. Color Coding has 6 Ranges (No Data, Quiet, Low, Medium, High, and Epidemic)

    read more | digg story

  • She Cracked my Hotmail Password: a sad shoulder surfing story

    Ever type in your password at work and notice that there is someone standing behind you watching your fingers very closely as if trying to decipher you password? This is known as “Shoulder Surfing.”

    If you don't think it is possible to eyeball someone's keystrokes and know their password, think again.

    In the '90s, I didn't know much about computers or computer security. I was a military cop well versed in physical security and air base ground defense and only used computers for screwing around. My passwords were as easy as possible so I could remember them.

    I didn't fully appreciate the importance of having a strong password until my wife hacked my Hotmail account. No big deal right… WRONG. Like I said I was screwing around. I was big into flirting in chat rooms and on email. I was just having fun with what I thought were beautiful young ladies, but who (realistically) were probably neither beautiful or young or (shedding a tear) ladies.

    I'd been spending so much time online with chatrooms and EverQuest (a.k.a EverCrack) that my wife started to get very jealous of the computer and suspected I was up to something. So she shoulder surfed me one night, got my password, and got into my account while I was at work.

    To make a long story even longer, my wife went crazy. She called my job screaming, I had to respond to my own house, my weapon was taken away (this is like being neutered for a cop), and the beautiful young lady that I was chatting with…. It was a man (yeah, it was like a cyber Crying Game). Needless to say, I don't do much of ANY chatting these days. But I digress.

    Tips to guard your hotmail account cracks, via shoulder surfers.

  • How to get Malware/Virus/Trojans on your Home Windows computer:

    1) Use Window 9x/2000/XP out of the box DO NOT bother to reconfigure it
      

    Don't create any login accounts with strong passwords
    Do all work from the adminstrator account (Windows does this out automatically  so   don't do anything)
    Do not bother with patches no matter how critical (Windows will prompt you to update, just ignore it)
    Don't disable the guest account
    Don't change the name of default administrator account
    Enable as many network protocols as you can

     

    2) Use Internet Explorer

    If you want your system to get infected with all kinds of malware DO NOT use Firefox or anytype of pop up blockers
    When you use IE, don't increase the security under: Tools | Internet Options | Security tab, just leave it as is
    Ensure all Java and ASP scripting languages are enabled, allowing other computers to load software on your computer remotely
    Never patch Internet Explorer

    3) Connect directly to the Internet

    Do not use any kind of firewall 
    Do not use Network Adress Translation (which will hide your IP adress)
    Do not load SP2 for Window XP
      

    4) Surf the deadliest sites with no protection

    Surf Serial/Crack/Warez sites and always completely trust their sites
    Porn sites with no protection
    Screen Saver sites
    “hacker sites”  not all hackers sites just “black hats” and script kiddie type sites
    Find dark IRCs
      

    5) Behavior that will help you get your system infected.

    Download Screen Savers from site you are not sure about
    Open emails from people you don't know
    If you get a Security Warning that says “Do you want to download XXXXPROCUT NAMEXXX..” Don't even bother reading the rest just click yes.
      

    6) Software that is more than likely infected

    Tools bars that automatically download without your permission
    Kazaa and some other free P2P tools

     

    List of Tools for faster Infection:

    Internet Explorer  (Firefox can affectively block malware)
    Broadband/DSL (use of a firewall using Network Adress Translation will hide you system)
    Windows 9.x/2k/XP (open source OSes such as Linux are less likely to be hacked)

     

  • ex-Guard Hacks GM by Social Engineering

    Green obtained the Social Security numbers of about 100 GM employees from the Detroit area and sent them e-mails posing as a representative of GM's company vehicle evaluation program.

    read more | digg story

  • "Windows has detected spyware infection!"

    Want to know how to get rid of the “Windows has detected spyware infection!

     

    “Your computer is infected! [tag]Windows has detected spyware infection[/tag]!
    It is recommended to use special antispyware tools to prevent data loss Windows
    will now download the most up to date antispyware for you.
    Click here to protect your computer from [tag]spyware[/tag]!”

    Here is how to delete that annoying “computer is infected” message.

    If your seeing this message your system really is infected with some [tag]malware[/tag] (virus, trojan, spyware) and that message you see is a part of the malware. This type of malware typically is trying to get you to purchase a product to clean your system. When you click on the link they provide, it takes you to the very source of the malware on your system. It is supposed to look like some of the Window system messages you can get about updates. DON’T fall for it.

    DO NOT GIVE THESE PEOPLE YOUR CREDIT CARD INFORMATION!

    This page will give your more information on what it is and how to get rid of it.

  • Security Testing on my Window 2000 system

    I've surfing on my Windows 2000 system while completely exposed to the Internet on my DMZ.  No firewalls, no anti-virus, not even a pop-up blocker.  The box is exploited immediately. 

    Many of the default configuration on a fresh Windows 2000 box are just plain ridiculous.  For example, the C$, and parts of the root are shared out on earlier versions of Windows 2000.  Message services, port 139 and other very easy to exploit applications and services are turned on by default on Windows 2000. 

    It is no wonder Windows systems are always getting taken down.  Just turning off some of those services do quite a bit to close some of the holes on Windows boxes.  With broadband getting more popular, the combination of unprotected systems and the viral marketing of malicious code are creating a storm on the Internet.  An unprotected system is rendered completely useless in a matter of weeks (days and hours if you surf porn or serial sites).

    Here are some of the vulnerabilities on Windows systems at SANS.org.

    In all honesty, if you have a good firewall, virus protection, maybe a pop-up stopper and a good security configuration you could have a Windows 98 machine and NEVER get a virus.  

  • suntzu – Hacking and the Security Professional

    suntzu

    suntzu,
    originally uploaded by elamb_blog.
    I've been hacked a few times (that I know of). As a security professional, it is my belief that being hacked (or hacking… ethically) is the best way to learn about phishing, social engineering, buffer overflows, denial of service attacks, malware etc.

    Unfortunately, a lot of “information security professionals” don't know anything about what hacking is or what hackers are all about. The term “hacker” is not always a criminal activity. Information Security professionals should have exposure to hacking like cops have exposure to drugs.

    Of course, some information security professionals don't have anything to do with hacking or anything technical (as Martin McKeay has pointed out to me). My point is that all Security Professionals (including cops, investigators, even Infantry) should know their enemies and their enemies tactics.

    Like a detective knowing the criminal mind.

    It was Sun Tzu, ancient Chinese warrior, author of The Art of War, that said that you must “know your enemy” before going into battle. If “you know your enemy and know yourself,” he wrote, “you need not fear the result of a hundred battles.” Sun Tzu went on to say, “If you know yourself but not the enemy, every victory gained you will also suffer a defeat.”

    And that is why I love going to Defcon. There is every spectrum of computer security aficionado.

    http://elamb.blogharbor.com/hacked/igothacked.htm

  • PS Guard Removal

    PS Guard is viscious scareware that loads itself each time you attempt
    to unistall it.  It is malware that claims to be malware
    remover.  It disables your Task Manager, informs you that your
    system is infected and doesn't allow you to exit from it while it scans
    your computer for viruses.

    Removing PS Guard
    it is a bit tricky.  Adaware and Hijack this will do nothing to
    remove it.  Noahdfear over at GeekstoGo.com wrote a sweet little
    script to remove it called smitrem.  It does the trick in removing PS Guard

    I picked it up at some Russian warez site on my Honeypot sytem.

  • Yet another university hacked for personal records

    College networks are always getting owned.  Why is that?  You'd think that these haven for some of the greatest developing minds in the country would be like digital fortresses with a battalion of young Internet hardened GEEKS patroling the college data 24/7.

    This is a sign that even though security awareness has risen people still are not taking it seriously. 

    POMONA – Computer hackers added Cal Poly Pomona to a growing list of schools from which personal information has been accessed illegally. Notification went out to 31,077 people Thursday that their records might have been stolen after Cal Poly Pomona discovered two computer servers were compromised in late June…

    read more | digg story