Category: Main Digg

  • Analyzing 20,000 MySpace Passwords

    In a day where browsers are coming out with anti-phising tactics, I can not believe how many people still fall for phising. It’s all over the news, and most email clients display warnings. So when I got an email from “Admin@MySpace.com” I kind of chuckled.

    I have a friend who is constantly getting her MySpace account hacked.  There seem to be lots of security issues in MySpace.

    read more | digg story

  • HOW TO: Bypass Windows Genuine Advantage!

    How to bypass Windows Genuine Advantage easily without patches or scripts in only a few steps. This is EXTREMELY EASY to do, and works!! What a big hole in trying to authenticate your Windows.

    read more | digg story

  • Information Security Gurus: Say Goodbye Mr. Network Geek

    “Information Security workers have found themselves caught up in this wave of change. Originally, it was an important and vital job to track down the current virus threats, manage the Service Packs in [Pick your Windows flavor here], install the few hotfixes needed and call it a day. The rest of our time was spent on the important matters – defining”

    The “wave of change” keeps me employed, but I must agree with Karn at Security-Guru.blogspot. There is a lot of times that I’m just playing “wack a mole” with security problems. The root of the problem needs to be taken care of.

    There is a movement of more proactive security instead of the old losing reactive security:


    – At Defcon Rick Wesson of Support Intelligence, LLC introduced a method of tracking botnets, and black listed malware server globally and in real-time.
    – Microsoft is heading up a proactive security project called Strider HoneyMonkey Exploit Detector. It is a kind of active honeypot that follows the links of malicious sites to find new exploits.

    read more | digg story

  • Hackers Post Code for New IE Attack

    Hackers have discovered a new vulnerability in Internet Explorer, and they’ve released code that could be used to attack users of Microsoft’s popular browser.

    Some of the hacks are really good.

    read more | digg story

  • ATM Reprogrammed to Give Out 4X More Money

    13 Sept 06 – VIRGINIA BEACH

    Last month, a man reprogrammed an automated teller machine at a gas station on Lynnhaven Parkway to spit out four times as much money as it should.

    No one noticed until nine days later, when a customer told the clerk at a Crown gas station that the machine was disbursing more money than it should. Police are now investigating the incident as fraud.

    Police spokeswoman Rene Ball said the first withdrawal occurred at 6:17 p.m. Aug. 19. Surveillance footage documented a man about 5-foot-8 with a thin build walking into the gas station on the 2400 block of Lynnhaven Parkway and swiping an ATM card.

    The man then punched a series of numbers on the machine’s keypad, breaking the security code. The ATM was programmed to disburse $20 bills. The man reprogrammed the machine so it recorded each $20 bill as a $5 debit to his account.

    read more | digg story

  • What is a Hacker?

    “A hacker is someone who thinks outside the box. It’s someone who discards conventional wisdom, and does something else instead. It’s someone who looks at the edge and wonders what’s beyond. It’s someone who sees a set of rules and wonders what happens if you don’t follow them. A hacker is someone who experiments with the limitations of systems for intellectual curiosity.”
    The above is a quote from crypto living legend Bruce Shneier’s book, Beyond Fear.  This is exactly how I feel about hacking.  Hacking is a major asset to Information System Security… if fact is THEE only real asset.  I’ve had arguements with some of my peers about this.  Information Security Pro vs. Hacker.  If the typical information system security pro doesn’t get smart on hacking (security/programming) techniques, security will continue to be a losing battle.  Cyber criminals have no problem learning the latest exploits, they have no boundaries and this gives them a “superpower” against security professionals.  Some Information security professionals, on the otherhand, restrict themselves by categorizing hacking as bad.  They see it as unethical and not responsible. 

    It is unethical and not responsible to NOT know hacking techniques that might exploit a customers system.

    Thanks for the post Bruce.  I hope you will make another appearance at the Defcon. 
    read more | digg story

  • One of the more ironic Windows errors.

    Windows is closing down the application that would normally patch the security holes. For your security. So does that mean you need a patch for the patching system. Or maybe your should patch the entire Window operating system with Linux.

    read more | digg story

  • Great anti RFID site

    Welcome to the world of “Spychipping”! How the government and major corporations are planning to track your every move. Privacy is a thing of the past. You don’t need it right… its not like you have something to hide.

    News related to RFID privacy issues and resources.

    read more | digg story

  • Hackers gain private information on all 642,720+ Second Life users

    Linden Labs has forced a password reset for every one of its 642,720+ residents after it was revealed hackers gained access to the entire user database. Customer service will not begin to address password issues until Monday, September 11.

    (the news story link is a “blog” because that is the “official” lines of communications from Linden Labs)

    read more | digg story

  • Guy Pranks Craigstlist Posts Ad as a Girl

    “This guy posted a Ad as a girl on Craigslist and gets many responses with pictures, cell phone numbers, real names and some emailed from work accounts such as .mil .. dumb asses :)”

    Lessons learned for n00bs online: You can’t trust everyone you meet online. They can post pictures, give you phone numbers, addresses, talk real nice, and seem to have lots in common with you but that doesn’t really mean anything because all that stuff can be falsified. I’ve met lots of cool people online, but I’ve also met a couple of sick, sad and even evil individuals. Bottom line is that you have to be a little conservative with your trust when online.

    read more | digg story