Showing posts with label hacks. Show all posts
Showing posts with label hacks. Show all posts

Monday, August 24, 2009

Hackers Put Social Networks Such as Twitter in Crosshairs

Web sites such as Twitter are becoming increasingly favored by hackers as places to plant malicious software in order to infect computers, according to a new study covering Web application security vulnerabilities.

Social-networking sites were the most commonly targeted vertical market according to a study of hacking episodes in the first half of the year. The study is part of the latest Web Hacking Incidents Database (WHID) report, released on Monday. In 2008, government and law enforcement sites were the most-hit vertical markets.

Social networks are "a target-rich environment if you count the number of users there," said Ryan Barnett, director of application security research for Breach Security, one of the report's sponsors, which also includes the Web Application Security Consortium.

Twitter has been attacked by several worms, and other social-networking platforms such as MySpace and Facebook have also been used to distribute malware. That's often done when an infected computer begins posting links on social-networking sites to other Web sites rigged with malicious software. Users click on the links since they trust their friends who posted the links, not knowing their friend has been hacked.

The WHID sample set is small, encompassing 44 hacking incidents. The report only looks at attacks that are publicly reported and those with which have a measurable impact on an organization. The WHID's data set is "statistically insignificant" compared to the actually number of hacking incidents, but shows overall attacker trends, Barnett said.

Other data showed how Web sites were attacked. The most common attack was SQL injection, where hackers try to input code into Web-based forms or URLs (Uniform Resource Locators) in order to get back-end systems such as databases to execute it. If the input is not properly validated -- and malicious code ignored -- it can result in a data breach.

Other methods used include cross-site scripting attacks, where malicious code gets push to on a client machine, and cross-site request forgery, in which a malicious command is executed while the victim is logged into a Web site.

The WHID found that defacing Web sites is still the most common motivation for hackers. However, the WHID includes the planting of malware on a Web site as defacement, which also points to a financial motivation. Hacked computers can be used to send spam, conduct distributed denial-of-service attacks and for stealing data.

Sunday, August 23, 2009

Hacking Yahoo ID

The very first thing you ppl shud understand is noone can just hack your yahoo id if you dont do something silly & stupid ...The four most common ways of Hacking Yahoo ids are ..
1.) Social Engineering
2.) Password Crackers
3.) Using Password Stealing Trojans/Keyloggers
4.) Fake Login Pages
Social Enginnering is actually nothing but trying to know your personal and confidential details and then using it to change your password ..BUT HOW? ok there's a forgot password option with Yahoo which asks for your B'day,Country & Zip Code & later your security question..Now generally lamers who try this mode of Hacking have lots of time to waste ..They will put you into some kinda friendship/emotional trap and try to get all the above mentioned information .It may take 1-2 days or even 1-2 month ...(Really I pitty on such lamers !! ).
Tip 1 : Never use your real information while registering on Yahoo(Infact don't use it anywhere on net)

Now if I talk bout a Hacker's perspective...
1.) The most common Security Question is "What's your Pet name?"..Now most of them answer it with very common pet names..I have put on a" names wordlist "in the worldlists section of the site so try those names n m sure u will crack it....Beside this some lamers confuse their NickName with Pet Names ..so if you know their Nick names u may be lucky lol :-)
2.) As far as country is concerned ..try out those countries which you have never heard of (weird names)...lol ( Probably thats what the smart victim thinks when he chooses a country...lmao) & do check Nepal,Phillipines & Bhutan..they r d most common
3.) Zip codes...123456 /007007/ ..something like this ...coz most of the smart victims are very lazy roflmao ...:-)
The second kinda Hacking attempt is done with the Help of Yahoo Password Crackers...I doubt bout their efficiency bt still some of them r lucky (other way round u r stupid lol)..Password Crackers & Password Changers use Brute Force Technique with their updated wordlists...WHAT IS BRUTE FORCE ?I'll make it simple ..it's like using all possible combinations and permutations on the available data and using it as a password ..You can download some frm the Yahoo Tools Section of the site ....Bt again it takes a hell lot of time to crack a password ....

Tip 2: Always use alphanumeric passwords and try to keep it atleast 8 characters long ..( I personally prefer 12 characters lol )
As far as Hacker's perspective is concerned...
Use the worldlist which has victims B'date,phone number,name,zipcode,lucky color,gf's name lol..words like sexy,love,cool,fun,insane,kill,hate & boss ..(You must have these personal informations or else it may take the shit out of u ..trying to hack ...).Beside this generally ppl use their vehicle number,phone number,social security number,credit card number etc as their passwords...

The third and one of the most frequently used way of hacking or stealing Yahoo password is using trojans and keyloggers ..WHAT ARE TROJANS? hmmm..read the tutorial ..I have already wrtten one ...bt still TROJANS are simple programs with a server part and the client part ..you infect the victims computer with the server part and the server then connects to the client running on your system and sends passwords and vital informations..and KEYLOGGERS are programs which record your keystrokes in a log.txt file and sends that log file to the Hacker...The two most famous Yahoo Password stealing Trojans are Magic PS 1.5 SE ++ ( u can download it from this site ... ) & Smart PS 1.5 SE ( Hmm...m trying to get it ...)...Once Infected by these trojans the infected server sends your password to the Hackers Yahoo Messenger id as PM 's ...

How to use MAGIC PS 1.5 ?
Ok download MPS.zip from this site then run the mps.exe in it ...you 'll see an user inteface...check the boxes which read"Send Password" & "Send OS name " ...and then gibe an Yahoo id on which you want the Hacked Passwords to be send ..If you want some icon on it then choose the specified icon from the list and then click "Create MPS" .A server.exe will be made in the same folder or in the temp folder in windows ....Send that file to the victim and once he executes it ..Bingo u Have Hacked him/her lol ....

Tip 3: If you see a regsvr.exe file in you windows folder then u r infected ..Also check the system folder(Win98) system 32 (WinXp)...Restart your windows in DOS Mode and delete the file or press CTRL+ALT+DEL and end that process(regsvr.exe){ Not regsvr32.exe it's a system file }or see the list of files from the combo box of MPS client reading" files after install" and then delete it if you find any of them in the windows/system32 folder.Beware sometimes the new MPS creates the server in more than 1 folder.Also look for tapi1314533.exe in your system32 folder( digits after tapi will vary) ** Only solution which will heal it permanently is to install a good antivirus(Norton 2005 /AVG updates/McAfee) are the best.

Tip 4: If u see a flash of PM window disapperaing as you login into you Yahoo & see some probs with the password field(stars changing with dots or vice-versa ).then its party time u r infected ...
Tip 5: Install a good Firewall /Anti-Hacker Program to kill all remote connections or a good freezer which cleans all fresh installations in your primary drive.
As far as Hacker's perspective is concerned...
Pack/Bind the sender.exe (server) so as to make it undetectable by antivirus and then use the flash icon or the setup icon to spoof your victim .Tell him/her that the .exe file is a software patch or some kinda fun stuff and let him/her execute that file...USE THE SEND FILE option of Yahoo messenger for this coz Yahoo mail is protected by Norton so its gonna eat up your server(If nt packed properly).You can also bind the server with some good softwares and then send it but be carefull that the properties of the MPS trojan are not changed (Try it on yourself first ....lol :) )

The last form of Yahoo Password stealing is done by using FAKE LOGIN PAGES ..Now wht the **** :-) is Fake login Page ?These are cloned pages of the real Yahoo Mail Sign in pages .They look very similar to the real conterparts and really very difficult to distinguish..Once you put inyour real id and password and press the submit button you will be either redirected to some other pasge /invalid login page but the trick had already been played by this time ..your id and password would have been mailed to the Hackers mail id by using a 3rd party SMTP server and you don't even realize that you are HACKED...
Tip 6: Always view the address bar ..If the address bar shows something like http://mail.yahoo.com or http://edit.login.yahoo.com then its the authentic page but if its something different then DONOT login.
Tip 7: Some older versions of IE support url redirecting for eg: http://mail.yahoo.com.profile=urid.123455@www.hackeme.com Now the former portion seems to be like the authentic yahoo server address but the page is being redirected to www.hackme.com so check out the URL well...
Tip8: Geocities is NOT YAHOO ..So don't get carried away ....
As far as Hacker's perspective is concerned...
Many free webhosts provide you with a feedback form option or a form mail option .So if you know a bit of HTML you can use their sever is POST ACTION = "" of the Yahoo Fake Page.Just do "Save As " of the real Yahoo page and then edit it form action section with your freeserver's address..But there's a problem..Generally these pages redirect you to THANK YOU PAGES ..So even if you manage to get the password it's of no use coz until and unless the victim is a reall ass lamer he/she would change his/her password after seeing this page ..So the best thing to do is PHP NUKE Now wats dat ?? okie you should know a bit of PHP $ <-- Values and you can code you own mailer.php and call that mailer the PHP on the submit buttons event ..Also dont forget to add some real looking HTML to your mailer the PHP ( may be a INVALID LOGIN PAGE ..)... Beside this there's always the fear of Physical Hacking ( Some one can juzz sneak in to see your password while you are typin it ) So be carefull..Some ppl do use Password Changers bt thats similar to Password Crackers which I have mentioned above.. Remember this tutorial only teaches the basic terminology behind yahoo password stealing . Hackers are always smarter than you so you never know .....

Thursday, August 6, 2009

How To Speed Up PC

Are you sick and tired of slow PC performance? Do you wish your computer run like it did when you first bought it? Since your computer is like any other machine, it needs maintenance to stay in top health. To speed up your computer ,you should use Perfect Optimizer. It is an registry cleaner that offers users a chance to restore their PCs to optimal performance. The Perfect Optimizer constitutes the industry’s leading error scan and repair technology blended with easy-to-use interface that makes the process of cleaning your registry both elegant and efficient. It can detect the corrupt paths, redundant entries, invalid file shortcuts and more that make your computer run slowly or display error messages. With Perfect Optimizer you can restore your computer to like-new condition, all with a simple click of the mouse.

Download Perfect Optimizer


3)Security - safeguards against bad ActiveX, worms, ad-popup, spyware and viruses. Eliminate malicious threats on contact using the real time scanning capabilities. You can also encrypt file, folder and disk; and block programs and malicious websites to protect your personal information like bank accounts, passwords and credit card numbers.

4)Repair Tools- Optimize your system, clean and repair windows registry, fix PC crashes and error messages, restore IE default settings

5)Speedup - include memory speedup, startup speedup, system speedup and internet speedup. These tools allow you to make your Windows computer faster, more efficient and more secure; and optimize your internet speed up to 150% by changing the reservable bandwidth limit while boosting your RAM memory.

6)Restore - Perform a full backup of your system files, registry, favorite websites, driver at any time you wish. If you encounter a system problem, backup and restore tools in Perfect Optimizer make it easier for you to keep your data safe from user error, hardware failure, and other problems.

Unfortunately Perfect Optimizer isn’t free, here you can buy it: BUY PERFECT OPTIMIZER
I recommend the following PC Optimizer to improve the speed and performance, it can make your PC faster

Rename Recycle Bin

Have you ever wondered whether it is possible to rename Recycle Bin? Of course it´s possible and in just a few steps you can do it too.Here is step by step tutorial for renaming recycle bin .

1. Click Start button then Run , Start->Run

2. In run option type regedit

3. HKEY_CLASSES_ROOT->CLSID->{645FF040-5081-101B-9F08-00AA002F954E}->ShellFolder ,you must in ShellFolder change the data value from “40 01 00 20” to “70 01 00 20“, after restart your computer ,will have the possibility to rename Recycle Bin, follow the image below



When working in the Registry Editor, be very careful, because any error can cause problems in the functioning of the operating system!!!

How To Recover Deleted Files

If you have lost important files from your harddrive and if you are sure that they have been deleted, don’t panic! Uneraser is simple software that can help. In this tutorial, we will see how Uneraser works. On this link you can download Uneraser.

For example, I delete move file on Local Disk (E:) , how to recover movie file?. It is simple

1. Run Uneraser , then select wizard , as shown below

2. When the wizard appears select “Do a lost files scan”, then click Next , as shown below

3. Select partition , where is deleted data, then click Next

4. Uneraser find my deleted movie

5. Now, just save your recover files, as shown below


Make Folders Invisible In Windows

If you have some folders that contain files you don’t want anyone else than you to see.The you should make those folders in Windows invisible. Here is step by step tutorial for creating hidden folders in windows xp.

1. Right click on the desktop>New>Folder

2.Remove the name and with the NUMPAD type 0160 while holding ALT

-Now your folder should appear unnamed and when we got that solved, we have to make the icon itself invisible to the eye:

3.Right click on the folder>Properties

4.Click the Customize tab and then Change icon

5.Just scroll a little bit and you can find here is a transparent icon

And voila; your folder is now invisible…(*just don’t forget where you put it)

Here’s a video instructional if you find it easier to follow the steps this way:

Locking your computer using sys.key

Sys.key is an interesting way to lock your computer;

1.Go to START>RUN… Type in “syskey”;

2. When the next window appears click UPDATE

3. Make sure that in the next window you select the next options

4. Before you click OK, insert the Floppy diskette;

5. Now just exit the program and restart your computer.

What we actually did with this simple tweak is a physical key you put inside a computer whenever you want to use it, the key being the diskette. It’s kinda fancy…

How To Make A Fake Virus

This is an interesting tutorial in which we will create a fake “virus” which can shutdown, restart and log off your pc(Can also write a message and specify the countdown time). This is actually a faster way to turn off your pc, ’cause it doesn’t require clicking START>TURNOFF button etc….And you can always do a little mischief by sending it to your friends.

1Create shortcut,(Right click on your desktop and go to new -> shortcut )
2)After this will appear window and that is where you type the code

There are few variants , this one will shutdown pc .
To log of computer type shutdown -l -t 300 -c “your message”
To restart computer type shutdown -r -t 300 -c ” your message”
The number after -t is the number of seconds countdown there will be before shutdown . After -c write own message , that will come up when shutdown box pops up.

3) Click Next, Finish

4) After this will appear icon on desktop, when someone click it, shutdown box will pops up.

3)How can I stop system shutdown ? Go to Start->Run , then open cmd,write shutdown -a and press ENTER on keyboard.

Here’s a video instructional if you find it easier to follow the steps this way:

How to Protect an Email Account from SPAM

Most of us get SPAM every day. Some of us get more and some little. Even a newly created email account will begin to receive spam just after a few days of it’s creation. Many times we wonder where these spam come from and why? But this question remains unanswered within ourselves. So in this post I will try my best to give every possible information about the spam and will also tell you about how to combat spam.

What is SPAM?

Spam is the abuse of electronic messaging systems (including most broadcast media, digital delivery systems) to send unsolicited bulk messages indiscriminately. Most widely recognized form of spam is email spam.

Where do these SPAM come from?

These spam come only from spammers and never from a legitimate user or a company. These spammers send a single email to hundreds (some times thousands or millions) of email addresses at a time. They either send it manually or use spambots to automate the process of spamming.

Why do spammers SPAM?

The main goal of spammers is to send the spam (unsolicited bulk messages) to as many people as possible in order to make profit. For example, John builds a small website to sell an ebook which gives information about weight loss. In order to make sales he needs publicity for his website. Instead of spending money on advertising, John decides to create an email which contains information about his site along with it’s link and send this email to say 100 email addresses in his contact list. If 1 person out of hundred buy this book john gets $10. What if he sends this email to 1000s of email addresses. He gets $100. Imagine, if he sends this email to 1 Million email addresses he gets $100000.

Now I hope you understood the idea behind spamming. So in order to make money, spammers send their advertising emails to as many people as possible without respecting the recipient’s privacy.

From where do SPAMmers get my email address?

On the Internet there exists many sites who collect the email IDs of people and sell them to spammers in bulk. Most often, people sign up for monthly newsletters and take up surveys. This is the time where these scam sites get their email addresses. Also many spammers collect email addresses by using spambots. These spambots collect email addresses from the Internet in order to build mailing lists. Such spambots are web crawlers that can gather email addresses from Web sites, newsgroups, forums, special-interest group (SIG) postings, and chat-room conversations.

Spammers also use the trick of creating Hoax Emails for gathering a huge list of email IDs. For example, a spammer sends a hoax email which says “Forward this Message to Help Severely Burned Child”. This email claims that 11 cents will be donated to the child’s family every time the message is sent to others. Most of the people believe this and start forwarding this hoax email to all of the IDs in their contact list. In this way the email spreads rapidly and eventually when it reaches the creator (spammer), the spammer gets a huge list of valid email addresses in the email header. When you get these kind of hoax emails, you can see for yourself in the email header which contains a huge list of email addresses of all those people to whom the email is being forwarded to. This is one of the effective methods used by spammers to gather email addresses.

Is SPAMming legal?

Spamming is completely illegal. Yet it is really difficult to stop spammers from spamming since they keep moving from one hosting company to another after getting banned. This makes it practically impossible to catch spammers and prosecute them.

How to protect my email account from getting SPAMmed?

The following methods can be used to combat email spam.

1. Use spam filters for your email account. If you’re using email services like Gmail, Yahoo, Hotmail etc. then spam filters are used by defaut. Each spam filter has it’s algorithm to detect spam emails and will automatically move them to SPAM folder. This keeps your inbox free from spam. However some spam emails become successful to make their way into the inbox by successfully bypassing the filters.

2. Do not post your email address in public forums, user comments and chat-rooms. Give your email address only to trustworthy websites while signing up for newsletters.

3. While taking up online surveys and filling up feedback forms, it is better not to give your personal email address. Instead singup for a dummy email account and use this for surveys and feedback forms.

4. While posting your contact email address on your website use this format: emailaddress [at] yoursite.com instead of emailaddress@yoursite.com. This protects your email address from being indexed by spambots.

5. Do not respond to hoax messages. When you receive a hoax email, avoid forwarding it to your friends. Examples of hoax messages can be found at www.hoax-slayer.com. If you really want to forward it to your friends, make sure that you use “Bcc” (blind certified copy) option to send the email. This will hide all the email IDs to which the mail is forwarded to.

I hope this helps. Pass your suggestions and feedback via comments.

Tuesday, July 21, 2009

How to hack your iPhone or iPod Touch

iPod TouchHave you ever wanted to break free from Apple’s enclosed list of apps.? Well, by simply doing the following, you will be free at last to try out other third-party apps. on your iPhone or iPod Touch.

The hackers of our generation are getting stronger and more determined as ever, and after Apple’s new 1.1.1 update that rendered unlocked iPhones useless, hackers took it personal. Therefore a group of hackers including hdm/metasploit, rezn, dinopio, drudge, kroo, pumpkin, davidc, dunham, and NerveGas have put together the “One-Touch” instant jailbreak which works with the iPhone and the iPod Touch. Basically making your device’s full disk available for use and adding Installer.app to the device, giving you access to installing almost any third-party app. on your iPhone or iPod Touch.

It’s simple to use, just open up your Safari web browser on your iPhone or iPod Touch and visit JailBreakMe.com (make sure NOT to click on this link unless you want to hack your device now!!!), after visiting the site simply read the instructions provided, then scroll down and click on the “Install AppSnapp” button. You’ve just hacked your iPhone or iPod Touch, that’s it!!!

Additional Notes: When “jailbreaking” (hacking) your device, Safari will commonly disappear and you will be brought back to the home screen, once there give it a minute for the device to restart and make sure not to touch anything at this point. Once your iPhone or iPod Touch has restarted and you get the “Slide to Unlock” screen, go ahead and unlock it and you’ll find that a new icon (Installer.app) is available on your home screen.

Also sometimes your Safari web browser will hang/stall when you activate the hack. If this happens, just press the Home button for about 5 seconds until it returns you to the home screen, then try again. Usually it’s best to use WiFi rather than EDGE when jailbreaking your device.

Advanced User Note: If you want to add SSH access to your device, then you’ll have to install the BSD subsystem, Community Sources, and then install Open SSH (you might also have to upgrade the Installer.app for this to work properly). By adding SSH/SSHFS, you’ll be able to open Finder Windows which may come in handy since you will have the ability to drag and drop files on your iPhone or iPod Touch.

The hack worked perfectly fine for me, and it only took about a minute to set up. Now I can add almost any app. I want to my iPhone and my iPod Touch. Hope you have fun with your newly hacked device!!!

Sunday, July 19, 2009

IFPI wants money from The Pirate Bay sale

The music industry will attempt to seize money paid to acquire the Pirate Bay, according to a high-level music industry source and a spokesman for the International Federation of the Phonographic Industry (IFPI), the trade group representing the music industry worldwide.

Pirate Bay co-founder Peter Sunde shows 'I owe you' note to the music industry following a judge's order that the site's founders pay the equivalent of $3.6 million.
(Credit: Mats Lewan/CNET )

Global Gaming Factory, a Swedish software company, made big news two weeks ago by announcing that it would acquire the Pirate Bay, the popular outlaw file-sharing site, for $7.8 million. Since then the company has been touting a new business model and even hiring executives, such as Wayne Rosso, the former Grokster president, to legally obtain content from film and music industries.

What remains to be seen is how that sale might be affected by attempts by the music industry to collect the $3.6 million damages that a court in Sweden awarded it in April. The court found the four operators of the Pirate Bay--Fredrik Neij, Gottfrid Svartholm Warg, Peter Sunde Kolmisoppi, and Carl Lundström--guilty of copyright violations and sentenced each to a year in jail. The court also ordered them to pay 30 million Swedish kronor ($3.6 million).

Alex Jacob, a spokesman for the IFPI, said that the group has always intended to collect the damages award, but now, should the sale go through, music execs know that the original Pirate Bay operators have access to the money.

Whether these attempts to seize part of the proceeds could hold up a sale remain unclear. The first thing to remember is that the sale isn't yet done.

According to a press release, Global Gaming's offer is to pay half of the $7.8 million in cash and the other half in the company's stock. To finance the deal, Global Gaming must issue new shares and to do that it needs the blessing of investors and board of directors. Any acquisition isn't expected to be finalized before August, the company said.

On the other side, the Pirate Bay's founders have said that they haven't owned the company for years.

"We never had any interest in earning money from the Pirate Bay," Peter Sunde told Dagens Nyheter, a Swedish newspaper. "We haven't owned TPB since the search and seizure in 2006... Those who will get the money, friends in a foreign company, have agreed as a condition to put the money in a foundation for future internet projects."

The legal adviser for Global Gaming has said that the Pirate Bay is owned by a company in the Seychelles called Reservella.

Jacob, from the IFPI, says it makes no difference who owns the Pirate Bay. He said: "The judge found the four operators guilty and ordered them to pay the damages."

That's who the IFPI will try to get the money from.

Thursday, June 11, 2009

Apple releases Safari 4 as “the fastest browser on any platform”

The final version of Safari 4 for Mac and PC desktops, released today, leaves rival browsers in the dust with a speedy JavaScript engine and standards-compliant WebKit rendering platform.

Apple announced that it has finalized Safari 4 at today’s WWDC keynote address. The browser is now available for OS X (Tiger and Leopard) as well as Windows (XP and Vista) and packs virtually no new features compared with the latest beta that has been out since late February.

Apple executives gave the most stage time to highlight Top Sites, the eye candy feature that renders thumbnails of your most visited sites mid-air, with cool reflections. However, many would be likely turning it off as it can be a significant resource hog on slower systems. While the browser lacks settings toggle for Top Sites, there are a number of Safari hacks that can turn the feature off.

On a brighter front, Apple claims that Safari 4 remains the world’s fastest web browser, citing tests that portray the browser 7.8 times faster at JavaScript interpreting than Microsoft’s Internet Explorer 8 and five times faster performance over Chrome 2. Powered by a byte-code optimized engine dubbed SquirFish Extreme, JavaScript in Safari should perform 50 percent faster when the browser is used with Snow Leopard (available in September) because the browser’s JavaScript engine runs in Snow Leopard’s 64-bit mode. An on-stage demo wowed the crowd with near-instant rendering of Google Maps, for example.



Safari 4’s WebKit rendering platform passes the Acid3 test with a 100/100 score. The test is used to measure how well a browser follows common web standards, an important factor for web developers who can rely on the browser to render web pages as intended, as opposed to spending additional time and money on putting in extra code to counter for the rendering inconsistencies. For instance, current IE8 version scores just 21/100, the least of all browsers, meaning developers need to put in IE-specific code to make the browser render pages correctly.

The presentation highlighted “crash resistance” as a new feature, stemming from the design that calls for a sandboxed environment that isolates tabs and plugins in their own processes, just like Google’s Chrome. Safari 4 also decodes QuickTime files faster due to a hardware-accelerated engine and packs a new streaming method that works with any webserver. Crash resistance will work only under Snow Leopard since it leverages new technologies that the operating system offers. The browser will come built-in with Snow Leopard.

Safari 4 also features an iTunes-like Cover Flow view of your bookmarks and browsing history and several other features previously described in my review of Safari 4 Beta.

Apple also said that the iPhone OS 3.0 software will include the latest version of mobile Safari. The company claims the browser packs three times faster JavaScript engine over mobile Safari version that ships with iPhone 2.2 firmware. In addition, it supports HTTP streaming of audio and video courtesy of

Tuesday, June 9, 2009

StrongWebmail.com gets hacked, hackers want their $10,000 prize

When you are running a service that claims to be, “The most secure email accounts on the planet”, then you have to promote that fact in some way. Telesign run the e-mail service StrongWebmail.com which proclaims that quote above and in order to prove how secure it is, they set hackers a challenge.

That challenge was called, “Break into our CEO’s email account and win $10K” and even gave the hackers his username and password for the account. The reason Telesign believe StrongWebmail.com is so secure is the fact it requires a special code to login that can only be known with a phone call, and that code changes every time you try and log in. So even with a username and password access should not be possible.

But even with that extra layer of security in place hackers claim to have already gained access to the CEO account. The hacking group sent evidence of the hack to the IDG news service including details of what was in the account on June 26 (the date Telesign wanted hackers to report upon). Telesign CEO Darren Berkovitz confirmed the information was from his account, but not that they had won as he had to check they followed the rules.

The details of the hack have not been released for obvious reasons, but it is suspected a man-in-the-middle solution was used, where the verification is bypassed by waiting for the real account owner to login and then just using that session to get the information they needed.

The group who performed the hack included Lance James, chief scientists at Secure Science, and Aviv Raff FraudAction Reasearch Lab Manager at RSA.

Monday, June 8, 2009

What is google hacking?

Google hacking is the use of a search engine, such as Google, to locate a security vulnerability on the Internet. There are generally two types of vulnerabilities to be found on the Web: software vulnerabilities and misconfigurations. Although there are some sophisticated intruders who target a specific system and try to discover vulnerabilities that will allow them access, the vast majority of intruders start out with a specific software vulnerability or common user misconfiguration that they already know how to exploit, and simply try to find or scan for systems that have this vulnerability. Google is of limited use to the first attacker, but invaluable to the second.

When an attacker knows the sort of vulnerability he wants to exploit but has no specific target, he employs a scanner. A scanner is a program that automates the process of examining a massive quantity of systems for a security flaw. The earliest computer-related scanner, for example, was a war dialer; a program that would dial long lists of phone numbers and record which ones responded with a modem handshake.

Today there are scanners that automatically query IP addresses to see what ports they have open, determine what operating system they're probably running, or determine the geographic location of the system. One of the most popular IP scanners is NMap, a free open source utility for network exploration and security auditing. When using NMap, the user specifies a range of hosts and the specific services on each one to scan for. The program will then return a list of the available (and presumably vulnerable) systems.

With a little creativity, Google can be made to operate in a similar way as NMap, even though they use different protocols. As an example, let's pretend we are intruders and we know there's an exploit that will allow us to steal credit card information from any online store that uses SHOP.TAX scripts and that www.secure.com uses SHOP.TAX. When we try our exploit, it turns out that they've already patched the vulnerability. What do we do now? We turn to Google and enter the following search string: inurl:shop.tax

Note that the above search employs advanced operators to produce a list of all sites that have "shop.tax" somewhere in their URL, essentially a list of potentially vulnerable targets. Just as with NMap, all that's left to do is try our exploit against each site on the list.

There are countless variations on this scheme, including some rather clever ways to find particular versions of server programs.

Sometimes administrators misconfigure their sites so badly, it's not even neccessary to use a "third party" exploit in order to gain access to a system. Google indexes the Web very aggressively, and unless a file is put behind in a password- or otherwise access-restricted area of a Web site, there is a good chance that it will be searchable in Google. This includes password files, credit reports, medical records, etc. In cases where the files are not adequately protected from Google, the search engine has basically already performed the exploit for the attacker.

In this way, Google can also be used as a proxy for exploits. A proxy is an intermediary system that an attacker can use to disguise his or her identity. For example, if you were to gain remote access to Bill Gates' computer and cause it to run attacks on treasury.gov, it would appear to the Feds that Bill Gates was hacking them. His computer would be acting as a proxy. Google can be used in a similar way.

The search engine has already gathered this information and will give it freely without a peep to the vulnerable site. Things get even more interesting when you consider the Google cache function. If you have never used this feature, try this:

Do a Google search for "SearchTechTarget.com." Click on the first result and read a few of the headlines. Now click back to return to your search. This time, click the "Cached" link to the right of the URL of the page you just visited. Notice anything unusual? You're probably looking at the headlines from yesterday or the day before. Why, you ask? It's because whenever Google indexes a page, it saves a copy of the entire thing to its server.

This can be used for a lot more than reading old news. The intruder can now use Google to scan for sensitive files without alerting potential targets -- and even when a target is found, the intruder can access its files from the Google cache without ever making contact with the target's server. The only server with any logs of the attack would be Google's, and it's unlikely they will realize an attack has taken place.

An even more elaborate trick involves crafting a special URL that would not normally be indexed by Google, perhaps one involving a buffer overflow or SQL injection. This URL is then submitted to Google as a new Web page. Google automatically accesses it, stores the resulting data in its searchable cache, and the rest is a recipe for disaster.

How can you prevent Google hacking?

Make sure you are comfortable with sharing everything in your public Web folder with the whole world, because Google will share it, whether you like it or not. Also, in order to prevent attackers from easily figuring out what server software you are running, change the default error messages and other identifiers. Often, when a "404 Not Found" error is detected, servers will return a page like that says something like:

Not Found
The requested URL /cgi-bin/xxxxxx was not found on this server.
Apache/1.3.27 Server at your web site Port 80

The only information that the legimitate user really needs is a message that says "Page Not found." Restricting the other information will prevent your page from turning up in an attacker's search for a specific flavor of server.

Google periodically purges it's cache, but until then your sensitive files are still being offered to the public. If you realize that the search engine has cached files that you want to be unavailable to be viewed you can go to ( http://www.google.com/remove.html ) and follow the instructions on how to remove your page, or parts of your page, from their database.

How to restore your hacked WordPress database from Google Cache through Ruby

The first thing was downloading the information from Google. I began by doing a site search (site:reganmian.net/blog) on Google. I got several pages worth of hits, and used a wonderful plugin called Antipagination for Firefox. It allows me to right-click on the “Next” button at the bottom of the screen, and choose “load all”. It will then load every single web page under each other in the same tab - it has to be seen to be believed. After all the 7 pages of Google hits (50 hits per page) had loaded, I saved the page as an html file.

This html file of course has a lot of superfluous material - all we really need are the URLs to Google’s cached versions of my pages. A quick way of picking out only the lines we want is to use grep, a command line tool. If we save the list of URLs to filelist.html, we can for example run grep reganmian.net filelist.html > filelist2.html. This will choose only the lines that contain reganmian.net (the name of my website), and put them in the new file filelist2.html (note that you should never have the same file on both sides of the > sign). If you want to exclude certain lines (for example, Google might also have listed a bunch of files ending in /trackback or /comments, or /feed, which might not be useful to you), you can also use grep -v, which only outputs the lines not matching the search string. (For example grep -v trackback filelist2.html > filelist3.html).

Now, I open filelist3.html in TextMate. TM is a great editor, with a very powerful regexp system. Regular expressions are a very powerful way of manipulating text, but it can seem quite baffling at first. Luckily, you only need to understand a few simple ways of using them - and I find it a lot easier to do a few different regexps in TM to get what I need done, than to try to craft “the ultimate” Regexp that does everything at once. (This is why I also often use grep, when I just want to select certain lines).

Basically, we want to isolate the cache URLs, so we have to look through the file and see what unique section comes immediate before the URL. We can then delete everything up to the URL. Go to find and replace, check “use regexps”. Let’s say that the line looks like this (very simplified):

Entry: Reganmian (cached) http://google.cache.com/reganmian (url) http://reganmian

We want the line to only contain http://google.cache.com/reganmian. First we remove the first part: search for ^(.*)cached) and replace with nothing (ie. remove it). Then we remove the end: search for (url)(.*)$ and again replace with nothing. ^ means the beginning of a line, and $ the end, so the first selectes everything between the beginning of the line, and the search string, etc. Holding alt down while selecting with the mouse also enables block-select, which is a great way of removing text, if the lines are aligned.

After playing with the different tools in TextMate to “clean up” the text, we should have a text file only containing a list of URLs, all of which we wish to download. Then it’s time for the superb tool wget. It’s extremely powerful, but now we will only use a small subset of the features. wget -i filelist3.html will download every single URL listed in that file.

However, Google does not like “robots” to download files, and based on the “user agent string” which says “I am wget, and I would like this file”, it will refuse all the requests. Luckily, wget knows how to lie. With this slightly longer line wget –user-agent=”Opera/9.25 (Windows NT 6.0; U; en)” -i filelist3.html, wget will pretend to be Opera, and Google will believe it, and let us download the files. However, it’s not quite over yet, because Google also becomes suspicious if you download too many files at once. In my case, it stopped me after 150 files, and called me a robot to my face. Luckily, a quick reboot of the cable modem gave me a new IP address, and I could get the last files. Another option might be to increase the delay between each file in wget’s options.

Now we have all the files. Unfortunately, they have horrible names based on the URLs, with all kinds of strange characters, that don’t play well with other programs. I used Name Mangler to rename the files to 001.html, 002.html, etc. (Using Automator.app doesn’t seem to work, because of all the strange characters).

If we just wanted a small archive of our writings, we could stop at this point. However, we don’t simply want to preserve the old pages, we want the information back into the database so that WordPress can display it dynamically, by category, by date, etc. This requires us to extract the relevant information from each page, and insert it into a WordPress database. For this, we will use Ruby.

The task is actually not that difficult, although it took me a few hours, both because I program in Ruby so seldom that I often forget the syntax for different commands, and because this kind of automatic text extraction is always a bit tedious. I could have tried to insert the data directly into the WordPress database using SQL, but it is much easier to use the XML-RPC interface metaWeblog to let WordPress update its own database (the same API that offline blog clients use).

Ruby has built-in support for XML-RPC, and I found some examples of using this with WordPress, but they didn’t show all the options, and I spent some more time trying to figure out how to include the categories (which you have to create first on the blog), and change the posting date (so it doesn’t look like they were all written today). One thing that metaWeblog doesn’t seem to support, is to change the “slug” for a post (the short web friendly name that is a part of the URL). This was a bit important for me, because I really wanted to keep the same permalinks as before, since there are already some places out there linking to certain posts. Luckily, almost all of the permalinks were automatically generated from the title when I wrote them, and with the right date, the resulting permalink should be OK. But there are a few that I changed manually, and they will now have a different permalink.