<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7467851609734946622</id><updated>2012-01-26T03:01:27.875-05:00</updated><category term='exports'/><category term='cipher'/><category term='web app'/><category term='protocol'/><category term='solution'/><category term='logs'/><category term='Taylor series'/><category term='bug'/><category term='vulnerability'/><category term='free'/><category term='certifications'/><category term='device'/><category term='instructor'/><category term='DefCon'/><category term='ARC4'/><category term='processing centers'/><category term='rat'/><category term='lawyer'/><category term='EPCA'/><category term='chain mail letter'/><category term='SonicWALL'/><category term='RSA Challenge'/><category term='boot up'/><category term='message'/><category term='AI'/><category term='IP addresses'/><category term='compromise'/><category term='Debugging'/><category term='online poker'/><category term='registration'/><category term='evil'/><category term='keystrokes'/><category term='seed'/><category term='BIOS'/><category term='exchange'/><category term='substitution'/><category term='probation officer'/><category term='New York'/><category term='rates'/><category term='lap dances'/><category term='vice president'/><category term='brute force'/><category term='Linksys'/><category term='policy'/><category term='guest'/><category term='chat room'/><category term='experiment'/><category term='social security number'/><category term='NSS'/><category term='CAS'/><category term='online'/><category term='DECAF'/><category term='AdSense'/><category term='anonymous'/><category term='desktop'/><category term='Booz Allen'/><category term='factorization'/><category term='entry point'/><category term='wincrypt.h'/><category term='software updates'/><category term='Spyro'/><category term='power'/><category term='white hat'/><category term='Internet Explorer'/><category term='Broadcom'/><category term='home page'/><category term='trialware'/><category term='ITU'/><category term='bookmarks. Faster'/><category term='GeForce'/><category term='OSI'/><category term='compiler'/><category term='convict'/><category term='guards'/><category term='shut down'/><category term='cryptography'/><category term='decrypt'/><category term='braviax'/><category term='list'/><category term='month'/><category term='SiteScan'/><category term='Gigabytes'/><category term='start menu'/><category term='CA'/><category term='key escrow'/><category term='search engine'/><category term='analog'/><category term='Link Crawler'/><category term='hacking'/><category term='hexadecimal'/><category term='military'/><category term='ripper'/><category term='Objective C'/><category term='IPSec'/><category term='Miley Cyrus'/><category term='lft'/><category term='tasks'/><category term='executable'/><category term='spy'/><category term='Hackulous'/><category term='leecher'/><category term='arrest'/><category term='court'/><category term='DES'/><category term='computer'/><category term='Notepad++'/><category term='services'/><category term='productivity'/><category term='code'/><category term='web server'/><category term='MC-10'/><category term='admin account'/><category term='gangs'/><category term='lincese fee'/><category term='hack'/><category term='Plenty of Fish'/><category term='exam'/><category term='KMIP'/><category term='wiretap'/><category term='cookies'/><category term='UNIX operating system'/><category term='bills'/><category term='startup'/><category term='stealing'/><category term='PowerPoint'/><category term='Puls'/><category term='degree'/><category term='Scull Security'/><category term='cameras'/><category term='filters'/><category term='click'/><category term='KEK'/><category term='Taiwan'/><category term='secret question'/><category term='illegal'/><category term='Boycott Brazil'/><category term='low orbit ion cannon'/><category term='P2P'/><category term='port scanning'/><category term='holes'/><category term='replacement'/><category term='Windows Task Manager'/><category term='asymmetric'/><category term='encoding'/><category term='Unswindle'/><category term='trading'/><category term='Phrack'/><category term='domain name'/><category term='password recovery'/><category term='web apps'/><category term='web developers'/><category term='WebKit'/><category term='rumor'/><category term='Richard Stallman'/><category term='flat fee'/><category term='encryption'/><category term='Shaw'/><category term='Enigma'/><category term='Code Complete'/><category term='antispyware'/><category term='per use'/><category term='performance'/><category term='credit cards'/><category term='kills'/><category term='activation'/><category term='mute'/><category term='private keys'/><category term='desktop icons'/><category term='ciphers'/><category term='law enforcement'/><category term='John Lambros'/><category term='thieves'/><category term='reverse engineer'/><category term='SANS'/><category term='Port knocking'/><category term='Adeona'/><category term='diff eq'/><category term='scan'/><category term='filter'/><category term='bankruptcy'/><category term='WEP'/><category term='3-D'/><category term='hacked'/><category term='PRNG'/><category term='errors'/><category term='subject line'/><category term='classified'/><category term='suspend'/><category term='chess'/><category term='wireless router'/><category term='bail'/><category term='complex'/><category term='gun'/><category term='Task Manager'/><category term='user ID'/><category term='bummies'/><category term='karma'/><category term='pilots'/><category term='fast'/><category term='Craft'/><category term='crack'/><category term='key tables'/><category term='TCP/IP'/><category term='pirated'/><category term='Steve Wozniak'/><category term='FIOS'/><category term='assembly'/><category term='GnuPGP'/><category term='DSA'/><category term='browsers'/><category term='Gentoo'/><category term='FIDE'/><category term='download'/><category term='developers'/><category term='revocation list'/><category term='MIPS'/><category term='PGP'/><category term='greatbuybooks'/><category term='rumors'/><category term='anonymous remailer'/><category term='script'/><category term='spell check'/><category term='Kazaa'/><category term='defrag'/><category term='DD-WRT'/><category term='Yahoo'/><category term='PerMonks'/><category term='3DES'/><category term='key'/><category term='IDEA'/><category term='vi'/><category term='Eric Raymond'/><category term='Digby'/><category term='search results'/><category term='tabs'/><category term='process'/><category term='goals'/><category term='monitoring'/><category term='instant messaging'/><category term='companies'/><category term='Kevin Mitnick'/><category term='denial of service'/><category term='public keys'/><category term='cap'/><category term='RFDPI'/><category term='cores'/><category term='certificate authority'/><category term='throughput'/><category term='digital'/><category term='C programming language'/><category term='Learning Tree'/><category term='FAQ'/><category term='AES'/><category term='Scrooge'/><category term='bugs'/><category term='debit'/><category term='rent'/><category term='Windows'/><category term='The Pirate Bay'/><category term='RSA'/><category term='Data Protect'/><category term='war'/><category term='prime'/><category term='Internet Explorer 6'/><category term='denial of servie'/><category term='Cryptoki'/><category term='job'/><category term='cracking'/><category term='copy'/><category term='Mobidedrm'/><category term='Internet Access'/><category term='apps'/><category term='torrent'/><category term='Bleeping Computer'/><category term='researchers'/><category term='redirect'/><category term='covert projects'/><category term='leverage'/><category term='lock down'/><category term='voting'/><category term='system'/><category term='Windows Vista'/><category term='price'/><category term='sieve'/><category term='S/MIME'/><category term='Tumblr'/><category term='froze'/><category term='Runtime error 216'/><category term='fee'/><category term='Playboy'/><category term='root'/><category term='industry'/><category term='social security numbers'/><category term='beta'/><category term='problems'/><category term='public defender'/><category term='text'/><category term='phone numbers'/><category term='consumption'/><category term='Darkreverse'/><category term='signing'/><category term='marketing'/><category term='EWG'/><category term='network'/><category term='structures'/><category term='Adrian Lamo'/><category term='overwrite'/><category term='V8'/><category term='content'/><category term='sharding'/><category term='cryptoSPI'/><category term='comment'/><category term='skills'/><category term='web page'/><category term='mask'/><category term='key server'/><category term='advertising'/><category term='non-negotiable'/><category term='ISP'/><category term='gangsters'/><category term='encrypt'/><category term='refusal'/><category term='Deitel'/><category term='fansite'/><category term='arcade'/><category term='hh86'/><category term='Afganistan'/><category term='CUDA'/><category term='virtual machine'/><category term='troops'/><category term='suspicious'/><category term='manufacturer'/><category term='Triple DES'/><category term='Facebook'/><category term='envelopes'/><category term='URLs'/><category term='Prey'/><category term='symmtric'/><category term='recovery'/><category term='finger'/><category term='DocX'/><category term='revival'/><category term='disabled'/><category term='steal'/><category term='championship'/><category term='quiz'/><category term='Google'/><category term='Avril Lavigne'/><category term='pay'/><category term='copyright'/><category term='Caesar cipher'/><category term='identity'/><category term='IPV6'/><category term='web site'/><category term='SSID'/><category term='calculator'/><category term='install'/><category term='GPU'/><category term='The Sun'/><category term='viruses'/><category term='stream cipher'/><category term='square root'/><category term='brute force attack'/><category term='BSD license'/><category term='keys'/><category term='car destruction'/><category term='poker'/><category term='web crawler'/><category term='crawl'/><category term='Kimble Goes to Monaco'/><category term='SQL injection'/><category term='USENET'/><category term='LOD'/><category term='screen scraper'/><category term='motel'/><category term='Wikileaks'/><category term='champion'/><category term='PDFSharp'/><category term='emotion'/><category term='e-mail'/><category term='web service'/><category term='link'/><category term='root passwords'/><category term='MD5'/><category term='offense'/><category term='legitimate'/><category term='FU'/><category term='blogs'/><category term='laptop'/><category term='Homebrew'/><category term='issuer'/><category term='personal information'/><category term='Downadup'/><category term='certificates'/><category term='threads'/><category term='SETI'/><category term='msconfig'/><category term='USSG'/><category term='floating'/><category term='WPA'/><category term='security'/><category term='Pirate Bay'/><category term='cheese'/><category term='DLL'/><category term='Avril Bandaids'/><category term='acidstorm'/><category term='robots'/><category term='Blogger'/><category term='game'/><category term='SAML'/><category term='forensics'/><category term='hacker'/><category term='hiring'/><category term='tap water'/><category term='farecard'/><category term='online crime'/><category term='resume'/><category term='exploits'/><category term='Iceland'/><category term='UAC'/><category term='key ring'/><category term='HTML'/><category term='session'/><category term='Secutiy+'/><category term='Visual C++'/><category term='JavaScript'/><category term='zero day'/><category term='office work'/><category term='127.0.0.1'/><category term='Insomniac'/><category term='app store'/><category term='A Team'/><category term='organization'/><category term='CISSP'/><category term='variants'/><category term='conference'/><category term='Nvidia'/><category term='transactions'/><category term='Spokeo'/><category term='cracked'/><category term='chat'/><category term='ZRTP'/><category term='domain'/><category term='CBC'/><category term='Visanet'/><category term='get even'/><category term='fence'/><category term='connections'/><category term='page file'/><category term='vacation'/><category term='2600 Magazine'/><category term='BOINC'/><category term='programming'/><category term='attacks'/><category term='backups'/><category term='e'/><category term='ballot'/><category term='Hacktivist'/><category term='harass'/><category term='network interface'/><category term='break in'/><category term='combination'/><category term='PKI'/><category term='CreateFile'/><category term='blue tooth'/><category term='handshake'/><category term='hard drive'/><category term='CISSO'/><category term='dictionary'/><category term='Zero For Owned'/><category term='password'/><category term='identity theft'/><category term='distribution'/><category term='toolkit'/><category term='Assembly language'/><category term='lawyers'/><category term='customer'/><category term='PayPal'/><category term='Blockbuster'/><category term='McAfee'/><category term='surveillance'/><category term='AdWords'/><category term='Masters of Deception'/><category term='cookie'/><category term='vulnerabilities'/><category term='forged address'/><category term='VPN'/><category term='acceptable use'/><category term='scams'/><category term='personality'/><category term='the suits'/><category term='2600'/><category term='Vigenère'/><category term='junk mail'/><category term='Solaris'/><category term='Kari'/><category term='attorney'/><category term='email'/><category term='overclocked'/><category term='Marble'/><category term='Red Team'/><category term='greed'/><category term='protection'/><category term='rant'/><category term='patch'/><category term='CSP'/><category term='LOIC'/><category term='Zeus crimeware toolkit'/><category term='decoder'/><category term='SSH'/><category term='Wireshark'/><category term='Free BSD'/><category term='graphics'/><category term='insurance policy'/><category term='reinstall'/><category term='registrar'/><category term='Fixboot'/><category term='the hole'/><category term='SDK'/><category term='organizers'/><category term='reroute'/><category term='bandwidth'/><category term='IP Address'/><category term='Rrrola'/><category term='CIA'/><category term='statistics'/><category term='Real Networks'/><category term='defense'/><category term='Diffie-Hellman'/><category term='disable'/><category term='MBR'/><category term='.NET'/><category term='Kasper Graversen'/><category term='tcpdump'/><category term='Microsoft'/><category term='Selenium'/><category term='X.25'/><category term='reporters'/><category term='reverse engineering'/><category term='Chinese'/><category term='documentary'/><category term='Tavis Ormandy'/><category term='demo'/><category term='AVG'/><category term='VGA'/><category term='OS X'/><category term='The Jester'/><category term='porn'/><category term='Fight Club'/><category term='specs'/><category term='n00b'/><category term='Phiber Optic'/><category term='solid state disk'/><category term='engineering notebook'/><category term='IRC'/><category term='electronic control units'/><category term='Cache Poisoning'/><category term='slave'/><category term='clickjacking'/><category term='county jail'/><category term='source control'/><category term='ElGamal'/><category term='SSL'/><category term='S-HTTP'/><category term='update'/><category term='tricks'/><category term='Coding the Wheel'/><category term='backdoor'/><category term='crypt32'/><category term='NYC Police Department'/><category term='blackmail'/><category term='peer to peer'/><category term='video camera'/><category term='program'/><category term='music'/><category term='who'/><category term='P1619'/><category term='elliptical curve cryptography'/><category term='regex'/><category term='PHP'/><category term='antenna'/><category term='words'/><category term='trick'/><category term='check in'/><category term='virus'/><category term='source code'/><category term='Starlogger'/><category term='static encryption'/><category term='standards'/><category term='Rijndal'/><category term='lab'/><category term='DSS'/><category term='DotNetZip'/><category term='management'/><category term='VOIP'/><category term='DOS'/><category term='hacker conferences'/><category term='college class'/><category term='Wordpress'/><category term='ATM'/><category term='Pi'/><category term='restart'/><category term='web'/><category term='loan'/><category term='PPTP'/><category term='ASN.1'/><category term='C'/><category term='radiation'/><category term='RSA Data Security'/><category term='m botnet'/><category term='chemicals'/><category term='mathemeticians'/><category term='puzzle'/><category term='rip off'/><category term='phone'/><category term='hijacked'/><category term='OID'/><category term='Comcast. Downloads'/><category term='Dark Reading'/><category term='keygen'/><category term='programmers'/><category term='sales'/><category term='attributes'/><category term='credit'/><category term='PKCS'/><category term='installer'/><category term='Breakpoint 2008'/><category term='app'/><category term='firmware'/><category term='registry DB'/><category term='IMified'/><category term='freelance'/><category term='TOS'/><category term='backup'/><category term='simulation'/><category term='SMS'/><category term='robots.txt'/><category term='tracking'/><category term='URL'/><category term='college'/><category term='XML'/><category term='cracker'/><category term='TOR'/><category term='online fraud'/><category term='broker tips'/><category term='boring'/><category term='I/O'/><category term='stalkers'/><category term='wincrypt'/><category term='wireless network'/><category term='SSN'/><category term='surveilance'/><category term='hacker web sites'/><category term='thesaurus'/><category term='exploit'/><category term='certificate policy'/><category term='grandmaster'/><category term='Twitter'/><category term='sentence4'/><category term='calculator hackage'/><category term='scanners'/><category term='search engines'/><category term='intruder'/><category term='digest'/><category term='handles'/><category term='signature'/><category term='packet inspection'/><category term='PKCS #7'/><category term='black box testing'/><category term='press'/><category term='MAC'/><category term='Fannie Mae'/><category term='Waledac'/><category term='ID Theft'/><category term='4chan'/><category term='social networking'/><category term='delete'/><category term='analysis'/><category term='tokenization'/><category term='browser'/><category term='foe'/><category term='Labbu'/><category term='cryptanalysis'/><category term='underground'/><category term='customer support'/><category term='key generator'/><category term='L0j1k'/><category term='coins'/><category term='count'/><category term='MLM'/><category term='accounts'/><category term='operating system'/><category term='incriminate'/><category term='Delae'/><category term='CERT'/><category term='crash'/><category term='decoding'/><category term='Internet'/><category term='Hack Day'/><category term='views'/><category term='culture'/><category term='RNG'/><category term='gift card'/><category term='Java'/><category term='DoD 5220.22-M'/><category term='UltraEdit'/><category term='signals'/><category term='MIT'/><category term='time'/><category term='White Hat Hackers'/><category term='hi tech'/><category term='free software'/><category term='Angband'/><category term='MITRE'/><category term='antivirus'/><category term='Altair'/><category term='ethical hacking'/><category term='boot sector. Emulator'/><category term='indexing bot'/><category term='teens'/><category term='traffic'/><category term='clean'/><category term='threats'/><category term='checksum'/><category term='house arrest'/><category term='Dummies'/><category term='Fortezza'/><category term='transport'/><category term='antivirus software'/><category term='development'/><category term='hashes'/><category term='malware'/><category term='robot'/><category term='hash'/><category term='Dan Kaminsky'/><category term='female bloggers'/><category term='service'/><category term='Microsoft SQL Server'/><category term='post office box'/><category term='RethinkDB'/><category term='FasterFox'/><category term='free site'/><category term='spelling'/><category term='900 number'/><category term='BitTorrent'/><category term='complaints'/><category term='noobs'/><category term='Hip Hop'/><category term='C2'/><category term='spam'/><category term='security clearance'/><category term='CCC'/><category term='video'/><category term='priority'/><category term='Luhn algorithm'/><category term='drone'/><category term='scanner'/><category term='real time'/><category term='new job'/><category term='winword'/><category term='Fed Ex'/><category term='rubico'/><category term='Denial of Service attack'/><category term='authentication'/><category term='central server'/><category term='intro'/><category term='Avenger PS3 controller'/><category term='information'/><category term='FBI'/><category term='TKIP'/><category term='format'/><category term='STU-III'/><category term='luck'/><category term='SKIPJACK'/><category term='USB'/><category term='block cipher'/><category term='iPhone'/><category term='code groups'/><category term='tracker'/><category term='optimization'/><category term='worm'/><category term='Netscape'/><category term='brokerage'/><category term='Midnight Deadline'/><category term='DDOS'/><category term='military patches'/><category term='security appliance'/><category term='challenge'/><category term='0day'/><category term='symmetric'/><category term='Malwarebytes'/><category term='UINX'/><category term='English'/><category term='Brigitte Dale'/><category term='Rustock'/><category term='manipulation'/><category term='secure'/><category term='elliptical curves'/><category term='Lockdown'/><category term='submission'/><category term='crimes'/><category term='Fast Company'/><category term='shell'/><category term='spyware'/><category term='access'/><category term='DVD'/><category term='firewall'/><category term='attack vectors'/><category term='blocked'/><category term='aggregator'/><category term='artificial intelligence'/><category term='free tools'/><category term='comments'/><category term='hardware'/><category term='router'/><category term='Amazon Kindle for PC'/><category term='speed'/><category term='ACM'/><category term='SPTH'/><category term='standby'/><category term='NSA Suite B'/><category term='account number'/><category term='appeal'/><category term='highlight'/><category term='administrator'/><category term='remote'/><category term='sides'/><category term='evil plans'/><category term='phone home'/><category term='bookmarks'/><category term='donation'/><category term='ego'/><category term='botnet'/><category term='concentration'/><category term='inmates'/><category term='X Factor'/><category term='signing key'/><category term='X509'/><category term='essay'/><category term='secure shell'/><category term='Dale Carnegie'/><category term='wireless'/><category term='servers'/><category term='Active Directory'/><category term='Linux'/><category term='disclosure'/><category term='web cam'/><category term='data entry'/><category term='snitch'/><category term='cash'/><category term='SHA-1'/><category term='Ubuntu'/><category term='score'/><category term='DCMA'/><category term='Zed Shaw'/><category term='HTTPS'/><category term='system tray'/><category term='downvote'/><category term='RC2'/><category term='Julian Assange'/><category term='registry'/><category term='bug fix'/><category term='fingerprint'/><category term='ads'/><category term='IDs'/><category term='xterm'/><category term='soundtrack'/><category term='algorithm cipher'/><category term='localhost'/><category term='quality assurance'/><category term='test'/><category term='MSDN'/><category term='psychology'/><category term='popup'/><category term='DRM'/><category term='Love Boat'/><category term='Crypto API'/><category term='Ron Bower'/><category term='Y-Cruncher'/><category term='raid'/><category term='notes'/><category term='buffers'/><category term='interactive'/><category term='fired'/><category term='undo'/><category term='Aurora Stinger'/><category term='rip'/><category term='Sony'/><category term='snatch up'/><category term='Gmail'/><category term='Adobe update'/><category term='script kiddies'/><category term='Slowloris'/><category term='PRTK'/><category term='algorithm'/><category term='online banking'/><category term='links'/><category term='ZF05'/><category term='construction'/><category term='Kim Dotcom'/><category term='whois'/><category term='directories'/><category term='digital signatures'/><category term='certificate'/><category term='dirty deeds'/><category term='proxies'/><category term='JavsScript'/><category term='automation'/><category term='plugins'/><category term='UNIX'/><category term='cease and desist'/><category term='Hacking Exposed'/><category term='delays'/><category term='network ports'/><category term='cache'/><category term='passwords'/><category term='DOJ'/><category term='enveloping'/><category term='piracy'/><category term='phone systems'/><category term='RC5'/><category term='zine'/><category term='criminals'/><category term='Windows Live'/><category term='manager'/><category term='overflow'/><category term='3G'/><category term='COFEE'/><category term='C++'/><category term='processes'/><category term='AccessData'/><category term='Spassky'/><category term='verdict'/><category term='Big Brother'/><category term='STS'/><category term='black ops'/><category term='python'/><category term='Mozilla'/><category term='telnet'/><category term='random numbers'/><category term='parallel'/><category term='swords'/><category term='Android'/><category term='sentence'/><category term='database'/><category term='prodigy'/><category term='court order'/><category term='NSA'/><category term='tech'/><category term='disguise'/><category term='web pages'/><category term='transaction ID'/><category term='RC4'/><category term='static'/><category term='break'/><category term='communication'/><category term='book'/><category term='blog'/><category term='McAffee'/><category term='CodeMeter'/><category term='malicious code'/><category term='password1'/><category term='counsel'/><category term='Legion of Doom'/><category term='asymmetric encryption'/><category term='RFID'/><category term='token'/><category term='WiFi'/><category term='profile'/><category term='money'/><title type='text'>Black of Hat</title><subtitle type='html'>Writing progs to achieve questionable ends.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default?start-index=101&amp;max-results=100'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>269</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3169946262829573303</id><published>2012-01-26T02:54:00.002-05:00</published><updated>2012-01-26T03:01:27.883-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Data Protect'/><category scheme='http://www.blogger.com/atom/ns#' term='Kimble Goes to Monaco'/><category scheme='http://www.blogger.com/atom/ns#' term='Kim Dotcom'/><title type='text'>Lifestyle of Megaupload's Founder</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-6ZCRUNGTLlI/TyEGyXZ1BiI/AAAAAAAAAkU/vE285Is4sW4/s1600/KimDotcom.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 210px; height: 320px;" src="http://2.bp.blogspot.com/-6ZCRUNGTLlI/TyEGyXZ1BiI/AAAAAAAAAkU/vE285Is4sW4/s320/KimDotcom.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5701846065573332514" /&gt;&lt;/a&gt;There has been a lot of buzz about the takedown of Megaupload. Today I read up on the history of its founder Kim Schmitz. This guy has a lot of aliases. His handle is Kimble. He had his name legally changed to Kim Dotcom (LOL). He also had a passport with the name Kim Tim Jim Vestor (WTF?).&lt;br /&gt;&lt;br /&gt;Kimble was a self proclaimed German hacker. He founder a security company called Data Protect. Kimble made some cash when he sold most of the company. He was convicted of insider trading when hyping then selling shares of another company.&lt;br /&gt;&lt;br /&gt;Kimble is a big boy. He is 6 foot 4 or mote. He once produced a video called Kimble Goes to Monca. It hyped up his extravagant lifestyle with fast cars and hot women. Not all of Kimble's image is hype. He did create his Megacar luxury car system, which unfortunately did not sell well. He also formed a group of hackers to combat terrorism.&lt;br /&gt;&lt;br /&gt;Kimble seemed to have got around a bit. He moved to Thailand for a while, where he created a bunch of companies. Most recently he tried to move to New Zealand. There were problems obtaining property. The country apparently does due diligence on its visitors. Let's circle back to the beginning. Megaupload actually made money with its premium download offering. Investigators estimate that since its beginning, the company has brought in $175M. That's no joke. It seems the guy is pretty much history now.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3169946262829573303?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3169946262829573303/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3169946262829573303' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3169946262829573303'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3169946262829573303'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2012/01/lifestyle-of-megauploads-founder.html' title='Lifestyle of Megaupload&apos;s Founder'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-6ZCRUNGTLlI/TyEGyXZ1BiI/AAAAAAAAAkU/vE285Is4sW4/s72-c/KimDotcom.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-4451249952707594548</id><published>2012-01-22T18:11:00.002-05:00</published><updated>2012-01-22T18:15:37.580-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='blackmail'/><category scheme='http://www.blogger.com/atom/ns#' term='spy'/><category scheme='http://www.blogger.com/atom/ns#' term='video camera'/><title type='text'>Pervert Hackers</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-ltekzVyqbyc/TxyXugd8dOI/AAAAAAAAAkI/xCj2o-hG384/s1600/Undress.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 282px;" src="http://1.bp.blogspot.com/-ltekzVyqbyc/TxyXugd8dOI/AAAAAAAAAkI/xCj2o-hG384/s320/Undress.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5700598053589513442" /&gt;&lt;/a&gt;I keep reading about this hacker dude who was able to spy on girls' video cameras. He somehow found a way to take over their computers and turn their web video cameras on. The bad boy caught girls stripping and pleasuring themselves and all kind of other goodies.&lt;br /&gt;&lt;br /&gt;The cops got onto the perp when he started blackmailing his victims. He tried to get them to make sex videos for him or something. WTF? Dude should have just got his jollies spying the girls. He even said he was onto a new hack that would enable the video camera without the camera light coming on.&lt;br /&gt;&lt;br /&gt;Instead the feds busted in and nabbed the guy with all his computer equipment. Turns out the dude was a victim of a drive by and ended up in a wheelchair. Didn't matter. The judge thew the book at him. Scum gotta pay, disabled or not.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-4451249952707594548?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/4451249952707594548/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=4451249952707594548' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4451249952707594548'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4451249952707594548'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2012/01/pervert-hackers.html' title='Pervert Hackers'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-ltekzVyqbyc/TxyXugd8dOI/AAAAAAAAAkI/xCj2o-hG384/s72-c/Undress.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-2867869871441093228</id><published>2012-01-05T01:52:00.003-05:00</published><updated>2012-01-05T01:58:11.067-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='hacked'/><category scheme='http://www.blogger.com/atom/ns#' term='Bleeping Computer'/><title type='text'>Win 7 Internet Security 2012</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/--oR3zIDvUKg/TwVIzBZOjYI/AAAAAAAAAj8/V8yX85ZXKm8/s1600/Win7.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 35px;" src="http://2.bp.blogspot.com/--oR3zIDvUKg/TwVIzBZOjYI/AAAAAAAAAj8/V8yX85ZXKm8/s320/Win7.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5694037345264635266" /&gt;&lt;/a&gt;I was browsing some web site when all of a sudden my computer got hijacked. There were all kinds of annoying pop ups and programs running. They all seemed to be related to "Win 7 Internet Security 2012". I knew something was fishy when I tried to used Internet Explorer and Chrome to visit Google. This malware stated that Google was a rogue site. LOL.&lt;br /&gt;&lt;br /&gt;I could not run any programs such as Windows Explorer. The Win 7 Internet Security 2012 app would come up instead. This thing was throwing out all kinds of buzzwords. It said my computer got hacked. It also said I was a victim of identity theft. How did this thing get installed without me running a program?&lt;br /&gt;&lt;br /&gt;I went on another computer and did some research. Apparently this malware intercepts browsers and any executables. There was a full set of instructions on how to remove this evil malware over at &lt;a href="http://www.bleepingcomputer.com/virus-removal/remove-win-7-internet-security-2012"&gt;Bleeping Computer&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The manual removal instructions seem to have done the trick. Right now I am running a full virus scan with Malware Bytes Anti-Malware. A quick scan already found some probs with my laptop.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-2867869871441093228?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/2867869871441093228/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=2867869871441093228' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2867869871441093228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2867869871441093228'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2012/01/win-7-internet-security-2012.html' title='Win 7 Internet Security 2012'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/--oR3zIDvUKg/TwVIzBZOjYI/AAAAAAAAAj8/V8yX85ZXKm8/s72-c/Win7.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-7130435000396334314</id><published>2011-12-31T03:42:00.002-05:00</published><updated>2011-12-31T03:50:47.808-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='karma'/><category scheme='http://www.blogger.com/atom/ns#' term='downvote'/><category scheme='http://www.blogger.com/atom/ns#' term='comment'/><category scheme='http://www.blogger.com/atom/ns#' term='database'/><title type='text'>Hacking Hacker News</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-UR2teqhogOA/Tv7LLYUP1FI/AAAAAAAAAjw/XivaOqhQzVs/s1600/HN.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 313px; height: 320px;" src="http://1.bp.blogspot.com/-UR2teqhogOA/Tv7LLYUP1FI/AAAAAAAAAjw/XivaOqhQzVs/s320/HN.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5692210375409259602" /&gt;&lt;/a&gt;Recently I have been following the disaster known as Paul Christoforo of Ocean Marketing. He flamed a customer of the Avenger PS3 controller. Then he got into it with Mike Krahulik of Penny Arcade, who managed to turn the masses of the Internet on him. Even though Christoforo messed up, I thought the mob mentality that followed on the net was overkill. Apparently that is an unpopular opinion to have. My comments on Hacker News got downvoted a lot.&lt;br /&gt;&lt;br /&gt;I don't post of Hacker News too often. In the past year I probably commented on two posts. However I got a lot of downvotes this latest go around. The result is that my Hacker News karma is low. I think if your karma goes low enough, they ban you automatically. WTF? Now I want to brainstorm a way to hack my karma up into the positive region. While I am at it, I might as well try to raise my karma up high enough to downvote others (you cannot downvote if your karma is too low).&lt;br /&gt;&lt;br /&gt;So how does one carry out such a hack? Well I could work within the system. I could try to post some hot new topic that appeals to a lot of reader. Then they could vote me up. Weak. I could find a way to trick the system. Create some Hacker News accounts. Ensure the system would not detect this. Essentially vote myself up to many karma points.&lt;br /&gt;&lt;br /&gt;The real win would be to find out how karma is stored. Then I would need to figure out a way to go in and just change my number. Is this thing stored in a relational database? Or perhaps it is in some NoSQL database. What O/S is hosting this database? How can I get in? This is a fun problem to think about. Got any idea?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-7130435000396334314?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/7130435000396334314/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=7130435000396334314' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7130435000396334314'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7130435000396334314'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/12/hacking-hacker-news.html' title='Hacking Hacker News'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-UR2teqhogOA/Tv7LLYUP1FI/AAAAAAAAAjw/XivaOqhQzVs/s72-c/HN.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-4667572471834867812</id><published>2011-12-27T13:52:00.003-05:00</published><updated>2011-12-27T14:11:21.506-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='customer support'/><category scheme='http://www.blogger.com/atom/ns#' term='Avenger PS3 controller'/><title type='text'>Customer Service Battle</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-Q2EAVAVsT_8/TvoUH8ERU2I/AAAAAAAAAjk/iN9gyezJ5PA/s1600/PennyArcade.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 253px; height: 314px;" src="http://1.bp.blogspot.com/-Q2EAVAVsT_8/TvoUH8ERU2I/AAAAAAAAAjk/iN9gyezJ5PA/s320/PennyArcade.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5690883205751722850" /&gt;&lt;/a&gt;I been reading this hilarious email exchange regarding an Avenger PS3 controller. I saw the emails over at Penny Arcade. The &lt;a href="http://avengercontroller.com"&gt;company&lt;/a&gt; was represented by Ocean Marketing. There is a small discussion about it over on &lt;a href="http://news.ycombinator.com/item?id=3395411"&gt;Hacker&lt;/a&gt; News as well.&lt;br /&gt;&lt;br /&gt;Here is the synopsis: Customer pre-orders a control paying full price. The product does not ship on time. He contacts customer support via email. The response gets the customer salty. Then the customer support dude goes to town on the customer. I actually love the put downs.&lt;br /&gt;&lt;br /&gt;Here are some gems the customer support guys sends to the customer: "Grow up you look like a complete child bro", "You just got told bitch", and "We just have to put you in the corner with your im stupid hat on". These were all from just one email. LMAO!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-4667572471834867812?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/4667572471834867812/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=4667572471834867812' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4667572471834867812'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4667572471834867812'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/12/customer-service-battle.html' title='Customer Service Battle'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-Q2EAVAVsT_8/TvoUH8ERU2I/AAAAAAAAAjk/iN9gyezJ5PA/s72-c/PennyArcade.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-5485253118726785795</id><published>2011-12-15T17:15:00.003-05:00</published><updated>2011-12-15T17:23:00.454-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hiring'/><category scheme='http://www.blogger.com/atom/ns#' term='C'/><category scheme='http://www.blogger.com/atom/ns#' term='cipher'/><category scheme='http://www.blogger.com/atom/ns#' term='RethinkDB'/><category scheme='http://www.blogger.com/atom/ns#' term='decrypt'/><category scheme='http://www.blogger.com/atom/ns#' term='python'/><category scheme='http://www.blogger.com/atom/ns#' term='Vigenère'/><title type='text'>The Cipher Challenge</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/-M4RQkRNPwLU/Tupxt18APiI/AAAAAAAAAjY/gfEnyr5TcY8/s1600/Rethinkdb.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 200px;" src="http://4.bp.blogspot.com/-M4RQkRNPwLU/Tupxt18APiI/AAAAAAAAAjY/gfEnyr5TcY8/s320/Rethinkdb.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5686482511895477794" /&gt;&lt;/a&gt;I was reading a &lt;a href="http://1.61803398874.com/"&gt;post&lt;/a&gt; on Hacker News from a company that is hiring. They were pretty smart about it. They did not give out their name or URL. Instead they made you work for it. The ciper text "xfbhlqtlj" was provided. You were told to decipher it using Vigenère decryption.&lt;br /&gt;&lt;br /&gt;Oh yeah. You were also told to use the number 61803398874 from their URL. What? Anyone know what the heck Vigenère decryption is? Sure. Wikipedia does. This is a Caesar ciper with a varying shift. The number provided tells you how many characters each letter in the cipher text needs to be shifted.&lt;br /&gt;&lt;br /&gt;I tried shifting them to the right. No luck. The result was mumbo jumbo. But when I shifted the letters to the "left" in the alphabet, I got their &lt;a href="http://rethinkdb.com/"&gt;name&lt;/a&gt;. Bamm. Nice way to make me work for the URL. Too bad I am not in the running for any of their positions or their location.&lt;br /&gt;&lt;br /&gt;Not sure why a C and python program would come up with different result while decrypting the text.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-5485253118726785795?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/5485253118726785795/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=5485253118726785795' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5485253118726785795'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5485253118726785795'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/12/cipher-challenge.html' title='The Cipher Challenge'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-M4RQkRNPwLU/Tupxt18APiI/AAAAAAAAAjY/gfEnyr5TcY8/s72-c/Rethinkdb.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-916637389636626168</id><published>2011-12-06T14:35:00.002-05:00</published><updated>2011-12-06T14:36:57.791-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TOS'/><category scheme='http://www.blogger.com/atom/ns#' term='donation'/><category scheme='http://www.blogger.com/atom/ns#' term='Scrooge'/><category scheme='http://www.blogger.com/atom/ns#' term='organizers'/><title type='text'>Moving Cash Around with Paypal</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-uGkuUYN117E/Tt5uqhMegqI/AAAAAAAAAjM/LAe1CFIyD_A/s1600/Etsy.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 233px;" src="http://1.bp.blogspot.com/-uGkuUYN117E/Tt5uqhMegqI/AAAAAAAAAjM/LAe1CFIyD_A/s320/Etsy.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5683101456532406946" /&gt;&lt;/a&gt;This week there was a massive PR campaign launched againt Paypal. Here is how it went down. Somebody set up a toy campaign for some poor kids. They funded it with Paypal payments from donors. The funds were collected via Paypal. The problem was that the organizers were not charitable foundations. But they still used a Donate button on their web sites. This is against Paypal's TOS.&lt;br /&gt;&lt;br /&gt;Paypal detected the violation and froze the account and payments. The organizer was left with a lot of toys purchased, but not funds to pay for them. The organizer started up a grass roots protest using readers of her blog. The users were outraged. Some of them had been donors. Paypal was made to look like a big Scrooge with kids getting cheated out of their gifts.&lt;br /&gt;&lt;br /&gt;In the end, Paypal relented. They unfroze the account. Initially Paypal stated that they had to freeze the account because this is how the bad guys transfer funds via Paypal. They set up fake donation schemes to their money. This organizer figured out how to get a giant corp like Paypal to submit to their will. Make Paypal look like a bad guy. Get a lot of people outraged. Engage the media. Giant corp pwned. Brilliant.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-916637389636626168?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/916637389636626168/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=916637389636626168' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/916637389636626168'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/916637389636626168'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/12/moving-cash-around-with-paypal.html' title='Moving Cash Around with Paypal'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-uGkuUYN117E/Tt5uqhMegqI/AAAAAAAAAjM/LAe1CFIyD_A/s72-c/Etsy.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-5456815116551218531</id><published>2011-11-30T01:39:00.003-05:00</published><updated>2011-11-30T01:45:26.347-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='software updates'/><title type='text'>HP Printers on Fire. Oh My.</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-4nv2KGuN4sc/TtXQ_yv6TII/AAAAAAAAAi0/lSTPaAJ8Y-4/s1600/HP.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 320px;" src="http://1.bp.blogspot.com/-4nv2KGuN4sc/TtXQ_yv6TII/AAAAAAAAAi0/lSTPaAJ8Y-4/s320/HP.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5680676299370810498" /&gt;&lt;/a&gt;I been seeing these sensationalist headlines about Hewlett Packard printers being able to be hacked. The ultimate danger is stated as the HP devices being overloaded and catching on fire. Makes for a great headline indeed. I thought this was just crazy talk. Turns out it probably is.&lt;br /&gt;&lt;br /&gt;Here are the details. Apparently the printers look for software updates during each print job. It is possible to sneak in an unscrupulous update as part of a print job. The theory is that one could overload the printer, causing it to heat up, and eventually catch on fire.&lt;br /&gt;&lt;br /&gt;HP has already come out and said that in the rare scenario where this happens and the printer does heat up, a hardware governor will kick in and shut the thing off before things heat up too make. Did anybody actually test out the theory and cause an HP printer to catch fire? No. Hell. They might as well said that HP printers would explode if they are hacked too much. Hehe.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-5456815116551218531?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/5456815116551218531/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=5456815116551218531' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5456815116551218531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5456815116551218531'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/11/hp-printers-on-fire-oh-my.html' title='HP Printers on Fire. Oh My.'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-4nv2KGuN4sc/TtXQ_yv6TII/AAAAAAAAAi0/lSTPaAJ8Y-4/s72-c/HP.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-738724614870346892</id><published>2011-11-16T00:02:00.003-05:00</published><updated>2011-11-16T00:12:11.960-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='social security number'/><category scheme='http://www.blogger.com/atom/ns#' term='forged address'/><category scheme='http://www.blogger.com/atom/ns#' term='whois'/><title type='text'>Spammer Pwned</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-GSk3lZwGBak/TsNEV4bu4TI/AAAAAAAAAic/91dClemTnBk/s1600/Spammer.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 214px;" src="http://3.bp.blogspot.com/-GSk3lZwGBak/TsNEV4bu4TI/AAAAAAAAAic/91dClemTnBk/s320/Spammer.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5675455098133602610" /&gt;&lt;/a&gt;I had a weird spam message in my email today. The spammer made it look like the email came from one of my other email accounts. I sometimes send myself email to transfer stuff quickly between machines. This spammer must have determined my email address and forged it to fool me. This reminds me of a situation that Mike from &lt;a href="http://www.attackvector.org/invasion-of-privacy/"&gt;Attack Vector&lt;/a&gt; ran into. His solution was to track down and call out the spammer.&lt;br /&gt;&lt;br /&gt;Mike checks out the email headers. He gets the spammer IP and email address. He uses whois to get a phone number. Then he finds a postal address and bamn. He can now spy on the spammer's house with Google Maps. Turns out the spammer is Steve Nicholas of Spokane, WA. Mike goes on to determine the spammer's wife name, some social security numbers, and all kinds of other private info. Eventually the spammer contacts Mike and begs him to take down the info. What an unlucky day to send email spam. Hehe.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-738724614870346892?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/738724614870346892/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=738724614870346892' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/738724614870346892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/738724614870346892'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/11/spammer-pwned.html' title='Spammer Pwned'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-GSk3lZwGBak/TsNEV4bu4TI/AAAAAAAAAic/91dClemTnBk/s72-c/Spammer.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-1497663986293933072</id><published>2011-11-01T16:19:00.002-04:00</published><updated>2011-11-01T16:24:20.976-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='program'/><category scheme='http://www.blogger.com/atom/ns#' term='browsers'/><category scheme='http://www.blogger.com/atom/ns#' term='free software'/><category scheme='http://www.blogger.com/atom/ns#' term='browser'/><title type='text'>Hacking YouTube Views</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-wWdXRdXqY5Q/TrBUdPojVzI/AAAAAAAAAiE/h3lTBbUHsrk/s1600/Perry.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 227px; height: 320px;" src="http://2.bp.blogspot.com/-wWdXRdXqY5Q/TrBUdPojVzI/AAAAAAAAAiE/h3lTBbUHsrk/s320/Perry.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5670124792249014066" /&gt;&lt;/a&gt;I got a friend that produced a video and uploaded it to YouTube. Some other friends did the same. Now they are all seeing who gets the most hits on YouTube. My friend wondered if there was anything I could do to help increase his views. No problem.&lt;br /&gt;&lt;br /&gt;I want to make it look like a user is viewing the video. The video is just a URL that gets accessed in a browser. I could just write a program that keeps launching the browser to start watching my friend's video. Perhaps I could have a small delay between viewings.&lt;br /&gt;&lt;br /&gt;Let's say I want to try and fool YouTube into thinking it is a real human. I could mix in access to some other videos from my program. My program could also launch one of the many different browser available on my machine.&lt;br /&gt;&lt;br /&gt;Let's think about taking this up a notch. I could write some hot software and release it for free. Then that software could quietly "watch" the video on some hidden screen. Makes it much harder for YouTube to detect something fishy. Let's see how far I need to take this.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-1497663986293933072?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/1497663986293933072/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=1497663986293933072' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1497663986293933072'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1497663986293933072'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/11/hacking-youtube-views.html' title='Hacking YouTube Views'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-wWdXRdXqY5Q/TrBUdPojVzI/AAAAAAAAAiE/h3lTBbUHsrk/s72-c/Perry.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-2936597233499252068</id><published>2011-10-13T11:40:00.002-04:00</published><updated>2011-10-13T11:44:20.296-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='UNIX operating system'/><category scheme='http://www.blogger.com/atom/ns#' term='C programming language'/><title type='text'>Dennis Ritchie RIP</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/-Erz1Eu9LoVI/TpcGgJQW2oI/AAAAAAAAAh4/n0JBAIBJivk/s1600/DennisRitchie.gif"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 216px; height: 288px;" src="http://4.bp.blogspot.com/-Erz1Eu9LoVI/TpcGgJQW2oI/AAAAAAAAAh4/n0JBAIBJivk/s320/DennisRitchie.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5663002205751794306" /&gt;&lt;/a&gt;Dennis Ritchie passed away this week. In case you were unaware, he was the creator of the C programming language. He also was one of the creators of the UNIX operating system. Damn. That is some resume. Dennis was one of those early pioneers of computer science in the 1970s whose work affects a lot of us coders.&lt;br /&gt;&lt;br /&gt;Have you ever heard of the K&amp;R book of C programming? The R stands for Ritchie. Yep. He invented the language and wrote the seminal work on it. I measure all programming books against the K&amp;R book. The rest usually do not even compare. How can you get so much info in such a small book? Elegance.&lt;br /&gt;&lt;br /&gt;Hats off to you Dennis. Rest in peace.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-2936597233499252068?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/2936597233499252068/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=2936597233499252068' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2936597233499252068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2936597233499252068'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/10/dennis-ritchie-rip.html' title='Dennis Ritchie RIP'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-Erz1Eu9LoVI/TpcGgJQW2oI/AAAAAAAAAh4/n0JBAIBJivk/s72-c/DennisRitchie.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-8840891743155374412</id><published>2011-10-04T12:06:00.003-04:00</published><updated>2011-10-04T12:17:27.352-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Java'/><category scheme='http://www.blogger.com/atom/ns#' term='rip off'/><category scheme='http://www.blogger.com/atom/ns#' term='Deitel'/><category scheme='http://www.blogger.com/atom/ns#' term='structures'/><title type='text'>Simpletron</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-gYEaO7kDEII/TosvINGIPqI/AAAAAAAAAhw/vFTvlWE6tUQ/s1600/Simpletron.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 300px; height: 214px;" src="http://2.bp.blogspot.com/-gYEaO7kDEII/TosvINGIPqI/AAAAAAAAAhw/vFTvlWE6tUQ/s320/Simpletron.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5659669174721986210" /&gt;&lt;/a&gt;I have been taking a community college class on advanced Java. The instructor is experienced in Java and that helps. However our text is a Deitel book that just can't seem to explain these advanced concepts to me successfully. I feel ripped off because the book cost me $130. Now I still read the chapters each week and work through the exercises. But I find myself googling around to figure out what the heck is going on.&lt;br /&gt;&lt;br /&gt;The latest chapter was on common structures like stacks, queues, and lists. We got into the internal implementation of these structures. I worked through almost all the exercises in the back of the chapter. I was pleased with a calculator app that used a stack to convert math expressions to a format the computer could read. I was amazed that such little code could figure out complex expressions.&lt;br /&gt;&lt;br /&gt;The last exercise in the chapter was to build a compiler for the BASIC programming language. Damn. That's a tall order. The problem was that this task relied on you finishing some exercises from previous chapters. Our advanced class had skipped over those chapters so I did not do them.&lt;br /&gt;&lt;br /&gt;The crucial exercise was to implement a computer called the Simpletron. This thing has its own set of assembly language instructions, registers, memory, and so on. I started hitting those Simpletron exercises hard. I wrote out some small programs in Simpletron assembly language. This was fun. The real challenge was to build a Java program that would implement the Simpletron computer. More about that grand task later.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-8840891743155374412?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/8840891743155374412/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=8840891743155374412' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8840891743155374412'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8840891743155374412'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/10/simpletron.html' title='Simpletron'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-gYEaO7kDEII/TosvINGIPqI/AAAAAAAAAhw/vFTvlWE6tUQ/s72-c/Simpletron.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-2037686071807363113</id><published>2011-09-22T14:17:00.002-04:00</published><updated>2011-09-22T14:21:57.843-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NYC Police Department'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='attacks'/><title type='text'>Day of Vengeance</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-WXhlL9WZFLc/Tnt78R4qbBI/AAAAAAAAAho/FVJL27nio3M/s1600/Vendetta.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 209px; height: 320px;" src="http://1.bp.blogspot.com/-WXhlL9WZFLc/Tnt78R4qbBI/AAAAAAAAAho/FVJL27nio3M/s320/Vendetta.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5655250032617221138" /&gt;&lt;/a&gt;I just heard that Anonymous has declared September 24th a "Day of Vengeance". They plan to launch a collaborated massive set of cyber attacks. They call out certain targets of their attack. It is undetstandable that they are going after corrupt banking institutions. I guess I can see why they would also go after Wall Street. The funny taget is the NYC Police Department.&lt;br /&gt;&lt;br /&gt;What kind of malice is Anonymous going to enact? It might just be a bunch of DDoS attacks. Whup de doo. Or perhaps they shall be defacing some web sites. A little better. Given their past activities, perhaps they shall infiltrate systems and share the secret info they find.&lt;br /&gt;&lt;br /&gt;I thought the British police had at least some of the Anonymous members locked up. Maybe they got the wrong people. Or perhaps Anonymous is a huge organization that cannot be brought down with a couple arrests.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-2037686071807363113?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/2037686071807363113/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=2037686071807363113' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2037686071807363113'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2037686071807363113'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/09/day-of-vengeance.html' title='Day of Vengeance'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-WXhlL9WZFLc/Tnt78R4qbBI/AAAAAAAAAho/FVJL27nio3M/s72-c/Vendetta.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-7792630782398826807</id><published>2011-09-17T23:46:00.002-04:00</published><updated>2011-09-17T23:52:15.086-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='wireless router'/><category scheme='http://www.blogger.com/atom/ns#' term='firewall'/><category scheme='http://www.blogger.com/atom/ns#' term='Internet Access'/><category scheme='http://www.blogger.com/atom/ns#' term='McAfee'/><title type='text'>No Internet Connection</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-c7ioPYYLIrQ/TnVpnIpV0JI/AAAAAAAAAhg/TTNljX-bDOI/s1600/McAfee.gif"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 249px; height: 320px;" src="http://1.bp.blogspot.com/-c7ioPYYLIrQ/TnVpnIpV0JI/AAAAAAAAAhg/TTNljX-bDOI/s320/McAfee.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5653541028290220178" /&gt;&lt;/a&gt;One of my boyz could not get onto the Internet. The thing found my wireless router. Windows kept saying there was no Internet Access. What the heck? I tried to add the computer to my home network. No luck. This thing would not get on the Internet. I was getting desperate.&lt;br /&gt;&lt;br /&gt;Personally I blame &lt;a href="http://micro-softus.blogspot.com/"&gt;Microsoft&lt;/a&gt;. But Microsoft somewhere game me a clue. It said that McAfee was providing firewall services. Perhaps that was to blame. I fired up msconfig. There was a whole lot of McAfee services and startup items up in there. I disabled all of them. Then I rebooted the computer.&lt;br /&gt;&lt;br /&gt;Boom. The computer was browsing the Internet with ease. I was able to set up and print to my local printer. Damn you McAfee. The thing might be trying to prevent some problems. It is the problem. Fail. I might have to write a program that disables all the McAfee stuff itself. I will call this prog "Cleaner" hehe.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-7792630782398826807?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/7792630782398826807/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=7792630782398826807' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7792630782398826807'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7792630782398826807'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/09/no-internet-connection.html' title='No Internet Connection'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-c7ioPYYLIrQ/TnVpnIpV0JI/AAAAAAAAAhg/TTNljX-bDOI/s72-c/McAfee.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-2828852537373778412</id><published>2011-09-16T14:41:00.002-04:00</published><updated>2011-09-16T14:46:12.711-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='refusal'/><category scheme='http://www.blogger.com/atom/ns#' term='counsel'/><category scheme='http://www.blogger.com/atom/ns#' term='lawyers'/><category scheme='http://www.blogger.com/atom/ns#' term='incriminate'/><title type='text'>Declinge the FBI Interview</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/-3NtBhkh6noM/TnOYe3tn-cI/AAAAAAAAAhY/twQYjAkvVYk/s1600/FBI.gif"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 208px; height: 320px;" src="http://4.bp.blogspot.com/-3NtBhkh6noM/TnOYe3tn-cI/AAAAAAAAAhY/twQYjAkvVYk/s320/FBI.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5653029613398915522" /&gt;&lt;/a&gt;I just finished reading a lengthy post about some FBI interview scenarios. It turns out that most of the time, speaking with the FBI can incriminate you. So what is a hacker supposed to do? There is one thing you should not do. Do not refuse to cooperate. That might look bad in a court of law. Instead the golden rule is to say that your lawyer will get in contact with the FBI for you.&lt;br /&gt;&lt;br /&gt;You got to have counsel. Now this might seem like a ploy for some high priced lawyers to rip you off. It is better pay these pied pipers than server time in jail for a casual slip up. It turns out that good lawyers are not going to want you to be subjected to an interview with the FBI. They can figure out what is up, and provide the best offense for you. That is a great defense right there.&lt;br /&gt;&lt;br /&gt;Do not just trust me on this. I am not a lawyer. I am a coder. Check out the original &lt;a href="http://library.findlaw.com/2004/May/11/147945.html"&gt;post&lt;/a&gt; by Solomon Wisenberg regarding 18 U.S.C. Section 1001.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-2828852537373778412?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/2828852537373778412/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=2828852537373778412' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2828852537373778412'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2828852537373778412'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/09/declinge-fbi-interview.html' title='Declinge the FBI Interview'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-3NtBhkh6noM/TnOYe3tn-cI/AAAAAAAAAhY/twQYjAkvVYk/s72-c/FBI.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-4839117266019718042</id><published>2011-09-12T15:13:00.002-04:00</published><updated>2011-09-12T15:28:56.032-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='domain'/><category scheme='http://www.blogger.com/atom/ns#' term='champion'/><category scheme='http://www.blogger.com/atom/ns#' term='free site'/><category scheme='http://www.blogger.com/atom/ns#' term='root'/><title type='text'>Directory Denial</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-iBV7TY5qjh8/Tm5aWYyxzqI/AAAAAAAAAhQ/iRhKE-GLMtA/s1600/Manga.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 240px;" src="http://3.bp.blogspot.com/-iBV7TY5qjh8/Tm5aWYyxzqI/AAAAAAAAAhQ/iRhKE-GLMtA/s320/Manga.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5651553923055603362" /&gt;&lt;/a&gt;Some time back I must have submitted by blog to an Internet directory. Today I received a message that I had been denied. It has been so long that I have forgotten that I requested that I be added. They did not specify exactly what was preventing me from being added to the directory. I don't really mind.&lt;br /&gt;&lt;br /&gt;Here were some of the reasons that one might not get added to this "elite" directory: You don't have your own domain. You blog on a free site. Blah blah blah. I am not going to even state the name of the directory that rejected me. Why give them any fame? I am just going to keep on hacking, and keep on writing.&lt;br /&gt;&lt;br /&gt;Perhaps I should email these schlubs back, telling them I don't need no stinking link in their directory. I'm already a champion. Or I could gain access to their root. Muhahaha.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-4839117266019718042?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/4839117266019718042/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=4839117266019718042' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4839117266019718042'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4839117266019718042'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/09/directory-denial.html' title='Directory Denial'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-iBV7TY5qjh8/Tm5aWYyxzqI/AAAAAAAAAhQ/iRhKE-GLMtA/s72-c/Manga.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-4333838955325674646</id><published>2011-09-09T20:24:00.002-04:00</published><updated>2011-09-09T20:28:11.259-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='resume'/><category scheme='http://www.blogger.com/atom/ns#' term='boot up'/><category scheme='http://www.blogger.com/atom/ns#' term='standby'/><category scheme='http://www.blogger.com/atom/ns#' term='shut down'/><category scheme='http://www.blogger.com/atom/ns#' term='suspend'/><title type='text'>Windows Sleep and Hibernate</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-lxCYDLziO34/TmquSj9EYMI/AAAAAAAAAhI/C8FpZoAadGg/s1600/Sleep.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 234px;" src="http://3.bp.blogspot.com/-lxCYDLziO34/TmquSj9EYMI/AAAAAAAAAhI/C8FpZoAadGg/s320/Sleep.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5650520316401967298" /&gt;&lt;/a&gt;I like to keep my computer on all the time. However I want the lights to go off at night so it does not bother anyone. I could shut the thing down. But it takes a long time to boot up. Windows provides the options of both Sleep and Hibernate. But what the heck do these things mean?&lt;br /&gt;&lt;br /&gt;Let's start with sleep. This has been called suspend or standby before. The state of the computer is kept in memory. So it does draw some power during the sleep. The good thing is that the transition back on (the resume) is fast. Hibernate writes the computer state to disk. Then it goes to a state that draws no power. The state is written to file "hiberfile.sys", whose size depends on the amount of RAM you have. The hibernate state is slower to resume than sleep, but faster than a whole boot up.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-4333838955325674646?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/4333838955325674646/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=4333838955325674646' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4333838955325674646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4333838955325674646'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/09/windows-sleep-and-hibernate.html' title='Windows Sleep and Hibernate'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-lxCYDLziO34/TmquSj9EYMI/AAAAAAAAAhI/C8FpZoAadGg/s72-c/Sleep.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-4489115607385675907</id><published>2011-09-08T12:41:00.003-04:00</published><updated>2011-09-08T12:53:38.629-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='robots'/><category scheme='http://www.blogger.com/atom/ns#' term='drone'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='wireless network'/><title type='text'>Attacks From the Sky</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/-dJVjKPvrj1w/TmjxDP5JpiI/AAAAAAAAAhA/xumr9N7Qnd4/s1600/Flying.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 234px;" src="http://4.bp.blogspot.com/-dJVjKPvrj1w/TmjxDP5JpiI/AAAAAAAAAhA/xumr9N7Qnd4/s320/Flying.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5650030770644428322" /&gt;&lt;/a&gt;I have been busy lately with my new Advanced Java college class. However I saw something today that caught my eye. There have been some trials of some futuristic unmanned robots which fly around and jack into your wireless network.&lt;br /&gt;&lt;br /&gt;Yeah. Before you knew your neighbor could "share" you wireless network. There could also have been a driveby where some hacker listens in on your wireless network activity. Now the spin is that a drone can fly around and listen in on everybody's wireless network traffic.&lt;br /&gt;&lt;br /&gt;This is novel because it brings up images of mini-drone aircraft flying around. But the defense against the drone is no different than the defense against your neighbor. Lock down your wireless networking using security. Know also that whatever you send over the air is liable to be compromised.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-4489115607385675907?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/4489115607385675907/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=4489115607385675907' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4489115607385675907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4489115607385675907'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/09/attacks-from-sky.html' title='Attacks From the Sky'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-dJVjKPvrj1w/TmjxDP5JpiI/AAAAAAAAAhA/xumr9N7Qnd4/s72-c/Flying.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3901958244327047131</id><published>2011-09-01T09:42:00.002-04:00</published><updated>2011-09-01T09:46:01.522-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='revival'/><category scheme='http://www.blogger.com/atom/ns#' term='highlight'/><category scheme='http://www.blogger.com/atom/ns#' term='web developers'/><category scheme='http://www.blogger.com/atom/ns#' term='overflow'/><title type='text'>COBOL ON COGS</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-m177cb2R4EM/Tl-L5L2sXeI/AAAAAAAAAg4/2csn5xHb4Gk/s1600/Cogs.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 289px; height: 124px;" src="http://2.bp.blogspot.com/-m177cb2R4EM/Tl-L5L2sXeI/AAAAAAAAAg4/2csn5xHb4Gk/s320/Cogs.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5647386272296885730" /&gt;&lt;/a&gt;I clicked over to a link from Reddit that got me to COBOL ON COGS. The screen colors were so dim I needed to highlight the text just to see the damn page. Don't you hate when web developers do that? Then I thought this was some COBOL revival site.&lt;br /&gt;&lt;br /&gt;I did get a LOL from the "(c) DATE OVERFLOW" at the bottom of the community page. Didn't anybody test test this thing? Then I figured that COBOL was not meant to work past the year 2000 or something. Finally I figured out that this was a prank. They got me. Turns out this was released one April Fools day.&lt;br /&gt;&lt;br /&gt;Heheh. Maybe I should code up a lulz like that.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3901958244327047131?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3901958244327047131/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3901958244327047131' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3901958244327047131'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3901958244327047131'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/09/cobol-on-cogs.html' title='COBOL ON COGS'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-m177cb2R4EM/Tl-L5L2sXeI/AAAAAAAAAg4/2csn5xHb4Gk/s72-c/Cogs.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3269830197979761759</id><published>2011-07-18T20:45:00.003-04:00</published><updated>2011-07-18T20:50:37.143-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='The Sun'/><category scheme='http://www.blogger.com/atom/ns#' term='Twitter'/><category scheme='http://www.blogger.com/atom/ns#' term='redirect'/><title type='text'>LulzSec Strikes Again</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/-Yk2dYVWySc4/TiTT237u1BI/AAAAAAAAAgw/VhPrJfkFW1w/s1600/Lulz.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 83px;" src="http://4.bp.blogspot.com/-Yk2dYVWySc4/TiTT237u1BI/AAAAAAAAAgw/VhPrJfkFW1w/s320/Lulz.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5630858373800842258" /&gt;&lt;/a&gt;&lt;br /&gt;Previously the LulzSec hacker group announced that they were disbanding. Some think that authorities were getting too close to their identity. Others speculated that they ran out of the easy hacks. Well that all came to an end. The LulzSec has struck again.&lt;br /&gt;&lt;br /&gt;Team Lulz hacked The Sun newspaper. They redirected the Sun's web page to their own Twitter account. Mischevious. It seems a little less hard core than their past exploits. Maybe this is just one of the team. Or perhaps it is the work of some other LulzSec wannabes.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3269830197979761759?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3269830197979761759/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3269830197979761759' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3269830197979761759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3269830197979761759'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/07/lulzsec-strikes-again.html' title='LulzSec Strikes Again'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-Yk2dYVWySc4/TiTT237u1BI/AAAAAAAAAgw/VhPrJfkFW1w/s72-c/Lulz.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3898860749435944583</id><published>2011-07-11T16:31:00.002-04:00</published><updated>2011-07-11T16:35:21.681-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='defense'/><category scheme='http://www.blogger.com/atom/ns#' term='Booz Allen'/><category scheme='http://www.blogger.com/atom/ns#' term='source code'/><category scheme='http://www.blogger.com/atom/ns#' term='shell'/><title type='text'>Anonymous Busts Booz Allen</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-KDXY4ZiZSE4/ThtdtftIxLI/AAAAAAAAAgo/CM91ZQTJl18/s1600/Legion.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 175px; height: 288px;" src="http://3.bp.blogspot.com/-KDXY4ZiZSE4/ThtdtftIxLI/AAAAAAAAAgo/CM91ZQTJl18/s320/Legion.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5628195195515880626" /&gt;&lt;/a&gt;I just saw an announcement from the group known as Anonymous. They infiltrated government contractor Booz Allen. Their main score was 90,000 email addresses and passwords. Anonymous claims these email accounts belong to military personnel.&lt;br /&gt;&lt;br /&gt;Anonymous found a Booz Allen server that had no security on it. They proceeded to install a shell program that got down to business. In addition to the emails, they found tons of source code which they deemed worthless. LOL.&lt;br /&gt;&lt;br /&gt;This is touted as a score since Booz Allen does defense contracts and homeland security contracts. One would think such a company runs a tight ship. Anonymous says they sunk the battleship, finding its defenses lacking. No matter what you think about their tactics, you got to give them props for their byline:&lt;br /&gt;&lt;br /&gt;We are Anonymous&lt;br /&gt;We are Legion&lt;br /&gt;We are AntiSec&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3898860749435944583?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3898860749435944583/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3898860749435944583' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3898860749435944583'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3898860749435944583'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/07/anonymous-busts-booz-allen.html' title='Anonymous Busts Booz Allen'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-KDXY4ZiZSE4/ThtdtftIxLI/AAAAAAAAAgo/CM91ZQTJl18/s72-c/Legion.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-179866057639492725</id><published>2011-07-01T16:40:00.002-04:00</published><updated>2011-07-01T16:48:53.791-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='admin account'/><category scheme='http://www.blogger.com/atom/ns#' term='exchange'/><category scheme='http://www.blogger.com/atom/ns#' term='crash'/><title type='text'>Bitcoinage</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-k9EsKcVW_aU/Tg4wuPKlOYI/AAAAAAAAAgg/F1RsgfaQ91k/s1600/Bitcoin.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 225px; height: 225px;" src="http://2.bp.blogspot.com/-k9EsKcVW_aU/Tg4wuPKlOYI/AAAAAAAAAgg/F1RsgfaQ91k/s320/Bitcoin.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5624486555535358338" /&gt;&lt;/a&gt;I read a fantastic story about a guy who claims his computer got hacked. No big deal, right? Well he claims that the hacking resulted in somebody stealing his bitcoins. There were a lot of them. The total value amounted to $500,000. The owner blames Microsoft Windows for the theft.&lt;br /&gt;&lt;br /&gt;There was a lot of discussion in the Bitcoin community about this claim. How could they stop the selling of so much Bitcoin? What would be the effect on the Bitcoin market? Is this story for real? Some people doubted the facts. Things sounded a bit fishy. I myself thought that it could be true. I never did find out any proof about the alleged theft. Other commenters wanted some proof.&lt;br /&gt;&lt;br /&gt;Move forward and we find that there was a run on the Mt. Gox bitcoin exchange. It caused a crash. Tons of bitcoins were put on the market for sale. This drove the value of a bitcoin from $17 to a penny. The exchange declared that it was going to roll back the transactions. Some who profited from the drop publicly groaned. The exchange justified this by stating that the crash came as a result of a theft. Once again the call was made for details and proof of the theft.&lt;br /&gt;&lt;br /&gt;Finally I see a public announcement from the Mt. Gox bitcoin exchange. It appears an admin account was compromised. The person assigned themselves a large amount of bitoins. Then they went to town trying to sell them all. They got away with 2000 bitcoins. The exchange said they would eat this loss and that security has been improved. However the exchange seems to have backed away from the story about somebody's personal bitcoin wallet with tons of bitcoins being stolen.&lt;br /&gt;&lt;br /&gt;I recall one guy who heard the initial story about a computer being hacked and tons of bitcoins being stolen. He postulated that maybe nobody's wallet was stolen, and that the exchange had an account that was hacked. Bamm. Right on target. Perhaps this person had insider info. Whatever the case, I find it odd how the story has changed from the exchange. I am glad I don't have any money in Bitcoins.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-179866057639492725?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/179866057639492725/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=179866057639492725' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/179866057639492725'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/179866057639492725'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/07/bitcoinage.html' title='Bitcoinage'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-k9EsKcVW_aU/Tg4wuPKlOYI/AAAAAAAAAgg/F1RsgfaQ91k/s72-c/Bitcoin.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-8707826156465642404</id><published>2011-06-25T03:22:00.002-04:00</published><updated>2011-06-25T03:27:01.571-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='X Factor'/><category scheme='http://www.blogger.com/atom/ns#' term='Love Boat'/><category scheme='http://www.blogger.com/atom/ns#' term='mute'/><title type='text'>The Lulz Boat</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-Gf_VZBXM5SU/TgWM46MfMyI/AAAAAAAAAgY/naiN-XCyCqc/s1600/LoveBoat.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 292px; height: 320px;" src="http://2.bp.blogspot.com/-Gf_VZBXM5SU/TgWM46MfMyI/AAAAAAAAAgY/naiN-XCyCqc/s320/LoveBoat.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5622054619164128034" /&gt;&lt;/a&gt;I am really starting to get a kick out of this LulzSec crew. Today I went to their web page. The theme from The Love Boat TV show start playing in the background. That is in reference to their Lulz Boat. I get it.&lt;br /&gt;&lt;br /&gt;There is a link at the button of the page to Mute the volume. But when you click the Mute link, the volume gets doubled, and they change the text to say that volume has increased 100%. LMAO. Now that is a worthwhile joke.&lt;br /&gt;&lt;br /&gt;On a more serious note, I checked out some of the data they posted on their sight. Damn. They got around 75,000 records of X-Factor contests details. Whew. They also have a long list of emails and passwords for a porn site. Ha ha. They have a good time at who they find registered at the sight. I am going to be keeping an eye on the Lulz folks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-8707826156465642404?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/8707826156465642404/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=8707826156465642404' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8707826156465642404'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8707826156465642404'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/06/lulz-boat.html' title='The Lulz Boat'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-Gf_VZBXM5SU/TgWM46MfMyI/AAAAAAAAAgY/naiN-XCyCqc/s72-c/LoveBoat.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-4576225671003437369</id><published>2011-06-24T15:00:00.004-04:00</published><updated>2011-06-24T15:10:53.967-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VPN'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='The Jester'/><category scheme='http://www.blogger.com/atom/ns#' term='Slowloris'/><category scheme='http://www.blogger.com/atom/ns#' term='Adrian Lamo'/><category scheme='http://www.blogger.com/atom/ns#' term='TOR'/><title type='text'>The Mind of LulzSec</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-aiu_r4OfH6M/TgThNeQKYaI/AAAAAAAAAgI/DdBwxFdfTS0/s1600/Slowloris.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 236px;" src="http://2.bp.blogspot.com/-aiu_r4OfH6M/TgThNeQKYaI/AAAAAAAAAgI/DdBwxFdfTS0/s320/Slowloris.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5621865856440623522" /&gt;&lt;/a&gt;The Guardian newspaper published an article online describing the personalities of the members of LulzSec. They gained this insight in part by viewing the logs of an IRC channel called "pure-elite". The Guardian went on to publish the contents of the logs, with some information redacted. From what I gather, the redacted info outs the perp who leaked the info.&lt;br /&gt;&lt;br /&gt;I read through the chat log and learned a great deal about the LulzSec crew. They value the Perl, Bash, C++, PHP, and assembly programming lanaugages. That does not mean they all have these skills. It is just what they need to write some apps or bots. In fact, during on session they were trying to identify some C++ programmers to help them out.&lt;br /&gt;&lt;br /&gt;They use technologies such as bots, IP spoofing, Virtual Private Networks (VPNs), and flooders. These are use in DDoS attacks. They also help conceal their identity. Or so they think. Muhahaha.&lt;br /&gt;&lt;br /&gt;These guys use tools such as Tor for anonymous communications, Slowloris for DDoS over HTTP, and anonine for VPN servers. LulzSec seems to hate The Jester, 2600, and Adrian Lamo.&lt;br /&gt;&lt;br /&gt;Overall this crew seemed to speak intelligently. They used a lot of slang appropriate for chat. But their speech was eloquent. They also seemed to know a lot of details about composing DDoS attacks. Not that I am a DDoS expert. But you could tell they were discussing the finer points of putting together cool attack vectors.&lt;br &gt;&lt;br /&gt;Hats off to the Guardian newspaper for obtaining and publishing the chat logs. I guess they have their security in order. Otherwise the LulzSec crew would have DDoSed them off the Internet.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-4576225671003437369?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/4576225671003437369/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=4576225671003437369' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4576225671003437369'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4576225671003437369'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/06/mind-of-lulzsec.html' title='The Mind of LulzSec'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-aiu_r4OfH6M/TgThNeQKYaI/AAAAAAAAAgI/DdBwxFdfTS0/s72-c/Slowloris.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3054447211634827712</id><published>2011-06-23T22:39:00.002-04:00</published><updated>2011-06-23T22:46:17.945-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='military patches'/><category scheme='http://www.blogger.com/atom/ns#' term='black ops'/><category scheme='http://www.blogger.com/atom/ns#' term='swords'/><category scheme='http://www.blogger.com/atom/ns#' term='covert projects'/><title type='text'>You Would Have To Be Destroyed By Me</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-_oqPtTd5cfE/TgP496Ndh1I/AAAAAAAAAf4/GhRzKzW6yjE/s1600/Patch1.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 160px; height: 166px;" src="http://2.bp.blogspot.com/-_oqPtTd5cfE/TgP496Ndh1I/AAAAAAAAAf4/GhRzKzW6yjE/s320/Patch1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5621610502369937234" /&gt;&lt;/a&gt;I am finally getting around to reading a book I brought a while ago. The title is "I Could Tell You But Then You Would Have to be Destroyed by me". This book catalogs a number of military patches from covert projects. Who would have though that you could get a patch for a mission you could not speak about? Apparently it happens all the time. I imagine many of these patches are not sanctioned by the military.&lt;br /&gt;&lt;br /&gt;I have only ready a portion of the book so far. However there are some themes that seem to be recurring. You get a lot of swords, stars, globes, and skeletons on these patches. Each item connotes something about the black ops project. Some of the patches are still a mystery even to the author.&lt;br /&gt;&lt;br /&gt;Take the image I posted above. You got a helmet or hat that means the bearer flies a helicopter. The footprints on top of the helmet make reference to search and rescue operations. Who knows what the G.H.O.S.T. stands for? I may give you some more info by the time I finish this book. That should not be too long. It is a quick read.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3054447211634827712?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3054447211634827712/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3054447211634827712' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3054447211634827712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3054447211634827712'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/06/you-would-have-to-be-destroyed-by-me.html' title='You Would Have To Be Destroyed By Me'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-_oqPtTd5cfE/TgP496Ndh1I/AAAAAAAAAf4/GhRzKzW6yjE/s72-c/Patch1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-1786026441182527953</id><published>2011-06-18T09:58:00.003-04:00</published><updated>2011-06-18T10:05:20.802-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phone numbers'/><category scheme='http://www.blogger.com/atom/ns#' term='social security numbers'/><category scheme='http://www.blogger.com/atom/ns#' term='CIA'/><category scheme='http://www.blogger.com/atom/ns#' term='Sony'/><title type='text'>LulzSec Identification</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-bflkMR-oLxY/TfyvWOhEwyI/AAAAAAAAAfw/tngWktfedCY/s1600/LulzSec.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 203px; height: 287px;" src="http://3.bp.blogspot.com/-bflkMR-oLxY/TfyvWOhEwyI/AAAAAAAAAfw/tngWktfedCY/s320/LulzSec.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5619559231440339746" /&gt;&lt;/a&gt;The LulzSec team has been all over the news. The biggest story was their hacking of Sony accounts. Lately they have infiltrated the CIA websites. Is there anything they can't do? Well the &lt;a href="http://lulzsecexposed.blogspot.com/"&gt;LulzSec&lt;/a&gt; blog is outing the identify of some LulzSec members.&lt;br /&gt;&lt;br /&gt;Who knows whether this blog has actual info on LulzSec members? The thing that surpised me was the detailed information the blog posts on some people. They got social security numbers, postal addresses, phone numbers including mobile, and email addresses. They know the ISPs used, IP addresses, pictures, and even family information.&lt;br /&gt;&lt;br /&gt;The LulzSec blog is brought to you by Team Web Ninjas. They provided the most information on one Corey R Barnhill. He is known as Kayla, Xyrix, and Parr0t. Leave it to a hacker to have so many handles. I am going to keep an eye on this blog. Perhaps they have the low down on LulzSec.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-1786026441182527953?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/1786026441182527953/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=1786026441182527953' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1786026441182527953'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1786026441182527953'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/06/lulzsec-identification.html' title='LulzSec Identification'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-bflkMR-oLxY/TfyvWOhEwyI/AAAAAAAAAfw/tngWktfedCY/s72-c/LulzSec.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-8962333140190403092</id><published>2011-06-14T23:38:00.003-04:00</published><updated>2011-06-14T23:42:04.429-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='registration'/><category scheme='http://www.blogger.com/atom/ns#' term='brute force'/><category scheme='http://www.blogger.com/atom/ns#' term='keygen'/><category scheme='http://www.blogger.com/atom/ns#' term='simulation'/><title type='text'>Keygen Fail</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-4kc4ih8-MgY/TfgpL39h4lI/AAAAAAAAAfo/021lznp1wMY/s1600/Keygen.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 298px; height: 169px;" src="http://3.bp.blogspot.com/-4kc4ih8-MgY/TfgpL39h4lI/AAAAAAAAAfo/021lznp1wMY/s320/Keygen.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5618285819122016850" /&gt;&lt;/a&gt;Last time I wrote, I had just created a keygen to test the security I put in my app. My keygen app tried a brute force attack on my app registration. It would simulate a user entering in all the combinations of keys. The keygen had to also press the Ok button on the registration dialog.&lt;br /&gt;&lt;br /&gt;Well the keygen app key trying all night. However the target of the attack blew up after a few hundred thousand attempts. Heck. I might consider that abort part of the security in the app. If you can't brute force the thing without it blowing up, that makes the brute force hacker's job even harder. That's not to say that the keygen app could not detect this and restart my app.&lt;br /&gt;&lt;br /&gt;I just wanted a little experience with creating a keygen. My app's registration screen will pause if you enter a wrong key. The more bad keys you enter, the longer it will pause between attemps. This will slow a brute force attack down in its tracks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-8962333140190403092?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/8962333140190403092/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=8962333140190403092' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8962333140190403092'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8962333140190403092'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/06/keygen-fail.html' title='Keygen Fail'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-4kc4ih8-MgY/TfgpL39h4lI/AAAAAAAAAfo/021lznp1wMY/s72-c/Keygen.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-4472643760706631043</id><published>2011-06-06T16:45:00.002-04:00</published><updated>2011-06-06T16:49:48.894-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Adobe update'/><category scheme='http://www.blogger.com/atom/ns#' term='start menu'/><category scheme='http://www.blogger.com/atom/ns#' term='Task Manager'/><category scheme='http://www.blogger.com/atom/ns#' term='desktop icons'/><title type='text'>Malware Attack</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/-qd-pf_GbNsc/Te08dR17oZI/AAAAAAAAAfg/CWwKYCQR_Nk/s1600/Icons.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 256px; height: 256px;" src="http://4.bp.blogspot.com/-qd-pf_GbNsc/Te08dR17oZI/AAAAAAAAAfg/CWwKYCQR_Nk/s320/Icons.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5615210784104358290" /&gt;&lt;/a&gt;I was in the middle of some brute force app attacking testing when my Windows system itself came under attack. I hastily allowed some Adobe update program to run. Turns out it was some malware masquerading as an Adobe update. I found a program which kept asking me to allow it to do something to my computer. It would not go away.&lt;br /&gt;&lt;br /&gt;My task manager was disabled. All the icons on my desktop were gone. All the items in my Windows start menu had also disappeared. I could not use Windows Explorer to browse to the location where the rogue program was at. Damn this was a serious virus.&lt;br /&gt;&lt;br /&gt;I did get to the command prompt. From there I ran the Windows registry editor. I changed the entry that disables task manager. With task manager back, I could kill off the malware process. Then I saw the real damage that had been done.&lt;br /&gt;&lt;br /&gt;This rogue app had made almost everything on my hard drive hidden. Therefore I could not see any files and directories. The directory that contains my start menu items was hidden, as was my desktop (which contains all my icons). The developers of this malware were pretty damn smart. This just reminds me that I need to do a better job of backing up the source code of my ongoing projects.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-4472643760706631043?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/4472643760706631043/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=4472643760706631043' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4472643760706631043'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4472643760706631043'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/06/malware-attack.html' title='Malware Attack'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-qd-pf_GbNsc/Te08dR17oZI/AAAAAAAAAfg/CWwKYCQR_Nk/s72-c/Icons.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-7745141720171647919</id><published>2011-06-06T02:20:00.002-04:00</published><updated>2011-06-06T02:25:15.051-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crack'/><category scheme='http://www.blogger.com/atom/ns#' term='cracker'/><category scheme='http://www.blogger.com/atom/ns#' term='defense'/><category scheme='http://www.blogger.com/atom/ns#' term='protection'/><category scheme='http://www.blogger.com/atom/ns#' term='keys'/><title type='text'>Brute Force Attack</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-IdzXQsMramM/Texx2b8K5vI/AAAAAAAAAfY/3Oy7z7v2-q0/s1600/Brute.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 118px;" src="http://2.bp.blogspot.com/-IdzXQsMramM/Texx2b8K5vI/AAAAAAAAAfY/3Oy7z7v2-q0/s320/Brute.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5614988015451170546" /&gt;&lt;/a&gt;I am getting close to completing my app which I plan to sell. This thing is going to need some crack protection. So I am shipping a alphanumeric key to customers that pay. You need to enter the key to get the software to work. I thought I would test to see how a brute force attack might work against this first level of defense.&lt;br /&gt;&lt;br /&gt;I coded up an app that would simulate a user trying combinations of characters, guessing what a legit key would be. This brute force cracker does not have any speed up techniques. Currently it is generating 2000 keys a minute. I plan to leave the thing running all night to see if it can get into my app.&lt;br /&gt;&lt;br /&gt;If it does get in, I will implement some delays on my app when it detects wrong keys being entered. That will slow down a brute force attack. However if I find it takes forever for the cracker to get into my app, then I might not even add that level of defense. No need to put up a higher gate if the existing one is keeping out the dogs.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-7745141720171647919?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/7745141720171647919/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=7745141720171647919' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7745141720171647919'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7745141720171647919'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/06/brute-force-attack.html' title='Brute Force Attack'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-IdzXQsMramM/Texx2b8K5vI/AAAAAAAAAfY/3Oy7z7v2-q0/s72-c/Brute.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-5054427835691893510</id><published>2011-06-02T17:21:00.003-04:00</published><updated>2011-06-02T17:27:50.543-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='poker'/><category scheme='http://www.blogger.com/atom/ns#' term='registration'/><category scheme='http://www.blogger.com/atom/ns#' term='install'/><category scheme='http://www.blogger.com/atom/ns#' term='college'/><category scheme='http://www.blogger.com/atom/ns#' term='brute force'/><title type='text'>Uncrackable</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-mnio9Z_sizc/Tef-96TMQuI/AAAAAAAAAfM/vGHgMk-F_Ow/s1600/Uncrackable.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 212px;" src="http://1.bp.blogspot.com/-mnio9Z_sizc/Tef-96TMQuI/AAAAAAAAAfM/vGHgMk-F_Ow/s320/Uncrackable.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5613735800115839714" /&gt;&lt;/a&gt;Sorry I have not posted anything in a while. Each night I have been working on a computer program that I plan to sell online. At first I was going to do something in the college scene. But now my direction has turned to poker.&lt;br /&gt;&lt;br /&gt;So far I already have a playable game. I just need to put in some rewards that makes the user want to keep playing my game. My recent research has turned to figuring out how to lock down my app. I want people to buy the thing. And I was only those who bought my app to be able to run it.&lt;br /&gt;&lt;br /&gt;I need to generate some registration keys that you need to install the game. The key needs to be long enough so you can't guess it. But it should be short enough so as not to cause valid users to make mistakes. Next I need to write some code that is hard to figure out, but that validates the key. I do not want anybody brute force attacking this key. So if you make a mistake, my program will pause before you can reenter the key.&lt;br /&gt;&lt;br /&gt;My program is written in C++. I hear that you should use some complex features of the programming language to make it harder to break. Speaking of C++, you should inline all calls to the key decryption. That way a hacker can't just patch one copy of your routine. They need to find all instances of it. There is a whole lot more to this key business. I plan to talk about it some more in the future.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-5054427835691893510?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/5054427835691893510/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=5054427835691893510' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5054427835691893510'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5054427835691893510'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/06/uncrackable.html' title='Uncrackable'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-mnio9Z_sizc/Tef-96TMQuI/AAAAAAAAAfM/vGHgMk-F_Ow/s72-c/Uncrackable.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3618159154574403068</id><published>2011-05-14T17:43:00.003-04:00</published><updated>2011-05-14T17:43:00.091-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='gift card'/><category scheme='http://www.blogger.com/atom/ns#' term='app store'/><category scheme='http://www.blogger.com/atom/ns#' term='activation'/><category scheme='http://www.blogger.com/atom/ns#' term='code'/><title type='text'>iTunes Money</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/-Mso-6xj9xAA/Tc2mCFq8AHI/AAAAAAAAAfE/Q63Q5sUA84g/s1600/iTunes.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 280px; height: 284px;" src="http://4.bp.blogspot.com/-Mso-6xj9xAA/Tc2mCFq8AHI/AAAAAAAAAfE/Q63Q5sUA84g/s320/iTunes.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5606319665958355058" /&gt;&lt;/a&gt;Somebody gave me an iTunes gift card as a present. I do download some apps from the iTunes app store. However I only get the free ones. I still activated the gift card and posted the credit to my account. Who knows? Maybe there will be some cool app I need to buy in the future.&lt;br /&gt;&lt;br /&gt;This is the thing I wondered about. How does the gift card and credit activation work? There is a code on the back of my gift card. It is a 16 character code. The first 15 characters are alphabetic. The last character is a number. You key it into the app store, and it knows the amount of credit to give you.&lt;br /&gt;&lt;br /&gt;Surely these numbers by themself do not equate the money. If that were so, I could steal a stack of them from the store and be app store rich. I imagine that when you purchase the card, the cashier scans it in and that activates the value on the card. That would be the smart way to regulate the cards from theft.&lt;br /&gt;&lt;br /&gt;But what is that 16 character code? It might be some sort of encrypted value. Or then again it might just be a random set of characters to make my card unique. This will require more thought before I can figure it out. What do you all know about this number? I want to know.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3618159154574403068?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3618159154574403068/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3618159154574403068' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3618159154574403068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3618159154574403068'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/05/itunes-money.html' title='iTunes Money'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-Mso-6xj9xAA/Tc2mCFq8AHI/AAAAAAAAAfE/Q63Q5sUA84g/s72-c/iTunes.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-5922217852489696698</id><published>2011-05-13T14:55:00.002-04:00</published><updated>2011-05-13T14:58:23.831-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='legitimate'/><category scheme='http://www.blogger.com/atom/ns#' term='compromise'/><category scheme='http://www.blogger.com/atom/ns#' term='rent'/><category scheme='http://www.blogger.com/atom/ns#' term='gangsters'/><category scheme='http://www.blogger.com/atom/ns#' term='criminals'/><title type='text'>Control of Your PC</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-gtEbSPizFjE/Tc1-nqV4SQI/AAAAAAAAAe8/ljMSMiNqvtI/s1600/Remote.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 194px; height: 320px;" src="http://2.bp.blogspot.com/-gtEbSPizFjE/Tc1-nqV4SQI/AAAAAAAAAe8/ljMSMiNqvtI/s320/Remote.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5606276330992191746" /&gt;&lt;/a&gt;You probably have heard of some malware trying to take control of your PC. But get this. Now people are renting out time for jobs to run on your PC. This appeals to the gangsters. The evil deeds they do will come from your PC under their control.&lt;br /&gt;&lt;br /&gt;Damn. This is quite a setup. Part of the defense against criminal activity is to check the IP address of the place where connections are coming from. If a botnet has compromised computers all across the world, the traffic might look legitimate to the untrained eye. Furthermore my computer might be aiding the crime.&lt;br /&gt;&lt;br /&gt;I used to not care too much about spyware and malware. Who really cares if somebody is stealing cycles from my PC? Now I know the answer. I care.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-5922217852489696698?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/5922217852489696698/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=5922217852489696698' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5922217852489696698'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5922217852489696698'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/05/control-of-your-pc.html' title='Control of Your PC'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-gtEbSPizFjE/Tc1-nqV4SQI/AAAAAAAAAe8/ljMSMiNqvtI/s72-c/Remote.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-8143861426739474155</id><published>2011-05-02T10:26:00.002-04:00</published><updated>2011-05-02T10:32:14.044-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='suspicious'/><category scheme='http://www.blogger.com/atom/ns#' term='winword'/><title type='text'>Software Impersonation</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-mIGyuGrgSYE/Tb6_Wm5k36I/AAAAAAAAAe0/0akxiiEXGyY/s1600/Security.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 254px;" src="http://3.bp.blogspot.com/-mIGyuGrgSYE/Tb6_Wm5k36I/AAAAAAAAAe0/0akxiiEXGyY/s320/Security.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5602125381615542178" /&gt;&lt;/a&gt;There are some security peeps in my customer's organization that are looking for malware. They identified some of the programs I was running as suspicious. Here is their reasoning. Nobody else is running programs with the same names as the ones I run. What?&lt;br /&gt;&lt;br /&gt;They must be auditing the name of all programs runs by everyone. Then they see which ones are unique to certain individuals. They conclude that there must be something fishy with these apps. Duh. I am a developer. I write and name my own tools.&lt;br /&gt;&lt;br /&gt;I tried to explain this to my management and to the customer. They said they would look into it. In the mean time, I am supposed to not run these programs. Hello? I need them to do my job. What is a coder supposed to do?&lt;br /&gt;&lt;br /&gt;I figured I could name the programs "winword.exe", or something like that. However that would be a subversive act. It might just get me past the keystone cops. Anyone else with any sense would be able to figure out that I am impersonating Microsoft Word. That might be an even more egregious offense. For now I am rewriting my crucial tools in Java. That way when they look at the name of the program I am running, all they see is "java.exe". Noobs.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-8143861426739474155?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/8143861426739474155/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=8143861426739474155' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8143861426739474155'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8143861426739474155'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/05/software-impersonation.html' title='Software Impersonation'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-mIGyuGrgSYE/Tb6_Wm5k36I/AAAAAAAAAe0/0akxiiEXGyY/s72-c/Security.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-7868660480485253635</id><published>2011-04-21T22:46:00.004-04:00</published><updated>2011-04-21T22:58:13.626-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='copyright'/><category scheme='http://www.blogger.com/atom/ns#' term='harass'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='porn'/><category scheme='http://www.blogger.com/atom/ns#' term='illegal'/><title type='text'>Terms and Conditions</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-uYo6Kgdi00Q/TbDsOt598jI/AAAAAAAAAes/TTmPPbngpmE/s1600/TOC.bmp"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 225px; height: 225px;" src="http://2.bp.blogspot.com/-uYo6Kgdi00Q/TbDsOt598jI/AAAAAAAAAes/TTmPPbngpmE/s320/TOC.bmp" border="0" alt=""id="BLOGGER_PHOTO_ID_5598234074406580786" /&gt;&lt;/a&gt;I am stayting at a hotel during my vacation. They have free wireless Internet. However you need to agree to their terms and conditions. I am interested in figuring out how they make your browser open up to their TOC page. However I did find the list of conditions interesting.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Do not display disturbing images&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Do not do anything illegal&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Do not harass others&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Do not destroy stuff belonging to others&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Do not copy protected material&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Do not access any porn&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Do not bypass any security&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Do not install any viruses&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;br /&gt;They did try to provide some guidance if you need encrption. They recommended some third party virtual private networks (VPN). You should use SSL to access email. You should also make use of SSH. Use your computer's personal firewall. Make use of antivirus software. Don't open attachments.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-7868660480485253635?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/7868660480485253635/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=7868660480485253635' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7868660480485253635'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7868660480485253635'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/04/terms-and-conditions.html' title='Terms and Conditions'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-uYo6Kgdi00Q/TbDsOt598jI/AAAAAAAAAes/TTmPPbngpmE/s72-c/TOC.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-6776967074034060364</id><published>2011-04-14T13:11:00.000-04:00</published><updated>2011-04-14T13:16:06.133-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vi'/><category scheme='http://www.blogger.com/atom/ns#' term='buffers'/><category scheme='http://www.blogger.com/atom/ns#' term='undo'/><category scheme='http://www.blogger.com/atom/ns#' term='UINX'/><category scheme='http://www.blogger.com/atom/ns#' term='spell check'/><category scheme='http://www.blogger.com/atom/ns#' term='regex'/><title type='text'>The Case for Emacs</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-_yOcjh2985M/TacqxwQAucI/AAAAAAAAAek/yClb_h7s-ro/s1600/Emacs.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 128px; height: 128px;" src="http://1.bp.blogspot.com/-_yOcjh2985M/TacqxwQAucI/AAAAAAAAAek/yClb_h7s-ro/s320/Emacs.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5595488096285145538" /&gt;&lt;/a&gt;When I am on UNIX, I use vi for file editing. However I read an article today about emacs that was most interesting. It touted some of the emacs power that I would like to have at my fingertips. I tried emacs before. It just did not feel natural. Maybe it is time for another look.&lt;br /&gt;&lt;br /&gt;One thing is certain. Emacs is not easy to learn. A key tenet of emacs is that you should be able to do anything by just pressing keys. There is not cut and paste per se in emacs. They have something like it though.&lt;br /&gt;&lt;br /&gt;You can open a whole lot of files in emacs. They each get their own buffer. Emacs has a built in spell checker. Nice. It also has sophisticated undo and selective searching.&lt;br /&gt;&lt;br /&gt;The list of emacs featues goes on and on. There is support for regular expressions. You can also execute shell commands directly from the program. I just may have to give it a try.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-6776967074034060364?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/6776967074034060364/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=6776967074034060364' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6776967074034060364'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6776967074034060364'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/04/case-for-emacs.html' title='The Case for Emacs'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-_yOcjh2985M/TacqxwQAucI/AAAAAAAAAek/yClb_h7s-ro/s72-c/Emacs.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-6417325060755402794</id><published>2011-04-13T22:19:00.002-04:00</published><updated>2011-04-13T22:34:46.450-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PDFSharp'/><category scheme='http://www.blogger.com/atom/ns#' term='DocX'/><category scheme='http://www.blogger.com/atom/ns#' term='Selenium'/><category scheme='http://www.blogger.com/atom/ns#' term='DotNetZip'/><title type='text'>Best Things are Free</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-a8t9w1TgLmo/TaZZwFYyLFI/AAAAAAAAAec/JMGE2Z7UZCA/s1600/Free.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 213px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5595258269669141586" border="0" alt="" src="http://3.bp.blogspot.com/-a8t9w1TgLmo/TaZZwFYyLFI/AAAAAAAAAec/JMGE2Z7UZCA/s320/Free.jpg" /&gt;&lt;/a&gt; I just went through a huge list of free &lt;a href="http://micro-soft-dot-net.blogspot.com/"&gt;.NET&lt;/a&gt; tools. Thanks to &lt;a href="http://qink.net/page/The-Ultimate-List-of-Freely-Available-_NET-Libraries.aspx"&gt;Qink&lt;/a&gt; for providing the links. I chose the top four tools I thought you might be interested in. Here is the low down on these freebies.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://dotnetzip.codeplex.com/"&gt;DotNetZip&lt;/a&gt; can do everything you want with zip files. Any dot Net apps can use it. It even works undo Mono. You obviously need the .NET framework to use this thing. It is distributed as a DLL. You can make self extracting zip files with it. The tool even supports AES encryption. Damn. Get this now.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pdfsharp.net/Default.aspx?AspxAutoDetectCookieSupport=1"&gt;PDFSharp&lt;/a&gt; lets you create PDF files. It is open sourced under the MIT license. The routines to draw on the PDF file are the same types you use to draw on the screen (i.e. GDI commands). It supports transparent images. Nuff said.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://seleniumhq.org/about/how.html"&gt;Selenium&lt;/a&gt; is a tool to help test web apps. You can record a session using Firefox. Then you can play back what happened. Alternatively you can export the activity to your programming language for modification. Your app can then work with the Selenium server to play back the actions. Sweet.&lt;br /&gt;&lt;br /&gt;Finally there is &lt;a href="http://docx.codeplex.com/"&gt;DocX&lt;/a&gt;. It allows you to create Microsoft Word documents. It is released as a DLL. DocX requries .NET and Visual Studio. All the Word goodies such as tables, headers/footers, and pictures are supported.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-6417325060755402794?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/6417325060755402794/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=6417325060755402794' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6417325060755402794'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6417325060755402794'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/04/best-things-are-free.html' title='Best Things are Free'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-a8t9w1TgLmo/TaZZwFYyLFI/AAAAAAAAAec/JMGE2Z7UZCA/s72-c/Free.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-4590898426862725469</id><published>2011-04-09T00:00:00.003-04:00</published><updated>2011-04-09T00:08:35.041-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='telnet'/><category scheme='http://www.blogger.com/atom/ns#' term='SSH'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='xterm'/><category scheme='http://www.blogger.com/atom/ns#' term='trialware'/><title type='text'>Hacking Tools</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-dBe8mlPm3rw/TZ_Z-MlV6aI/AAAAAAAAAeM/ykt9IXTFSKs/s1600/Putty.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 240px;" src="http://3.bp.blogspot.com/-dBe8mlPm3rw/TZ_Z-MlV6aI/AAAAAAAAAeM/ykt9IXTFSKs/s320/Putty.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5593428924770412962" /&gt;&lt;/a&gt;I have been talking about free tools recently. But instead of any old tools, I should focus more on hacking tools. Let's do that here.&lt;br /&gt;&lt;br /&gt;Date Cracker 2000 gets you past most time sensitive software. You know. It pwns trial software that expires in 30 days. It also works on shareware. The tools is distributed "for educational purposes only". LOL. The authors have agreements with some software developers. So it won't crack all trialware. It can come in handy when you are coding up some software that expires.&lt;br /&gt;&lt;br /&gt;PuTTY is an SSH client. It also does Telnet as well as xterm terminal emulation. The web site where you download it from has a warning. The software is illegal if encryption is illegal in your country. Weird. This program is better than the stock applications that come with Microsoft Windows.&lt;br /&gt;&lt;br /&gt;The Advanced Port Scanner is a tool that runs on Windows. You enter an IP address or a range of addresses to scan. This program is fast because it is multithreaded. You actually specify how many threads you want it to run. The latest version of the program was released in 2006. You can save the options for reuse.&lt;br /&gt;&lt;br /&gt;Some other tools of interest include nmap and p0f. They are a network mapper and passive listener respectively. Maybe I will review them in depth some time later.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-4590898426862725469?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/4590898426862725469/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=4590898426862725469' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4590898426862725469'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4590898426862725469'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/04/hacking-tools.html' title='Hacking Tools'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-dBe8mlPm3rw/TZ_Z-MlV6aI/AAAAAAAAAeM/ykt9IXTFSKs/s72-c/Putty.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-7538384306223631833</id><published>2011-04-06T11:01:00.002-04:00</published><updated>2011-04-06T11:32:26.342-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='plugins'/><category scheme='http://www.blogger.com/atom/ns#' term='Notepad++'/><title type='text'>More Free Tools</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-F4YLI9wmhFo/TZyAXiQp0gI/AAAAAAAAAeE/JCuxnjM72i8/s1600/Notepad.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 256px; height: 256px;" src="http://2.bp.blogspot.com/-F4YLI9wmhFo/TZyAXiQp0gI/AAAAAAAAAeE/JCuxnjM72i8/s320/Notepad.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5592485979109315074" /&gt;&lt;/a&gt;I just finished reading a post about the massive amount of plugins that are available for Notepad++. There were a bunch of them that sounded cool. The post states that these plugins can make developers ultra productive.&lt;br /&gt;&lt;br /&gt;Notepad++ is a free application that replaces Windows Notepad. It runs only on the Windows platform. The app is released under the GPL license. It is written in C++, and uses raw Win32 calls plus the Standard Template Library (STL). This thing is fast.&lt;br /&gt;&lt;br /&gt;Let's talk about the plugins themselves. XML Tools lets you edit XML files. The Compare Plugin shows you the difference between two files. Windows Manager shows the files you have opened in Notepad++. XBrackets Lite matches up brackets in your code. TopMost puts the Notepad++ window on top of all others always.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-7538384306223631833?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/7538384306223631833/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=7538384306223631833' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7538384306223631833'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7538384306223631833'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/04/more-free-tools.html' title='More Free Tools'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-F4YLI9wmhFo/TZyAXiQp0gI/AAAAAAAAAeE/JCuxnjM72i8/s72-c/Notepad.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-5635312264934091041</id><published>2011-04-05T14:51:00.002-04:00</published><updated>2011-04-05T14:58:41.940-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='tcpdump'/><category scheme='http://www.blogger.com/atom/ns#' term='backups'/><title type='text'>Open Source Tools</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/-Zyj6XBV5ho4/TZtk2FMqxrI/AAAAAAAAAd8/rTPM1yjJSTo/s1600/Axcrypt.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 150px; height: 112px;" src="http://4.bp.blogspot.com/-Zyj6XBV5ho4/TZtk2FMqxrI/AAAAAAAAAd8/rTPM1yjJSTo/s320/Axcrypt.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5592174242581628594" /&gt;&lt;/a&gt;It seems like there are a lot of free open source tools out there in the security sector. I just read an article that listed 59 such tools. I checked most of them out. Some of them look worthwhile. I am going to highlight three of them here.&lt;br /&gt;&lt;br /&gt;Take a look at Bacula for doing backups. You can perform the backup over a network. This tool is truly simple to set up. It is called "enterprise ready". This tool has its own conference. Damn. It is released in an AGPL license. Code is stored in Sourceforge.&lt;br /&gt;&lt;br /&gt;How about AxCrypt? It is totally integrated into Windows. Right click to encrypt. Double click to decrypt. It does not get any simpler than that. Currently there are 2 million users of this product. The developers request a $5 or $10 donation if you love this software.&lt;br /&gt;&lt;br /&gt;You may have heard of tcpdump for UNIX. Well now we have WinDump for Windows. This is a command line network analyzer. It needs the WinPCap library. It can deal with wireless networks. This software is being released under the BSD license.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-5635312264934091041?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/5635312264934091041/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=5635312264934091041' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5635312264934091041'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5635312264934091041'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/04/open-source-tools.html' title='Open Source Tools'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-Zyj6XBV5ho4/TZtk2FMqxrI/AAAAAAAAAd8/rTPM1yjJSTo/s72-c/Axcrypt.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-4296563320827106633</id><published>2011-04-04T13:06:00.002-04:00</published><updated>2011-04-04T13:11:35.997-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='registrar'/><category scheme='http://www.blogger.com/atom/ns#' term='registry DB'/><category scheme='http://www.blogger.com/atom/ns#' term='snatch up'/><category scheme='http://www.blogger.com/atom/ns#' term='domain name'/><title type='text'>Front Running</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-_7mI6x-k_VY/TZn6tMJpHNI/AAAAAAAAAd0/jTfyqh5l1sQ/s1600/Registrar.gif"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 278px;" src="http://1.bp.blogspot.com/-_7mI6x-k_VY/TZn6tMJpHNI/AAAAAAAAAd0/jTfyqh5l1sQ/s320/Registrar.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5591776066619907282" /&gt;&lt;/a&gt;You want to register a domain for yourself. The first thing you do is search whether somebody else already owns the domain. The problem is that by doing the search, people get informed that you are interested. Registrars will then do some front running, actually registering the domain for themselves. Then you need to deal with them to buy it from them. That can be prohibitive.&lt;br /&gt;&lt;br /&gt;What a sleazy business some of these registrars run. I have heard about this nonsense before. The trick to making sure somebody does not scoop up the new domain you want is to do the query against the actual registry database. Don't go through one of the registrars. Don't even do a Google search for the domain. Somebody is most likely going to snatch up your domain.&lt;br /&gt;&lt;br /&gt;I thought about this problem a bit. Why not attack the source of the problem? Stick it to the greedy registrars. Let's flood them with a bunch of queries checking for domains. I can write a problem that comes up with random domain names and then checks them. If the cost to pre-register all these domain names is too high, perhaps they will stop this idiotic behavior. Sounds like a nice little project for me to code up. What language should I used?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-4296563320827106633?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/4296563320827106633/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=4296563320827106633' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4296563320827106633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4296563320827106633'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/04/front-running.html' title='Front Running'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-_7mI6x-k_VY/TZn6tMJpHNI/AAAAAAAAAd0/jTfyqh5l1sQ/s72-c/Registrar.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3171136123967107150</id><published>2011-03-31T14:19:00.002-04:00</published><updated>2011-03-31T14:33:28.422-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Starlogger'/><category scheme='http://www.blogger.com/atom/ns#' term='manufacturer'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><title type='text'>Samsung Shipping Spyware?</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-upp0gvzwAvk/TZTFvkn9fRI/AAAAAAAAAds/LE9DMt5Ty2o/s1600/StarLogger.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 247px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5590310458549435666" border="0" alt="" src="http://2.bp.blogspot.com/-upp0gvzwAvk/TZTFvkn9fRI/AAAAAAAAAds/LE9DMt5Ty2o/s320/StarLogger.jpg" /&gt;&lt;/a&gt;Some dude came out and accused Samsung of shipping laptops with spyware installed. He used a program that detected Starlogger installed on his laptop. So he deduced that the culprit must be the manufacturer. This guy founded a consulting company. Maybe this is him doing a good dead by spreading the info. Or maybe he is looking for some free publicity.&lt;br /&gt;&lt;br /&gt;Samsung has since come out and refuted the guy's claims. He says they do not install any such spyware. In fact, they determined that the dude was using a program that thinks it detects Starlogger, but is in error. Well this made for a sensational headline anyway.&lt;br /&gt;&lt;br /&gt;Starlogger is a $23 piece of shareware that will secretly record all the keystrokes on a computer. It is supposed to be "undetectable". Starlogger can then email you data it collects. By the way, it can also take screen shots at given intervals to see what the user is doing.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3171136123967107150?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3171136123967107150/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3171136123967107150' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3171136123967107150'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3171136123967107150'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/03/samsung-shipping-spyware.html' title='Samsung Shipping Spyware?'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-upp0gvzwAvk/TZTFvkn9fRI/AAAAAAAAAds/LE9DMt5Ty2o/s72-c/StarLogger.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-4113805144591652854</id><published>2011-03-13T21:27:00.002-04:00</published><updated>2011-03-13T21:33:20.297-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iPhone'/><category scheme='http://www.blogger.com/atom/ns#' term='arcade'/><category scheme='http://www.blogger.com/atom/ns#' term='cash'/><category scheme='http://www.blogger.com/atom/ns#' term='restart'/><category scheme='http://www.blogger.com/atom/ns#' term='apps'/><category scheme='http://www.blogger.com/atom/ns#' term='coins'/><title type='text'>Coin Dozer Hack</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-Hbq2C03gaqM/TX1vXbyuQlI/AAAAAAAAAdk/yf9c6wyh7MA/s1600/Dozer.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 214px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5583741561397461586" border="0" alt="" src="http://3.bp.blogspot.com/-Hbq2C03gaqM/TX1vXbyuQlI/AAAAAAAAAdk/yf9c6wyh7MA/s320/Dozer.jpg" /&gt;&lt;/a&gt;I finally finished coding my &lt;a href="http://legend-angband.blogspot.com/2011/03/introducing-my-roguelike-jsrl.html"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;roguelike&lt;/span&gt;&lt;/a&gt; game &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;JSRL&lt;/span&gt;. Now let's get back to hacking. I have been addicted to this iPhone game called Coin &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Dozer&lt;/span&gt;. It looks like a real arcade game where you put coins in and try to make coins fall out in front.&lt;br /&gt;&lt;br /&gt;You start out with 40 coins. There are many ways to get new coins. You slowly gain them as time goes on. You can install other apps on your phone to get some coins. Some of those apps cost money. You can also pay real cash for coins.&lt;br /&gt;&lt;br /&gt;My goal is to not have to pay for apps or coins. So how do you do this? There are many techniques to do well in the game. But there is one hack that is very handy. You can always exit the game, and restart it. When you do this, the gold coins get restored back to the original position. This can help you out a lot.&lt;br /&gt;&lt;br /&gt;I found the optimal game play is to do two sets of three coins each. That ensures a bunch of coins get pushed out the end for you. Then exit and restart the game. Repeat. This can keep me playing indefinitely with a lot of coins. Yeah it is just a game. But I play this game all the time. This little "feature" is keeping me stocked full of a lot of coins. Good luck in your coin dozing.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-4113805144591652854?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/4113805144591652854/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=4113805144591652854' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4113805144591652854'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4113805144591652854'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/03/coin-dozer-hack.html' title='Coin Dozer Hack'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-Hbq2C03gaqM/TX1vXbyuQlI/AAAAAAAAAdk/yf9c6wyh7MA/s72-c/Dozer.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-6108708721739530907</id><published>2011-03-05T00:41:00.003-05:00</published><updated>2011-03-05T00:50:28.668-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='JavaScript'/><category scheme='http://www.blogger.com/atom/ns#' term='Java'/><category scheme='http://www.blogger.com/atom/ns#' term='Netscape'/><category scheme='http://www.blogger.com/atom/ns#' term='browser'/><category scheme='http://www.blogger.com/atom/ns#' term='Angband'/><title type='text'>Out of Commission</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/-PQSZ8IiJS3w/TXHNKdR_niI/AAAAAAAAAdc/t_iIiTHcsgs/s1600/JavaScript.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 258px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5580466992831241762" border="0" alt="" src="http://4.bp.blogspot.com/-PQSZ8IiJS3w/TXHNKdR_niI/AAAAAAAAAdc/t_iIiTHcsgs/s320/JavaScript.jpg" /&gt;&lt;/a&gt;I have been a bit busy lately. My college cancelled a class I wanted to take in &lt;a href="http://xmlhome.blogspot.com/2011/02/debugging-javascript.html"&gt;JavaScript&lt;/a&gt;. I decided to take matters into my own hands and learn the programming language myself. I bought the college textbook on Amazon and started to learn. I find the best way to learn is to actually code in the language. I do all the exercises at the end of each chapter.&lt;br /&gt;&lt;br /&gt;So far I have gone through about 10 chapters. At first I did not like JavaScript much. But I am learning to appreciate some things. JavaScript is an interpreted language. When there is an error, the browser knows exactly which line has the error. But let's get back to the beginning. What the heck is JavaScript?&lt;br /&gt;&lt;br /&gt;JavaScript is a language invented by the now defunct Netscape. It is a scripting style language that runs in the web browser. The goal of the language was to add the ability to do dynamic operations on web pages. Note that JavaScript is unrelated to &lt;a href="http://enableassertions.blogspot.com/"&gt;Java&lt;/a&gt;, which is a general purpose programming language. JavaScript is now starting to be used on servers as well. But that is a story for another post.&lt;br /&gt;&lt;br /&gt;Next week I plan to enter a game writing contest to generate a game like &lt;a href="http://legend-angband.blogspot.com/"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Angband&lt;/span&gt;&lt;/a&gt;. And I am going to code the darn thing in JavaScript if at all possible. I did the same exercise in the past when I was learning the Java programming language. After I get JavaScript out of my system, expect more posts on hacking material.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-6108708721739530907?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/6108708721739530907/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=6108708721739530907' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6108708721739530907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6108708721739530907'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/03/out-of-commission.html' title='Out of Commission'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-PQSZ8IiJS3w/TXHNKdR_niI/AAAAAAAAAdc/t_iIiTHcsgs/s72-c/JavaScript.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-8609027062475914330</id><published>2011-02-14T09:49:00.003-05:00</published><updated>2011-02-14T09:57:10.973-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='lincese fee'/><category scheme='http://www.blogger.com/atom/ns#' term='registry'/><category scheme='http://www.blogger.com/atom/ns#' term='antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='browsers'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><title type='text'>AVG Antivirus 2011</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-XVkSTNql-2U/TVlBlBPbm2I/AAAAAAAAAdU/APSxNXuk20E/s1600/AVG.png"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 147px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5573558118091823970" border="0" alt="" src="http://3.bp.blogspot.com/-XVkSTNql-2U/TVlBlBPbm2I/AAAAAAAAAdU/APSxNXuk20E/s320/AVG.png" /&gt;&lt;/a&gt;There is a phony version of AVG Antivirus 2011 going around. It tries to trick users into paying a license fee to avoid the annoying &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;popups&lt;/span&gt; it produces. The real hack is that it also adds some registry entries that make most major browsers run the fake program instead.&lt;br /&gt;&lt;br /&gt;If you want to get around this, rename your browser executable file names. Get rid of "avg.&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;exe&lt;/span&gt;: that is located in C:\Program Files\AVG Antivirus 2011. You should also delete C:\Windows\system32\&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;iesafemode&lt;/span&gt;.&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;exe&lt;/span&gt;. A good antivirus such a &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;Spyware&lt;/span&gt; Doctor can help rid you of this nuisance.&lt;br /&gt;&lt;br /&gt;How does the program hijack the other browsers? It adds some registry keys in &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;HKEY&lt;/span&gt; LOCAL MACHINE. &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;Specifially&lt;/span&gt; there is an &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;ImageFileExecution&lt;/span&gt; Options location in the registry that allows you to redirect &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;iexplore&lt;/span&gt;.&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;exe&lt;/span&gt;, chrome.&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;exe&lt;/span&gt;, &lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;firefox&lt;/span&gt;.&lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;exe&lt;/span&gt;, and any other executable name. The fake AVG Antivirus 2011 intercepts these and all other popular web browsers. What an effort.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-8609027062475914330?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/8609027062475914330/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=8609027062475914330' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8609027062475914330'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8609027062475914330'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/02/avg-antivirus-2011.html' title='AVG Antivirus 2011'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-XVkSTNql-2U/TVlBlBPbm2I/AAAAAAAAAdU/APSxNXuk20E/s72-c/AVG.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3765002796944041892</id><published>2011-02-08T15:20:00.003-05:00</published><updated>2011-02-08T15:24:56.288-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='BOINC'/><category scheme='http://www.blogger.com/atom/ns#' term='SETI'/><category scheme='http://www.blogger.com/atom/ns#' term='torrent'/><category scheme='http://www.blogger.com/atom/ns#' term='TOR'/><title type='text'>Use for Old Computers</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_VDmxk13I3SA/TVGlojyd9GI/AAAAAAAAAdE/kVdhUg-WwR8/s1600/Computer.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 240px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5571416330254283874" border="0" alt="" src="http://3.bp.blogspot.com/_VDmxk13I3SA/TVGlojyd9GI/AAAAAAAAAdE/kVdhUg-WwR8/s320/Computer.jpg" /&gt;&lt;/a&gt;I just read an article on the many uses of old computers. The best ideas seemed to be ways to allow your computer to be used by others over the net. One obvious use is to let the old computer serve up torrent files. Even a lanky old Pentium came server this purpose.&lt;br /&gt;&lt;br /&gt;Another noble use for your old PC is to have is join the TOR network. This essentially allows users to hide their location and identity. It makes it harder for somebody to track their internet traffic. The goal of this system is to provide personal freedom. The software is open source. It is good for IRC, Instant Messaging, and web browsing.&lt;br /&gt;&lt;br /&gt;Finally you can install the BOINC client on your computer. It lets you choose worthy projects for your computer to work on during idle processing. For example, you can help the search for extra terrestials by choosing the SETI project. If your old computer has a graphics processing unit (GPU), it will help the effort even more. Now there is no need to junk that old PC. Put it to good use.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3765002796944041892?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3765002796944041892/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3765002796944041892' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3765002796944041892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3765002796944041892'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/02/use-for-old-computers.html' title='Use for Old Computers'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VDmxk13I3SA/TVGlojyd9GI/AAAAAAAAAdE/kVdhUg-WwR8/s72-c/Computer.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-2331052701473993182</id><published>2011-02-02T14:54:00.001-05:00</published><updated>2011-02-02T14:54:00.106-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQL injection'/><category scheme='http://www.blogger.com/atom/ns#' term='Plenty of Fish'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft SQL Server'/><title type='text'>Two Tales of a Hacking</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_VDmxk13I3SA/TUcTlqtr12I/AAAAAAAAAc4/qCYPV_dueDo/s1600/PlentyOfFish.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 287px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5568441002108901218" border="0" alt="" src="http://3.bp.blogspot.com/_VDmxk13I3SA/TUcTlqtr12I/AAAAAAAAAc4/qCYPV_dueDo/s320/PlentyOfFish.jpg" /&gt;&lt;/a&gt;Markus &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Frind&lt;/span&gt;, founder of dating web site Plenty of Fish, says his site got hacked last week. The hacker got away with user email addresses, user names, and passwords. Plenty of Fish has since reset the passwords.&lt;br /&gt;&lt;br /&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;Frind&lt;/span&gt; accuses Chris Russo as the hacker. He said it took Russo 2 days to break into their system. Then &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Frind&lt;/span&gt; states that Russo called &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;Frind's&lt;/span&gt; home to extort him. He says that Russo is a 23 year old from Argentina. &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;Frind&lt;/span&gt; says Russo wanted access to all the source code from Plenty of Fish, as well as unspecified money for "security services".&lt;br /&gt;&lt;br /&gt;Chris Russo, on the other hand, says he only reported a bug. He discovered a vulnerability that affected all 28 million Plenty of Fish user accounts. The vulnerability was fixed. Russo goes on to say that Plenty of Fish wanted to hire him as a security professional.&lt;br /&gt;&lt;br /&gt;The specifics of the &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;vuln&lt;/span&gt; were based on a Microsoft &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;SQL&lt;/span&gt; Server injection hole. It allowed a hacker to make a full backup of the database. You combine that with the fact that Plenty of Fish stores user passwords in plain text, and you get disaster. So who are we going to believe here? I bet like most cases, both sides are telling some truth, and are also adding some lies. It really seems like a mess.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-2331052701473993182?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/2331052701473993182/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=2331052701473993182' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2331052701473993182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2331052701473993182'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/02/two-tales-of-hacking.html' title='Two Tales of a Hacking'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VDmxk13I3SA/TUcTlqtr12I/AAAAAAAAAc4/qCYPV_dueDo/s72-c/PlentyOfFish.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-2188121778041256761</id><published>2011-02-01T14:05:00.002-05:00</published><updated>2011-02-01T14:05:00.652-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='script kiddies'/><category scheme='http://www.blogger.com/atom/ns#' term='FBI'/><category scheme='http://www.blogger.com/atom/ns#' term='low orbit ion cannon'/><title type='text'>Anonymous was not Really Anonymous</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TUcIGyfnAtI/AAAAAAAAAcw/i9llJiNBWjg/s1600/Anonymous.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 267px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5568428376993497810" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TUcIGyfnAtI/AAAAAAAAAcw/i9llJiNBWjg/s320/Anonymous.jpg" /&gt;&lt;/a&gt;I saw an interesting article on &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Arstechnica&lt;/span&gt; about the FBI raiding people in the Anonymous group. However the real gem was all the reader comments on the post.&lt;br /&gt;&lt;br /&gt;Here is what went down. In the USA, the FBI raided the houses of a number of members in the group called Anonymous. They must have been a part of a recent &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;DDOS&lt;/span&gt; attack, and used their own computers in their houses. In other words, they got tracked down.&lt;br /&gt;&lt;br /&gt;Anonymous says they launched the &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;DDOS&lt;/span&gt; as a method of protest. They used the low orbit ion cannon app to blast some web sites. Well if you are going to protest, you got to be ready for the cops to round you up and cuff you.&lt;br /&gt;&lt;br /&gt;People are calling the Anonymous &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;DDOS&lt;/span&gt; team a bunch of script kiddies. Whatever they are, it looks like the FBI literally was busting down their doors. Couldn't these so called hackers have used some &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;unsecure&lt;/span&gt; &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;WiFi&lt;/span&gt; that belonged to someone else?&lt;br /&gt;&lt;br /&gt;Nope. It looked like they downloaded "&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;loic&lt;/span&gt;.&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;exe&lt;/span&gt;" onto their own computers and ran it. The thing that is strange is that the FBI usually does not kick down doors when following up on white collar crime like &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;DDOS&lt;/span&gt; attacks. Perhaps the Anonymous crew was exaggerating a bit.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-2188121778041256761?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/2188121778041256761/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=2188121778041256761' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2188121778041256761'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2188121778041256761'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/02/anonymous-was-not-really-anonymous.html' title='Anonymous was not Really Anonymous'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TUcIGyfnAtI/AAAAAAAAAcw/i9llJiNBWjg/s72-c/Anonymous.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3919698136098821349</id><published>2011-01-31T11:16:00.004-05:00</published><updated>2011-01-31T11:25:11.528-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rustock'/><category scheme='http://www.blogger.com/atom/ns#' term='Waledac'/><category scheme='http://www.blogger.com/atom/ns#' term='Zeus crimeware toolkit'/><title type='text'>Botnet Activity</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_VDmxk13I3SA/TUbgYesEMXI/AAAAAAAAAco/T_KG6X58UGg/s1600/Botnet.png"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 248px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5568384700449567090" border="0" alt="" src="http://2.bp.blogspot.com/_VDmxk13I3SA/TUbgYesEMXI/AAAAAAAAAco/T_KG6X58UGg/s320/Botnet.png" /&gt;&lt;/a&gt;Security experts had noticed a downturn in &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;botnet&lt;/span&gt; activity at the end of 2010. It was just a temporary effect. &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;Botnets&lt;/span&gt; are coming back strong in 2011. Some popular &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;botnets&lt;/span&gt; running &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-corrected"&gt;amok&lt;/span&gt; now are the &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;Waledac&lt;/span&gt; &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;botnet&lt;/span&gt; and the &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;Rustock&lt;/span&gt; &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;botnet&lt;/span&gt;. These are email spamming &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;botnets&lt;/span&gt; that operate on a huge scale.&lt;br /&gt;&lt;br /&gt;There are predictions that the Zeus &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-corrected"&gt;crime ware&lt;/span&gt; toolkit will take home the prize for 2011. This is a tool that steals personal data. Specifically it targets banking info. You can use this toolkit to create your own &lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;botnet&lt;/span&gt; variant. Since it is easy to use, even noons can get down with Zeus. This tool attacks traffic (even secure traffic) send through the browser.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3919698136098821349?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3919698136098821349/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3919698136098821349' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3919698136098821349'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3919698136098821349'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/01/botnet-activity.html' title='Botnet Activity'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VDmxk13I3SA/TUbgYesEMXI/AAAAAAAAAco/T_KG6X58UGg/s72-c/Botnet.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-425908667646998182</id><published>2011-01-24T13:17:00.003-05:00</published><updated>2011-01-24T13:20:24.232-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Luhn algorithm'/><category scheme='http://www.blogger.com/atom/ns#' term='issuer'/><category scheme='http://www.blogger.com/atom/ns#' term='industry'/><category scheme='http://www.blogger.com/atom/ns#' term='account number'/><title type='text'>Credit Card Numbers</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_VDmxk13I3SA/TT3COFWhEoI/AAAAAAAAAcg/k4Mk9rMMSno/s1600/CreditCard.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 214px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5565818261710377602" border="0" alt="" src="http://1.bp.blogspot.com/_VDmxk13I3SA/TT3COFWhEoI/AAAAAAAAAcg/k4Mk9rMMSno/s320/CreditCard.jpg" /&gt;&lt;/a&gt;Your 16 digit credit card number is not a random number. Each of the digits means something. I read about this today and am passing on what I learned.&lt;br /&gt;&lt;br /&gt;The first digit is the industry of the credit card issuer. The first six digits are the ID of the issuer. Digits 7 through 15 are your account number. And the last digit is a &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;checksum&lt;/span&gt; of sorts.&lt;br /&gt;&lt;br /&gt;The &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;checksum&lt;/span&gt; uses the &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Luhn&lt;/span&gt; algorithm. This is also &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-corrected"&gt;called&lt;/span&gt; the mod 10 algorithm. It doesn't use any cryptography. It just tries to detect if any one of the digits is incorrect due to error.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-425908667646998182?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/425908667646998182/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=425908667646998182' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/425908667646998182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/425908667646998182'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/01/credit-card-numbers.html' title='Credit Card Numbers'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VDmxk13I3SA/TT3COFWhEoI/AAAAAAAAAcg/k4Mk9rMMSno/s72-c/CreditCard.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-2681933042243796236</id><published>2011-01-06T15:25:00.003-05:00</published><updated>2011-01-06T15:37:00.941-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='EWG'/><category scheme='http://www.blogger.com/atom/ns#' term='filters'/><category scheme='http://www.blogger.com/atom/ns#' term='tap water'/><title type='text'>Bottled Water Debate</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_VDmxk13I3SA/TSYlT_BBF5I/AAAAAAAAAcY/l4M0-OYrwkY/s1600/Water.bmp"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 290px; FLOAT: left; HEIGHT: 250px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5559171815298897810" border="0" alt="" src="http://1.bp.blogspot.com/_VDmxk13I3SA/TSYlT_BBF5I/AAAAAAAAAcY/l4M0-OYrwkY/s320/Water.bmp" /&gt;&lt;/a&gt;I am starting to hear some rumblings from the Environmental Working Group (&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;EWG&lt;/span&gt;). They are a non-profit organization. Their goal is to advocate the government to assist in figure out what the heck goes into bottled water. They achieve this means by doing research on the subject.&lt;br /&gt;&lt;br /&gt;Here is what the &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;EWG&lt;/span&gt; has to say. By all means drink a bunch of water. But avoid bottled water. The contents of public drinking water is well documented. Use the correct filters (e.g. carbon or reverse osmosis). They also recommend you use a safe water container.&lt;br /&gt;&lt;br /&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;EWG&lt;/span&gt; also has a 2011 report on their findings for pretty much all the bottled water distributors. They complain that most of these companies keep secret the contents of the water they distribute. &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;EWG&lt;/span&gt; wants the EPA to start cracking down on these water bottlers to disclose the contents of their water.&lt;br /&gt;&lt;br /&gt;All of this sounds like big business. Bottled water is probably a huge dollar industry. I am not exactly sure what to think about the &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;EWG&lt;/span&gt;. Usually there is some underlying motive in groups such as this.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-2681933042243796236?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/2681933042243796236/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=2681933042243796236' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2681933042243796236'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2681933042243796236'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/01/bottled-water-debate.html' title='Bottled Water Debate'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VDmxk13I3SA/TSYlT_BBF5I/AAAAAAAAAcY/l4M0-OYrwkY/s72-c/Water.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-1659655656236118714</id><published>2011-01-03T15:12:00.003-05:00</published><updated>2011-01-03T15:16:29.363-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='seed'/><category scheme='http://www.blogger.com/atom/ns#' term='leecher'/><category scheme='http://www.blogger.com/atom/ns#' term='tracker'/><category scheme='http://www.blogger.com/atom/ns#' term='torrent'/><title type='text'>BitTorrent</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_VDmxk13I3SA/TSItrzTtRMI/AAAAAAAAAcQ/xcJot0IUj3w/s1600/Bittorrent.png"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 256px; FLOAT: left; HEIGHT: 256px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5558055120659104962" border="0" alt="" src="http://1.bp.blogspot.com/_VDmxk13I3SA/TSItrzTtRMI/AAAAAAAAAcQ/xcJot0IUj3w/s320/Bittorrent.png" /&gt;&lt;/a&gt;I confess that I do not know a lot about &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;BitTorrent&lt;/span&gt;. So I picked up a dummies book about it at the public library. Here is what I learned.&lt;br /&gt;&lt;br /&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;BitTorrent&lt;/span&gt; traffic accounts for almost a third of all Internet traffic. That might be because it is suitable to transmission of large files. We are talking about &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Gigabyes&lt;/span&gt; here. The file sharing is distributed, which is different from FTP where there is one serving giving you the goods.&lt;br /&gt;&lt;br /&gt;There is a lot of vocabulary in the &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;BitTorrent&lt;/span&gt; world. A torrent is a small file &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-corrected"&gt;containing&lt;/span&gt; the table of contents for a file. A &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;leecher&lt;/span&gt; is somebody who has not downloaded the entire file yet. A seed, on the other hand, has the whole file and is sharing it.&lt;br /&gt;&lt;br /&gt;A swarm is the set of &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;leechers&lt;/span&gt; and seeds for a given file. Trackers are web server software packages that manage the interaction between seeds and leeches. Now down to a bit of technical data. &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;BitTorrent&lt;/span&gt; uses ports 6881 through 6889 for its communications. So open up those ports in your firewall.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-1659655656236118714?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/1659655656236118714/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=1659655656236118714' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1659655656236118714'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1659655656236118714'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2011/01/bittorrent.html' title='BitTorrent'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VDmxk13I3SA/TSItrzTtRMI/AAAAAAAAAcQ/xcJot0IUj3w/s72-c/Bittorrent.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-7541883548237898854</id><published>2010-12-29T21:42:00.004-05:00</published><updated>2010-12-29T21:51:13.712-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IRC'/><category scheme='http://www.blogger.com/atom/ns#' term='Delae'/><category scheme='http://www.blogger.com/atom/ns#' term='SPTH'/><category scheme='http://www.blogger.com/atom/ns#' term='zine'/><category scheme='http://www.blogger.com/atom/ns#' term='hh86'/><title type='text'>Chick Virus Writers</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_VDmxk13I3SA/TRvxvBEbYQI/AAAAAAAAAcI/XBhBxo7HLhs/s1600/Female.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 193px; FLOAT: left; HEIGHT: 261px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5556300355334791426" border="0" alt="" src="http://1.bp.blogspot.com/_VDmxk13I3SA/TRvxvBEbYQI/AAAAAAAAAcI/XBhBxo7HLhs/s320/Female.jpg" /&gt;&lt;/a&gt;I read this interview with a female hacker. She writes viruses and is a freelancer. She goes by the handle  &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;hh&lt;/span&gt;86. Credit to &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;SPTH&lt;/span&gt; for the original interview.&lt;br /&gt;&lt;br /&gt;So &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;hh&lt;/span&gt;86 says that her friends really don't know she is a virus writer. Incognito. Nice. She is hard core in that she writes her viruses in assembly language. Writing with compiled languages is restricting for her.&lt;br /&gt;&lt;br /&gt;Shrug for the 64 bit Windows platform is a virus she admires. She is author of the &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;Delae&lt;/span&gt; family of viruses. These are ones with names that start with w32.&lt;br /&gt;&lt;br /&gt;One of &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;hh&lt;/span&gt;86's techniques is to obscure the entry point of her viruses. Unlike other virus authors, she does not do &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;IRC&lt;/span&gt; much. She is in contact with antivirus peeps.&lt;br /&gt;&lt;br /&gt;Look for a new zine to be released by &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;hh&lt;/span&gt;86 next month.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-7541883548237898854?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/7541883548237898854/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=7541883548237898854' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7541883548237898854'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7541883548237898854'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/12/chick-virus-writers.html' title='Chick Virus Writers'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VDmxk13I3SA/TRvxvBEbYQI/AAAAAAAAAcI/XBhBxo7HLhs/s72-c/Female.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3989141350456822123</id><published>2010-12-29T11:24:00.002-05:00</published><updated>2010-12-29T11:26:13.089-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='JavsScript'/><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='MAC'/><category scheme='http://www.blogger.com/atom/ns#' term='DefCon'/><title type='text'>Find Your Foe</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_VDmxk13I3SA/TRtg2At1c0I/AAAAAAAAAcA/aV4_XJ4eWCs/s1600/GPS.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 240px;" src="http://3.bp.blogspot.com/_VDmxk13I3SA/TRtg2At1c0I/AAAAAAAAAcA/aV4_XJ4eWCs/s320/GPS.jpg" alt="" id="BLOGGER_PHOTO_ID_5556141046313087810" border="0" /&gt;&lt;/a&gt;Continuing from my last post, I learned a few tricks by watching some video from &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;DefCon&lt;/span&gt; 18. Everyone has a web browser. You can use the browser to deliver software to users.&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;FaceBook&lt;/span&gt; has a feature where the client checks whether a user's friends are online or not. This is just an HTTP request to &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;FaceBook&lt;/span&gt;. Good stuff to know.&lt;br /&gt;&lt;br /&gt;Here was the finale of the talk I watched. Create a web page with malicious code. Have a piece of JavaScript that inquires the MAC address of the user's router.&lt;br /&gt;&lt;br /&gt;The MAC address is set in hardware. It cannot be changed. Once you have the user's MAC address, you can send it to Google. Then Google will tell you where the router is located geographically. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Bamm&lt;/span&gt;. You can track the people who come to your web paged. Owned.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3989141350456822123?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3989141350456822123/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3989141350456822123' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3989141350456822123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3989141350456822123'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/12/find-your-foe.html' title='Find Your Foe'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VDmxk13I3SA/TRtg2At1c0I/AAAAAAAAAcA/aV4_XJ4eWCs/s72-c/GPS.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-6781796998324454953</id><published>2010-12-28T04:25:00.003-05:00</published><updated>2010-12-28T04:35:19.474-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PHP'/><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='cookie'/><category scheme='http://www.blogger.com/atom/ns#' term='Hip Hop'/><category scheme='http://www.blogger.com/atom/ns#' term='session'/><title type='text'>Cracking the FaceBook Session</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_VDmxk13I3SA/TRmtJ5CTUxI/AAAAAAAAAbw/oBz2jv_9vWU/s1600/Girlfriend.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 217px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5555662000779121426" border="0" alt="" src="http://2.bp.blogspot.com/_VDmxk13I3SA/TRmtJ5CTUxI/AAAAAAAAAbw/oBz2jv_9vWU/s320/Girlfriend.jpg" /&gt;&lt;/a&gt;Just watched a 3 part series on YouTube. It was from &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;DefCon&lt;/span&gt; 18. Dude was looking to exploit another guy on &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;FaceBook&lt;/span&gt;. He noted that &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;FaceBook&lt;/span&gt; uses &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;PHP&lt;/span&gt;. And &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;PHP&lt;/span&gt; is open source, including its session management code. When you log into &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;FaceBook&lt;/span&gt;, you get a session which is nothing &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-corrected"&gt;more&lt;/span&gt; than a random string.&lt;br /&gt;&lt;br /&gt;The session string is stored as a cookie in your browser. &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;PHP&lt;/span&gt; session creation uses a 160 bit string. It would take millions of year to brute force such a string. However you can study the properties of the string to narrow down the possible values it might contain. Then you can narrow down the bits that are truly random, and break down the door.&lt;br /&gt;&lt;br /&gt;One part of the string is the &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;IP&lt;/span&gt; address. You can grab this by sending a person to your web site. Another piece of the string are two random number seeded with the web server start time. Cause the server to reboot, and you will approximately know when the start time is.&lt;br /&gt;&lt;br /&gt;So after narrowing down the cookie, our friend managed to narrow the random bits down from 160 to 20. Now 20 bits can be cracked in a few seconds. He measured that it takes on average 500k attempts to guess 20 bits of random numbers. Good stuff. Getting back to &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;FaceBook&lt;/span&gt;, they actually use a modified version of &lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;PHP&lt;/span&gt; called Hip Hop. And after our boy figured out how to crack the session cookie, &lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;PHP&lt;/span&gt; was patched to make it harder to crack.&lt;br /&gt;&lt;br /&gt;Maybe next time I will also go over how this dude can figure out where you are geographically located by hacking your router. I love it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-6781796998324454953?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/6781796998324454953/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=6781796998324454953' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6781796998324454953'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6781796998324454953'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/12/cracking-facebook-session.html' title='Cracking the FaceBook Session'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VDmxk13I3SA/TRmtJ5CTUxI/AAAAAAAAAbw/oBz2jv_9vWU/s72-c/Girlfriend.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-6132494921046723424</id><published>2010-12-21T00:48:00.002-05:00</published><updated>2010-12-21T00:56:27.689-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Midnight Deadline'/><category scheme='http://www.blogger.com/atom/ns#' term='ATM'/><category scheme='http://www.blogger.com/atom/ns#' term='non-negotiable'/><category scheme='http://www.blogger.com/atom/ns#' term='junk mail'/><title type='text'>Phony Checks</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_VDmxk13I3SA/TRA_vQzeoUI/AAAAAAAAAbk/kZrwwABKMoU/s1600/Check.gif"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 124px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5553008421745107266" border="0" alt="" src="http://2.bp.blogspot.com/_VDmxk13I3SA/TRA_vQzeoUI/AAAAAAAAAbk/kZrwwABKMoU/s320/Check.gif" /&gt;&lt;/a&gt;I just read this &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;doozy&lt;/span&gt; of a story. It was from way back in 1995. A dude got a piece of junk mail with a $95,000 check in it. The check had the words non-negotiable written in the corner. So the guy goes to his ATM and deposits the check. 10 days later, the money is still in his account. A teller from the bank says the money is his since it has been over 10 business days and the check had not been returned. This is a synopsis of the Midnight Deadline.&lt;br /&gt;&lt;br /&gt;The dude did some researching on check validity. The authority on this subject if the banking book by Brady. It states what a check needs in order to be valid. Just because a check has the words non-negotiable on it does not make it invalid. So the guys thinks about trying to get the $95k out of his account in cash. But that is a big process because banks usually don't dole out so much cash. Instead he gets a cashiers check.&lt;br /&gt;&lt;br /&gt;Over a month later, a security officer from the bank accuses the guy of fraud. However all checks are initially assumed to be valid. The bank must server the depositor a notice of dishonor in a timely fashion. This was obviously not the case with this guy (it had been over a month). The guy decides he wants to get the Wall Street Journal to do an article on him. It takes a long time for that article to make it to print.&lt;br /&gt;&lt;br /&gt;The guy decides to put the story on his own web site. His bank account gets frozen. His ATM card gets confiscated. He tries unsuccessfully to reach the president of the bank. In the end, he winds up negotiating with senior counsel from the bank. He can't get any photographers in the bank on the day when he hands the &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-corrected"&gt;cashiers&lt;/span&gt; check back to them. It is too bad he did not try to keep the money in the end. He had a good legal ground to stand on. If he did not want the money himself, he could have given it to charity.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-6132494921046723424?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/6132494921046723424/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=6132494921046723424' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6132494921046723424'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6132494921046723424'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/12/phony-checks.html' title='Phony Checks'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VDmxk13I3SA/TRA_vQzeoUI/AAAAAAAAAbk/kZrwwABKMoU/s72-c/Check.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-709248350740669152</id><published>2010-12-19T18:38:00.004-05:00</published><updated>2010-12-19T18:38:00.469-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='house arrest'/><category scheme='http://www.blogger.com/atom/ns#' term='CCC'/><category scheme='http://www.blogger.com/atom/ns#' term='probation officer'/><title type='text'>Prison Break</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_VDmxk13I3SA/TQ1GGdoBfMI/AAAAAAAAAbc/JFxD3Ehn9cY/s1600/Release.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 274px; FLOAT: left; HEIGHT: 184px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5552170992463346882" border="0" alt="" src="http://2.bp.blogspot.com/_VDmxk13I3SA/TQ1GGdoBfMI/AAAAAAAAAbc/JFxD3Ehn9cY/s320/Release.jpg" /&gt;&lt;/a&gt;Let's talk about getting out of prison. No. I am not talking about breaking out. I mean serving your time and being released. If you remain on good behavior, you will accrue 54 days off per year. These can add up if you spend many years in the slammer.&lt;br /&gt;&lt;br /&gt;You can normally serve the last portion of your sentence in a Community Corrections Center (&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;CCC&lt;/span&gt;). This is a house out in the city. You get to work a job. But you must spend nights and weekends back at the house.&lt;br /&gt;&lt;br /&gt;Do well at the &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;CCC&lt;/span&gt;, and you may be able to serve the very end of your sentence under house arrest. After you are out, you must report to your probation officer frequently. Try to stay out of trouble. Sooner or later things will lighten up. &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Ok&lt;/span&gt;. I have been going over the highlights of what I know about the big house. Time to return to more &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;hackology&lt;/span&gt; like coding mad apps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-709248350740669152?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/709248350740669152/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=709248350740669152' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/709248350740669152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/709248350740669152'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/12/prison-break.html' title='Prison Break'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VDmxk13I3SA/TQ1GGdoBfMI/AAAAAAAAAbc/JFxD3Ehn9cY/s72-c/Release.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-6373868432587556718</id><published>2010-12-18T18:28:00.003-05:00</published><updated>2010-12-18T18:35:45.696-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='snitch'/><category scheme='http://www.blogger.com/atom/ns#' term='threats'/><category scheme='http://www.blogger.com/atom/ns#' term='complaints'/><category scheme='http://www.blogger.com/atom/ns#' term='the hole'/><title type='text'>Prison Life</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_VDmxk13I3SA/TQ1DtWYI--I/AAAAAAAAAbU/Ib07OlFDiA4/s1600/Life.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 250px; FLOAT: left; HEIGHT: 256px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5552168361997695970" border="0" alt="" src="http://1.bp.blogspot.com/_VDmxk13I3SA/TQ1DtWYI--I/AAAAAAAAAbU/Ib07OlFDiA4/s320/Life.jpg" /&gt;&lt;/a&gt;Here are a bunch of tips to guide your life behind bars. Don't threaten other prisoners. If you want to make an impressive, be like Nike and just do it. You know what they say. Actions speak louder than words.&lt;br /&gt;&lt;br /&gt;When you do have a beef with another prisoner, don't involve the guards. That makes you seem like a snitch. Nobody likes a snitch. If your problem involves a guard, then you can submit a complaint.&lt;br /&gt;&lt;br /&gt;Complaints against guards or other prison employees will take a long time for resolution. To maximize the chance that your complaint will be effective, keep it short and specific.&lt;br /&gt;&lt;br /&gt;Finally let's talk about solitary confinement. You get put into "the hole". It is a small area. Most everything is concrete, except your toilet and bed, which are steel. It is cold in there. The food you get fed is minimal and also cold. Normal punishments get you into the hole for 1 week.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-6373868432587556718?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/6373868432587556718/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=6373868432587556718' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6373868432587556718'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6373868432587556718'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/12/prison-life.html' title='Prison Life'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VDmxk13I3SA/TQ1DtWYI--I/AAAAAAAAAbU/Ib07OlFDiA4/s72-c/Life.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3107479864135354162</id><published>2010-12-18T00:52:00.003-05:00</published><updated>2010-12-18T01:00:48.766-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='convict'/><category scheme='http://www.blogger.com/atom/ns#' term='sentence'/><category scheme='http://www.blogger.com/atom/ns#' term='inmates'/><category scheme='http://www.blogger.com/atom/ns#' term='offense'/><category scheme='http://www.blogger.com/atom/ns#' term='guards'/><category scheme='http://www.blogger.com/atom/ns#' term='fence'/><title type='text'>Federal Bureau of Prisons</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TQxMKcJE53I/AAAAAAAAAbM/A9IfP9Q6XKU/s1600/Bureau.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 298px; FLOAT: left; HEIGHT: 296px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5551896182877644658" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TQxMKcJE53I/AAAAAAAAAbM/A9IfP9Q6XKU/s320/Bureau.jpg" /&gt;&lt;/a&gt;There are a whopping six different levels of security in the federal prison system. A designator at the prison will figure out what level you start out at. Let's get into the different levels.&lt;br /&gt;&lt;br /&gt;1. Minimum - This is for short sentence convicts. There is no fence to keep you in. If it is your first time, you will probably wind up here unless you were convicted of a violent offense.&lt;br /&gt;&lt;br /&gt;2. Federal Correctional Institution - You are fenced in here. You got sharp stuff at the top of the fence to prevent you from climbing over.&lt;br /&gt;&lt;br /&gt;3. Medium Federal Correctional Institution - There are extra guards on duty here. Inmates are serving long sentences. You don't get to move around as much compared to the lesser security prisons.&lt;br /&gt;&lt;br /&gt;4. High Federal Correctional &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-corrected"&gt;Institution&lt;/span&gt; - More oversight by guards. Less movement by inmates. Very long sentences served by inmates.&lt;br /&gt;&lt;br /&gt;5. United States &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-corrected"&gt;Penitentiary&lt;/span&gt; - The real bad guys are kept here. You cell mates will be murders and such. They don't use a fence to keep you in. There is a very high brick wall surrounding the prison. If you make it in here, you may get roughed up bad by other prisoners.&lt;br /&gt;&lt;br /&gt;6. &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Supermax&lt;/span&gt; - Also known as Max. You are always stuck in your cell. If you need a shower, you get a sponge and some water. If you must leave your cell, you are cuffed and escorted by a lot of guards.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3107479864135354162?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3107479864135354162/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3107479864135354162' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3107479864135354162'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3107479864135354162'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/12/federal-bureau-of-prisons.html' title='Federal Bureau of Prisons'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TQxMKcJE53I/AAAAAAAAAbM/A9IfP9Q6XKU/s72-c/Bureau.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-866719935613571080</id><published>2010-12-15T14:48:00.002-05:00</published><updated>2010-12-15T14:54:48.292-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='court order'/><category scheme='http://www.blogger.com/atom/ns#' term='wiretap'/><category scheme='http://www.blogger.com/atom/ns#' term='probation officer'/><title type='text'>Surveillance and Defending Yourself</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TQkbq3xFWTI/AAAAAAAAAbE/rIWzfwKagr4/s1600/Surveillance.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 210px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5550998439049124146" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TQkbq3xFWTI/AAAAAAAAAbE/rIWzfwKagr4/s320/Surveillance.jpg" /&gt;&lt;/a&gt;If the Feds need hard evidence on your, they can do a wiretap. This requires a court order. It is also expensive to operate. There are some devices you can buy that detect whether you are under surveillance.&lt;br /&gt;&lt;br /&gt;Before sentencing you meet up with a probation officer. That title is a bit misleading. Their job at this point has nothing to do with probation. They write up a report which is &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-corrected"&gt;supposed&lt;/span&gt; to be a comprehensive profile of you. Make sure you have your lawyer present during this interview.&lt;br /&gt;&lt;br /&gt;Lawyers cost a lot. If you cannot afford one, your best bet is to study up yourself. This is good advice even if you must rely on the public defender. Buy a couple of the great books such as The Prisoners Self Help Litigation Manual. You should also pick up Federal Sentencing Guidelines, as well as Federal Criminal Codes and Rules. You got to lean the rules of the game before you can play ball.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-866719935613571080?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/866719935613571080/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=866719935613571080' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/866719935613571080'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/866719935613571080'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/12/surveillance-and-defending-yourself.html' title='Surveillance and Defending Yourself'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TQkbq3xFWTI/AAAAAAAAAbE/rIWzfwKagr4/s72-c/Surveillance.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-9106455723655459379</id><published>2010-12-14T14:42:00.003-05:00</published><updated>2010-12-14T14:48:35.898-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='snitch'/><category scheme='http://www.blogger.com/atom/ns#' term='FBI'/><category scheme='http://www.blogger.com/atom/ns#' term='rat'/><category scheme='http://www.blogger.com/atom/ns#' term='county jail'/><category scheme='http://www.blogger.com/atom/ns#' term='attorney'/><title type='text'>Jails and Sentencing</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TQfIy_s3RgI/AAAAAAAAAa8/Z6llrUEESok/s1600/Jail.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 314px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5550625844176045570" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TQfIy_s3RgI/AAAAAAAAAa8/Z6llrUEESok/s320/Jail.jpg" /&gt;&lt;/a&gt;Not all jails are created equal. County jails are rough. You might spend some time there before you get sentenced. State prisons are also hard core. In general it is better to go to federal prison.&lt;br /&gt;&lt;br /&gt;Here is the trade off. If you do serve time at a tough state prison, you will most likely serve a shorter sentence. The federal prisons are better to be in, but you will probably spend more time there.&lt;br /&gt;&lt;br /&gt;Let's switch gears and talk about how to handle yourself when you are charged. Don't say anything. Speak only with your attorney. Anything you say will only count against you.&lt;br /&gt;&lt;br /&gt;If people do snitch, the only ones that benefit are usually the first ones to talk. So if you are going to be a rat, do it early. I don't recommend it though. Providing useful information to the FBI might get you a sentence reduction. Hope for upwards of half your sentence eliminated. In reality you will only get about a third of your sentence chopped.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-9106455723655459379?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/9106455723655459379/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=9106455723655459379' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/9106455723655459379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/9106455723655459379'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/12/jails-and-sentencing.html' title='Jails and Sentencing'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TQfIy_s3RgI/AAAAAAAAAa8/Z6llrUEESok/s72-c/Jail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-9111165073450247994</id><published>2010-12-13T11:32:00.002-05:00</published><updated>2010-12-13T11:40:00.878-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='appeal'/><category scheme='http://www.blogger.com/atom/ns#' term='bail'/><category scheme='http://www.blogger.com/atom/ns#' term='skills'/><category scheme='http://www.blogger.com/atom/ns#' term='lawyer'/><category scheme='http://www.blogger.com/atom/ns#' term='public defender'/><title type='text'>Bail and Sentencing</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_VDmxk13I3SA/TQZKq8aqOTI/AAAAAAAAAa0/Tn3QLnbPSTA/s1600/Bail.gif"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 269px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5550205692413622578" border="0" alt="" src="http://2.bp.blogspot.com/_VDmxk13I3SA/TQZKq8aqOTI/AAAAAAAAAa0/Tn3QLnbPSTA/s320/Bail.gif" /&gt;&lt;/a&gt;Much of your court success will depend on the skills of your attorney. Here is a hint. You should not use the public defender. Instead you got to hire your own lawyer. The problem is that they will cost you a whole lot of cash. We are talking $100k or more.&lt;br /&gt;&lt;br /&gt;It is good to know a lot about the laws and court yourself. Here are some tips if you are going to sign a plea agreement. Try not to sign away your right to an appeal. Later you might find a way to lesson your sentence. Have a list of issues you can appeal ready during your sentencing. Bring these issues up at sentencing. Follow through by filing a notice to appeal. Do this quickly after your sentencing.&lt;br /&gt;&lt;br /&gt;There are some factors that might extend your sentence. If you are highly skilled, and your used those skills to hack, you get extra time. Now let's talk a little about bail. You get locked up as soon as they come to collect the evidence and yourself. In general, you do not get released on bail. That is a low probability event. If you do make bail, it can take weeks to process the bail papers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-9111165073450247994?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/9111165073450247994/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=9111165073450247994' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/9111165073450247994'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/9111165073450247994'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/12/bail-and-sentencing.html' title='Bail and Sentencing'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VDmxk13I3SA/TQZKq8aqOTI/AAAAAAAAAa0/Tn3QLnbPSTA/s72-c/Bail.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-7799975030815864513</id><published>2010-12-10T15:01:00.003-05:00</published><updated>2010-12-10T15:09:08.996-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='gangs'/><category scheme='http://www.blogger.com/atom/ns#' term='lawyer'/><category scheme='http://www.blogger.com/atom/ns#' term='sentence4'/><category scheme='http://www.blogger.com/atom/ns#' term='crimes'/><category scheme='http://www.blogger.com/atom/ns#' term='press'/><category scheme='http://www.blogger.com/atom/ns#' term='USSG'/><title type='text'>Prison Guidance</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_VDmxk13I3SA/TQKIxpeoF_I/AAAAAAAAAas/z9k9YFEq5iY/s1600/Prison.gif"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 253px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5549148077403150322" border="0" alt="" src="http://3.bp.blogspot.com/_VDmxk13I3SA/TQKIxpeoF_I/AAAAAAAAAas/z9k9YFEq5iY/s320/Prison.gif" /&gt;&lt;/a&gt;I just read a huge file on what to do when you get arrested for hacking. It was written by a dude who served 42 months in the pen. Some advice was common sense. For example, try not to pick enemies. However there was some advice that shows true insight. You should not join a group or gang. It will only count against you.&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Get ready for the press to lie about you. Trust no one. You are probably being arrested because you allowed somebody else to know what you were doing. If you do get caught, you had better have studied up. It might reduce your sentence by half or more.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;After you have been convicted of some crime(s), they will calculate the duration of your sentence. Here is the freaky thing. The length of your stay will not only depend on the crimes you have been convicted of. It might might also include other crimes that were not even brought forth against you.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Get a lawyer. The best bang for your buck will be one that specializes in sentencing. It would be best if you knew the United States Sentencing Guidelines (&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;USSG&lt;/span&gt;). Don't put your hopes in beating the Fed. They have a 95% conviction rate. Try to minimize the damage and your time in the slammer.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-7799975030815864513?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/7799975030815864513/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=7799975030815864513' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7799975030815864513'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7799975030815864513'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/12/prison-guidance.html' title='Prison Guidance'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VDmxk13I3SA/TQKIxpeoF_I/AAAAAAAAAas/z9k9YFEq5iY/s72-c/Prison.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-2958777795361849294</id><published>2010-12-07T13:47:00.002-05:00</published><updated>2010-12-07T13:52:10.583-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='insurance policy'/><category scheme='http://www.blogger.com/atom/ns#' term='Wikileaks'/><category scheme='http://www.blogger.com/atom/ns#' term='Julian Assange'/><title type='text'>Doomsday File</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_VDmxk13I3SA/TP6BXt8ehqI/AAAAAAAAAak/aluE-vj_9Xo/s1600/WL.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 192px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5548014035437258402" border="0" alt="" src="http://1.bp.blogspot.com/_VDmxk13I3SA/TP6BXt8ehqI/AAAAAAAAAak/aluE-vj_9Xo/s320/WL.jpg" /&gt;&lt;/a&gt;Scotland Yard has arrested Julian &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Assange&lt;/span&gt;. He is &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;cofounder&lt;/span&gt; of &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Wikileaks&lt;/span&gt;. Britain plans to extradite &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;Assange&lt;/span&gt; to Sweden, where he is wanted for sexual misconduct crimes. &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;Assange&lt;/span&gt; is an Australian citizen. The judge in Britain says this has nothing to do with &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;Wikileaks&lt;/span&gt;. However the &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;Wikileaks&lt;/span&gt; servers are located in Sweden. &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;Hmmm&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;What I find most interesting is &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;Assange's&lt;/span&gt; "insurance policy" against being apprehended. He has widely distributed a doomsday file. The file is named "insurance.&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;aes&lt;/span&gt;256". It supposedly contains a bunch of secret info that has not been released to the public yet.&lt;br /&gt;&lt;br /&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;Assange&lt;/span&gt; warns that if he gets detained, the password to this file will be distributed and chaos will ensue. The file itself is 1.4G large. Who knows what goodies are in there. The way things are going with his Swedish case, I bet we are about to get the next large dose of &lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;Wikileaks&lt;/span&gt; mania.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-2958777795361849294?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/2958777795361849294/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=2958777795361849294' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2958777795361849294'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2958777795361849294'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/12/doomsday-file.html' title='Doomsday File'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VDmxk13I3SA/TP6BXt8ehqI/AAAAAAAAAak/aluE-vj_9Xo/s72-c/WL.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-1352507546677672752</id><published>2010-11-19T14:32:00.002-05:00</published><updated>2010-11-19T14:32:00.218-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pilots'/><category scheme='http://www.blogger.com/atom/ns#' term='policy'/><category scheme='http://www.blogger.com/atom/ns#' term='radiation'/><title type='text'>TSA Body Scanners</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_VDmxk13I3SA/TOV_WpHZN6I/AAAAAAAAAac/6g-yUuoGCbY/s1600/Scanner.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 228px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5540974943519979426" border="0" alt="" src="http://3.bp.blogspot.com/_VDmxk13I3SA/TOV_WpHZN6I/AAAAAAAAAac/6g-yUuoGCbY/s320/Scanner.jpg" /&gt;&lt;/a&gt;The &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;TSA&lt;/span&gt; is now requiring airplane passengers to submit to a full body scan machine. Supposedly a &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;TSA&lt;/span&gt; employee in the back room will view the images. Passengers did have the ability to opt out of the scan and receive a pat down. However the new &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;TSA&lt;/span&gt; policy is to give you the full feel up during this pat down. Madness has ensued.&lt;br /&gt;&lt;br /&gt;You know this is wrong when even the pilots are complaining about the new procedures. They worry about the radiation from the body scan. And some pilots hate being felt up when they opt out. Don't you love it when the &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;TSA&lt;/span&gt; comes up with crazy rules like this?&lt;br /&gt;&lt;br /&gt;When I fly, I will just obey and go through the scanner. So what if some chump in the back gets to see my privates. I don't want nobody feeling up my junk. The rest of the American public may not be willing to take this any more though.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-1352507546677672752?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/1352507546677672752/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=1352507546677672752' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1352507546677672752'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1352507546677672752'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/11/tsa-body-scanners.html' title='TSA Body Scanners'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VDmxk13I3SA/TOV_WpHZN6I/AAAAAAAAAac/6g-yUuoGCbY/s72-c/Scanner.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-339168207924144639</id><published>2010-11-18T11:49:00.002-05:00</published><updated>2010-11-18T11:52:45.393-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='gangs'/><category scheme='http://www.blogger.com/atom/ns#' term='Phrack'/><category scheme='http://www.blogger.com/atom/ns#' term='hexadecimal'/><title type='text'>Making it in Prison</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_VDmxk13I3SA/TOVZH-zmasI/AAAAAAAAAaU/sPFaVXTiLqE/s1600/Phrack.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 205px; FLOAT: left; HEIGHT: 151px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5540932910202645186" border="0" alt="" src="http://1.bp.blogspot.com/_VDmxk13I3SA/TOVZH-zmasI/AAAAAAAAAaU/sPFaVXTiLqE/s320/Phrack.jpg" /&gt;&lt;/a&gt;I just checked out the latest issue of &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Phrack&lt;/span&gt; magazine. This one is issue 67. Inside the thing, they refer to it as issue 0x43. Ha ha. Put your numbers in hexadecimal huh?&lt;br /&gt;&lt;br /&gt;The best article this month is "How to Make it in Prison". It seems to be written by an insider with insider knowledge. Here is a summary of the tips:&lt;br /&gt;&lt;br /&gt;* stay clean&lt;br /&gt;* do not join a gang&lt;br /&gt;* fight those who challenge you&lt;br /&gt;* hide all personal info&lt;br /&gt;* do not do favors without payment&lt;br /&gt;&lt;br /&gt;You really should check out the Prison article yourself if you plan to do any hard time.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-339168207924144639?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/339168207924144639/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=339168207924144639' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/339168207924144639'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/339168207924144639'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/11/making-it-in-prison.html' title='Making it in Prison'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VDmxk13I3SA/TOVZH-zmasI/AAAAAAAAAaU/sPFaVXTiLqE/s72-c/Phrack.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-2116019829839366430</id><published>2010-11-17T17:49:00.002-05:00</published><updated>2010-11-17T17:49:00.405-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tumblr'/><category scheme='http://www.blogger.com/atom/ns#' term='LOIC'/><category scheme='http://www.blogger.com/atom/ns#' term='filter'/><category scheme='http://www.blogger.com/atom/ns#' term='war'/><category scheme='http://www.blogger.com/atom/ns#' term='4chan'/><title type='text'>DDoS Wars</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TOMKnAQa6FI/AAAAAAAAAaM/oaRS4ChEdaE/s1600/Cannon.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 214px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5540283631795890258" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TOMKnAQa6FI/AAAAAAAAAaM/oaRS4ChEdaE/s320/Cannon.jpg" /&gt;&lt;/a&gt;This is too funny to be true. Hackers from the 4&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;chan&lt;/span&gt; site declared war on &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;Tumblr&lt;/span&gt;. Their goal was to launch a denial of service attack on the rival web site. Their weapon of choice was the Low Orbit Ion Cannon (&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;LOIC&lt;/span&gt;). The &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;LOIC&lt;/span&gt; is a &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;prog&lt;/span&gt; that you can use to flood a web site. The source code is actually available on &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;SourceForge&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;The funny thing is that you should be able to set up a filter to block any effects from the &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;LOIC&lt;/span&gt;. Well any web site worth their salt should be able to defend against such child's play. &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;Tumblr&lt;/span&gt; decided to launch their own counter offensive. They called upon their members to blast 4&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;chan&lt;/span&gt;. The end result of this war was that both sites went down hard. &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;LOL&lt;/span&gt;. You got to love some of the propaganda each site used to rally their users to join in the &lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;DDoS&lt;/span&gt; battle. This is great stuff if you are looking for a chuckle.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-2116019829839366430?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/2116019829839366430/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=2116019829839366430' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2116019829839366430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2116019829839366430'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/11/ddos-wars.html' title='DDoS Wars'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TOMKnAQa6FI/AAAAAAAAAaM/oaRS4ChEdaE/s72-c/Cannon.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-1433222678938711550</id><published>2010-11-16T11:30:00.004-05:00</published><updated>2010-11-16T11:35:47.532-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='floating'/><category scheme='http://www.blogger.com/atom/ns#' term='specs'/><category scheme='http://www.blogger.com/atom/ns#' term='construction'/><title type='text'>Canoe from Plywood</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TOKy0xCUxUI/AAAAAAAAAaE/Wl-_W-f-TJI/s1600/Canoe.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 129px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5540187111205160258" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TOKy0xCUxUI/AAAAAAAAAaE/Wl-_W-f-TJI/s320/Canoe.jpg" /&gt;&lt;/a&gt;I just read a sweet instructional on how to build a &lt;a href="http://koti.kapsi.fi/hvartial/oss3/oss3.htm"&gt;canoe&lt;/a&gt; out of a single sheet of plywood. This thing is a working floating canoe. Sure anybody can slap a thing together out of a sheet of plywood. But this one was designed so that an amateur can actually float in it and not tip over.&lt;br /&gt;&lt;br /&gt;The bad boy goes over &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-corrected"&gt;trade offs&lt;/span&gt; involving thick and thin plywood. He then goes on to give you the specs to build the darn thing. He also gets technical on how to maximize the boat size without making it unstable. Check out his main page on other boat construction skills. Tight.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-1433222678938711550?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/1433222678938711550/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=1433222678938711550' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1433222678938711550'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1433222678938711550'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/11/canoe-from-plywood.html' title='Canoe from Plywood'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TOKy0xCUxUI/AAAAAAAAAaE/Wl-_W-f-TJI/s72-c/Canoe.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-4327183549507456190</id><published>2010-11-08T11:02:00.003-05:00</published><updated>2010-11-08T11:06:08.615-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='administrator'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='security clearance'/><title type='text'>Making Money</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_VDmxk13I3SA/TNgfQzAEmxI/AAAAAAAAAZs/W0krWJ0IpuA/s1600/Security.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5537210115280902930" border="0" alt="" src="http://2.bp.blogspot.com/_VDmxk13I3SA/TNgfQzAEmxI/AAAAAAAAAZs/W0krWJ0IpuA/s320/Security.jpg" /&gt;&lt;/a&gt;It is all fun and games to get technical and figure things out. But you got to eat right? How much can you realistically make in the security industry. Let me tell you this much. You got to get a government security clearance. That opens all kinds of doors, including the high pay.&lt;br /&gt;&lt;br /&gt;Real security admins make between $70k to $90k. And these are the normal mid level peeps. I am not talking about the senior administrators. Mid level admins top out around 6 figures. These are real wages being made by real people I know.&lt;br /&gt;&lt;br /&gt;It almost makes you want to drop the programming game and get into &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-4327183549507456190?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/4327183549507456190/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=4327183549507456190' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4327183549507456190'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4327183549507456190'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/11/making-money.html' title='Making Money'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VDmxk13I3SA/TNgfQzAEmxI/AAAAAAAAAZs/W0krWJ0IpuA/s72-c/Security.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-1752867503455159138</id><published>2010-10-28T22:28:00.002-04:00</published><updated>2010-10-28T22:33:09.208-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='n00b'/><category scheme='http://www.blogger.com/atom/ns#' term='wireless'/><category scheme='http://www.blogger.com/atom/ns#' term='cameras'/><category scheme='http://www.blogger.com/atom/ns#' term='HTML'/><title type='text'>WireShark Skills</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TMoxSe4qEiI/AAAAAAAAAZk/4X7kzC8o_Rc/s1600/WireShark.png"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 200px; FLOAT: left; HEIGHT: 200px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5533289285776183842" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TMoxSe4qEiI/AAAAAAAAAZk/4X7kzC8o_Rc/s320/WireShark.png" /&gt;&lt;/a&gt;I read a blogger bragging that he snuck into a building. He avoided the security cameras. He got off the elevator but could not enter the floor. Instead he pulled out his laptop, ran his &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;WireShark&lt;/span&gt; app, and sniffed some wireless network traffic.&lt;br /&gt;&lt;br /&gt;This dude was proud that he captured all kinds of info on the computer sending the network traffic over the air. A lot of people thought this guy was a n00b, because what he did was nothing special. I disagree. I give him props for using &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;WireShark&lt;/span&gt; to extract meaningful data from network traffic he was not familiar with.&lt;br /&gt;&lt;br /&gt;I know another guy that tried to show that he could capture the HTML code for a web site, even if the web site programmer tried to prevent it. This other dude installed a copy of &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;WireShark&lt;/span&gt;, installed the prerequisite Win P-Cap software, and booted up &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;WireShark&lt;/span&gt;. He knew exactly what he was looking for. He only captured the traffic on his own box. However he was still unable to capture the HTML source code for a web page.&lt;br /&gt;&lt;br /&gt;This second guy considers himself the ultimate hacker. Guess not. The moral is that &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;WireShark&lt;/span&gt;, while powerful, requires some skills to operate. I should know. I used it before to do some password risk analysis. That is a story for another day. However I do respect the guy who could run &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;WireShark&lt;/span&gt; on random wireless network traffic and figure out what was going on.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-1752867503455159138?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/1752867503455159138/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=1752867503455159138' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1752867503455159138'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1752867503455159138'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/10/wireshark-skills.html' title='WireShark Skills'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TMoxSe4qEiI/AAAAAAAAAZk/4X7kzC8o_Rc/s72-c/WireShark.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3165121350567363847</id><published>2010-10-19T18:24:00.002-04:00</published><updated>2010-10-19T18:31:46.770-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='UNIX'/><category scheme='http://www.blogger.com/atom/ns#' term='Debugging'/><category scheme='http://www.blogger.com/atom/ns#' term='Code Complete'/><category scheme='http://www.blogger.com/atom/ns#' term='Dale Carnegie'/><title type='text'>Hacker Book List</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_VDmxk13I3SA/TL4avT7cPKI/AAAAAAAAAZc/vpEWkyuvOAc/s1600/Hacking.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 210px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5529886792563309730" border="0" alt="" src="http://2.bp.blogspot.com/_VDmxk13I3SA/TL4avT7cPKI/AAAAAAAAAZc/vpEWkyuvOAc/s320/Hacking.jpg" /&gt;&lt;/a&gt;I just went through this massive list of hacker news books. Wow. Where are I going to get the cash to purchase a bunch of these goodies? I mean they don't carry most of those at the library. Anybody know a good way to get sought after books for cheap?&lt;br /&gt;&lt;br /&gt;Well here are some of the books off the list that I have read. Check out Code Complete by Steve McConnell. It will tell you how to write code the right way. Then there is the Mythical Man Month. This is useful if you are writers code with a bunch of other people (on a team). One book a buddy of mine just got is How To Win Friends and Influence People. Dale Carnegie wrote this one way back when. It is timeless.&lt;br /&gt;&lt;br /&gt;Next is &lt;a href="http://verifcation-and-validation.blogspot.com/2009/10/debugging.html"&gt;Debugging&lt;/a&gt; by David &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Agans&lt;/span&gt;. I wrote a blog post about this one. Then I put some random book cover image in the post. The author emailed me complaining. &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;Sheesh&lt;/span&gt;. Good book anyway. Another book on the list is The One Minute Manager. Can't say I remember much from the read. You might as well skip it.&lt;br /&gt;&lt;br /&gt;A good one is The UNIX Programming Environment. I just consulted this book last month when working on a UNIX project. Good stuff. I read Dive Into Python because I got a free copy. Don't remember much about it either. Finally I checked out Getting Real by 37Signals Corporation. That one was free too. You might want to check it out if you are starting up a company on your own.&lt;br /&gt;&lt;br /&gt;Happy reading.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3165121350567363847?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3165121350567363847/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3165121350567363847' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3165121350567363847'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3165121350567363847'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/10/hacker-book-list.html' title='Hacker Book List'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VDmxk13I3SA/TL4avT7cPKI/AAAAAAAAAZc/vpEWkyuvOAc/s72-c/Hacking.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-6069139573021395409</id><published>2010-10-07T22:27:00.003-04:00</published><updated>2010-10-07T22:33:08.365-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='UNIX'/><category scheme='http://www.blogger.com/atom/ns#' term='web server'/><category scheme='http://www.blogger.com/atom/ns#' term='online'/><category scheme='http://www.blogger.com/atom/ns#' term='college'/><category scheme='http://www.blogger.com/atom/ns#' term='ballot'/><title type='text'>D.C. Voting Hackage</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_VDmxk13I3SA/TK6Bw6GBSiI/AAAAAAAAAZU/QaN34EkpRhQ/s1600/Vote.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 235px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5525496470058388002" border="0" alt="" src="http://1.bp.blogspot.com/_VDmxk13I3SA/TK6Bw6GBSiI/AAAAAAAAAZU/QaN34EkpRhQ/s320/Vote.jpg" /&gt;&lt;/a&gt;The District of Columbia subjected their online voting system to penetration testing. Some college kids hacked the thing in about a day. &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Doh&lt;/span&gt;! Part of the voting process was to upload a file which got encrypted.&lt;br /&gt;&lt;br /&gt;Guess how the hack worked? The students could name the file their were uploading whatever they wanted. Turns out they embedded UNIX commands within in the &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;filename&lt;/span&gt;. This allowed them to run whatever commands they wanted. The result was that they totally owned the web server.&lt;br /&gt;&lt;br /&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;LOL&lt;/span&gt;. They are trying hard to spin this &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;pwnage&lt;/span&gt;. Luckily this was not a system for everybody in the nation's capital to vote online. It was just an absentee ballot voting system. People like the troops overseas have to vote through absentee ballot. I hear they are still going to use this system to distribute ballot electronically. However you will have to print out the form and mail it back. Can't have any more server &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;hackage&lt;/span&gt; going on in Washington DC.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-6069139573021395409?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/6069139573021395409/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=6069139573021395409' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6069139573021395409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6069139573021395409'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/10/dc-voting-hackage.html' title='D.C. Voting Hackage'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VDmxk13I3SA/TK6Bw6GBSiI/AAAAAAAAAZU/QaN34EkpRhQ/s72-c/Vote.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-839326339171324395</id><published>2010-09-10T14:36:00.002-04:00</published><updated>2010-09-10T14:40:26.587-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='solid state disk'/><category scheme='http://www.blogger.com/atom/ns#' term='computer'/><category scheme='http://www.blogger.com/atom/ns#' term='bookmarks'/><title type='text'>Browser Tab Speedup</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TIp6t-gMceI/AAAAAAAAAZM/GLYhVWEWuwU/s1600/Tabs.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 231px; FLOAT: left; HEIGHT: 138px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5515355623959327202" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TIp6t-gMceI/AAAAAAAAAZM/GLYhVWEWuwU/s320/Tabs.jpg" /&gt;&lt;/a&gt;I read about a tech dude who opens a lot of tabs in his browser. He then keeps them open for days. The only problem is that this causes lots of performance problems in his system. He had an inexpensive computer. So he decided to build one on his own to support his strange browsing habit.&lt;br /&gt;&lt;br /&gt;Dude's parts came out to $1300. That's a lot of dough for a PC. He spent a lot on a solid state disk drive. It is supposed to be very fast. He figure that Windows uses the drive for virtual memory. So it must be ultra fast. He is very pleased with the performance of the beast. He also got a lot of the latest ran. He sprung for a top of the line CPU.&lt;br /&gt;&lt;br /&gt;A lot of people commented that the guy could have switched to using bookmarks instead of tabs. The dude wanted fast access to the data. Another reader thought he could save the web pages off to disk for immediate recall. That still did not sit well with the dude. I thought I opened a lot of tabs. But heck, this guy takes the prize. I guess he did the right thing as long as he is happy. Personally I don't got $1300 to spend on mega browser tabs.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-839326339171324395?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/839326339171324395/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=839326339171324395' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/839326339171324395'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/839326339171324395'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/09/browser-tab-speedup.html' title='Browser Tab Speedup'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TIp6t-gMceI/AAAAAAAAAZM/GLYhVWEWuwU/s72-c/Tabs.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3207908979542909968</id><published>2010-09-08T14:51:00.003-04:00</published><updated>2010-09-08T15:10:12.517-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DOS'/><category scheme='http://www.blogger.com/atom/ns#' term='diff eq'/><category scheme='http://www.blogger.com/atom/ns#' term='chemicals'/><category scheme='http://www.blogger.com/atom/ns#' term='graphics'/><category scheme='http://www.blogger.com/atom/ns#' term='intro'/><title type='text'>Difuze by Rrola</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_VDmxk13I3SA/TIfbQLIBOtI/AAAAAAAAAZE/4X-SAZKNvHM/s1600/Difuze.JPG"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 200px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5514617339649276626" border="0" alt="" src="http://3.bp.blogspot.com/_VDmxk13I3SA/TIfbQLIBOtI/AAAAAAAAAZE/4X-SAZKNvHM/s320/Difuze.JPG" /&gt;&lt;/a&gt;The hacker who goes by the handle &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Rrola&lt;/span&gt; has done it again. He produced a 256 byte intro called &lt;a href="http://pouet.net/prod.php?which=55777"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;Difuze&lt;/span&gt;&lt;/a&gt;. We are not talking about 256 kilobytes of code here. It is just 256 bytes. This blog post is is probably a lot more than 256 bytes.&lt;br /&gt;&lt;br /&gt;I found this gem while reading &lt;a href="http://www.reddit.com/r/programming/comments/d9syb/another_256_byte_intro_by_rrrola_this_time_with/"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Reddit&lt;/span&gt;&lt;/a&gt;. The thing runs in DOS. It has a lot of interesting graphics, with music to boot. The easiest way to experience this program is to watch the &lt;a href="http://www.youtube.com/watch?v=41DJ7UOc-sA"&gt;YouTube&lt;/a&gt; video of it.&lt;br /&gt;&lt;br /&gt;So how did &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;Rrola&lt;/span&gt; pack such a &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-corrected"&gt;brilliant&lt;/span&gt; changing graphics display in just 256 bytes? He has a set of partial differential equations that govern how the graphics should look. They are rules referred to as the Gray-Scott reaction-diffusion. Thus the name &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;Difuze&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;The reason these graphics are cool is because they simulate 2 chemicals interacting with each other. The system also adds back the chemicals as they are consumed. It is like something that occurs in nature. Great stuff. I salute you &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;Rrola&lt;/span&gt;. Keep em coming.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3207908979542909968?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3207908979542909968/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3207908979542909968' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3207908979542909968'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3207908979542909968'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/09/difuze-by-rrola.html' title='Difuze by Rrola'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VDmxk13I3SA/TIfbQLIBOtI/AAAAAAAAAZE/4X-SAZKNvHM/s72-c/Difuze.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-2077429657021116394</id><published>2010-08-26T09:12:00.003-04:00</published><updated>2010-08-26T09:12:00.439-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='advertising'/><category scheme='http://www.blogger.com/atom/ns#' term='operating system'/><title type='text'>Malvertising</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_VDmxk13I3SA/THUW-jA5dlI/AAAAAAAAAY8/u1USk0Dri7Q/s1600/Browser.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5509334982964377170" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 280px; CURSOR: hand; HEIGHT: 280px" alt="" src="http://3.bp.blogspot.com/_VDmxk13I3SA/THUW-jA5dlI/AAAAAAAAAY8/u1USk0Dri7Q/s320/Browser.png" border="0" /&gt;&lt;/a&gt;The new entry point for attacking the enterprise is the web browser. Bugs in web browser implementations allow hackers to exploit your users. You know what Google says? The browser is the new operating system.&lt;br /&gt;&lt;br /&gt;It is difficult to lock down web browsers. Hackers are injecting &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;malware&lt;/span&gt; in advertising. This process is being coined &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;malvertising&lt;/span&gt;. It is simpler than trying to get a user to download and execute a file.&lt;br /&gt;&lt;br /&gt;The injection of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;malware&lt;/span&gt; ads is also pretty simple. You just put together a real ad which has the hack embedded in it. You don't need to take user a web site. Allow the web site to come to you to serve up your ad.&lt;br /&gt;&lt;br /&gt;How do you stop such a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;malvertising&lt;/span&gt; attack? You can make sure you users are not administrators of their machines. You can also disable the technologies that allow the attacks to work. This includes JavaScript and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;ActiveX&lt;/span&gt;. The only problem with these extreme measures is that it may impact legitimate user activities.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-2077429657021116394?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/2077429657021116394/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=2077429657021116394' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2077429657021116394'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2077429657021116394'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/08/malvertising.html' title='Malvertising'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VDmxk13I3SA/THUW-jA5dlI/AAAAAAAAAY8/u1USk0Dri7Q/s72-c/Browser.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-8672693219436889245</id><published>2010-08-25T13:18:00.002-04:00</published><updated>2010-08-25T13:18:00.073-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='startup'/><category scheme='http://www.blogger.com/atom/ns#' term='services'/><category scheme='http://www.blogger.com/atom/ns#' term='FasterFox'/><category scheme='http://www.blogger.com/atom/ns#' term='cache'/><category scheme='http://www.blogger.com/atom/ns#' term='UAC'/><category scheme='http://www.blogger.com/atom/ns#' term='page file'/><title type='text'>Tweaking Vista</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/THKtm1TsKRI/AAAAAAAAAYs/LGrcW0L860I/s1600/Vista.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5508656176883837202" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 320px; CURSOR: hand; HEIGHT: 240px" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/THKtm1TsKRI/AAAAAAAAAYs/LGrcW0L860I/s320/Vista.jpg" border="0" /&gt;&lt;/a&gt;My friend's Windows Vista computer is slow. I have gone through some general steps to get the thing running fast. Let's now go over some last ditch specifics to speed things up.&lt;br /&gt;&lt;br /&gt;The theme is that you should disable anything that might take up extra CPU resources, and thus slow things down. Turn off any fancy visual effects. Turn off disk performance monitoring. Disable user account control (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;UAC&lt;/span&gt;).&lt;br /&gt;&lt;br /&gt;Clear out your Internet Explorer browsing history. There might be tons of stuff in your web browser cache. And if you are using &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Firefox&lt;/span&gt; as your default browser, install &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;FasterFox&lt;/span&gt; to help it run better.&lt;br /&gt;&lt;br /&gt;Turn off any Windows services you don't need. This one is a little tricky. You don't want to make Windows crash. However every service may be configurable to run at &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;startup&lt;/span&gt;. If you can identify some that you definitely don't need, disable them.&lt;br /&gt;&lt;br /&gt;Finally you can fine tune your page file. This is a big file on your disk that acts as virtual memory. Make this file be on your fastest disk if you have many physical hard drives. Set the size to a fixed large size. Normally Windows can manage this for you. However if you have a lot of free disk space, make it big and constant size.&lt;br /&gt;&lt;br /&gt;If you follow all my advice from the last couple posts, I bet you can get some old hardware running Windows Vista lightning fast. Good luck.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-8672693219436889245?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/8672693219436889245/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=8672693219436889245' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8672693219436889245'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8672693219436889245'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/08/tweaking-vista.html' title='Tweaking Vista'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/THKtm1TsKRI/AAAAAAAAAYs/LGrcW0L860I/s72-c/Vista.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3171758488056117447</id><published>2010-08-24T13:00:00.002-04:00</published><updated>2010-08-24T13:00:00.614-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='msconfig'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='defrag'/><title type='text'>Windows Optimization</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_VDmxk13I3SA/THKpOwkNA1I/AAAAAAAAAYk/DXSC-FdNFNE/s1600/Spyware.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5508651365247550290" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 282px; CURSOR: hand; HEIGHT: 320px" alt="" src="http://1.bp.blogspot.com/_VDmxk13I3SA/THKpOwkNA1I/AAAAAAAAAYk/DXSC-FdNFNE/s320/Spyware.jpg" border="0" /&gt;&lt;/a&gt;How do you make a Windows machine run fast? There are a couple themes. One is to ensure that unnecessary programs are not running. Another is to make sure the system is optimized.&lt;br /&gt;&lt;br /&gt;If you have &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;spyware&lt;/span&gt; running on your system, it might slow it down. Run a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;spyware&lt;/span&gt; removal program like &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;AdAware&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;When Windows starts up, it runs a number of programs that you have configured as &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;startup&lt;/span&gt; items. Execute &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;msconfig&lt;/span&gt; from the Windows command prompt. Then &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;uncheck&lt;/span&gt; any &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;startup&lt;/span&gt; programs that you don't want to run. This will get your system faster in booting and running.&lt;br /&gt;&lt;br /&gt;Another way to prevent &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;spyware&lt;/span&gt; or bloatware from running on &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;startup&lt;/span&gt; is to &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;uninstall&lt;/span&gt; the stuff. Go to Add/Remove programs from your Control Panel. Get rid of anything you don't use. The &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;uninstall&lt;/span&gt; will normally take the items out of the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;startup&lt;/span&gt; path.&lt;br /&gt;&lt;br /&gt;Then there are some system optimization tricks you can try. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;Defragment&lt;/span&gt; your hard disk(s). Turn off indexing on your hard drive. Get programs out of your system tray. All the items I mentioned so far could increase your performance significantly. Maybe I will do one more post with some very special techniques.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3171758488056117447?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3171758488056117447/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3171758488056117447' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3171758488056117447'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3171758488056117447'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/08/windows-optimization.html' title='Windows Optimization'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VDmxk13I3SA/THKpOwkNA1I/AAAAAAAAAYk/DXSC-FdNFNE/s72-c/Spyware.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3081858033629105727</id><published>2010-08-23T11:47:00.003-04:00</published><updated>2010-08-23T11:50:48.541-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='speed'/><category scheme='http://www.blogger.com/atom/ns#' term='hard drive'/><title type='text'>Making Windows Fast</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/THKYMrmlHBI/AAAAAAAAAYc/y19AOWbBUo8/s1600/Fast.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5508632637857930258" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 320px; CURSOR: hand; HEIGHT: 212px" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/THKYMrmlHBI/AAAAAAAAAYc/y19AOWbBUo8/s320/Fast.jpg" border="0" /&gt;&lt;/a&gt;A friend of mine was complaining how slow their computer was. It was taking around 5 minutes to copy a file locally. That did not sound right. He was running Windows Vista. Luckily I have never ran that version of Windows. How do you make such a beast run faster? It seems to be a black art.&lt;br /&gt;&lt;br /&gt;To start with, I have heard that you should have at least 1GB of RAM to run Windows Vista. And it always helps to have more memory. But I doubt that is the specific cause of this slowness. Another hardware option I read about was to get a faster hard drive. Upgrade from a 5400rpm drive to a 7200rpm one will give you some gains. That also did not seem to be the root cause.&lt;br /&gt;&lt;br /&gt;I plan to review how Windows works, and what might make a system slow. Then I can try these things out on this machine.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3081858033629105727?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3081858033629105727/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3081858033629105727' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3081858033629105727'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3081858033629105727'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/08/making-windows-fast.html' title='Making Windows Fast'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/THKYMrmlHBI/AAAAAAAAAYc/y19AOWbBUo8/s72-c/Fast.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-4052647789683793933</id><published>2010-08-16T00:37:00.002-04:00</published><updated>2010-08-16T00:41:45.073-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='solution'/><category scheme='http://www.blogger.com/atom/ns#' term='sides'/><category scheme='http://www.blogger.com/atom/ns#' term='luck'/><title type='text'>Rubik's Cube</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_VDmxk13I3SA/TGjAwZCW9sI/AAAAAAAAAYU/41Z-VElnS9g/s1600/Rubik.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 318px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5505862482047465154" border="0" alt="" src="http://2.bp.blogspot.com/_VDmxk13I3SA/TGjAwZCW9sI/AAAAAAAAAYU/41Z-VElnS9g/s320/Rubik.jpg" /&gt;&lt;/a&gt;A &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-corrected"&gt;friend&lt;/span&gt; recently got a bunch of Rubik's cube, as well as a solution guide. I decided to try the cube by myself. Did not want to "cheat" and read the solution. That initially got me 1 side solved. Got lucky and solved a second side. I figure it is time to analyze this thing and come up with some techniques to solve the whole thing.&lt;br /&gt;&lt;br /&gt;One good start is to get one side solved. However that is not enough. Each side adjacent to the solved side must also have the common squares in the correct order. That way you can solve a second or third side without having to move the pieces on the first side. That's the way I want to proceed with my hack. I want to figure out a way to manipulate some cube faces without messing up a side that I have already solved.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-4052647789683793933?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/4052647789683793933/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=4052647789683793933' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4052647789683793933'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4052647789683793933'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/08/rubiks-cube.html' title='Rubik&apos;s Cube'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VDmxk13I3SA/TGjAwZCW9sI/AAAAAAAAAYU/41Z-VElnS9g/s72-c/Rubik.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-3307054953333064138</id><published>2010-08-13T17:18:00.002-04:00</published><updated>2010-08-13T17:21:36.398-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cookies'/><category scheme='http://www.blogger.com/atom/ns#' term='bug'/><category scheme='http://www.blogger.com/atom/ns#' term='Chinese'/><category scheme='http://www.blogger.com/atom/ns#' term='English'/><title type='text'>Blogger Start Page</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TGW2pfuXZyI/AAAAAAAAAYM/iTUqVxUi718/s1600/Blogger.png"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 246px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5505006943537162018" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TGW2pfuXZyI/AAAAAAAAAYM/iTUqVxUi718/s320/Blogger.png" /&gt;&lt;/a&gt;I like using Blogger. They give you free unlimited blogging abilities. However I had a problem with it recently. The start page where you log in was always being displayed in Chinese. WTF? I always view my pages in English. This curse just would not go away.&lt;br /&gt;&lt;br /&gt;Logically Google must be storing some Chinese language preference somewhere. Should I get rid of all my cookies? Or is there some other secret place where they stored the language? This questioning was getting me nowhere.&lt;br /&gt;&lt;br /&gt;Then I found out a trick of my own. I forced Blogger to display in &lt;a href="https://www.blogger.com/start?hl=en"&gt;English&lt;/a&gt;. From then on, the Blogger start page always shows English. I consider this a Blogger bug. But hey. The thing is free so I won't complain too loudly.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-3307054953333064138?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/3307054953333064138/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=3307054953333064138' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3307054953333064138'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/3307054953333064138'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/08/blogger-start-page.html' title='Blogger Start Page'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TGW2pfuXZyI/AAAAAAAAAYM/iTUqVxUi718/s72-c/Blogger.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-7719999557689316439</id><published>2010-08-02T00:52:00.002-04:00</published><updated>2010-08-02T00:57:47.532-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='brute force'/><category scheme='http://www.blogger.com/atom/ns#' term='UltraEdit'/><category scheme='http://www.blogger.com/atom/ns#' term='BitTorrent'/><category scheme='http://www.blogger.com/atom/ns#' term='crawl'/><category scheme='http://www.blogger.com/atom/ns#' term='cracked'/><title type='text'>FaceBook Infio</title><content type='html'>&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 240px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5500670974748252322" border="0" alt="" src="http://3.bp.blogspot.com/_VDmxk13I3SA/TFZPG5Qr2KI/AAAAAAAAAYE/c6a5PzCxFo0/s320/FB.jpg" /&gt;So 171 million &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;FaceBook&lt;/span&gt; names and profiles have been captured and put into a text file. You need &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;BitTorrent&lt;/span&gt; to download the files. Let me tell you. The files are huge. I spent a number of hours downloading the torrent.&lt;br /&gt;&lt;br /&gt;The text file with the URLs of all the profiles grabbed was so huge I could not open it up. I downloaded a few programs to see if they could open up such a massive file (10Gig). The only one I found that worked was called &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;UltraEdit&lt;/span&gt;. This program costs $60 for the full version. Strangely enough there was a cracked copy of &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;UltraEdit&lt;/span&gt; available as a torrent. I used the 30-day trial version to spy on the &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;FaceBook&lt;/span&gt; profiles.&lt;br /&gt;&lt;br /&gt;My next idea is to stuff all these URLs into an Oracle database. Then I will run a program that browses the profiles to see what nice info I can grab. The profiles sometimes show the user's &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;FaceBook&lt;/span&gt; friends. That might provide even more profiles. A brute force crawl of the profiles could take a couple years. Might need to put an army of machines on that task. I will start with a few trial runs, and keep you posted.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-7719999557689316439?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/7719999557689316439/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=7719999557689316439' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7719999557689316439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7719999557689316439'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/08/facebook-infio.html' title='FaceBook Infio'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VDmxk13I3SA/TFZPG5Qr2KI/AAAAAAAAAYE/c6a5PzCxFo0/s72-c/FB.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-8434618521141086985</id><published>2010-07-31T20:45:00.002-04:00</published><updated>2010-07-31T20:52:24.873-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='Scull Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Ron Bower'/><category scheme='http://www.blogger.com/atom/ns#' term='Pirate Bay'/><category scheme='http://www.blogger.com/atom/ns#' term='torrent'/><title type='text'>FaceBook Profile Leak</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TFTDxwuGMyI/AAAAAAAAAX8/yUA5lRh6_hw/s1600/Facebook.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 263px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5500236304585470754" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TFTDxwuGMyI/AAAAAAAAAX8/yUA5lRh6_hw/s320/Facebook.jpg" /&gt;&lt;/a&gt;Hacker Ron &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Bowes&lt;/span&gt; used a scraper to grab the name and profile URL of 171 million &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;FaceBook&lt;/span&gt; users. You might think he would sell this information. But he did not. Instead he blogged about it on the Scull Security blog. He also uploaded the data in text files as a 2.8 gigabyte torrent to the Pirate Bay.&lt;br /&gt;&lt;br /&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Bowes&lt;/span&gt; used a script that interrogated the &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;Facebook&lt;/span&gt; public profile directory. All of this is publicly available data. Search engines like Google have access to this information already. You can tell whether your data is publicly available on &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;FaceBook&lt;/span&gt; by seeing whether "search for me on &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;FaceBook&lt;/span&gt;" is set to everyone in your settings. You can also see whether "enable public search" is checked in your settings.&lt;br /&gt;&lt;br /&gt;I am going to download this large torrent and see what this data is all about. Probably will just get &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;usernames&lt;/span&gt; and URLs. Then perhaps I can write a small program that scrapes the profiles and builds up my own database. Not sure if I have enough bandwidth, disk space, and processing power to do that. We shall see.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-8434618521141086985?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/8434618521141086985/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=8434618521141086985' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8434618521141086985'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8434618521141086985'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/07/facebook-profile-leak.html' title='FaceBook Profile Leak'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TFTDxwuGMyI/AAAAAAAAAX8/yUA5lRh6_hw/s72-c/Facebook.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-903249693220298931</id><published>2010-07-27T23:57:00.003-04:00</published><updated>2010-07-28T00:01:53.721-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='disclosure'/><category scheme='http://www.blogger.com/atom/ns#' term='Afganistan'/><category scheme='http://www.blogger.com/atom/ns#' term='kills'/><category scheme='http://www.blogger.com/atom/ns#' term='foe'/><category scheme='http://www.blogger.com/atom/ns#' term='classified'/><title type='text'>WikiLeaks Disclosure</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_VDmxk13I3SA/TE-qrN4PBUI/AAAAAAAAAX0/ax9WOlyNZEs/s1600/Wikileaks.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 241px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5498801329479288130" border="0" alt="" src="http://1.bp.blogspot.com/_VDmxk13I3SA/TE-qrN4PBUI/AAAAAAAAAX0/ax9WOlyNZEs/s320/Wikileaks.jpg" /&gt;&lt;/a&gt;It seems &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;WikiLeaks&lt;/span&gt; is the big story these days. I read about them on the front page of my local paper. There were links to their recent disclosure all around the web. What they did was post a massive amount of classified information about the war in Afghanistan.&lt;br /&gt;&lt;br /&gt;I downloaded all the data from &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;WikiLeaks&lt;/span&gt; and am still waiting to be impressed. It seems that what they have is a whole lot of small reports of incidents. There is more formatting than actual content there. You get a blurb about some Afghanistan incident. You have counts of if anybody got killed. And they tag whether it was friend or foe.&lt;br /&gt;&lt;br /&gt;In my mind, I was thinking there &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-corrected"&gt;would&lt;/span&gt; be some juicy details of being there in the war. Instead I got a huge amount of small entries which were initially classified by the government. Maybe I will uploaded all this data to a database. &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;WikiLeaks&lt;/span&gt; makes it easy by providing scripts to uploaded the data. However I still think I will not be &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-corrected"&gt;wowed&lt;/span&gt; by their data. All they show is that there is a source willing to give them classified government information. The actual data is a bit boring. Next.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-903249693220298931?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/903249693220298931/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=903249693220298931' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/903249693220298931'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/903249693220298931'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/07/wikileaks-disclosure.html' title='WikiLeaks Disclosure'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VDmxk13I3SA/TE-qrN4PBUI/AAAAAAAAAX0/ax9WOlyNZEs/s72-c/Wikileaks.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-552900276168452393</id><published>2010-07-17T22:56:00.003-04:00</published><updated>2010-07-17T23:03:11.108-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Steve Wozniak'/><category scheme='http://www.blogger.com/atom/ns#' term='Altair'/><category scheme='http://www.blogger.com/atom/ns#' term='Homebrew'/><title type='text'>Old School Hacking</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TEJtlUuW4FI/AAAAAAAAAXs/FDO8BZvGeS4/s1600/Hackers.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 204px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5495074983331160146" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TEJtlUuW4FI/AAAAAAAAAXs/FDO8BZvGeS4/s320/Hackers.jpg" /&gt;&lt;/a&gt;Check out a book online called &lt;a href="http://sites.google.com/site/hackheroes/"&gt;Hackers&lt;/a&gt; : Heroes of the Computer Revolution. This book covers monumental events from the hacking world of the 1970's and 1980's. Let's look at the topics of some of the chapters.&lt;br /&gt;&lt;br /&gt;Of course they need to talk about the Homebrew Computer Club. It was a meeting for electronics hobbyists. They first met in 1975. The meeting was held in a garage in California. Apple cofounder Steve Wozniak attended.&lt;br /&gt;&lt;br /&gt;Woz gets his own chapter. He build his own computer before personal computers were around. It was based on the Motorola 6502 processor. Of course Woz worked with Steve Jobs back in the early days.&lt;br /&gt;&lt;br /&gt;The book talks about the origins of Altair BASIC. It was created by Microsoft ihn the early days. The thing was immediately pirated, causing Bill Gates to write a letter to the thieves. This is the BASIC that was involved in the creation of the now defunct Doctor Dobb's Journal.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-552900276168452393?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/552900276168452393/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=552900276168452393' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/552900276168452393'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/552900276168452393'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/07/old-school-hacking.html' title='Old School Hacking'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TEJtlUuW4FI/AAAAAAAAAXs/FDO8BZvGeS4/s72-c/Hackers.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-7271201371669569814</id><published>2010-07-13T01:30:00.002-04:00</published><updated>2010-07-13T01:36:31.110-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='JavaScript'/><category scheme='http://www.blogger.com/atom/ns#' term='challenge'/><category scheme='http://www.blogger.com/atom/ns#' term='app'/><category scheme='http://www.blogger.com/atom/ns#' term='free'/><category scheme='http://www.blogger.com/atom/ns#' term='SDK'/><category scheme='http://www.blogger.com/atom/ns#' term='HTML'/><title type='text'>BitTorrent Contest</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_VDmxk13I3SA/TDv6ZM9IGqI/AAAAAAAAAXk/pe3orJAU91U/s1600/Torrent.png"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 300px; FLOAT: left; HEIGHT: 300px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5493259481389734562" border="0" alt="" src="http://2.bp.blogspot.com/_VDmxk13I3SA/TDv6ZM9IGqI/AAAAAAAAAXk/pe3orJAU91U/s320/Torrent.png" /&gt;&lt;/a&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;BitTorrent&lt;/span&gt; is sponsoring a contest. You got to design an app that uses their software development kit. The &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;SDK&lt;/span&gt; is restrictive in that you can only code in HTML and JavaScript. The top prize is a grand and prime app placement.&lt;br /&gt;&lt;br /&gt;Hey. I bet anybody could use an extra thousand for toys. However I cannot imagine you making any money off an app for &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;BitTorrent&lt;/span&gt;. These users are trading files for free. They want stuff for free. If you try to sell the app, somebody is going to get &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;ahold&lt;/span&gt; of your app and trade it for free.&lt;br /&gt;&lt;br /&gt;Still I find this an interesting &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-corrected"&gt;challenge&lt;/span&gt;. Too bad I am concentrating on learning how to write &lt;a href="http://enableassertions.blogspot.com/2010/07/applet-time.html"&gt;applets&lt;/a&gt; in &lt;a href="http://enableassertions.blogspot.com/"&gt;Java&lt;/a&gt; right now.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-7271201371669569814?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/7271201371669569814/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=7271201371669569814' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7271201371669569814'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7271201371669569814'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/07/bittorrent-contest.html' title='BitTorrent Contest'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VDmxk13I3SA/TDv6ZM9IGqI/AAAAAAAAAXk/pe3orJAU91U/s72-c/Torrent.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-8638105458406734007</id><published>2010-07-09T22:01:00.000-04:00</published><updated>2010-07-09T22:01:00.241-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='credit cards'/><category scheme='http://www.blogger.com/atom/ns#' term='surveilance'/><category scheme='http://www.blogger.com/atom/ns#' term='online banking'/><title type='text'>Ideas From War Games</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TDaDLb2OopI/AAAAAAAAAXc/aIu0IGNgH30/s1600/WarGames.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 227px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5491721028101907090" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TDaDLb2OopI/AAAAAAAAAXc/aIu0IGNgH30/s320/WarGames.jpg" /&gt;&lt;/a&gt;I am watching War Games 2, the movie. Started out looking like a serious B movie. There are no real stars in this thing. However there are some interesting ideas in there.&lt;br /&gt;&lt;br /&gt;The government put a type of war games on the &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-corrected"&gt;Internet&lt;/span&gt;. This game offered real cash for people who could get to level 5. However those who made it got targeted for &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-corrected"&gt;surveillance&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;The problem was that the computer that tried to get players and track them got smart. This program is called Ripley. Too bad it did not need human intervention.&lt;br /&gt;&lt;br /&gt;I did get a few laughs out of the main character doing some hacking. He gained the trust of his neighbor. Then he used his neighbor's online banking account to "borrow" some cash.&lt;br /&gt;&lt;br /&gt;The main character also dealt with stolen credit cards, and also some prepaid phone cards. The dude liked playing online games. He also was a true to heart hacker.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-8638105458406734007?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/8638105458406734007/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=8638105458406734007' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8638105458406734007'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/8638105458406734007'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/07/ideas-from-war-games.html' title='Ideas From War Games'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TDaDLb2OopI/AAAAAAAAAXc/aIu0IGNgH30/s72-c/WarGames.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-6872104240818345675</id><published>2010-07-08T15:29:00.002-04:00</published><updated>2010-07-08T15:36:02.871-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='social networking'/><category scheme='http://www.blogger.com/atom/ns#' term='military'/><category scheme='http://www.blogger.com/atom/ns#' term='troops'/><title type='text'>Robin Sage</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_VDmxk13I3SA/TDYnSgtT_II/AAAAAAAAAXU/lNxjWAKX64Y/s1600/RobinSage.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5491619994596015234" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 73px; CURSOR: hand; HEIGHT: 73px" alt="" src="http://2.bp.blogspot.com/_VDmxk13I3SA/TDYnSgtT_II/AAAAAAAAAXU/lNxjWAKX64Y/s320/RobinSage.png" border="0" /&gt;&lt;/a&gt;Some time ago, a woman named Robin Sage started appearing on social networks. She was supposed to be in her twenties. She was supposed to have worked for the Naval Network Warfare Council. As you might expect, she was getting connected with military personnel.&lt;br /&gt;&lt;br /&gt;The online persona looked good. Her picture was hot. She was allegedly a grad of MIT. And she interned at the National Security Agency. It turns out this profile was fabricated. A hacker put it together as part of an experiment.&lt;br /&gt;&lt;br /&gt;The funny thing is that the online persona networked with military top brass. She even got some job offers extended to her. The tragedy is that, through her military contacts, the hacker was able to get a lot of information about troop movements in Iran and Iraq. Nice.&lt;br /&gt;&lt;br /&gt;A nice picture, and some early assumptions, caused the scam to pick up momentum. Luckily some skeptics dug deep and discerned the sham. Beware who you meet online. Often they are not who they seem.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-6872104240818345675?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/6872104240818345675/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=6872104240818345675' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6872104240818345675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6872104240818345675'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/07/robin-sage.html' title='Robin Sage'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VDmxk13I3SA/TDYnSgtT_II/AAAAAAAAAXU/lNxjWAKX64Y/s72-c/RobinSage.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-1690948964652670806</id><published>2010-07-02T23:38:00.003-04:00</published><updated>2010-07-02T23:47:52.972-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mask'/><category scheme='http://www.blogger.com/atom/ns#' term='Big Brother'/><category scheme='http://www.blogger.com/atom/ns#' term='disguise'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineer'/><title type='text'>Face Camoflage</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_VDmxk13I3SA/TC6xIjGONqI/AAAAAAAAAXM/-8nvxg2tT_o/s1600/Camo.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 74px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5489519756229621410" border="0" alt="" src="http://1.bp.blogspot.com/_VDmxk13I3SA/TC6xIjGONqI/AAAAAAAAAXM/-8nvxg2tT_o/s320/Camo.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;I just read a blog post at &lt;a href="http://social.venturebeat.com/2010/07/02/facial-recognition-camouflage/"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;SocialBeat&lt;/span&gt;&lt;/a&gt; on techniques to disguise your face from recognition software. People be posting their image to the web on sites like &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;FaceBook&lt;/span&gt;. And there is software that is growing smart at figuring out who you are just from your picture. This is kind of like a Big Brother future. But the software is only so smart. A little mask can throw the software off track.&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Now nobody is saying you need to make sure you go out looking like &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-corrected"&gt;cat woman&lt;/span&gt;. You can maybe just touch up your face using &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;photoshop&lt;/span&gt; before you post it online. Then you can remain below the radar from the image trackers online.&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;I think what we really need is some type of image processing which can mask your face from the image processing, but leave it looking the same for humans. Sounds like a good research project. You could start with the actual facial recognition software. Then you could try out different subtle hacks to the image to make it confuse the software. Or you could reverse engineer the code in the facial recognition software, and find its weakness. That's even better.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-1690948964652670806?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/1690948964652670806/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=1690948964652670806' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1690948964652670806'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1690948964652670806'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/07/face-camoflage.html' title='Face Camoflage'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VDmxk13I3SA/TC6xIjGONqI/AAAAAAAAAXM/-8nvxg2tT_o/s72-c/Camo.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-7873871295930054910</id><published>2010-06-28T14:05:00.004-04:00</published><updated>2010-06-28T14:13:29.242-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='online fraud'/><category scheme='http://www.blogger.com/atom/ns#' term='ID Theft'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><title type='text'>Government Agency for Cyperspace Identity</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_VDmxk13I3SA/TCjksOb8cqI/AAAAAAAAAW8/KRMtTP2UXTI/s1600/Trust.gif"&gt;&lt;img id="BLOGGER_PHOTO_ID_5487887594391630498" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 320px; CURSOR: hand; HEIGHT: 214px" alt="" src="http://3.bp.blogspot.com/_VDmxk13I3SA/TCjksOb8cqI/AAAAAAAAAW8/KRMtTP2UXTI/s320/Trust.gif" border="0" /&gt;&lt;/a&gt;The United States Federal Government and a number of entities in the private sector have drafted the "National Strategy for Trusted Identities in Cyberspace". Their goal is to secure cyberspace. This effort is a direct response to the increasing amount of identity theft and online fraud going on each year. Last year there were over 10 million &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_0"&gt;occurrences&lt;/span&gt; of identity theft. Ouch.&lt;br /&gt;&lt;br /&gt;This proposal recommends creation of an Identity Ecosystem. There should be an authority to authenticate digital identification. Participation is supposed to be mandatory. The new system will be built with interoperability in mind. That means everything works with everything else like ATM systems do with cash. The proposal is for this not to be all done by the government.&lt;br /&gt;&lt;br /&gt;People do not seem to have control over their personal info any more. And there are other problem plaguing people which will not be solved by this initiative such as &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;malware&lt;/span&gt;. However the president is to designate a government agency to lead this effort. The proposal goes out of its way to clarify that they are not talking about a national ID card. This is a digital problem requiring a digital solution.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-7873871295930054910?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/7873871295930054910/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=7873871295930054910' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7873871295930054910'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/7873871295930054910'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/06/government-agency-for-cyperspace.html' title='Government Agency for Cyperspace Identity'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VDmxk13I3SA/TCjksOb8cqI/AAAAAAAAAW8/KRMtTP2UXTI/s72-c/Trust.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-2706484988167867680</id><published>2010-06-24T23:19:00.003-04:00</published><updated>2010-06-24T23:29:23.589-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kazaa'/><category scheme='http://www.blogger.com/atom/ns#' term='pirated'/><category scheme='http://www.blogger.com/atom/ns#' term='BitTorrent'/><category scheme='http://www.blogger.com/atom/ns#' term='rip'/><category scheme='http://www.blogger.com/atom/ns#' term='peer to peer'/><title type='text'>Topsites</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_VDmxk13I3SA/TCQgSpJ2DyI/AAAAAAAAAW0/JbaEgREy9Zg/s1600/Movie.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 217px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5486545750700986146" border="0" alt="" src="http://3.bp.blogspot.com/_VDmxk13I3SA/TCQgSpJ2DyI/AAAAAAAAAW0/JbaEgREy9Zg/s320/Movie.jpg" /&gt;&lt;/a&gt;Like most folks, I have friends that download movies from &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;BitTorrent&lt;/span&gt; sites. Personally I don't have much experience getting movies from such sites. However I did read a story about &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;topsites&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Topsites&lt;/span&gt; are secret web sites that share pirated stuff like movies and software games. These aren't normal peer to peer sites like &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;Kazaa&lt;/span&gt;. These are open to a limited amount of people in the club. You need to be on their list to get access to the sites.&lt;br /&gt;&lt;br /&gt;Getting movies and such onto &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;topsites&lt;/span&gt; is not easy. They only want the high quality stuff. That requires high tech and expensive hardware to rip movies. But you do get some bragging rights when your stuff is downloaded by everyone.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-2706484988167867680?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/2706484988167867680/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=2706484988167867680' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2706484988167867680'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2706484988167867680'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/06/topsites.html' title='Topsites'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VDmxk13I3SA/TCQgSpJ2DyI/AAAAAAAAAW0/JbaEgREy9Zg/s72-c/Movie.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-6526554958272380943</id><published>2010-06-23T00:09:00.001-04:00</published><updated>2010-06-23T00:09:00.300-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='surveillance'/><category scheme='http://www.blogger.com/atom/ns#' term='blue tooth'/><category scheme='http://www.blogger.com/atom/ns#' term='spy'/><category scheme='http://www.blogger.com/atom/ns#' term='law enforcement'/><title type='text'>Spying on Cell Phones</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_VDmxk13I3SA/TCA3f5khiLI/AAAAAAAAAWs/HFJocn1KvXU/s1600/Cell.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 302px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5485445367306750130" border="0" alt="" src="http://3.bp.blogspot.com/_VDmxk13I3SA/TCA3f5khiLI/AAAAAAAAAWs/HFJocn1KvXU/s320/Cell.jpg" /&gt;&lt;/a&gt;I was reading some interesting blog today. Then I saw some ads on the site. I clicked through one ad to find a big web page on a product that let's you spy on someone &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;else's&lt;/span&gt; cell phone usage. The marketing sounded too good to be true. I wondered whether such a hack could actually exist. Perhaps it is some type of blue tooth device hacking. You ever hear of blue snarfing or blue bugging? I seem to have studied this stuff in school a while ago.&lt;br /&gt;&lt;br /&gt;Let's get back to the features of this offer. You can listen in on another person's calls. You can read their text messages. You can also track them via GPS. You can view their contact list. And you can see their photos. All of this is supposed to be undetectable. These are alleged features. I am not sure whether I belief them or not.&lt;br /&gt;&lt;br /&gt;This functionality is supposedly not limited to cell phones. It works on any &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-corrected"&gt;blue tooth&lt;/span&gt; enables devices like laptops as well. Law enforcement uses these techniques as well. This works on any phone. You do not see evidence of this on the target's phone. You do not see any apps on the target phone. Nor does it consume much memory. All the data collected fits in megabytes, even after a year's worth of recording. There is different software to install on your phone based on your model. Nothing is logged on the target phone. It is an all software solution.&lt;br /&gt;&lt;br /&gt;There are some bonuses with this deal such as how to catch cheaters, how to use spy gadgets, and how to get the truth. Those are the names of the bonus products. These products include detailed info on dirty tricks, covert surveillance, spying via web cams, lie detection, and mind games. I almost would go for this deal just for the bonuses if I could trust them. The whole thing costs $99. If I had more cash, I would try going for this. But if something sounds too good to be true, it most likely is. This might be a hack to get my credit card number and leave me with nothing. Still I can dream that such a broad tool set of capability actually exists out there. Anybody want to give this deal a try?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-6526554958272380943?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/6526554958272380943/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=6526554958272380943' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6526554958272380943'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/6526554958272380943'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/06/spying-on-cell-phones.html' title='Spying on Cell Phones'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VDmxk13I3SA/TCA3f5khiLI/AAAAAAAAAWs/HFJocn1KvXU/s72-c/Cell.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-2040613824404255123</id><published>2010-06-21T18:05:00.004-04:00</published><updated>2010-06-21T18:13:51.520-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='raid'/><category scheme='http://www.blogger.com/atom/ns#' term='Legion of Doom'/><category scheme='http://www.blogger.com/atom/ns#' term='Masters of Deception'/><category scheme='http://www.blogger.com/atom/ns#' term='MC-10'/><title type='text'>Meet Phiber Optik</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_VDmxk13I3SA/TB_iH6pKYxI/AAAAAAAAAWk/QFR4PV9K3_w/s1600/PhiberOptik.gif"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 150px; FLOAT: left; HEIGHT: 110px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5485351496789418770" border="0" alt="" src="http://3.bp.blogspot.com/_VDmxk13I3SA/TB_iH6pKYxI/AAAAAAAAAWk/QFR4PV9K3_w/s320/PhiberOptik.gif" /&gt;&lt;/a&gt;This post is going to be something of a history lesson. I just finished reading a book about the hacker gang Masters of Deception. One of the main characters in the book is Mark &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Abene&lt;/span&gt;. In the late 1980's and early 90's he went by the handle &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;Phiber&lt;/span&gt; &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Optik.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;Phiber&lt;/span&gt; &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;Optik&lt;/span&gt; starting computing on a &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;TRS&lt;/span&gt;-80 MC-10. This is a little home computer from Radio Shack that was essentially a scaled down version of the &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;TRS&lt;/span&gt;-80 Color Computer. I know because I started out on a Color Computer I (&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;CoCo&lt;/span&gt; 1), and later graduated to a &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;CoCo&lt;/span&gt; 3. Once &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;Phiber&lt;/span&gt; &lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;Optik&lt;/span&gt; got a modem, he was off to the races.&lt;br /&gt;&lt;br /&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;Phiber&lt;/span&gt; &lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;Optik&lt;/span&gt; initially started making claims that he was a part of the hacker gang Legion of Doom (&lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;LoD&lt;/span&gt;). The thing is that you cannot will yourself into that group. You needed to be voted in. Luckily the members unanimously voted him in due to his skills and exploits. Some of these exploits results in &lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;Phiber&lt;/span&gt; &lt;span id="SPELLING_ERROR_15" class="blsp-spelling-error"&gt;Optik&lt;/span&gt; getting raided by the Secret Service back in 1990. This is weird. I thought the Secret Service just guarded the president.&lt;br /&gt;&lt;br /&gt;&lt;span id="SPELLING_ERROR_16" class="blsp-spelling-error"&gt;Phiber&lt;/span&gt; &lt;span id="SPELLING_ERROR_17" class="blsp-spelling-error"&gt;Optik&lt;/span&gt; was only 17 years old when he first got raided. He was just a junior in high school. This did not end his hacking career. There are different stories of how it happened. But he eventually got kicked out of the Legion of Doom. He then went on to form a new group - the Masters of Deception. It was a play on the &lt;span id="SPELLING_ERROR_18" class="blsp-spelling-error"&gt;LoD&lt;/span&gt;. This was the &lt;span id="SPELLING_ERROR_19" class="blsp-spelling-error"&gt;MoD&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;All the founding members of the &lt;span id="SPELLING_ERROR_20" class="blsp-spelling-error"&gt;MoD&lt;/span&gt; were eventually brought up on charges by the New York grand jury. Mark held out the longest. All the other members pleaded &lt;span id="SPELLING_ERROR_21" class="blsp-spelling-corrected"&gt;guilty&lt;/span&gt; to the charges to avoid too much jail time. One of the members turned on the others and &lt;span id="SPELLING_ERROR_22" class="blsp-spelling-corrected"&gt;cooperated&lt;/span&gt; with the authorities. These guys were so very interesting that I might do some more history reporting and let you know more about them.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-2040613824404255123?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/2040613824404255123/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=2040613824404255123' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2040613824404255123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2040613824404255123'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/06/meet-phiber-optik.html' title='Meet Phiber Optik'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VDmxk13I3SA/TB_iH6pKYxI/AAAAAAAAAWk/QFR4PV9K3_w/s72-c/PhiberOptik.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-535775974079792033</id><published>2010-06-20T23:55:00.002-04:00</published><updated>2010-06-21T00:02:05.474-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Legion of Doom'/><category scheme='http://www.blogger.com/atom/ns#' term='Masters of Deception'/><category scheme='http://www.blogger.com/atom/ns#' term='LOD'/><title type='text'>The MOD</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TB7i248kGVI/AAAAAAAAAWc/IscNd0wcJVE/s1600/MOD.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5485070828811065682" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TB7i248kGVI/AAAAAAAAAWc/IscNd0wcJVE/s320/MOD.jpg" /&gt;&lt;/a&gt;I finished reading the book Masters of Deception by Michelle &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Slatalla&lt;/span&gt; and Joshua &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;Quittner&lt;/span&gt;. The book chronicles the lives of the main members of the hacking group Masters of Deception (MOD). The group's name is actually a play on the Legion of Doom (&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;LOD&lt;/span&gt;), which was a rival hacker group.&lt;br /&gt;&lt;br /&gt;The book itself was a good read. It was hard to keep all the hackers straight, given that they all go by handles. Some hackers have multiple handles given the system they are on. The thing that annoyed me about the book was that there was no Table of Contents. Well I am going to rectify that. Here is the table of contents I would have created for this book:&lt;br /&gt;&lt;br /&gt;Prologue - AT&amp;amp;T Crash&lt;br /&gt;Chapter 1 - Scorpion&lt;br /&gt;Chapter 2 - &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;Phiber&lt;/span&gt; &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;Optik&lt;/span&gt;&lt;br /&gt;Chapter 3 - &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;Plik&lt;/span&gt;&lt;br /&gt;Chapter 4 - New York Telephone&lt;br /&gt;Chapter 5 - MOD&lt;br /&gt;Chapter 6 - Corrupt&lt;br /&gt;Chapter 7 - The Learning Link&lt;br /&gt;Chapter 8 - Raided&lt;br /&gt;Chapter 9 - Alfredo&lt;br /&gt;Chapter 10 - Fifth &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-corrected"&gt;Amendment&lt;/span&gt;&lt;br /&gt;Chapter 11 - &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;Tymet&lt;/span&gt;&lt;br /&gt;Chapter 12 - &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;MODNET&lt;/span&gt;&lt;br /&gt;Chapter 13 - &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;Parmaster&lt;/span&gt;&lt;br /&gt;Chapter 14 - Broker&lt;br /&gt;Chapter 15 - Grand Jury&lt;br /&gt;Chapter 16 - Plea&lt;br /&gt;Afterward - 2600&lt;br /&gt;&lt;br /&gt;I recommend you get this book and read it. The thing gives you a good feel for who these people are. I might go over some of the hackers revealed in this book.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-535775974079792033?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/535775974079792033/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=535775974079792033' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/535775974079792033'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/535775974079792033'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/06/mod.html' title='The MOD'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TB7i248kGVI/AAAAAAAAAWc/IscNd0wcJVE/s72-c/MOD.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-4678796373159514323</id><published>2010-06-20T00:56:00.001-04:00</published><updated>2010-06-20T00:56:00.115-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tavis Ormandy'/><category scheme='http://www.blogger.com/atom/ns#' term='reporters'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><title type='text'>Windows Help Center Vuln</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TBxOKX6UOfI/AAAAAAAAAWU/MCecpxcNMS0/s1600/Vuln.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 240px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5484344386354690546" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TBxOKX6UOfI/AAAAAAAAAWU/MCecpxcNMS0/s320/Vuln.jpg" /&gt;&lt;/a&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Tavis&lt;/span&gt; &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;Ormandy&lt;/span&gt; discovered an old &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;vuln&lt;/span&gt; in Windows Help Center that allows an attacker to run an arbitrary command on your machine. This only applies to older operating systems like Windows 2003 and Windows &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;XP&lt;/span&gt;. &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;Tavis&lt;/span&gt; alerted Microsoft to the problem. Then he went public with his info.&lt;br /&gt;&lt;br /&gt;The real hack here is that people are making a big deal about &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;Tavis&lt;/span&gt; being employed by Google. Supposed reported are making it look like &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;Tavis&lt;/span&gt; reported the hole to Microsoft and immediately shared the zero day with the world before Microsoft could patch the hole. Imagine that. Reporters are hacking security consultants with their stories. What will they think of next?&lt;br /&gt;&lt;br /&gt;You can find a lot of technical details on the original vulnerability from &lt;a href="http://seclists.org/fulldisclosure/2010/Jun/205"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;SecLists&lt;/span&gt;&lt;/a&gt;. They even disassemble the Windows Help Center executable code, and show you how the &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-corrected"&gt;arbitrary&lt;/span&gt; commands can get through the parsing. That is some deep stuff.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-4678796373159514323?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/4678796373159514323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=4678796373159514323' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4678796373159514323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4678796373159514323'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/06/windows-help-center-vuln.html' title='Windows Help Center Vuln'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TBxOKX6UOfI/AAAAAAAAAWU/MCecpxcNMS0/s72-c/Vuln.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-5640118626223377417</id><published>2010-06-19T00:03:00.004-04:00</published><updated>2010-06-19T00:06:51.666-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='teens'/><category scheme='http://www.blogger.com/atom/ns#' term='phone systems'/><category scheme='http://www.blogger.com/atom/ns#' term='Phiber Optic'/><category scheme='http://www.blogger.com/atom/ns#' term='cracked'/><title type='text'>Masters of Deception</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/TBxBkuYjNnI/AAAAAAAAAWM/F-QjLqX8SpU/s1600/Masters.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 206px; FLOAT: left; HEIGHT: 320px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5484330545412519538" border="0" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/TBxBkuYjNnI/AAAAAAAAAWM/F-QjLqX8SpU/s320/Masters.jpg" /&gt;&lt;/a&gt;A buddy of mine &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-corrected"&gt;bought&lt;/span&gt; me the book Master of Deception. It &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-corrected"&gt;chronicles&lt;/span&gt; the exploits of some young hackers from the 1980's. One of them is the famous &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Phiber&lt;/span&gt; &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;Optik&lt;/span&gt;. I have heard this name before. And I thought he was some ominous hacker. Indeed he might have been. But the book paints him as a teen that stayed up all night trying to figure out phone systems. That is not the thug I expected him to be.&lt;br /&gt;&lt;br /&gt;The book annoyed me a bit. There was no table of contents. That does not help me get a feel for what I am reading in each chapter. When I finish the book, I will come up with my own proposed table of contents for the book and post it here. Okay? For now I really do like the insight into the lives of the kids that cracked the phone system, as well as the authorities that pursued them.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-5640118626223377417?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/5640118626223377417/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=5640118626223377417' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5640118626223377417'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5640118626223377417'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/06/masters-of-deception.html' title='Masters of Deception'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/TBxBkuYjNnI/AAAAAAAAAWM/F-QjLqX8SpU/s72-c/Masters.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-4528908414783187807</id><published>2010-06-12T23:33:00.003-04:00</published><updated>2010-06-12T23:37:16.233-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='priority'/><category scheme='http://www.blogger.com/atom/ns#' term='gun'/><category scheme='http://www.blogger.com/atom/ns#' term='check in'/><category scheme='http://www.blogger.com/atom/ns#' term='transport'/><category scheme='http://www.blogger.com/atom/ns#' term='Fed Ex'/><title type='text'>Plane Protection</title><content type='html'>&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 240px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5482096298994824450" border="0" alt="" src="http://1.bp.blogspot.com/_VDmxk13I3SA/TBRRid4R9QI/AAAAAAAAAWE/OxNM6twpCW4/s320/Case.jpg" /&gt;Here is a smart idea I have read about. Suppose you need to fly, and want to transport something of value. Sure you can carry it on board and keep it close. But maybe you want to check it in. How do you make sure it has the best chance of making it to your destination? You pack it with a gun.&lt;br /&gt;&lt;br /&gt;This is the scoop. You need to declare that you are checking in a package with a gun. Then you sign some forms. The package then gets priority handling and storage during the flight. That is understandable. Who at the airline wants to be responsible for a gun checked in disappearing? I like this idea. Except you need to carry a gun and bring it to the airport.&lt;br /&gt;&lt;br /&gt;The more sensible approach might just be to Fed Ex your item and insure it. That way the shipping company has a financial incentive to make sure you package arrives without being tampered. It is a little more hassle than checking a package. However it may give you more peace of mind that bringing the gun along on the flight.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-4528908414783187807?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/4528908414783187807/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=4528908414783187807' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4528908414783187807'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/4528908414783187807'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/06/plane-protection.html' title='Plane Protection'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VDmxk13I3SA/TBRRid4R9QI/AAAAAAAAAWE/OxNM6twpCW4/s72-c/Case.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-9135571458797801210</id><published>2010-05-29T13:33:00.002-04:00</published><updated>2010-05-29T13:33:00.518-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ZRTP'/><category scheme='http://www.blogger.com/atom/ns#' term='VOIP'/><category scheme='http://www.blogger.com/atom/ns#' term='NSA Suite B'/><category scheme='http://www.blogger.com/atom/ns#' term='SMS'/><category scheme='http://www.blogger.com/atom/ns#' term='WiFi'/><category scheme='http://www.blogger.com/atom/ns#' term='3G'/><title type='text'>Secure Voice and Texting</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_VDmxk13I3SA/S_6tGbD6zZI/AAAAAAAAAV8/O3WzrhNCBg0/s1600/Red.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5476004522784116114" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 320px; CURSOR: hand; HEIGHT: 320px" alt="" src="http://4.bp.blogspot.com/_VDmxk13I3SA/S_6tGbD6zZI/AAAAAAAAAV8/O3WzrhNCBg0/s320/Red.jpg" border="0" /&gt;&lt;/a&gt;I just read about tow new apps that run on Android to secure your cell phone communications. They are Red Phone and Text Secure. You will be able to view the source code for these apps. It is limited to the Android platform, and for calls in the USA only.&lt;br /&gt;&lt;br /&gt;Red Phone is an end to end encryption solution for voice calls. It uses &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;ZRTP&lt;/span&gt; encryption developed by the dude who brought you &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;PKZIP&lt;/span&gt;. This is a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;VOIP&lt;/span&gt; implementation. So the calls do not use up your cell phone minutes. Instead you communicate over &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Wifi&lt;/span&gt; or 3G. It uses &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;SMS&lt;/span&gt; to initiate the calls.&lt;br /&gt;&lt;br /&gt;Text Secure uses the Off The Record protocol. All messages are stored in an encrypted database on your phone. Messages are compressed and sent via &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;SMS&lt;/span&gt;. This technology is based on the NSA Suite B standard. That is the same one used for Top Secret government communications. So you know it is secure.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-9135571458797801210?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/9135571458797801210/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=9135571458797801210' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/9135571458797801210'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/9135571458797801210'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/05/secure-voice-and-texting.html' title='Secure Voice and Texting'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_VDmxk13I3SA/S_6tGbD6zZI/AAAAAAAAAV8/O3WzrhNCBg0/s72-c/Red.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-5599979789279157815</id><published>2010-05-28T13:16:00.003-04:00</published><updated>2010-05-28T13:16:00.113-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CUDA'/><category scheme='http://www.blogger.com/atom/ns#' term='threads'/><category scheme='http://www.blogger.com/atom/ns#' term='Nvidia'/><category scheme='http://www.blogger.com/atom/ns#' term='GPU'/><category scheme='http://www.blogger.com/atom/ns#' term='cores'/><category scheme='http://www.blogger.com/atom/ns#' term='GeForce'/><title type='text'>High Performance Graphic Card Computing</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_VDmxk13I3SA/S_6o5uiUzBI/AAAAAAAAAV0/_gB6CGB_XRU/s1600/Nvidia.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5475999906627111954" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 291px; CURSOR: hand; HEIGHT: 320px" alt="" src="http://3.bp.blogspot.com/_VDmxk13I3SA/S_6o5uiUzBI/AAAAAAAAAV0/_gB6CGB_XRU/s320/Nvidia.jpg" border="0" /&gt;&lt;/a&gt;There is a hot trend out there to get high performance from your code. Run it on your graphics card hardware. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Nvidia&lt;/span&gt; has released their &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;CUDA&lt;/span&gt; architecture which let's you do this &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_2"&gt;easily&lt;/span&gt;. You write your code in the C programming language, along with some extensions provided by &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Nvidia&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;You need a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;GeForce&lt;/span&gt; style card to use &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;CUDA&lt;/span&gt;. The card itself has a number of multiprocessor. Each multiprocessor has a bunch of cores on it. The cores handle different threads executing in parallel. This can give you 10 times the performance of your normal CPU.&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;Nvidia&lt;/span&gt; distributes both a toolkit and software development kit for the Linux platform. You also need the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;gcc&lt;/span&gt; compiler. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;CUDA&lt;/span&gt; comes with a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;cudart&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;runtime&lt;/span&gt;. You set up what &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;CUDA&lt;/span&gt; calls kernels that run in separate threads on different cores. You use the local multiprocessor memory which is faster than your main system memory.&lt;br /&gt;&lt;br /&gt;You probably already have sunk some cash on a nice video card. If you had chosen the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;Nvidia&lt;/span&gt; card and run Linux, you can take advantage of some very high performance &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;GPU&lt;/span&gt; programming.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-5599979789279157815?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/5599979789279157815/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=5599979789279157815' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5599979789279157815'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5599979789279157815'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/05/high-performance-graphic-card-computing.html' title='High Performance Graphic Card Computing'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VDmxk13I3SA/S_6o5uiUzBI/AAAAAAAAAV0/_gB6CGB_XRU/s72-c/Nvidia.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-1934289082477844430</id><published>2010-05-27T10:01:00.003-04:00</published><updated>2010-05-27T10:06:57.937-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Red Team'/><category scheme='http://www.blogger.com/atom/ns#' term='intruder'/><category scheme='http://www.blogger.com/atom/ns#' term='USB'/><category scheme='http://www.blogger.com/atom/ns#' term='break in'/><category scheme='http://www.blogger.com/atom/ns#' term='disguise'/><title type='text'>Penetration Testers</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_VDmxk13I3SA/S_57XDcJaxI/AAAAAAAAAVs/dHlPcBs3Rk8/s1600/Pen.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5475949832919673618" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 320px; CURSOR: hand; HEIGHT: 215px" alt="" src="http://2.bp.blogspot.com/_VDmxk13I3SA/S_57XDcJaxI/AAAAAAAAAVs/dHlPcBs3Rk8/s320/Pen.jpg" border="0" /&gt;&lt;/a&gt;Once you think your systems are locked down, you should probably get somebody to try to break in. Normally you imagine hackers from the outside breaking in. However the truth is that the intruder may be somebody on the inside. Or an attacker can have some help from somebody on the inside. So your security tests need to take this into account.&lt;br /&gt;&lt;br /&gt;You are going to want the guys who disguise themselves and try to physically gain entry to your systems doing your tests. I read a funny story the other day. A guy left a bunch of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;USB&lt;/span&gt; flash drives around. More than half of them were picked up people and used. They got a surprise when the guy's software automatically ran on their machines. People are just not too careful.&lt;br /&gt;&lt;br /&gt;Just like you have internal software test teams, you could also have an internal penetration tests team. These guys are called the Red Team. But it is best to use somebody from the outside. Just make sure you are not hiring a criminal, even if they are "reformed".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-1934289082477844430?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/1934289082477844430/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=1934289082477844430' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1934289082477844430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/1934289082477844430'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/05/penetration-testers.html' title='Penetration Testers'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VDmxk13I3SA/S_57XDcJaxI/AAAAAAAAAVs/dHlPcBs3Rk8/s72-c/Pen.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-2117075465098083706</id><published>2010-05-22T16:03:00.002-04:00</published><updated>2010-05-22T16:03:00.495-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='JavaScript'/><category scheme='http://www.blogger.com/atom/ns#' term='clickjacking'/><category scheme='http://www.blogger.com/atom/ns#' term='trick'/><title type='text'>Frame Busting</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_VDmxk13I3SA/S_bnJP95pMI/AAAAAAAAAVk/Uy1YZtgbZA0/s1600/Frame.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5473816543206417602" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 320px; CURSOR: hand; HEIGHT: 247px" alt="" src="http://2.bp.blogspot.com/_VDmxk13I3SA/S_bnJP95pMI/AAAAAAAAAVk/Uy1YZtgbZA0/s320/Frame.jpg" border="0" /&gt;&lt;/a&gt;I read a detailed paper on how popular web sites perform frame busting. There are web site attacks like &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;clickjacking&lt;/span&gt; where the site uses frames to trick users. The attack goes like this. The site uses a frame to make you think that you are running on the real web site. Instead you are seeing the real web site, but are on the hacker's frame. Web sites try to prevent this by detecting whether you are on their site, or in an unscrupulous frame.&lt;br /&gt;&lt;br /&gt;The frame busting technique is normally some extra JavaScript on the real site to detect the frame problem. This technique is not normally used on every single page on a web site. It is seen on &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;login&lt;/span&gt; screens. Hackers are trying to bypass the frame busting techniques. For example, when they enclose their site in double frames, the prevention sometimes fails. So how can you combat such frame hacks on the Internet?&lt;br /&gt;&lt;br /&gt;Your code can check the domain name. But that can be tricked away as well. You can play some tricks with some overlay &lt;a href="http://xmlhome.blogspot.com/2010/02/microsoft-and-html-5.html"&gt;HTML&lt;/a&gt; elements. However those are not fool proof either. What you really need is some support from the browser. IE8 has defenses against &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;clickjacking&lt;/span&gt;. So does Mozilla. But you have to employ these defenses in your code. You also have to have users with the right browsers to take advantage of it. The paper I read recommended that you do some HTML hacks of your own to hide content if your pages are found to be framed.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-2117075465098083706?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/2117075465098083706/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=2117075465098083706' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2117075465098083706'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/2117075465098083706'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/05/frame-busting.html' title='Frame Busting'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VDmxk13I3SA/S_bnJP95pMI/AAAAAAAAAVk/Uy1YZtgbZA0/s72-c/Frame.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7467851609734946622.post-5907674622644990846</id><published>2010-05-21T10:24:00.002-04:00</published><updated>2010-05-21T10:32:09.055-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='documentary'/><category scheme='http://www.blogger.com/atom/ns#' term='The Pirate Bay'/><category scheme='http://www.blogger.com/atom/ns#' term='Adrian Lamo'/><title type='text'>Hackers Wanted</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_VDmxk13I3SA/S_aX2C-kq2I/AAAAAAAAAVc/U9E3wIP66Zk/s1600/Wanted.gif"&gt;&lt;img id="BLOGGER_PHOTO_ID_5473729351883467618" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 229px; CURSOR: hand; HEIGHT: 320px" alt="" src="http://1.bp.blogspot.com/_VDmxk13I3SA/S_aX2C-kq2I/AAAAAAAAAVc/U9E3wIP66Zk/s320/Wanted.gif" border="0" /&gt;&lt;/a&gt;Word on the street is that the documentary "Hackers Wanted" has been leaked onto the Pirate Bay. This documentary features people such as &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Woz&lt;/span&gt; (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;cofounder&lt;/span&gt; Apple Corp), Kevin Rose (founder of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;Digg&lt;/span&gt;), and Adrian &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Lamo&lt;/span&gt;. More on Adrian later. The documentary is &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_4"&gt;narrated&lt;/span&gt; by actor Kevin Spacey.&lt;br /&gt;&lt;br /&gt;In case you do not know, the Pirate Bay (also know as &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;TPB&lt;/span&gt;), is a web site hosted in Sweden. It is a big bit torrent site. You got to register to access the porn on it. They run Linux, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;Lighttpd&lt;/span&gt;, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;PHP&lt;/span&gt;, and MySQL to provide the site. It seems to always be in the news for controversy. The place got raided by police back in '06. And last year they got taken to court. The site is supported by ads.&lt;br /&gt;&lt;br /&gt;The most interesting part of the documentary seems to be the coverage on Adrian &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;Lamo&lt;/span&gt;. To tell the truth, I had not heard of him before this documentary. This guy used to be a grey hat hacker. He hacked big corporations, identifying security holes for free. They called him the Homeless Hacker because he roamed around. His is most known for hacking into the New York Times, adding himself as an expert source in their database. They prosecuted him for that, and he got 6 months confinement, 2 years probation, and a heft $65k fine. The dude has since gone on to college, and is now a journalist.&lt;br /&gt;&lt;br /&gt;I will leave with a funny story about Adrian &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;Lamo&lt;/span&gt;. They wanted him on the NBC Nightly News. He was asked to demonstrate his skills. So he proceeded to quickly hack the NBC Network, upon which he was &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_10"&gt;escorted&lt;/span&gt; out the building. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;LMAO&lt;/span&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7467851609734946622-5907674622644990846?l=black-of-hat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://black-of-hat.blogspot.com/feeds/5907674622644990846/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7467851609734946622&amp;postID=5907674622644990846' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5907674622644990846'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7467851609734946622/posts/default/5907674622644990846'/><link rel='alternate' type='text/html' href='http://black-of-hat.blogspot.com/2010/05/hackers-wanted.html' title='Hackers Wanted'/><author><name>Xero</name><uri>http://www.blogger.com/profile/04429435625407357843</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_VDmxk13I3SA/R-B4oiKKoUI/AAAAAAAAAAM/mmlWLBhTq-4/S220/BlackHat.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VDmxk13I3SA/S_aX2C-kq2I/AAAAAAAAAVc/U9E3wIP66Zk/s72-c/Wanted.gif' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
