Boosting Your Chess Skills


Recently I have read a few articles on how to quickly boost your chess ability. Hey I am always down for a shortcut. Well you can't get something for nothing. There is some work involved. However you can maximize your bang for your buck in studying.

One thing you got to do is manually analyze your games. Don't just let the computer do it. Record your moves and go back over them after your games. You also got to study up some exercises. There are a lot of books to help you do that. Practicing the basics can give you quite a boost.

Here is some advice that I found strange. Avoid studying openings. That is not a high return on investment type of study. Go figure. All I know is that I need to step up my game so I can put my chess computer program in its place.

Beware of Emily


Some bad boys came up with a plan to infiltrate a government security agency. They set up a fake social media profile of a hottie. They used some random good looking girl's photo. They also made it seem like she graduated from MIT. Her resume boasted 10 years experience in the industry. Poor government officials had no chance.

Emily started making virtual connections. Got some FaceBook likes and friends. Also got some LinkedIn love. It was not long before she was getting offers to help her cut through the red tape to get jobs at government agencies and commercial companies alike.

Did I mention that some emails sent from emily had viruses in the payload? Yep. Government computers compromised. What is a security professional to do? Guys cannot help themselves when they see poor Emily needing an assist. Social engineering at its best.

Wide Open for Attack


I switched over to a new router recently. Set up WPA-2 encryption on the wireless access. Don't want the neighbors stealing my Internet bandwidth. Then I had to move all my printer over to use the new router. I got a ton of printer. But I use three of them wirelessly all the time. Two of them are cheap Brother printers. The other is a color HP.

Turns out the easiest way to configure the printer network configuration is to connect to the printer over the network. Each of these guys seems to have a built in mini-web server. You just figure out the printer's IP address. Then you put that address in the browser URL bar. Presto. You are greeted with a tons of menus to control the printer.

Now changing the printer network configuration requires you to enter a username and password. The problem is that I never changed those passwords from the factory defaults. Doh. This is just like leaving the default passwords on my wireless routers.

Now I figure there can't be too much damage done if someone comes in and mucks around with my printer configuration. I could always press the button that returns them to their factory configuration, then lock them down. But why wait? Lock them up tight I say.

Operation Honey Pot


I have used the default SSID on my wireless router at home. Did not enable any encryption on the thing. The whole neighborhood could use it to access the Internet. The rest of the people in my home got irked that they had to share bandwidth with random strangers. I caved in and decided I would put a password on our connection.

However I decided to achieve the bandwidth goal using another means. I bought a separate router that had a secure connection. But I left my old router on. I bet there are lots of people using the old connection to get to the Web. Why not turn that router into a honey pot?

I still needed to keep the Internet connection open. First I figure I could just log who is using this open router. Then maybe I could start to spy on their traffic. Finally I could see whether I could reach back into their devices (computers) to poek around. This is going to be fun.

Perhaps I should google around to find some tools to help me with my exploits. Or I could just roll my own tools. That would be truly educational. Fair warning people. If you are leeching off a router with SSID linksys, you might be owned soon.

Cracking Cobalt Strike


I read an interesting article by Raphael Mudge, creator of Cobalt Strike. He explains how one could download the Cobalt Strike program and crack it. You can inject your own evil code into the install. Then you can post your results up on some site as a cracked version. Read all the details on his blog.

Part of the reason why this is possible is that he uses the Sleep scripting language in his solution. So you can modify his Sleep scripts to do some of your own work. I like how the guy freely comes out and explains how to do it. His software is, after all, a tool to help penetration testers. I do understand why people might want to crack his software. Prices start at $2500 per year per user. And that is the discounted price!

Choices of Edward Snowden


Every day I am hearing more details about Edward Snowden. He is the whistleblower that leaked information about the NSA spying on US citizens. Snowden previously worked for the CIA as a security guard. He most recently was employer by Booz Allen Hamilton, a government contractor. Snowden's worked on a contract for the NSA. There he found that NSA had set up the abiltity to track phone calls, emails, and who know what else with tech companies. Then he went public with the information.

Why did this guy do this? I think he only had a high school degree. Still he was pulling down a fat salary living in Hawaii, where he had a hot girlfriend. Now he is on the lam running from the US government. Is this guy some sort of patriotic hero? He did seem to give up a whole lot to expose the dirty deeds on the NSA. I guess he was fully committed to outing the government. You got to give the man credit for that. Now he is allegedly hiding in Hong Kong.

The real question is what is going to happen to the spy programs set up by the NSA? Tech companies like Verizon, Google, and FaceBook are already in bed with the NSA. The suspicious detail is that all these companies are under a gag order to ensure they do not cough up details of the access they have provided the NSA. Man are we moving in to a police state or what? Perhaps we have always been there, and Americans just want to ignore it at their peril. Myself included.

Operation Troll the NSA


In reaction to the latest evidence of the NSA spying on US citizens, somebody has come up with a plan to DDoS the data collecting machines. The pitch is to overwhelm the email and phone circuits on Wednesday with juicy keywords. You know, words like overthrow, blueprints, bomb and such. See the full script at Operation Troll the NSA.

Now the idea might sound interesting in theory. Overload the listeners. However I doubt it will have any effect. Since the NSA could detect that such a scheme was going on, they could explicitly filter out all the trolling. This is especially true if participants follow the exact script. However at least this is a start.

I did LOL that the only link on the trolling page was an Gmail contact link.