Chick Virus Writers

I read this interview with a female hacker. She writes viruses and is a freelancer. She goes by the handle hh86. Credit to SPTH for the original interview.

So hh86 says that her friends really don't know she is a virus writer. Incognito. Nice. She is hard core in that she writes her viruses in assembly language. Writing with compiled languages is restricting for her.

Shrug for the 64 bit Windows platform is a virus she admires. She is author of the Delae family of viruses. These are ones with names that start with w32.

One of hh86's techniques is to obscure the entry point of her viruses. Unlike other virus authors, she does not do IRC much. She is in contact with antivirus peeps.

Look for a new zine to be released by hh86 next month.

Find Your Foe

Continuing from my last post, I learned a few tricks by watching some video from DefCon 18. Everyone has a web browser. You can use the browser to deliver software to users.

FaceBook has a feature where the client checks whether a user's friends are online or not. This is just an HTTP request to FaceBook. Good stuff to know.

Here was the finale of the talk I watched. Create a web page with malicious code. Have a piece of JavaScript that inquires the MAC address of the user's router.

The MAC address is set in hardware. It cannot be changed. Once you have the user's MAC address, you can send it to Google. Then Google will tell you where the router is located geographically. Bamm. You can track the people who come to your web paged. Owned.

Cracking the FaceBook Session

Just watched a 3 part series on YouTube. It was from DefCon 18. Dude was looking to exploit another guy on FaceBook. He noted that FaceBook uses PHP. And PHP is open source, including its session management code. When you log into FaceBook, you get a session which is nothing more than a random string.

The session string is stored as a cookie in your browser. PHP session creation uses a 160 bit string. It would take millions of year to brute force such a string. However you can study the properties of the string to narrow down the possible values it might contain. Then you can narrow down the bits that are truly random, and break down the door.

One part of the string is the IP address. You can grab this by sending a person to your web site. Another piece of the string are two random number seeded with the web server start time. Cause the server to reboot, and you will approximately know when the start time is.

So after narrowing down the cookie, our friend managed to narrow the random bits down from 160 to 20. Now 20 bits can be cracked in a few seconds. He measured that it takes on average 500k attempts to guess 20 bits of random numbers. Good stuff. Getting back to FaceBook, they actually use a modified version of PHP called Hip Hop. And after our boy figured out how to crack the session cookie, PHP was patched to make it harder to crack.

Maybe next time I will also go over how this dude can figure out where you are geographically located by hacking your router. I love it.

Phony Checks

I just read this doozy of a story. It was from way back in 1995. A dude got a piece of junk mail with a $95,000 check in it. The check had the words non-negotiable written in the corner. So the guy goes to his ATM and deposits the check. 10 days later, the money is still in his account. A teller from the bank says the money is his since it has been over 10 business days and the check had not been returned. This is a synopsis of the Midnight Deadline.

The dude did some researching on check validity. The authority on this subject if the banking book by Brady. It states what a check needs in order to be valid. Just because a check has the words non-negotiable on it does not make it invalid. So the guys thinks about trying to get the $95k out of his account in cash. But that is a big process because banks usually don't dole out so much cash. Instead he gets a cashiers check.

Over a month later, a security officer from the bank accuses the guy of fraud. However all checks are initially assumed to be valid. The bank must server the depositor a notice of dishonor in a timely fashion. This was obviously not the case with this guy (it had been over a month). The guy decides he wants to get the Wall Street Journal to do an article on him. It takes a long time for that article to make it to print.

The guy decides to put the story on his own web site. His bank account gets frozen. His ATM card gets confiscated. He tries unsuccessfully to reach the president of the bank. In the end, he winds up negotiating with senior counsel from the bank. He can't get any photographers in the bank on the day when he hands the cashiers check back to them. It is too bad he did not try to keep the money in the end. He had a good legal ground to stand on. If he did not want the money himself, he could have given it to charity.

Prison Break

Let's talk about getting out of prison. No. I am not talking about breaking out. I mean serving your time and being released. If you remain on good behavior, you will accrue 54 days off per year. These can add up if you spend many years in the slammer.

You can normally serve the last portion of your sentence in a Community Corrections Center (CCC). This is a house out in the city. You get to work a job. But you must spend nights and weekends back at the house.

Do well at the CCC, and you may be able to serve the very end of your sentence under house arrest. After you are out, you must report to your probation officer frequently. Try to stay out of trouble. Sooner or later things will lighten up. Ok. I have been going over the highlights of what I know about the big house. Time to return to more hackology like coding mad apps.

Prison Life

Here are a bunch of tips to guide your life behind bars. Don't threaten other prisoners. If you want to make an impressive, be like Nike and just do it. You know what they say. Actions speak louder than words.

When you do have a beef with another prisoner, don't involve the guards. That makes you seem like a snitch. Nobody likes a snitch. If your problem involves a guard, then you can submit a complaint.

Complaints against guards or other prison employees will take a long time for resolution. To maximize the chance that your complaint will be effective, keep it short and specific.

Finally let's talk about solitary confinement. You get put into "the hole". It is a small area. Most everything is concrete, except your toilet and bed, which are steel. It is cold in there. The food you get fed is minimal and also cold. Normal punishments get you into the hole for 1 week.

Federal Bureau of Prisons

There are a whopping six different levels of security in the federal prison system. A designator at the prison will figure out what level you start out at. Let's get into the different levels.

1. Minimum - This is for short sentence convicts. There is no fence to keep you in. If it is your first time, you will probably wind up here unless you were convicted of a violent offense.

2. Federal Correctional Institution - You are fenced in here. You got sharp stuff at the top of the fence to prevent you from climbing over.

3. Medium Federal Correctional Institution - There are extra guards on duty here. Inmates are serving long sentences. You don't get to move around as much compared to the lesser security prisons.

4. High Federal Correctional Institution - More oversight by guards. Less movement by inmates. Very long sentences served by inmates.

5. United States Penitentiary - The real bad guys are kept here. You cell mates will be murders and such. They don't use a fence to keep you in. There is a very high brick wall surrounding the prison. If you make it in here, you may get roughed up bad by other prisoners.

6. Supermax - Also known as Max. You are always stuck in your cell. If you need a shower, you get a sponge and some water. If you must leave your cell, you are cuffed and escorted by a lot of guards.