Showing posts with label English. Show all posts
Showing posts with label English. Show all posts

Friday, November 6, 2015

There are tons of websites to find a job, that's the thruth


 

There are tons of websites to find a job, that's the thruth

So? There has been a long time since my last post, I've been starting so many projects including some business and stuff and today I'm back to write about this topic which is not even close about the last posts.

So if you are looking for some networking or computing cheat, that's not your post :)

I'm here to think and write about job hunting websites and all about those things.

There was an age...


There was an age where sites like linkedin and infojobs were cool sites to find a job, but, to be honest the have lost that charming brand new magic and they are just a huge curriculum store.

And now what? what's the trend?

That's the point, there are no reference in this matter, it becomes a problem when you are trying to upload your CV to the Internet because you need to keep up-to-date from three to ten profiles in different websites which are roughly the same thing.

There are no fashion sites, the trend now is that there is no trend; and that's a real problem.


I've no tips about which site is the best, so that's my idea, create your own.
Maybe it looks a bit crazy, but it's just an idea.

My own site? What kind shit is that?

Ha ha! You may be right, it could be crappy if you do by the wrong way and the problem is... that there is no best-way but I think that this may be a good chance to take the attention about a head hunter / human resources crew if you make the difference by sending your CV just all-in-one by sending a URL.


Some examples?

I've no examples but I have some ideas to tell to you:

- Create a easy-quick-free site using services like blogger. This is easy to do and free, the only problem may be the low customization level.
            www.blogger.com

- Contact with cheap webhosting services like 1and1 "my web" or something like this, they are intended for small business but you can try it. They have medium customization level.
           www.1and1.com

- You can try too by contacting the MiniWeb guys, they are a brand new website design&hosting company, they just started a few months ago but they are doing quite well. You can contact them both in English or Spanish, you'll find a very cheap service packs. Can contact by facebook, twitter or send a message from the web form contact.
          www.miniwebspain.tk


We are legion

Tuesday, January 20, 2015

My preferred linux distros. Wireless auditory

Hello there,

Long time ago from my last post, there were too many changes in my life but finally I'm back :)

Today we are here to discuss about current linux live distros for wireless auditory.

There were many changes during this while, lots of linux flavours with many wireless audit tools already installed and ready to run live, persistent or installed on your hard disks but today I will write for my favourites.

  • Xiaopan OS (the tiny one)
  • WifiWay / WifiSlax (actually, the same)
  • Kali (huge, a beast)

The tiny one, Xiaopan OS

Xiaopan Logo

You can download the ISO file from http://sourceforge.net/projects/xiaopanos/   just ~70 Mb and all the info about it at http://xiaopan.co/


From it's own website we get this comments:

Xiaopan OS is an easy to use security and penetration testing with a collection of wireless security and forensics tools. It includes a number of advanced tools for network administrators, security professionals and home users to test the strength of their wireless networks and eliminate any vulnerabilities.
Xiaopan (0.4.7.2 is the latest)

I've tested this distro three times:
The first one: my desktop computer, It worked great live from my USB device, I tested many tools and opcions, all working fine. It's tiny but powerful.
The second one with my laptop, it was unable to detect my wireless network interface, testing tons of "solutions" from the Xiaopan forums, end of story :(
The last one: With my girlfriend's notebook, same as the previous one, wireless interface not detected.

So, my conclusion is that Xiaopan is a very light linux distribution full of options and utilities but it needs a few more controllers and drivers to be widely compatible to many computers and devices. It will be great in the near future, I hope.


WifiWay / WifiSlax

These are awesome linux distributions that I love, it's light enough to be stored in a cheap USB device but has drivers, utilities....  enough to be a great penetration testing linux distribution.

WifiSlax Logo


We can call them the twin distributions, you can test both of them, they are likely the same but from time to time one of them releases a new version, so, I switch between them properly.

You can download it from http://www.wifislax.com/category/download/nuevas-versiones/
Its website has many tutorials and news it Spanish but you'll be able to translate it with no problem, all of them are plenty of photos and videos where you can find all then info you may need.

Both distributions will work great both live or persistent (obviously installed too). I used to test many linux distributions but I'm always  back to WifiSlax when I need to do something important, with no problems, no issues, just working quick and fine.


Kali

It's, (said by their own website) the rebirth of BackTrack, if you know, that's the only presentation that it needs.
BackTrack was the best well-known penetration testing linux distribution in the world, everybody loved it; and now, everybody should love Kali too.

I say that because there are a few changes in the way it works (most of them have improved it) but there are many nostalgic people who misses backtrack.


Kali Logo
You can download Kali here https://www.kali.org/downloads/



 There are many Kali versions, for 32 bit, 64 bit, for ARMEL chips, for ARMHF chips... eventualy you have the chance to download the core and build a custom version for your own.


In summary, it's a huge linux looking at the tools, functions, utilities... it has all you will need for seven lifes! But, it's (from my point) too big for live USB. I mean, it works live from USB but it's not as responsive and quick like WifiSlax



I always love to summarize with images to make things easier to think, that's my view of these distros:

WifiSlax

Xiaopan
Kali



Xiaopan, you'll feel like Bart Simpson
WifiSlax, quick and effective.
Kali, huge and powerful.

In the next post I will write about how to make your own linux USB bootable.

We are legion










Saturday, May 12, 2012

Windows 8 will not allow SW non-MS SW

Hello all,

A few days ago we read at the Mozilla forums:
"an unwelcome return to the digital dark ages where users and developers didn’t have browser choices."Said by Harvey Anderson, general counsel in Mozilla co.

Do you have to imagine a future only with MS apps? You won't be able to use Firefox, Chrome, WinZip, WinRar, WinAmp...


Some art in the street:





Some people could think "who will buy a OS which will not allow me to decide which internet browser I want?"

Even: Who the hell is going to buy that?

My own opinion: "Nobody!!!!!!!"


Which could be the explanation for this behavior?

Easy to answer too :) It is the kind of action undertaken by a company that has lost its way.

Really, does anybody think that this action will help them? I really think that this action will definitely push people to try Linux/Unix at home, don't you know?

If you are one of those users, I will recomend you Ubuntu or even BackTrack :)

Thus, this image will take sense, right? :)







I know that is a very short post, but.... I HAVE TO inform of this, I think is absolutely needed.


Next post: "My preferred linux distros. Wireless auditory" (English)
Siguiente post: "Mis distribuciones favoritas de Linux. Auditoria WiFi" (Español)


We are legion

Wednesday, April 18, 2012

Shutting down the Internet #OpBlackout

(Now you can access to the Spanish version of this post | Ya puedes leer la versión en Español de este post)

Hi there,
Hope you are doing well.

Does someone know what is the Operation Blackout?
Referring to the post title, this could mean "shutting down the internet" but the title is not 100% accurate.


We will proceed step by step.


What is a IP address?

In a easy way, is the registration plate of your PC. The only thing you should know is that you will share your registration plate with other users if you are sharing a router (like the ADSL router in your home)


What is a DNS Server?

In a short manner, a DNS Server is a address translator on the Internet.
When you type in your internet browser "www.mywebpage.com", your PC won't know what's that because
your PC only knows about IP addresses.

Then, the DNS will help your PC when translating:
www.mywebpage.com  ====>  12.34.56.78




How DNS Servers work?

There are only a few main dns servers, other DNS servers are working just by getting data from another DNS servers.
This is a distributed work which will improve the DNS translation performance.




Then, how can Anonymous shut down the internet?

Anonymous """""only?""""" need to bring down those root DNS servers and other will bring down in a domino effect.

Click here to get more information about root DNS Servers.

Why we say "only"?

There are many technical reasons that turns this attack very hard or even impossible.
The main reason is that these main DNS servers are implemented as clusters using Unycast but we won't explain this because this blog only explains the easy and basic hacking issues.

Next post: "Windows 8 will not allow SW non-MS SW" (English)
Siguiente post: "Windows 8 bloqueará programas de terceros" (Spanish)

We are legion

Friday, April 13, 2012

CISPA (the new version of SOPA)

(Now you can read this post in Spanish | Ahora puedes acceder a la versión en Español de este post)

Hi all!

Are you living at the US?

If so, I have bad news for you. During this month a new bill is being prepared and it will be called "CISPA" (Cyber Intelligence Sharing and Protection Act)

You can get some official information about the HR3523 here. Also known as the Rogers-Ruppersberger bill.
We 're very worried about this new bill and hope it won't become a law in the US.



Many people are writting information about this new bill what as far as I know, it will mean the return of SOPA, PIPA and ACTA together. This bill is being showed "not like SOPA" but has lots of similar topics. By the way, this new look of SOPA+PIPA+ACTA bill has already collected many supporters including a very famous one, Facebook is the main supporter.

There are many points were this bill is not very clear, but it explains that ISPs will be able to intercept private comunications and to send it to the NSA (National Security Agency) and the DOD's Cibercommand.

The most dangerous part of this bill is that some companies would be able to spy and monitor de user connections without the needing of notify this activity to the user or the Government. Thus, many people thinks that this bill would become in a law that allows industrial espionage.

Companies like AT&T, IBM, Oracle, Symantec, Microsoft, EMC... will support CISPA because their responsabilities will be reduced in case of legal issues

Even companies as Google or Facebook would intercept emails and share it between them and the government.

Do you want to investigate further? Follow this link



Really, this is a bad bill like SOPA and CISPA or even worse and it looks like it's going to pass unless people speak up.


If you are not at the US you should be worried too (as me) because most of US bill are often "exported" to other countries like Spain, UK, Germany, France...

We are legion





Monday, April 9, 2012

Hacking XBox360 card credit data

(Now you can access to the Spanish version of this post | Ahora puedes leer este post en Español)

Hi all,

Did you sold your old Xbox 360?

If you didn't hit the disc with a hammer, I've bad news for you.
Some investigations about Xbox 360 data security at Drexel University found security issues about the storage of credit card data.

Even a "full factory reset" will not be enough to completely delete your credit card data. You'll need to be more exhaustive in order to perform a full deletion.


What about other MS products?

This issue is reproduced in other Microsoft systems, like Windows.
When you're formatting your hard disk on a windows system, you will be noticed about the data deletion, but, that's true?

The answer is "NO",  during the "disk formatting" MS Windows is just setting the data as "unused" but the information remains in the disk. This is the way that some data recovery tools work, these tools will read the full disk including sectors labeled as unused.


Don't you sold your Xbox yet and you wanna erase your data?

First you should remove the disk from the Xbox360, then, I would recommend you some disk utilities like "Hiren's Boot", "Q Manager", "Partition disk manager".... all of them will perform a low level disk formatting and this implies low level disk erasing.

Now, you can sell it :)




Are there news related from Microsoft?

There are some news about this issue, but it's not very clear. Someone said that MS is investigating the issue but there are no official information yet.

We are legion.

Next post "CISPA (the new version of SOPA)" (English)
Next post "CISPA (La nueva versión de SOPA)" (Spanish)


P.S: This post took longer because the Semana Santa holidays in Spain :)





Thursday, March 29, 2012

OpenVas Vs Nessus

(Now you can access to the Spanish version of this post | Ya está disponible la versión en Español de este post)

Hi there!

Today we will talk about OpenVas and Nessus but I think we will start the post explaining from a most basic idea:


What's a vulnerability?

Vulnerabilities are also known as "security holes". A simple meaning of this holes can be this "Security holes can be saw as open doors in your PC when you are think that this doors are closed"







I really think that most people do not know that these doors do not even exist.










Now that we know that these doors exists, how can we close it?



Most of vulnerabilities are not easy to detect by a human, even a security expert can not be aware his/her own PC vulnerabilities.

We should know that most of vulnerabilities are caused by well know software applications like internet browsers, messenger apps (like MS Messenger, Skype, IRC...).

Malicious emails are a big source of security risks too.


If you're worried about if your computer is vulnerable, you should run a vulnerability scanner.



What's a vulnerability scan?

In a simple manner, a vulnerability scan is a script-tool with a huge amount of plugins which are able to detect vulnerabilities automatically.
Each plugin is a special "module" will be able to detect a particular kind of vulnerability.
Back to the post title, OpenVas and Nessus are vulnerability scanners.




Nessus
Nessus: Network Vulnerability Scanner

Nessus is a well known vulnerability scanner.

Pros:

  • Easy to install
  • Simple interface, it has just the neccesary items.
  • Higher quality tests
  • Only one support company
  • Higher amount of plugins.
Cons:

  • There are a home (free) edition is very limited
  • The professional edition is very expensive.
Opinion:
  • I only tried the home edition, it's easy-to-use. Ok to perform your first scannings for learning about this "world".
  • I had not the pleasure to work with Nessus "paid" editions :(

OpenVas

Pros:

Open Vulnerability Assessment System
  • Completely free and, more, completely open source. You will be able to recode it if you want to do it.
  • Being free and opensource means that it will supported by many companies.
  • It is able to implement more advanced funcions than Nessus.
  • It's 100% operative, you will be able to enjoy the full power of OpenVas, not like Nessus.
  • It has better access tools, like a web client, a console client...
Cons:
  • It's more difficult to install, to config and to use it.
  • A free-opensource software could not transmit the confiability than a "paid one".
Opinion:

  • This is my favourite one, with it you will be able to perform very advanced scans. It's powerful but not easy-to-use.


We are legion
Next post "Hacking XBox360 card credit data" (English)
Next post "Piratear la tarjeta de crédito de tu Xbox360" (Spanish)

Monday, March 26, 2012

HOIC

Hi again!

Today we will talk about HOIC (High Orbit Ion Cannon), from my point of view is the most powerful tool in the world right now.

HOIC is based in the previous software tool called LOIC (Low Orbit Ion Cannon).


Matchings

In a general overview of both tools, there are no differences between them:
- Both are built to launch a DDoS attack
- Both use HTTP flood to perform the attack
- None of them requiere to install in your computer
- Both of them works based in a script
- None of them will hide your ID (you will do it by your own. e.g. "VPNs, SSH tunneling...")






Differences


About some differences between them:
- HOIC can't be controlled by a remote user, LOIC was able to work like a botnet.
- HOIC has higher hardware requierements
- HOIC could be more destructive than LOIC (HOIC has some booster scripts enhancements)
- HOIC introduces some randomization data, thus, It's more complex to detect a HOIC attack than a LOIC attack.
- HOIC can work with TCP, LOIC is able to work with both TCP and UDP.






Easy-to-use software

1) Click the "plus" button (+) and add the hosts to attack
2) Enable the maximum power and boost options
3) Click launch HOIC and wait :)


We are legion
REMEMBER, USING THIS APPLICATION CAN CAUSE LEGAL ISSUES, BE CAREFUL!!!!


---------------------------------------


You can check the previous post related to LOIC and DDoS attacks
Next Post: "OpenVas vs. Nessus" (English)
Next Post: "OpenVas vs. Nessus" (Spanish)

Friday, March 23, 2012

PayPal is vulnerable, XSS

(There is another post in Spanish | Puedes acceder a la versión de post en Español aqui)
Today, here we are with the next post about a kind of hacking.


A few months ago (about December'11) two Indian hackers were able to launch an attack using the URL from the PayPal site.
That not means anything about the server breaking-into, this is not correct. But that could mean a "Man in the middle" attack (MITMA).









Why wanna do with a MITM attack?
Easy to know, to review and steal your sensitive information like user accounts and passwords, bank accounts...




What's a "man in the middle attack"??


We will supose: I want to launch a MITM between Google and a friend's pc. I'll need a software to "cheat" my friend's pc (i.e. Metasploit). When he writes google.com he won't access to google,he'll access to my pc camouflaged as Google web site and I will be connected to the real Google server.

In the image (right), "Web Server" could be Google in our example and the victim PC is our friend's PC.




In the image (left), the victim is "authorized user". The attacker say to the access point (AP) that he is the authorized user and the attacker say to user that he is the AP.



By the way, the attacker will be in the middle of the data traffic.

Thus, the authorized one will think that he is directly connected to the corporate LAN but the attacker will be seeing all his data transmission.







Then, what's XSS - (Cross Site Scripting)???


XSS is a kind of vulnerability directly related with websites and/or web applications that allows an attacker to send data bypassing server validations. This vulnerability could cause a few kinds of attacks: persistent, non-persistent...

In summary (if your an expert hacker you will feel stomach ache with this summary and definitions, it's just for let a simple definition for non-experts):

- If the hacker "cheat" the remote user and use its data to access the server data, it's non-persistent XSS attack
- If the hacker "cheat" the server admin user and use its data to access the client data, it persistent XSS attack

For the second type, this is a graphical explanation:


If you wanna get more advanced definitions about XSS, click here.
------------------------

We are legion.
Next post: "HOIC: new improved version of LOIC"

Tuesday, March 20, 2012

Reaver (WPS attack) and WPAMagicKey tools

wep wpa WPA
(There is a Spanish version of this post | haga click aqui para acceder a este post en Español)
Just a few months ago we heard:  "WPA is down, we've cracked it!"



That's absolutely wrong, no body has cracked this security algorithm. Today, this will be our main idea.
At least, no body had published anything about WPA cracking. It was long time ago from WEP cracking but not yet for WPA (of course, WPA2 is included)

There are some ways to access to a WPA wireless network, but none of them could be called "cracking":

- Capture the WPA - TKIP handshake (aircrack + dictionary): this is not cracking because you need a later dictionary attack to be able to get the password. If you have no dictionary, you won't be able to get the password.
- Use the WPA Magic Key dictionaries (w/o aircrack): This tool can generate the default password list for this router if your wireless is WLAN_XXXX or JAZZTEL_XXXX and you never changed your password.
- John The Ripper (to use with aircrack): You can generate your own dictionary if you know the password pattern and it's not very long (shorter than 4 - 5 characters), if it's long your dictionary will be huge and you won't be able to use it. (View table and pie chart below)




From the calculations in the table above, it could be a bad idea try to crack by using brute force attack in a WPA wireless network.


In the pie chart below you can check what most passwords are in the strongest group (mixed character type).





Then, I think still nobody cracked a WPA password, right?


From the hacker point of view, the most important difference between WEP and WPA is what they transmits on the IP package. A WPA packet is not transmitting any information about the network master key, this is not true about WEP encryption.

Now, we must learn about WPS (Wikipedia EN). The most simple&easy way to think what's WPS: "WPS is a button which allows us to connect (or not) to a WiFi".
Finally, if nobody was able to crack a WPA... what the hell is reaver? what the hell can it do for me? will I be able to use reaver?

- Reaver: Is a script-tool which will use a WPS vulnerability algorithm to "cheat" a router and get the WPA key.
- As far as I know, reaver will only be able to help you when your're using TKIP (not supported for AES yet)
- Previous to execute "reaver" you should execute the "walsh" script-tool. It's a "twin-app" what will tell you which wireless networks are vulnerable to this attack.

There are lots of video tutorials about reaver... (my favority one is the first video)
Video#1 (here you will learn how to install too, very interesting)
Video#2

You maybe need this tips.

In most cases you will get reaver from linux distributions like Backtrack or WifiWay.
We will talk soon about the new rease of WifiWay (v.3)

You mustn't use this information for hacking, you have to use it just for learn about security, right?

We are legion


================================================================
Next Post: "PayPal is vulnerable, XSS"

Wednesday, March 14, 2012

Google Hacking, be careful with your web site!

(Now you can access to the Spanish version of this post | Puede acceder a la versión en Español de este post)

Hi there!
Long time ago from last post, I was very busy last months.
We're back again to talk about a old-classic way of hacking: "Google hacking".
This hacking is very simple a it doesn't require any advanced tool or software, it can be done just by using a 56k modem connection to the internet  (I really hope your connection is a bit faster than this  :D   )
All of us know about the advanced search algorithms and powerful data pickup of Google, I think Google is the most technologically advanced search engine in the world right now (in the last 5 - 10 years).
Google is much than a text box and a "Search" button; even much higher than a "I'm feeling lucky" button  :)
We should know Google has able to pickup data from other files than classic html web pages, every day Google is detecting a huge amount of pdf, doc,... files. Google has many filter and advanced search options, like search by filetype, by some text in a web address (url), by file extension...
This mechanism is simple as:
- Searching Doc. Watson logs from a machine
- Searching important information about personal data
- Searching files with users accounts
- Searching files with user and passwords!!!!
Yeah, absolutely, all of this info is there, we have free access at many files just using Google.
You can access to google help in order to learn about Google "commands" to perform some advanced searches.
Recently, this easy simple hacking type was used against many important security organisms from the U.S. and West-Europe.

This method can be considered "Social Engineering"

We are legion.
Next post: "Reaver and WPS attack"

Sunday, September 25, 2011

WifiWay 2, hack the air!

(Visit the brand new version of this old post in Spanish)
Today we will write about "WifiWay".

WifiWay is a free open linux distribution which is "the son" of the WifiSlax distribution.
This is a well known linux distribution related with wireless auditing.

From the older one, WifiSlax, WifiWay inherited a lot of utilities and tools, like the aircrack framework, including airodump, aircrack, aireplay... etc.

Those tools was great but they were not easy-to-use for new users or auditors with a low knowledge.

This distribution evolved to "WifiWay 1.0", that distribution was simplified with a ".sh" script called airoscript and airoscript.es (Spanish version); that script helped users to launch auditories without the difficulty of long command line sequences and lots of "parameter:values"

WifiWay 1.0 had an "hole", dictionary attacks was not automated and simplified, yet.

A few time ago, WifiWay 2.0 arrived and got us a more simplified interface and some utilities related with dictionary attacks; it included a new version of airoscript, easier and more powerful, again.



Now, the current version is "WifiWay 2.0.3 final" a free open powerful automated linux distribution. It has a improved airoscript with "auto crack" mode, it allows us to automatically crack or attack a wireless access point near to us, yeah!, full automated :)

You can get longer information about at  http://www.wifiway.org/

Hey man, don't forget, just for auditing, not hacking
 :)
Enjoy it!

"We are legion"
Next Post: "Google hacking, be careful with your website!"

Thursday, September 22, 2011

What the hell is Nessus? Fast overview

Today we will write about Nessus (from my point of view) the best vulnerability scanner.

There are many network scanners:
 * nmap: a very simple command line network scanner.
 * wireshark: a network sniffer, GUI and command line.
 * airodump: wireless scanner.
 * airsnort: an old wireless scanner.


There are many scanners, but none of them gets the level of nessus. This is my favourite one :)
Why?

Nessus is a free vulnerability scanner, you can use it as GUI or command line, no problem.

Nessus works as client <-> server. This is (in short), our nessus server will do the work which we launch from the nessus client.

The GUI client interface is very friendly and easy-to-use.
The command line has a powerful engine that allows us to integrate nessus with metasploit framework (we will talk about metasploit framework in later posts)

Once installed, up and running, we have a "light" version of nessus, it has only a few plugins available.

We have to go to the nessus website and register our nessus. (I asume we are NOT a company, just home users; companies should buy a enterprise version of nessus)

After register our nessus server, we can download all of plugins and full update our nessus engine.
Then we will have our nessus engine ready to run.

Thus, which is the functionality for this plugins?

Plugins are used as working modules, they are used to detect vulnerabilities, each one is dedicated to some type of vuln. Then, you should keep your plugins updated, in order to have the best vuln detection.

Nessus works in a three module manner:

- Policies: policies are used to define the scanner behavior, which IPs will be scanned...
- Scanners: this is the main nessus function, a scanner is a "policy running"
- Reports: a report is created after scanner execution, is the output of the scanner, listing all the vulns detected and the exploit, if it is available.


Those reports can be read by metasploit, to execute commands like "db_autopwn"     :)


"We are legion"
Next Post: "WifiWay2, hack the air!!!"(English)
Siguiente Post: "WifiWay2, hack the air!!!"(Español)

Wednesday, September 14, 2011

Differences between DDoSing/DoSing and hacking

Today we will talk about differences between DDoSing a service and hacking a server.

If you don't know what't DDoS and DoS, go to posts about LOIC and RefRef.
I asume all of we know what the hell is "hacking", now, we are all DoS experts :)

Could be DoS or DDoS considered a type of hacking? I think it is not, at all.
From my point of view, hacking is all actions that uses some security hole to break something in our systems.

By the way, if a guy is lauching a DoS attack, this guy is not breaking anything.
The attacker is not getting any information from our system, he is not thieving, he is not breaking.

Thus, why can be a DoS considered an illegal action? I can't understand that.
I think that arresting a guy for lauching a DoS attack is not correct at all.

I think we can explain it with a example:

===================================================================
You are going home after work.


When you arrive at home, a guy is in your house door, just "blocking" it.
Your door is not broken.
Should be this guy arrested? Is that correct?  I think not.


Instead that, you should think what you did to motivate this guy to block your house door.


You just may use other door or push him out of your door (this is just, reboot a service) and you will be able to use your house normally.
===================================================================

After the example, all of we may agree, DoS should not be considered illegal, because is not damaging anything, right?

"We are legion"
Next Post: "What the hell is Nessus? Fast overview"

Monday, September 12, 2011

"URGE" (Universal Rapid Gamma Emitter) Hijacking Twitter

(Spanish follows | Después en Español)

Today we will talk about the new tool called URGE. This is a tool to auto-tweet, just that.

Are you tired of trending topics from twitter never reflect our interests?
Are you tired of those trendings like "sex" or other non-actual topics?
Are you tired of twitter never reflects our world news or problems?




URGE is here to solve it, now you can tweet your news many times without the need of continous copy&paste&tweet.

This a hijacking tool:
 - NOT hacking, URGE is not exploiting any security hole.
 - NOT DoSing, it is not blocking twitter access.
 - NOT DDoSing, it is not coordinating a DoS.

Let's free the twitter trending topics!

"We are legion"
Next Post: "Differences between DDoSing/DoSing and hacking"

=================================================================

Hoy hablaremos sobre la nueva herramienta llamada URGE. Esta herramienta sirve para twitear automaticamente, solo eso.


Cansado de que los trending topics de twitter nunca reflejen tus intereses?
Cansado de esos trendings como "sexo" o otros desactualizados?
Cansado de que twitter nunca refleje los problemas y noticias mundiales?





URGE ha llegado para solucionarlo, ahora puedes twitear y retwitear tus noticias y novedades muchas veces sin la necesidad de copiar, pegar y twitear.

Esta es una herramienta de hijacking:
 - NO es hacking, URGE no está atancando a los sistemas de twitter.
 - NO es DoSing, no está bloqueando ni colapsando el sistema de twitter.
 - NO es DDoSing, no está coodinando ninguna ataque DoS.

Liberemos los trending topics de twitter!

"Somos legión"

Siguiente Post: "Differences between DDoSing/DoSing and hacking"



Friday, September 9, 2011

RefRef - Creating a huge army

(Spanish follows)

LOIC was retired due to most of the hacktivists who were arrested last year used this software.
Their connection data was tracked by police and they were finally arrested.
They should used several hidding methods like VPNs, proxies, connetion through cyber-cafe...

RefRef is the brand new weapon which is being tested from a few time ago. RefRef is called to replace LOIC (Low Orbit Ion Cannon) and upgrade its capabilities.

The weapon will be available for download from this month. First news about the tests reveals that RefRef have a lot of power :)

This new weapon offers new possibilities, due to it's based on JavaScript, this means that can be used from most platforms like computers, laptops, tablets, smartphones...
And maintains older ones like the possibility of creating "zombies", that is, to build up a bot-net and launch a huge attack at the same time.

RefRef has a new one advantage that turns it more powerful than LOIC, RefRef is able to perform SQL-i to create a devastating effect combined to the attack behavior from LOIC.


What is SQL-i?

Have you ever seen a web URL like this?

        www.myownweb.com/post?user=JohnDoh

Just try to change the parameter "user" to access to another data, something like:

        www.myownweb.com/post?user=MikeH

Yeah! You have completed your first SQL-i attack! :)
Of course, this is not representative for the RefRef behavior but this is the essence :)

Do you remember when people talk about "Web 2.0"?
I think "DDoS 2.0" is comming.


"We are legion"

PS: www.myownweb.com is just an example. Do not try to SQL-i attack this URL
Next Post: "URGE (Universal Rapid Gamma Emitter) Hijacking Twitter"
---------------------------------------------------------
Next topics:
- "URGE (Universal Rapid Gamma Emitter) Hijacking Twitter"
- "Operation Icarus"
- "Differences between DDoSing/DoSing and hacking"
- "Can we effectively hide our data connection?"
- "What the hell is Nessus?"


======================================================================
                      Spanish / Español:

LOIC ha sido retirado debido a que la mayor parte de los hacktivistas arrestados el año pasado habían utilizado esta aplicacion.
Los datos de su conexión fueron rastreados por la policia y fueron finalmente arrestados.
Deberían haber utilizado de forma combinada diversos metodos de ocultación de sus datos como VPNs, proxy y/o conexiones desde luegares publicos.


RefRef es la novedosa arma que está siendo probada desde hace algun tiempo. RefRef es el reemplazo de LOIC y mejorará sus capacidades.

Esta arma estara disponible para su descarga durante este mes. Las primeras noticias confirman  que es muy poderoso :)

Esta nueva arma ofrece nuevas posiblidades, debido a que esta basada en JS, esto implica que puede ser ejecutado desde diversas plataformas como ordenadores de sobremesa, portatiles, tables o telefonos de ultima generación.
Además mantiene las ventajas de LOIC como la posiblidad de crear PC zombis, esto es, crear una red de bots para preparar un ataque a gran escala.

RefRef tiene una novedad que la proporciona una gran ventaja frente a su predecesor, es capaz de atacar con SQL-i, lo que aumenta muchisimo sus capacidades.


¿Que es SQL-i?

¿Alguna vez habeis visto una direccion como esta?

        www.myownweb.com/post?user=JohnDoh

Probad a cambar el parametro "user" para intentar acceder a otros datos, algo así:

        www.myownweb.com/post?user=MikeH

Toma ya! Acabas de realizar tu primer ataque de injección SQL!
Por supuesto, esto no es representativo para RefRef, pero es la idea. :)

Recordais cuando se hablaba de la "Web 2.0"?
Pues os doy la bienvenida a "DDoS 2.0"


"Somos legion"

PD: www.myownweb.com no es más que un ejemplo. 
No intenteis atacar esta dirección, por favor.
Siguiente Post: "URGE (Universal Rapid Gamma Emitter) Hijacking Twitter"
---------------------------------------------------------
Proximos temas:
- "URGE (Universal Rapid Gamma Emitter) Hijacking Twitter"
- "Operación Icaro"
- "Diferencias entre DDoSing/DoSing y hacking"
- "Podemos ocultar de forma eficiente nuestros datos?"
- "Que coño es Nessus?"

Monday, September 5, 2011

Low Orbit Ion Cannon - One of the best weapons


(Spanish follows) (En Español a continuación)
--------------------------------------------------------------------------------------------------------------------------------
This post is dedicated to a great friend and journalist.

Today we will write about LOIC, one of the most used DDoS weapons on the internet.
But we will start from bottom to top.

What the hell is a "DoS"?

It stands for "Denial of Service", that means: it is to perform a huge number of requests to a server, a number enough to don't let the server to attend other request but yours.

A cool example could be a pub

When you go to ask for a pint of beer, the waiter could attend other people, but, if you ask for ten thousand pints of beer the waiter will become very busy to attend other request but yours.

Thus, what the hell is "DDoS"?

This stands for "Distributed Denial of Service", that means: it is to form a team and all of you perform a huge amount of requests, each one of you. This is to say, to perform several simultaneous "DoS" attacks.

I'll try to continue with the example of the pub.

If your friends and you go to a pub and all of you agrees to ask for ten thousand of pints at the same time, the waiter will become very busy, really overloaded.

Moreover, depending on the time you maintain this attack, the result of it may change.

A short time attack could be useful to know how the system can resist a stress load.
But, if the DoS or DDoS is maintained for a long time could cause a full system lock.

On our example in the pub:

If the waiter is working at full of his capacity during many time, he can suffer a heart attack and die.
(I really hope nobody will suffer a heart attack, it is just a example)

Now, we are DoS and DDoS experts :)

What is LOIC (Low Orbit Ion Cannon)?

LOIC is an application designed to perform stress tests on systems but it could be used to lauch a DoS or DDoS attack.
On the last version, it has many plugins that will allow you to perform very advanced attacks.
One of this plugins allows to let the control of your LOIC to another person, your PC becomes a "zombie" controlled by another PC.
If there is a PC controlling one million of zombies ... this is an army!!!

"We are legion"
Next Post: "RefRef - Creating a huge army"

====================================================================

Spanish / Español:

Este post está dedicado a un gran amigo y periodista.


Hoy vamos a escribir sobre LOIC, una de las armas DDoS más utilizadas en internet.
Pero vayamos de abajo a arriba.

¿Qué demonios es "DoS"?

Significa "Denegación de Servicio", esto es: ejecutar una enorme cantidad de peticiones a un servidor, un numero suficiente para no permitir al servidor que atienda ninguna peticion que no sea de las tuyas.

Un ejemplo chulo puede ser un bar

Cuando vas a pedirte una cerveza, el camarero puede ir atentiendo a otras personas, pero si pides diez mil pintas de cerveza el camarero estará un tiempo demasiado ocupado para poner cualquier pinta que no sea una de las tuyas.

Entonces, ¿Que demonios es "DDoS"?

Esto significa "Denegacion de Servicio Distribuido", eso es: que un equipo de atacantes ejecute una enorme cantidad de peticiones al mismo tiempo. es decir, varios DoS simultaneos.

Intentemos conitnuar con el ejemplo del bar.

Si tus amigos y tu vais a un bar y quedais de acuerdo para pedir diez mil pintas cada uno al mismo tiempo, el camarero estará muy ocupado, completamente sobrecargado de trabajo.

Ademas de todo esto, en función del tiempo que se mantenga el attack, el resultado del mismo podria variar mucho.

Un ataque breve puede ser muy util para saber como puede un sistema resistir una carga de estres.
Pero, si el DoS o el DDoS se matiene en un largo periodo de tiempo, es probable que el sistema acabe por caerse o bloquearse.

En nuestro ejemplo del bar:

Si el camarero esta trabajando a pleno rendimiento durante mucho tiempo, podria sufrir un paro cardíaco y morirse.
(Espero encarecidamente que nadie sufra un ataque cardíaco, tan solo es un ejemplo)

Ahora que somos expertos en DoS y DDoS :)

¿Que es LOIC?

LOIC is una aplicación diseñada para ejecutar ataques de estrers en diversos sistemas aunque puede ser facilmente utilizado para llevar a cabo un ataque DoS o DDoS.

En su última versión incluye una gran variedad de plugins que te permiten ejecutar ataques realmente complejos.
Uno de sus ultimos plugins permiten ceder el control de tu maquina a otro operador remoto, de forma que tu PC se convierte en un zombi.
Si hubiese un PC controlando un millón de zombis.... menudo ejercito!!!!.

"Somos legión"

Siguiente Post: "RefRef - Creating a huge army"

Thursday, September 1, 2011

AnonPlus is coming


Today I will think about  Anonymous and issues from last weeks.

Everybody already knows Anonymous and their fights against injustice all over the world.
Anonymous had protested all about other people but must protest about itself too.

Some weeks ago we heard about some news, some news of the Anonymous was banned from different social networks and/or other websites, like facebook or google plus.

I can't get this question out of my mind: "Why?"
- Could it be due to fight against corrupt governments?
- Could it be due to fight against corrupt companies?
- Could it be due to fight against corrupt all-types corrupt media?

I couldn't believe it when I heard that news.

But, I should forward and spread a news that appears just a few weeks ago, a new social network is comming, is being coded just now.
This social network will be absolutely free, the information will can be shared without censorship.

That will be great.

The information gets you powerful, the information gets you free.

At the moment we can access to http://www.anonplus.com


This website is available now with access to the anon-forums and the anon-chat (directly connected to some IRC servers to chat with other anons)

I think the most interesting zones in this web are: anonplus social network and other just dedicated to education about anon themes. Those two will let us to be informed people and we know that means: power and free :)

"We are legion"
Next Post: "LOIC - One of the best weapons"


Sunday, August 21, 2011

Enterprise hacking

Today we will think about enterprise hacking.


I really think most of companies had ever paid for hacking another ones.
Even more, there are some companies that have contracted some white-hat hackers to hack it self.

There are a huge amount of histories  about companies hacking other companies, governments hacking governments...

I think many people will recognize the history and the company:

--------------------------------------------------------------------------------------------------------------------------------
Some years ago, there was a company that had a problem, somebody was filtering strategic information out of the company (that was a very famous technological north american company)


The company paid some white-hat hackers to get all the information needed to hack itself, in order to get information needed to discover the "traitor".


They should do all needed in order to get the truth.


Those hacker attacked some personal email accounts, bank accounts, telephonic information... a lots of information to discover who was filtering data out of company.


Finally, the company was able to found the traitor, but he denounced to the company to breaking into his personal data and accounts. 


At the end, the company president and some directives were arrested about piracy issues.
BUT, those authorized hackers were arrested too.
--------------------------------------------------------------------------------------------------------------------------------

This controversial history didn't end with a fair finish, specially for the hackers, who are working as security computer experts.
They are not  breaking into another company to get some advantage from one to another.

We are surrounded of managers who only can think about money and numbers, keep out of them because you could be affected about their decisions.

If you are a computer expert, feel free to learn and improve. Feel free to work as a computer expert.
Most of hackers are cool, they rules!  :)

"We are legion"
Next Post: "AnonPlus is comming"

Sunday, August 14, 2011

How easy is to hack a server? (Part 2 out of 2)


Today we will talk about the second type of hacking.

From my point of view, this is the most powerful hacking type due to directly attacks the weakest point in every system, people.

There lots of ways to perform social attacks, sometimes we will get some information to directly exploit and access the target system, other times we will get some information in order to access other information, and using the second one, get access to the target system.

It depends on the system strength, we will need more or less information to obtain this access.

I will tell a history based on phishing to get access to a enterprise server in a short way:


We will suppose we know that we have access to the company "X", "X" is a big company with lots of manager hierarchies, most of the company employees could use "Linkedin"; scanning the company profiles we can find a guy who is fan of old stamps.


We must think that a big company employee probably access his email at working time.


Now we will build a website that looks serious about old stamps, like an antiquarian shop where buys and sells old stamps. At this website we will place a malicious frame in order to execute a web-client exploit.


Then we will send him an email full of stamp discounts related to a very exclusive stamp collection.
And.... "voilà": full access to the company network from the manager PC.



This is a very simple and short history in order to explain an example about how easy could be to hack an enterprise server.

We can get three steps in social hacking:
1) Get information
2) Preparing our trap
3) Exploit and access


We must know that time spent in the first step will improve our second step effectiveness
We must know that time spent in the second step will improve our third step effectiveness.

Between steps 2 and 3 can take a while, due to the company manager could be on holiday or very busy.

Now we can ask our question: How easy is to hack a enterprise server?

Very much.


"We are legion"
Next Post: "Enterprise Hacking"

Popular Posts