Showing posts with label social. Show all posts
Showing posts with label social. Show all posts

Friday, November 6, 2015

There are tons of websites to find a job, that's the thruth


 

There are tons of websites to find a job, that's the thruth

So? There has been a long time since my last post, I've been starting so many projects including some business and stuff and today I'm back to write about this topic which is not even close about the last posts.

So if you are looking for some networking or computing cheat, that's not your post :)

I'm here to think and write about job hunting websites and all about those things.

There was an age...


There was an age where sites like linkedin and infojobs were cool sites to find a job, but, to be honest the have lost that charming brand new magic and they are just a huge curriculum store.

And now what? what's the trend?

That's the point, there are no reference in this matter, it becomes a problem when you are trying to upload your CV to the Internet because you need to keep up-to-date from three to ten profiles in different websites which are roughly the same thing.

There are no fashion sites, the trend now is that there is no trend; and that's a real problem.


I've no tips about which site is the best, so that's my idea, create your own.
Maybe it looks a bit crazy, but it's just an idea.

My own site? What kind shit is that?

Ha ha! You may be right, it could be crappy if you do by the wrong way and the problem is... that there is no best-way but I think that this may be a good chance to take the attention about a head hunter / human resources crew if you make the difference by sending your CV just all-in-one by sending a URL.


Some examples?

I've no examples but I have some ideas to tell to you:

- Create a easy-quick-free site using services like blogger. This is easy to do and free, the only problem may be the low customization level.
            www.blogger.com

- Contact with cheap webhosting services like 1and1 "my web" or something like this, they are intended for small business but you can try it. They have medium customization level.
           www.1and1.com

- You can try too by contacting the MiniWeb guys, they are a brand new website design&hosting company, they just started a few months ago but they are doing quite well. You can contact them both in English or Spanish, you'll find a very cheap service packs. Can contact by facebook, twitter or send a message from the web form contact.
          www.miniwebspain.tk


We are legion

Saturday, May 12, 2012

Windows 8 bloqueará programas de terceros


Hola a todos,

Hace poco tiempo leiamos en los foros de Mozilla:
"an unwelcome return to the digital dark ages where users and developers didn’t have browser choices."Said by Harvey Anderson, general counsel in Mozilla co.

Refiriendose al problema que significaría el que Microsoft no permita otros exploradores de internet que no sea el de "la casa".

¿Podeis imaginar un futuro sin programas no-microsoft? No podriamos usar Firefox, Chrome, WinZip, WinRar, WinAmp...


Un poco de arte callejero:




Some people could think "who will buy a OS which will not allow me to decide which internet browser I want?"
La gente podria pensar "¿Que va a comprar un Sistema Operativo que no me va a permitir que explorador de Internet quiero usar?"

Habrá quien llegue más alla: "¿Quien coño va a comprar eso?"

Aqui mi propia opinion: "Ni Dios!!!!!!!"

¿Cual creemos que es la explicación para este comportamiento?

Otra facil de responder!  :)
Es el tipo de action emprendida por una compañía que ha perdido el Norte.

Realmente, ¿alguien cree que esto ayudará a la empresa? Lo que pensamos realmente es que esto va a ayudar a la gente  a plantearse si poner un sistema Unix/Linux en su casa. No?

Si eres uno de esos usuarios, te vamos a recomendar Ubuntu e incluso BackTrack (si eres un atrevido, jejeje) 


Despues de esto seguro que esta imagen adquiere significado para ti.


Se que este es un post más corto que los demas, pero estoy convencido de que NECESITABA informar de esto.


Next post: "My preferred linux distros. Wireless auditory" (English)
Siguiente post: "Mis distribuciones favoritas de Linux. Auditoria WiFi" (Español)

Somos legión!!!

Windows 8 will not allow SW non-MS SW

Hello all,

A few days ago we read at the Mozilla forums:
"an unwelcome return to the digital dark ages where users and developers didn’t have browser choices."Said by Harvey Anderson, general counsel in Mozilla co.

Do you have to imagine a future only with MS apps? You won't be able to use Firefox, Chrome, WinZip, WinRar, WinAmp...


Some art in the street:





Some people could think "who will buy a OS which will not allow me to decide which internet browser I want?"

Even: Who the hell is going to buy that?

My own opinion: "Nobody!!!!!!!"


Which could be the explanation for this behavior?

Easy to answer too :) It is the kind of action undertaken by a company that has lost its way.

Really, does anybody think that this action will help them? I really think that this action will definitely push people to try Linux/Unix at home, don't you know?

If you are one of those users, I will recomend you Ubuntu or even BackTrack :)

Thus, this image will take sense, right? :)







I know that is a very short post, but.... I HAVE TO inform of this, I think is absolutely needed.


Next post: "My preferred linux distros. Wireless auditory" (English)
Siguiente post: "Mis distribuciones favoritas de Linux. Auditoria WiFi" (Español)


We are legion

Sunday, April 22, 2012

#OpBlackout, desconectando internet (Spanish)

(Puedes acceder desde aqui a la versión en Ingles de este post | You can read this post in English here)

Hola!

Espero que os haya ido bien desde el último post.

¿Sabeis lo que es la operación #OpBlackout?

En relación con el título del post, esto podría significar "el cierre de la Internet", pero el título no es fiable al 100%.
Vamos paso a paso.

¿Qué es una dirección IP?

De una manera fácil, es la placa de matrícula de tu PC. La única cosa que tienes que saber es que podrias compartir tu matrícula con otros usuarios si estás compartiendo un router (por ejemplo, el router ADSL en casa o en una oficina)

¿Qué es un servidor DNS?

De manera breve, un servidor DNS es un traductor de direcciones en Internet.
Cuando se escribe en el navegador de Internet "www.mipagina.com", el PC no se sabe qué es eso, porque el ordenador sólo entiende las direcciones IP.

Entonces, el DNS le ayudará a su PC durante la traducción:
www.mipagina.com ====> 12.34.56.78




¿Cómo funcionan los servidores DNS?

Hay sólo unos pocos servidores principales de DNS, los servidores DNS están funcionando sólo intercambiando los datos de otros servidorer DNS.
Este es un trabajo distribuido que mejorará la calidad/velocidad de traducción DNS.




Entonces, ¿cómo puede Anonymous apagar el internet?

Anonymous """""solamente?""""" tiene que bloquear o tirar los servidores raíz de DNS y los otros caeran en un efecto dominó.

Haga clic aquí para obtener más información acerca de servidores DNS raíz.

¿Por qué decimos """""solamente?"""""?

Hay muchas razones técnicas que convierte a este ataque en algo muy difícil o incluso imposible.
La razón principal es que estos servidores DNS principales se implementan como clusters a través de unicast pero no vamos a explicar esto porque este blog sólo explica los temas de hacking sencillos y básicos.

Next post: "Windows 8 will not allow SW non-MS SW" (English)
Siguiente post: "Windows 8 bloqueará programas de terceros" (Spanish)

Somos legión

Wednesday, April 18, 2012

Shutting down the Internet #OpBlackout

(Now you can access to the Spanish version of this post | Ya puedes leer la versión en Español de este post)

Hi there,
Hope you are doing well.

Does someone know what is the Operation Blackout?
Referring to the post title, this could mean "shutting down the internet" but the title is not 100% accurate.


We will proceed step by step.


What is a IP address?

In a easy way, is the registration plate of your PC. The only thing you should know is that you will share your registration plate with other users if you are sharing a router (like the ADSL router in your home)


What is a DNS Server?

In a short manner, a DNS Server is a address translator on the Internet.
When you type in your internet browser "www.mywebpage.com", your PC won't know what's that because
your PC only knows about IP addresses.

Then, the DNS will help your PC when translating:
www.mywebpage.com  ====>  12.34.56.78




How DNS Servers work?

There are only a few main dns servers, other DNS servers are working just by getting data from another DNS servers.
This is a distributed work which will improve the DNS translation performance.




Then, how can Anonymous shut down the internet?

Anonymous """""only?""""" need to bring down those root DNS servers and other will bring down in a domino effect.

Click here to get more information about root DNS Servers.

Why we say "only"?

There are many technical reasons that turns this attack very hard or even impossible.
The main reason is that these main DNS servers are implemented as clusters using Unycast but we won't explain this because this blog only explains the easy and basic hacking issues.

Next post: "Windows 8 will not allow SW non-MS SW" (English)
Siguiente post: "Windows 8 bloqueará programas de terceros" (Spanish)

We are legion

Sunday, April 15, 2012

CISPA (La nueva versión de SOPA)


!Hola a todos!

¿Vives en EE.UU.?


Si es así, tengo malas noticias para ti. Durante este mes un nuevo proyecto de ley está siendo preparado y se llamará "CISPA" ( Cyber Intelligence Sharing and Protection Act )

Puede obtener información oficial sobre la HR3523 aquí. También conocida como el proyecto de ley de Rogers-Ruppersberger.
Estoy muy preocupado por este nuevo proyecto de ley y espero que no seconvierta en ley en los EE.UU.

Mucha gente está escribiendo información acerca de este nuevo proyecto de ley lo que hasta donde yo sé, significará el regreso de SOPA, PIPA y ACTA juntas. Este proyecto de ley se quiere mostrar "distinto a SOPA", pero tiene un montón de temas similares. Por cierto, este nuevo look del proyecto SOPA+ACTA+PIPA ya ha recogido muchos seguidores entre ellos uno muy famoso, Facebook, que es el principal apoyo.

Hay muchos puntos de este proyecto de ley donde no es muy clara, pero explica que los ISPs serán capaces de interceptar comunicaciones privadas para enviar a la NSA (National Security Agency) y DOD's Cibercommand. .

La parte más peligrosa de este proyecto de ley es que algunas empresas serían capaces de espiar y controlar las conexiones de los usuarios sin necesidad de notificar esa actividad a que el usuario o el Gobierno. Por lo tanto, mucha gente piensa que este proyecto de ley se convertiría en una ley que permite el espionaje industrial.

Empresas como AT & T, IBM, Oracle, Symantec, Microsoft, EMC ... apoyarán CISPAdebido a que sus responsabilidades se reducirán en caso de problemas con la ley.

Incluso las empresas como Google o Facebook podían interceptar correos electrónicos y compartir entre ellos y el gobierno.

¿Quieres investigar más a fondo? Sigue este enlace

 

Realmente, esta es una mala ley, como SOPA y CISPA o, peor aún, y parece que va a pasar sin que la gente hable.

Si no estás en EE.UU. debes estar muy preocupado (como yo) porque la mayor parte de las leyes de EE.UU. se acaban "exportando" a otros países como España, Reino Unido, Alemania, Francia ...

Somos legión.


Siguiente Post"#OpBlackout, shutting down the internet" (Ingles)
Siguiente Post"#OpBlackout, desconecando internet" (Español)

Friday, April 13, 2012

CISPA (the new version of SOPA)

(Now you can read this post in Spanish | Ahora puedes acceder a la versión en Español de este post)

Hi all!

Are you living at the US?

If so, I have bad news for you. During this month a new bill is being prepared and it will be called "CISPA" (Cyber Intelligence Sharing and Protection Act)

You can get some official information about the HR3523 here. Also known as the Rogers-Ruppersberger bill.
We 're very worried about this new bill and hope it won't become a law in the US.



Many people are writting information about this new bill what as far as I know, it will mean the return of SOPA, PIPA and ACTA together. This bill is being showed "not like SOPA" but has lots of similar topics. By the way, this new look of SOPA+PIPA+ACTA bill has already collected many supporters including a very famous one, Facebook is the main supporter.

There are many points were this bill is not very clear, but it explains that ISPs will be able to intercept private comunications and to send it to the NSA (National Security Agency) and the DOD's Cibercommand.

The most dangerous part of this bill is that some companies would be able to spy and monitor de user connections without the needing of notify this activity to the user or the Government. Thus, many people thinks that this bill would become in a law that allows industrial espionage.

Companies like AT&T, IBM, Oracle, Symantec, Microsoft, EMC... will support CISPA because their responsabilities will be reduced in case of legal issues

Even companies as Google or Facebook would intercept emails and share it between them and the government.

Do you want to investigate further? Follow this link



Really, this is a bad bill like SOPA and CISPA or even worse and it looks like it's going to pass unless people speak up.


If you are not at the US you should be worried too (as me) because most of US bill are often "exported" to other countries like Spain, UK, Germany, France...

We are legion





Tuesday, April 10, 2012

Piratear la tarjeta de crédito de tu Xbox360

(Esta es la versión en Español de un post anterior en ingles | Now you can access to the English version of this post)

Hola a todos,

¿Has vendido tu antigua Xbox 360?

Si no golpeaste el disco con un martillo tengo malas noticias para ti.
Algunas investigaciones sobre la seguridad de los datos de Xbox 360 en la Universidad Drexel encontraron problemas de seguridad sobre el almacenamiento de datos de las tarjetas de crédito.

Incluso un "resetde fábrica" no sería suficiente para eliminar por completo los datos de la tarjeta de crédito. Habría que ser más exhaustivos con el fin derealizar un borrado completo.


¿Qué pasa con otros productos de Microsoft?

Este problema se reproduce en otros sistemas de Microsoft, como Windows.
Cuando se está formateando el disco duro en un sistema Windows, serás avisado de la eliminación de datos, pero, ¿eso es cierto?

La respuesta es "NO", durante el "formateo del disco" MS Windows sólo ajusta los datos como "no usado", pero la información permanece en el disco. Esta es la forma de trabajo en que algunas herramientas de recuperación de datos, estas herramientas leeran el disco completo, incluyendo los sectores marcados como no utilizados.


¿No vendiste tu Xbox y que quieres borrar sus datos?

En primer lugar debes quitar el disco de la Xbox 360, entonces, yo recomendaría algunas utilidades de disco como "Hiren Boot", "QMagic", "Partition Magic" .... todos ellos llevarán a cabo un formateo de bajo nivel de disco y esto implica el borrado completo.

Ahora ya se puede vender la Xbox  :)




¿Hay noticias relacionadas de Microsoft?

Hay algunas noticias sobre este tema, pero no está muy claro. Alguien dijo que MS está investigando el tema, pero no hay información oficial todavía.


Somos legión.



Siguiente post "CISPA (the new version of SOPA)" (Inglés)
Siguiente post "CISPA (La nueva versión de SOPA)" (Español)




PD: Este post llevó más tiempo debido a las vacaciones de Semana Santa en España

Monday, April 9, 2012

Hacking XBox360 card credit data

(Now you can access to the Spanish version of this post | Ahora puedes leer este post en Español)

Hi all,

Did you sold your old Xbox 360?

If you didn't hit the disc with a hammer, I've bad news for you.
Some investigations about Xbox 360 data security at Drexel University found security issues about the storage of credit card data.

Even a "full factory reset" will not be enough to completely delete your credit card data. You'll need to be more exhaustive in order to perform a full deletion.


What about other MS products?

This issue is reproduced in other Microsoft systems, like Windows.
When you're formatting your hard disk on a windows system, you will be noticed about the data deletion, but, that's true?

The answer is "NO",  during the "disk formatting" MS Windows is just setting the data as "unused" but the information remains in the disk. This is the way that some data recovery tools work, these tools will read the full disk including sectors labeled as unused.


Don't you sold your Xbox yet and you wanna erase your data?

First you should remove the disk from the Xbox360, then, I would recommend you some disk utilities like "Hiren's Boot", "Q Manager", "Partition disk manager".... all of them will perform a low level disk formatting and this implies low level disk erasing.

Now, you can sell it :)




Are there news related from Microsoft?

There are some news about this issue, but it's not very clear. Someone said that MS is investigating the issue but there are no official information yet.

We are legion.

Next post "CISPA (the new version of SOPA)" (English)
Next post "CISPA (La nueva versión de SOPA)" (Spanish)


P.S: This post took longer because the Semana Santa holidays in Spain :)





Saturday, March 24, 2012

PayPal is vulnerable, XSS (Spanish)

(Esta es la versión en Español de un post previo en ingles | This is the previous version of a post in English)

Hoy estamos aqui con el siguiente post sobre un tipo de haking.


Hace unos meses (sober Diciembre de 2011) dos hackers de India fueron capaces de ejecutar un ataque utiliando la URL del website de PayPal.
Eso no significa ni de lejos que hayan conseguido asaltar los servidores de esta empresa, no es esa la idea. Pero ellos podrian haber ejecutado algun tipo de ataque "Man in The Middle/Hombre en Medio" (MITM)




¿Porque y/o para que querria alguien ejecutar un ataque MITM?

Este es el punto más simple del post: para robar información sensible como pueden ser usuarios y contraseñas e incluso cuentas bancarias.








¿Que es un ataque MITM?


Vamos a suponer: Quiero ejecutar un ataque MITM entre un servidor de Google y el PC de un amigo.
Inicialmente necesetariamos algun programa o herramienta para "engañar" al PC de tu amigo (p.ej: Metasploit).
Cuando el acceda a www.google.com, realmente no estará accediendo a Google, el accederá a mi PC que estará camuflado como tal servidor mientras yo estoy conectado realmente al servidor de Google.

En la imagen superior, "Web Server" podria ser Google de nuestro ejemplo y "Victim" sería el PC de nuestro amigo.

En la imagen de la izquierda, la victima es "authorized user". El atacante dice al punto de acceso (AP) que él es la victima (el usuario autentico) y el atancante también le dice al usuario que él es el AP.

Te este modo, el atacante estará literalmente en el medio de la comunicación de datos.
Entonces, el usuario autentico pensará que está conectado directamente a la red corporativa pero el atacante estará revisando e incluso almacenando toda la información que transmita.



Entonces ¿Que es XSS?

XSS es un tipo de vulnerabilidad directamente relacionada con paginas y aplicaciones web que permiten al atacante introducir y obtener datos saltandose cualquier validación por parte del servidor.
De este tipo de vulnerabilidad pueden darse varios casos y tipos, veremos lo más sencillo.

A modo de resumen (si eres un hacker o experto en seguridad probablemente estas afirmaciones te producirán ardor de estomago, este blog siempre piensa en explicaciones sencillas para gente que no es experta)

- Si el hacker engaña al usuario remoto y usa sus datos para entrar en el servidor, es un ataque XSS no persistente.
- Si el hacker engaña al servidor y utiliza sus datos para conectarse con el cliente y obtener sus datos, es un ataque XSS persistente.

Para hacerse una idea del segundo tipo, una explicación gráfica:

Si ya quieres meterme más en el tema sobre XSS te remito aqui.
------------------------


Somos legión.
Siguiente post: "HOIC: new improved version of LOIC"

Friday, March 23, 2012

Google Hacking, cuidado con tu sitio web!!! (Spanish)

(Esta es una versión traducida de un post anterior en Ingles - This is the Spanish version from a previous one in English)

¡Hola!
Hace mucho tiempo del último post, he estado muy ocupado los últimos meses.
Estamos de vuelta otra vez a hablar de un estilo antiguo clásico de hacking: "Google Hacking".

Esta forma es muy simple ya que no requiere ninguna herramienta avanzada o software, se puede hacer simplemente con una conexión de módem de 56k a Internet (Aunque realmente espero que tu conexión es un poco más rápida!!)

Todos nosotros sabemos de los algoritmos de búsqueda avanzados y recolección de datos de gran potencia de Google, creo que Google es el buscador más avanzado tecnológicamente en el mundo en este momento (en los últimos 5 - 10 años).

Google es mucho más que un cuadro de texto y un botón de "Buscar", e incluso mucho más que un "voy a tener suerte" :)

Debemos saber que Google tiene capacidad de recoger datos de archivos que no sean clásicos de las páginas web html, cada día Google está detectando una gran cantidad de archivos pdf, doc, ... .

Google tiene muchas opciones y filtros de búsqueda avanzada, como la búsqueda por tipo de archivo, por parte de texto en una dirección web (url), por la extensión de archivo ...

Este mecanismo es simple como:

- Búsqueda de doc. Watson informa de un servidor
- Buscando información importante de los datos personales
- Búsqueda de archivos con cuentas de usuario
- Búsqueda de archivos con usuarios y contraseñas!!

Sí, por supuesto, toda esta información está ahí, tenemos libre acceso, a muchos archivos sólo a través de Google.

Puede acceder a la ayuda de Google con el fin de aprender "comandos" para llevar a cabo algunas búsquedas avanzadas.

Recientemente, este tipo de piratería informática fácil y simple fue utilizado contra muchos organismos de seguridad importantes de los EE.UU. y Europa Occidental.

Este método puede ser considerado "Ingeniería Social"

----------------------------------------------------------------------------------------------

Somos legión.
Siguiente post:
"Reaver (WPS attack) and WPAMagicKey tools"

Wednesday, March 14, 2012

Google Hacking, be careful with your web site!

(Now you can access to the Spanish version of this post | Puede acceder a la versión en Español de este post)

Hi there!
Long time ago from last post, I was very busy last months.
We're back again to talk about a old-classic way of hacking: "Google hacking".
This hacking is very simple a it doesn't require any advanced tool or software, it can be done just by using a 56k modem connection to the internet  (I really hope your connection is a bit faster than this  :D   )
All of us know about the advanced search algorithms and powerful data pickup of Google, I think Google is the most technologically advanced search engine in the world right now (in the last 5 - 10 years).
Google is much than a text box and a "Search" button; even much higher than a "I'm feeling lucky" button  :)
We should know Google has able to pickup data from other files than classic html web pages, every day Google is detecting a huge amount of pdf, doc,... files. Google has many filter and advanced search options, like search by filetype, by some text in a web address (url), by file extension...
This mechanism is simple as:
- Searching Doc. Watson logs from a machine
- Searching important information about personal data
- Searching files with users accounts
- Searching files with user and passwords!!!!
Yeah, absolutely, all of this info is there, we have free access at many files just using Google.
You can access to google help in order to learn about Google "commands" to perform some advanced searches.
Recently, this easy simple hacking type was used against many important security organisms from the U.S. and West-Europe.

This method can be considered "Social Engineering"

We are legion.
Next post: "Reaver and WPS attack"

Monday, September 12, 2011

"URGE" (Universal Rapid Gamma Emitter) Hijacking Twitter

(Spanish follows | Después en Español)

Today we will talk about the new tool called URGE. This is a tool to auto-tweet, just that.

Are you tired of trending topics from twitter never reflect our interests?
Are you tired of those trendings like "sex" or other non-actual topics?
Are you tired of twitter never reflects our world news or problems?




URGE is here to solve it, now you can tweet your news many times without the need of continous copy&paste&tweet.

This a hijacking tool:
 - NOT hacking, URGE is not exploiting any security hole.
 - NOT DoSing, it is not blocking twitter access.
 - NOT DDoSing, it is not coordinating a DoS.

Let's free the twitter trending topics!

"We are legion"
Next Post: "Differences between DDoSing/DoSing and hacking"

=================================================================

Hoy hablaremos sobre la nueva herramienta llamada URGE. Esta herramienta sirve para twitear automaticamente, solo eso.


Cansado de que los trending topics de twitter nunca reflejen tus intereses?
Cansado de esos trendings como "sexo" o otros desactualizados?
Cansado de que twitter nunca refleje los problemas y noticias mundiales?





URGE ha llegado para solucionarlo, ahora puedes twitear y retwitear tus noticias y novedades muchas veces sin la necesidad de copiar, pegar y twitear.

Esta es una herramienta de hijacking:
 - NO es hacking, URGE no está atancando a los sistemas de twitter.
 - NO es DoSing, no está bloqueando ni colapsando el sistema de twitter.
 - NO es DDoSing, no está coodinando ninguna ataque DoS.

Liberemos los trending topics de twitter!

"Somos legión"

Siguiente Post: "Differences between DDoSing/DoSing and hacking"



Sunday, August 21, 2011

Enterprise hacking

Today we will think about enterprise hacking.


I really think most of companies had ever paid for hacking another ones.
Even more, there are some companies that have contracted some white-hat hackers to hack it self.

There are a huge amount of histories  about companies hacking other companies, governments hacking governments...

I think many people will recognize the history and the company:

--------------------------------------------------------------------------------------------------------------------------------
Some years ago, there was a company that had a problem, somebody was filtering strategic information out of the company (that was a very famous technological north american company)


The company paid some white-hat hackers to get all the information needed to hack itself, in order to get information needed to discover the "traitor".


They should do all needed in order to get the truth.


Those hacker attacked some personal email accounts, bank accounts, telephonic information... a lots of information to discover who was filtering data out of company.


Finally, the company was able to found the traitor, but he denounced to the company to breaking into his personal data and accounts. 


At the end, the company president and some directives were arrested about piracy issues.
BUT, those authorized hackers were arrested too.
--------------------------------------------------------------------------------------------------------------------------------

This controversial history didn't end with a fair finish, specially for the hackers, who are working as security computer experts.
They are not  breaking into another company to get some advantage from one to another.

We are surrounded of managers who only can think about money and numbers, keep out of them because you could be affected about their decisions.

If you are a computer expert, feel free to learn and improve. Feel free to work as a computer expert.
Most of hackers are cool, they rules!  :)

"We are legion"
Next Post: "AnonPlus is comming"

Thursday, August 4, 2011

The weakest node in a system

Today we have lots of security mechanisms which provides us a big computer security.

https, ssl, tls, dnssec, vpn, ipsec, firewall, antivirus... there are enormous amounts of security protocols thought to keep secured our systems.

Then, why we are experiencing a wave of computer attacks?

Because, most of hackers discovered the weakest point in all systems:
Humans.

Nowadays, we are the weakest point of whichever network or system.

If a security hole was found at a OS, just in a while, we got a patch to the system.

If a person has a poor knowledge about computer security, he/she is the biggest security hole in the system.

This person must assist to security courses, have to learn a lot about security; that's expensive and slow.

Due to that, now we have words like pishing, trojan horses, malware... all of them attacks the weakest point, humans.

There are enormous amounts of information about everybody in the internet, forums, chats, social webs (like facebook)...

This information is used to "exploit" us and get the chance to attack.

Are the hackers breaking into our systems?

Are we letting them to access in a very easy way?



What do you think about? Keep your eyes open!


"We are legion"
Next Post: "How easy is to hack a server part 1"

Popular Posts