Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Saturday, April 16, 2016

Yahoo steps against Hackers

Yahoo steps in to try and stop foreign Hackers


Yahoo stepsYahoo steps in to warn its users against foreign hackers; Yahoo has become another big tech company which has decided to warn its users if their account is or has been a target of foreign hacker. Google started giving out such warnings in 2012 followed by Facebook and Twitter.
Yahoo said in its statement that it will send users notifications if, “We strongly suspect that you may have been a target of an attack, and want to encourage you to take steps to secure your online presence.”

Hackers from countries such as China and Russia can not crack corporate or government agency networks often go for employees’ or relatives’ personal accounts which they can use to send email with malware to the real target. Several studies have shown a very bright chance that same password is being used by most of the people across all social and work networks and log on to work network from home are easy targets for the hackers.
The incidents like Sony Pictures Entertainment and the Office of Personnel Management are part of such attacks by the hackers from North Korea and China.

 

[caption id="attachment_2645" align="alignleft" width="150"]Tom Kellermann on Yahoo steps Tom Kellermann[/caption]

Tom Kellermann, chief cyber security officer at the Tokyo-based security company Trend Micro said that the hackers are not looking for the Christmas photos from the accounts but are targeting people to fulfill specific objectives such as gaining access to Government or Corporate network.
Kellerman said,” If you are a Fortune 1,000 corporate official, C-level, or a senior executive in the U.S. government, or you are within one degree of separation from them — as in, you are a spouse of them, a child of them or a deputy of them — you will and have been targeted already.”
Al Pascual, director of fraud and security at Javelin Strategy & Research said that,” Consumers in general are not at risk.
You have to be in a specific role for something like this to be likely to occur to you.”
According to him, the industries which are vulnerable to such attacks include financial services, critical infrastructure, defense and politics.
If you get such notification from any social network or email service provider, the first thing to do is to notify your employer.

This denial of the risks, leaves everyone vulnerable to hackers attack, and yahoo will remain to be an amazing target for hackers all across the world, untill yahoo steps up their game and admits to some security flaws

 

Yahoo steps against hackers

 

 

If you wish to protect yourself, from keyloggers, spyware, virus and other malicious software that may steal your private information you can try to get this app:Protect Yourself with Norton Security

 

Another good choice (less expensive)would be this one: Detect Threats with PCKeeper AntiVirus

Monday, April 4, 2016

Tails - Get your privacy back

Tails, because there is never too much security!tailslinux


Almost all O.S. (Operating systems) like Windows, Mac, Ios, Ubuntu, Android, etc will track you and send your details to other persons.

This means that for you to become secure, first and foremost you will need to increase your privacy.

On this post I will guide you step by step on how to achieve this.
Following this steps, In the end you will get a fully working O.S. running on your computer from a pen drive!

The system that I will recommend you to use is named Tails, it is a Unix based system, specially design to keep your online activity anonymous.

You are going to need a Internet connection to download the ISO and a Pen drive (4gb is enough for what you will need)

Lets start with the instructions

Step by step guide to create a bootable Pen disk with Tails the anonymous system


Tails USB

Thursday, March 24, 2016

Three Syrian Electronic Army Suspects Got Charged by the US

After the attack to independent.co.uk the US Justice managed to find the Hackers responsible for these attacks and charged them for multiple offences. The only small problem is that they live in Syria, so a little bit away from US justice so for the time being they are quite safe.

most-wanted-syrian-electronic-army

First seen in 2011, the Syrian Electronic Army (SEA) claims to support the regime of Syrian President Bashar al-Assad. They've been linked to hacking the Websites of the US Marine Corps, Microsoft, Skype, eBay and PayPal. Arrest warrants have been issued for the suspects:

Friday, March 18, 2016

detecting the operation system from any person

On this post I will give you a small tutorial, on how to detect what OS any person is using, and how to protect against such a detection.


This detection can be used by malicious hackers to use the correct applications, to hack into the targets.

Everyone should at least know the basics to be able to prevent the attack and keep their system a bit more secure.

There are not many prerequisites to be able to do this. But the basics are:

Having a *nix system

Connecting to the Internet

Downloading the Xprobe applications

First let me talk about the Xprobe application.

 

Xprobe is a simple tool to perform a fingerprint of a remote server.

The Xprobe application is used to identify the possible operating system (OS) of the target.

An attacker uses this information to launch appropriate attacks for the results obtained.

This is the download link : https://sourceforge.net/projects/xprobe/

detecting the operation system with xprobe2

Tuesday, March 8, 2016

BIN list and why you need one!


Viewers be advised! This is a basic tutorial, and just for educational purposes I would never ever really suggest that someone would use this knowledge. And all of those who do use them will rot in jail for a long long time.


Iam not going to give you the very basics, like were to get this stuff, there are already a lot of blog posts suggesting some markets and autoshops. How to burn a plastic CC will be another topic, on this one I will talk about BIN's


What is a binlist? Why do I need one?



visadiscovermaestroamex



To answer this question you should know that a BIN or IIN , both of these are acronyms for Bank Identification number or Issuer Identification number. The BIN or IIN Is the first 6 digits on a credit card that determines the bank and level of the card, a BIN List is a list of BINs that you know will be aproved for your region, having a BIN list is the difference between guessing for approve and hoping to eliminating the guess and knowing it will work


Ok now that you know what a BIN and BIN list is exactly, how do you get one?


Here is the tricky part! As always you need money to make money. As such the first round of dumps you invest on should be a learning experience.


You should get a mixpack all from different BINs and test them out one by one to see which ones work in your area.


Now you are thinking “How tha Hell can I test these cards since I dont know my bins and its a guessing game whether its a decline or not” even worse what happens if it shows Hold call or Stolen??!!, Dont worry! I will tell you all about it :) (But just for you to know how the evil persons do it! You should never ever do this).


What to do in order to test your card I will suggest


1. Go to one of those movie ticket vending machines where you can pay with CC,


2. Going to ANY self slide checkout, some areas have more than others


3. Coca Cola or vending machines that take CC


4. and nowadays even Cigarette machines accept credit card, so you can use them at will


Along the way you always need to be taking notes. Write down 1 by 1 which BIN actually work and which ones are “dead” or declined. That is how you can get a Bin List.


I went back to basics with this article. Was getting a little bored of writing about MS Windows on how to open an email account :)


Hope you like this Article and keep reading for some more real tips.

Saturday, March 5, 2016

DoS and DDoS attacks - Basics


DoS and DDoS attacks - Basic notionsDDoS


DoS or (Denial of services) attacks are a way to exploit a user resources in a way the “services ” become unavaliable.

While DDoS stands for (Distributed Denial of Service) attacks. Are the same as DoS except that they use hundreds, or even thousands of machines to flood the services and cause the malfunction.

Usually this is performed by flooding the service with ICMP packets forcing a server to respond to the request by the attackers (this is achieved by the need to reply to the ICMP packet). Other attacks including sending malformed ICMP packets, flooding the site with resource requests, or SYN flood attacks.


Despite the ICMP traffic uses the TCP protocol, this kind of attack will not work on a Tor network. There are hundreds of reasons for .onion websites and markets to become unavailable, but rest assure a ICMP attack is not one of them.


But when this kind of attack is targeted at the Clearnet for example against www.facebook.com. Over and over again they keep being successful.


Or another method of achieving the same result- Ping of death attack (catchy name right!)ping-of-death


This attack is accomplished in two different ways, the first method is quite obvious, just send too many packages to flood the system. A system using Windows as the absolute packet size limit of 64K (65535 bytes).


This means that if you are able to send packets larger then the 64k limit, it will either completely crash down the system, or it will enable the attacker to successfully perform a privilege escalation attack. Flooding the site with requests for resources (videos, pictures, login requests, etc.)


To prevent this attacks you need to focus more on the hardware control then the implementations with the site itself. If you are hosting and managing both, the server and the website, you should try to enable ingress filtering over your network, to stop some of the attacks on the spot. If you use the backscatter traceback method  you will be able to do just that.


Also take care to block the ICMP packets looking for your external interface (the WAN). Take special attention to block all the "unallocated source address'".


Following these steps you will not stop a DDoS, but you certainly will weaken the effect.




Tools for DDos and DoS attacks


Microsoft PIN revolution the new “advance”

Hello, if you recently upgraded for Windows 10. You may have noticed this notification: pin notification
“Using a PN is faster and more secure than a password – we think you'll love it.”

This got me thinking, how can a 4 digits PIN code ever be safer then a long password with all the rules they require nowadays. 8 characters or more, special symbols, numbers, etc.

I could not figure it out, so I had to do some research on the topic, and this is what I found out in the end.

First and foremost the “PIN” code will not directly increase the security of your computer, but it definitely increases the security of your online account with Microsoft.

How is it possible?

  • The PIN is only used to log in a particular computer, but does not guarantee access to the all the accounts that the owner may have used on that computer before.



  • The idea seems to be: In case shit happens and someone manage to enter this PC he will only have access to this single computer, but will leave the rest of the network safe.


Thursday, March 3, 2016

Silk Road is dead. What next?

On this article I will talk about Silk Road from the beginning to the end, and I will talk about what's coming now that Silk Road is dead.

1- What Silk Road was
2- What happened to Silk Roadsilk road logo
3- Consequences
4- Whats happening now

1- Silk Road was a dark net Market best know for selling all kinds of drugs Worldwide.
Silk Road was launched on February of 2011 and operated under the Tor network.
The original onion address was http://silkroadvb5piz3r.onion untill it got seized by the FBI back in 2013

Silk_Road_Seized

 

2- What happened to Silk Road was that it got really big, the media started to be all over it and it got the attention of the US government.
After grabbing the atenttion from autoritys, small dealers started to get caught and convicted here and there.
Untill finally the FBI was able to locate the real location of the server, from there they infiltrated deep on the website and eventually were able to arrest the supposed owner/creator/administrator Ross William Ulbricht AKA"Dread Pirate Roberts"ross ulbritch linkedin
3- A consequence of all this, was that the Dark Web gained notoriety, more and more Illegal markets started to emerge. Inclusive soon after the FBI closed the Silk Road Market the Silk Road 2 Market was created by three administrators of the original Silk Road website relaunched it under the name Silk Road 2, this website was operational from Nov 06 2013 untill Nov 06 2014.
Silk Road 3 would follow, but this one was just a rebrand of another Dark Web Market "Diabolus"
4- What we have now is a crazy uprising of new dark web markets. It seems that for each market the authorities take down, 2 more appear to replace them.silk-road-2

 



Saturday, February 27, 2016

Useful information and tips

After some time I decided to give you some more good tips, so here they are:

 

 

USEFUL STUFF YOU SHOULD KNOW


● IF YOU JUST WANT TO BROWSE THE WEB ANONIMOUSLY THEN TOR CAN ACT AS YOUR VPN BUT DO NOT USE THIS FOR ANY OTHER REASON SUCH AS MARKET PLACES, CARDING ETC YOU WILL REALLY REQUIRE A STRONGER SECURITY SUCH AS VYPRVPN AND SOCKS

● I RECOMMEND FIREFOX TO BE YOUR NUMBER ONE CHOICE BROWSER WHEN DOING CARDING OR ANY ILLEGAL ACTIVITY I HAVE NOTICED THIS ONE TO BE THE EASIEST TO CLEAN (WITH CCLEANER)

GOOGLE CHROME STILL HAS COOKIES EVEN THOUGH YOU HAVE RAN IT THROUGH CCLEANER (MANUAL CLEAN IS REQUIRED) I DO NOT RECOMMEND CHROME ANYWAY

VIP72 HAS SOCKS THAT COME AND GO OFFLINE FOR EXAMPLE DAYTIME IN THE UK THERE ARE LOADS OF UK SOCKS.

BUT AT NIGHT THEY DROP BY A LOT SO ALWAYS TRY TO HIT THE COUNTRY YOU NEED IN THERE “DAYTIME” HOURS

PAYPAL’S SECURITY CAN SEE THE FOLLOWING
IP - TIME ZONE - KEYBOARD LANGUAGE - HDD SERIAL - PC ACCOUNT NAME

 

VyprVPNYearlyProSpecial_468x60_EN

 

Thursday, February 25, 2016

Dedicated to the script kiddies out there!

 

I want to dedicate a video to the script kiddies out there, on the dark and the public web alike.
On this video we can see a scene from Jurassic Park in which dr. Ian Malcom gives a speech to mr. Hammond explaining what is wrong in using the technology to create Jurassic Park.

First the video, then I explain why.


https://www.youtube.com/watch?v=4PLvdmifDSk

Wednesday, February 24, 2016

Hansa Market on the deep/dark web

'Login __ HANSA Market' - hansamkt2rr6nfg3_onion_loginHello, in this post Iam going to tell you about one of my favorite markets on the deep/dark web.
The Hansa Market.
Here is the onion link: http://hansamkt2rr6nfg3.onion/

First I will start with the basics, what is a dark web market?
Basically a dark web market is a webpage located on the Tor network, using a .onion domain.
You can only access it using the Tor network. And on this "market" users can sell goods and services to eachother under a big level of anonymity.

Sunday, February 21, 2016

Hacker how to define it

In this post, I categorize hackers into three groups that reflect different levels of experience and capabilities.

My objective is not to propagate any stereotypes but merely to create a framework so that we can talk about the other side and their skill levels. This information is provided to facilitate an
understanding of the different types of people who are commonly called hackers.
Security professionals have started using the term cracker to refer to malicious computer hackers.hackers

Unfortunately, the media and general population have given the term hacker a negative connotation, so we use it to describe any person who attempts to access a system through unauthorized channels. This chapter also presents a profile of information security professionals and discusses popular hacker and information security myths.

Categorizing hackers by the technology they deal with can be

 

5 Hacker Myths VS the reality

hackers meme

All the perceptions of hackers and their portrayal in movies and entertainment have lead to the development of hacker myths.
These myths involve common misconceptions about hackers and can lead to misconceptions about how to defend against them.
Here we have attempted to identify some of these hacker myths and dispel common misconceptions.

List of the hacker myths Iam going to discuss:

  1. Hackers are a well-organized, malicious group  

  2. If you build it, they will come

  3. It is safe if you hide in the tall grass.

  4. Security through obscurity

  5. All hackers are the same


 



Friday, February 19, 2016

The best hacker in the world

Who is the best hacker in the world?

Earlyer today I found a blog securefreak.wordpress.com that I went to visit.
One of the posts that catched my eye was “Who is the greatest “hacker” in the world?” I went in and found this text:
The Best “Hacker” in the World
Posted on March 18, 2013 by securefreak

Today I was asked by a good friend of mine “Who is the greatest
“hacker” in the world?”. After thinking about it for several hours
I have come to the conclusion that it is impossible to know. I say
this because in my opinion the “greatest hacker” is the one that
has never been caught in whatever his/her endeavors have been.
There are people such as ex-hacker Kim Dotcom for example, who all
though very impressive and I must give credit where it is due, is
very talented, was still caught and did serve time in jail. Maybe
it is just my skewed view of the hacker community but there has to
be another individual who has come away with more information and
damage and has never been caught. Any people reading this post
please feel free to comment and give your opinion on who you
believe is the “greatest hacker in the world”.

In the text he talks about Kim Dotcom as his favorite/best hacker in the world.
He is a very talented programmer, obviously as great skills, he is the fundator of Megaupload which was a great service for file sharing.