Showing posts with label hacker. Show all posts
Showing posts with label hacker. Show all posts

Friday, June 07, 2013

Don't Panic

Maybe it's because I used to be a professional hacker.
Maybe it's because I understand the truth of data
Actually, it's probably because I'm a paranoid hacker and a anti-government libertarian.

But this is my surprised face that the fedgov has been tracking all phone calls, all facebook/youtube/skype/google/apple interactions, all locations from which you use these services.

If you weren't already operating under this assumption you haven't been paying attention.

But don't worry, here's a few reasons why you're not already in jail for thought crimes!


1. Too much raw data

Good news: My suspicions were somewhat confirmed here that they can't process all the data yet. At the moment, they're just storing it. It's just a numerically indexed amorphous blob of data.

Now if you have an indexing point, such as "Dzhokhar Tsarnaev" then, there's TONS of data you can review, and new branches on the connection tree you can investigate off that one leaf of data. But you need a starting point.

Bad news: Computing power is getting to the point where the amount of data is trivial. They're saving it not because they intend to go through all of it, but because they intend to, one day, have the technology to do so automatically.

2. Too many cooks, no one follows the recipes

Good news: If you go to recipe.com and myrecipe.com and search for wild rice gumbo on each, and your friendly neighborhood Big Brother FISA warrants all the information from those websites, there would not be a way to combine that data to output: "Times searched for wild rice gumbo=2" automatically.

Recipe.com and Myrecipe.com store their data differently, so no matter how similar they are, you won't be able to lock the data together like to lego bricks.

However, if they knew they wanted data on your IP address, and you connected to both sites from home using the same IP address, a person, not a computer, but a PERSON could review the data from both web sites, apply brainpower, and say, "It appears this person searched for wild rice gumbo from both sites."

But what if CableCo refreshed your IP address between the time that you went to recipe.com and myrecipe.com? Well then BB would need a FISA warrant for all of CableCo's data, and then a PERSON would have to review that data, and figure out how to connect a subscriber to a certain IP address for a certain block of time.

This problem becomes exponential because the more data you try to connect, the more complexity you add.

Bad news: There are new heuristics engines that can take a pretty solid guess at what things are, and how they might connect. They're not perfect, and a slight imperfection at the second generation means a HUGE imperfection at the twentieth generation, but they're getting better. Or worse, they might get data wrong and implicate or single you out simply due to a mistake.


3. Analog recognition

Good news: If I upload a video to youtube, youtube would love to be able to scan it automatically and return, "This video is about a cat that appears to be playing the keyboard. However, as this is unlikely, the owner is probably controlling the cat's arms. Additionally, the cat seems disinterested." But to a computer, a video is just a bunch of flickering lights. It can tell you technical things about it, the date it was recorded, the size of the file, the metadata, but it can't interpret the flickering lights.

Similarly, a phone call is a series of electronic modulations. Some are static, some are speech, some are background noise, some are all of those things together. Interpreting those warbles into actual speech can be very difficult.

The other difficulty is the sheer size of the data. Because each frame or millisecond of analog data may be important, you can't skip any of it. A high quality recording of me farting into the air intake of your central air system is a huge file. If BB could wave a magic wand and turn that waste of space and processing effort into "ET farts in vent lol" that's much easier to process and store.

Bad news: Speech to text recognition is pretty darn good, and getting better every day. Each time you use google's voice recognition or chat idly with Siri, you make their systems (and therefore, BB's systems) better at turning analog data into text or metadata that they can store and process at a tiny fraction of the computing/storage cost.

Facial recognition is up and coming, but far from where it needs to be. It still relies on old hardware and requires certain conditions. Sounds good right? Well, if you can control the hardware and conditions, like inside an airport terminal, or at the sidewalk outside a government building, they work just fine for exposed faces.


4. The noise to signal ratio

Good news: What percentage of all the data they're gather do you think they're actually interested in? It's nowhere near as high as 0.0001%

The sheer volume of data is gargantuan... no, monumental... no, unfathomable... no, galactic! Yes, the amount of data is GALACTIC. Think of every fart joke on twitter, every racist youtube comment, every "Lol LeIk YoU KaRe aBot Mi tRbL dAy OMGWTFBBQ" post on the faces book, all screaming in your face while you try to find where John Doeson saved a draft email reading, "These reasons and more are why I will strike back against The West for its crimes against my people."

Noise data is being created every day, it's unstoppable. The more of it there is, the harder it is to sift through. No matter the computing power.

A computer that processes all data instantly using unicorns is still limited by the pipes that feed that computer data.

60 million people processing this data day and night would never catch up to real time, so there MUST be limits on what data is deemed important enough to process, therefore, there are places where (barring some true stupidity) your data will be ignored.

Bad news: ... ? I guess if that unicorn computer existed, we could worry about faster pipes, but that just means more noise, faster. It's hard to get around this, even with quantum computing.

As terrible as it sounds, all the useless data on the internet does actually have a use... Be sure to thank a racist youtube commenter.


5. Data packages not partnership

Good news: All accounts I've read have indicated daily full data exports or individual requests. This is likely a function of legal requirements. BB may be able to subpoena X information between Y and Z date, but it cannot enforce a partnership.

Full data exports are giant blobs of data that must be transmitted, entered, and processed before something can be done with them. This means more overhead, and more difficulty. More importantly, this means BB has to conform and contort to work with THE COMPANY'S systems.

That means this data is not optimized, is subject to the company's limitations, and is affected by the company's data storage processes.

Your gmail notes how much free space you have available. What happens if you have 4 GB available, upload a 3.9 GB file of your manifesto (padded with 1080p recordings of bloggers farting into vents), then delete it, and upload a 3.9 GB file of 1080p recordings of paint drying? Does google "delete" the first 3.9 GB file, but secretly stores it forever? Good question.

Blogger keeps a history of posts I've made and drafts I've saved. If I delete a post, might Blogger keep it considering it's so small? Maybe. Multiply that by the tens of millions of users deleting posts every day, and there starts to be a serious cost to Blogger. But lets assume for a moment that they do.

What if I'm actively writing a post, and it's auto saving as I type, and I write "That's why we should kill the president and enforce sharia law" then erase it, and continue normally? Does blogger save all the iterations of my draft posts as they're automatically saved? Pretty unlikely. Maybe just the changes? But that requires more processing power to compare.

What if I delete my blog? Seems pretty likely that blogger might store the whole of my blog for some time in case I change my mind, or if BB requests the information I'm clearly trying to hide. But what if I overwrite ALL my blog posts with random bits of a book I downloaded from Project Gutenberg, THEN delete my blog?

Now you're thinking laterally!

Bad news: The real danger is data partnerships. This would be BB commanding all the company's data, in real time, be forwarded to them, in their own format, for processing. This is 100% connectivity from the company to BB. It eliminates thousands of man-hours, adds an instant update of all changes (ALL not just what the company keeps at the end of the day), and becomes limited only by processing power (which will become unlimited when they figure out that whole unicorn/CPU interface).

Companies may choose to interface in this way, but it's very unlikely. It is also unlikely BB may compel companies to interface in this way. But lots of things that have already happened were unlikely.


6. Your foe is a 20' foot 10,000lb dullard

Good news: At the end of the day, even backed by magical unicorn technology, the Federal Government just sucks at doing everything.

Categorically.

Bad news: There are individuals so zealous for statism and fascism that they work tirelessly to enforce their will upon you simply for their own personal satisfaction. You may be singled out by the dullard, and if he begins the paperwork to swing his fist at you, and you are in the same place long enough for that fist to hit you, it can destroy you.


So what do I do?

Treat all things that happen on networks you don't control as public information. Don't talk about your drug deal/tax evasion/murder over the phone, near your unused phone while under investigation, or with your onStar device tracking your every move and listening for "car accidents" (who owns GM again?).

Don't post things online that you don't want BB to see. (That includes this blog)

Use PGP for all electronic communications.

Obfuscate your meaning in messages.

Don't get on the radar. (I'm not talking about the "I'm a libertarian, Eff the fedgov" radar, I mean the "Plant the bomb on the first and third load bearing support in the parking garage of the federal building at 2am" kind of radar. The fedgov already knows ornery libertarians exist, and they certainly know they don't much care for the fedgov, but that only makes you one out of tens of millions of people.

Make your online persona fit one of BB's molds. Psychological profiles are excellent things to gather, and easy to extrapolate with "close enough" heuristics. Remember how the signal to noise ratio is so high that there must be things BB doesn't both to look at normally? Well there are certain personalities that BB is just not that interested in. Try to become one of those personalities filed under "loud but gutless" or "mostly harmless."

Poke holes in your online persona, and passingly embrace the stereotypes that others want to believe about you. Show that you are philosophically dishonest, and occasionally abandon your morals when convenient (at least, say you do online). "Yeah, I took that government aid, but it's only because it's my money anyways, I paid into the system, and it's not like it's stealing from someone else because it's my money too!" Become someone who doesn't stand out by fitting a stereotype.

Appear to fall into their trap. After the next attack, have a "Come to Obama" moment, where you realize that these "turrists" are "just too dangerous" for us to continue being "free" anymore because "freedom" doesn't mean anything if you're suicide bombed with anthrax ball bearings pressure cooker box cutter TERRORISTS!!!!11 From then on, let your online persona be that of a statist and government apologist.

But don't change too much too fast. A drastic swing in the content of your online postings is more worrisome that you posting, "Someone otta kill dem gubmint offishils!" every day for years.


WARNING: DO NOT DEVIATE


Remember when I was talking about heuristics? Patterns are something computers are GREAT at figuring out and monitoring. A computer system can definitely detect variations in activity, and flag them for review! The sensitivity must be reduced so it doesn't flag every person who buys their Starbucks five minutes later than normal, so if you must change, gradual changes are the key! It would be better to maintain, if you can, what you were doing previously in conjunction with your new activites.

Don't go dark!

Refusing to use all online services and primary phone carriers may be more of a red flag than doing exactly what you're doing right now. Especially when BB thinks he has a bead on you.

Besides, why out the informant when he's more useful to you delivering counter-intelligence? Use these systems knowing they are specifically for BB.

Don't pull the onStar out of your car, wire it for battery power, and leave it in your garage on your special trip.

Don't stop using your debit card, use it to buy your groceries with your rewards card like normal. Then go back in, and buy what you want with cash and no customer card. Yes, the Jack Bauer 5000 license plate tracking system followed you to the store, and yes, Kroger's customer records show you bought X items for Y dollars, and yes, your debit card shows exactly Y dollars at that place in that time window. Do you think they're going to go through the trouble of pulling the security video tapes (if they're not overwritten!) to confirm that this was ALL you bought when they've already got so much data fitting their expectations?

Don't stop texting/calling your comrades! This is a huge indicator of some other form of communication, and will draw further scrutiny into how you might be communicating beyond BB's vision. Maybe a series of passive aggressive texts followed by a long shouting match over the phone, and some final four letter words exchanged via text? The ruse may fall apart when you buy Chinese food with your debit card at the place across the street from his house once a week.

Create digital alibis for your out of character actions. If you're going to meet someone at a book shop you've never been before, do a google search for a book you want, search for nearby bookstores, call the nearby book stores, do a google search for "book store inventory search online", call a couple more, then call your target book store, map directions to the place, text your wife that you're going to get the book and will be back soon, take your phone along, and buy gas on the way, actually buy the book, but not before going for a walk with your friend (with your phone in the car, and his phone at home so you're not on the same tower).

Provide a natural progression for your searches. Think of the murderers who google searched "How to kill someone" then after various searches searched "Where to buy trimetholpoisonate" and out-clicked to chemistrydirect.com. It wouldn't be much better for them to search, out of the blue, "trimetholpoisonate." But maybe if they were searching "My cat is constipated", then "diuretic", then "diuretic for cats", then "where to buy Shitty Kitty Drops", then "Shitty Kitty coupon", then "Shitty Kitty generic brand", then "Shitty Kitty active ingredient", then "trimetholpoisonate for cats", then "Where to buy trimetholpoisonate" and out-clicked to chemistrydirect.com. This stands out a lot less (assuming you actually have a cat... OR searched on google "craigslist free kittens [local city]", posted about your new cat on facebook, and used your debit card to buy cat food and kitty litter once a month)


Practice privacy

Make one or two everyday tasks completely private, just for practice.

Buy and use a prepaid cell phone or credit card with cash.

Turn on a netflix movie at home, then drive somewhere without your cell phone, and add the spent gas back to your car (with cash) before you get home.

Create an email account that you only access from a Starbucks on the other side of town. (Left your cell at home, and refilled your gas tank before you got back, right?)

Pull the battery out of your cell phone and have a private conversation, or put it in the bathroom with the exhaust fan running loudly, and flush before you pick it back up.

Work out codes with your friend, and text each other with unassuming messages that are actually code for other messages.

Keep track of all the "traffic" cameras at the intersections near you, practice plotting routes that pass few or no cameras (You probably shouldn't do this on Google Maps...)

Don't ever think BB is all knowing.




By the way, listen to Glenn Beck. He's the only one who has been putting these things together in an honest and measured way.

Thursday, October 14, 2010

For you to succeed, I must fail.

I know that the ideal outcome of a web application vulnerability assessment is that the hacker finds nothing, and reports that the site is very secure.

But that doesn't keep me from feeling crappy when I can't find anything wrong.

Bleh.

Thursday, July 15, 2010

"You're all assholes."

Through a bit of luck, I was off on a day when my friend was speaking at a local hacker meeting. I was going to be anti-social, but I dragged myself there, and was rewarded with some interesting conversation.

One guy told us about a talk he saw called "You're all assholes." So named because they took suggestions on what to do the talk on, and got suggestions like "Email," "Websites," and "SSH." At which point they realized their attendees were all assholes. The talk continued, mostly about how you were supposed to be attending the meeting because you wanted to engage in a high-level discussion about application and network functions, but instead, were attending because you don't understand basic computing.

The final point of the talk was; if you're not personally interested enough to look up some basic information yourself by spending the day at Barnes and Noble or the library with a pen and notepad (recently found one of my old notepads) or (at the risk of sounding "kids these days have it so easy") do a simple fucking google search and just start reading, then you are never going to have the complete knowledge necessary to effectively consider all possible attack vectors, and effectively exploit them.

Almost any human can learn or do just about anything if they have the drive to do it. But there is a difference between someone who can do something, and someone who wants to do something.

This is why enthusiasts will always beat the people who are only doing something because it's their job.

The enthusiast will do the extra research, work the extra hours, and return the next day excited to continue.

We were expanding on this point to a newbie, and I started listing the things you need to know and be able to do to be an effective hacker, and surprised myself with all the things I've taught myself the years in order to accomplish my goal. Esoterica abound.

But I still do it, because I still love it.

The old saying about finding out what you're good at, and finding out what you love doing is still very much in effect. I just wonder if my generation had time to find out what those things are.

Thursday, October 29, 2009

My Workspace

I've gotten a few comments on how I run my work computers, so I think I'll go over my work setup. Normally people like to talk about their hardware setup, but I think I've found a seriously productive and versatile software setup.

Two boxes, one Windows, one Linux.

The Windows box has a dual monitor setup, and all inputs (mouse, keyboard) connected to it. The task bar is set vertically to increase the amount of windows it can display while showing title title text. Horizontally the similar programs either clump into one item, or shrink until only the icon is visible. The vertical bar lets me see everything. Windows taskbar lets you set your own shortcuts, and in the vertical position, I have some width to fit shortcuts to all the programs I use easily. I very rarely have to use the start menu.

The Linux box is a Red Hat flavor that runs headless (has no monitor/mouse/keyboard, only network connection and power), and runs GNOME for simplicity. It runs a VNC server that I connect to from my Windows box, and full screen on the entire left monitor.

VNC is a remote connection software that gets a bad rap from people who use it on windows (I was one of them) because on windows it's slow and annoying. Using it on anything other than a LAN connection meant "painting" the screen with your cursor every time you click on something and other annoyances. VNC servers on linux, however, are more like RDP. Seriously, you can watch youtube videos with it. The VNC fullscreen is a true fullscreen, and catches all keypresses and combinations with no latency on a LAN. (But make sure you match your duplex settings. On auto I experience lag)

At first, my GNOME desktop ran four virtual desktops (four separate screens you can flip through on your one monitor) that I rarely used. But after I assigned a keyboard shortcut to switching left and right through virtual desktops it became much easier to flip between different programs on different desktops.

My resolution is actually rather low. Because the LCDs I work with max out at 1280x1024, I had to make the most of the limited space by using multiple desktops on my Linux box, and the vertical taskbar on my windows box.

The amount of desktops I had on my linux session gradually grew. As it became easier to move between them, it just made more sense to put different windows on different desktops to keep different types of work separate. Compared to alt-tabbing or finding and clicking on the taskbar, finding the windows I want is much easier when I know what desktop they're on.

I currently run with 10 virtual desktops.


I do most of my work on my linux box, so my windows box rarely has to be rebooted, but my linux box does have one problem... Firefox.

Since I tend to run my PCs hard, it's very common that I'll have many windows of firefox with many tabs open on each, that I'll leave running for days at a time. The reason I don't leave them open for weeks at a time, is because Firefox will eventually crash, peg my CPU, hog my memory, or just lag intolerably. I've hit every update they've released, and tried every fix I've read. Same issue. I've come to the conclusion that Firefox just wasn't meant to be run like this.

Firefox aside, the linux box has been exceedingly stable at continuous running of mysql servers, terminal server connections, security scans, various scripts I run, and pretty much anything else I can throw at it. It's only a 1.2ghz box with 1gb of ram, but it runs like a champ. Every few months, I do get the occasional nautilus crash which is easily recovered from, and once or twice a year, I get a kswap0 freak-out that can only be resolved by restarting my X server, but those problems are nothing compared the stability I get on this configuration.

The windows box runs only the programs that won't run on linux or need to run locally. Most of my interface with the ticketting and database resources are done through the terminal server connection on the linux box. But the windows box is the only one with a soundcard, so the only browsing it does is online radio, media player, and the odd youtube video. This has kept the windows box running pretty strong. It will still get the occasional program run amok, but I'm quick on the draw with the end task button on the task manager.

I think it's a strong, productive, stable workspace that I've found perfect for processing work orders, engaging with customers, keeping research data available, writing and testing code, and pretty much any other odd job that gets sent my way.

Tuesday, June 23, 2009

A bit of fun with cryptography





Before you start clicking the clues below, really try to exhaust every angle. Spend some time on it. It'll be much more rewarding to get it without the hints.

For a hint, click here.
For a clue, click here here.
For a BIG clue, click here here.
For a near spoiler, click here here.

Tuesday, December 30, 2008

SSL broken! Hackers create rogue CA certificate using MD5 collisions

SSL broken! Hackers create rogue CA certificate using MD5 collisions

You're likely asking yourself how the FUCK they managed to process all these MD5 collisions, they used the processing power of 200 PS3s. That's right; two hundred.

Just make sure you watch for spoofing guys. Don't trust that little lock icon any more. Trust that you browse directly to your banking/credit card site.

And now, the above post repackaged for the more visually minded;





Monday, December 15, 2008

Do not meddle in the affairs of hackers

... for you use technology far too much.

I've been receiving unsolicited SMS messages on my cell phone lately, from the same sender.
The first one, I let pass, thinking it was just a random blast.
The second one, I replied to the SMS asking that I be removed.
The THIRD one, I called the number I was supposed to call, and told whoever answered that I wanted off his list. He told me to reply with an "X." I did.
The FOURTH one, I called the number directly, and got a voice mail. I left a message making myself very clear that if I was not removed from his list, I would pursue more official channels.

He mentioned his name on the voice mail, so I did a quick google search followed by a few more pointed searches. I quickly found his picture, his address, his (insecure) website hosted with a service I know to have insecurities, his myspace and facebook accounts, and where he seems to be currently employed (along with sites for rdp and mail for this company).

With just this information, I could childishly annoy him, cramp his business to the point that it would no longer be profitable, or put him under serious scrutiny of several three letter acronym government agencies, and everything in between.

With a little more effort, and a little more information, I'd be able to do a lot worse.
A lot worse.

Spammers piss me off.

Friday, October 10, 2008

The world can be an informative place

If you know what to look for.

1 hour video on No-Tech Hacking.

VERY worth your time.

I don't think I'm going to be missing any DefCons in the future.

From SurvivalBlog

Friday, September 12, 2008

Hackers infiltrate LHC!!!!! Except not.

Hackers infiltrate Large Hadron Collider systems and mock IT security

"Infiltrate" is a bit of a strong word for this. Their website was defaced. That is all.

As far as skill and complexity of attacks go, website defacement is a few steps above port scan.

Website defacement is particularly limited in scope because the website was likely run on a Linux Apache server, and if you let it get out of date, or attackers know of an undiscovered vulnerability, the Apache server can be compromised. HOWEVER! Since it's not a windows server, compromising the Apache server means that the attacker would only have access to Apache stuff. The worst they'd be able to do (assuming there is no leverage) is deface the website. Oo ho hoho! Scary!

But even if t3h L337 hax0rz DID totally compromise the system, so what? Does anyone honestly believe the controls for the supercomputers managing every aspect of the Large Hardron Collider are connected to the internet!? (directly or indirectly) This is not Sneakers, where you fire up your modem, and connect to a power grid controller.

Yeah, I know this douche was probably just trying to drum up traffic with his sensationalist title, but who cares? Don't be such a fucktard.

Monday, August 04, 2008

The death of Hackers

Most true hackers follow a natural progression. They start out bored in school, not because it's hard or they're lazy, because it's not challenging. So they look for new challenges, usually in electronics because of they are based on logic. After they begin to understand how the computer works, they start seeing if they can make it do tasks by itself, they learn to code. When they begin to understand program architecture, they become interested in the architecture of other code, they speculate on how programs they use work. They discover (on their own or through other sources) that if you give some programs tweaked or improper input, you can make the program do different things, including things it's not supposed to do.

That's really the essence of hacking. Making something do something it shouldn't do, just to see if you can. Why part out a VCR, learn to write serial interfaces, and do some minor PIC programing so you can have an automatic pet feeder, when you can just buy one from a store? Curiosity. You know what it is, you understand what it does, and you have most of the knowledge to make something that accomplishes the same task, why not see if you can make one yourself? You've never made something like that before, but you only need to learn a few more skills, and you'll be able to do it, then you can use those skills for other things.

Curiosity makes you see something and wonder if you could make a better one. Curiosity makes you see existing hardware or software with potential for new functionality, and try to add that functionality. Curiosity makes you stay up all night reading reference books and white papers on obscure topics you'll never use again just because they're interesting. Curiosity makes you toss an apostrophe in a web field to see what error it gives. Curiosity makes you learn javascript because your entry was sanitized. Curiosity leads you to learn that by modifying the raw POST data you can bypass java restrictions.

Curiosity is the mother of innovation.
Curiosity is what defines a hacker.

One would think hackers would be viewed as assets to our society, and country. They're the people who grow up to found new technologies, and advance our technical understanding. But based on the (over)reactions and statements released by the "Cyber Crime" division of many government TLA departments of departments, this seems closer to reality than it should... Funny I should make that association, because the electronic crime group I'm a member of, which is run by see-krit service and populated by various agents from various government agencies, offers a free showing of Die Hard 4 at the next meeting. I'm sure they'll preface it with "This is fiction, and is not an indication of something that could actually happen." Yeah... I'm sure they will...

Contrary to what those who know little but speak much would like you to think, hackers are not (all) angry, anarchistic, teenagers out to disprove mommy and daddy. They're regular people who apply clever solutions to complex problems. I'm inclined to agree with O'Reilly's definition of "hack."

Hack: A clever solution to an interesting problem.

This includes a little bit of mischief. Usually, because early hackers don't have a complete testing environment with all forms of systems and software. I won't say that these young hackers are doing nothing wrong, because in legal terms, they are, but I also won't say what they do is any more destructive than a kid sneaking a candy from the bin at the store.

These baby steps, and missteps eventually culminate in the evolution of a true hacker. Someone who does not think the way school-taught programmers think. Someone who sees problems from angles others are not taught to see. Someone who founds new technologies, and creates The Next Big Thing. I've had many experiences with these cookie-cutter outsourced programmers, and what I always find lack is exactly what is most important; creativity.

Except that hackers seem to be dying out now.

Our technical creativity is being outsourced more and more, with depressing results. Our paradigm shifts are decades old, and rotting on the vine. Our shining new worlds few and far between.

Why?

Because hackers are terrorists.

They control a media that our world depends heavily upon, yet fails to understand. They are feared for it.

Like early man feared the gods, the notion that a lone hacker could hack the planet, and crash our economy, triggering the second great depression looms in the minds of regular people, and infinitely more frighteningly; the minds of our government.

I've personally viewed presentations at aforementioned government attended meetings that warn "attacks" such as an innocuous port scan, should be regarded as an attempt to disrupt service, and the economy. Certainly I allow them some dramatic flair, but it seemed clear to me that many of these government officials returned to their offices and turned on logging for such an event.

The idea that a lone hacker, or group of hackers will do any more than temporarily interrupt availability to a website is incredibly unlikely. The idea that systems will be damaged so badly that recovery will be impossible is simply false when you consider the infinite funds of any government or financial institution.

Indeed, the idea that hackers have the power to destroy the country and should be regarded as terrorists is so wrongheaded, it actually invokes memories of the Salem witch hunts.

But that doesn't stop hackers, mostly kids, from being tossed in jail, ordered not to touch computers, or put on lists for the rest of their lives. Nor does it stop professional hackers from being regarded with the same distrust centuries of people gave to those who understood what they did not. Not while government "specialists" get to send out press releases of foiled "cyber crimes," and extricate more funding from taxpayers to buy the latest and greatest wizbang toys for their playgrounds. These "specialists" know how little most people know about their profession, and make a name for themselves by cracking down on kids who have no idea what they're doing, and filling the collective public mind with visions of fantastic Die Hard 4 "Fire Sales."

With the continued fervor over domestic terrorists, and the constant expansion of that term, it seems unlikely this will stop any time soon.

Our innovation will continue to suffer in fields we should be leading, and we will lag behind the world while we chase our tail until the surprising and enlightening day we actually catch it.

Wednesday, June 25, 2008

Don't fucking insult me.

Our VP got into... something with a subsidiary of a customer. The subsidiary said they were secure, and didn't need our service. VP said they weren't secure, and needed our service. Then it got personal between them. Enter me, stage right;

Me: You called?
VP: Yeah, we've got this guy down in oceanside who's cockblocking us from some business down there because he claims his network is secure. If we prove him wrong, we'll be poised to get the account.
Me: ... Okay...
VP: He was all in my face, all like, 'no, eff this, eff them, I don't need them' whatever. I want to show this guy up.
Me: *eyebrow tweak*
VP: This has gotten totally personal. I want this to happen.
Me: Okay... Well... Do they have any internet-facing services, or other means to get in?
VP: I don't know, but I really want to get in this network. I want to go over to that guy, slam a paper down on the desk, and say 'There. That's why you're full of shit.'
Me: Well, it doesn't exactly work like that, I mean, I can't just hack anyone. They need to have services or some form of "in" to the network. If they've just got a cable router and five computers behind a firewall, it's almost impossible to get in without some form of social engineering.
VP: I don't care, I know you can do it. I just really want in to that network. This'll be a big account for us, and it's ours for the taking if we can just prove this idiot wrong.
Me: ... [given up talking to someone who isn't going to listen]
VP: And, hey; [my name]...
Me: ... yeah?
VP: If you get in... [dramatic pause] There's 100 bucks in it for ya.
Me: ...
VP: Yeah. So. We should get in. Ka-Ching!

VP Exulent left.

WHOAAAAAAAA! One HUNDRED dollars?! Cash money?! Well, THAT changes EVERYTHING! Before I was just going to phone it in, but NOW... Well, shit! You know that 30 acre plot in AZ with the quarry? That shit is MINE NOW.

Don't

fucking

insult me.


I'm a hacker. I'm good at what I do. That's why we're charging a mid-sized customer 10k for security work. That's why I'm doing it all myself, and that's why we have no other security people on staff. But you come to me, and tell me that YOU have made it personal? You tell me that YOU want to get into this network? You tell me that YOU have no idea what the attack vectors are, or even if there ARE any? THEN, you have the nerve to personally offer me one hundred dollars as incentive to get in?!

First of all, what in your experience with me has lead you to believe that I half-ass my security work? Was it the time I didn't get in, and worked on it two extra nights until I found an opening? Was it the time I went beyond scope just so we didn't have an empty report for the customer? Somehow I think not. The idea that by simply offering me 100 smackers, I'm suddenly going to try EXTRA hard to get in, is insulting. Secondly, I have a pretty good idea how much you get for signing a customer, and 100 fucking dollars is a goddamn insult. Especially considering I'm the one closing the deal for you! And yes, I still remember when you promised me a finders fee when I delivered a customer to you, and I still remember when I got that "bonus" of $150 as you closed the 6K account (recurring!).

Fuck you, fuck your "personal" conflict with this guy, fuck your trying to get me in on your conflict, and fuck your hundred dollars!


---------------
COOL OFF PERIOD
---------------


Ok. Venting is good. I'm going to do the work, because I'm a professional, and because we could use the customer. When you give me the hundred dollars, I'm going to smile and accept it graciously.

If he ever offers me an insultingly small "incentive" to do my job again, I'm going to decline, and leave it at that. If he presses me on it, I'm going to leave the room, for fear I might tell him where he can put his "incentive."

Monday, June 16, 2008

NO! BAD! STOP!


NO, performance systems international; we do NOT sanitize our input in java!
That is how we get our boxes hacked!

Java is on a different layer than the traffic transmission. Setting a java script to limit input of a record search number from 1-100 will do nothing when someone modifies the HTML POST on its way out, and changes 50 to 1000000, instantly tying up your database with a single request. Or perhaps you are trying to remove special characters? Can you say; SQL INJECTION?

We sanitize our input on the BACK END...
Say it with me; BAAAAACCCKKKK EEEENNNNDDD

You know how you defeat back end limits?
If you code it right; you can't.

NETWORK SECURITY IS EVERYONE'S RESPONSIBILITY.

YES, EVEN LAZY CODERS.

Wednesday, March 26, 2008

Hacker Quickie v1.0

[The following is provided for informational purposes only, and only to further the understanding of the curious.]
MAC addresses
The Media Access Control (MAC) address is a hardware based address that is unique to each networking device. This means that when you go to the store and see boxes and boxes of network cards, each one has its own unique MAC address. If you remove the Network Interface Card (NIC) (NOT NOT NOT "NIC Card") from your computer, and install it on another computer, that computer will have the same MAC address of your old computer. It's tied to the actual, physical device.

MAC addresses are used for low level routing (low level means on a local area network basis), and are not found out on the internet. If you connect your computer to your home router or cable modem, your MAC address will not go beyond that gateway device. The MAC address is used in a number of ways, but primarily it is used for unique identification of individual network devices. If you take two computers, and give them identical IP addresses, your router will know something's wrong, because there are two computers with two different MAC addresses, and the same IP address.

The idea that MAC addresses will always be unique is what we're going to exploit.

The MAC address that is set on the hardware will never change, the MAC address that your operating system stores for use, however, can change. Basically your networking drivers picks up the MAC address from the hardware, and uses it for future traffic. By simply changing that address after it has been obtained from the hardware by the software, you can effectively change your MAC address.

Ok, so your MAC address is different now. How is this useful? Well, since most networking hardware is predicated on networking devices playing by the rules, you can bypass restrictions set by networking hardware. To do something like, oh, I don't know... Obtain free internet access at a local coffee shop with one of those shit-eating website redirects that wants you to pay for internet access. Networking hardware recognizes computers based on IP address and MAC address, by changing your IP address and MAC address to that of someone who has already paid for access, you will be permitted internet access. This, of course, requires someone already be paying for internet access, and since you can't swing a dead cat without hitting a douchebag writing his novel or trying to look important while he checks his blog for comments over and over, this shouldn't be a problem.

You can also bypass the MAC address filtering on an unsecure wireless network. Simply obtain the MAC of an allowed machine, and emulate it.

Changing your MAC address for windows is as easy as SMAC. Hmmm... I've been out of the windows game for a while, and SMAC now appears to be a pay utility. I'm sure there's some other free utility that will allow you to change your MAC address on windows. You will probably have to disable the device or the connection before you can make the change, and then turn it back on. I forget what I had to do, but it was something similar.

Changing your MAC address for linux is an existing option that comes with the OS.
ifconfig hw eth0 12:FE:AB:78:90:CD
You may have to ifdown the interface before making the change, and then ifup it and check that it stuck.

Also know that the MAC address you change to must be valid. You can't just pick random numbers and letters. There are a number of random MAC address generators online, so grab one.

Coming up next time, capturing and reading network traffic.
For things like valid MAC addresses!

Disclaimer: ExistingThing does not condone the use of services which you are not allowed to use, even though there is a minuscule chance that you'll get caught, and a microscopic chance that you'll actually get charged. ExistingThing also reminds all the s00pr l33t hax0rz out there that hackers don't get slaps on the wrist any more, they get shipped to Guantanamo Bay as enemy combatants. No lawyer. No habeus corpus. No phone call. Go directly to jail. Do not pass go. Do not collect $200.

Tuesday, October 23, 2007

Better RDP brute forcing

Win.

I hated TS grinder with a passion.

UPDATE
Bugger. Seems it can't cope with a GP "Legal Notice" (banner). Oh well, it's still good.

Wednesday, October 10, 2007

Sanitize your input.

You certainly don't want something like this to happen.

and don't forget input that is managed by java (direct POST modification bypasses java restrictions), and input that calls web pages by IDs for SQL queries instead of actual URLs.

Thursday, July 26, 2007

holy hell!

Coworker: *ring* Hey (my name), I've got... uh... (female name) from the Secret Service for you...

brain instantly pegs at 100% usage, then stops abruptly.

Me: Oh-ho-ho! You got me good. Man! Haha! Tell her I'll be right with her while I run out to my car!

Coworker: No, seriously. She's on the phone right now...

brain instantly pegs at 100% usage

Coworker: Do I need to call you a lawyer?

racking brain over everything I've done in the last few months

Me: Uh... Can you ask what it's regarding?

Coworker: Yeah, sure man. *click*

Gah! I can't remember anything! WTF RELAX, you're not shady anymore! OMGOMGOMGOMG Should I start /usr/bin/shredding?! WTFWTFWTF I'm fine! I haven't done anything that bad! I haven't done anything I can't defend against-- *ring*

Me: Yeah?

Coworker: She's calling about the (acronym) meeting.

*deep exhale*

Me: Ok, thanks, put her through.

Coworker: You cool?

Me: Yeah, it's fine, put her through.

I'm a member of a task force run by the secret service and DHS that covers cyber crime (I'm refraining from using names and actual acronyms for obvious reasons, if you're familiar with the group, please don't post it's name or guess at it.), turns out they messed something up and had to call all the members.

Monday, May 14, 2007

lol cn U tch me 2 hax intrnets?

The bane of a hacker's existence. Noobs asking (or demanding) for you to "teach" them how to become hackers. The question is so common it's nearly universally ignored. I, however, usually tell them I'd be happy to teach them how to "hax0r teh intarnets" if they're willing to do the work to learn. Everyone always says yes to this. I then explain to them that becoming a true hacker requires a deep understanding of software models, networking, programming languages, and how software interacts with other software. Most will agree they're willing to learn this. I then tell them to learn a programming language if they don't already know one. Only a few have known any languages before my request, and even fewer return after having learned a new language. Next I ask them to write a simple trojan horse that will run on one box and accept commands from another location. This simple task has only been completed by one person. I then asked that person to read about and understand a few attack vectors and write a sample exploit tool for one of the exploits. He did it. I asked him to learn SQL and proper management techniques in order to better understand how to run exploits against SQL servers and backends. He did.

Truly impressed, I asked him if he still wanted to become a hacker. He said he did, but he now he wasn't sure what being a black hat hacker (proper term) was about. I told him, and told him why I don't do what I used to do anymore. He said he didn't want to be a hacker anymore. I then told him that I never had any intention to teach him to become a malicious hacker, but used his drive to push him to learn skills he probably wouldn't have learned on his own. I then told him that without realizing it, he'd developed a series of marketable skills that are in demand in the IT industry. I told him that with his drive and skills he should have little problem finding work that pays better and doesn't bear the threat of federal prison (or now, being labeled as an enemy combatant and being thrown in gitmo sans habius corpus). Then I didn't hear from him.

I hope he's doing well.

After most hackers learn the skills required to become elite they realize that they've got big fat paychecks waiting for them all over the tech industry. Nothing takes the angry teenager fighting against the government's systems of perpetual poverty and tyranny out of you like the promise of good pay and the hopes of making said pay while avoiding federal pound-me-in-the-ass prison.

Wednesday, May 09, 2007

A NEW CHALLENGAR APPEARS!!!

Just in time for dear old Jack's demise, the hacker community finds a new villain! Say hello to the new guy ready to prevent you from posting things on the internet: Michael Ayers.

Some reading if you want more of the story.

AACS LA: Internet "revolt" be damned, this fight is not over
HD DVD "The Code" Shirt
Breaking: Digg Riot in Full Effect Over Pulled HD-DVD Key Story

Basically, the HD-DVD encryption can be broken by a certain 32 character hex key. Cue the content controller trying to stop people from printing or reproducing the code. Problem is, the code is essentially data. It's almost like saying your car uses the color blue, so anything that's blue is unauthorized reproduction of "trade secrets". Certainly this series of hex characters is a bit more esoteric than the color blue, but all software is made of 1's and 0's, and when displayed in the hex format, this series likely exists in countless places. It's also like patenting the "curve". Things already exist in the world that use curves in countless ways, you can't just say it's illegal to use it because YOU use it!

It's amazing how many parallels you can draw from this and the DeCSS idiocy. Since "data" is not protected speech (due to technically inept law-makers), the code is being reproduced as art, shirts, and in song. It seems the AACS LA can't fire off cease and decists fast enough.

I really enjoyed how Think-Geek approached the problem of fighting these idiotic threats while keeping themselves from legal action. They've made a shirt which reads the following:

09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-bd
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-be
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-bf
[redacted]
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c1
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c2
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c3


People knowledgeable in such things know what key is missing without it having to be printed! Genius.

On a completely unrelated note, I've written a random number generator, but it doesn't seem to be working... Every time I run it, it just returns the same hex characters over and over again! Here's some sample output...
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0
09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0


Anyone know how to fix this?

Thursday, April 26, 2007

DING DONG Jack is dead!

Jack Valenti, Hollywood's Lobbyist, Dies at Age 85

I don't take enjoyment in the death of another human, but this guy was quite the villain to hackers and coders everywhere. He suppressed the free speech of hacker magazine 2600, by filing a preliminary injunction under the DMCA.

DVD playing software is licensed out by the MPAA. When you buy a computer with DVD viewing software or buy a DVD player, a bit of money goes to the MPAA for use of a license to decrypt the CSS encoding and watch the DVD. Linux is a "free as in beer" so it costs nothing, there are many reasons for this, but suffice to say, Linux users didn't want to have to pay money for software to view a DVD that they'd already legally purchased. The MPAA was asked to provide a free Linux/Unix player to let people view the content of DVDs they'd paid money to watch. When the MPAA refused to deal with developers, and told them to use windows instead, the gauntlet was cast. One one side people who bought movies and just wanted to watch them on their computers at home, and on the other, a huge corporation unwilling to provide a simple program to allow viewers to watch the DVDs they'd already purchased. When DVD John, as he is now known all over the world, published the DeCSS to decrypt the CSS protection the MPAA tried to stop 2600 from printing it. Suddenly they began suing and shutting down hackers and strong-arming ISPs of people or sites which simply POSTED the information to the internet! By simply printing something, you could be charged. This is why my license plate frame says "Source code is free speech"

Jack is known for his quote,
If we have to file a thousand lawsuits a day,we'll do it.


Jack wanted to beat down people with the threat of lawsuit. People who wanted nothing more than to view a DVD they'd legally purchased. As time wore on, the lawsuits slowed because judges were less and less likely to uphold the idea of punishing someone for simply printing something.

I think I'll be wearing my "You don't know Jack" shirt tomorrow. (I'd find a pic, but its been discontinued) ... (as has he)