<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Joe Tech &#187; hacking</title>
	<atom:link href="http://www.joetech.com/tag/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.joetech.com</link>
	<description>Gadget reviews, technology news, software reviews, cool tech news</description>
	<lastBuildDate>Fri, 03 Feb 2012 20:18:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.4</generator>
		<item>
		<title>How To Avoid Online Scams</title>
		<link>http://www.joetech.com/how-to-avoid-online-scams/</link>
		<comments>http://www.joetech.com/how-to-avoid-online-scams/#comments</comments>
		<pubDate>Mon, 24 Jan 2011 00:03:44 +0000</pubDate>
		<dc:creator>Joe Tech</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[avoid]]></category>
		<category><![CDATA[cracking]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[online]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[safe]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spot]]></category>

		<guid isPermaLink="false">http://www.joetech.com/?p=2456</guid>
		<description><![CDATA[In 2009, I wrote What Is Phishing And How To Avoid Online Scams. While the information in that article is still very valid and worth a read, I thought I should follow up with an updated guide on how to spot and avoid scams online.


Related posts:<ol><li><a href='http://www.joetech.com/what-is-phishing-and-how-to-avoid-online-scams/' rel='bookmark' title='Permanent Link: What Is Phishing And How To Avoid Online Scams'>What Is Phishing And How To Avoid Online Scams</a></li>
<li><a href='http://www.joetech.com/how-to-avoid-falling-victim-to-email-fraud/' rel='bookmark' title='Permanent Link: How to Avoid Falling Victim to Email Fraud'>How to Avoid Falling Victim to Email Fraud</a></li>
<li><a href='http://www.joetech.com/youre-being-watched/' rel='bookmark' title='Permanent Link: You&#8217;re being watched'>You&#8217;re being watched</a></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>In 2009, I wrote <a href="http://www.joetech.com/what-is-phishing-and-how-to-avoid-online-scams/">What Is Phishing And How To Avoid Online Scams</a>.  While the information in that article is still very valid and worth a read, I thought I should follow up with an updated guide on how to spot and avoid scams online.</p>
<p><img src="http://www.joetech.com/wp-content/uploads/2008/01/burlgar.jpg" alt=creeper" /></p>
<h3>Social Engineering And Phishing</h3>
<p>Phishing is the act of fishing for sensitive information from a target.  This is usually done by baiting the hook with either something very tempting or a sense of urgent attention needed to something they value.  Social Engineering is the art of getting someone to do what you want using only creative manipulation.  Phishing is more closely associated with fraud and illegal activities.  Social Engineering can be used in Phishing and hacking, but is also useful in many legal and morally neutral situations.</p>
<p>Examples of phishing largely include those fake bank and PayPal emails everyone eventually gets.  Usually, the email will report that they are upgrading security or that your account is frozen (or in danger of being frozen).  The quality of the email lends to how believable it is and can vary widely, but the goal is always the same.  The sender wants you to feel the urgency to log into your account to prevent a threatened interruption in your access to your money.  Similarly, you may have seen emails, seemingly from Facebook, telling you that you need to log in to keep your account open or for some other immediate reason.  Don&#8217;t narrow your suspicion to just these examples, though.  This type of bait email can apply to anything from your banking site to your Amazon wish list.  Phishing isn&#8217;t just for a username and password, either.  The rule of thumb is that any piece of information (or pieces in combination) that should be considered sensitive should be guarded carefully and you should think twice before giving anyone this information.</p>
<p>Social Engineering is a little broader in concept, but is just as important to be aware of.  In fact, it may be more important to think about because your web browser can&#8217;t warn you about something suspicious when someone calls you on the phone and has a trick up their sleeve.  Social Engineering relies heavily on perception and the target&#8217;s openness to trust that perception.  For example, if a scammer calls you, sounding very professional and polite, and wants to confirm account information for your PayPal account, they are creating the perception that they are already in posission of your sensitive information and that you shouldn&#8217;t worry about giving them any of it.</p>
<p>Luring you in with something tempting is another trick people use all the time, and it&#8217;s one I fell for once, as careful as I usually am.  It may be something as simple as information about who&#8217;s viewing your Facebook profile or it could be something as tempting as a free iPad.  Either way, these scams attempt to trick you into giving your account credentials, signing up for a spammy Facebook group, or emailing a link to all your friends or worse.  In my case it was worse, but I&#8217;ll share that below.</p>
<h3>How To Spot A Scam</h3>
<p>The sad fact is that nobody can truly spot every scam.  Sadder still, is that most people don&#8217;t even think about it and could easily spot scams if they did.  For scams we can&#8217;t spot, there are some rules to live by below, but for those we can spot, there&#8217;s some easy things to look for.</p>
<p>The number one thing I always ask myself is &#8220;Did I expect this email/message/phone call?&#8221;  If receive any form of communication, that I didn&#8217;t expect, claiming to be from my bank or anywhere that might need sensitive information confirmed in order to discuss my account, I become immediately suspicious.  About 95% of the time, I&#8217;m right and it&#8217;s a phishing attempt or a scam of some kind.</p>
<p>Who was the email sent to and who was it from?  An alarming number of people don&#8217;t pay any attention to this, assuming that the email designed to look like it came from Bank of Arizona actually did.  Sometimes, you can see the suspicious email easily and other times you may need to &#8220;View All Headers&#8221; in your email program to see the details.  In GMail, you simply hold your mouse over your name or the sender&#8217;s name.  When you can&#8217;t see who the email is to or from, it&#8217;s best to defer to the Rules to Live By below.  This applies to phone calls as well.  If my cell phone rings and I don&#8217;t recognize the number, it goes to voicemail.  Any reputable company or person worth calling back will leave a message.  No message = no call back from me.</p>
<p>With any unexpected contact, ask yourself what the end goal is.  Usually, you can elevate your suspicion depending on the apparent goal of the communication.  For example, if asked to log in somewhere or to reply with your phone number, name, address, and birth date, you should be pretty suspicious.  On the other hand, if an email just says &#8220;Welcome to Bank of Arizona&#8221; and doesn&#8217;t prompt you for any action at all, it&#8217;d probably pretty safe.</p>
<h3>Even If It Doesn&#8217;t Look Or Walk Like A Duck</h3>
<p>Sometimes, we just assume that scams are obvious when we&#8217;ve fallen for them because our Facerbook accounts get hacked or our bank accounts get drained.  Unfortunately, not all scams look like scams, even after you&#8217;ve fallen for them.  My wife and I came upon a couple great reminders of this while searching for a new place to live recently.</p>
<p>While looking on Craigslist for a house to rent, Michelle found a house that was listed for about half the monthly rent she&#8217;d expect.  Curious, she searched for the address on Google and found it listed by a realty company in several places with a more realistic rent requirement.  The realtor confirmed that the Craigslist ad was not posted by them.  The most likely scenario is that someone responds to the ad, eventually paying deposits and first month&#8217;s rent only to find that the key doesn&#8217;t work in the lock.</p>
<p>Later, Michelle found another home listed for a too-good-to-be-true price and emailed to inquire about the exact location and how we could drop by for a walk-through.  The response she received indicated that the owner was worried about dealing with strangers on Craigslist and could only arrange a walk-through and give out the exact address after a potential renter got a credit check at a site that the email linked to.  Although the credit check site is legit, the scam is that there&#8217;s no home to rent.  If we get the credit check, the person who listed the ad gets a referral commission and would probably then email and say that the house had been rented or some other excuse.  This type of scam happens all the time with domain sales&#8230; &#8220;I want to buy your domain name, but I need to you get it appraised at this site first.&#8221;  I recognized it right away, having seen it when selling domains, but I imagine a lot of people fell for it and still don&#8217;t know they were scammed.</p>
<h3>Rules To Live By</h3>
<p>I&#8217;ve been online since Yahoo was just a couple hundred links organized by a couple guys in a dorm room, and in my time online, I&#8217;ve developed some rules that I live by to help keep me out of trouble.  While these rules help me avoid phishing scams, they have also helped in keeping viruses away from my computer and I think they&#8217;re just good rules to live by, if just a little paranoid.</p>
<p>1. If I don&#8217;t expect it, I don&#8217;t trust it.  I touched on this above, but I think it&#8217;s the number one defense I live by, so I&#8217;ll mention it again.  If you get an email from someone and it has a file in it, call them and ask.  If really is the &#8220;funniest think [they've] ever seen&#8221;, they&#8217;ll get to enjoy your laughter over the phone.  If it&#8217;s an email from your bank, PayPal, Facebook, Ebay, etc. just go to a browser and manually type in the URL or use your existing bookmark.  This way, you&#8217;re sure you&#8217;re on the real site and if it really is important, you&#8217;ll probably have a notification in your account, too.  It&#8217;s when you just blindly trust everything that comes your way that you open yourself up to scams.</p>
<p>2. Look at the URL. Most of the phishing emails I see would have you click on a link to log in somewhere.  While I don&#8217;t think you should ever click on an email link to log in to an account, some links are just way easier to click.  For these, don&#8217;t just look at what&#8217;s on the surface.  Mouse over the link and see what the real URL is.  Watch out for domains like login.facebook.com.ru or www.bankofarizona.com.cn.  As clever as these face domains are, they&#8217;re easy enough to spot if you take a second to look.</p>
<p>3. Use the tools available to you.  Use anti-virus software and malware detection.  You wouldn&#8217;t leave your car unlocked with your wallet in it, would you?  You shouldn&#8217;t leave your computer wide open to this stuff.  There&#8217;s even free anti-virus software out there and most modern browsers will warn you if you try to visit a site that they deem suspicious.  Listen to your browser and your instincts.</p>
<p>4. If it looks too good to be true&#8230; You know the saying.  &#8220;If it looks too good to be true, it probably is.&#8221;  To be fair, the occasional internet goodies are out there.  I have gotten free iPods and PlayStations before, but most of the time, those things are scams.  Don&#8217;t be so greedy that you dive in head first without looking.  Weigh what you have to do and information you have to give against the prize.  Aside from contests, nothing is truly free.  If the promise is for an iPad with no signing up friends, no purchase and no random drawings, it&#8217;s probably a scam.</p>
<h3>Damage Control</h3>
<p>You are not perfect.  Chances are that one day, you&#8217;ll slip and give someone what they&#8217;re phishing for.  I did.  I feel a little dumb even admitting it, but I once gave out my debit card pin online in response to an email that I&#8217;d won an XBox and just had to cover the shipping myself.  I have my rules, I can usually see scams, and I think I&#8217;m pretty smart.  Still, I got suckered in, thinking I&#8217;d won and getting excited at the idea of a free game system.  As bad as that is, it could have been worse.  I could have just prayed nothing would happen, hoping to avoid having to cancel a card or I could have been too embarrassed to call my bank.  Instead, as embarrassed as I was, I called my bank only minutes after sending the email and admitted that I&#8217;d been suckered and needed to cancel the card.  I felt really dumb, but more importantly, I felt relieved that I had reversed the problem quickly by canceling my card.</p>
<p>If you get scammed, don&#8217;t let your pride get in the way of the damage control.</p>
<h3>Help Others</h3>
<p>The internet is a giant community.  When you see scams, report them.  I always forward phishing emails to the real companies the email is disguised as.  They have incredible incentive to go after the scammers and usually do.  Don&#8217;t stop there, either.  Most of you have a lot of friends online.  Let them know about any phishing scams going around.  I&#8217;d rather a friend be quietly aware of scams than hear that they fell for one I could have warned about.</p>
<p>On that note, use the comment form below to tell us about scams you&#8217;ve come across or any tips you have for staying safe online.  And don&#8217;t forget to &#8220;Share&#8221; and &#8220;Like&#8221; this article on Facebook.</p>


<p>Related posts:<ol><li><a href='http://www.joetech.com/what-is-phishing-and-how-to-avoid-online-scams/' rel='bookmark' title='Permanent Link: What Is Phishing And How To Avoid Online Scams'>What Is Phishing And How To Avoid Online Scams</a></li>
<li><a href='http://www.joetech.com/how-to-avoid-falling-victim-to-email-fraud/' rel='bookmark' title='Permanent Link: How to Avoid Falling Victim to Email Fraud'>How to Avoid Falling Victim to Email Fraud</a></li>
<li><a href='http://www.joetech.com/youre-being-watched/' rel='bookmark' title='Permanent Link: You&#8217;re being watched'>You&#8217;re being watched</a></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.joetech.com/how-to-avoid-online-scams/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Tracking And Stopping Web Site IFRAME Code Injection</title>
		<link>http://www.joetech.com/tracking-and-stopping-web-site-iframe-code-injection/</link>
		<comments>http://www.joetech.com/tracking-and-stopping-web-site-iframe-code-injection/#comments</comments>
		<pubDate>Sat, 25 Apr 2009 17:27:41 +0000</pubDate>
		<dc:creator>Joe Tech</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[compromised]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[logs]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.joetech.com/?p=968</guid>
		<description><![CDATA[Yesterday, I wrote about getting paid to hack. Part of what I talked about was computer forensics. Earlier in the day, I was presented with an opportunity to practice my own IT security skills. Below, I&#8217;ll explain what happened to my client, how an employee of mine and I found the source of the problem [...]


Related posts:<ol><li><a href='http://www.joetech.com/how-to-move-a-web-site-with-minimal-down-time/' rel='bookmark' title='Permanent Link: How to Move a Web Site with Minimal Down Time'>How to Move a Web Site with Minimal Down Time</a></li>
<li><a href='http://www.joetech.com/cool-trick-edit-any-web-site-in-any-browser/' rel='bookmark' title='Permanent Link: Cool Trick: Edit Any Web Site In Any Browser'>Cool Trick: Edit Any Web Site In Any Browser</a></li>
<li><a href='http://www.joetech.com/coderos-web-site-gets-refresh/' rel='bookmark' title='Permanent Link: Codero&#8217;s Web Site Gets A Refresh'>Codero&#8217;s Web Site Gets A Refresh</a></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Yesterday, I wrote about <a href="http://www.joetech.com/2009/04/24/get-paid-to-hack/">getting paid to hack</a>.  Part of what I talked about was computer forensics.  Earlier in the day, I was presented with an opportunity to practice my own IT security skills.  Below, I&#8217;ll explain what happened to my client, how an employee of mine and I found the source of the problem and what we did to fix it.</p>
<p><a href="http://www.flickr.com/photos/nodomain1/3473102101/" title="Log file by nodomain1, on Flickr"><img src="http://farm4.static.flickr.com/3330/3473102101_bc96b038b5_o.jpg" width="455" height="158" alt="Log file" /></a></p>
<p><strong>Discovering a problem</strong><br />
A client called, complaining that the content management system we built for them was not working properly, so one of the developers took a look at the code and immediately alerted me to a problem.  When he looked at the code, he discovered two extra lines at the end.  The lines were similar to the following and existed at the bottom of every index.php file in the site:</p>
<blockquote><p>&lt;iframe src=&#8221;http: //lotmachinesguide .cn/ in.cgi?income56&#8243; width=1 height=1 style=&#8221;visibility: hidden&#8221;&gt;&lt;/iframe&gt;</p></blockquote>
<p>My first thought was that someone hacked in and changed the files.  What about the rest of the server?  This is where you get that sick feeling in your stomach and hope it&#8217;s not as bad as it could be.  I emailed my wife and told her I&#8217;d be unavailable via phone/email/etc. for the next few hours.</p>
<p><strong>Finding the cause</strong><br />
Tracking down the source of a hack or code injection like this can often be tricky.  How tricky it is depends on your individual skill set, past experiences, and the complexity of the problem, itself.  This one turned out to be easy, partially because I&#8217;ve done this before and know many of the places to look, but mostly because it wasn&#8217;t really a hack.  Not locally, anyway.  One of my developers and I sat down in my office and I started looking at the hacked files.  Using the following command (from the client&#8217;s web root), I displayed a list of all files that were modified that day:</p>
<p><code>ls -laR |grep "Apr 24"</code></p>
<p>What it returned was a list of the index files I was already aware of.  Good.  I then ran the same command on other sites to be sure this was isolated and it was.  Next, I checked &#8220;last&#8221; to see who&#8217;s been logging into my server:</p>
<p><code>last |grep [client username redacted] |grep Apr</code></p>
<p>Last shows all the recent logins from SSH, FTP, etc.  Immediately, I noted a large number of FTP connections for the client site I was investigating, which looked suspicious.  I headed to my FTP log files and grepped my &#8220;secure&#8221; log files for &#8220;Incorrect&#8221;:</p>
<p><code>grep Incorrect /var/log/secure*</code></p>
<p>Your system may use something other than &#8220;Incorrect&#8221; to indicate a bad login and your &#8220;secure&#8221; log file location may vary.  This grep showed only a few bad attempts, which is fairly normal and not what I expected to see if the account had been brute-forced.  I moved on to the FTP log file to see what transfers were made.  You&#8217;ll need to find your own FTP log location if you don&#8217;t know where it is already.</p>
<p><code>grep "Apr 24" xferlog*</code></p>
<p>I did this mostly to confirm that I was on the right track, but it uncovered even more oddness.  Here&#8217;s a bit of what I saw:</p>
<blockquote><p>Fri Apr 24 11:17:32 2009 0 [ip redacted] 4289 /var/www/vhosts/[domain redacted]/httpdocs/index.php a _ o r [username redacted] ftp 0 * c<br />
Fri Apr 24 11:17:38 2009 2 [ip redacted] 4402 /var/www/vhosts/[domain redacted]/httpdocs/index.php a _ i r [username redacted] ftp 0 * c<br />
Fri Apr 24 11:17:51 2009 0 [ip redacted] 2836 /var/www/vhosts/[domain redacted]/httpdocs/admin/index.php a _ o r [username redacted] ftp 0 * c<br />
Fri Apr 24 11:17:56 2009 0 [ip redacted] 2949 /var/www/vhosts/[domain redacted]/httpdocs/admin/index.php a _ i r [username redacted] ftp 0 * c
</p></blockquote>
<p>For each index file that had the iframe HTML added to the end, there was a download and then an upload five or six seconds later.  The speed indicated that it was a script and the fact that it was all done via FTP indicated that if there was a compromised computer somewhere, it was remote and my server was safe.</p>
<p><strong>Cleaning it all up</strong><br />
In this case, cleanup was easy.  First, I backed up all the log files for further review just in case I need them.  Then I changed the client&#8217;s FTP password.  Finally, I pulled the latest (clean) versions of the affected index.php files from our subversion repository and uploaded them back to the site.</p>
<p><strong>Preventing future occurrences</strong><br />
I wanted to find out exactly how someone who should clearly not have the client&#8217;s FTP credentials wound up with them.  My theory was that the client&#8217;s computer had been compromised.  I headed to <a href="http://www.arin.net">arin.net</a> and used their handy IP whois tool to see who the one prominent IP address from the log files belonged to.  It turned out to be a COX IP registered to Atlanta, GA.  We called the client and asked them if they had anyone there.  They did not.  The FTP logs also showed uploads, recently, of files documents that related to the client and looked to be legitimate, so we asked who uploaded them and conferenced him in.  A couple questions quickly revealed that not only was the IP their local office computers, but the computers there had been &#8220;acting funny, randomly rebooting, etc.&#8221; for the last day or so.  We sent their computer guy out to take care of the problem, which turned out to be a trojan.</p>
<p><strong>Conclusions</strong><br />
First of all, this was a very easy problem to diagnose and fix.  I&#8217;ve been on the bad end of some serious hacks and this was by no means a bad one.  For the client, however, the day proved much more frustrating.  The expense incurred from having the IT guy come out and the thought that it could have been much worse (like their site replaced with something untoward), should be a lesson to be very careful about what you download, what you click, and the sites you visit.  The best policy is to only open or run things from sites and people you trust, and even then, use caution.</p>


<p>Related posts:<ol><li><a href='http://www.joetech.com/how-to-move-a-web-site-with-minimal-down-time/' rel='bookmark' title='Permanent Link: How to Move a Web Site with Minimal Down Time'>How to Move a Web Site with Minimal Down Time</a></li>
<li><a href='http://www.joetech.com/cool-trick-edit-any-web-site-in-any-browser/' rel='bookmark' title='Permanent Link: Cool Trick: Edit Any Web Site In Any Browser'>Cool Trick: Edit Any Web Site In Any Browser</a></li>
<li><a href='http://www.joetech.com/coderos-web-site-gets-refresh/' rel='bookmark' title='Permanent Link: Codero&#8217;s Web Site Gets A Refresh'>Codero&#8217;s Web Site Gets A Refresh</a></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.joetech.com/tracking-and-stopping-web-site-iframe-code-injection/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Get Paid To Hack</title>
		<link>http://www.joetech.com/get-paid-to-hack/</link>
		<comments>http://www.joetech.com/get-paid-to-hack/#comments</comments>
		<pubDate>Sat, 25 Apr 2009 06:31:13 +0000</pubDate>
		<dc:creator>Joe Tech</dc:creator>
				<category><![CDATA[Communication]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[#CEH]]></category>
		<category><![CDATA[class]]></category>
		<category><![CDATA[council]]></category>
		<category><![CDATA[ethical hacking]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[iclass]]></category>
		<category><![CDATA[learning]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://www.joetech.com/?p=945</guid>
		<description><![CDATA[One of the things I love most about computers is the ability to learn something new every day. The internet helps me do that from the comfort of my own home and gives me more options than I can shake a stick at for learning new things. You can even take classes online and not [...]


Related posts:<ol><li><a href='http://www.joetech.com/how-to-hack-a-person/' rel='bookmark' title='Permanent Link: How to Hack a Person'>How to Hack a Person</a></li>
<li><a href='http://www.joetech.com/gawker-media-hack-is-a-password-reminder/' rel='bookmark' title='Permanent Link: Gawker Media Hack Is A Password Reminder'>Gawker Media Hack Is A Password Reminder</a></li>
<li><a href='http://www.joetech.com/omg-ashley-marc-james-is-a-virus/' rel='bookmark' title='Permanent Link: OMG! Ashley Marc James is a Virus!!!'>OMG! Ashley Marc James is a Virus!!!</a></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>One of the things I love most about computers is the ability to learn something new every day.  The internet helps me do that from the comfort of my own home and gives me more options than I can shake a stick at for learning new things.  You can even take classes online and not just the boring ones, either.  This sponsored post is about some of the coolest <a href="http://socialspark.com/metrics/click/post?slot_id=36467&#038;url=http%3A%2F%2Furlbrief.com%2F98d904" rel="nofollow">IT Security</a> classes you can take online.  Learn to hack online and then make money doing it.</p>
<p><a href="http://www.flickr.com/photos/nodomain1/3464986632/" title="Security Enforcement by nodomain1, on Flickr"><img src="http://farm4.static.flickr.com/3634/3464986632_4bf12c009e_o.jpg" width="455" height="247" alt="Security Enforcement" /></a></p>
<p><strong>Ethical Hacking</strong><br />
There&#8217;s a couple different ways to think about what hacking means.  To some people, it&#8217;s just seedy characters in seedy places trying to break into your computer and steal your identity.  While there&#8217;s people out there who do things like that, it&#8217;s not the true definition of a hacker.  A hacker is someone who thinks outside the box to obtain information and learn new things that is normally unavailable via popular channels.  That said, bad hackers are out there, but there is such a thing as <a href="http://socialspark.com/metrics/click/post?slot_id=36467&#038;url=http%3A%2F%2Furlbrief.com%2F98d904" rel="nofollow">Ethical Hacking</a>.  Since the <a href="http://socialspark.com/metrics/click/post?slot_id=36467&#038;url=http%3A%2F%2Furlbrief.com%2F98d904" rel="nofollow">EC-Council</a> site does such a good job explaining ethical hacking, I&#8217;ll let them tell you in their own words:</p>
<blockquote><p>The goal of the ethical hacker is to help the organization take preemptive measures against malicious attacks by attacking the system himself; all the while staying within legal limits.
</p></blockquote>
<p>It&#8217;s important to note that Ethical Hacking can be learned on your own, but it&#8217;s a slow road.  Besides, a <a href="http://socialspark.com/metrics/click/post?slot_id=36467&#038;url=http%3A%2F%2Furlbrief.com%2F98d904" rel="nofollow">Certified Ethical Hacker</a> is bound to have better odds making more money.  Friends of mine have done this as teams or solo projects and if you&#8217;re good, it pays well and is a lot of fun.  Now, the pay is better than ever, even in our economy.  According to a recent article on CIO.com, the pay for an ethical hacker is up 40%.  One of my friends was flown to Japan to hack in to a large company&#8217;s network and make a dramatic point about their security needs by walking into a security needs meeting in a highly secured part of the building using only his skills to gain access.  &#8220;You should have seen their faces&#8221;, he told me with a big grin.  Speaking for the other side, I manage several servers myself and I can tell you it&#8217;s a lot cheaper to pay someone to find all the holes than it is to clean up the mess that an unethical hacker can leave if you don&#8217;t.</p>
<p><strong>Roles in IT Security</strong><br />
What if you don&#8217;t think hacking is for you?  Hacking is rewarding, but there are other <a href="http://socialspark.com/metrics/click/post?slot_id=36467&#038;url=http%3A%2F%2Furlbrief.com%2F98d904" rel="nofollow">IT Security</a> roles that can also be very rewarding and they all pay well.  Some of these include pro-active positions like Security Awareness, Security Fundamentals, Advanced Penetration Testing and Application Security as well as some more re-active roles like Disaster Recovery (be the hero), and Computer Forensics (see my post tomorrow for a great real-life example of this from what I dealt with today).</p>
<p>One thing many online classes seem to miss is that a lot of people benefit vastly from the interaction with an actual instructor that a class room environment offers.  These guys know that better learning comes from the ability to talk to a real live instructor and get detailed answers to unique and specific questions.  They give you access to a real person to help you along as you go.</p>
<p>It&#8217;s really a good looking package and I just have to pound the point home&#8230; Ethical hacking and IT security is just plain rewarding financially as well as in every other way.  If you&#8217;re thinking about a career in IT, you should look into this.</p>
<p> <img src="http://ad.doubleclick.net/ad/N5654.139913.9527099420421/B3455931;sz=1x1" width="1" height="1" border="0" /></p>
<map name="map2697">
<area href="http://socialspark.com/metrics/click/disclosure?slot_id=36467&#038;url=http%3A%2F%2Furlbrief.com%2F98d904" shape="rect" coords="0,0,206,45" rel="nofollow" />
<area href="http://socialspark.com/code_of_ethics" shape="rect" coords="207,0,225,45" rel="nofollow" /></map>
<p><img alt="Post?slot_id=36467&#038;url=http%3a%2f%2fsocialspark" border="0" src="http://socialspark.com/metrics/view/post?slot_id=36467&#038;url=http%3A%2F%2Fsocialspark.com%2Fimages%2Fdisclosure_badges%2Fdisclosure_badge_grey.png" style="border:0" usemap="#map2697" /></p>


<p>Related posts:<ol><li><a href='http://www.joetech.com/how-to-hack-a-person/' rel='bookmark' title='Permanent Link: How to Hack a Person'>How to Hack a Person</a></li>
<li><a href='http://www.joetech.com/gawker-media-hack-is-a-password-reminder/' rel='bookmark' title='Permanent Link: Gawker Media Hack Is A Password Reminder'>Gawker Media Hack Is A Password Reminder</a></li>
<li><a href='http://www.joetech.com/omg-ashley-marc-james-is-a-virus/' rel='bookmark' title='Permanent Link: OMG! Ashley Marc James is a Virus!!!'>OMG! Ashley Marc James is a Virus!!!</a></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.joetech.com/get-paid-to-hack/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>How to Crack the Account Password on Any Operating System</title>
		<link>http://www.joetech.com/how-to-crack-the-account-password-on-any-operating-system/</link>
		<comments>http://www.joetech.com/how-to-crack-the-account-password-on-any-operating-system/#comments</comments>
		<pubDate>Fri, 30 Jan 2009 01:22:39 +0000</pubDate>
		<dc:creator>Joe Tech</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[ophcrack]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[username]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.joetech.com/?p=610</guid>
		<description><![CDATA[This guest post was written by Blair Mathis from LaptopLogic.com &#8211; your premier source for the latest laptop software news and best laptop accessories. Computer passwords are like locks on doors &#8211; they keep honest people honest. If someone wishes to gain access to your laptop or computer, a simple login password will not stop [...]


Related posts:<ol><li><a href='http://www.joetech.com/gawker-media-hack-is-a-password-reminder/' rel='bookmark' title='Permanent Link: Gawker Media Hack Is A Password Reminder'>Gawker Media Hack Is A Password Reminder</a></li>
<li><a href='http://www.joetech.com/how-to-reset-your-password-on-vista-with-the-help-of-a-usb-flash-drive/' rel='bookmark' title='Permanent Link: How To Reset Your Password on Vista with the Help of a USB Flash Drive'>How To Reset Your Password on Vista with the Help of a USB Flash Drive</a></li>
<li><a href='http://www.joetech.com/how-to-crack-pdf-passwords-in-your-sleep/' rel='bookmark' title='Permanent Link: How To Crack PDF Passwords In Your Sleep'>How To Crack PDF Passwords In Your Sleep</a></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.joetech.com/suggests/thuh" title="learn-how-to-hack.net"><img src="http://farm4.static.flickr.com/3378/3443681448_3ddc22e012_o.gif" border="0" alt="Learn How To Hack" title="Learn Hacking"  /></a></p>
<p><em>This guest post was written by Blair Mathis from LaptopLogic.com &#8211; your premier source for the latest <a href="http://laptoplogic.com/laptop-accessories/laptop-software">laptop software</a> news and best <a href="http://laptoplogic.com/laptop-accessories">laptop accessories</a>.</em></p>
<p>Computer passwords are like locks on doors &#8211; they keep honest people honest. If someone wishes to gain access to your laptop or computer, a simple login password will not stop them. Most computer users do not realize how simple it is to access the login password for a computer, and end up leaving vulnerable data on their computer, unencrypted and easy to access. </p>
<p><a href="http://www.joetech.com/suggests/thuh" title="Password image by nodomain1, on Flickr"><img src="http://farm4.static.flickr.com/3418/3238029478_aa1df44c98.jpg" width="400" height="300" alt="Password image" /></a></p>
<p>Are you curious how easy it is for someone to gain access to your computer? If so, read on to see the technique one might use to figure out your computer password. </p>
<p><strong>Windows</strong><br />
Windows is still the most popular operating system, and the method used to discover the login password is the easiest. The program used is called <a href="http://ophcrack.sourceforge.net/">Ophcrack</a>, and it is free. Ophcrack is based on Slackware, and uses rainbow tables to solve passwords up to 14 characters in length. The time required to solve a password? Generally 10 seconds. The expertise needed? None. </p>
<p><a href="http://www.joetech.com/suggests/thuh" title="ophcrack by nodomain1, on Flickr"><img src="http://farm4.static.flickr.com/3423/3237188885_1527db4c72_m.jpg" width="180" alt="ophcrack" align="right" valign="top" /></a>Simply download the Ophcrack ISO and burn it to a CD (or load it onto a USB drive via UNetbootin). Insert the CD into a machine you would like to gain access to, then press and hold the power button until the computer shuts down. Turn the computer back on and enter BIOS at startup. Change the boot sequence to CD before HDD, then save and exit. </p>
<p>The computer will restart and Ophcrack will be loaded. Sit back and watch as it does all the work for your. Write down the password it gives you, remove the disc, restart the computer, and log in as if it were you own machine. </p>
<p><strong>Mac</strong><br />
The second most popular operating system, OS X is no safer when it comes to password cracking then Windows. </p>
<p>The easiest method would be to use Ophcrack on this, also, as it works with Mac and Linux in addition to Windows. However, there are other methods that can be used, as demonstrated below.</p>
<p>If the Mac runs OS X 10.4, then you only need the installation CD. Insert it into the computer, reboot. When it starts up, select UTILITIES > RESET PASSWORD. Choose a new password and then use that to log in. </p>
<p>If the Mac runs OS X 10.5, restart the computer and press COMMAND + S. When at the prompt, type:</p>
<p><strong>fsck -fy</strong></p>
<p><strong>mount -uw /</strong></p>
<p><strong>launchctl load /System/Library/LaunchDaemons/com.apple.DirectoryServices.plist</strong></p>
<p><strong>dscl . -passwd /Users/UserName newpassword</strong></p>
<p>That&#8217;s it. Now that the password is reset, you can login. </p>
<p><strong>Linux</strong><br />
Finally, there is Linux, an operating system quickly gaining popularity in mainstream, but not so common you&#8217;re likely to come across it. Though Mac and Linux are both based on Unix, it is easier to change the password in Linux than it is OS X. </p>
<p>To change the password, turn on  the computer and press the ESC key when GRUB appears. Scroll down and highlight &#8216;Recovery Mode&#8217; and press the &#8216;B&#8217; key; this will cause you to enter &#8216;Single User Mode&#8217;. </p>
<p>You&#8217;re now at the prompt, and logged in as &#8216;root&#8217; by default. Type &#8216;passwd&#8217; and then choose a new password. This will change the root password to whatever you enter. If you&#8217;re interested in only gaining access to a single account on the system, however, then type &#8216;passwd username&#8217; replacing &#8216;username&#8217; with the login name for the account you would like to alter the password for. </p>
<p><strong>Conclusion</strong><br />
There you have it &#8211; that is how simple it is for someone to <a href="http://www.joetech.com/suggests/thuh">hack</a> your password. It requires no technical skills, no laborious tasks, only simple words or programs. The moral of the story? Encrypt your data to keep it safe. Don&#8217;t use only a password, but actually encryption, such as Blowfish or AES-128. There are a number of programs that can do this &#8211; TrueCrypt for Windows, or the native encryption found on Ubuntu, creating a disk image in Mac, etc.</p>


<p>Related posts:<ol><li><a href='http://www.joetech.com/gawker-media-hack-is-a-password-reminder/' rel='bookmark' title='Permanent Link: Gawker Media Hack Is A Password Reminder'>Gawker Media Hack Is A Password Reminder</a></li>
<li><a href='http://www.joetech.com/how-to-reset-your-password-on-vista-with-the-help-of-a-usb-flash-drive/' rel='bookmark' title='Permanent Link: How To Reset Your Password on Vista with the Help of a USB Flash Drive'>How To Reset Your Password on Vista with the Help of a USB Flash Drive</a></li>
<li><a href='http://www.joetech.com/how-to-crack-pdf-passwords-in-your-sleep/' rel='bookmark' title='Permanent Link: How To Crack PDF Passwords In Your Sleep'>How To Crack PDF Passwords In Your Sleep</a></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.joetech.com/how-to-crack-the-account-password-on-any-operating-system/feed/</wfw:commentRss>
		<slash:comments>149</slash:comments>
		</item>
		<item>
		<title>How to Hack a Person</title>
		<link>http://www.joetech.com/how-to-hack-a-person/</link>
		<comments>http://www.joetech.com/how-to-hack-a-person/#comments</comments>
		<pubDate>Thu, 24 Jan 2008 01:21:57 +0000</pubDate>
		<dc:creator>Joe Tech</dc:creator>
				<category><![CDATA[Communication]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[Just Cool]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[phising]]></category>
		<category><![CDATA[social engineer]]></category>
		<category><![CDATA[trick]]></category>

		<guid isPermaLink="false">http://www.joetech.com/2008/01/23/how-to-hack-a-person/</guid>
		<description><![CDATA[Most people are a familiar with the term &#8220;hacking&#8220;. In general, it refers to gaining unauthorized access to a computer. One definition from m-w.com is &#8220;to gain access to a computer illegally&#8221;. To me, hacking refers to gaining unauthorized access to information. I&#8217;m not going to explain how to hack a computer. Instead, I&#8217;m going [...]


Related posts:<ol><li><a href='http://www.joetech.com/gawker-media-hack-is-a-password-reminder/' rel='bookmark' title='Permanent Link: Gawker Media Hack Is A Password Reminder'>Gawker Media Hack Is A Password Reminder</a></li>
<li><a href='http://www.joetech.com/real-life-sims-control-a-live-person-via-the-web/' rel='bookmark' title='Permanent Link: Real Life SIMS: Control a Live Person Via the Web'>Real Life SIMS: Control a Live Person Via the Web</a></li>
<li><a href='http://www.joetech.com/get-paid-to-hack/' rel='bookmark' title='Permanent Link: Get Paid To Hack'>Get Paid To Hack</a></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Most people are a familiar with the term &#8220;<a href="http://www.stephanmiller.com/the-refresh-georgian-hacker/">hacking</a>&#8220;.  In general, it refers to gaining unauthorized access to a computer.  One definition from <a href="http://www.m-w.com">m-w.com</a> is &#8220;to gain access to a computer illegally&#8221;.  To me, hacking refers to gaining unauthorized access to information.  I&#8217;m not going to explain how to hack a computer.  Instead, I&#8217;m going to talk about how to hack a person, or, how to gain information from a person that they would not otherwise provide.  This is also widely known as &#8220;<a href="http://en.wikipedia.org/wiki/Social_engineering_(security)">social engineering</a>&#8220;.</p>
<p><img src='http://www.joetech.com/wp-content/uploads/2008/01/burlgar.jpg' alt='burlgar.jpg' alt="Computer and Internet Security" /></p>
<p><strong>Get to know your mark</strong><br />
A mark is simply the victim of your information theft.  While you may have valid, legal, motives for sneaking around normal channels, I&#8217;ll refer to the target as your &#8220;mark&#8221; because I&#8217;m lazy.</p>
<p>Social engineering often involves pretending to be someone you are not.  Many times, you may need to pretend to be a client, for example, in order to get their password from their domain registrar or internet service provider.  You may have other, more sinister, motives for gathering sensitive data, too.  Either way, you will need to be prepared with answers to key questions, appropriate reactions, etc.  Research all the information you can about whatever you are trying to get access to as well as the person you are claiming to be (where applicable).  For example, if you were to call a large ISP, attempting to get the password to your mark&#8217;s email account, you would want to know his or her full name, email address, and birth date at a minimum.  Other helpful things to know are names of the girl/boyfriend, spouse, child, pet, etc., hobbies, bands or stars the person likes, and anything else very personal.  More often than not, one of these things is the answer to your mark&#8217;s &#8220;hint&#8221; question, that question they ask you before divulging your password when you&#8217;ve forgotten it.  Sometimes, that one word is all you need.</p>
<p><strong>Some alarming facts</strong><br />
Around 2-4% of all people have a password of &#8220;password&#8221; or a pin/security code of &#8220;1234&#8243;.  Many of the rest have passwords that can be found in a dictionary file (a file full of dictionary words used for guessing a password randomly).  If your mark is 16 and her boyfriend is named Mark (but she calls him &#8220;markypoo&#8221; all over her MySpace page), you might be able to skip all the dirty work by just trying &#8220;mark&#8221;, &#8220;markypoo&#8221;, &#8220;ilovemark&#8221;, or &#8220;ilovemarkypoo&#8221; as her password.  Just about every demographic seems to fall under the rule that you can usually guess a password within about 20 tries if you get to know the owner of the account.  Some more clues that can help are birth dates, nicknames, sports teams, and movie/tv charaters.  Know your mark (above) and the rest is pretty easy.</p>
<p><strong>Get to know your source</strong><br />
When I say &#8220;source&#8221;, I mean the source of your information.  This could be anything from an automated web form to a phone support representative, to a front desk employee at a hotel.  The type of information you are looking for should dictate what your source is and is should be fairly obvious to you.  Pretend, for a second, that you&#8217;re looking for that email password from above.  Logic dictates that your source is going to the your mark&#8217;s ISP.  Become a customer, client, or user.  Sign up for an email account of your own and make note of the security questions.  Test the password entry form and see if it has a minimum/maximum amount of characters or has any other requirements.  Does the site suggest a username for you like Yahoo! does (eg: JohnDoe2008)?  Any information you can glean through creative and thoughtful experimentation can be instrumental in your success.</p>
<p><strong>Confidence is key</strong><br />
You&#8217;ve probably heard that before, but in another context.  It&#8217;s a popular phrase when talking about sales or success in business.  Confidence can drive your job interview home, it can get you sales, and it can even get you a date, but it can also be the key ingredient when trying to con a source out of information.  If you act nervous in your efforts, it will likely get noticed and make your source suspicious.  Speak clearly, act casual, and act like you&#8217;re supposed to get the information you&#8217;re asking for.  Many times, you can even act as if you were waiting for a third party (whose name you now forget) to call you back with that information.  Begin a support call by saying &#8220;I somehow got disconnected.  I called in because I forgot my password and I forget who I spoke to, but he asked me the security questions and then the call dropped.&#8221;  If you gently suggest to your source that another person in the company trusted your authority to access a password and was about to give it to you, this will sometimes lower their guard just enough to squeak by.</p>
<p><strong>Confident does not mean sloppy</strong><br />
Sometimes you are acting in the best interest of someone who knows what you&#8217;re doing, but what if you&#8217;re just trying to snoop through someone&#8217;s email or you want to throw a surprise party for someone and just need to grab their contact list from their gmail account?  If you don&#8217;t want anyone to know what you&#8217;re doing, you had better not leave a trail behind you.  Getting caught can be embarrassing and get you into trouble with your mark.  Worse, if you&#8217;re doing what I think you shouldn&#8217;t be, you could get jail time.  That said, here&#8217;s some things to think about before you begin:</p>
<ul>
<li>- Don&#8217;t use your real name&#8230; anywhere</li>
<li>- If using the phone, block your number</li>
<li>- If using the web, go through a proxy (from a library)</li>
<li>- If using email, get a throwaway email account and check via web mail (from the library)</li>
<li>- Know the legality of what you&#8217;re planning</li>
<li>- Try not to break the law if possible</li>
</ul>
<p>The more careful you are, the less you have to worry about, and the more confident you can be when faced with the human interaction.</p>
<p><strong>Get more than information</strong><br />
People-hacking works for more than just snooping on your ex-girlfriend&#8217;s email (stop obsessing and get over her).  You can also work out discounts and deals by knowing how to deal with a particular source.  Here&#8217;s <a href="http://www.schneier.com/blog/archives/2007/09/how_to_get_free.html">an easy experiment</a> you can do: Call a fast food joint on a weekday afternoon (right during the busy lunch time) and explain that your order was messed up.  Your complaint should be believable, but bad enough that your meal was practically not edible to you.  Say they put ketchup on your burger after you asked for no ketchup.  Know ahead of time what you ordered (a popular combo meal will probably have been ordered in the last hour by someone at the drive-thru, making it more plausible).  Almost every time, they will write down your first name (which can be any name you want to give them).  The next day, show up and explain that you were told you would get a complimentary meal for the one they messed up.  Give them the name you gave over the phone, order the same meal, and enjoy eating for free.  I can&#8217;t publicly condone doing this, so if you happen to try it for the purpose of experimentation, even the score by donating $6 to charity or something.</p>
<p>There are many morally valid and many morally corrupt reasons for needing to obtain information, goods, or services via unconventional means like social engineering.  Whatever your reason, identify what you want, plan it out, and go get it.</p>


<p>Related posts:<ol><li><a href='http://www.joetech.com/gawker-media-hack-is-a-password-reminder/' rel='bookmark' title='Permanent Link: Gawker Media Hack Is A Password Reminder'>Gawker Media Hack Is A Password Reminder</a></li>
<li><a href='http://www.joetech.com/real-life-sims-control-a-live-person-via-the-web/' rel='bookmark' title='Permanent Link: Real Life SIMS: Control a Live Person Via the Web'>Real Life SIMS: Control a Live Person Via the Web</a></li>
<li><a href='http://www.joetech.com/get-paid-to-hack/' rel='bookmark' title='Permanent Link: Get Paid To Hack'>Get Paid To Hack</a></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.joetech.com/how-to-hack-a-person/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
	</channel>
</rss>

