Wednesday, May 18, 2011
Hack Blogger
Here's the link for your perusal.
http://www.nirgoldshlager.com/2011/03/blogger-get-administrator-privilege-on.html
Hacking a Password Protected Iphone
For those who may or may not know, it’s possible to setup a password on your iphone. This way, if someone gets their hands on your phone, they wont have access to any of your information. Now a way to bypass that password has surfaced. By pressing certain things in sequence on the emergency call screen, a thief can gain access to all of your contacts, voicemails, and history. They don’t get access to the rest of the phone, but I think we can agree that your contacts and voicemails are most important to keep private.
Below is the video I found in a link on twitter. Go ahead and try the hack on your own iphone, I did :) If you get stuck and can’t back out of the screen, just call a phone number and then cancel it. This will send you back to the passcode screen.
—-Update: This trick only works on iphones that are currently up to date. Tried to show a friend yesterday and it didn’t work because their iphone had never even been updated—
[youtube=http://www.youtube.com/v/ugADxS5ol48?fs=1]
Firesheep, Sidejacking Made Easy
Toorcon, a network and computer security conference, was just last weekend. Over the past few days, the internet has gone crazy over a new firefox extension, Firesheep, that was unveiled there. You wont be able to find Firesheep where you typically get all of your firefox extensions, but you can download it on the authors website at http://codebutler.github.com/firesheep/
So why has this extension taken over the internet by storm? And by storm, I mean over 120,000 downloads, and news stories about this tool on every news website I typically visit. Firesheep is a one click, simple (except for some windows users) way to hijack someone’s facebook, twitter, etc. If your on a local wifi, you’re probably susceptible to getting your accounts broken into. This is because most local wifis are unencrypted or at least running WEP (which is also susceptible).
What is sidejacking? Sidejacking is a technique used to gain access to a victims online account without needing to find their username or password. This is made possible by grabbing a users cookie. You have probably heard or seen cookies when cleaning them out in your browser. A cookie is what keeps your signed in to your account. Without it, you would have to keep logging in everytime you visited a different webpage. Cookies are also used with the shopping carts seen on websites; that’s how it remembers what you ordered. So cookies are very useful in the online world. The main problem is that most sites don’t encrypt them. A website, like facebook, will encrypt your login information but will send you the cookie unencrypted. Over a wireless network, it’s just simple prey floating through the air, just waiting for another attacker like firesheep to grab it.
The picture to the right is firesheep in action. Firesheep sits in the bar at the left, and sniffs port 80 (unless otherwise specified) for all of those yummy cookies. As it finds them, it lists the victims name, pic, and what website they’re on. You can double click one of the listed sites, and the session will appear in the window to the right, already open and logged in.
Google is safe, somewhat, against this type off attack. They have actually deployed SSL for everything on their site as of last December. I myself have always been told that running SSL on everything is a complete waste and takes way to much computing power. Google has stated that they only see a 2% increase in CPU usage and feel that everyone should move to using SSL on everything and not just the login. For smaller companies with one server, this is hard, but for big companies like Facebook, Twitter, and Hotmail…. you need to pick up the slack!
Pictured to the left is the preferences menu inside of Firesheep. You need to specify which device to do the sniffing on. I had some problems myself with the wireless sniffing, mainly due to windows. Your card needs to be put into a passive mode in order to sniff packets. In windows, this is a pain in the butt to do. You have to have winPcap downloaded, but sometimes that doesn’t solve the problem for you. I’m waiting for the linux one myself, so I can load this up into Ubuntu. At least there, it’s possible to put my card into the passive mode.
If you want to read more on Firesheep, check out the authors website here
Again, you can download it on his website here
You can also download winPcap here
If you’re interested in sidejacking in general. There is another cool tool called Hamster and Ferret. It’s a little more complicated than Firesheep, and requires man in the middle, but it’s another tool to try out.
Wednesday, January 06, 2010
Jailbroken Iphone

The above pic shows some of the programs I've used in jailbreaking my iphone, like blackra1n and cydia. The terminal in the pic is used to change your default root password
I don't know why it's taken me so long to jailbreak my iphone being as curious as I am. I think it was the scare of bricking my only phone aka lifeline :) , that has kept me from doing it. The thought of playing mario and older NES games on my iphone is what one me over. Plus I read up on some things to do at the command line that I found really intriguing.
If you are considering jailbreaking your iphone, think about why you want to do it first and if it's possible to do without jailbreaking. It's awesome to have an open and "FREE!" iphone, but it's now also open to more security threats. Not to mention that you may end up turning your iphone into a fancy paperweight.
If I haven't scared you yet, and you still want to jailbreak your iphone, I'll point you to some of the sources that I used when Jailbreaking my iphone. Now mind you my iphone is version 3.1.2. If you are an older version of iphone you may want to update it before applying the hack. There have been reports of problems where iphones that were jailbroken, not working after the update.
I used a program called Blackrain to jailbreak the iphone. It's very simple to do and was in fact done from a computer that wasn't my main one. Firstly have your iphone connected to your computer with it's cord. Then download and run the blackrain program. A simple box with one button will open up...click the button. Voila your phone is cracked :) yes that simple.
Now your phone is going to reboot, and you will notice that the blackra1n pic shows while your iphone loads.. don't panic and yell hax! it's ok. When your iphone is finally booted all the way up and you are logged in; you will find an application titled blackra1n. Go ahead and run that app. It will give you 3 options, select hacker. You will need the command line to change your root password later. When it came to packages, I downloaded the cydia package. You also have the option here to unlock your iphone so you can use it on different carriers other than ATT
Your basically done and free to do whatever you want with your phone. I recommend you poke around the packages and find things to install and play with. I also have links at the bottom of this post that you should look through. They talk about securing your iphone now that you've made it a little more vulnerable.
blackra1n website
securing your iphone article
changing your root password here
happy cracking
if you need any help, feel free to ask in the comments.
Thursday, October 22, 2009
SSL (security socket layer)

SSL, what is that? Have you ever noticed while browsing the web, the 's' in https://etc.etc. When the s is sitting there, that means you are using an encrypted connection. So all data you send out to the web server is locked, and the website has the only key to unlock it. This is really nice when doing online banking, as you don't want anyone listening on your network trying to intercept your banking data. If a hacker is on your network, listening to all of your internet traffic, he wont be able to read the data when you are using SSL.
Well there exists a little vulnerability with all web browsers, that can make you think you are secure, while you're actually not. Sometimes a website wont give you the s at the end of the http until you go to login. You may think that's secure because your data is now being encrypted, but that damage has already been done when you visited the site without the s. A hacker can sit between you and the website, a man in the middle, and intercept all data between you and that website. When you first visit the website, you send the request to the hacker, who forwards it onto the website, who then responds back to the hacker, and the hacker forwards the response to you. So when you click that secure login, you actually tell the hacker you want the secure login, who then talks to the website and gets himself a secure login. He/she then spoofs a secure login back to you, so that you are thinking all of your data is being encrypted. But actually, it's as clear as day to the hacker.
So how do you stop a hacker from being the man in the middle? Well, if you had encrypted the data when you first visited the website, he would have never been able to spoof the secure login, and he'll be locked out completely.
So my advice to you, when you visit a website, no matter what site it is, hand type that s at the end of http and press enter. Most websites support SSL, but you'll be surprised how many don't automatically load with it. Gmail doesn't use SSL unless you set in the options that you want it to. Another suggestion of mine to save you from hand typing that s in all the time, is to bookmark the page with the s in it. That way every time you click the bookmark, you automatically go to the page using SSL.
I implore that anyone reading this, whenever visiting a site that contains personal information, or takes a login and password. Especially when you are on a public hot spot, like star bucks. In one day, it has been possible to record as many as 1200 different pieces of personal information off of a public wifi. That was simply a person sitting with a computer running software, that listens to the net chatter. It could have been negated if people would be using the SSL.