CBT Response

29 06 2008 Hacking

Since I wasn’t able to catch the commenter before they went offline I will leave it anonymous but they make a good point about my Crazed Bovine Traversal post:

In response to your “Crazed Bovine Traversal” blog post, a ringtone virus would likely depend upon some sort of code execution bug in the audio parsing code of the mobile device. Propagation could simply be done via text messaging or web site. It’s possible but to be honest sort of unlikely that it would last long. Most exploits for these types of vulnerabilities would be targeted towards a specific mobile device but you could always do something like...

-- Anonymous

The response was never completed, but I would like to pose this question. Wouldn’t it be a specific mobile OS not just a specific device? I mean, how often does your phone say. “Patch available, press here to update”. Not to be cynical, but even Microsoft Windows gets updates faster than most phones. I have absolutely no knowledge of how a mobile OS works or the versioning behind them. So please correct me if I am wrong. To be honest, the iPhone, from what I have seen, gets more updates than Windows Mobile and Blackberry combined. I mean just search for Blackberry 4.3 and AT&T. That update has been out for something like a year, and AT&T still won’t release it to it’s customers.

 


Hacker steals Quake

29 06 2008 Breaking News

On a Dutch news site there was a story about a hacker that stole 50,000 credit cards (well, the information at least) and also stole a prerelease version of Quake Wars. What do you think made the title line? Quake Wars. That puts things in perspective on what is impotant. Big companies like the one that made Quake Wars have the liquid budget to chase this guy down, but the 50,000 individuals don’t.

Is it bad that my sole thought after reading this article is wondering how he got into the Id Software servers?

Source: HERE

In other hacker news,

 


Interactive Mode SUDO

27 06 2008 Archiving

So, I made a new category basically for posts that I want to keep for myself and also post for other people not to have as hard a time finding: Archiving.

In Ubuntu I have always set a password for root and “su -” up to root to run things that needed root access. Well after watching IronGeek’s latest video on Labrea (click here to watch the video). I gleaned a new way to get to a root prompt without having to set a password and su up each time. He called it SUDO Interactive mode. And al you do is:

sudo -i

That’s it, and you are good. Just thought I would share.

 


Network Security Projects Using Hacked Wireless Routers

24 06 2008 Pimping

Just wanted to pimp Paul from PaulDotCom’s class coming up here shortly. Also, to register go to  http://www.pauldotcom.com/sans  and help their podcast out.

SANS Institute - SANSFIRE 2008

Wednesday, July 23, 2008 : 9am - 5pm
Paul Asadoorian, Defensive Intuition
6 CPE Credits

Maltego Goes Communal

23 06 2008 Pimping

Now that everyone and their mother has posted about Back|Track Final being released I feel that I am safe in disclosing that information. But on to the topic, with said release, the folks over at Paterva have released a “Community” edition of Maltego. Straight from the horses mouth, here are the limitations:

Limitations

The Community Edition is limited in the following ways:

  • A 15second nag screen
  • Save and Export has been disabled
  • Limited zoom levels
  • Can only run transforms on a single entity at a time
  • Cannot copy and paste text from detailed view
  • Transforms limited to 75 per day
  • Throttled client to TAS communication

Also, directly on the heals of this release is a community forums! Which haven’t quite been linked to from the main site, but I HAVE AUTHORIZATION THIS TIME!... not going to make the same mistake twice. Anyways, go check it out.