Tutorial: Create An Auto Hack USB Drive {via IronGeek}

13 10 2007

Hot off the presses from IronGeek (so you know its good):

Creating An Auto Hack USB Drive Using Autorun and Batch Files. By Dosk3n (Hacking Illustrated Series)

During 2005 Sony BMG was discovered to be including Extended Copy Protection (XPC) and MediaMax CD-3 software on music CDs. The software was automatically installed in the background onto users computers systems that used the autorun function to start running the CD. The software could hide itself from the computers process list in the same way a rootkit would. There was over 100 titles in total that included this “rootkit”. Using similar techniques we are going to use the autorun feature with a USB drive to run multiple hacking tools…

As part of IronGeek’s “Hacking Illustrated Series”, this tutorial is a video (by Dosk3n).  Go watch it over at IronGeek (pro tip – click the article title).  There’s even a download link so you can watch it at your leisure over and over again.

Big ups to IronGeek and DosK3n on the tutorial and the sweet sweet “turn their own weapons against them” intro.

Enjoy.





File This Under, “I Wish I Thought Of That First”

12 10 2007

Just a quickie:

Security vuln auction site pulls in research | The Register
A controversial marketplace for security exploits and vulnerabilities said it has exceeded expectations with the submission of more than 150 vulnerabilities in its first two months of operations.

WabiSabiLabi encourages security researchers to sell their findings to vetted buyers. Herman Zampariolo, chief exec of WSLabi which runs the WabiSabiLabi marketplace, said that the quality of the submitted vulnerabilities is as important as their quantity.

Damn, that site is going to make some big money.  At the same time those vulnerabilities and exploits might actually never be used with malicious intent.  Especially if the big tech companies are the ones buying.

This is straight from their website:

WabiSabiLabi is aiming to a single moving target: to bring the world closer to zero risk.
If the world must become a safer place, the first part of the recipe is simple: to provide a better rewarding for the security researchers, organising an efficient and transparent marketplace, here to maximise the results of their efforts.

Damn I wish I had thought of that first.





RNC Got FARKED!! (Pix)

11 10 2007

A friend passed this one to me and I just couldn’t resist passing it on:

[via] Fark Logo
The Republicans unveiled their new national convention logo. Design something better in five minutes.
KellyLockhart [TotalFark]

The ‘O’fficial design

THEN THE FUN STARTS!!  Here are my favorites so far.

 200 yrs of tradition by Godscrack

WWRJD? by butthold

And those are just two of many many entries that all deserve to win.  Go see them all here: 
http://forums.fark.com/cgi/fark/comments.pl?IDLink=3112814

nJoy L8s





Ha.ckers.org on: De-anonymizing Tor, or any HTTP Proxy

8 10 2007

Just a heads up for all you peeps seeking anonymity and or privacy on the net. I saw this article on Ha.ckers.org – De-anonymizing Tor and Detecting Proxies

This code (it takes a several seconds to load) uses a piece of JavaScript to instantiate a Java socket call back to the origin site. In doing so it bypasses the proxy settings of the browser, allowing you to de-anonymize people using proxies. It works great for Tor or just about any HTTP proxy that I can think of. Cool stuff.

Source – ha.ckers.org web application security lab

Daaaaaaamn!!  That’s some scary shit for those of us just trying to keep a bit of privacy on the net.  Some of us just want to look at some titties without the whole net following us around.  Some of us want to study some information perceived clandestine by our governments. (Note: Germany just made posting penetration testing tools illegal!! See Darknet)

There’s alot of information to cover here and some of it just plain confused me at first, so I summarized what I saw as potential  bullet points in the article.

Follow the jump to read the rest: Read the rest of this entry »





California Community Says Companies Are Not People

7 09 2007

Common Sense Prevails Against All Odds!!!

Source AlterNet (please read the WHOLE article)
In 2006, Humboldt County, California, became the latest, and largest, jurisdiction to abolish the legal doctrine known as “corporate personhood.”

Measure T [The Referendum’s Legal-speak Name] was successful because our all-volunteer campaign came together to pass a law that bans non-local corporations from participating in Humboldt elections. The referendum, which passed with 55 percent of the vote, also asserts that corporations cannot claim the First Amendment right to free speech.

By enacting Measure T, Humboldt County has committed an act of “municipal civil disobedience,” intentionally challenging “settled law.” But voters also recognize that Measure T is an act of common sense.

The gears of the American Legal system may work slowly, but they are still in fact working.   Three cheers for the people of Humboldt County!!

This is living proof that governments should be afraid of their people.  Now all we need is for the rest of America to wake up and use common sense.

Keep fighting that good fight!