Thursday, May 24, 2012

Sunday, April 1, 2012

Total Recall Remake




Are they doing this? Is this really happening? You know, the trailer looks great. It's got some of my favorite actors in it (Jessica Beil, John Cho), the special effects look outstanding, it's got an even more dystopian flavor, and, just from this trailer, I see that there are a lot of cyberpunk themes in there too. (Pay attention, Steven Spielberg, because if you screw up Ghost in The Shell, so help me God, I will find you...)

But FUCK YOU Hollywood! There is nothing wrong with Total Recall! Arnold pulled that Christmas tree light out of his nose and there was a chick with a third breast made out of Papier-mâché and it was perfect!

You know what? It looks like it's gonna be good, so you know what I'm gonna do? You know what I'm gonna do, Hollywood? I'M GONNA DOWNLOAD IT! I'M GONNA WATCH IT FOR FREE AT A FRIEND'S HOUSE! I'M GONNA WAIT 'TILL IT COMES OUT ON TELEVISION!

Did that writer's strike really screw you so badly that you can't write a new movie? Not one?

Suck my balls, Hollywood. And while you're at it, suck Arnold's too.

Looks like a sweet movie, though. It's gonna be pretty good.

Sunday, March 18, 2012

So dude climbed up this mountain back in the day to see this Kung Fu master. He meets him, and he's all like "Peep dis, hommie: I've been to every dojo in the valley and have mastered every style. I've become the best fighter around. I've heard everyone say yours is the best Kung Fu, son, so i came all the way up this mountain so you can teach me yo!"

The old man at the top of the mountain pondered this young man's story, and was a little freaked out that the young traveller didn't speak at all like some one from eleventh century China, but thought 'Whatevs' and put some tea on.

The young guy said "Hey, man, why are you making tea? We gots ta get our Kung Fu on!"

But the old man replied "Chill out, slick. We gonna get our drank on with some of this pimp-tea!"

The old man poured tea into the cup he had placed out for the young man, but it overflowed from the cup and splashed into the traveller's lap.

"WHAT THA FUCK, B?!" the young man exclaimed. "Aww hell naw!" And he ran back down the mountain, holding his pants out away from his crotch to keep the scalding hot tea away from his balls. "This crazy-ass fool burned mah junk..." he muttered to himself as he waddled away. He kinda looked like a kid that pee'ed his pants, you know. Waddle waddle.

Look, this isn't how the story really goes. It's late, and there's a helicopter and an airplane that keeps circling around, like there's some crazy shit going down right now. Plus, I'm really sick, so I'm not gonna fix the story.

Sorry

Goodnight.

Go to sleep, now.

I'm not sorry.

Wednesday, February 29, 2012

WEP at a doctor's office?

In light of some recent events, I'm going to do my token "Full-Disclosure" blog entry right now. I'm going to discus the dangers of using Wired Equivalent Privacy, or WEP, to secure a WiFi access point. WEP is now fully depreciated, has been for some years, and more detailed explanations are vast on the 'net. My hope is that some one will read this, and then think twice about implementing WEP.

Side note: WEP does have its place, and I'll get to that.


Imagine, if you will, a doctor's office. Now, imagine a disgruntled divorcee. (Warning, the divorcee's language is very NSFW. If you're reading this line, then the NSFW content is already visible on your screen. lol)


    "I fucking hate that bitch! She got everything in the divorce! The house... the kids... my Corvette... I even lost my job and half my friends! I want her life to be as ruined as mine! I want her to lose her job! Now, I know you can to all that 'hacker' stuff. I want you to ruin her employer's network so they go out of business or get in trouble or something. I want revenge. I'll pay you a thousand dollars!"

Not at all a far-fetched scenario. And, if I'm, hypothetically speaking, taking the place of the nefarious individual with whom the divorcee is speaking, all I heard was "...a thousand dollars".

Now lets hear from our hypothetical bad guy hacker cloak and dagger whatever.


    "Dude, it was hella easy. All I had to do was spend a few hours in the parking lot across the street. I connected a USB WiFi dongle to a USB extension cord so I could run it out my moon roof. Then booted up BackTrack and, well, I'm not some damned skiddie, but I wanted to be as fast as possible, so I used Kismet to locate their WiFi, used Gerix to crack their WEP key, and the rest was pretty easy. They thought that they were playing it safe by requiring users to authenticate to a Radius server, but not really. I just changed my MAC address to one of the devices already authenticated - I think it was a Cisco VOIP phone - to prevent the network from booting me every five minutes. Then I just did a little ARP Poisoning with Ettercap causing a copy of all network traffic to be routed to my laptop. Then I opened up Wireshark to record all of the data. Later on, at home, I reassembled that captured traffic, and actually got some fascinating stuff. Some emails, a couple phone calls, x-rays, cat scans, ultra-sound, and just a TON of transcriptions destined for patient's charts. I gave this info to my dude, who gave me the grand he promised"
"What happened next?" we  ask our shadowy fiend.

    "I gave him his info, he gave me my money... I'm not exactly sure what he did with it, since I don't really care, as long as I got paid... But... I do remember hearing something in the news about that place. Yeah, they had some 'hippa' violations, and got sued by a bunch of patients. They settled out of court, but that's not what put them out of business. I guess that after this happened, their physicians couldn't get any malpractice insurance, and had to give up their doctoism, or something. Everyone lost their jobs."

"What did you do with the money?"

    "I used to to buy a motorcycle."


See? See why WEP is a terrible idea when security is your goal? Don't use WEP, unless you want to get in trouble, and let some black-hat hacker buy a motorcycle via your hardship and woe.

Why would anyone ever want to use WEP? Well, it's kind o a psychological thing, really. Think of it as a property marker. WPA is like a chain link or wooden fence. WPA2 is that same fence, topped with electrically charged razor wire. WEP is nothing more than a few sticks with pink spray-paint, delineating where your yard begins and ends. Some one would have to knowingly "trespass" your WiFi yard. It's like saying, I'm not really going to make sure that you can't get into my WiFi, but I'm making it well known that I don't want you there, and have legal recourse if you do break in.

That's stupid, though.

The other use that I can think of would be a diversion, like a WiFi honeypot. Set up a WEP network with some computers on it doing mundane things filled with useless or false information. Hopefully, the attacker will hack into your WEP WiFi, and ignore the one you've secured with WPA2 and made "invisible".

The most important thing we can do with WEP is use it as an example of what NOT to do, and to make jokes about it.

I like to refer to WEP as "Weak Encryption Protocol".

Final Presentation

I decided to table the blog entry I was working about liars.

Last night I had the opportunity to sit in on a presentation that some students did. This presentation was sort of the final test for them to receive their degree. It was somewhat reminiscent of a review board one may encounter in any industry.

I'd  like to offer some observations, but I won't get into any detail, because I'd rather not identify the individuals in the group - I'm not trying to criticize here.

That being said, it seems that the major challenges this group faced were challenges common to any project that requires a presentation. Specifically, I saw three major flaws with the presentation itself, and one major flaw on the material presented.

The first flaw was something inherent to public speaking, and is a difficult skill to develop if it's not something that comes to you naturally. A good deal of this group stuttered, stammered, and just plain froze-up. It happens to the best of us. However, this project was to simulate a company getting a contract. If I'm considering hiring a company to do a job, and the people sent to my office to present all seem scared and grasping for replies to my questions... yeah, they're not getting my contract.

REHEARSE! 
Rehearsing your presentation is an absolute necessity. I'm not saying that this group didn't rehearse, but they definitely stood to benefit from MORE rehearsing.

The second flaw was with their documentation. The cadre on the review board, as well as some of the spectators, brought up a couple of good points on this. One slide dealt with a particular technology. The next slide dealt with a wholly different technology, but because not the title, nor the bullet items, but the subtitle from the previous slide was erroneously carried over to the next slide, this group misrepresented two of the products involved in their service. It was clarified, but no doubt, points were taken off. It was a minor error, but the next error was not so minor. One of the other people sitting on the review board noticed a discrepancy on the cost-breakdown, one that would cost the client around $7,000. To a choosy CEO, that's possibly enough to Kibosh the entire show.

Make sure your documentation is 100% accurate!
Seems like kind of a no-brainier, and perhaps an insurmountable task, but it could be the difference between winning or losing a contract. Lose the contract, lose money. No money, no food. No food, you dead! The financial error really surprised me. The group used Microsoft Excel to make this part of their presentation. Why then, I wonder, did they not utilize the calculation features of Excel? The error occurred when certain items were removed from the list, and the total costs were updated erroneously, or not at all. When used correctly, Excel takes care of all of that for you!

Finally, there were questions asked of the group, and no answers were given, other than "Oh, I'd have to look into that and get back to you." After about the third or fourth one of these, one of the cadre replied "Yeah, I'll be expecting that answer next quarter." which is funny, because those students were supposed to be graduating this quarter.

Be an EXPERT!
There were five people in this group. While no one person could be an expert on everything in it, there should have, given the information presented, and keeping with common current affairs in their particular discipline, been zero questions that went unanswered. Again, this may seem harsh, or even impossible, but allow me to explain.

Remember that fourth error I mentioned? The one dealing with the presentation itself? Well, it had to do with security. Since network security (and compliance with HIPPA) is a huge facet of building a network from the ground up, at least one person in that group needed to become an "expert".  I'm using the word expert loosely, here. At least one person should have been able to explain what their honeypot actually does, or how they plan on defending against a DDoS, a very very common form of cyber attack. And finally, some one should have been able to defend their choice of using, of all things, WEP, to secure their WiFi.

It was clear to me that not one person in the group was an expert on security (or even knowledgeable). I'm not saying that everyone should be as focused on, *ahem* hacking, as I am, but if I'm told to present a topic on something, I had damn well better figure it out. If anyone of these people had Googles 'WEP', they would have made a better choice.

Again, I'm not trying to criticize, I'm simply stating that there were things that should have been done better - things that are not specific to anyone presentation, and are, in fact, common to all presentations.

Rehearse | Become knowledgeable (or expert) in what's being presented | Eliminate typos!


On the flip-side, the groups information that was correctly presented was pretty spot on! I'm sure that they had passed their review, and will be cleared to get those lovely pieces of paper that say "Gradamatated!" on it.

Again, while this was an IT presentation, these faux pas are common to any type of presentation. Regardless of what you're presenting, make sure not to make those basic mistakes!

Friday, February 17, 2012

High School Mischief

As I thought about how funny these two stories are (to me, anyway), I kept remembering more and more details. I thought about adding them in, and then having to clarify and stating my moral stance on things like ethics and hacking and school kids doing things on the computer that the adults don't want them to (the same adults who only knew the difference between Microsoft Works and Claris Works, and tying meccpro on the older computers would bring up WordMuncher, yadda-yadda-yadda®, and decided to just say "fuck it" and write the damn blog.

Have whatever opinions you want. I don't care what they are.

In my freshman year, I had decided that my high school, and everything in it was really out dated. I'm not going to mention the school's name, because, truth be told, it's a lot better now. There's a five and ten year gap between my younger siblings and I, and from what they've told me, the school has improved vastly. When my little brother graduated (early, w00t), they even had their own robotics and programming teams. Not too shabby.

But back in 1999, when I was 15, the only computer related classes were Intro to Computers and Intro to C++. Boring classes, but computers where one of my hobbies, so I took them. And this was before I knew anything about hacking.
  • Hacking:(computing) Playful solving of technical work that requires deep understanding, especially of a computer system.
    From hacker: "A person who delights in having an intimate understanding of the internal workings of a system, computers and computer networks in particular."


I didn't know it at the time, but by definition, I, and many of my friends, were already "hackers". Neat.

Lots of good fun that is funny!
So the school network, back in the day, ran on a network operating system called Novell. Novell sucked then, and kinda sucks now. I had heard a rumor that a student was able to get what the rumor mill was calling "admin" or "super user" access to the network. Immediately I imagined Mathew Broderick in WarGames changing his love intrest's biology grade from an F to an A. I personally would never do that (an A would be suspicious... maybe a C...) but I bet there was some fun to be had.

I thought in reverse, something that has proved invaluable to me. I went to a search engine (probably Yahoo, since I hadn't yet decided Google was right for me), and searched "How do I stop users from getting admin?" That's when I discovered The Net Plug exploit. It ran like this: I intentionally screw up my log in three times to get locked out of my account, reboot the computer, and press 'del' to get into the BIOS menu. Then I tell the teacher that my computer's messed up. The IT guy comes and boots the conmputer into Windows. At the log in prompt, I tell him I'm logged out. I tell him my username, and then run to the bathroom holding my tummy and ass. Then I have some one... we'll call him P---, run interference. He laughs and yells as run out "I told you not to eat that chili!" The IT guy logs into his account on my workstation and resets my password. I spend at least 20 minutes in the can. IT guy gets impatient, writes my temporary password down, gives it to the teacher, and tells him it is very important that I change my password as soon as I log in. As soon as the IT guy leaves, P--- unplugs the network cable to my workstation. I return, with only a few minutes of class time left, and reboot the machine. With the network cable unplugged, I select the option that allows me to  - without a password or user name - log in to the local machine. Then I plug the cable back in. Confused, Windows asks Novell what user I  am. Just as confused, Novell tells Windows that I'm the IT guy. And in true retard fashion, Novell asks Windows who I am, and Windows tells Novell that I'm the IT guy.

Guess what? Now I'm the IT guy.

Using the IT guy's account, I created several student accounts that had admin level access, and used them to create users that had teacher level access. The I changed my password, and never logged into any of those accounts I created, out of fear of being caught. They were all set to expire in December of 2003. And so it goes.

But I did use this "thinking backwards" method for more fun. In stead of searching for "How do I bypass Bessie Content Filter?", I searched "How do I prevent users from bypassing Bessie Content Filter?" And I did the same thing for Novell Messenger. These searches led me to regedit.exe, which allowed me to disable the content filter, and enable the messenger. Cool, I guess. I looked at boobs and paint ball guns and IMed other students.

"What a slacker!"

Sure, why not. Call me a slacker. Other shenanigans involved pranking some of my friends. Let's call one of them E---. It was my turn to prank E---, and I knew that the teacher of Intro to Computers has a pet-peeve; he hated when kids wrote on his dry-erase board. He also had a habit of yelling really loudly, and suffering from halitosis. So, naturally, when he wasn't looking, I wrote on the board.

I wrote: E---HAS NO WIENER!!

Then I pointed to the board and said "E---! Look what I, Tony, have done!"

He retaliated by erasing his name, and writing Tony, except before he got finished with the 'n', I yelled "MR. S----, LOOK WHAT E--- IS DOING!" And E--- had to smell Mr. S----'s perpetual fish breathe.

Then, when I became a high school upper classmen, I went to the local vocational school to study computers even more. (Better than burying my face in a history book from 1976, right?)

At the vocational school, we learned about Net Send, something more useful than Novell Messenger, since it didn't require us to change anything. Our computer teacher actually encouraged us to use it when working on assignments that allowed collaboration, as it would keep the noise down. We found a little utility that used a GUI, and everyone downloaded it. Then, the school's head IT guy discovered it on my computer, and threatened to have me expelled. The teacher threw me under the bus, claiming she had never condoned the use of Net Send. (Italicized because you know who you are). I was facing a suspension, and being prhibited from touching a computer on school grounds, meaning I would have to drop out of my computer classes, and return to the high school I had just escaped. Luckily for me, my nerd like qualities had me in places of power in a ton of student organisations, and was actually an intern on the school's marketing/PR department (and later IT department. Go figure). I pulled some strings, and got out of it. Politics are the devil, BTW.

Anyway, I kept the whole Novell messenger thing a secret until there were only two weeks left of our senior year. I told some students who where in some other computer classes. (I was in networking, there was also the Cisco class that I was supposed to have been in, a business class, electronics, and programming & web design.

Some how word of my dry-erase board trick spread to a student in the electronic class. A student named C----. C---- was good friends with E---, and thought that was hilarious. He also thought, during a project that involved all of the classes, that it would be funny to send E--- the message "E--- HAS NO WIENER!!" during class. But he didn't stop there. When selecting the recipient of the message, he clicked on EVERY SINGLE USER NAME IN THE SYSTEM.

Let me explain that a little better. Novell Messenger is an administration utility for admins to send messages to users, so the sender is presented with a convenient list of every single user account. That's teachers, students, other IT personnel, the secretary, public relations (yes, we had a PR department), principle, vice  principles, the janitor, EVERYONE! Now, let me explain why, in addition to users, servers were included in this list. If a specific server needed to be rebooted, for whatever reason, an admin could message that server, and the server would in turn forward that message to every user on that server. Student server needs rebooting? Send this message to student.server:

    Attention users, please log out within five minutes and do not log back in until an announcement stating that it's okay to log in or all your progress will be lost.

You get the idea now, right? Anyway, he selected the servers too, so after the shock set in, and the student or teacher selected "OK", they were presented with the message again. 


Suffice it to say, the entire school came to a screeching halt. The cherry on top was when the loud speakers, throughout the school, rang out with "C----- T-----, please report to the office. C----- T-----, please report to the office, IMMEDIATELY!"

But wait, there's more!

Allow me to explain the vocational school's relationship with the highschools in the county (and one in a neighboring county). Students who's grades were high enough had the option, in 11th and 12th grade, to either spend the entire day at their high school, half at their high school and half at the vocational school, or the entire day at the vocational school.

While I spent my entire day at the vocational school, many did not. So, naturally word spread to the seven high schools that feed into the vocational school, but it happened faster than you might think. That's because the principles and vice principles were connected, probably via a VPN, to the vocational school's network, so they got this pop-up message as well!

Aaaaaaaaaaand

Then there were the students at the vocational school who weren't in a computer class, and there for didn't use a school computer every day. But those students all had reports due before finals week. Whether it was an entire English class using a computer lab, or a couple of cosmetology or mechanics students in the library, all students would eventually log in. And one by one, they were all greeted with:
    E--- HAS NO WIENER!!

"Who the hell is E---?" they'd ask each other. "Who is C.T----?" and "E--- has no wiener!" they'd shout!

It left a legacy. Years after my departure, they were still talking about the user C.T----- and the alleged eunuch  named E---.


Epilogue:


'Hackers', MFW
 Does screwing around on the computer mean that s student is bad and won't amount to anything? During middle school, I was involved in a group called Civil Air Patrol. CAP is the civilian auxiliary of the United States Air Force. Although many saw it as a weird Boy Scouts clone, CAP is actually responsible for over 90% of all inland search and rescue operations in the United States. In addition to learning about aeronautics & aerospace, flying a single-engine aircraft (with instructor pilot), learning about and using two-way radio communication, building model rockets and flying them in competitions, learning basic survival skills, and training for search and rescue with CAP and other organizations, such as the USAF, Air National Guard, Air Force Reserve, local, state, and county law enforcement, and becoming acclimated to a military way of life, we actually went on search and rescue sorties and found downed aircraft.

Later, in high school, I was the president of our local chapter of Key Club, the secretary (then later vice-president) of our school's Business Professionals of America chapter, a tour-guide for groups of prospective students that would come see the school, and a school representative that would go to the local high schools, and give a presentation to the students there. I was a journalist in our schools chapter of the CNN Student-Bureau. I also interned for the school's IT department, and the IT department of one of the other high schools. I also had a full time job,and bills, the entire time.

And then how did this SLACKER do at graduation time? I'll let my two honors diplomas speak for themselves.

I went on to study aeronautics and spent some time in the Air Force Reserve Officer Training Corps. I am now an FAA licensed pilot, and I am currently studying computer forensics and network security at the collegiate level.

I'm not trying to brag, just trying to preemptively address some of the "kids shouldn't screw around at school or they'll spend their life flipping burgers and America will degrade and be invaded by Canada and Mexico in a hundred years." rhetoric that fucking morons always spew when they encounter anything involving students "screwing around" with computers. I guess they forgot about the students who lit stink bombs and stuff when they were kids. Or maybe those pranksters didn't do as well in life as the "hackers" did? I don't know.

I've rambled.

tl;dr Hackers, FTW. Old people are teh lulz

Sunday, February 12, 2012

Lowe's Wants You to FAX a Signed Form to LINK TO THEIR SITE!

I just read over at&
nbsp;Ars Technica that Lowe's thinks that it has the legal authority to make people download a form, sign it, fax it to Lowe's, and then wait for Lowe's to grant permission before anyone can post a link to Lowe's website!

This is what happens when, in business, the people you put in charge of internet things don't know shit about the internet! The experts are the people that old people (like congress) call "nerds".

To keep it short, Robert Downy Jr. said it best. Lowe's, are you listening?



http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com http://www.lowes.com