Wednesday, July 18, 2012

You know that annoying auto-correct feature that changes all of your swear words into more benign language? Well my new(ish) Android phone didn't really come with one. I mean, it did, but it only had a dictionary containing proper nouns from my address book. Great when I'm trying to spell names like Galifinakis, not so great when I'm trying to spell  deoxyribonucleic-acid, since my own spelling skills have been crippled by years and years of using word processing programs with spell check.

DISCLAIMER: Truth be told, I was never really good at spelling. Derp.

DISCLAIMER TWO: Oddly enough, deoxyribonucleic is one of the few words that I can spell, but the spell-checker built into Google Chrome is telling me it's not even a real word. Thanks a lot, Google.


But this post isn't just me complaining about my phone. No, not at all. You see, it got me wondering, why would the Motorola Triumph, a "budget" phone by today's standards which ships with Android 2.2.2, but still way beyond the power of my previous Android's, would ship with an integral feature crippled - a feature that has been a mainstay of "smart phones" before "smart phones" even existed? (I'm thinking about some of my "flip phones" circa 2004 - 2005 which had a wonderful text predictions / spell check system called T9)


Now for a stretch...


Hon Hai Precision Industry Co., Ltd. which you know as Foxconn, is a Taiwanese manufacturing company with their most famous factories manufacturing iPads and iPhones in China. One of their facilities in Ciudad Juárez, Mexico, manufactures Motorola's handsets. The conspiracy is that Foxconn deliberately installed firmware on the Triumph that had a crippled spell check to 1) Make their big bank roller Apple look better, and 2) get some revenge on Motorola, since they dropped Foxconn.

In any case, Foxconn doesn't build Motorola phones anymore, and Google now owns Motorola, taking out one more step between Google and Android consumers - which means one less middle man to fill your phone with bloatware and spyware. (Please note it's less spy and bloat-ware, not zero spy and bloat-ware)

In bigger news, I have an upcoming blog post about smart homes, and their features that you can expect to be in every home in a few decades time, a trio of noodle recipes (as soon as Brandi gets around to collaborating with me on the third one) and possible a way long over due post to my cybernetics blog. God, I'd really like to work on that blog, but I won't allow myself to post to it will-nilly, like I do this one, and I need time and quiet to do it properly - things that I don't really get. I'm okay with that though. I really can hardly stand to spend time away from my wife and daughter even if it's just to do homework in the other room, so serious blogging is on the back burner.

Tuesday, July 10, 2012

Parallel Universe Twitter


So by accident I seem to have found a website running a parallel Twitter. I think it's a phishing scam - they want you to log into it so they can hijack your account.

See, the thing of it is, I'm logged into Twitter, so if this parallel website were legit, I'm pretty sure my login token would carry over, like when I log into Twitter, it carries over to Twitpic.

Anyway, here's the address: http://199.59.148.20/ NSLookup says it's domain name is r-199-59-148-20.twttr.com, and twttr.com redirects to www.twitter.com, but the source is the same, so it's a decent copy, unlike the Facebook clone I blogged about recently that was clearly a product of Metasploit.

Anyway, don't log into it.

Wednesday, June 27, 2012

People Are Still Falling For This Crap?!

I saw a comment on a photo on Facebook that read something like "I saw you in this photo your buddy showed me. (link to what looks like a Facebook webpage) That's pretty jacked up, lol. Did you see it yet?" When you click the link, you're presented with the Facebook log-in page. Okay, you think, no big deal. I'll just enter my username and password, and I'll be logged back in and looking at this 'jacked up' picture in no time!


People are still falling for this crap?



Wait a minute, you didn't actually log out, did you? Well, no matter, you say to yourself. Sometimes that just happens. Okay, take a closer look at that link. It doesn't really look right, does it?


I'm going to put an actual link to a Facebook BUT FOR THE LOVE OF GOD, DO NOT GO TO THE WEBSITE! AND IF YOU DO, DON'T ENTER ANY LOG IN INFORMATION!






Look at that link. The facebook.com part look normal enough, but what's that at the end? justsomefuns.com... Well, it turns out that when you clicked that link, you were taken to a website called http://justsomejuns.com. The facebook.com part is a sub-domain of justsomefuns.com.


So what is this justsomefuns.com bologna? Well, if you don't know, you certainly don't want to give them your username and password to the world's most prolific social-network, do you?


It turns out that, at the very least, justsomefuns takes your log-in credentials, and then *gasp* logs in to your account, and makes status updates and comments that contain links to - you guessed it - justsomefuns.com, thus continuing the cycle.


That is, I guess, somewhat benign, but what else can they do with those login credentials? Well for starters, they can sell it. Or, since you were already stupid enough to hand over your log-in info to them, you'll probably fall for some other tricks. They'll convince you that you're allowing some app access to your account (like Farmville or something) or maybe (and this is a bit of a throwback to the 90's) installing a codec or driver to watch a video of a celebrity semi-nude dancing on a table at Starbucks; when in reality, you're voluntarily installing a rootkit that will give them access to your computer. So, whatever is stored on your computer, they can now access. Think embarrassing files and log-in credentials to your bank or credit cards.


Hello virus, goodbye money.


Taking a look at the attack vector website.


It looks a lot like Facebook.com, doesn't it? 

A cursory glance at the source code reveals some tell-tale signs that this is a duplicate website.


What?


Okay, sorry if that was too technical. Right-click somewhere on the page, and select view page source. (It may be different in different browsers, but if you see an option that says "source", it's probably the one you need to click on)


Here's what I found:




See that red arrow?




It says that this webpage was saved from Facebook's log-in page. If it was saved from the log-in page, then logically, it cannot be the log-in page. Think of it this way: If you make a copy of a key, you are copying the original key, or copying a copy of the original key, but the copy has to come from somewhere. The original key is not a copy. So, by this same line of reasoning, if what you're looking at is a copy, or "saved from" the original, or a copy of the original, or, anything, for that matter, then it is not the original!


How about a less technical way to verify that you're logging into Facebook? Okay, well, if you're logged-in to Facebook, browsing around, making comments, looking at pictures of cats, and telling Chuck Norris jokes, and then, out of nowhere, you're asked to log in again, DON'T!


Instead, do the following:  In the very same window (or tab) that is displaying the log-in screen, type in this address: https://www.facebook.com/ That is Facebook's secure log-in page. You can dissect the URL if you want some reassurance. https stands for hyper-text transfer protocal - secure. That's the de facto protocol for delivering secure content on the internet. The :// denotes that the text to the left indicates what protocol is being used. www stands for World Wide Web, and in many cases is superflous, but type it in to be 100% sure you get to Facebook. facebook is the domain name for Facebook, and .com is the top-level domain in facebook.com. There's nothing extra in there.


Now that you've logged-in to the real Facebook, hit the back button until you find the page that wanted you to log in again, and refresh (press the F5 key) the page. If, after refreshing, it still wants you to log-in, chances are it's not really Facebook at all!


Epilogue

So what about this justsomefuns website? I did a little snooping, and I found that it is a webpage hosted by Russian internet service provider CityTelecom.ru which claims to have "Serious solutions for serious people." (citytelecom.ru). Now I'm sure our friends over at CityTelecom.ru have nothing to do with the scam, but we know that Facebook is not based in Mother Russia, nor does it use CityTelecom.ru to connect its massive server farms to the glorious intertubes. 








Thursday, May 24, 2012

Sunday, April 1, 2012

Total Recall Remake




Are they doing this? Is this really happening? You know, the trailer looks great. It's got some of my favorite actors in it (Jessica Beil, John Cho), the special effects look outstanding, it's got an even more dystopian flavor, and, just from this trailer, I see that there are a lot of cyberpunk themes in there too. (Pay attention, Steven Spielberg, because if you screw up Ghost in The Shell, so help me God, I will find you...)

But FUCK YOU Hollywood! There is nothing wrong with Total Recall! Arnold pulled that Christmas tree light out of his nose and there was a chick with a third breast made out of Papier-mâché and it was perfect!

You know what? It looks like it's gonna be good, so you know what I'm gonna do? You know what I'm gonna do, Hollywood? I'M GONNA DOWNLOAD IT! I'M GONNA WATCH IT FOR FREE AT A FRIEND'S HOUSE! I'M GONNA WAIT 'TILL IT COMES OUT ON TELEVISION!

Did that writer's strike really screw you so badly that you can't write a new movie? Not one?

Suck my balls, Hollywood. And while you're at it, suck Arnold's too.

Looks like a sweet movie, though. It's gonna be pretty good.

Sunday, March 18, 2012

So dude climbed up this mountain back in the day to see this Kung Fu master. He meets him, and he's all like "Peep dis, hommie: I've been to every dojo in the valley and have mastered every style. I've become the best fighter around. I've heard everyone say yours is the best Kung Fu, son, so i came all the way up this mountain so you can teach me yo!"

The old man at the top of the mountain pondered this young man's story, and was a little freaked out that the young traveller didn't speak at all like some one from eleventh century China, but thought 'Whatevs' and put some tea on.

The young guy said "Hey, man, why are you making tea? We gots ta get our Kung Fu on!"

But the old man replied "Chill out, slick. We gonna get our drank on with some of this pimp-tea!"

The old man poured tea into the cup he had placed out for the young man, but it overflowed from the cup and splashed into the traveller's lap.

"WHAT THA FUCK, B?!" the young man exclaimed. "Aww hell naw!" And he ran back down the mountain, holding his pants out away from his crotch to keep the scalding hot tea away from his balls. "This crazy-ass fool burned mah junk..." he muttered to himself as he waddled away. He kinda looked like a kid that pee'ed his pants, you know. Waddle waddle.

Look, this isn't how the story really goes. It's late, and there's a helicopter and an airplane that keeps circling around, like there's some crazy shit going down right now. Plus, I'm really sick, so I'm not gonna fix the story.

Sorry

Goodnight.

Go to sleep, now.

I'm not sorry.

Wednesday, February 29, 2012

WEP at a doctor's office?

In light of some recent events, I'm going to do my token "Full-Disclosure" blog entry right now. I'm going to discus the dangers of using Wired Equivalent Privacy, or WEP, to secure a WiFi access point. WEP is now fully depreciated, has been for some years, and more detailed explanations are vast on the 'net. My hope is that some one will read this, and then think twice about implementing WEP.

Side note: WEP does have its place, and I'll get to that.


Imagine, if you will, a doctor's office. Now, imagine a disgruntled divorcee. (Warning, the divorcee's language is very NSFW. If you're reading this line, then the NSFW content is already visible on your screen. lol)


    "I fucking hate that bitch! She got everything in the divorce! The house... the kids... my Corvette... I even lost my job and half my friends! I want her life to be as ruined as mine! I want her to lose her job! Now, I know you can to all that 'hacker' stuff. I want you to ruin her employer's network so they go out of business or get in trouble or something. I want revenge. I'll pay you a thousand dollars!"

Not at all a far-fetched scenario. And, if I'm, hypothetically speaking, taking the place of the nefarious individual with whom the divorcee is speaking, all I heard was "...a thousand dollars".

Now lets hear from our hypothetical bad guy hacker cloak and dagger whatever.


    "Dude, it was hella easy. All I had to do was spend a few hours in the parking lot across the street. I connected a USB WiFi dongle to a USB extension cord so I could run it out my moon roof. Then booted up BackTrack and, well, I'm not some damned skiddie, but I wanted to be as fast as possible, so I used Kismet to locate their WiFi, used Gerix to crack their WEP key, and the rest was pretty easy. They thought that they were playing it safe by requiring users to authenticate to a Radius server, but not really. I just changed my MAC address to one of the devices already authenticated - I think it was a Cisco VOIP phone - to prevent the network from booting me every five minutes. Then I just did a little ARP Poisoning with Ettercap causing a copy of all network traffic to be routed to my laptop. Then I opened up Wireshark to record all of the data. Later on, at home, I reassembled that captured traffic, and actually got some fascinating stuff. Some emails, a couple phone calls, x-rays, cat scans, ultra-sound, and just a TON of transcriptions destined for patient's charts. I gave this info to my dude, who gave me the grand he promised"
"What happened next?" we  ask our shadowy fiend.

    "I gave him his info, he gave me my money... I'm not exactly sure what he did with it, since I don't really care, as long as I got paid... But... I do remember hearing something in the news about that place. Yeah, they had some 'hippa' violations, and got sued by a bunch of patients. They settled out of court, but that's not what put them out of business. I guess that after this happened, their physicians couldn't get any malpractice insurance, and had to give up their doctoism, or something. Everyone lost their jobs."

"What did you do with the money?"

    "I used to to buy a motorcycle."


See? See why WEP is a terrible idea when security is your goal? Don't use WEP, unless you want to get in trouble, and let some black-hat hacker buy a motorcycle via your hardship and woe.

Why would anyone ever want to use WEP? Well, it's kind o a psychological thing, really. Think of it as a property marker. WPA is like a chain link or wooden fence. WPA2 is that same fence, topped with electrically charged razor wire. WEP is nothing more than a few sticks with pink spray-paint, delineating where your yard begins and ends. Some one would have to knowingly "trespass" your WiFi yard. It's like saying, I'm not really going to make sure that you can't get into my WiFi, but I'm making it well known that I don't want you there, and have legal recourse if you do break in.

That's stupid, though.

The other use that I can think of would be a diversion, like a WiFi honeypot. Set up a WEP network with some computers on it doing mundane things filled with useless or false information. Hopefully, the attacker will hack into your WEP WiFi, and ignore the one you've secured with WPA2 and made "invisible".

The most important thing we can do with WEP is use it as an example of what NOT to do, and to make jokes about it.

I like to refer to WEP as "Weak Encryption Protocol".