Beng Hacks: March 2007

Thursday, March 29, 2007

Project update

So I promised an update on the trojan project I did previously. I managed to get the usual, like chatlogs, email logins to Gmail, Hotmail, AOL, etc, forum logins... the usual so it wasn't terribly interesting. OK lah got some sex chats quite funny to read hheheh. KK I did get one VERY interesting thing tho.

1 victim was using Symantec Norton 360, the latest antivirus from Symantec, makers of Norton Anti-Virus. Not only that, at 1 point a scan was initiated (I think automatically), then canceled by the victim, then I think automatically started again.

Seems Norton 360 very troublesome like to initiate scan whenever it want. But the VERY interesting part was the scan at 1 point completed, and it did not detect anything. LOL!

This week's Digital Life has an article about how to protect yourself from outside attacks and one of the tips was to again install AV and FW. Goes to show how much people really know and whether they are just trying to sell their software and make big bucks from SCAREWARE.

About scareware LOL recently MSN allowed a scareware to appear in their MSN Messenger ads! LOL pwned... Proof that Microsoft is in cahoots with teh devil???

Sunday, March 11, 2007

School hols

Mooching as I type this... :)

School hols!!!! Sianz 45 more mins need to pack up and go McD part-time liaoz...

Meanwhile, newspapers say IT jobs on the boom, IT jobs big pay and stuff. Wonder how much people pay for people with h4k3r skillz. My cousin told me big audit firms like Earnst and Young have a counter-hacking unit and they teach hacking classes.... wonder how good they are.

The big news today for me is that the US is fast-forwarding daylight savings by 3 weeks. Usually means nothing, but in servers and computer systems, it's a BIG deal, cuz most server software are hardcoded the DST calculation, with no way to change it, except manually unless u have the source then have to remake and rebuild.

This means TONS and TONS of servers out there in the US will have the wrong time and likely for 3 weeks, 21 whole days remain having the wrong time!

BWHAHAHA SQL servers all wrong timestamp. Emails esp those that are legally binding all wrong times. Govt and biz e-transactions all fucked!

Unless of cuz they were warned months in advance. But even then, how about the small businesses? There are millions of small businsess who run server and sell server space. How about co-loc servers? How many will update?

Will be interesting to see wat happens. I predict 3 major failure if ppl dun update now: bank transfer, credit card sales and e-transaction like online air ticket, etc.

Saturday, March 03, 2007

I know where you have been to...lately

Knn...i was awoken by some kids playing soccer under my block....yaya...it's past lunch time...but kunz is my fav pastime...haha...or something that i'm good at...

Aiya...let's digress and get back to topic liao.

Recently, i have been taking lots of free-lance web programming(knn...not enuff moolah lah...u really think i rike to work meh...boh bianz)...I just realised that even if you n00bs turn Javascript off and installed "No Scripts"...I'll still have ur weeny ass pwned if you visit my blog.

Basically, if u r god-damn-good in CSS using conditional logic....u could be singing...."2Nite i need ur CSS, coding in the darkness...".
You could simply make use of CSS to find out the browser history of visitors to your website even without javascript. We have tested it to be working on IE7 and FF 2.0.0.2

Anyway...I got to munch on something riao...cyaz.