<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Geeknizer &#187; Hacking</title>
	<atom:link href="http://geeknizer.com/tag/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://geeknizer.com</link>
	<description>iPhone, Android, mobile, Technology news</description>
	<lastBuildDate>Wed, 08 Feb 2012 16:55:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
		<item>
		<title>Network Spoofer for Android over WiFi [ARP Spoof hacks]</title>
		<link>http://geeknizer.com/network-spoofer-android-arp-spoof-hacks/</link>
		<comments>http://geeknizer.com/network-spoofer-android-arp-spoof-hacks/#comments</comments>
		<pubDate>Sun, 29 Jan 2012 17:48:27 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[WiFi]]></category>

		<guid isPermaLink="false">http://geeknizer.com/?p=9651</guid>
		<description><![CDATA[Network Spoofer lets you run arpspoof attacks and other fun hacks from Android, messing with your Wifi internet from your phone, just like WifiKill can kick users from Wifi. Note:... <span class="meta-more"><a href="http://geeknizer.com/network-spoofer-android-arp-spoof-hacks/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p>Network Spoofer lets you run arpspoof attacks and other fun hacks from Android, messing with your Wifi internet from your phone, just like <a href="http://geeknizer.com/kick-users-devices-from-wifi/">WifiKill can kick users from Wifi</a>.</p>
<p>Note: This app is just for fun, it doesn&#8217;t cause any damages to anyone other than annoyance. Use it with precaution.</p>
<p><a href="http://geeknizer.com/wp-content/uploads/2012/01/network-spoofer.jpg"><img class="alignnone size-full wp-image-9652" title="network-spoofer" src="http://geeknizer.com/wp-content/uploads/2012/01/network-spoofer.jpg" alt="" width="200" height="272" /></a></p>
<p>The project is similar to the <a href="http://www.ex-parrot.com/pete/upside-down-ternet.html">Upside-down-ternet</a> project: from the phone you can flip pictures on someone&#8217;s computer upside down. There are couple of fun things you can do with this app. It lets you:</p>
<ul>
<li>Flip pictures on someone&#8217;s PC.</li>
<li>Change Google searches keywords,</li>
<li> redirect websites to some other sites,</li>
<li>and many more features to come.</li>
</ul>
<p>App works well in combination with Shark for Android &#8211; combined they allow you to capture packets when logged onto wifi networks.</p>
<p><a href="http://geeknizer.com/wp-content/uploads/2012/01/networkspoofer.jpg"><img class="alignnone size-full wp-image-9653" title="networkspoofer" src="http://geeknizer.com/wp-content/uploads/2012/01/networkspoofer.jpg" alt="" width="250" height="417" /></a></p>
<p>Simply install from the Android Market (on a rooted device running &gt;2.2), and download the setup files from the application. This requires about 600MB free SD card space. The program needs the phone to be rooted, and have busybox (most custom firmwares have this).</p>
<p>Developers can contribute at <a href="https://launchpad.net/android-netspoof">Launchpad</a> (main project) and <a href="http://sourceforge.net/projects/netspoof/">Sourceforge</a>.</p>
<p><a href="https://market.android.com/details?id=uk.digitalsquid.netspoofer">Download</a> the App from Market.</p>
<p>We write latest and greatest in <a href="http://geeknizer.com/tag/guide">Tech Guides</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/tablet">Tablets</a>, <a href="http://geeknizer.com/tag/android">Android</a>,  <a href="http://geeknizer.com/tag/open-source">Open Source</a>, Latest in Tech, subscribe to us <a href="http://twitter.com/geeknizer"><strong>@geeknizer </strong>on Twitter</a> OR on <a href="https://www.facebook.com/geeknizer"><strong>Facebook</strong> Fanpage</a>, <a href="https://plus.google.com/b/117636454220284616721/"><strong>Google+</strong></a>:<br />
&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/network-spoofer-android-arp-spoof-hacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Siri Protocol Cracked, Explained</title>
		<link>http://geeknizer.com/siri-protocol-cracked-explained/</link>
		<comments>http://geeknizer.com/siri-protocol-cracked-explained/#comments</comments>
		<pubDate>Tue, 15 Nov 2011 17:50:54 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[IOS]]></category>
		<category><![CDATA[iphone 4s]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[siri]]></category>

		<guid isPermaLink="false">http://geeknizer.com/?p=9114</guid>
		<description><![CDATA[Soon after the hackers made first successful attempts of porting Siri to iPhone 4, iPod Touch &#38; 3GS, it was obvious that more is coming. After a sufficient amount of... <span class="meta-more"><a href="http://geeknizer.com/siri-protocol-cracked-explained/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p>Soon after the hackers made first successful attempts of porting <a href="http://geeknizer.com/siri-on-iphone-4-ipod-touch/">Siri to iPhone 4, iPod Touch &amp; 3GS</a>, it was obvious that more is coming.</p>
<p>After a sufficient amount of reverse engineering, enough understanding has been made regarding the Siri Protocol. To tap the app communication with the cloud, hackers setup a rogue DNS server that manipulates and tracks the interactions.</p>
<p><img class="alignnone size-full wp-image-9117" title="siri-iphone" src="http://geeknizer.com/wp-content/uploads/2011/11/siri-iphone.jpg" alt="" width="224" height="312" /></p>
<p><strong>Siri </strong>communicates with server at port 443, to a server at 17.174.4.4 which is nothing but https://guzzoni.apple.com. The connection, obviously, is over https that uses SSL certificates to verify if the domain and the client are both authentic. Hackers managed to create custom SSL certification authority, added it to their iPhone 4S, then used it to sign their own certificate for a fake &#8220;guzzoni.apple.com&#8221;. This proved to be successful – Siri was happily sending commands to a faked HTTPS sever, which, as stated before, can be replicated again and again. Using this data, they managed to understand the data thats transmitted for every command.</p>
<p>Siri’s protocol is opaque. Let’s have a look at a Siri HTTP request. The request’s body is binary but headers look like this:</p>
<blockquote><p>ACE /ace HTTP/1.0<br />
Host: guzzoni.apple.com<br />
User-Agent: Assistant(iPhone/iPhone4,1; iPhone OS/5.0/9A334) Ace/1.0<br />
Content-Length: 2000000000<br />
X-Ace-Host: 4620a9aa-88f4-4ac1-a49d-e2012910921</p></blockquote>
<p><strong>Facts about Siri Header :</strong></p>
<ul>
<li>The request is using a custom “ACE” method, instead of a more usual GET.</li>
<li>The url requested is “/ace”</li>
<li>The Content-Length is nearly 2GB. Which is obviously not conforming to the HTTP standard.</li>
<li>X-Ace-host is some form of GUID. After trying with several iPhone 4Ses, it seems to be tied to the actual device (pretty much like an UDID).</li>
</ul>
<p><strong>Siri Body payload (binary data)</strong></p>
<p>When Siri binary data is looked in a hex editor, you would notice that it starts with 0xAACCEE. Oh, seems like header ! Unfortunately, nothing after that is readable coz its compressed using zlib.</p>
<p>To be more precise this AACCEE header in the request body is 3 bytes, but actual data payload starts after 4th byte.  Unzipping data after 4th byte yields actual data that is sent over the network.<br />
Unzipped data still has some binary artifacts plus some human readable text in form of bplist00 i.e. data is some binary plist.</p>
<p>Here is the description of the payload chunks:</p>
<ul>
<li>Chunks starting with 0x020000xxxx are “plist” packets, xxxx being the size of the binary plist data that follows the header.</li>
<li>Chunks starting with 0x030000xxxx are “ping” packets, sent by the iPhone to Siri’s servers to keep the connection alive. Here xx is the ping sequence number.</li>
<li>Chunks starting with 0x040000xxxx are “pong” packets, sent by Siri’s server as a reply to ping packets. Without surprise, xx is the pong sequence number.</li>
</ul>
<p><strong>Deciphering the content of binary plists: </strong>Its easy, you can do it on Mac OS X with the “plutil” command-line tool. Or in ruby with the CFPropertyList gem on any platform.</p>
<p><strong>How iPhone 4S talks with apple Servers:</strong><br />
<strong></strong></p>
<p><strong>The audio data: </strong>The iPhone 4S sends raw audio data compressed using the popular VoIP codex Speex audio.<br />
<strong></strong></p>
<p><strong>Signature: </strong>The iPhone 4S sends identifiers everywhere. So if you want to use Siri on another device, you still need the identfier of at least one iPhone 4S. You would need one of the tools from below tool chain to extract that. But beware, Apple could blacklist an identifier.<br />
<strong></strong></p>
<p><strong>The actual content: </strong>The protocol is actually very, very network chatty. Your iPhone sends a tons of things to Apple’s servers. And those servers reply an incredible amount of informations. For example, when you’re using text-to-speech, Apple’s server even reply a confidence score and the timestamp of each word.</p>
<p><strong>Writing your own Siri-based Application for Android, iOS</strong></p>
<p>You can download <a href="https://github.com/applidium/Cracking-Siri" target="_blank">Applidium&#8217;s tool chain</a> and get started with your own app that&#8217;s Siri enabled.</p>
<p>Update: <strong>Spire: <a href="http://geeknizer.com/install-siri-on-ipad-ipod-touch-iphone-4-iphone-3gs/">Install Siri on iPad, iPod Touch, iPhone 4, iPhone 3GS</a></strong></p>
<p>We write latest and greatest in <a href="http://geeknizer.com/tag/guide">Tech Guides</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/tablet">Tablets</a>, <a href="http://geeknizer.com/tag/android">Android</a>,  <a href="http://geeknizer.com/tag/open-source">Open Source</a>, Latest in Tech, subscribe to us<a href="http://twitter.com/geeknizer"><strong>@geeknizer </strong>on Twitter</a> OR on <a href="https://www.facebook.com/geeknizer">Facebook Fanpage</a>:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/siri-protocol-cracked-explained/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Decipher, Bypass Captcha codes [DeCaptcha]</title>
		<link>http://geeknizer.com/decipher-bypass-captcha-codes/</link>
		<comments>http://geeknizer.com/decipher-bypass-captcha-codes/#comments</comments>
		<pubDate>Thu, 03 Nov 2011 16:15:39 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://geeknizer.com/?p=9067</guid>
		<description><![CDATA[To bypass spams and brute force attempts on various sites, whether its registering for accounts or submitting forms, sites world over use Captcha codes. Till today, these captcha codes would... <span class="meta-more"><a href="http://geeknizer.com/decipher-bypass-captcha-codes/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p>To bypass spams and brute force attempts on various sites, whether its registering for accounts or submitting forms, sites world over use Captcha codes. Till today, these captcha codes would have to be entered as indicated by humans, but this is changing with discovery of new way to decipher it.</p>
<p><img class="alignnone size-full wp-image-9071" title="captcha" src="http://geeknizer.com/wp-content/uploads/2011/11/captcha.jpg" alt="" width="299" height="175" /></p>
<p>Captcha stands for Completely Automated Public Turing Test to differentiate between Computers and Humans. It was invented by Carnegie Mellon University computer science graduate student in 2000 as a security tool to safeguard web sites from automated bot attacks and spammers.</p>
<p>Team of researchers at Stanford have outsmarted the Captcha codes. Their anti-spam tool-breaker was able to kill off captcha’s protective cover.</p>
<blockquote><p>“As we substantiate by thorough study, many popular websites still rely on schemes that are vulnerable to automated attacks. For example, our automated Decaptcha tool breaks the Wikipedia scheme&#8230; approximately 25% of the time. 13 out of 15 of the most widely used current schemes are similarly vulnerable to automated attack by our tool. Therefore, there is a clear need for a comprehensive set of design and testing principles that will lead to more robust captchas.”</p></blockquote>
<p><strong>Decaptcha</strong> is capable of isolating the text from noise in the captcha image. From the clean text image, it then runs a smart <a href="http://geeknizer.com/convert-image-to-text-online-ocr-free/">OCR</a> (optical character recognition) to translate image to text.Each text character is identified individually.</p>
<p>To prototype was able to break into Real world websites with Captcha. Decaptcha worked successfully on Visa&#8217;s Authorize.net payment gateway was defeated 66 per cent of the time. eBay&#8217;s captcha was sidestepped 43 per cent of the time. Lower thwart rates were recorded at Wikipedia, Digg and CNN.</p>
<p>Google and reCAPTCHA were the only two that beat out the Stanford team’s automated tool&#8211;no gotchas for either one.</p>
<p>More details: <a href="http://cdn.ly.tl/publications/text-based-captcha-strengths-and-weaknesses.pdf" target="_blank">PDF</a></p>
<p>We write latest and greatest in <a href="http://geeknizer.com/tag/guide">Tech Guides</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/tablet">Tablets</a>, <a href="http://geeknizer.com/tag/android">Android</a>,  <a href="http://geeknizer.com/tag/open-source">Open Source</a>, Latest in Tech, subscribe to us<a href="http://twitter.com/geeknizer"><strong>@geeknizer </strong>on Twitter</a> OR on <a href="https://www.facebook.com/geeknizer">Facebook Fanpage</a>:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/decipher-bypass-captcha-codes/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Kick users, devices from Wifi</title>
		<link>http://geeknizer.com/kick-users-devices-from-wifi/</link>
		<comments>http://geeknizer.com/kick-users-devices-from-wifi/#comments</comments>
		<pubDate>Sun, 16 Oct 2011 06:08:10 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WiFi]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://geeknizer.com/?p=8940</guid>
		<description><![CDATA[Is your roommate eating all of your Wifi bandwidth downloading those crazy torrents? Is your wife streaming too many movies from Netflix? Are your younger ones spending so much time... <span class="meta-more"><a href="http://geeknizer.com/kick-users-devices-from-wifi/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p>Is your roommate eating all of your Wifi bandwidth downloading those crazy torrents? Is your wife streaming too many movies from Netflix? Are your younger ones spending so much time on nothing but Facebook? Its almost time start kicking them from Wifi connection.</p>
<p><img class="alignnone size-full wp-image-8943" title="wifikill" src="http://geeknizer.com/wp-content/uploads/2011/10/wifikill.jpg" alt="" width="288" height="512" /></p>
<p>You can now<strong> kick users &amp; devices from Wifi </strong>using an android app called <strong>WiFiKill</strong>. The app makes sure that a targeted users is not able to connect to Internet using your Wifi.</p>
<p>WiFiKill is pretty simple: it scans your network for connected devices and gives the option to individually kill their network connectivity. You can also chose to Kick all users, if you intend to. Tick the &#8220;all&#8221; box and the network will be completely empty in a matter of seconds. To re-enable connectivity for any device, simply uncheck the box next to its name.</p>
<p><img class="alignnone size-medium wp-image-8944" title="wifi-kill" src="http://geeknizer.com/wp-content/uploads/2011/10/wifi-kill-168x300.jpg" alt="" width="168" height="300" /></p>
<p><em>Note: App does wacky stuff to your wifi by injecting spoofing DNS and several other UDP stuff, works only on <a href="http://geeknizer.com/tag/root">Rooted </a>phones.</em></p>
<p>There&#8217;s alot of things you can do with it, but doing so for Public or shared networks can create  serious problems. We hope you don&#8217;t boot users and create havoc using this app. Use it wisely, don&#8217;t be a jackass. If you promise to be ethical, feel free to install the app from <a href="https://market.android.com/details?id=net.ponury.wifikill" target="_blank">market</a>.</p>
<p>We write latest and greatest in <a href="http://geeknizer.com/tag/guide">Tech Guides</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/tablet">Tablets</a>, <a href="http://geeknizer.com/tag/android">Android</a>,  <a href="http://geeknizer.com/tag/open-source">Open Source</a>, Latest in Tech, subscribe to us<a href="http://twitter.com/geeknizer"><strong>@geeknizer</strong> on Twitter</a> OR on <a href="https://www.facebook.com/geeknizer">Facebook Fanpage</a>:</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/kick-users-devices-from-wifi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Police can Tap, Steal Phone data</title>
		<link>http://geeknizer.com/how-police-can-tap-steal-phone-data/</link>
		<comments>http://geeknizer.com/how-police-can-tap-steal-phone-data/#comments</comments>
		<pubDate>Sat, 01 Oct 2011 21:43:07 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[smartphones]]></category>

		<guid isPermaLink="false">http://geeknizer.com/?p=8855</guid>
		<description><![CDATA[You will be amazed by the fact that Police can now Tap &#38; steal your personal data from your smartphone/ feature-phone alike. This data is extremely valuable, contains not just... <span class="meta-more"><a href="http://geeknizer.com/how-police-can-tap-steal-phone-data/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p>You will be amazed by the fact that Police can now Tap &amp; steal your personal data from your smartphone/ feature-phone alike. This data is extremely valuable, contains not just the call records, Text but also your location history and what not.</p>
<p>Michigan police was already found to do that last month, but if sources are to be trusted, they are going nationwide in US and soon in several other countries. The device used is the <strong>CelleBrite UFED, </strong>which is able to copy most of the data on over 2500 different mobile devices. It does all that in under 2 minutes. UFED brochure claims:</p>
<blockquote><p>The UFED system extracts vital information from 95% of all cellular phones on the market today, including smartphones and PDA devices (Palm OS, Microsoft, Blackberry, Symbian, iPhone, and Google Android). Simple to use even in the field with no PC required, the UFED can easily store hundreds of phonebooks and content items onto an SD card or USB flash drive.</p></blockquote>
<p><img title="cellbrite-scanner" src="http://geeknizer.com/wp-content/uploads/2011/10/cellbrite-scanner.jpg" alt="" width="300" height="247" /></p>
<p>And technical <a href="http://www.cellebrite.com/images/stories/ufed%202/UFED_PA_user_guide.pdf" target="_blank">description</a>:</p>
<blockquote><p>The UFED hardware with Physical Extraction module, used to create Physical and/or Logical dumps from mobile devices, which can then be saved to a USB disk drive, SD memory card, or directly to your PC. The UFED Physical Analyzer (PA) PC application, which provides an in-depth physical memory analysis of the extracted mobile phone data (phonebook contents, SMS messages, call logs, image files, video files, audio files, and more) The Physical Analyzer also serves to generate comprehensive and verified evidence reports of relevant data extracted and analyzed from the mobile device.</p>
<p>The UFED Physical Analyzer software allows the investigator to perform in-depth analysis of the extracted data<br />
and generate reports. The UFED PA application provides the following key features:</p>
<ul>
<li> Analysis of the hex dump with a layered view of memory content</li>
<li>Provides a detailed view of the hex dump</li>
<li>Reconstructs the phone file system</li>
<li>Decodes contact lists, SMS messages, call logs, phone information (IMSI, ICCID, user codes) and more</li>
<li>Provides a view of data files – images, videos, etc.</li>
<li>Provides access to both current and deleted data</li>
<li>Retrieves phone passwords</li>
<li>Simple viewing and user friendly browsing of information</li>
</ul>
<p> Powerful search tools</p>
<ul>
<li>Instantly search for project content</li>
<li>Search the hex dump or file system</li>
</ul>
<p>Search by various parameters such as strings, bytes, numbers, dates</p>
<ul>
<li>Use GREP search (regular expressions) to look for specific data strings</li>
<li>Bookmarking memory locations for indexing of key areas for later review</li>
</ul>
</blockquote>
<p><img class="alignnone size-full wp-image-8858" title="cellbrite-hack" src="http://geeknizer.com/wp-content/uploads/2011/10/cellbrite-hack.jpg" alt="" width="612" height="344" /></p>
<p>The ACLU fears that the next time you get stopped for speeding in Michigan, you’ll be handing over your cell phone, and your entire mobile history, to the nice officers. Of course, you have no idea into what all they can grab. Of course, you don&#8217;t have an option.</p>
<p>There&#8217;s something thats more scary than being able to extract your information &#8212; Being able to inject information into the phone like fake call logs, gps logs, text messages, calendar appointments. It would open your call log SQLLite DB (in the case of an iPhone, Android) and write a new entry. e.g. If my intake information says I received the phone at 15:20:00 but there is a write to phonecalls.sql at 16:22:00 User better have a logical explanation.</p>
<p>We write about <a href="http://geeknizer.com/tag/google">Google</a>, <a href="http://geeknizer.com/tag/twitter">Twitter</a>, <a href="http://geeknizer.com/tag/security">Security</a>, <a href="http://geeknizer.com/tag/open-source">Open Source</a>, <a href="http://geeknizer.com/tag/programming">Programming</a>, <a href="http://geeknizer.com/">Web</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/android">Android</a> and latest in Tech <a href="http://twitter.com/geeknizer"><strong>@geeknizer </strong>on Twitter</a> or by subscribing below:</p>
<p>&nbsp;</p>
<div></div>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/how-police-can-tap-steal-phone-data/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Crack OSX Lion Password</title>
		<link>http://geeknizer.com/crack-osx-lion-password/</link>
		<comments>http://geeknizer.com/crack-osx-lion-password/#comments</comments>
		<pubDate>Sun, 18 Sep 2011 22:54:35 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[osx-lion]]></category>

		<guid isPermaLink="false">http://geeknizer.com/?p=8793</guid>
		<description><![CDATA[Apple has always prioritized beauty and ease of use over maintaining aspects of the system that most users are not aware of: Security. Primary vulnerability had been left open in... <span class="meta-more"><a href="http://geeknizer.com/crack-osx-lion-password/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-8796" title="Mac-OS-X-Lion-cracked" src="http://geeknizer.com/wp-content/uploads/2011/09/Mac-OS-X-Lion-cracked.jpg" alt="" width="300" height="224" />Apple has always prioritized beauty and ease of use over maintaining aspects of the system that most users are not aware of: Security.<br />
Primary vulnerability had been left open in authentication &amp; authorizations in all OS X versions, that highly depend on using shadow files, which can be accessed by users with a high privilege (typically root). On all OS X platforms (Tiger, Leopord, Snow Leapord and Lion) each user has their own shadow file (hash database) whose data is accessible only by the root user.</p>
<p>Apple, unfortunately, overlooked an important aspect.</p>
<p>If we invoke the directory services listing using the /Search/ path, we see a different result:</p>
<p>$ dscl localhost -read /Search/Users/bob</p>
<p>From the output, we can see the following data:</p>
<p>dsAttrTypeNative:ShadowHashData:</p>
<p>62706c69 73743030 d101025d 53414c54 45442d53 48413531 324f1044 <strong>74911f72</strong> <em>3bd2f66a 3255e0af 4b85c639 776d510b 63f0b939 c432ab6e 082286c4 7586f19b 4e2f3aab 74229ae1 24ccb11e 916a7a1c 9b29c64b d6b0fd6c bd22e7b1 f0ba1673</em> 080b1900 00000000 00010100 00000000 00000300 00000000 00000000 00000000 000060</p>
<p>Note: The SHA512 hash is stored from bytes 32-96 (italic) and the salt is stored from bytes 28-31(bold). Hashes are discussed in detail <a href="http://www.hackmac.org/forum/topic/260-cracking-107-lion-password-hashes/">here</a>.</p>
<p>This ShadowHashData attribute actually contains the same hash stored in user bob&#8217;s shadow .plist file. What makes it worst is that root privileges are not required. All users on the system, regardless of privilege, have the ability to access the ShadowHashData attribute from any other user&#8217;s profile and can be cracked using a simple brute-force dictionary attack <a href="http://pastebin.com/RYqxi7Ca">python script</a>. But you, perhaps, don&#8217;t need need to get into that coz there are easier ways.</p>
<p>You can easily change passwords in Lion, you don&#8217;t need to authenticate when changing password for another user. So, cracking password in Lion is as easy as:</p>
<p>$ dscl localhost -passwd /Search/Users/geek</p>
<p>Boom! You can now change User&#8217;s password, without having to authenticate as that user.</p>
<p>We write latest and greatest in <a href="http://geeknizer.com/tag/guide">Tech Guides</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/tablet">Tablets</a>, <a href="http://geeknizer.com/tag/android">Android</a>,  <a href="http://geeknizer.com/tag/open-source">Open Source</a>, Latest in Tech, subscribe to us<a href="http://twitter.com/geeknizer"><strong>@geeknizer</strong> on Twitter</a> OR on <a href="https://www.facebook.com/geeknizer">Facebook Fanpage</a>:</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/crack-osx-lion-password/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>DIY Cheap GSM Cellular Data Network</title>
		<link>http://geeknizer.com/diy-gsm-cellular-data-network/</link>
		<comments>http://geeknizer.com/diy-gsm-cellular-data-network/#comments</comments>
		<pubDate>Sun, 28 Aug 2011 06:07:41 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[DIY]]></category>
		<category><![CDATA[wireless]]></category>
		<category><![CDATA[GSM]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://geeknizer.com/?p=8661</guid>
		<description><![CDATA[Open source GSM cellular network have been in news for a while, and we&#8217;ve seen people hacking GSM networks in a matter of minutes. However what was left was an... <span class="meta-more"><a href="http://geeknizer.com/diy-gsm-cellular-data-network/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><img src="http://geeknizer.com/wp-content/uploads/2011/08/diy-gsm-cellular-data.jpg" alt="" title="diy-gsm-cellular-data" width="260" height="172" class="alignright size-full wp-image-8664" /><a href="http://geeknizer.com/open-source-gsm/">Open source GSM cellular network</a> have been in news for a while, and we&#8217;ve seen people <a href="http://geeknizer.com/how-to-hack-gsm-nework-phone/">hacking GSM networks</a> in a matter of minutes. However what was left was an easy to do DIY Cellular data network, which has now been made available masses. [<a href="http://www.cs.berkeley.edu/~kheimerl/pubs/vbts_nsdr10.pdf" target="_blank">PDF</a>]</p>
<p>[<a href="http://mobileactive.org/village-base-station-project" rel="nofollow">image credit</a>]</p>
<p>This new DIY Data network is low cost, low-power, easy to deploy tool developed by Berkeley professor <a href="http://www.eecs.berkeley.edu/~kheimerl/" target="_blank">Kurtis Heimerl</a>. Its essentially a good alternative for regions with low or no coverage.Recently one of such prototypes has been tested here in Unitesd States and results seem to be very promising. <br />
<a href="http://mobileactive.org/village-base-station-project" target="_blank">The benefits </a>of the Village Base Station:</p>
<blockquote><p>ﬂexible off-the grid deployment due to low power requirements that enable local generation via solar or wind; explicit support for local services within the village that can be autonomous relative to a national carrier; novel power/coverage trade-offs based on intermittency that can provide bursts of wider coverage; and a portfolio of data and voice services (not just GSM).</p></blockquote>
<p><img src="http://geeknizer.com/wp-content/uploads/2011/08/diy-cellular-data.jpg" alt="" title="diy-cellular-data" width="500" height="238" class="alignnone size-full wp-image-8665" /></p>
<p>A similar prototype has been used in Jalalabad, Afghanistan. Jalalabad&#8217;s longest link is currently 2.41 miles, between the <a href="http://fabfi.fablab.af/">FabLab</a> and the water tower at the public hospital in Jalalabad, transmitting with a real throughput of 11.5Mbps (compared to 22Mbps ideal-case for a standards compliant off-the-shelf 802.11g router transitting at a distance of only a few feet). The system works consistently through heavy rain, smog and a couple of good sized trees.</p>
<p>Here&#8217;s how this GSM DIY equipment works, video explains the channeling &#038; signaling concepts of GSM based on OpenBTS:</p>
<p><iframe width="640" height="390" src="http://www.youtube.com/embed/ZoWKYJ1ATeE" frameborder="0" allowfullscreen></iframe></p>
<p><img src="http://geeknizer.com/wp-content/uploads/2011/08/cellular-network.jpg" alt="" title="cellular-network" width="473" height="295" class="alignnone size-full wp-image-8666" /></p>
<p>Developing countries &#038; rural areas with limited Internet access would benefit from this project. And of course there are endless hobby activities it can get you started with.</p>
<p><a href="http://buythissatellite.org/">&#8220;Buy This Satellite&#8221;</a> is an effort to crowdfund enough money to purchase the communications satellite TerreStar-1.</p>
<p>Related: <a href="http://geeknizer.com/diy-drone-plane-hack-wifi-phone-calls/">DIY Drone Plane: Hack Wifi, Phone calls</a></p>
<p>We write latest and greatest in <a href="http://geeknizer.com/tag/guide">Tech Guides</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/tablet">Tablets</a>, <a href="http://geeknizer.com/tag/android">Android</a>,  <a href="http://geeknizer.com/tag/open-source">Open Source</a>, Latest in Tech, subscribe to us <a href="http://twitter.com/geeknizer"><strong>@geeknizer </strong>on Twitter</a> OR on <a href="https://www.facebook.com/geeknizer">Facebook Fanpage</a>:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/diy-gsm-cellular-data-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIY Drone Plane: Hack Wifi, Phone calls</title>
		<link>http://geeknizer.com/diy-drone-plane-hack-wifi-phone-calls/</link>
		<comments>http://geeknizer.com/diy-drone-plane-hack-wifi-phone-calls/#comments</comments>
		<pubDate>Fri, 05 Aug 2011 06:15:01 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[DIY]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[GSM]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WiFi]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://geeknizer.com/?p=8484</guid>
		<description><![CDATA[Every year, at BlackHat, DefCon conference, several new hacks, cracks and vulnerabilities are exposed for the popularly used technology, blowing away the users and geeks alike. Two security researchers, Mike... <span class="meta-more"><a href="http://geeknizer.com/diy-drone-plane-hack-wifi-phone-calls/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p>Every year, at BlackHat, DefCon conference, several new hacks, cracks and vulnerabilities are exposed for the popularly used technology, blowing away the users and geeks alike.</p>
<p><a rel="attachment wp-att-8487" href="http://geeknizer.com/diy-drone-plane-hack-wifi-phone-calls/drone-hack-wireless/"><img class="alignright size-full wp-image-8487" title="drone-hack-wireless" src="http://geeknizer.com/wp-content/uploads/2011/08/drone-hack-wireless.jpg" alt="" width="230" height="188" /></a>Two security researchers, Mike Tassey and Richard Perkins,  have unleashed a complete DIY methodology to Launch your personal, specially equipped WASP (Wireless Aerial Surveillance Platform) drone that to flys overhead and <strong>sniff Wi-Fi network</strong>, <strong>intercept cellphone calls</strong>, or launch <strong>denial-of-service attacks with jamming signals</strong>.</p>
<p>This drone plane runs on Arduino and would cost you $6,000. This drone is based on FMQ-117B U.S. Army target drone and equipped it with Wi-Fi and hacking tools &#8212; IMSI catcher and antenna to spoof a GSM cell tower and hack calls. What&#8217;s more? It can launch a dictionary attack on the network using its database of 340million words.</p>
<p><a href="http://geeknizer.com/how-to-hack-gsm-nework-phone/">GSM Hack</a> to break into voice calls has been floating around for a while, and that&#8217;s what inspires these security researchers. Recommended read: <a href="http://geeknizer.com/how-to-hack-gsm-nework-phone/">How to Hack GSM Nework, Phone</a></p>
<p>The device onboard tricks phones to disable encryption, and records call details and content before they’re routed to their intended receiver through VoIP or redirected to anywhere else the hacker wants to send them.</p>
<p><a rel="attachment wp-att-8490" href="http://geeknizer.com/diy-drone-plane-hack-wifi-phone-calls/wasp/"><img class="alignnone size-full wp-image-8490" title="WASP" src="http://geeknizer.com/wp-content/uploads/2011/08/WASP.jpg" alt="" width="580" height="435" /></a></p>
<p>Drone plane weighs 5Kgs and is 2.5m long and is quiet enough to spy on anyone, without trouble. You know, its US military drone, designed to be quiet. It can be automated to travel through programmed GPS coordinates and Google Earth, whole thing is self-driven apart from take off and landings which need to be controlled.</p>
<p>&nbsp;</p>
<p>While such a drone may violate a few flying laws, it doesn’t break any FCC regulations as it uses the HAM radio frequency band or a 3G connection for communication. As to the reason for building it, creators Mike Tassey and Richard Perkins just wanted to prove there is a vulnerability that can easily be taken advantage of with a UAV such as this. It can easily cover 10,000 sq. ft of area using its inboard basestation.</p>
<p>WASP is an open source platform called Auto Pilot using Arduino that Tassey will <a href="https://www.defcon.org/html/defcon-19/dc-19-speakers.html#Tassey">discuss how to build</a> at DEFCON-19 next week. It was originally unveiled last August with the following video giving you a close up view and interview with the creators</p>
<p><strong>Update</strong>: <a href="https://rabbit-hole.org/how-to/" target="_blank">Instructions to Build this drone</a></p>
<p><embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" width="555" height="312" src="http://revision3.com/player-v6180" allowscriptaccess="always" quality="high" allowfullscreen="true"></embed></p>
<p><strong>Endless Possibilities</strong></p>
<p><em>Darker side:</em><br />
Its pretty much obvious that if two security researchers can collaborate to create such a destructive element for communications, wonder how strong could it be when its in terrorists hands.</p>
<p>Hackers would use them to fly above corporations to steal data like confidential IP (intellectual property) or may be launch a DoS attack or jam the cellphone signals of a corporation, without letting anyone know.</p>
<p>You can stop a car, a person from coming into your facility, but what about things that fly overhead? These drones can not just broadcast jamming signal, they can laser focus specific users in crowd.</p>
<p><em>Positives: </em><br />
If you think about positive aspects of such drones, they can prove out to be quiet helpful during natural disasters when other communications break. They can be bagged with more sensors, cameras and help army in critical missions, possibilities are endless.</p>
<p>Related: <a href="http://geeknizer.com/diy-gsm-cellular-data-network/">DIY GSM Cellular Data Network</a></p>
<p>We write latest and greatest in <a href="http://geeknizer.com/tag/guide">Tech Guides</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/tablet">Tablets</a>, <a href="http://geeknizer.com/tag/android">Android</a>,  <a href="http://geeknizer.com/tag/open-source">Open Source</a>, Latest in Tech, subscribe to us <a href="http://twitter.com/geeknizer"><strong>@geeknizer </strong>on Twitter</a> OR on <a href="https://www.facebook.com/geeknizer">Facebook Fanpage</a>:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/diy-drone-plane-hack-wifi-phone-calls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hack Macbook using Battery</title>
		<link>http://geeknizer.com/hack-macbook-using-battery/</link>
		<comments>http://geeknizer.com/hack-macbook-using-battery/#comments</comments>
		<pubDate>Sat, 23 Jul 2011 07:38:49 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[battery]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[macbook]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://geeknizer.com/?p=8366</guid>
		<description><![CDATA[Charlie Miller, the famous Apple security researcher has found another flaw with macbooks. The latest hack is very interesting as he had made it possible to hack  MacBook using the... <span class="meta-more"><a href="http://geeknizer.com/hack-macbook-using-battery/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-8369" href="http://geeknizer.com/hack-macbook-using-battery/macbook_battery/"><img class="alignright size-full wp-image-8369" title="macbook_Battery" src="http://geeknizer.com/wp-content/uploads/2011/07/macbook_Battery.jpg" alt="" width="230" height="173" /></a>Charlie Miller, the famous Apple security researcher has found another flaw with macbooks. The latest hack is very interesting as he had made it possible to hack  MacBook using the battery, alone.</p>
<p>Modern Laptop battery contains its own monitoring circuit which reports the status of the battery to the OS. The circuit is also responsible for preventing battery from overcharging, this comes handy when the laptop is switched off.</p>
<p>The scurity researcher has discovered that the batteries on Macbooks are shipped with the default password on the micro-controller. It can be inferred that if someone knows the default password, the firmware of the battery can be controlled to do many things from simply ruining the battery to install a malware which reinstalls whenever the OS boots. Since you gain access to the micro-controller that controls the battery, it becomes actually possible to overuse and overheat the battery to a limit where it can even catch fire.</p>
<p>Miller claims this hack can make the hacker achieve something that was unachievable before &#8212;  it’s possible to use them to do something really bad &#8211; Insert a new Hard drive, reinstall the software, flash the BIOS, and every time it would reattack and screw the user. And the worse part, it undetectable and impossible to  eradicate other than removing the battery.</p>
<p>Apple released a fix in 2009 to fix problems by creating two passwords used for the chip on the battery. By hacking that password, its possible to do anything like giving false reading to the charger and let it overcharge to cause fire, or to completely rewrite the firmware.</p>
<p><strong>Hack is Not Easy</strong></p>
<p>Luckily enough, miller hasn&#8217;t made all details public. He claims that to successfully exploit this vulnerability,  attacker has to analyze the 2009 software updates from Apple for the password. If he is able to retrieve the password, he will have to find a vulnerability in the interface between the OS and the firmware.</p>
<p>But these details would be made public at te yearly security conference, BlackHat. He will also be unveiling a tool to public that will change the password of the battery to a random string. Hope Apple releases a fix before that.</p>
<p>We write latest and greatest in <a href="http://geeknizer.com/tag/guide">Tech Guides</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/tablet">Tablets</a>, <a href="http://geeknizer.com/tag/android">Android</a>,  <a href="http://geeknizer.com/tag/open-source">Open Source</a>, Latest in Tech, subscribe to us <a href="http://twitter.com/geeknizer"><strong>@geeknizer </strong>on Twitter</a> OR on <a href="https://www.facebook.com/geeknizer">Facebook Fanpage</a>:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/hack-macbook-using-battery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lulzsec hacks 62,000 Passwords, publishes online, User Security compromised</title>
		<link>http://geeknizer.com/lulzsec-hacks-passwords-user-security-compromised/</link>
		<comments>http://geeknizer.com/lulzsec-hacks-passwords-user-security-compromised/#comments</comments>
		<pubDate>Sat, 18 Jun 2011 17:24:10 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://geeknizer.com/lulzsec-hacks-passwords-user-security-compromised/</guid>
		<description><![CDATA[Lulzsec is the biggest name these days that scares almost every organization around the world, government and private companies alike. Lulzsec hacker group have been on a hacking rampage since... <span class="meta-more"><a href="http://geeknizer.com/lulzsec-hacks-passwords-user-security-compromised/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><a href="http://geeknizer.com/wp-content/uploads/2011/06/lulzsec.jpg"><img class="alignright" title="lulzsec" src="http://geeknizer.com/wp-content/uploads/2011/06/lulzsec_thumb.jpg" border="0" alt="lulzsec" width="210" height="191" /></a>Lulzsec is the biggest name these days that scares almost every organization around the world, government and private companies alike.</p>
<p>Lulzsec hacker group have been on a hacking rampage since a while now. They have been taking down sites of the CIA, Sony, FBI and a bulk of other large and small companies. Motive behind the hacks has rather been dicey, is it for fun or something else. The document is available on <a href="http://pastebin.com/HZtH523f">Pastebin</a> and their activities are visible via their <a href="http://twitter.com/#!/lulzsec">Twitter</a> account.</p>
<p>Very recently they hacked released <strong>62,000 username and passwords of a popular porn site</strong>. However, the ugly part of the story is that users tend to have similar passwords for all their accounts: mail, facebook and even paypal. Hackers and script buggies have been scanning the password list and discovered that this is actually the case for most users whose username/passwords have been shared in the leak.</p>
<p>If you analyze the password list, its not hard to figure out that a lot of users registered on the porn site are actually people from government organizations. Other than that Google, Yahoo, facebook have already out the accounts corresponding to those ids on hold till user verifies the ownership to prevent all kinds of misuses. However, hotmail and other unpopular email providers are still vulnerable.</p>
<p><strong>What You can do: Staying secure online</strong></p>
<p>Go through the <a href="http://lulzsecurity.com/releases/pronz.txt" target="_blank">password list</a> and if you are on it, you are probably already in trouble. Going further, make it a habit to have different user/password combos for different sites. Doing so can be hard but if you follow a pattern for passwords, remembering them could be piece of a cake. e.g. you can change the first or last digit of the password based on the domain name. A password that was “pA$$w0rdG” on gmail would become  “pA$$w0rdf” on facebook. Do something similar, but purely your own idea.</p>
<p><strong>What is the Future of LulzSec</strong></p>
<p>Lulzsec would continue to hack down the internet with almost no clear intent. The press release states that for the past month or so they have been causing chaos throughout the internet by attacking several targets and they&#8217;re going to bring down more internet laws by continuing their public shenanigans, and that their actions are causing clowns with pens to write new rules for users.</p>
<p>They say that releasing data is just as ‘evil’; however they mock by saying, “This is the Lulz lizard era, where we do things just because we find it entertaining.”</p>
<p>They conclude by saying, “We&#8217;ve been entertaining you 1000 times with 140 characters or less, and we&#8217;ll continue creating things that are exciting and new until we&#8217;re brought to justice, which we might well be.“</p>
<p>We write latest and greatest in <a href="http://geeknizer.com/tag/guide">Tech Guides</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/tablet">Tablets</a>, <a href="http://geeknizer.com/tag/android">Android</a>,  <a href="http://geeknizer.com/tag/open-source">Open Source</a>, Latest in Tech, subscribe to us<a href="http://twitter.com/geeknizer"><strong>@geeknizer</strong>on Twitter</a> OR on <a href="https://www.facebook.com/geeknizer">Facebook Fanpage</a>:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/lulzsec-hacks-passwords-user-security-compromised/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Hackers Hack Car with Music</title>
		<link>http://geeknizer.com/hack-car-with-music/</link>
		<comments>http://geeknizer.com/hack-car-with-music/#comments</comments>
		<pubDate>Sat, 19 Mar 2011 16:11:07 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Cars]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://geeknizer.com/hack-car-with-music</guid>
		<description><![CDATA[It was once said that by English playwright William Congreve &#8220;music has charms to soothe a savage breast, to soften rocks, or bend a knotted oak.&#8221; As per the latest... <span class="meta-more"><a href="http://geeknizer.com/hack-car-with-music/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" src="http://geeknizer.com/wp-content/uploads/car-hacking1.jpg" alt="car-hacking.jpg" width="220" height="147" />It was once said that by English playwright William Congreve &#8220;music has charms to soothe a savage breast, to soften rocks, or bend a knotted oak.&#8221; As per the latest research, music actually lets hackers break into your car.</p>
<p>Researchers at UaC &amp; University of Washington have spent years trying to fin security flaws in modern cars which are controlled via mini-computer systems and so far they have identified a bunch of security flaws in cars.</p>
<p>The most interesting attacks were triggered via car&#8217;s Bluetooth and cellular network systems, or through malicious software in the diagnostic tools used in automotive repair shops.</p>
<p>The one that interested us was on the Car stereo. By adding extra code to a digital music file, they were able to turn a song burned to CD into a Trojan horse. When played on the car&#8217;s stereo, this song could alter the firmware of the car&#8217;s stereo system, giving attackers an entry point to change other components on the car. This type of attack could be spread on P2P file-sharing networks without arousing suspicion.</p>
<p>&#8220;It&#8217;s hard to think of something more innocuous than a song,&#8221; said Stefan Savage, a professor at the University of California.</p>
<p>The same team had achieved wide Car hacks in experiments in which they were able to <a href="http://geeknizer.com/car-hacking" target="_blank">kill the engine, lock the doors, turn off the brakes and falsify speedometer readings</a> on a late-model car of 2009. In that experiment, they had to plug a laptop into the car&#8217;s internal diagnostic system in order to install their malicious code. In 2010, team also hacked Cars from <a href="http://arstechnica.com/security/news/2010/08/cars-hacked-through-wireless-tyre-sensors.ars" target="_blank">wireless tyre sensors</a>.</p>
<p>But the latest research, is about remotely controlling cars. The attacks over Bluetooth, the cellular network, malicious music files and via the diagnostic tools used in dealerships were all possible, if difficult to pull off, Savage said. &#8220;The easiest way remains what we did in our first paper: Plug into the car and do it,&#8221; he said.</p>
<p><strong>Car Hacking: Possibilities &amp; Future</strong></p>
<p>Now, thieves could instruct cars to unlock their doors and report their GPS coordinates and Vehicle Identification Numbers to a central server. &#8220;An enterprising thief might stop stealing cars himself, and instead sell his capabilities as a service to other thieves,&#8221; Savage said. A thief looking for certain kinds of cars in a given area could ask to have them identified and unlocked, he said.</p>
<p>With the high technical barrier to entry, the researchers believe that hacker attacks on cars will be very difficult to pull off, but they say they want to make the auto industry aware of potential problems before they become pervasive.</p>
<p>Another problem for would-be car thieves is the fact that there are significant differences among the electronic control units in cars. Even though an attack might work on one year and model of vehicle, it&#8217;s unlikely to work on another. &#8221;</p>
<p>So far, carmakers have been very receptive to the university researchers&#8217; work and appear to be taking the security issues they&#8217;ve raised very seriously.</p>
<p><span style="font-family: Verdana,Arial,Tahoma,Calibri,Geneva,sans-serif; font-size: 13px; color: #333333;">We write latest and greatest in <a href="http://geeknizer.com/tag/guide">Tech Guides</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/tablet">Tablets</a>, <a href="http://geeknizer.com/tag/android">Android</a>, <a href="http://geeknizer.com/tag/open-source">Open Source</a>, Latest in Tech, subscribe to us <a href="http://twitter.com/taranfx"><strong>@taranfx</strong> on Twitter</a> OR on <a href="http://facebook.com/taranfx">Facebook Fanpage</a>:</span></p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/hack-car-with-music/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Hack Open/Unlock Office Door</title>
		<link>http://geeknizer.com/how-to-hack-open-office-door/</link>
		<comments>http://geeknizer.com/how-to-hack-open-office-door/#comments</comments>
		<pubDate>Thu, 03 Feb 2011 14:52:39 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Guide]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[howto]]></category>

		<guid isPermaLink="false">http://geeknizer.com/how-to-hack-open-office-door</guid>
		<description><![CDATA[In movies, geeks would pitch-in and attach a PDA to the door that sweeps the magnetic field patterns against the doors or analyze the lock code in matter of seconds.... <span class="meta-more"><a href="http://geeknizer.com/how-to-hack-open-office-door/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><a href="http://geeknizer.com/wp-content/uploads/door-lock.jpg"><img src="http://geeknizer.com/wp-content/uploads/door-lock.jpg" alt="" title="door-lock" width="220" height="192" class="alignleft size-full wp-image-6979" /></a>In movies, geeks would pitch-in and attach a PDA to the door that sweeps the magnetic field patterns against the doors or analyze the lock code in matter of seconds. They employ modern science, mostly imaginary, but it sure looks complex. In reality, <strong>unlocking doors</strong> can be as easy as buying a Good Magnet.</p>
<p>Most office doors employ magnetic sensors that require a access card to be swiped across to unlock. These magnetic cards have unique magnetic pattern underneath the plastic, which when scanned is matched against a person&#8217;s identity.</p>
<p>Among the most popular lineup of Office door lock, Kaba Ilco Simplex lineup has been there for more than 3 decades, and had been pretty much unhackable till 2010. But if you have a strong  magnet, it opens up effortlessly in under 3 seconds.<br />
<a href="http://geeknizer.com/wp-content/uploads/strong-magnet.jpg"><img src="http://geeknizer.com/wp-content/uploads/strong-magnet.jpg" alt="" title="strong-magnet" width="371" height="288" class="alignnone size-full wp-image-6980" /></a></p>
<p>You devise the Hack, you need powerful <a rel="nofollow" href="http://en.wikipedia.org/wiki/Rare-earth_magnet"> rare-earth magnets</a>, which formulates the state-of-the-art attack.</p>
<div id="19712" title="image"></div>
<p>Worst part is,  most other locks that use a  combination chamber are equally vulnerable.</p>
<p><strong>How it Works</strong></p>
<p>Normally, these door locks need to capture weak magnetic fields generated in vicinity of a access card or a specific combination of buttons  have to be pressed to make the bolt withdraw. However, when a strong magnet is presented,  it messes with the magnetic field inside the combination chamber, the system scrambles making the bolt withdraw  even if no buttons are pressed/ no card is presented.</p>
<p>Kaba, being the industry leader, has fixed the problem with a new combination chamber design in the latest models of its lock, but that won&#8217;t change the existing locks that have lying world over in offices since last 3 decades.</p>
<p>The rare earth (<a title="Lanthanide" href="http://en.wikipedia.org/wiki/Lanthanide">lanthanide</a>) elements are metals that are ferromagnetic, meaning that like iron they can be magnetized, but their Curie temperatures are below room temperature, so in pure form their magnetism only  appears at low temperatures. However, they form compounds with the transition metals such as iron, nickel, and cobalt, and some of these have Curie  temperatures well above room temperature. Rare earth magnets are made  from these compounds.</p>
<p>You can buy one of these <a rel="nofollow" href="http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=neodymium+magnet#q=neodymium+magnet&amp;hl=en&amp;safe=off&amp;prmd=ivns&amp;source=lnms&amp;tbs=shop:1&amp;ei=bfhITea-ENPngQewtIXUBQ&amp;sa=X&amp;oi=mode_link&amp;ct=mode&amp;cd=5&amp;ved=0CDQQ_AUoBA&amp;biw=1024&amp;bih=513&amp;fp=eca856c87e6637d1">neodymium magnet</a> for about $10, no experience required.</p>
<p><strong>Warning</strong>: This is just for educational purposes, do not hack into someone&#8217;s office, you and alone you would be responsible for any consequences.</p>
<p>Alternatively, you can design a a card writer that can hack magnetic locks:</p>
<p><iframe title="YouTube video player" width="480" height="390" src="http://www.youtube.com/embed/z7oPn7V5mHg" frameborder="0" allowfullscreen></iframe></p>
<p>In the above demo, hacker used pre-made connectors so he could easily disconnect and reconnect the device. When you put the reader&#8217;s cover back, the Gecko would be hidden behind it.</p>
<p>The card reader also continues to work fine with the Gecko attached. It passes along the signal from the reader to the control system as it&#8217;s supposed to. But when someone swipes an authorized card that unlocks the door, Gecko saves that signal.</p>
<p>With that saved unlock signal, the attacker can swipe a &#8216;replay&#8217; card that tells Gecko to re-send that saved signal, and the doors unlock. What&#8217;s more, any saved access logs would only show that the same person who originally swiped the saved signal swiped his card again.</p>
<p>The replay card isn&#8217;t anything special, and could be any card. It&#8217;s just one that Gecko knows about beforehand. When it sees that card&#8217;s code &#8211; because the card reader passes it along &#8211; Gecko knows to send its saved signal in response.</p>
<p>The device also knows to look out for another card code &#8211; again, just a regular card &#8211; and in that case, disable the system. Only the recognized replay card can unlock the door. Every other card, authorized or not, will fail.</p>
<p>We write about <a href="http://geeknizer.com/tag/security">Security</a>,  <a href="http://geeknizer.com/tag/open-source">Open Source</a>, <a href="http://geeknizer.com/tag/programming">Programming</a>, <a href="http://geeknizer.com/">Web</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>,<a href="http://geeknizer.com/tag/android">Android</a> and latest in Tech <a href="http://twitter.com/taranfx"><strong>@taranfx</strong> on Twitter</a> or by subscribing below:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/how-to-hack-open-office-door/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Crack Mac App Store</title>
		<link>http://geeknizer.com/how-to-crack-mac-app-store/</link>
		<comments>http://geeknizer.com/how-to-crack-mac-app-store/#comments</comments>
		<pubDate>Sat, 08 Jan 2011 08:55:27 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[piracy]]></category>
		<category><![CDATA[App Store]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[mac os]]></category>
		<category><![CDATA[MAC OS X]]></category>

		<guid isPermaLink="false">http://geeknizer.com/how-to-crack-mac-app-store</guid>
		<description><![CDATA[Mac App store sucks at few things and that&#8217;s what encourages hackers to crack the security and enable Piracy on Mac app store. The hacker of the iPhone App store... <span class="meta-more"><a href="http://geeknizer.com/how-to-crack-mac-app-store/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><a href="http://geeknizer.com/wp-content/uploads/mac-app-store-pirated.jpg"><img class="alignleft" title="mac-app-store-pirated" src="http://geeknizer.com/wp-content/uploads/mac-app-store-pirated_thumb.jpg" border="0" alt="mac-app-store-pirated" width="240" height="147" /></a>Mac App store sucks at few things and that&#8217;s what encourages hackers to crack the security and enable Piracy on Mac app store.</p>
<p>The <a href="http://geeknizer.com/pirated-ios-app-store-ipa-apps-shared-bittorrent">hacker of the iPhone App store</a> has come with a solution for Mac App store, and claims that <a href="http://geeknizer.com/pirated-ios-app-store-ipa-apps-shared-bittorrent">they don&#8217;t encourage piracy</a> but they hate a model where a <strong>user cannot try before buy</strong>. There should be app testing bracket before buying.</p>
<p><strong> Why Mac App Store sucks</strong>:</p>
<ol>
<li>You&#8217;ll have to Re-purchase many of your apps</li>
<li>No trials, no demos, no beta versions</li>
<li>Heavily restricted, controlled Apps.</li>
<li>Many apps would not be available on App Store, thanks to their policies (VLC media player included)</li>
<li>No System-related apps: Apps have no &#8220;root&#8221; permissions, whatsoever.</li>
<li>No downloaders: No ftp, http downloaders or even browsers. WTF?</li>
<li>Not many open source apps: Mac App Store violates GPL, most open source would never make it to app store.</li>
</ol>
<p>Do you still need another reason ?</p>
<p><em><strong>Disclaimer:</strong> This method doesn&#8217;t encourage Piracy. Try the apps, buy them if you like them, support the developers OR one day you wouls stop getting good apps.</em></p>
<p><em><strong>Warning:</strong> The illegal app sharing violates the copyright and Apple App Store rules.</em></p>
<p><strong>How to Crack / Pirate Mac App Store</strong></p>
<ol>
<li>Install the latest Snow Leopard update (10.6.6) from system updates.</li>
<li>Log in the new App Store (from your dock) and download Twitter (free app)</li>
<li>Now go to Applications folder, locate Twitter, right click, Show Package Contents, navigate to Contents folder and copy _CodeSignature, _MASReceipt and CodeResources.\</li>
<li>Download Angry Birds ( <a href="http://bit.ly/gy9wzk">http://bit.ly/gy9wzk</a> ) and run the dmg file.</li>
<li>Now drag Angry Birds into the Applications folder. Right click, Show Package Contents, navigate to Contents folder and delete _CodeSignature, _MASReceipt and CodeResources. Now paste in the files you copied from the Twitter.app in step 3.</li>
<li>Complete, now your Mac App Store is cracked. You can enjoy Angry birds and other .app file from the new Mac App store which you can find online.</li>
</ol>
<p><a href="http://geeknizer.com/wp-content/uploads/crack-mac-app-store.jpg"><img style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" title="crack-mac-app-store" src="http://geeknizer.com/wp-content/uploads/crack-mac-app-store_thumb.jpg" border="0" alt="crack-mac-app-store" width="454" height="105" /></a></p>
<p>We write latest and greatest in <a href="http://geeknizer.com/tag/guide">Tech Guides</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>,<a href="http://geeknizer.com/tag/tablet">Tablets</a>, <a href="http://geeknizer.com/tag/android">Android</a>, <a href="http://geeknizer.com/tag/google">Google</a>, <a href="http://geeknizer.com/tag/open-source">Open Source</a>, Latest in Tech, subscribe to us <a href="http://twitter.com/taranfx"><strong>@taranfx </strong>on Twitter</a> OR:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/how-to-crack-mac-app-store/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>How to Install Custom Firmware on PS3 [Fail0verflow Hack]</title>
		<link>http://geeknizer.com/install-custom-firmware-on-ps3/</link>
		<comments>http://geeknizer.com/install-custom-firmware-on-ps3/#comments</comments>
		<pubDate>Wed, 05 Jan 2011 17:38:48 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Game consoles]]></category>
		<category><![CDATA[Gaming]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[PS3]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[Mod]]></category>
		<category><![CDATA[piracy]]></category>
		<category><![CDATA[PS3 slim]]></category>

		<guid isPermaLink="false">http://geeknizer.com/install-custom-firmware-on-ps3</guid>
		<description><![CDATA[Few days back, failoverflow demoed that they had successfully installed custom Firmware on PS3, and achieve piracy of all sorts. This PS3 Hack lets you Pirate PS3 games, Run Linux... <span class="meta-more"><a href="http://geeknizer.com/install-custom-firmware-on-ps3/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" src="http://geeknizer.com/wp-content/uploads/ps3-usb-mod.jpg" alt="" />Few days back, <a href="http://geeknizer.com/ps3-hacked-to-allow-linux-os-pirated-games">failoverflow demoed</a> that they had successfully installed custom Firmware on PS3, and achieve piracy of all sorts.</p>
<p><strong>This PS3 Hack lets you Pirate PS3 games, Run Linux OS, Play PS1, PS2 Games on PS3.</strong></p>
<p><a rel="nofollow" href="http://kakaroto.homelinux.net/2011/01/ps3-first-custom-firmware-now-working/" target="_blank">KakaRoto</a> has announced the details of the hack.</p>
<blockquote><p>First CFW working. Grab <a href="http://bit.ly/hszcH3">http://bit.ly/hszcH3</a>, then &#8220;./create_cfw.sh PS3UPDAT.355.PUP CFW.PUP&#8221;. Permanently adds &#8220;install pkg files&#8221; menu.</p></blockquote>
<p>Folks at <a href="http://www.ps3-hacks.com" target="_blank">PS3hacks</a> has detailed the process.</p>
<p><strong>How to install Custom Firmware on PS3 for Pirated Games, OtherOS/Linux Support [PS3 Slim, Fat]</strong></p>
<p><strong>Download ps3 utilities and ps3 tools</strong> from github / team fail0verflow using these commands on your Linux PC:</p>
<ol>
<li>
<ul>
<li>
<pre>git clone https://github.com/kakaroto/ps3utils.git</pre>
</li>
<li>
<pre>cd ps3utils</pre>
</li>
<li>
<pre>make</pre>
</li>
<li>
<pre>cd ..</pre>
</li>
<li>
<pre>git clone git://git.fail0verflow.com/ps3tools.git</pre>
</li>
<li>
<pre>cd ps3tools</pre>
</li>
<li>
<pre>make</pre>
</li>
<li>
<pre>cp pkg unpkg ../ps3utils</pre>
</li>
</ul>
</li>
<li>Grab the PS3 encryption/decryption/signing keys from github:
<ul>
<li>
<pre>git clone https://github.com/kakaroto/ps3keys.git ~/.ps3</pre>
</li>
</ul>
</li>
<li>Download PS3 3.55 (or whatever official firmware PUP) from <a href="http://www.ps3-hacks.com/category/3" target="_blank">here</a></li>
<li>Extract and copy &#8220;PS3UPDAT.PUP&#8221; to the &#8220;ps3utils&#8221; directory</li>
<li>Create the PS3 Custom Firmware (CFW) from the original/official update (OFW):
<ul>
<li>
<pre>cd ps3utils</pre>
</li>
<li>
<pre>./create_cfw.sh PS3UPDAT.PUP CFW.PUP</pre>
</li>
</ul>
</li>
<li>Copy and rename CFW.PUP to a USB storage device keeping this directory structure in mind: /PS3/UPDATE/PS3UPDAT.PUP</li>
<li>Connect that USB device to your PS3 and install from Settings -&gt; System Update</li>
</ol>
<p>If you&#8217;re currently running 3.41 (or earlier) you can either remain there and create a specific CFW PUP for that version, or you can upgrade to a later PS3 firmware version, like 3.55 for example. It&#8217;s whatever original PUP file you use &#8211; only you cannot flash a version lower than the current version installed on your PS3. So if you&#8217;re already at 3.55, where you&#8217;re unable to downgrade, then for the moment you have no other choice but CFW (or OFW) 3.55. 3.41 on the other hand: upgrade <em>or</em> create CFW 3.41 and for the interim you&#8217;re still able to jailbreak and run unsigned &#8216;brews. See the other notes below.</p>
<p><strong>Download: </strong><a href="http://www.ps3-hacks.com/download.php?id=240">PS3 CFW 3.41</a><strong> </strong><strong> | </strong><a href="http://www.ps3-hacks.com/download.php?id=239">PS3 CFW 3.55</a><strong></strong></p>
<p>Note:</p>
<ol>
<li>This CFW does not modify the kernel in any way, meaning all the current compiled homebrew out there will not <a href="http://www.ps3-hacks.com/2011/01/04/ps3-custom-firmware-creator-released-permanently-add-install-pkgs-to-the-xmb/#">install</a> or run using &#8220;Install Package Files&#8221; from the XMB.</li>
<li>With the above point in mind you should know this CFW does not enable piracy. No piracy, no backups &#8211; straight homebrew.</li>
<li>Current PS3 homebrew and new homebrew will need to be &#8220;retail&#8221; packaged and signed; that&#8217;ll happen with <a href="http://www.ps3-hacks.com/2011/01/02/ps3-development-tools-from-fail0verflow/">fail0verflow&#8217;s tools</a>.</li>
<li>This is only the beginning. Prepare yourself for utter and absolute awesomeness.</li>
<li>PSN works.</li>
<li>PS1, PS2 games run in backward compatibility mode</li>
</ol>
<p>You may need to install the CFW PUP from the PS3 Recovery Menu. To do that, follow these steps:</p>
<ol>
<li>Ensure the PS3UPDAT.PUP is in /PS3/UPDATE/ on your USB device.</li>
<li>Power down the PS3.</li>
<li>Now press and hold the power button, the system will startup and shutdown again.</li>
<li>Release the power button, then press &amp; hold power again, you&#8217;ll hear one beep followed by two consecutive beeps.</li>
<li>Release power then follow the on-screen instructions. You&#8217;re now in the recovery menu.</li>
<li>Connect the USB device and select &#8220;System Update.&#8221;</li>
<li>Hope for the best.</li>
</ol>
<p>Note: you can restore OFW using the above method too.</p>
<p>Related:</p>
<ul>
<li><a href="http://geeknizer.com/ps3-jailbreak-psjailbreak">DIY Open Source PS3 Jailbreak allows Unsigned Apps, Games</a></li>
<li><a href="http://geeknizer.com/jailbreak-mod-ps3">HowTo Jailbreak, Mod PS3 Slim, Fat</a></li>
<li><a href="http://geeknizer.com/ps3-usb-mod-chip">PS3 USB mod Chip: Backup Games on HDD</a></li>
<li><a href="http://geeknizer.com/jailbreak-ps3-android-phone">Jailbreak your PS3 with Android Phone</a></li>
</ul>
<p>For latest <a href="http://geeknizer.com/tag/gaming">Gaming</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/android">android</a>, Tech news<strong> </strong><strong><a href="http://twitter.com/taranfx"><strong>@taranfx</strong> on Twitter</a> </strong>and you can also subscribe to use below:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/install-custom-firmware-on-ps3/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How to Hack GSM Nework, Phone</title>
		<link>http://geeknizer.com/how-to-hack-gsm-nework-phone/</link>
		<comments>http://geeknizer.com/how-to-hack-gsm-nework-phone/#comments</comments>
		<pubDate>Sat, 01 Jan 2011 13:05:15 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Telecom]]></category>
		<category><![CDATA[communications]]></category>
		<category><![CDATA[GSM]]></category>
		<category><![CDATA[hack]]></category>

		<guid isPermaLink="false">http://geeknizer.com/how-to-hack-gsm-nework-phone</guid>
		<description><![CDATA[A Group of researchers demonstrated a start-to-finish means of monitoring an encrypted GSM cellphone calls and text messages, using only sub-$15 telephones as network &#8220;sniffers,&#8221; attached to a laptop computer&#160;... <span class="meta-more"><a href="http://geeknizer.com/how-to-hack-gsm-nework-phone/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><a href="http://geeknizer.com/wp-content/uploads/gsm-hacked.jpg"><img class="alignleft" title="gsm-hacked" border="0" alt="gsm-hacked" src="http://geeknizer.com/wp-content/uploads/gsm-hacked_thumb.jpg" width="145" height="83" /></a>A Group of researchers demonstrated a start-to-finish means of monitoring an encrypted GSM cellphone calls and text messages, using only sub-$15 telephones as network &#8220;sniffers,&#8221; attached to a laptop computer&#160; powered by open source softwares.</p>
<p>GSM Security is inherently weak and that&#8217;s why it was made possible to <a href="http://geeknizer.com/the-unsecure-gsm-encryption-you-are-vulnerable-to-hack-the-dark-secret">Hack GSM Security (GSM&#8217;s 64-bit A5/1 encryption),</a> last year. However, governments own devices that are worth $50,000, which essentially monitor phone activities for National security.</p>
<blockquote><p>&#8220;GSM is insecure, the more so as more is known about GSM,&#8221; said <a href="http://srlabs.de/" target="_blank">Security Research Labs</a> researcher Karsten Nohl. &#8220;It&#8217;s pretty much like computers on the net in the 1990s, when people didn&#8217;t understand security well.&#8221; </p>
</blockquote>
<p>Every aspect of the <strong>GSM Hack</strong> was demonstrated from start to end including scenarios in which GSM networks exchange subscriber location data, in order to correctly route phone calls and SMSs, allows anyone to determine a subscriber&#8217;s current location with a simple Internet query, to the level of city or general rural area. Once a phone&#8217;s City is known, a potential attacker can drive through the area, sending the target phone &#8220;silent&#8221; or &#8220;broken&#8221; SMS messages that do not show up on the phone. By sniffing to each bay station&#8217;s traffic, listening for the delivery of the message and the response of the target phone at the correct time, the location of the target phone can be more precisely identified.</p>
<p><strong>GSM Network Sniffer</strong></p>
<p>Researchers replaced the firmware of a simple Motorola GSM phone with their own, which allowed them to retain the raw data received from the cell network, and examine more of the cellphone network space than a single phone ordinarily monitors. Modifying the USB interface, helped them send this data in real time to a computer, which captured every bit of the information.</p>
<p>By sniffing the network while sending a target phone an SMS, they were able to determine precisely which random network ID number belonged to the target. This gave them the ability to identify which of the myriad streams of information they wanted to record from the network. After that, the next step is essentially decrypting the information. ITs not that easy, but was made possible by the way operator networks exchange system information with their phones.</p>
<p><a href="http://geeknizer.com/wp-content/uploads/gsm-hack.jpg"><img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="gsm-hack" border="0" alt="gsm-hack" src="http://geeknizer.com/wp-content/uploads/gsm-hack_thumb.jpg" width="500" height="242" /></a></p>
<p>As part of this background communication, GSM networks send out identifying information, as well as &#8220;keepalive&#8221; messages and empty spaces are filled with buffered bytes. Truth be told, a new GSM standard was put in place several years ago to turn these buffers into random bytes, they in fact remain largely identical today, under a much older standard. Sticking to older standards enabled hackers to predict with a high degree of probability the plain-text content of these encrypted system messages. This, combined with a 2 terabyte table of pre-computed encryption keys (a so-called rainbow table), allows a cracking program to discover the secret key to the session&#8217;s encryption in about 20 seconds. (Rainbow tables are usually used in all kinds of Brute-force password hacking).</p>
<p>Many GSM operators reuse these session keys for several successive communications, allowing a key extracted from a test SMS to be used again to record the next telephone call, minimizing the need for recomputation.</p>
<p>The process was demonstrated using their software to sniff the headers being used by a phone, extract and crack a session-encryption key, and then use this to decrypt and record a live GSM call between two phones in no more than a few minutes.</p>
<p><a href="http://geeknizer.com/wp-content/uploads/gsm-phone-hack.jpg"><img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="gsm-phone-hack" border="0" alt="gsm-phone-hack" src="http://geeknizer.com/wp-content/uploads/gsm-phone-hack_thumb.jpg" width="550" height="335" /></a></p>
<p><strong>Can something be done about GSM&#8217;s security?</strong></p>
<p>Any geek can make such devices and with the help of the open source software, can mimic these hacks. So can we really do something to prevent these kinds of hacks from happening? </p>
<blockquote><p>&#8220;Much of this vulnerability could be addressed relatively easily&#8221;, Nohl said. &#8220;Operators could make sure that their network routing information was not so simply available through the Internet. They could implement the randomization of padding bytes in the system information exchange, making the encryption harder to break. They could certainly avoid recycling encryption keys between successive calls and SMSs&#8221;.</p>
<p> &#8220;This is all a 20-year-old infrastructure, with lots of private data and not a lot of security,&#8221; he said. &#8220;We want you to help phones go through the same kind of evolutionary steps that computers did in the 1990s.&#8221;</p>
</blockquote>
<p>Worst part is, all the current 3G phones are NOT shielded from this hack. Knowing that 3G is primarily used for Data, its now easy to capture any 3G user&#8217;s online activity including their passwords and credit card numbers.</p>
<p>Maybe its high time for GSM consortium to wakeup and address these issues, or atleast learn few things from CDMA networks, which are inherently secure.</p>
<p><strong>Resources</strong>:</p>
<p>Rainbow tables, Airprobe, Kraken&#160; <a href="http://srlabs.de" target="_blank">srlabs.de</a>    <br />OsmocomBB firmware <a href="http://osmocom.or" target="_blank">osmocom.or</a></p>
<p><a href="http://events.ccc.de/congress/2010/Fahrplan/attachments/1783_101228.27C3.GSM-Sniffing.Nohl_Munaut.pdf" target="_blank">PDF Presentation</a></p>
<p>The <strong>Video Presentation</strong> can be downloaded here: <a href="http://achtbaan.nikhef.nl/27c3-stream/releases/mkv/%5b4208%5d%20Wideband%20GSM%20Sniffing/20101228-134503.wmv.mkv" target="_blank">Part1</a>, <a href="http://achtbaan.nikhef.nl/27c3-stream/releases/mkv/%5b4208%5d%20Wideband%20GSM%20Sniffing/20101228-143153.wmv.mkv" target="_blank">Part2</a>.</p>
<p>We write about <a href="http://geeknizer.com/tag/security">Security</a>,&#160; <a href="http://geeknizer.com/tag/open-source">Open Source</a>, <a href="http://geeknizer.com/tag/programming">Programming</a>, <a href="http://geeknizer.com/">Web</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>,<a href="http://geeknizer.com/tag/android">Android</a> and latest in Tech <a href="http://twitter.com/taranfx"><strong>@taranfx</strong> on Twitter</a> or by subscribing below:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/how-to-hack-gsm-nework-phone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://achtbaan.nikhef.nl/27c3-stream/releases/mkv/%5b4208%5d%20Wideband%20GSM%20Sniffing/20101228-134503.wmv.mkv" length="220275177" type="video/x-matroska" />
<enclosure url="http://achtbaan.nikhef.nl/27c3-stream/releases/mkv/%5b4208%5d%20Wideband%20GSM%20Sniffing/20101228-143153.wmv.mkv" length="173851021" type="video/x-matroska" />
		</item>
		<item>
		<title>How BitTorrent becomes a DDoS Tool [Hacking]</title>
		<link>http://geeknizer.com/bittorrent-as-ddos-tool/</link>
		<comments>http://geeknizer.com/bittorrent-as-ddos-tool/#comments</comments>
		<pubDate>Thu, 30 Dec 2010 16:34:22 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[torrent]]></category>

		<guid isPermaLink="false">http://geeknizer.com/bittorrent-as-ddos-tool</guid>
		<description><![CDATA[A talk at the 27C3 has revealed curtains off a new kind of swarms that can exploit DDoS attacks.  One of the speakers at Chaos Communications Congress revealed how BitTorrent... <span class="meta-more"><a href="http://geeknizer.com/bittorrent-as-ddos-tool/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><a href="http://geeknizer.com/wp-content/uploads/bittorrent-ddos.jpg"><img src="http://geeknizer.com/wp-content/uploads/bittorrent-ddos.jpg" alt="" title="bittorrent-ddos" width="220" height="220" class="alignleft size-full wp-image-6623" /></a>A talk at the 27C3 has revealed curtains off a new kind of swarms that can exploit DDoS attacks. <br />
One of the speakers at Chaos Communications Congress revealed how BitTorrent swarms can be exploited to take down large websites with relative ease under <a href="http://events.ccc.de/congress/2010/Fahrplan/events/4210.en.html" target="_blank">a talk</a> named &#8220;Lying To The Neighbours&#8221; .</p>
<p>The vulnerability is actually found in the technology that works on <a href="http://geeknizer.com/download-torrentz-without-torrent-file">trackerless torrents (DHT).</a> Its now possible for someone to trick downloaders of popular files into send thousands of requests to a webserver of choice, taking it down as a result. Effectively turning <strong>BitTorrent into a very effective DDoS tool</strong>.</p>
<p>BitTorrent have lived over the years because of their reliability and effectiveness. Unlike a server centric model, where the dependency is on a one server (or distributed servers), its distributed and directly available through individual nodes that auto-discover each other, resulting in faster and more reliable data transfers. This is the reason why, everyday, millions of people (Swarm) use bittorrents to download Terabytes of data.</p>
<p><a href="http://geeknizer.com/wp-content/uploads/bittorrent-swarm.jpg"><img style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" title="bittorrent-swarm" src="http://geeknizer.com/wp-content/uploads/bittorrent-swarm_thumb.jpg" border="0" alt="bittorrent-swarm" width="500" height="478" /></a></p>
<p>Hackers have now used the popular DHT technology to abuse BitTorrent downloaders to DDoS a webserver of choice. DHT, under normal operation, discovers peers who are downloading the same files, without communicating with a central BitTorrent tracker. If there are enough peers downloading the same file, this could easily take down medium to large websites. The worrying part is that the downloaders who are participating in the DDoS will not be aware of what&#8217;s going on.</p>
<blockquote><p>&#8220;The core problem are the random NodeIDs. The address hashing and verification scheme works for scenarios like the old Internet, but becomes almost useless in the big address space of IPv6,&#8221; Astro told TorrentFreak in a comment. As a result, any BitTorrent swarm can be abused to target specific websites and potentially take them down.</p></blockquote>
<p>These days,  DDoS attacks have been in the news regularly, mostly carried out under the flag of Anonymous &#8220;Operation Payback&#8221;. Initially anti-piracy targets such as the MPAA and RIAA were taken offline, and last month the focus switched to organizations that acted against Wikileaks, including Mastercard, then Visa and Paypal.</p>
<blockquote><p>&#8220;Not connecting to privileged ports (&lt; 1024) where most critical services reside,&#8221; is one ad-hoc solution, but Astro says that since it&#8217;s a design error, the protocol has to be redefined eventually.</p></blockquote>
<p>The idea of using BitTorrent as a DDoS tool is not entirely new. In fact, researchers have previously <a href="http://www.google.com/search?&amp;q=DDoS+Vulnerability+Analysis+of+BitTorrent+Protocol" target="_blank">shown</a> that adding a webserver&#8217;s IP address as a BitTorrent tracker could result in a similar DDoS. The downside of this method is, however, that it requires a torrent file to become popular, while the DHT method can simply exploit existing torrents that are already being downloaded by thousands of people.</p>
<p>Over the next few years, it may actually be able to create no<a href="http://geeknizer.com/non-blockable-torrents">n-blockable Torrents</a>. Even today, there are ways of <a href="http://geeknizer.com/bypass-torrent-throttling-shaping-blocking">Bypassing torrent blocking, throttling</a>. Now, what remains to be seen is that will BitTorrent developers do enough to fix DDoS vulnerability or will it remain open and cause havoc.</p>
<p>You can find the Slides of the presentation <a href="http://events.ccc.de/congress/2010/Fahrplan/attachments/1765_27c3-lying-to-the-neighbours.pdf" target="_blank">here</a>.<br />
Update: <a href="http://achtbaan.nikhef.nl/27c3-stream/releases/mkv/%5b4210%5d%20Lying%20To%20The%20Neighbours/20101228-124503.wmv.mkv">Download Video Presentation here</a></p>
<p>For latest <a href="http://geeknizer.com/tag/security">Security</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/android">android</a>, Tech news<strong> </strong><strong><a href="http://twitter.com/taranfx"><strong>@taranfx</strong> on Twitter</a> </strong>and you can also subscribe to use below:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/bittorrent-as-ddos-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://achtbaan.nikhef.nl/27c3-stream/releases/mkv/%5b4210%5d%20Lying%20To%20The%20Neighbours/20101228-124503.wmv.mkv" length="314694210" type="video/x-matroska" />
		</item>
		<item>
		<title>PS3 Hacked to allow Linux OS, Pirated Games</title>
		<link>http://geeknizer.com/ps3-hacked-to-allow-linux-os-pirated-games/</link>
		<comments>http://geeknizer.com/ps3-hacked-to-allow-linux-os-pirated-games/#comments</comments>
		<pubDate>Thu, 30 Dec 2010 14:18:07 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Gaming]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[PS3]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[PS3 slim]]></category>

		<guid isPermaLink="false">http://geeknizer.com/ps3-hacked-to-allow-linux-os-pirated-games</guid>
		<description><![CDATA[PS3 has been hacked multiple times, and Sony has been fixing it, and what they did was penalized the hack by removing  3rd party OS installation, or Linux installation in... <span class="meta-more"><a href="http://geeknizer.com/ps3-hacked-to-allow-linux-os-pirated-games/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><a href="http://geeknizer.com/wp-content/uploads/ps3-hack.jpg"><img class="alignleft size-full wp-image-6616" title="ps3-hack" src="http://geeknizer.com/wp-content/uploads/ps3-hack.jpg" alt="" width="245" height="149" /></a>PS3 has been hacked multiple times, and Sony has been fixing it, and what they did was penalized the hack by <a href="http://geeknizer.com/ps3-linux-support">removing  3rd party OS</a> installation, or Linux installation in simpler words.</p>
<p><a href="http://geeknizer.com/jailbreak-mod-ps3">PSJailbreak</a> Exploit worked great hack and actually made pirated games possible because Hypervisor allows unsigned code to run on PS3.</p>
<p>It has now been Hacked again, this time to Enable Linux Installation, and even Play pirated games on PS3 &amp; PS3 Slim. The good work was announced today at 27C3 congress by a group called fail0verflow which would make it possible to Install Full Linux OS (with 3d) and Pirated Games on Linux.</p>
<p>The first few minutes of the conference were spent explaining the state of security on other consoles (Wii, 360, etc). Following this, the group went on to explain the current state of affairs on the PS3. First, explaining Geohot&#8217;s memory line glitching exploit from earlier this year. The team then went on to explain the current PS3 security bypasses, such as jailbreaking and service mode/downgrading.</p>
<p>Approximately a half hour in, the team revealed their new PS3 secrets, the moment we all were waiting for. One of the major highlights here was, dongle-less jailbreaking by overwriting the bootup NOR flash, giving complete control over the system. The other major feat, was calculating the public private keys (due to botched security), giving users the ability to sign their own SELFs Following this, the team declared Sony&#8217;s security to be &#8220;EPIC FAIL&#8221;! Even though it took decade to break this security.</p>
<p>The recent advent of these new exploits means current firmware is vulnerable, v3.55 and possibly beyond. It will be very difficult for Sony to fix the described exploits.</p>
<p>The team then displayed the website http://fail0verflow.com/, where we assume they will host examples of the new exploits and further details. They stated, that easy to use tools would be coming next month.</p>
<p>Download Presentation PPT: <a href="http://www.multiupload.com/LJTFC1621B" target="_blank">1780_27c3_console_hacking_2010.rar (1.43 MB</a>)</p>
<p>Here is a video that actually explains the indepth details of How PS3 Hacks have worked in the past, and what&#8217;s the new <a href="http://fail0verflow.com" target="_blank">fail0verflow</a> Hack is about.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="640" height="385" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/hcbaeKA2moE?fs=1&amp;hl=en_US" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="640" height="385" src="http://www.youtube.com/v/hcbaeKA2moE?fs=1&amp;hl=en_US" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>Stay tuned to this article and Taranfx.com we will be updating it as more info is available.</p>
<p>If you are looking for Jailbreaking guides:</p>
<ul>
<li><a href="http://geeknizer.com/jailbreak-ps3-android-phone">Jailbreak your PS3 with Android Phone</a></li>
<li><a href="http://geeknizer.com/ps3-jailbreak-psjailbreak">DIY Open Source PS3 Jailbreak allows Unsigned Apps, Games</a></li>
<li><a href="http://geeknizer.com/jailbreak-mod-ps3">HowTo Jailbreak, Mod PS3 Slim, Fat</a></li>
<li><a href="http://geeknizer.com/ps3-usb-mod-chip">PS3 USB mod Chip: Backup Games on HDD</a></li>
</ul>
<p>For latest <a href="http://geeknizer.com/tag/gaming">Gaming</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/android">android</a>, Tech news<strong> </strong><strong><a href="http://twitter.com/taranfx"><strong>@taranfx</strong> on Twitter</a> </strong>and you can also subscribe to use below:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/ps3-hacked-to-allow-linux-os-pirated-games/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Skype Protocol Obfuscation Security Source Code</title>
		<link>http://geeknizer.com/skype-protocol-obfuscation-security-source-code/</link>
		<comments>http://geeknizer.com/skype-protocol-obfuscation-security-source-code/#comments</comments>
		<pubDate>Mon, 20 Dec 2010 16:44:12 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[voice]]></category>
		<category><![CDATA[voip]]></category>

		<guid isPermaLink="false">http://geeknizer.com/skype-protocol-obfuscation-security-source-code</guid>
		<description><![CDATA[Skype is the undisputed leader in VoIP services both in quality and security. For years, hackers had been working hard to crack the strong Encryption Skype Protocol uses to Obfuscate... <span class="meta-more"><a href="http://geeknizer.com/skype-protocol-obfuscation-security-source-code/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><a href="http://geeknizer.com/wp-content/uploads/skype-encryption.jpg"><img class="alignleft size-full wp-image-6513" title="skype-encryption" src="http://geeknizer.com/wp-content/uploads/skype-encryption.jpg" alt="" width="200" height="210" /></a>Skype is the undisputed leader in VoIP services both in quality and security. For years, hackers had been working hard to crack the strong Encryption Skype Protocol uses to Obfuscate its voice packets.</p>
<p>Encryption was so good that almost no one has been able to reverse engineer it out of the numerous Skype binaries. Those who claimed to have actually get through, failed to release it publicly. It was all shadowed until someone released the complete Obfuscation algorithm to the web in Plain C code.</p>
<p>The complete source code is available at <a href="http://cryptolib.com/ciphers/skype">http://cryptolib.com/ciphers/skype</a> . On carefully analyzing the code, one can come to the conclusion that the greatest secret of Skype communication protocol, is in obfuscated Skype RC4 key expansion algorithm.</p>
<p>The leak actually happened a couple of months ago. Within few weeks of the leak, the code was being used by hackers &amp; spammers.  A better thing was to make the algorithm available to IT security Gurus as publication will help the IT security community help secure Skype better.</p>
<p>There is plenty of good cryptography in Skype. Most of it is implemented properly too. There are seven types of communication encryption in Skype: its servers use <strong>AES-256</strong>, the <strong>supernodes</strong> and clients use <strong>three types of RC4 encryption</strong> &#8211; the <strong>old TCP RC4</strong>, the <strong>old UDP RC4</strong> and the new <strong>DH-384 based TCP RC4</strong>, while the clients also use <strong>AES-256 on top of RC4</strong>.</p>
<p>I tried to analyze the code, trust me its really complicated, really rocket science of Cryptography.</p>
<p>Stay tuned for more on Latest in tech, Security, <a href="../tag/android">Android</a>, <a href="../tag/iphone">iPhone</a>, <a href="../tag/programming">Programming </a>and Tech news via <a href="http://twitter.com/taranfx" target="_blank"><strong>@taranfx</strong> on Twitter</a> or:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/skype-protocol-obfuscation-security-source-code/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hijack Facebook, Twitter accounts with Firesheep, How to Secure against it</title>
		<link>http://geeknizer.com/hijack-facebook-twitter-accounts/</link>
		<comments>http://geeknizer.com/hijack-facebook-twitter-accounts/#comments</comments>
		<pubDate>Tue, 26 Oct 2010 14:01:29 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Social networks]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[WiFi]]></category>

		<guid isPermaLink="false">http://geeknizer.com/hijack-facebook-twitter-accounts</guid>
		<description><![CDATA[How easy can hacking get? Do you wish to hack someone else&#8217;s Amazon, Facebook, Twitter or Windows Live account in just one click? Its now as easy as that with a... <span class="meta-more"><a href="http://geeknizer.com/hijack-facebook-twitter-accounts/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><a href="http://geeknizer.com/wp-content/uploads/wifi-hijack.jpg"><img class="alignleft size-full wp-image-6142" title="wifi-hijack" src="http://geeknizer.com/wp-content/uploads/wifi-hijack.jpg" alt="" width="245" height="223" /></a>How easy can hacking get? Do you wish to hack someone else&#8217;s Amazon, Facebook, Twitter or Windows Live account in just one click?</p>
<p>Its now as easy as that with a a Firefox extension called Firesheep which can  hijack a person&#8217;s current user-session over an open Wi-Fi connection.</p>
<p>Firesheep is a work of  Eric Butler who made the proof oc concept public after after presenting at a Security event. The purpose of the experiment was to showcase the security risks associated with session hijacking, aka <strong>sidejacking</strong>.</p>
<p>So what all can be hacked with Firesheep? Nearly  26 online services, which includes all popular online services: Amazon, Facebook, Foursquare, Google, The New York Times, Twitter, Windows Live, WordPress and Yahoo.</p>
<p>The extension is so flexible that it can be customized to allow a hacker to target other Websites not listed by Firesheep.</p>
<p>While Firesheep sounds scary, its not as scary as it may sound first. Even though the extension is downlaoded more than 100,000 times, there&#8217;s nothing to be scared of.</p>
<p><strong>How Firesheep works</strong></p>
<p>Firesheep is basically a packet sniffer that can analyze all the unencrypted Web traffic on an open Wi-Fi connection between a Wi-Fi router and the personal computers on the same network. The extension polls around network for someone to log in, when someone does, browser&#8217;s site-specific cookie communicates with the site and contains personally identifying information such as your user name and an site specific session ID.</p>
<p>As victim&#8217;s browser swaps cookie information back and forth with the Website, our packet sniffer can capture this information and hijack the session. Coz cookies has no password information and it  has session timeout, it does eventually. But on a serious ote, even temporary access to the account can bring havocs.</p>
<p><strong>How to use Firesheep</strong></p>
<p>Install WinPcap on windows (Mac Os doesn&#8217;t need this) and get the <a href="http://codebutler.github.com/firesheep/" target="_blank">Firesheep extension</a> and then open it up by clicking on View&gt;Sidebars&gt;Firesheep. Click the button that says &#8220;Start Capturing.&#8221;</p>
<p>Once you click the button, it starts snooping. Then onwards all sessions that are captured are automatically displayed</p>
<p><strong>How to Bypass Firesheep Hijacks?</strong></p>
<ol>
<li>If you feel your account has been compromised, immidiately logout. As soon as you do that, hijacked cookie becomes invalid, and no longer can be mis-used.</li>
<li>Use A VPN: Try using a Virtual Private Network client such as the free version of HotSpot Shield. This piece of software basically creates a secure tunnel for your data that runs between the Wi-Fi router and your computer.</li>
<li>USe HTTPS Everywhere: If you&#8217;re a Firefox user you can also use extensions such as HTTPS Everywhere built by the Electronic Frontier Foundation. This extension forces certain Websites to use a secure SSL connection for your entire browsing session instead of just the login.</li>
<li>Use Strict Transport Security (STS): Strict Transport Security (STS) is a relatively new security feature that is starting to appear in some browsers. STS automatically forces your browser to make a secure connection with every Web page that supports SSL encryption. Once you start using STS, you will not be able to use an insecure connection ever again when connecting to a specific site such as Facebook or Amazon. Chrome has supported STS since Chrome 4, and Firefox 4 will include STS when the official version launches in the coming months.</li>
<li>Encrypt your home/office network:  Use the strongest possible encryption on your Home and office Wifi connections.  WPA2 is much better than WEP.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/hijack-facebook-twitter-accounts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Capture, Sniff Wifi Traffic</title>
		<link>http://geeknizer.com/capture-sniff-wifi-traffic/</link>
		<comments>http://geeknizer.com/capture-sniff-wifi-traffic/#comments</comments>
		<pubDate>Fri, 01 Oct 2010 14:53:40 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WiFi]]></category>

		<guid isPermaLink="false">http://geeknizer.com/capture-sniff-wifi-traffic</guid>
		<description><![CDATA[Its not tough to Hijack / Capture / Sniff Wifi Traffic on almost any network as long as you are connected to it. Once you apply all the correct tricks,... <span class="meta-more"><a href="http://geeknizer.com/capture-sniff-wifi-traffic/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><a href="http://geeknizer.com/wp-content/uploads/wifi-hacking.jpeg"><img class="alignleft size-full wp-image-5947" title="wifi-hacking" src="http://geeknizer.com/wp-content/uploads/wifi-hacking.jpeg" alt="" width="245" height="136" /></a>Its not tough to <strong>Hijack / Capture / Sniff Wifi Traffic</strong> on almost any network as long as you are connected to it. Once you apply all the correct tricks, all future traffic for Wifi clients i.e. laptops, mobiles will be routed from your PC, giving you every bit of information about what others are doing on the network.</p>
<p><strong>How to hijack/ capture/ Sniff HTTP traffic</strong></p>
<p>We will be using  <a href="http://en.wikipedia.org/wiki/Address_Resolution_Protocol">ARP</a> and <a href="http://linux.die.net/man/8/iptables">iptables</a> on a Linux machine to accomplish most of the stuff. It’s an easy and fun way to harass your friends, family, or flatmates while exploring the networking protocols.</p>
<p><strong>Warning</strong>: Do not attempt to do this on a Public Wifi or a Corporate Wifi. Doing so could lead you to serious consequences. In no way is Taranfx responsible for any harms. This is solely intended for fun @ home.</p>
<p>Lets take 3 PCs into reference for our activity:</p>
<ul>
<li><em>Real gateway router</em>: IP address 192.168.0.1, MAC address 48:5d:34:aa:c6:aa</li>
<li><em>Fake gateway</em>: A Laptop PC called hacker-laptop, IP address 192.168.0.200, MAC address c0:30:2b:47:ef2:74</li>
<li><em>Victim</em>: a laptop on wireless called victim-laptop, IP address 192.168.0.111, MAC address 00:23:6c:8f:3f:95</li>
</ul>
<p><em> The gateway router, like most modern routers, is bridging between the wireless and wired domains, so ARP packets get broadcast to both domains.</em></p>
<p><strong>Step 1: Enable IPv4 forwarding</strong><br />
Unless IP forwarding is enabled, hacker-laptop won&#8217;t receive all the network traffic because the networking subsystem is going to ignore packets that aren’t destined for us. So step 1 is to enable IP forwarding. To enable it, set a non zero value like:</p>
<blockquote><p>root@hacker-laptop:~# echo 1 &gt; /proc/sys/net/ipv4/ip_forward</p></blockquote>
<p><strong>Step 2: Set routing rules</strong><br />
We want to set rules so that all traffic routes through hacker-laptop, acting like a NAT router. Just like a typical NAT, it would  rewrite the destination address in the IP packet headers to be its own IP address.</p>
<p>This can be done as follows:</p>
<blockquote><p>tarranfx@hacker-laptop:~$ sudo iptables -t nat -A PREROUTING \<br />
&gt; -p tcp &#8211;dport 80 -j NETMAP &#8211;to 192.168.0.200</p></blockquote>
<p>The iptables command has 3 components:</p>
<ul>
<li>When to apply a rule (-A PREROUTING)</li>
<li>What packets get that rule (-p tcp &#8211;dport 80)</li>
<li>The actual rule (-t nat … -j NETMAP &#8211;to 192.168.0.200)</li>
</ul>
<p><em>What above command does:</em> If you’re a TCP packet destined for port 80 (HTTP traffic), actually make my address, 192.168.0.200, the destination, NATting both ways so this is transparent to the source.”</p>
<p><strong>Step 3: Adding IP adddress to interface</strong><br />
The networking subsystem will not allow you to ARP for a random IP address on an interface — it has to be an IP address actually assigned to that interface:</p>
<blockquote><p>taranfx@hacker-laptop:~$ sudo ip addr add 192.168.0.1/24 dev eth0</p></blockquote>
<p>and verify that the original IP address 192.168.0.200, and the gateway address 192.168.0.1.</p>
<blockquote><p>taranfx@hacker-laptop:~$ ip addr<br />
&#8230;<br />
3: eth0:  mtu 1500 qdisc noqueue state UNKNOWN<br />
link/ether c0:30:2b:47:ef2:74 brd ff:ff:ff:ff:ff:ff<br />
inet 192.168.0.200/24 brd 192.168.1.255 scope global eth0<br />
inet 192.168.0.1/24 scope global secondary eth0<br />
inet6 fe80::230:1bff:fe47:f274/64 scope link<br />
valid_lft forever preferred_lft forever<br />
&#8230;</p></blockquote>
<p><strong> Step 4: Responding to HTTP requests</strong><br />
hacker-laptop would need a HTTP server setup. t could be any damn server, I used Apache for ease of use. Here you can get creative, e.g. respond with random pages for specific URLs or define a local URL e.g. http://fun</p>
<p><strong>Step 5: Test pretending to be the gateway</strong><br />
Most of the things are already done and our hacker-laptop is ready to pretend as the Wifi Gateway, but the trouble is convincing victim-laptop that the MAC address for the gateway has changed, to that of hacker-laptop.</p>
<p>The solution is to send a <strong>Gratuitous ARP</strong>, which says “I know nobody asked, but I have the MAC address for 192.168.0.1”. Machines that hear that Gratuitous ARP will replace an existing mapping from 192.168.0.1 to a MAC address in their ARP caches with the mapping advertised in that Gratuitous ARP.<br />
There are lots of command line utilities and bindings in various programming language that make it easy to issue ARP packets. I used the arping tool:</p>
<blockquote><p>taranfx@hacker-laptop:~$ sudo arping -c 3 -A -I eth0 192.168.0.1</p></blockquote>
<p>We’ll send a Gratuitous ARP reply (-A), three times (-c -3), on the eth0 interface (-l eth0) for IP address 192.168.0.1.</p>
<p>This can be then verified on the victim&#8217;s machine using &#8220;arp -a&#8221; command</p>
<p>Bingo! victim-laptop now thinks the MAC address for IP address 192.169.1.1 is 0:30:1b:47:f2:74, which is hacker-laptop’s address.<br />
If I try to browse the web on victim-laptop, I am served the resource matching the rules in hacker-laptop’s web server.</p>
<p>That means all of the non-HTTP traffic associated with viewing a web page still happens as normal. In particular, when hacker-laptop gets the DNS resolution requests for Google.com, the test site I visited, it will follow its routing rules and forward them to the real router, which will send them out to the Internet:</p>
<p>The fact is that hacker-laptop has rerouted and served the request is totally transparent to the client at the IP layer and victim-laptop has no clue.</p>
<p><strong>Undo the changes</strong></p>
<p><strong> </strong>So, you had enough fun and wish to revert? Here we go:</p>
<blockquote><p>taranfx@hacker-laptop:~$ sudo ip addr delete 192.168.0.1/24 dev eth0<br />
taranfx@hacker-laptop:~$ sudo iptables -t nat -D PREROUTING -p tcp &#8211;dport 80 -j NETMAP &#8211;to 192.168.0.200</p></blockquote>
<p>To get the client machines to believe the router is the real gateway, you might have to clear the gateway entry from the ARP cache with arp -d 192.168.0.1, or bring your interfaces down and back up.</p>
<p>We write about Latest in tech, <a href="http://geeknizer.com/tag/google">Google</a>,  <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/gizmos">Gadgets</a>, <a href="http://geeknizer.com/tag/open-source">Open Source</a>, <a href="http://geeknizer.com/tag/programming">Programming</a>. Grab them all <a href="http://twitter.com/taranfx">@taranfx on Twitter</a> or below:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/capture-sniff-wifi-traffic/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How to Hack VoIP, Video Conference</title>
		<link>http://geeknizer.com/how-to-hack-voip-video-conference/</link>
		<comments>http://geeknizer.com/how-to-hack-voip-video-conference/#comments</comments>
		<pubDate>Mon, 20 Sep 2010 17:03:37 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Video]]></category>
		<category><![CDATA[voip]]></category>

		<guid isPermaLink="false">http://geeknizer.com/how-to-hack-voip-video-conference</guid>
		<description><![CDATA[Network admins and users have a big mis-conception about VoIP, IP Video. They think its secure  enough to be used in Coporate offices. IP Video conference can be easily hacked... <span class="meta-more"><a href="http://geeknizer.com/how-to-hack-voip-video-conference/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><a href="http://geeknizer.com/wp-content/uploads/voip-hacked.jpg"><img class="alignleft size-full wp-image-5871" title="voip-hacked" src="http://geeknizer.com/wp-content/uploads/voip-hacked.jpg" alt="" width="250" height="177" /></a>Network admins and users have a big mis-conception about <strong>VoIP, IP Video</strong>. They think its secure  enough to be used in Coporate offices.</p>
<p><strong>IP Video conference</strong> can be <strong>easily hacked</strong> using a freeware tool that allows attackers to <strong>monitor calls in real-time</strong> and record Video files.</p>
<p>The original exploit was<a href="http://www.darkreading.com/insiderthreat/security/app-security/showArticle.jhtml?articleID=219000196" target="_blank"> first demonstrated</a> more than a year ago, but sadly, most corporate networks are still vulnerable to it, says Jason Ostrom, director of VIPER Lab at <a href="http://geeknizer.com/tag/voip">VoIP </a>vendor Sipera, where he performs penetration tests on clients&#8217; business VoIP networks.</p>
<p>He says he sees only 5% of these networks are properly configured to block this attack, which can yield audio and video files of entire conversations. &#8220;I almost never see encryption turned on,&#8221; he says.</p>
<p>Only about one in 20 organizations secures its IP video with encryption or other measures, according to Sipera&#8217;s research, so IP video is ripe for attack. Ostrom and fellow researcher Arjun Sambamoorthy used a pair of homegrown open-source tools to perform the hacks at Defcon, which performs <strong>video eavesdropping, and VideoJak</strong>, which <strong>intercepts and replays video</strong>.</p>
<p>However, the attacker needs physical access to the IP network to execute these hacks, the researchers say, as well as access to a VLAN port on which the video application resides.</p>
<p>Ostrom demonstrated the attack at the Forrester Security Forum in Boston last week using a <a href="http://geeknizer.com/tag/cisco">Cisco </a>switch, two Polycom videophone and a laptop armed with a hacking tool called <strong><a href="http://www.sipera.com/index.php?action=resources,uc_sniff" target="_blank">UCSniff </a></strong>that he pulled together from <a href="http://geeknizer.com/tag/open-source">open source</a> tools.</p>
<p><a href="http://geeknizer.com/wp-content/uploads/ucsniff.jpg"><img class="aligncenter size-full wp-image-5869" title="ucsniff" src="http://geeknizer.com/wp-content/uploads/ucsniff.jpg" alt="" width="608" height="386" /></a></p>
<p><strong>How VoIP, IP video hack works</strong></p>
<p>Hacker needs to get access to a VoIP phone jack to which he plugs a laptop with the hacking tool- UCSniff. Using address-resolution protocol (ARP) spoofing, the device gathers the corporate VoIP directory, giving the hacker the ability to keep an eye on any phone and to intercept its calls. There&#8217;s a tool within UCSniff called ACE that simplifies capturing the corporate directory.</p>
<p>Once intercepted, the audio and video from the targeted call flow through the laptop, where it can be viewed as it streams by and also where it is recorded in separate files, one for each end of the conversation, Ostrom says.</p>
<p>They used UCSniff to record a &#8216;safe&#8217; video stream, then converted it to an AVI file. Then we used the VideoJak tool that also supports man-in-the-middle,&#8221; he says. VideoJak intercepts the video stream, and replaces it with a malicious or phony video payload.</p>
<p>So, for instance, a bad guy could replace a surveillance feed of his breaking into the CEO&#8217;s office with a routine clip trained on the office door, with no sign of the break-in.</p>
<p><strong>How to Prevent VoIP, Video Conference Hacking?</strong></p>
<p>The strongest answer &#8212; apply Encryption for both signaling and media. The problem isn&#8217;t with the networking or VoIP and video gear itself, but rather with how they are configured in the network.</p>
<p>The scary thing is, 70% of the networks tested by pen-testers are vulnerable to toll fraud attacks that use the corporate network as a proxy for make long distance calls.</p>
<p>We write about Latest in tech, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>, <a href="http://geeknizer.com/tag/android">Android</a>, <a href="http://geeknizer.com/tag/tablet">Tablets</a>, <a href="http://geeknizer.com/tag/gizmos">Gadgets</a>, <a href="http://geeknizer.com/tag/open-source">Open Source</a>, <a href="http://geeknizer.com/tag/programming">Programming</a>. Grab them<a href="http://twitter.com/taranfx"><strong>@taranfx</strong> on Twitter</a> or below:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/how-to-hack-voip-video-conference/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ATM Hacking Techniques Revealed at BlackHat</title>
		<link>http://geeknizer.com/atm-hacking-techniques/</link>
		<comments>http://geeknizer.com/atm-hacking-techniques/#comments</comments>
		<pubDate>Sat, 31 Jul 2010 17:46:23 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ATM]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[vulnerable]]></category>

		<guid isPermaLink="false">http://geeknizer.com/atm-hacking-techniques</guid>
		<description><![CDATA[ATM Hacking has been popular for years. With some nasty tricks, it had been easy to hack into most ATM systems. But as the time evolved, those methods became obsolete... <span class="meta-more"><a href="http://geeknizer.com/atm-hacking-techniques/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><a href="http://geeknizer.com/wp-content/uploads/atm-hacking.jpg"><img class="alignleft size-medium wp-image-5540" title="atm hacking" src="http://geeknizer.com/wp-content/uploads/atm-hacking-300x225.jpg" alt="" width="250" /></a>ATM Hacking has been popular for years. With some nasty tricks, it had been easy to hack into most ATM systems.</p>
<p>But as the time evolved, those methods became obsolete and hardly few of those  hacks still persist and the ones that remain in sight are relative harder and un-popular.</p>
<p>With the latest Hack, as demoed at BlackHat conference, it can get pretty easy. <a href="http://ioactive.com/about_management.html#bj">Barnaby Jack</a>, director of security testing at Seattle-based IOActive,  brought two ATMs onto the <a href="http://www.tarranfx.com/tag/blackhat">Black Hat conference</a> stage and demonstrated that with a press of a button, ATM machine is spits out its cash till the last one in the Pile.</p>
<p>&#8220;I hope to change the way people look at devices that from the outside are seemingly impenetrable,&#8221; said Jack. He demonstrated a hack that allows the hacker to connect to the ATM through a telephone modem and, without knowing a password, instantly force it to bankrupt the ATM machine.</p>
<p><strong>How the Hacking started</strong></p>
<p>Initially, in order to kick start hacking, Jack said that he had bought a pair of standalone ATMs&#8211;one from  <a href="http://www.tranax.com/">Tranax Technologies</a> (yea, its not Taranfx) and the other by <a href="http://www.tritonatm.com/">Triton</a>. His study yielded success in within few years, during which he discoverred Vulnerabilities that had let him gain complete access to those machines.</p>
<p>Jack seems to be so confident about his technique that he said, &#8220;Every ATM I&#8217;ve looked at, I&#8217;ve found a game-over vulnerability that allows an attacker to get cash from the machine&#8221; .</p>
<p>On the good note, he had been an Ethical hacker and hence had brought up vulnerabilties to the notice of both ATM companies and was fixed an year ago. However, theres a twist to the tstory. These updates were pushed to ATMs which had been under support from the companies, not every ATM had been updated, hence,  a large number of the machines remain vulnerable.</p>
<p><strong>Hacking ATMs: Now &amp; then</strong></p>
<p>Hacking ATMs had been popular under two techniques known as &#8220;<a href="http://www.snopes.com/fraud/atm/atmcamera.asp">card skimming</a>&#8221; and &#8220;<a href="http://pindebit.blogspot.com/2009/10/card-trapping-latest-rage-with-bad-guys.html">card trapping</a>&#8221; which are now relatively uncommon coz these electronic cash-extraction techniques were limited because they didn&#8217;t rely on a deep analysis of an ATM&#8217;s code.</p>
<p>We got to knew <a href="http://geeknizer.com/cybercriminals-hack-into-bank-atms-in-eastern-europe">what exactly</a> happened when <a title="Permanent Link to Cybercriminals hack into Bank ATMs in Eastern Europe" rel="bookmark" href="http://geeknizer.com/cybercriminals-hack-into-bank-atms-in-eastern-europe">Cybercriminals hacked into Bank ATMs in Eastern Europe</a>.</p>
<p>Most modern ATMs run on Windows CE with an ARM processor and use a dialup or leased-line connection to connect to the other branches over the interent/Intranet VPNs, ost of which is through a serial port connection. Jack used standard debugging techniques to interrupt the normal boot process and instead start Internet Explorer, and using some nasty IE hacks, he got access to the file system for copying off the files for analysis.</p>
<p>A remote access vulnerability was found to occur on Taranax ATMs, that allows full access to the machine, without password. The Hack uses two softwares: a utility called <strong>Dillinger</strong>, which attacks an ATM remotely, and one called <strong>Scrooge</strong>, a rootkit that inserts a backdoor and then conceals itself from discovery. Scrooge &#8220;hides itself from the process list, hides itself from the operating system, there&#8217;s a hidden pop-up menu that can be activated by a special key sequence or a custom card.&#8221;</p>
<p>For Triton&#8217;s ATMs, scenario was different. PC motherboard that dispenses cash from the vault was protected only by a standard (shared) key that could be purchased over the Internet for about $10. So Jack found out that he could force the machine to accept his backdoor-enabled software as a legitimate update, which then can do the damage thats irreversible.</p>
<p>Both companies have responded to the hacks, but necessary actions may still not have been taken place to fix all the machines. I just hope someone takes care of this sometime soon.</p>
<p>The difficult part in hacking the <a href="http://geeknizer.com/tag/atm">ATMs </a>is evaluating the software for <a href="http://geeknizer.com/tag/vulnerable">vulnerabilities</a>, but once some one like Jack  creates it, its a childsplay to empty the machine.</p>
<p>We write about <a href="http://geeknizer.com/tag/google">Google</a>, <a href="http://geeknizer.com/tag/twitter">Twitter</a>, <a href="http://geeknizer.com/tag/security">Security</a>, <a href="http://geeknizer.com/tag/open-source">Open Source</a>, <a href="http://geeknizer.com/tag/programming">Programming</a>, <a href="http://geeknizer.com/">Web</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>,<a href="http://geeknizer.com/tag/android">Android</a> and latest in Tech <a href="http://twitter.com/taranfx"><strong>@taranfx</strong> on Twitter</a> or by subscribing below:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/atm-hacking-techniques/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers Hack Cars Remotely, disable Engines, brakes</title>
		<link>http://geeknizer.com/car-hacking/</link>
		<comments>http://geeknizer.com/car-hacking/#comments</comments>
		<pubDate>Fri, 14 May 2010 17:49:07 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Cars]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://geeknizer.com/car-hacking</guid>
		<description><![CDATA[How far can softwares hackers reach? Perhaps, everywhere where software reaches? In a world where a complete PC can be hacked with a USB stick, everything appears possible. In a paper[... <span class="meta-more"><a href="http://geeknizer.com/car-hacking/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><a href="http://geeknizer.com/wp-content/uploads/car-hacking.jpg"><img class="alignleft size-full wp-image-4951" title="car hacking" src="http://geeknizer.com/wp-content/uploads/car-hacking.jpg" alt="car pwned" width="240" height="180" /></a>How far can softwares hackers reach? Perhaps, everywhere where software reaches? In a world where a complete <a href="http://geeknizer.com/pc-mac-usb-hid-hack">PC can be hacked with a USB</a> stick, everything appears possible.</p>
<p>In a <a href="http://www.autosec.org/">paper</a>[ by autosec], the security researchers claim that by connecting to a standard diagnostic computer port included in late-model cars, they were able to do some Really nasty things, such as turning off the brakes, changing the speedometer reading, wishfully blowing hot air or music on the radio, and even locking passengers in the car.</p>
<div>Earlier, same hackers hacked into a test car&#8217;s braking system and prevented the test driver from applying brakes. Additionally, they were able to kill the engine, falsify the speedometer reading, and automatically lock the car&#8217;s brakes unevenly. The test was done by attaching a laptop into the car&#8217;s diagnostic system and then controlling that computer wirelessly, from a laptop in a vehicle driving in close vicinity of the car. However, if this laptop had been on 3G, possibilities of remote control/hacking were endless.</div>
<div id="related_content">
<dl>
<dt></dt>
<dd></dd>
</dl>
</div>
<p>Stefan Savage, an associate professor with the UoC, describes the real-world risk of any of the attacks they&#8217;ve worked out as extremely low. An attacker would have to have sophisticated programming abilities and also be able to physically mount some sort of computer on the victim&#8217;s car to gain access to the embedded systems. But as they look at all of the wireless and Internet-enabled systems the auto industry is dreaming up for tomorrow&#8217;s cars, they see some serious areas for concern.</p>
<p>Obviously, if there&#8217;s no action taken on the part of all the relevant stakeholders, then I think there might be a reason to be concerned.Researchers found existing automotive systems to be tremendously vulnerable to easy hacks.</p>
<p>The Car hacking is all cooked with Controller Area Network (CAN) system, mandated as a diagnostic tool for all U.S. cars built (2008 onwards). The concept is simple: they developed a sniffer called <strong>CarShark </strong>that listens in on CAN traffic as it&#8217;s sent about the onboard network, and then inject their own packets. By learning the complete protocol of the car&#8217;s controls, its not hard to control almost anything from radio to popping car&#8217;s trunk.</p>
<p>A lot of it is done with Brute-force too: The specific jargon is called &#8220;fuzzing&#8221; &#8212; where they simply bombard a large number of random packets at a component and analyze the response.</p>
<p>In addition, the researchers found that they could change the firmware on some systems without any sort of authentication. In another attack called &#8220;Self-destruct&#8221;  a 60 second countdown is shown on the driver&#8217;s dashboard with  clicks, when the time hits zero, the car&#8217;s engine is killed and the doors are locked. To give you an idea of how simple it is, it was done with less than 200 lines of code &#8212; and  most of it devoted to keeping time during the countdown.</p>
<p>This clearly shows how vulnerable these softwares are. Car manufacturers are introducing some great features into modern cars though, falling back on security. These manufacturers should start worrying about security more than anything else or in future someone else might take over control, while you are on the way.</p>
<p><strong>Update: <a href="http://geeknizer.com/hack-car-with-music">Hackers Hack Car with Music</a></strong></p>
<p>[via <a rel="nofollow" href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/news/2010/051410-car-hackers-can-kill-brakes.html&amp;pageurl=http://www.networkworld.com/news/2010/051410-car-hackers-can-kill-brakes.html&amp;site=printpage" target="_blank">nww</a>]</p>
<p>We write about <a href="http://geeknizer.com/tag/google">Google</a>, <a href="http://geeknizer.com/tag/twitter">Twitter</a>, <a href="http://geeknizer.com/tag/security">Security</a>, <a href="http://geeknizer.com/tag/open-source">Open Source</a>, <a href="http://geeknizer.com/tag/programming">Programming</a>, <a href="http://geeknizer.com/">Web</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>,<a href="http://geeknizer.com/tag/android">Android</a> and latest in Tech <a href="http://twitter.com/taranfx"><strong>@taranfx</strong> on Twitter</a> or by subscribing below:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/car-hacking/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>How I would Hack your PC, Mac with USB HID</title>
		<link>http://geeknizer.com/pc-mac-usb-hid-hack/</link>
		<comments>http://geeknizer.com/pc-mac-usb-hid-hack/#comments</comments>
		<pubDate>Thu, 15 Apr 2010 18:48:45 +0000</pubDate>
		<dc:creator>Tarandeep Singh</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[usb]]></category>

		<guid isPermaLink="false">http://geeknizer.com/pc-mac-usb-hid-hack</guid>
		<description><![CDATA[We live in the world full of serpents, overlook things for seconds and you are bitten to death. Trojans, viruses, malware are everywhere. They find new ways to enter our sacred computers some... <span class="meta-more"><a href="http://geeknizer.com/pc-mac-usb-hid-hack/">Read more &#187;</a></span>]]></description>
			<content:encoded><![CDATA[<p><a href="http://geeknizer.com/wp-content/uploads/2010/04/usb-hid.jpg"><img class="alignleft size-full wp-image-4715" title="usb hid" src="http://geeknizer.com/wp-content/uploads/2010/04/usb-hid.jpg" alt="usb hid" width="250" height="188" /></a>We live in the world full of serpents, overlook things for seconds and you are bitten to death.</p>
<p>Trojans, viruses, malware are everywhere. They find new ways to enter our sacred computers some way or the other. Talking about scenarios where hacker had physical access, traditionally, lame Autorun based USBs could install unwanted programs on your PCs the moment they are plugged, but those are easy to get rid of: Switch off autoplay. What if a <a href="http://geeknizer.com/tag/usb">USB </a>uses a cross-platform native profile to inject malicious programs into computers? &#8212; It becomes unstoppable.</p>
<p>One such device was demoed at this year&#8217;s Shmoocon, it&#8217;s called &#8220;Phantom Keystroker&#8221;. It&#8217;s a simple USB dongle form factor device, which when plugged to a computer uses USB HID class to identify itself as a Human interface mouse and keyboard from a  legit manufacturer and start execution of instructions, which would perhaps annoy the user by flashing LEDs on keyboards, and make the mouse behave as drunkard.</p>
<p>Since USB HID doesn&#8217;t need any drivers across all popular platforms (<a href="http://geeknizer.com/tag/linux">Linux</a>, <a href="http://geeknizer.com/tag/windows">Windows</a>, <a href="http://geeknizer.com/tag/mac-os">Mac OS</a>), it just works everywhere.</p>
<p><a href="http://www.hak5.org" target="_blank">Hak5 team </a>has extrapolated the idea with USB HID device to allow executing terminal commands quickly, without drawing as much attention from the user who sits in front of it. The user just turns his head for couple of seconds and  the hacker plugs in their programmable USB key stroke dongle, Boom! All sorts of command could be run.</p>
<p><strong>Why this behavior is Not considered &#8220;Bad&#8221; by Current Anti-viruses</strong></p>
<p>When we plug-in such USB HID device, it acts just like any other USB peripheral. It could identify itself as aLogitech HID keyboard, or a HID compliant Mouse. The moment it identifies itself, your computer assumes its you who is typing/clicking and has no idea about &#8220;these devices&#8221; being automated.</p>
<p>Daren and Snubs<a href="http://www.hak5.org" target="_blank"> from Hak5</a> had been working on such a project they call as &#8220;USB Rubber Ducky&#8221; with a soft duck attached at the Dongle.</p>
<p><strong>How this can be done?</strong></p>
<p>It could start with a cool Arduino hack, but implementing a USB HID with the standard Arduino is a bit of a pain (atleast for me). The alternative way (read  as &#8220;Better&#8221;)  is to use <a href="http://www.pjrc.com/teensy/" target="_blank">Teensy</a>, which lets you program  in C, or the easier Arduino development environment, and already supported USB HID out of the box! With the price tag of  $18, its ultra-affordable for enthusiasts and nightmare for potential victims.</p>
<p><a href="http://geeknizer.com/wp-content/uploads/2010/04/teensy.gif"><img class="alignleft size-full wp-image-4716" title="teensy" src="http://geeknizer.com/wp-content/uploads/2010/04/teensy.gif" alt="" width="692" height="225" /></a></p>
<p>When teensy is interfaced with a flash card, it could store multiple programs, which can then be dynamically loaded instead of reflashing the device everytime when you need to perform a different task. Also, one can store a large number of files/scripts that let you do more.</p>
<p>Watch the Video, from Hak5: <em>(video automatically starts from 12:xx, where main talk starts)</em></p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="625" height="394" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/3pAIQZw1TeE&amp;start=742&amp;end=1329" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="625" height="394" src="http://www.youtube.com/v/3pAIQZw1TeE&amp;start=742&amp;end=1329" allowfullscreen="true"></embed></object></p>
<p>The possiblities are endless. You can create a CRON Job or schedule events to happen in a later time. e.g. running a script at a time in the future when it downloads and install a keylogger or perhaps damage/steal local files. Or it could be an instantaneous Auto-job that copies all executables from the USB flash for running on the local computer.</p>
<p><strong>What other Bad things are Possible:</strong></p>
<ul>
<li>Automate Brute-force Admin passwords on Windows server (Windows 2003 server doesn&#8217;t lockout when passwords are entered from keyboard, in our case USB HID device)</li>
<li>Brute-force BIOS passwords</li>
<li>Fake a BSOD and do anything in the background. Before User reboots PC (i.e. couple of seconds) damage is probably done.</li>
<li>Add a user to the box or the domain.( this is nasty)</li>
<li>Run a program that sets up a permanent back door.</li>
<li>Copy files to flash card</li>
<li>Go to a website they have a cookie for, and do some sort of transaction.</li>
</ul>
<p>Possibilities are endless, use your wild imagination.</p>
<p><strong>How about Good things?</strong></p>
<p>Apart from being an un-avoidable bad element, it can be a great pen-tester&#8217;s device and even an automation device. It could:</p>
<ul>
<li>Automate Pen-testing tasks</li>
<li>Perform certain tasks much faster than you can type, and that too without typos.</li>
<li>Schedule tasks</li>
</ul>
<p><strong>Potential Shortcomings?</strong></p>
<p>There is one disadvantage, though its not big. The first time you plugin the device, it takes few seconds (5-20s) to identify HID device and load the drivers. Though this is fully automated by all operating systems, this delay varies from OS to OS.</p>
<p><em>You can contribute</em></p>
<p>Obviously, there can be other good reasons why this project should go futher. If you&#8217;ve some brilliant ideas and happen to be a strong C, Arduino programmer, you can contribute to this project by <a href="http://www.hak5.org/iwanttodevelopfortheducky" target="_blank">filling a form at hak5</a> to register to receive a Free USB Rubber Ducky dev kit. Devkits will be delivered via via snail-mail around the world.</p>
<p>Related: <a href="http://geeknizer.com/diy-electronics-projects-with-android/">Arduino Alternative : Android based DIY projects</a></p>
<p>We write about <a href="http://geeknizer.com/tag/google">Google</a>, <a href="http://geeknizer.com/tag/twitter">Twitter</a>, <a href="http://geeknizer.com/tag/security">Security</a>, <a href="http://geeknizer.com/tag/open-source">Open Source</a>, <a href="http://geeknizer.com/tag/programming">Programming</a>, <a href="http://geeknizer.com/">Web</a>, <a href="http://geeknizer.com/tag/apple">Apple</a>, <a href="http://geeknizer.com/tag/iphone">iPhone</a>,<a href="http://geeknizer.com/tag/android">Android</a> and latest in Tech <a href="http://twitter.com/taranfx"><strong>@taranfx</strong> on Twitter</a> or by subscribing below:</p>
]]></content:encoded>
			<wfw:commentRss>http://geeknizer.com/pc-mac-usb-hid-hack/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 2.250 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2012-02-09 01:01:15 -->
<!-- Compression = gzip -->
