Monday, September 29, 2008

back to websense.....

Sooo

I figured I'd revisit an old flame. Here is some of Websense's greatest hits..


damn...these people are retarded... Internet censorship is something that has to go. If you are as against it as I am, then visit www.peacefire.org to see what you can do to help!

Thursday, September 18, 2008

the audacity of some people.....

Hacker impersonated Palin, stole e-mail password
Sep 18 03:25 PM US/Eastern
By TED BRIDIS
Associated Press Writer
36 Comments



Republican vice presidential candidate, Alaska Gov., Sarah Palin, answers...




This screenshot from Gawked.com shows an email account of Republican vice...


WASHINGTON (AP) - Details emerged Thursday behind the break-in of Republican vice presidential candidate Sarah Palin's e-mail account, including a first-hand account suggesting it was vulnerable because a hacker was able to impersonate her online to obtain her password.

The hacker guessed that Alaska's governor had met her husband in high school, and knew Palin's date of birth and home Zip code. Using those details, the hacker tricked Yahoo Inc.'s service into assigning a new password, "popcorn," for Palin's e-mail account, according to a chronology of the crime published on the Web site where the hacking was first revealed.

The FBI and Secret Service launched a formal investigation Wednesday. Yahoo declined to comment Thursday on details of the investigation, citing Palin's privacy and the sensitivity of such investigations.

The person who claimed responsibility for the break-in did not respond Thursday to an e-mail inquiry from The Associated Press.

"i am the lurker who did it, and i would like to tell the story," the person wrote in the account, which circulated on the Internet. What started as a prank was cut short because of panic over the possibility the FBI might investigate, the hacker wrote.

Investigators were waiting to speak with Gabriel Ramuglia of Athens, Ga., who operates an Internet anonymity service used by the hacker. Ramuglia told the AP on Thursday he was reviewing his own logs and promised to turn over any helpful information to authorities because the hacker violated rules against using the anonymity service for illegal activities.

"If you're doing something illegal and causing me issues by doing this, I'm willing to cooperate," Ramuglia said. "Obviously this is the most high profile situation I've dealt with."

The break-in of Palin's private account is especially significant because Palin sometimes uses non-government e-mail to conduct state business. Previously disclosed e-mails indicate her administration embraced Yahoo accounts as an alternative to government e-mail, which could possibly be released to the public under Alaska's Open Records Act.

At the time, critics of Palin's administration were poring over official e-mails they had obtained from the governor's office looking for evidence of improper political activity.

Details of this week's break-in, if authentic, were consistent with speculation by computer security experts who said Yahoo's "forgot-my-password" service almost certainly was exploited. The mechanism allows customers to retrieve or change their password if they can verify their identity by confirming personal information such as birthdate, zip code and the answer to a "secret question," such as a childhood pet's name or school mascot.

Palin's hacker was challenged to guess where Alaska's governor met her husband, Todd. Palin herself recounted in her speech at the Republican National Convention that the pair began dating two decades ago in high school in Wasilla, a town near Anchorage.

"I found out later though (sic) more research that they met at high school, so I did variations of that, high, high school, eventually hit on 'Wasilla high'," the person wrote.

The McCain campaign issued a statement describing the hacking as an invasion of Palin's privacy.

Wednesday, September 17, 2008

Helpdesks can be so helpful!!!!!!

So.... I recently did a Social Engineering project for a major US financial institution. The goal was to try and get someone at the helpdesk to reset a users password. This helpdesk was in Ft. Wayne Indiana. I found the user name through some google searches on the company and had previously called another one of there helpdesks where they generously gave me the format of user ids..... Here is a play by play of how this went down....

HD - Helpdesk, Charlie speaking
me - Hey Charlie, I think I'm having a problem with my passwd
HD - What is the problem?
me - I just got back from a break and when I tried to unlock my computer it said the password was no good
HD - alright, that happens from time to time..What's your user id ?
me - v3pXXX
HD - John Doe?
me - yeah, that's me.
HD - like I said, this happens sometimes, the only way to fix this is to reboot your computer and start over
me - alright, so just hit the power button?
HD - yeah, you will have to since you can't log back in
me - alright..hold on i guess this will take a minute
HD - alright, I'll stay on the phone with you to make sure you get in alright....
(Pause for 10-15 secs)
me - so did you watch the hall of fame game last night?
HD - Yeah, I watched a little bit, but it's hard to get excited about preseason football.. You a colts fan?
me - of course!!!!!!
HD - Oh, I'm a cowboys fan
me - the cowboys should be very good this year now that they fixed there secondary, I think they'll probably win there division
HD - yeah, if they can get past the Giants
me - alright, I'm back.... nope just tried to login, still says my password is no good.... I know I'm typing the right password!
HD - are you sure the caps lock is not on?
me - oh, let me try it again... (put phone close to keyboard so he could hear me hitting keys ) nope still didn't work....
HD - alright, looks like we are gonna have to reset your password...What's your employee number?
me - 529406
HD - 529406??? should be a 5 digit number
me - Oh sorry....11865
HD - no, that's not what I have on file with you...it should begin with a 2
me - no, it's definitely 11865
HD - is that the number you log on to ??????? system with?
me - yeah
HD - well we can go ahead and reset your password.. Hopefully there will not be a problem with ??? system
HD- What's your current password?
me - aren't we not supposed to give out our passwords to anyone?
HD - it's alright, you can give it to us, sometimes we can login as you without having to reset your password
me - Oh, I didn't know that, I remember going to some training and they said not to give your password to anyone...
HD - yeah, that's right, tell you what, I can just reset your password, and it'll force you to change it.. try Summer08
me - (phone next to keyboard again) alright, cool... it worked, now its asking me to change my password...thanks alot!
HD - Your'e welcome....have a good day
me - thanks...you too!

Websense???? more like NO sense

So....Who are all of the content monitoring companies getting there blacklists from??? Take Websense for example..... I as a penetration tester am not allowed to go to insecure.org while I'm at work because it is classified as "Hacking;Computers/Internet". This is inherently wrong on multiple levels....

First off... why would anyone not be able to go anywhere because it is labeled Computers / Internet. I guess in my profession it is only acceptable to visit sites pertaining to food recipes.

Second.....Insecure.org is not a "Hacking" website. It's not like I'm visiting the webpage for the Canadian Mafia. Insecure.org is a website for security professionals to download the award winning NMAP scanner which is a tool EVERY security professional should know like the back of there hand.

Metasploit.com NOPE
Milw0rm.com NOPE
Packetstorm.org NOPE

Not only does Websense deny visits to insecure.org but it also will prohibit you from visiting sectools.org

ARE YOU KIDDING ME??? websense in there infinite wisdom declares that a security professional should not have the ability to go view or download the top 100 security tools? I would definitely say that a computer security professional going to sectools.org is probably going to get a tool for use in there daily job function...

That's enough ranting for now... I could have sworn that we don't live in China.....