Contribute  :  Advanced Search  :  Site Statistics  :  Directory  :  Calendar  :  Links  :  Polls  :  About Us  :  The Staff  
Topsight.net Discussions on computers and beyond
Welcome to Topsight.net
Monday, May 12 2008 @ 03:18 AM EDT
 Email Article To a Friend View Printable Version 

Ebay Hacked

Security 2 meAccording to various sources, ebay was compromised at 6am PDT. The attacker or attackers began posting user information directly to eBay forums including users name, address, phone, and complete credit card info. For more information see: PLMK.COM. To check and see if your information was disclosed see shenemanfamily.com which has posted a list of all the ID's of the accounts that were listed.
As PLMK authors note It beggars belief that eBay took over an hour and a half to close down the board completely!
 Email Article To a Friend View Printable Version 

Latest iPhone Mods

AppleiPhone modifcations - This list will be updated as new mods are made public
1. Install SSHD & Apache: See natetrue.com, or ifastnet.com (easier)

2. Laptop Tethering: From cre.ations.net

3. Custom Ring Tones: Easy Mac instructions or harder windows instructions

4. Change the iPhone's icons: From:hacktheiphone.com

5. Use the iPhone without activation: DVD Jon's activation crack

6. VNC from your iPhone:WinVNC/WebVNC for windows or AjaxVNC for OSX

7. Access Field Test Mode: Enter *3001#12345#* then hit call.

8. Nintendo emulator for Apple's iPhone

9. Instructions to unlock the phone and use it with a provider other then at&t here or here

10. Simple gui app to unlock the iPhone anySIM from the Iphone Dev Team

11. Installer.app is a UIKit based package manager for the iPhone. It works by downloading packages over WiFi (wireless networking) or EDGE. It supports installing, updating and uninstalling applications from multiple sources.

12. SummerBoard is an extension to the iPhone's SpringBoard user experience. SummerBoard adds a variety of useful and fun features to your iPhone, including scrolling icons, wallpaper and themes.

13. HD Moore to develop Metasploit frame work for the iPhone. .

 Email Article To a Friend View Printable Version 

The Apple wireless hack

AppleAccording to a recent infoworld.com article a Non disclosure agreement that was preventing David Maynor from releasing the details of a wireless attack against Apple Computers is now no longer valid. As such David has released a paper on uninformed.org describing the attack in detail.

See uninformed.org to read the paper.

 Email Article To a Friend View Printable Version 

Learn to Pirate TV shows

Interesting StuffCNET writter Chris Soghoian describes how to automate TV show downloads for linux, Mac OSX, and Windows in this little gem on Cnet.com

For more info see http://www.tvrss.net/

 Email Article To a Friend View Printable Version 

Windows Vista Tweaking Companion

MicrosoftTweakguides.com has released an all inclusive guide for Windows Vista (all versions). If you're new to windows vista or an advanced user looking to speed up or lock down your vista machine this guide is equally useful and effectively replaces any printed reference material. Best of all it's free.

Note as of writing this post the guide was last update 7/5/07

 Email Article To a Friend View Printable Version 

10 claims that scare security pros

SecurityI love this: Jon Espenschied for computerworld writes this little "10 claims" article, but it's amazingly true, in that I keep seeing this over and over and over.... like this:

3. "That doesn't apply to the boss."

Most of these bad apples can be managed by appealing to their Machiavellian sense of influencing others' behavior: that they at least ought to appear to be leading by example, while continuing to do whatever it is they do with the door closed. Few would admit it, but I've run across many IT organizations that simply budget a DSL line for "guest" access in the executive's office, turn a blind eye to whatever gets plugged in and chalk up support time to the test lab. It's not a desirable solution, but if the executive's still willing to sign a Sarbanes-Oxley attestation, the rest comes down to plausible deniability.

read original article

 Email Article To a Friend View Printable Version 

When iPhones attack!

AppleUpdate 07/22/07: Duke University said yesterday that widely publicized problems with its campus wireless network it had originally blamed on Apple Inc. iPhones had instead been traced to Cisco Systems Inc. hardware. See article at computer world
It’s been widely reported now (thanks to Network World for the poor fact checking) that the iPhone has downed over 30 access points on the Duke University network due to a continued flood of ARP packets.

Here are some questions I have for the Admins at Duke:

1. How do you know the iPhone is causing the flood? A fairly old attack against switches to be able to sniff packets going over the switch involves overloading a switches CAM table. This is done by flooding a switch with bogus arp traffic with many different source mac addresses. See: Packet Sniffingon Layer 2 Switched also see winArpAttacker - a window tool that will perform these attacks

2. Is it possible you have a bridging loop? In the case of loops and arp packets, your system may broadcast a single ARP packet but the bridging loop causes it to appear many times over, hence your routers (and WiFi controllers) would spend lots of time replying to the same request. Do you have Spanning tree protocol disabled? For more info on bridging loops see: wildpackets.com

Its funny how we take Duke at there word, I personally own an iPhone. I’ve connected it to many wireless networks and found that it has always performed as expected. I’ve also used ARP cache poising against the device using Cain and Abel. I found that each time I performed the attack on the iPhone, the iPhone simply disassociated from the wireless network.I'd imagine that on seeing an arp flood on the Duke network those iPhones would also disassociate.

 Email Article To a Friend View Printable Version 

oh Look apple worm

AppleFrom: http://infosecsellout.blogspot.com

"This is for you all Apple fans, please be aware that there are no such thing as full proof system and stop been all crazy about it. Sure Apple builds cool computers but stop ignoring the truth.

Please follow this link: http://www.securityfocus.com


Enough. It's bad enough that this supposed worm author intends to release a fully functional worm based on an undisclosed vulnerability (ethics anyone?), but where's the proof? Shame on securityfocus for including this in there database with zero proof.
 Email Article To a Friend View Printable Version 

Data Carving With PhotoRec

SoftwareThe nice folks at Iron geek have done a great tutorial on the use of the opensource file recovery tool PhotoRec.

See:
http://www.irongeek.com/i.php?page=videos/data-carving-with-photorec-to-retrieve-deleted-files-from-formatted-drives-for-forensics-and-disaster-recovery

Or for the direct download:
http://www.cgsecurity.org/
 Email Article To a Friend View Printable Version 

NSA information assurance operating system guides

SecurityThe NSA has published a number of security guidelines for Apple OS X, Windows 2K, XP, 2003 and Sun Solaris 8 & 9. The Guides are about as detailed as you could expect from a government agency of the size and class of the NSA (extremely detailed).

See: http://www.nsa.gov/snac/downloads_os.cfm?MenuID=scg10.3.1.1