Showing posts with label IRC. Show all posts
Showing posts with label IRC. Show all posts

Sunday, August 21, 2011

Reminiscing the Hacker’s Manifesto


Have you guys heard of the Hacker’s Manifesto?

Probably some of you may say yes and some may say no. But for those of you who haven’t heard of it, it’s an essay written by Loyd Blankenship (a.k.a. The Mentor, stylized as +++The Mentor+++).

It’s also known as the “The Conscience of a Hacker” which was written on January 8, 1986 which followed after the arrest of Loyd and was published in an underground ezine (online magazine) Phrack.

So who is Loyd Blankenship a.k.a The Mentor? He is a well known American computer hacker and writer since the 80’s and was a member of the hacker groups, “Extasyy Elite” and “Legion of Doom”. He also wrote the game “Cyberpunk” which was seized by the Secret Service.

It is believed that the “Hacker’s Manifesto” is the cornerstone and the foundation of the hacker culture and the article also gave some insight into the psychology of early hackers.

The Manifesto states that hackers hack out of curiosity and that they want to learn more.

Hackers don’t learn to hack, they hack to learn.

The article reflects the attitude and the personality of the hackers in the early 80’s and 90’s. During these days, being a script kiddie was moderately cool, packet wars were in and lame DOS attacks like WinNUKE and the ath0++ modem drop were cool.

Phreaking also became a mainstream during these days and that sharing of knowledge like cracking, cryptography, programming (C++, VB, Delphi, C, Pascal, Assembly, Python, PERL, Bash and so on), network security, Linux, Windows, UNIX, etc. became the main topics in IRC.

The essay of Loyd was also quoted in the 1995 Movie entitled “Hackers”. Mentor received a credit from this movie. Also a poster about the said article appears in the movie "The Social Network" on the wall of Mark Zuckerberg's dorm room.

Below is the complete essay of +++The Mentor+++:

Loyd Blankenship a.k.a +++The Mentor+++


The Hacker’s Manifesto

Another one got caught today, it's all over the papers. "Teenager Arrested in Computer Crime
Scandal", "Hacker Arrested after Bank Tampering"...

Damn kids. They're all alike.

But did you, in your three-piece psychology and 1950's technobrain, ever take a look behind the eyes of the hacker? Did you ever wonder what made him tick, what forces shaped him, what may have molded him?

I am a hacker, enter my world...

Mine is a world that begins with school... I'm smarter than most of the other kids, this crap they teach us bores me...

Damn underachiever. They're all alike.

I'm in junior high or high school. I've listened to teachers explain for the fifteenth time how to reduce a fraction. I understand it. "No, Ms. Smith, I didn't show my work. I did it in my head..."

Damn kid. Probably copied it. They're all alike.

I made a discovery today. I found a computer. Wait a second, this is cool. It does what I want it to. If it makes a mistake, it's because I screwed it up. Not because it doesn't like me... Or feels threatened by me.. Or thinks I'm a smart ass.. Or doesn't like teaching and shouldn't be here...

Damn kid. All he does is play games. They're all alike.

And then it happened... a door opened to a world... rushing through the phone line like heroin through an addict's veins, an electronic pulse is sent out, a refuge from the day-to-day incompetencies is sought... a board is found. "This is it... this is where I belong..." I know everyone here... even if I've never met them, never talked to them, may never hear from them again... I know you all...

Damn kid. Tying up the phone line again. They're all alike...

You bet your ass we're all alike... we've been spoon-fed baby food at school when we hungered
for steak... the bits of meat that you did let slip through were pre-chewed and tasteless. We've been dominated by sadists, or ignored by the apathetic. The few that had something to teach found us willing pupils, but those few are like drops of water in the desert.

This is our world now... the world of the electron and the switch, the beauty of the baud. We make use of a service already existing without paying for what could be dirt-cheap if it wasn't run by profiteering gluttons, and you call us criminals. We explore... and you call us criminals. We seek after knowledge... and you call us criminals. We exist without skin color, without nationality, without religious bias... and you call us criminals. You build atomic bombs, you wage wars, you murder, cheat, and lie to us and try to make us believe it's for our own good, yet we're the criminals.

Yes, I am a criminal. My crime is that of curiosity. My crime is that of judging people by what they say and think, not what they look like. My crime is that of outsmarting you, something that you will never forgive me for.

I am a hacker, and this is my manifesto. You may stop this individual, but you can't stop us all... after all, we're all alike.



About the Contributor:

Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.



ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Thursday, August 18, 2011

Cool Ubuntu Shell Account


Good news for Ubuntu fans and shell enthusiasts out there. Nvita.org is offering a Ubuntu shell account that provides users with access to softwares and services like GCC (GNU Compiler Collection), IRC access, Irrsi, background processes, FTP (File Transfer Protocol), and text editors (like nano and vi) for free.

Yes! You are not dreaming, this is true and not only that, the shell account could also be used for tunneling. Honestly, I do love their service because I love free stuffs. This kind of project really conforms to the philosophy of Richard Stallman about Open Source and Free Software. This is the power of Linux and the GNU Project!


NVITA (Northern Virginia Information Technology Association) deserves recognition for their excellent shell project which has the latest Ubuntu 11.04 as its Operating System (Linux Ubuntu 2.6.35-22-generic-pae #33-Ubuntu SMP Build Server). Unlike other shell providers, NVITA also allows users to install packages with their permission.

But there are some flaws in their project because they allow too much background which could possibly be used for illegal activities. We could not deny the fact that some users may tend to abuse their privileges as a user like using it for udpflooding, tcpflooding, hosting botnets, scanning SSH, etc. because of allowing too much background processes. Maybe next time they should put some limit to prevent abuses in their server.

But in the long run, NVITA is still one of the best shell account providers for allowing us to connect to their server with good services despite the said flaws. NVITA offered free shells which are not meant to be abused but meant for a purpose thus we should use it ethically. It’s now up to the user where he wants to use it as long as it does not violate the ethical laws of Internet and computers.



About the Contributor:

Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.



ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved.Designated trademarks, brands and articles are the property of their respective owners.

Read More

Sunday, July 17, 2011

The Artificial Lurkers of IRC



I guess most of you are familiar with the IRC or the Internet Relay Chat. According to Wiki, IRC is a form of real-time Internet text messaging (chat) or synchronous conferencing. It is mainly designed for group communication in discussion forums, called channels, but also allows one-to-one communication via private message as well as chat and data transfer, including file sharing.

But is IRC still alive these days? Yes it is, in fact it is the home of underground hackers and crackers, to name a few; defacers, rooters, carders, script kiddies, hardcore Linux users, etc. IRC is often referred as a primitive way of chatting because of its style and because of the new generation of voice and video chatting just like Tinychat and Facebook. And because of Facebook, some of the teenagers don't even know how to use IRC clients.

But of course, we will not deal more about how to use it and where to have a good chat mate. Instead we will talk about some of the hidden agendas of IRC users and the dark side of IRC. Forgive me for referring to it as the dark side thingy but that's what other IRC users usually call it.

In IRC there are some users that have botnets or bots in their channel which can do ; udpflooding, check for vulnerable websites, portscanning, nmap, sqli, rfi, lfi, check for good credit cards and many more. These botnets are coded in languages like perl, php and python.

In fact, some of these bots are hosted on a hacked or rooted boxes or even websites that have backdoor shells. Users with bad intentions like doing a DDoS attack would not run their scripts on their own machine in order to avoid getting traced or caught.

The images below are screenshots I took and uploaded so that people may be aware that these kinds of lurkers exist in the cyber world and could also be a threat or an advantage.



Thus it would be easier to say that an IRC bot is an independent program or script that connects to IRC as one of the clients but differs to other clients because it performs automated functions.


Nowadays, these bots are often scattered in public channels and who knows, you may be able to encounter one. Now don't panic, they won't infect you, they are just waiting for their handlers to command them. Like I said, they are different from infecting botnets like the Zeus Bot.

The bots shown here are for educational purposes only, no live accounts and servers were tested and rooted in order to run these scripts.



About the Contributor:

Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.



ROOTCON is managed by like minded InfoSec professionals across the Philippines. All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Thursday, June 02, 2011

Pinoy Hacker's Confession 2004



On February 7, 2011 a user uploaded a video entitled "Pinoy Hackers Confession 2004". From the title itself this documentary video was dated in the year 2004.

This video clip is from Loren Legarda's Real Life Stories TV Program which I am not so familiar with. I was still on my sixth grade then at that time. I am not sure if you are familiar with this documentary video but if you are an infosec enthusiast, this is worth watching for.

This documentary video is a story about two Internet Relay Chat (IRC) users in Dalnet who are not only chatters but are associated with pinoy underground groups, namely #philcarder, #asianpride and #phteam to name a few and also a guy named Henry who is a cracker.

Tamby
The first video is about a carder named Tamby who showed Loren how carding is done.

Carding is a term for theft and fraud using a credit card (CC) in order to purchase goods, gadgets, shirts, etc. Tamby explained that he got the full credit card details from another IRC user who posted the CC details of an American credit card owner. Tamby also showed how he ordered and received his shipment without being caught.

Michael
The second video is another carder named Michael who finished two computer courses - Computer Science and Computer Engineering.

He didn't have much to show but explained that he does scamming, phishing and also carding. Michael not only pawns people's accounts, he also sells the goods he purchased online.

He’s a linux user and was frequently on IRC channel #philcarder.
This same channel is also featured on this video clip.


Henry
The third video is another cracker named Henry. He
was branded here as a computer wizard because he monitors other people's computer and mobile phones. Yeah, you read me right! He also RATs cellphones.


This video was documented in 2004 and it has been three years since the Love Bug (I Love You Virus) incident of Onel de Guzman.

The first two people showed the capabilities of some IRC users in Dalnet which is common on IRC chat rooms. What struck me most is the third person who RATs another computer and mobile phones.


What Now?

To date, the NBI has been tracking carders but there has been no luck lately. This kind of people still exists today and in fact younger people are starting to get hooked up with this dilemma. I bet you have just read the story of a
14 year old boy who was hired by Microsoft.


Still, I don't like to brand them as l337 hackers but IRC enthusiasts and people who cracks out of curiosity. Ordinary users would call them hackers but if you pack them all together, they are just ordinary people like me and you.

What you see in this clip could not be branded as
real hacking because hacking is more than just what is shown here.


Hacking is more than what you can acquire physically. Hacking is when you advance yourself to learn more about the intricacies of technology and you help people secure themselves from these prying eyes on cyberspace.


Talk Back
Please comment on this blog at our ROOTCON
Forum. We all learn from each other when your views and opinions are shared.

Participate ROOTCON 2011 Security Conference
Our objective here in
ROOTCON is to promote "Security Awareness".

Please join us on September 9 - 10, 2011. Venue will be at Parklane International Hotel, Cebu City, Philippines.

Early bird registration is until June 30, 2011. For more info about the registration click
here. Check also the list of our seminar tracks and bio of our speakers.

ROOTCON is an independent conference, not owned or controlled by any vendors, the speakers don’t have to “stay on message” – and
it’s not a marketing event.

ROOTCON goes beyond the sessions with independent experts that focuses on what works in the real world. That means the experts give the straight scoop on how to workaround any limitations and manage network security wisely.


About the Contributor:

Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.


ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More