Showing posts with label crackers. Show all posts
Showing posts with label crackers. Show all posts

Sunday, September 25, 2011

The Simple Mass WEP and WPA Cracker

If there is Piata Scanner for scanning and cracking mass SSH (Secure Shell), there is also Wifite.py for mass WEP (Wired Equivalent Privacy) and WPA (Wi-Fi Protected Access) cracking. Wait, wait… say what??

You read me right! There is Wifite.py for mass WEP and WPA cracking. Wifite.py is a cool tool coded in python which makes cracking WIFI passwords and security easier. It can be executed by using the command line python wifite.py or ./wifite.py. To see a list of command lines with detailed information for the script, you can just type in the terminal ./wifite.py –help or python wifite.py –help.

The tool is customizable to be automated with only a few arguments. Cool ey? Yeah, but it should always be noted that it requires Aicrack-ng suite which is used for auditing wireless networks and also needs macchanger which is of course  available via apt-get install.

What makes this tool easier is that it also has a GUI mode which runs by default after executing the script if it has a python-tk module. So far, the tool works good on my Backtrack 5 R1 and my Ubuntu 10.04 and a must have for Wi-Fi ninja geeks out there. It also works great with Blackbuntu. Not to mention that it also has a built in updater and can be updated by the command line ./wifite.py –upgrade or python wifite.py –upgrade.

Wifite.py was also mentioned in New York Times' article "New Hacking Tools Pose Bigger Threats to Wi-Fi Users" last February 16, 2011.

If you want to download the python script, click here.


About the Contributor:

Shipcode is a prolific blogger of ROOTCON and at the same time an InfoSec enthusiast from Cebu. He was inspired to join ROOTCON as part of the core team to share his knowledge in information security.  He encourages other like minded individuals to come forward and share their knowledge through blogging right here at ROOTCON Blog section. Email your contributions to info[at]rootcon[dot]org.


ROOTCON is managed by like minded InfoSec professionals across the Philippines.  All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Sunday, August 21, 2011

Reminiscing the Hacker’s Manifesto


Have you guys heard of the Hacker’s Manifesto?

Probably some of you may say yes and some may say no. But for those of you who haven’t heard of it, it’s an essay written by Loyd Blankenship (a.k.a. The Mentor, stylized as +++The Mentor+++).

It’s also known as the “The Conscience of a Hacker” which was written on January 8, 1986 which followed after the arrest of Loyd and was published in an underground ezine (online magazine) Phrack.

So who is Loyd Blankenship a.k.a The Mentor? He is a well known American computer hacker and writer since the 80’s and was a member of the hacker groups, “Extasyy Elite” and “Legion of Doom”. He also wrote the game “Cyberpunk” which was seized by the Secret Service.

It is believed that the “Hacker’s Manifesto” is the cornerstone and the foundation of the hacker culture and the article also gave some insight into the psychology of early hackers.

The Manifesto states that hackers hack out of curiosity and that they want to learn more.

Hackers don’t learn to hack, they hack to learn.

The article reflects the attitude and the personality of the hackers in the early 80’s and 90’s. During these days, being a script kiddie was moderately cool, packet wars were in and lame DOS attacks like WinNUKE and the ath0++ modem drop were cool.

Phreaking also became a mainstream during these days and that sharing of knowledge like cracking, cryptography, programming (C++, VB, Delphi, C, Pascal, Assembly, Python, PERL, Bash and so on), network security, Linux, Windows, UNIX, etc. became the main topics in IRC.

The essay of Loyd was also quoted in the 1995 Movie entitled “Hackers”. Mentor received a credit from this movie. Also a poster about the said article appears in the movie "The Social Network" on the wall of Mark Zuckerberg's dorm room.

Below is the complete essay of +++The Mentor+++:

Loyd Blankenship a.k.a +++The Mentor+++


The Hacker’s Manifesto

Another one got caught today, it's all over the papers. "Teenager Arrested in Computer Crime
Scandal", "Hacker Arrested after Bank Tampering"...

Damn kids. They're all alike.

But did you, in your three-piece psychology and 1950's technobrain, ever take a look behind the eyes of the hacker? Did you ever wonder what made him tick, what forces shaped him, what may have molded him?

I am a hacker, enter my world...

Mine is a world that begins with school... I'm smarter than most of the other kids, this crap they teach us bores me...

Damn underachiever. They're all alike.

I'm in junior high or high school. I've listened to teachers explain for the fifteenth time how to reduce a fraction. I understand it. "No, Ms. Smith, I didn't show my work. I did it in my head..."

Damn kid. Probably copied it. They're all alike.

I made a discovery today. I found a computer. Wait a second, this is cool. It does what I want it to. If it makes a mistake, it's because I screwed it up. Not because it doesn't like me... Or feels threatened by me.. Or thinks I'm a smart ass.. Or doesn't like teaching and shouldn't be here...

Damn kid. All he does is play games. They're all alike.

And then it happened... a door opened to a world... rushing through the phone line like heroin through an addict's veins, an electronic pulse is sent out, a refuge from the day-to-day incompetencies is sought... a board is found. "This is it... this is where I belong..." I know everyone here... even if I've never met them, never talked to them, may never hear from them again... I know you all...

Damn kid. Tying up the phone line again. They're all alike...

You bet your ass we're all alike... we've been spoon-fed baby food at school when we hungered
for steak... the bits of meat that you did let slip through were pre-chewed and tasteless. We've been dominated by sadists, or ignored by the apathetic. The few that had something to teach found us willing pupils, but those few are like drops of water in the desert.

This is our world now... the world of the electron and the switch, the beauty of the baud. We make use of a service already existing without paying for what could be dirt-cheap if it wasn't run by profiteering gluttons, and you call us criminals. We explore... and you call us criminals. We seek after knowledge... and you call us criminals. We exist without skin color, without nationality, without religious bias... and you call us criminals. You build atomic bombs, you wage wars, you murder, cheat, and lie to us and try to make us believe it's for our own good, yet we're the criminals.

Yes, I am a criminal. My crime is that of curiosity. My crime is that of judging people by what they say and think, not what they look like. My crime is that of outsmarting you, something that you will never forgive me for.

I am a hacker, and this is my manifesto. You may stop this individual, but you can't stop us all... after all, we're all alike.



About the Contributor:

Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.



ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Sunday, July 31, 2011

BackTrack 5 R1 to be released on August 10th




The BackTrack Team has announced that Backtrack 5 R1 (Release One) is set to be released on the 10th of August 2011.

I’m sure many of our infosec friends out there are already excited to download its new release on the said date. The update includes 100 bug fixes, package updates, and the addition of over 30 new tools and scripts.

BackTrack 5 will surely rock your ninja skills because it’s the most favored penetration testing linux distro; and once again it’s back in action.

The crew will also have a pre-release event of BackTrack 5 R1 at the BlackHat / Defcon Conference a few days earlier. Cool isn't?

May the sauce be strong with you.” – BackTrack Crew

Way to go BackTrack Team!

For more info, just visit the BackTrack Official Website.


P.S.

I attached a spoofed video about Backtrack 4 but its thoughts are true.

So anyone out there who wants to master this tool and show off your skills on our next meet up?
Perhaps on ROOTCON 2012? Any volunteers? Email us at info[at]rootcon[dot]org. Thanks.



About the Contributor:

Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.


ROOTCON is managed by like minded InfoSec professionals across the Philippines. All rights reserved.Designated trademarks, brands and articles are the property of their respective owners.

Read More

Sunday, July 17, 2011

The Artificial Lurkers of IRC



I guess most of you are familiar with the IRC or the Internet Relay Chat. According to Wiki, IRC is a form of real-time Internet text messaging (chat) or synchronous conferencing. It is mainly designed for group communication in discussion forums, called channels, but also allows one-to-one communication via private message as well as chat and data transfer, including file sharing.

But is IRC still alive these days? Yes it is, in fact it is the home of underground hackers and crackers, to name a few; defacers, rooters, carders, script kiddies, hardcore Linux users, etc. IRC is often referred as a primitive way of chatting because of its style and because of the new generation of voice and video chatting just like Tinychat and Facebook. And because of Facebook, some of the teenagers don't even know how to use IRC clients.

But of course, we will not deal more about how to use it and where to have a good chat mate. Instead we will talk about some of the hidden agendas of IRC users and the dark side of IRC. Forgive me for referring to it as the dark side thingy but that's what other IRC users usually call it.

In IRC there are some users that have botnets or bots in their channel which can do ; udpflooding, check for vulnerable websites, portscanning, nmap, sqli, rfi, lfi, check for good credit cards and many more. These botnets are coded in languages like perl, php and python.

In fact, some of these bots are hosted on a hacked or rooted boxes or even websites that have backdoor shells. Users with bad intentions like doing a DDoS attack would not run their scripts on their own machine in order to avoid getting traced or caught.

The images below are screenshots I took and uploaded so that people may be aware that these kinds of lurkers exist in the cyber world and could also be a threat or an advantage.



Thus it would be easier to say that an IRC bot is an independent program or script that connects to IRC as one of the clients but differs to other clients because it performs automated functions.


Nowadays, these bots are often scattered in public channels and who knows, you may be able to encounter one. Now don't panic, they won't infect you, they are just waiting for their handlers to command them. Like I said, they are different from infecting botnets like the Zeus Bot.

The bots shown here are for educational purposes only, no live accounts and servers were tested and rooted in order to run these scripts.



About the Contributor:

Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.



ROOTCON is managed by like minded InfoSec professionals across the Philippines. All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Thursday, June 02, 2011

Pinoy Hacker's Confession 2004



On February 7, 2011 a user uploaded a video entitled "Pinoy Hackers Confession 2004". From the title itself this documentary video was dated in the year 2004.

This video clip is from Loren Legarda's Real Life Stories TV Program which I am not so familiar with. I was still on my sixth grade then at that time. I am not sure if you are familiar with this documentary video but if you are an infosec enthusiast, this is worth watching for.

This documentary video is a story about two Internet Relay Chat (IRC) users in Dalnet who are not only chatters but are associated with pinoy underground groups, namely #philcarder, #asianpride and #phteam to name a few and also a guy named Henry who is a cracker.

Tamby
The first video is about a carder named Tamby who showed Loren how carding is done.

Carding is a term for theft and fraud using a credit card (CC) in order to purchase goods, gadgets, shirts, etc. Tamby explained that he got the full credit card details from another IRC user who posted the CC details of an American credit card owner. Tamby also showed how he ordered and received his shipment without being caught.

Michael
The second video is another carder named Michael who finished two computer courses - Computer Science and Computer Engineering.

He didn't have much to show but explained that he does scamming, phishing and also carding. Michael not only pawns people's accounts, he also sells the goods he purchased online.

He’s a linux user and was frequently on IRC channel #philcarder.
This same channel is also featured on this video clip.


Henry
The third video is another cracker named Henry. He
was branded here as a computer wizard because he monitors other people's computer and mobile phones. Yeah, you read me right! He also RATs cellphones.


This video was documented in 2004 and it has been three years since the Love Bug (I Love You Virus) incident of Onel de Guzman.

The first two people showed the capabilities of some IRC users in Dalnet which is common on IRC chat rooms. What struck me most is the third person who RATs another computer and mobile phones.


What Now?

To date, the NBI has been tracking carders but there has been no luck lately. This kind of people still exists today and in fact younger people are starting to get hooked up with this dilemma. I bet you have just read the story of a
14 year old boy who was hired by Microsoft.


Still, I don't like to brand them as l337 hackers but IRC enthusiasts and people who cracks out of curiosity. Ordinary users would call them hackers but if you pack them all together, they are just ordinary people like me and you.

What you see in this clip could not be branded as
real hacking because hacking is more than just what is shown here.


Hacking is more than what you can acquire physically. Hacking is when you advance yourself to learn more about the intricacies of technology and you help people secure themselves from these prying eyes on cyberspace.


Talk Back
Please comment on this blog at our ROOTCON
Forum. We all learn from each other when your views and opinions are shared.

Participate ROOTCON 2011 Security Conference
Our objective here in
ROOTCON is to promote "Security Awareness".

Please join us on September 9 - 10, 2011. Venue will be at Parklane International Hotel, Cebu City, Philippines.

Early bird registration is until June 30, 2011. For more info about the registration click
here. Check also the list of our seminar tracks and bio of our speakers.

ROOTCON is an independent conference, not owned or controlled by any vendors, the speakers don’t have to “stay on message” – and
it’s not a marketing event.

ROOTCON goes beyond the sessions with independent experts that focuses on what works in the real world. That means the experts give the straight scoop on how to workaround any limitations and manage network security wisely.


About the Contributor:

Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.


ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Sunday, May 15, 2011

What makes ROOTCON different?

Determining what really sets ROOTCON apart from others and communicating it effectively is not an easy thing to do. Considering that ROOTCON was molded through our collective efforts, volunteers from across the country, invited guest speakers and seeking sponsors to support the whole event is and will always be a learning adventure.

Technically speaking, like what I said in my previous post - ROOTCON is not associated with any of the businesses or companies in the country. Thus we make it a point from the very beginning that all the topics in our seminar tracks are not disguised as a marketing tool.

Topics that we have in every convention are not recycled. These are topics approved by our committee through our "Call For Papers". We scrutinize our speakers and so with their topics if they are obsolete or updated. Now you know that our speakers are “The Experts” with solid experience on security.

Hacking contest is also available during the conference but the targets are local NOT public servers or your production network. We set up our own private network at the venue. We also put up an FAQ section for you to review.

When asked to support ROOTCON privately, my basic question was – “What makes ROOTCON different?” My discussion with the founder was a lengthy one and I guess by now you know why I’m giving my full support. We discussed about his plans, how to share that same passion to a bigger audience and change the security mindset in the country.

Being different gets you noticed and it's undeniably true. But creating value is another thing.

If we build ROOTCON around one company or one person, then it may not last – build ROOTCON around YOU and what we can offer to people who join us in any gatherings, then it will gain the credibility for all the fantastic trainings and support we can bring to everybody and your organization (and of course, you need to make sure that you do!)

To your success! Be it on personal level or career wise!

“Hackers love technology, but crackers love to break it. Which one are you?”


About the Contributor:

A self-confessed blogger minus the coffee. He maximizes his skills in consultancy, project management, professional networking, social media campaigns and very active in conceptualizing things. To date he already conducted several IT / Information Security events as his passion since 2007. Currently he's working as a Technical Support Specialist in a local company.


ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More