Friday, August 19, 2011

NodeZero supports ROOTCON 5

We are glad that we have NodeZero as Media Partner for ROOTCON 5.


As a brief introduction, NodeZero is Ubuntu based linux designed as a complete system which can also be used for penetration testing.
NodeZero uses Ubuntu repositories so your system will be always up to date.

NodeZero is packaged with around 300 tools for penetration testing and set of basic services which are needed in penetration testing.

This is a good tool you ought not to miss!

Proof of their support for ROOTCON 5:

Follow our friend at http://netinfinity.org/


Grab a copy on September 9 and 10, 2011 at Parklane International Hotel, Cebu City, Philippines.

About the Contributor:
A self-confessed blogger minus the coffee. He maximizes his skills in consultancy, project management, professional networking, social media campaigns and very active in conceptualizing things. To date he already conducted several IT / Information Security events as his passion since 2007. Currently he's working as a Technical Support Specialist in a local company.



ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Thursday, August 18, 2011

Cool Ubuntu Shell Account


Good news for Ubuntu fans and shell enthusiasts out there. Nvita.org is offering a Ubuntu shell account that provides users with access to softwares and services like GCC (GNU Compiler Collection), IRC access, Irrsi, background processes, FTP (File Transfer Protocol), and text editors (like nano and vi) for free.

Yes! You are not dreaming, this is true and not only that, the shell account could also be used for tunneling. Honestly, I do love their service because I love free stuffs. This kind of project really conforms to the philosophy of Richard Stallman about Open Source and Free Software. This is the power of Linux and the GNU Project!


NVITA (Northern Virginia Information Technology Association) deserves recognition for their excellent shell project which has the latest Ubuntu 11.04 as its Operating System (Linux Ubuntu 2.6.35-22-generic-pae #33-Ubuntu SMP Build Server). Unlike other shell providers, NVITA also allows users to install packages with their permission.

But there are some flaws in their project because they allow too much background which could possibly be used for illegal activities. We could not deny the fact that some users may tend to abuse their privileges as a user like using it for udpflooding, tcpflooding, hosting botnets, scanning SSH, etc. because of allowing too much background processes. Maybe next time they should put some limit to prevent abuses in their server.

But in the long run, NVITA is still one of the best shell account providers for allowing us to connect to their server with good services despite the said flaws. NVITA offered free shells which are not meant to be abused but meant for a purpose thus we should use it ethically. It’s now up to the user where he wants to use it as long as it does not violate the ethical laws of Internet and computers.



About the Contributor:

Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.



ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved.Designated trademarks, brands and articles are the property of their respective owners.

Read More

Tuesday, August 16, 2011

Thoughts on the Operation Shady Rat



Let it be known that the year 2011 is best described as the Year of the Hackers. And I know, one way or another you will agree or disagree with me. But hey! The media publicized these sophisticated security attacks targeting CIA, US Senate, Sony, PBS, Philippine Congress and the list continues. All of these attacks are attributed to hacker groups such as AntiSec, Anonymous and LulzSec.
What is very surprising from these groups is that most of their members are teens just like Topiary who recently posted on bail.
These attacks and media whoring already existed in the past but it’s only now that it has been the center of attention and worst it gained a lot of followers on what will be their next target as most of them have their own social network page on Facebook and Twitter.
In other news, Dmitri Alperovitch, Vice President of Threat Research at the Cyber-Security Firm of McAfee recently posted a blog entitled “Revealed: Operation Shady Rat” which demystified a five year hacking campaign which infiltrated the computer systems of national governments, global corporations, oil companies, and other profit and non-profit organizations. The campaign which took down 72 targets, making it perhaps the largest concerted hacking attempt in history, McAfee said. Government agencies in India, South Korea, Taiwan, and the U.S. were also attacked, plus high-profile targets like the International Olympic Committee.

I have been quiet for a couple of days because of constant research of this unprecedented cyber-espionage campaign which was discovered in the year 2006 because of the logs which was discovered by McAfee. In fact, some people blame China and Russia behind this espionage but it should be noted that McAfee disclaimed that China or Russia is responsible for this and that they also declined to reveal the source where the “Shady RAT” came from.

I’m not really sure who suggested that China should be blamed for this but I think they blamed some of the Chinese hackers because of the recent information gathering they made. It is said that in the past years, they have stolen highly confidential information that is kept secret in supercomputers in the US. But the Chinese government denied its involvement of the said campaign.

Some people may also say that it’s the Russian government because of the unforgotten Cold War between the US but then again it is really unfair to point our fingers to Russia and China because of insufficient evidence against them. All countries are innocent until proven guilty.

I guess McAfee has unleashed a new media storm because of their discovery since 2006. Their rival company, Symantec also posted its own analysis of the campaign and was skeptical of its impact. "Is the attack described in Operation Shady RAT a truly advanced persistent threat? I would contend that it isn’t, especially when you consider the errors made in configuring the servers and the relatively non-sophisticated malware and techniques used in this case," Symantec's Hon Lau wrote in a blog post.

"Sure the people behind it are persistent but no more than the myriad of other malware groups out there such as Zeus, Tidserv, and others like them," said Lau.

Although, it is highly controversial and questionable why McAfee discovered this campaign before any antivirus company or government agency; but could it be possibly an excuse to put blame on China? That I’m not sure of and I lay my hands off regarding this case.

To our valuable readers, I’ll give you a room for your opinions and views regarding this campaign. If you ask me, I have 60% trusts on this revelation. Whether this is true or not, there are questions that will cloud up our minds. So are we ready for this cyber espionage and cyber terrorism?
Philippines is not included in the list but who knows?





About the Contributor:
Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.

ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved.Designated trademarks, brands and articles are the property of their respective owners.
Read More

Monday, August 15, 2011

Do You Need Snort for Intrusion Detection?


If you haven't heard of Snort, you may be surprised at how much this system has to offer for FREE!

Snort has a proven track record, excellent performance and accuracy that will surely be around for a long term.

There are many products out there and some of them are rather expensive. Snort is an open source IDS (intrusion detection system) which is just as powerful and popular as any commercial product.

However, the big down side is that you don't have a customer support to help you out and you have to teach yourself on how to install, configure and maintain your IDS.

I know a former colleague of mine who has a good experience in using Snort. I'm not sure if he's available for an invitation to give a talk.

Well, if you're one of the good guys out there who loves to share your knowledge, then by all means contact us at info[at]rootcon[dot]org. We can have an informal meet-ups. After all, we are here to share and be part of ROOTCON community.

Stay Safe!


About the Contributor:
A self-confessed blogger minus the coffee. He maximizes his skills in consultancy, project management, professional networking, social media campaigns and very active in conceptualizing things. To date he already conducted several IT / Information Security events as his passion since 2007. Currently he's working as a Technical Support Specialist in a local company.

ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Real-time PC Security Protection

There are many security tools out there, but most of them only scan your system when you tell them to, allowing attacks or changes to your system to take place.

WinPatrol is a nice little program that will alert you when there is any change to your system without your permission, allowing you to detect many security related issues in real-time.

This program is created by a Studio founder and industry insider named Bill Pytlovany.

These days Bill is better known for his contribution in helping increase the
performance and security of hundreds of thousand of computers.

If you don't know him that much, direct your mouse and click his website at www.winpatrol.com/download.html.

Do you want to be our Guest Blogger?

ROOTCON Blog section is open for anybody who wish to be our guest blogger. Feel free to contact us at info[at]rootcon[dot]org.

Stay safe!



About the Contributor:
A self-confessed blogger minus the coffee. He maximizes his skills in consultancy, project management, professional networking, social media campaigns and very active in conceptualizing things. To date he already conducted several IT / Information Security events as his passion since 2007. Currently he's working as a Technical Support Specialist in a local company.


ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Saturday, August 13, 2011

Vatican Library Uses Linux and UNIX


So the Vatican Library uses Linux and UNIX? Who would have thought
about it? You heard me right! The keepers of the 15th century Vatican Apostolic Library uses Linux and UNIX to keep their invaluable collection intact.


The Vatican Library's Website
revealed that
The Information Technology Center (C.E.D.) of the Vatican Library uses Red Hat. C.E.D.’s networks “are protected internally by two first-level firewalls in a Linux Red Hat environment”. But that’s not all. It is also revealed that of the 27 servers the IT Center uses, 19 are in a SUSE and Red Hat environment. The rest are running in a UNIX AIX environment and in a Microsoft environment (virtualized on Linux systems with VMware).


It all began in 1985 wherein the system “uses a Geac 8000/F system with about ten terminals in serial connection at 9,600 bps. The birth of the URBS network, five years later, brought about a substantial upgrade of the system, and the number of terminals was increased to about fifty, of which fifteen have a baseband connection to the relevant remote access points at 9,600 bps.


As a Catholic Linux enthusiast and an ex-seminarian, it’s a good thing that the Vatican sees the Free and Open Source Movement as beneficial to the Catholic Church. Open source is better than a closed source which is costly. According to
Fr. Stephen Cuyos, MSC (A Filipino Priest who blogs about Linux and Free/Open Source Software), “The philosophy of Free and Open Source Software (FOSS) is based on cooperation, common good and mutual benefit, and is in many ways consistent with the Catholic Church’s preferential option for the poor.”


It should also be noted that Richard Stallman and Linus Torvalds totally rock!



About the Contributor:

Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.



ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved.Designated trademarks, brands and articles are the property of their respective owners.

Read More

Monday, August 08, 2011

ROOTCON 5 Parteh and etc...etc...

ROOTCON 5 is 31 days away, the question is have you planned what to do during the two day Hacker CON? Or should it be, do you have an idea what its like to be at a Hacker CON? Well to give you an idea, ROOTCON like any other Hacker CON on the planet it's an awesome venue for Geeks, Hackers, Developers, and all tech enthusiasts.

The first thing to look forward are the talks, ROOTCON has gathered several cool talks, the next thing to look are the games hosted at ROOTCON, if you are into hacking, wargaming, then this is your place, ROOTCON Folks crafted some cool Capture The Flag games for the CON, from WiFi, Web to Shell breaking we have it all, and its all free for ROOTCON attendees.

And the coolest part being at a Hacker CON are the Partehs, yes you heard it right, Partehs. After Day 1 there will be a Geek-Up and Ninja/Pirate/Geek Parteh that will be held, right after Day 2 there will be a post-con parteh as well. Hacker CON is the best time to socialize with our fellow G33ks and H4x0rs. This is the best part of the CON that you don't want to miss at all.

At the time of writing we are already planning these Partehs, you can even plan with us!!! Be updated with our Twitter (@_rootcon_) and our Facebook (https://www.facebook.com/rootcon). Our brainstorming and planning will be put to public at our ROOTCON 5 Google Groups (rootcon5@googlegroups.com)

Let the Partheh and the Hacking begins..........
Read More

10 year old girl hacker CyFi reveal her first zero-day in Game at #DefCon 19


Another awesome day at DefCon 19 . Today a 10 year old Girl hacker - pseudonym CyFi revealed her zero-day exploit in games on iOS and Android devices that independent researchers have confirmed as a new class of vulnerability. The 10-year-old girl from California first discovered the flaw around January 2011 because she "started to get bored" with the pace of farm-style games.

About CyFi :
She is cofounder of DEFCON Kids. CyFi is a ten-year-old hacker, artist and athlete living in California. She has spoken publicly numerous times, usually at art galleries as a member of “The American Show,” an underground art collective based in San Francisco. CyFi’s first gallery showing was when she was four. Last year she performed at the SF MOMA Museum in San Francisco. DEFCON Kids will be her first public vulnerability disclosure. CyFi’s has had her identity stolen twice. She really likes coffee, but her mom doesn’t let her drink it.

CyFi said, "It was hard to make progress in the game, because it took so long for things to grow. So I thought, 'Why don't I just change the time?'" Most of the games she discovered the exploit in have time-dependent factors. Manually advancing the phone or tablet's clock forced the game further ahead than it really was, opening up the exploit.

CyFi said that she discovered some ways around those detections. Disconnecting the phone from Wi-Fi made it harder to stop, as did making incremental clock adjustments. CyFi's mother, who must remain anonymous to protect her daughter's identity, told at the end of CyFi's presentation at DefCon Kids that they would offer a $100 reward to the young hacker who found the most games with this exploit over the following 24 hours. The reward is sponsored by AllClearID, a identity protection company that is also sponsoring the DefCon Kids.

CyFi revealed that she was only a little bit nervous about having to speak in front of the 100 or so expected attendees. She admitted that while it was probably different publicly speaking about a topic with such a specific focus, it would be hard for her to imagine what those differences might be. "Well, I haven't done it yet," she said.

Source: The Hacker News


ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Department of Defense tries to court hackers

Las Vegas, Nevada (CNN) -- Dear hackers: The U.S. government wants you.

Or, at the very least, the Department of Defense's research wing wants to pay you to help it block cyber threats, a project manager at the Defense Advanced Research Projects Agency said Thursday.

Former hacker Peiter Zatko announced the start of a fund-the-hackers program, called Cyber Fast Track, in a keynote talk at the Black Hat conference, which is aimed at hackers and computer security experts. The program began officially late Wednesday, he said.

Experts say the government has done a lousy job in the past of getting money to security researchers quickly enough for them to actually help mitigate cyber threats. Or the feds have avoided dealing with hackers entirely.

"One of the ways I see fixing it is bridging the gap between the government and the hacker community," said Zatko, who goes by the handle "Mudge."

By "hacker," he doesn't mean criminal. He's referring to people who try to break computer systems with the goal of making them more secure. These people are sometimes referred to in the security industry as "white hats," as opposed to nefarious "black hats."

"We have all sorts of other criminals, be it in politics or finance, and those elements may be bigger than the criminal element in the hacker community," he said.

Other wings of the government appear to be courting the hacker community as well. The Federal Bureau of Investigation and the Internal Revenue Service both have booths set up on the expo floor here at Caesars Palace. Federal agents are so commonplace at this hacker conference -- and at another, called DEF CON, which happens later this week -- that some of the hackers have held a "Spot the Fed" contest, with T-shirts as prizes.

Law enforcement and hackers don't always play well in these arenas. Speakers at past Black Hat and DEF CON conferences have been threatened with injunctions aimed at stopping them from explaining how to hack into certain systems.

The hackers say they're making public such exploits for the public's own good. If they can find the bugs, then bad guys who want to steal information and make money could, too.

In an interview after his talk, Zatko declined to say how much money DARPA will put into the new program, or how big the individual grants will be.

The goal is to fund independent security researchers, who currently do much of their work on nights and weekends without pay, in hopes that they will help make the Internet safer.

One of those hacker-researchers is Dino Dai Zovi, who says his girlfriend gets annoyed that he spends almost all of his free time on his computer.

"Look at the bags under my eyes -- I never stop working," he said.

Dai Zovi said the DARPA program will help hackers actually get paid for their work.

The stakes for the new program are also high.

Zatko, the hacker-turned-DARPA official, said the number of malware attacks continues to increase even as government agencies spend more money to stop them.

In 2000, he said, there were about 1,400 "incidents of malicious cyber activity." Nine years later, that number had jumped to more than 71,000.

Current computer systems are needlessly complicated, he said, which leaves them more open to malicious hacking. He suggested that researchers work, for example, to simplify Microsoft Word with its list of 3,000 fonts and many potential exploits.

Zatko, whose notable life as a hacker has been the inspiration for fictional characters, said he's trying to change how the government works from the inside.

"I hope the old Mudge of 1999 is looking at the current Mudge of 2011 and saying, 'Yeah, you're wearing a pocket square and you don't have long hair,' " he said, " 'but, yeah, you're still remaining true to the cause.' "


Source: CNN


ROOTCON is managed by like minded InfoSec professionals across the Philippines.

All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

DEF CON trains 8-year-olds in hacking

Las Vegas, Nevada (CNN) -- Joseph Horman already had seen the lock-picking videos on YouTube. But it was a different thing entirely for the 13-year-old puzzle-lover to get lessons in lock picking and computer hacking at an event sanctioned by adults.

The world's largest gathering of computer hackers -- DEF CON, which is happening this weekend at the Rio Hotel and Casino in Las Vegas -- held its first-ever hacking classes for kids this year, at an event appropriately called DEF CON Kids.

Sessions in hacking were designed for kiddos ages 8 to 16.

A common parent's reaction to something this might be: They're teaching them what?! But hear these hackers out. Their intentions are good.

Take Horman's uncle, Adam Steed, a computer security professional in Salt Lake City, Utah, who brought his nephew to these training sessions because he already was fascinated with games and coding. (He actually has written his own computer game, called "Blooks," in which players "try to build as many buildings as you can while avoiding enemies," he said.)

"You can watch lock-picking videos on YouTube, but where do you hear the ethical side of this?" said Steed, the uncle. "Not on YouTube."

He added: "I would rather someone learn in a controlled environment. They're going to learn it anyway."

Horman, the video game-writing nephew, sat attentively in the second row of a small classroom on Saturday, fiddling with a Rubik's Cube during sessions with titles like "Secrets Revealed," "Meet the Feds" and "Google Hacking."

That last class title is a bit misleading, since instructor-hacker Johnny Long focused more on non-technical hacking -- looking at people's laptops over their backs in airports; picking locks with toilet paper rolls and pen caps; and digging social security numbers out of corporate trash bins -- instead of actual search-engine hacking.

Long went to great lengths to remind the kids in attendance that the point of the class was to teach them what bad guys might be doing -- and how to avoid breaches in their own security or privacy.

"Don't let me catch you guys stealing toilet paper and breaking locks," he said. "If you do, it's not my fault."

Horman said he would only pick a lock if his family got locked out of their own house or car. That's happened before, he said, so that skill might be handy.

"Our family has had some trouble with locks," he said, smiling. "Let's say the younger ones love playing with the key and slipping them under the door."

In the "Meet the Feds" session, representatives from NASA, the Department of Homeland Security, the National Security Agency and the Navy told the kids they were smart to pick up hacking skills early because the government needs employees who can hack.

Several kids raised their hands to ask about hacking as a career path.

Part of the potential confusion about DEF CON Kids comes from the very term "hacker," which people here use to refer to anyone who has the skills needed to modify computer software and hardware. Some hackers extend the domain further, to locks and such.

Those skills could be used for criminal activity, but quite a few DEF CON attendees are actually computer security professionals -- the "good guys" trying to make the Internet less vulnerable to attacks by computer criminals.

Still, all this talk about malicious hacking made 10-year-old Dennis Mikhaylov a bit nervous.

"I'm getting a locker next year," he said after one of the class sessions. He's about to start middle school. "I thought it was cool, but now I'm afraid someone might open it."

Mikhaylov said he'd deal with this by keeping any valuables, which he defined as anything with his address on it; textbooks; and his Nook e-reader, which he apparently carries around all the time, out of that school locker.

The DEF CON Kids event also included a competition, where kids went around the hacker conference trying to break codes and solve puzzles.

Isabel Holland, 10, made up one-half of a team called "Sonic Death-Monkeys," a name she says is "weird" but went with because the boy who was her partner chose it.

"You have to, like, find people, and it's really hard because they're all over the place," she said of one piece of the challenge which required her to search out hackers.

Her dad, Bo Holland, from Austin, Texas, said it's cool for kids to get a chance to see how the technology and video games they use all the time actually work.

Ultimately, it will make the kids safer, he said, especially in this age of social networking, when the collective memory of the Internet has no expiration date.

"You're building up your reputation and it's not going to go away. If you do bad things, that's going to stick with you," he said.He added: "You can say, 'Oh, we don't want to hear how this (hacking) stuff works and that's scary ... but it's really important kids know how to protect themselves."


Source: CNN


ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Sunday, August 07, 2011

My Gmail Got Hacked!


Relax.

I know I have your attention now.
Take a deep breath before I continue with this story.

I just arrived at my pad at around 11PM (Saturday, August 6) after a meeting with an old friend.

Like you, I always check my emails every now and then. So I jumped in front of my working table, turned on my laptop and hurriedly checked my emails. Whoa! Alas! Look what I found?

How do you react if you receive an email from a friend with a subject line - “My Gmail Got Hacked”?

I know…

Below is the screen shot of the message I got from my friend. I hid her family name, email address and her friend’s name who is a System Administrator to protect their privacy.



(Click the image to enlarge)

Yes, it’s a big nightmare if someone else is in control of your email accounts whether it’s Gmail, Yahoo or Hotmail. Worse if it’s your company email address! Argh!

Here are some options that you can do:

1) Act immediately, don’t wait.
2) Change the password.
3) Check your sent items / sent folder
4) Contact your Email Support Team (e.g. Google Support Team).
5) Check your other email accounts.
6) Send an apology to all your contacts like what my friend did
7) Pay it forward. If you receive similar incidents, advice your friend to minimize damage.

Have you been in this situation before? How did you handle it?

Oh BTW, what’s your comment about this line on her email:



(Click the image to enlarge)

Is it the fault of Gmail or the user?

Share your thoughts.


About the Contributor:
A self-confessed blogger minus the coffee. He maximizes his skills in consultancy, project management, professional networking, social media campaigns and very active in conceptualizing things. To date he already conducted several IT / Information Security events as his passion since 2007. Currently he's working as a Technical Support Specialist in a local company.


ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
Read More