Friday, June 10, 2011
Catholic Bishop’s Conference of the Philippines (CBCP) website defaced anew
A website of the Catholic Bishops' Conference of the Philippines (CBCP) was defaced anew Thursday, while it was undergoing "maintenance."
Visitors to the CBCP Episcopal Commission on Health Care as of Thursday morning were greeted with the message "DEATH_K1ng."
However, there was no indication of who was behind the apparent hacking as the rest of the page was blank (www.cbcphealthcare.org).
In past days, the site displayed a message indicating it was undergoing "maintenance."
The site was defaced on Nov. 27 last year, hours before a major pro-life Catholic group was to hold a vigil against the Reproductive Health (RH) bill.
At the time, the site's home page featured the image of a man with his back turned to the viewer.
"HackEd BY LordDem0n EgYpT!0n - H4Ck3r ... Your Security Can Not Face Us !!!" read the message on the defaced website.
The defacement was removed as of noon, although the site continues to remain under maintenance. — TJD, GMA News
Source: GMA News
Talk Back
Please comment on this blog at our ROOTCON Forum. We all learn from each other when your views and opinions are shared.
About the Contributor:
A self-confessed blogger minus the coffee. He maximizes his skills in consultancy, project management, professional networking and very active in conceptualizing things. To date he already conducted several IT / Information Security events as his passion since 2007. Currently he's working as a Technical Support Specialist in a local company.
ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
Thursday, June 09, 2011
Hacker hacks electronic traffic sign and posted “Caution! Zombies Ahead!!!"


On Jan 29, 2009, an anonymous hacker hacked traffic signs in some parts of the US and posted a sign that says “Caution! Zombies Ahead!!!" - another hilarious mayhem was unleashed! In fact, so many cars pulled over and people started taking pictures in front of it. Cops were deployed in the scene to keep the traffic moving. This happened in Reno, Nevada USA. Hilarious but true!
Actually, this news is kinda old already but hey, I think this incident is funny and will drop you on the floor laughing. It was featured in NBC's Today's Show. The show was all over this hacking electronic road signs story, saying that the officials in Texas were "scrambling" to protect electronic road signs from the threat of hackers trying to warn the residents about the hordes of zombies ahead.
This morning, I chatted with the hacker’s good old friend and we exchanged a lot of information regarding the hacker who hacked the electronic traffic signs. He said to me that the hacker’s name is Jake and that he doesn't have a handle name. He found out that all the electronic traffic signs for road construction have a default password and username. Jake is a hardware hacker.
What happened next, was that the hacker posted a tutorial on how to hack electronic traffic signs which was posted in http://www.i-hacked.com/. Now I’m not sure if it was Jake who posted it. It says there that the default password is DOTS (weird). But one thing we know now is that Zombies do exist! LOL
About the Contributor:
Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.
ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
Thursday, June 02, 2011
Pinoy Hacker's Confession 2004
This video clip is from Loren Legarda's Real Life Stories TV Program which I am not so familiar with. I was still on my sixth grade then at that time. I am not sure if you are familiar with this documentary video but if you are an infosec enthusiast, this is worth watching for.
Tamby
Carding is a term for theft and fraud using a credit card (CC) in order to purchase goods, gadgets, shirts, etc. Tamby explained that he got the full credit card details from another IRC user who posted the CC details of an American credit card owner. Tamby also showed how he ordered and received his shipment without being caught.
Michael
He didn't have much to show but explained that he does scamming, phishing and also carding. Michael not only pawns people's accounts, he also sells the goods he purchased online.
He’s a linux user and was frequently on IRC channel #philcarder. This same channel is also featured on this video clip.
Henry
The third video is another cracker named Henry. He was branded here as a computer wizard because he monitors other people's computer and mobile phones. Yeah, you read me right! He also RATs cellphones.
This video was documented in 2004 and it has been three years since the Love Bug (I Love You Virus) incident of Onel de Guzman.
The first two people showed the capabilities of some IRC users in Dalnet which is common on IRC chat rooms. What struck me most is the third person who RATs another computer and mobile phones.
What Now?
To date, the NBI has been tracking carders but there has been no luck lately. This kind of people still exists today and in fact younger people are starting to get hooked up with this dilemma. I bet you have just read the story of a 14 year old boy who was hired by Microsoft.
Still, I don't like to brand them as l337 hackers but IRC enthusiasts and people who cracks out of curiosity. Ordinary users would call them hackers but if you pack them all together, they are just ordinary people like me and you.
What you see in this clip could not be branded as real hacking because hacking is more than just what is shown here.
Hacking is more than what you can acquire physically. Hacking is when you advance yourself to learn more about the intricacies of technology and you help people secure themselves from these prying eyes on cyberspace.
Talk Back
Please comment on this blog at our ROOTCON Forum. We all learn from each other when your views and opinions are shared.
Participate ROOTCON 2011 Security Conference
Our objective here in ROOTCON is to promote "Security Awareness".
Please join us on September 9 - 10, 2011. Venue will be at Parklane International Hotel, Cebu City, Philippines.
Early bird registration is until June 30, 2011. For more info about the registration click here. Check also the list of our seminar tracks and bio of our speakers.
ROOTCON is an independent conference, not owned or controlled by any vendors, the speakers don’t have to “stay on message” – and it’s not a marketing event.
ROOTCON goes beyond the sessions with independent experts that focuses on what works in the real world. That means the experts give the straight scoop on how to workaround any limitations and manage network security wisely.
About the Contributor:
Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.
ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
Wednesday, June 01, 2011
ROOTCON Meeting at Bo's Coffee Shop, Cebu

[May 31, 2011 at around 6:30PM]
In just a short notice, Ms. T, Mr. S and I finally met at Bo’s Coffee Shop at Raintree Mall (Cebu City). We had a lengthy discussion on how we can extend support to ROOTCON to promote “Security Awareness”.
We are planning of organizing another informal small gathering sometime on July 2011. The sponsor for the food and venue will be taken care of by Ms. T.
Semprix is also planning to fly from Manila to Cebu and join the gathering to introduce ROOTCON 101. Please be reminded that ROOTCON is not an underground movement but an event and a community by itself to share ideas and proof of concept about your research.
In the past, Ms. T attended a lot of international security conferences from abroad and she gave us tips on how to make Philippines in the spotlight as another destination for Information Security Conference. She also mentioned that India has a good standing on this kind of event and widely supported by different companies.
Her interest began when she was a victim of identify thief in the US using her credit card. Her profession is more on headhunting servicing corporate clients in the states.
While busy sipping our coffee, Mr. S showed to us how to spoof and clone a MAC address using a device and gain FULL Internet access (4G) on a wireless connection of a Mobile / Telephone Company. These are IP Addresses that can be spoofed in Cebu and Manila randomly. For privacy, I won’t mention the name of the company here.
Amazed at what I saw, I asked Mr. S – “You can watch YouTube using this connection with no buffering at all?
“Yes”, said Mr. S.
Take note, we did not use the password protected WiFi of the said coffee shop but use the connection presented by Mr. S.
Sniff, Sniff, Sniff at the Coffee Shop
Moving forward, at the back of my head I asked myself, “Is it safe to use a WiFi connection inside the coffee shop? After gaining access on their WiFi, will the attacker be able to sniff around and capture our username and password?”
That question lingers at the back of my head. I’m curious to try it out myself and blog about it next time.
We parted our ways at around 10PM and bid goodbye.
P.S.
If you have projects or research concerning security, please contact us and we will be glad to feature it here. Remember, our objective is to promote “Security Awareness”.
You don’t know if you will be the next victim like what I heard and read. Installing Antivirus in your system is not always a guarantee for security.
Join us and participate ROOTCON! For more info email us at info[at]rootcon[dot]org.
We hope to see you during the CON!
Other blogs you might be interested to read:
GMA Website and Twitter ~ Pawned
About the Contributor:
ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
Sunday, May 29, 2011
ROOTCON welcomes Shipcode as a Blog Contributor

In less than a month, after posting “Are you a Techie Blogger? Join ROOTCON!”, one of our regular online visitors emailed us at info[at]rootcon[dot]org and introduced himself as Shipcode and interested to apply as a Techie Blogger for ROOTCON.
He has been with us since DEFCONPH (then became PinoyGreyHat) and finally ROOTCON. We started DEFCONPH in 2008 and now it’s already 2011. ROOTCON followed in 2009. Time flies so fast! Wew!
I was not mistaken when I posted “Are you a Techie Blogger? Join ROOTCON!” because he was inspired to share his knowledge about security after reading that post. He’s a student enrolled in Computer Programming course in one of the universities here in Cebu City, Philippines.
Technically speaking, I saw his nick in our ROOTCON Forum but only this time that I get the chance to know him better.
The reason why ROOTCON decided to invite contributors / techie bloggers because we know from the very beginning that it will also benefit the community to see someone contribute right before their eyes. First I had to ask myself: How would that benefit the community?
My first hope was that people would see what it takes to start from the very beginning and what it will become in the future.
What is the Future of ROOTCON?
My online friends and even those in the industry encouraged me to continue contributing to ROOTCON because they compare this to any international security events like DEFCON and BlackHat in the US.
Like in India, they started ROOTCON 2011 just this year and look what they have now. India has good sponsors and supported by their government. View and read their appreciations. Please don't be confused, it's not a copycat because ROOTCON Philippines started in 2009.
Reading about it and joining our ROOTCON Forum is one thing, but seeing it in action can be even better.
How can you support ROOTCON? Email us at info[at]rootcon[dot]org.
About the Contributor:
A self-confessed blogger minus the coffee. He maximizes his skills in consultancy, project management, professional networking and very active in conceptualizing things. To date he already conducted several IT / Information Security events as his passion since 2007. Currently he's working as a Technical Support Specialist in a local company.
ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
GMA News Hacking Incident
Around 1:00AM May 29, 2011 news spread all over Twitter and some other blog sites, mentioning the attack that occurred within the GMA News website. Basing on the defaced note and tweets posted on Twitter, a nick D4rkb1t caught up our attention because he is one of our speakers this coming ROOTCON 5 event.
We cannot easily confirm if it was indeed D4rkbit or somebody else using his nick to destroy his credibility.
D4rkb1t is one of the many folks that submitted a paper through our Call For Papers. We carefully examined his talk and it was approved by the topics committee.
His talk was about MITM on SSL With BackDoor As An After Effect.
==============================================
Man In The Middle Attack on SSL with BackDoored After Effect
by: D4rkB1t
Synopsis
You think SSL is secure? This talk will demo out Man In The Middle Attack on SSL with BackDoored After Effect, on this talk the speaker will be using BackTrack 4 as a primary hacking tool to achieve the goal of the attack vector.
==============================================
We at ROOTCON do not condone any illegal activities - however we do not criticize our speakers through an incident like what happened to the GMA News Hacking Incident.
ROOTCON will always serve its purpose as a neutral ground for white hats, black hats, grey hats and other security professionals. ROOTCON is not an underground organization nor an underground movement but an event and a community of free thinking individuals.
We preserve our speakers identity and privacy. Later today we received an email that D4rkb1t will cancel his talk this coming ROOTCON 5, we totally understand and respect the decision made by the speaker. This is to protect the image of ROOTCON.
ROOTCON Founder,
Semprix