home flickr
Your Ad Here
Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Tuesday, August 18, 2009

Hackers break into police computer as sting backfires



An Australian Federal Police boast, on the ABC's Four Corners program last night, about officers breaking up an underground hacker forum, has backfired after hackers broke into a federal police computer system.

Security consultants say police appear to have been using the computer as a honeypot to collect information on members of the forum but the scheme came undone after the officers forgot to set a password.

Last Wednesday, federal police officers in co-operation with Victoria Police executed a search warrant on premises in Brighton, Melbourne, connected to the administrator of an underground hacking forum, r00t-y0u.org, which had about 5000 members.

Many details of the investigation were revealed for the first time on Four Corners last night.

After the raid, the federal police covertly assumed control of the forum and began using it to gather evidence about members.

"We can operate in a covert activity here fairly seamlessly with no harm to our members with continual and actual significant penetration," Neil Gaughan, national manager of the federal police's High Tech Crimes Operation, told Four Corners.

However, what the federal police did not know was that hackers had already cottoned on to their plan.

Police were monitoring the forum by logging into the account of the administrator they had raided, but this aroused suspicion among members who knew the raid had taken place.

A hacker broke into the federal police's computer system and, according to a source close to the investigation, accessed both police evidence and intelligence about federal police systems such as its IP addresses.

A spokeswoman for the federal police confirmed that the hacker broke into a computer system used in its investigation but denied that any evidence was compromised, saying the computer was not connected to other federal police systems.

"The AFP has identified a person whom [sic] has attempted to access the stand-alone computer system and we are currently working with our law enforcement partners regarding this matter," the spokeswoman said.

The hacker appears to have been provoked by a message published on the r00t-y0u.org site by the federal police, warning members they were under surveillance and that "all member IP addresses have been logged", with some arrests having already been made.

In two provocative messages published on anonymous document-sharing site pastebin.com, the hacker slammed the federal police for "making it sound like they can bust 'hackers', when all they have done is busted a COUPLE script kiddies". "Script kiddies" is hacker parlance for novice hackers.

The second of these messages contained several links to screenshots allegedly proving that the writer had access to the federal police's server.

These included shots of files containing fake IDs and stolen credit card numbers, as well as the federal police's server information.

The hacker then defaced the r00t-y0u.org website with the same message it had posted on the anonymous document-sharing site.

The federal police spokeswoman said: "The information posted on the http://pastebin.com website is information contained on a stand-alone [federal police] system designed specifically to be used in investigations such as this.

"The information consists of directory file names of previously compromised credentials. No information or files exist that have, or could have, been compromised."

The hacker wrote "I couldn't stop laughing" on seeing that the federal police's server was running Windows, which is known among hacker communities for being insecure. Police had also "left the MYSQL password blank".

"These dipshits are using an automatic digital forensics and incident response tool," the hacker wrote.

"All of this [hacking] had been done within 30-40 minutes. Could of been faster if I didn't stop to laugh so much."

Shaon Diwakar, a security consultant at Hack Labs in Sydney, explained how the hack occurred.

"The attacker has discovered that the server didn't have a password for its database application and he has logged on ... and, using a technique called SQL injection, he created a PHP file on the disk and browsed through that PHP file to get complete control of that particular server," he said.

Diwakar said the hacker would have had access to anything that was stored on the computer.

"When they took this action they should have known that they would have been a big target, so they should have taken more precautions," he said.

The federal police said it had yet to charge anyone over the r00t-y0u.org forum bust, but "numerous items" were seized and the investigation was ongoing.

It declined to comment further on the case.

Monday, November 10, 2008

Sneakey

Few of us would care if our house keys appeared in a photograph of the family picnic posted on the internet.

But we should be concerned because advances in digital imaging and optics means any photograph of a key posed a potential security threat, Stefan Savage, a computer science professor at the University of California, warns.

Professor Savage and two of his PhD students have developed a software program called Sneakey that can clone a key in "two to three minutes" after analysing a digital photograph.

The algorithm is so sophisticated it easily copes with the low-resolution mobile phone images routinely posted on social networking sites such as MySpace and Facebook.

"The software looks at the key, adjusts the image for any rotations or distortions, then produces a string of numbers that is appropriate for that key," Professor Savage said.

"Those numbers are fed into a key-cutting machine and it makes a perfect copy.

Professor Savage, 39, said his team at the University's Jacobs School of Engineering in San Diego found "thousands" of images of keys inadvertently posted on the photo-sharing site Flickr.

They also used a camera fitted with a telephoto lens to photograph and duplicate a set of keys on a cafe table from a distance of more than 60 metres.

Far from being unique, the bumps and valleys on a conventional key can be "completely described" using a five- or six-digit number, he said.

"The design of the keys we use today is 150 years old and the world has changed."

As a result, Professor Savage believes we should protect our keys in the same way we protect the code to our debit card.

Sneakey runs on an ordinary personal computer and uses key-cutting hardware that is readily available in Australia.

The University of California team is keeping the code secret, but Professor Savage admits anyone with a basic knowledge of programming and computer vision techniques would be able to reproduce it.

He believes the "keyless" locking systems used on modern cars will eventually become the standard for all security applications. Until then, you might think twice before posing for a happy snap with your keys dangling from your belt.


.. from smh


Sunday, June 29, 2008


This is the Image Fulgurator, half guerrilla-art stunt and half homemade-gadget awesomeness.

Berlin based artist Julius von Bismarck uses his oddly named camera-mod to project images onto street furniture where they appear in the photos of strangers, but remain invisible to their eyes.

How?
It's simple. The device has a slave unit on top which is triggered when it sees a flash fire. This triggers his own flash, which fires through the back of the camera, through a film slide containing his slogan and then on and out through the lens at the front.

This works because a camera is pretty much a projector in reverse. And because the light-graffiti is fired at the exact same moment the unsuspecting victim takes a picture, it ends up in their photograph and paranoid mind ramblings result.

Sunday, June 01, 2008


What the CIA Learned From 'Get Smart'



Maxwell Smart always "missed it by that much," but some of those dopey spy shows of the '60s were right on the money. "Many of the devices first seen in movies and on TV actually came about," says Robert Wallace, former head of the CIA's covert skunk works, the Office of Technical Services.

"Remember the Cone of Silence? We built shielded enclosures that did the same thing. And the pen communicator in The Man From U.N.C.L.E.? That evolved, 10 years later, into short-range agent communication." Wallace, who was basically the agency's real-life Q, reveals these gadgets and more in his new book, Spycraft, the first comprehensive look at the technical achievements of American espionage from the 1940s to the present.

"Here's the laboratory," Wallace used to tell new recruits. "The only thing that is going to limit what you can do is your imagination." It seems they took him at his word.



1940's: Cigarette gun

Lipping this pistol disguised as a cigarette, an agent could easily release the safety pin. Rotating the filter end counterclockwise armed the gun, and a push of the thumb caused it to fire a single .22-caliber bullet. It really worked.




1940's: Combustible notebook

An ordinary-looking bound notebook contained pages of Pyrofilm and came packaged with an incendiary pencil. To prevent notes from falling into the wrong hands, an agent could simply pull the eraser out of the pencil, causing the notebook to burst into flames.



1960's: Acoustic kitty

During an hour-long procedure, techs embedded a 3/4-inch transmitter in the skull of a live cat. An antenna made of very fine wire was woven into the cat's fur, and a microphone was placed in its ear canal. After setting the kitty free, agents could listen in on nearby conversations undetected. Cats being cats, however, the system proved unreliable.



1970's: Rat concealment device

When it comes to a "dead drop" — a hiding place where spies leave messages — nothing's better (or deader) than a dead rat. Who's going to look inside unless they have to? CIA techs gutted a rat carcass, inserted secret missives wrapped in foil, and then stitched the animal back together. To ward off scavengers, the rodent was often doused in Tabasco.




1975: T-100 subminiature camera watch

A working Seiko timepiece concealed the world's smallest point-and-shoot camera. The device held a 15-inch strip of auto-advancing film and could snap about 100 crisp shots. A quick twist of the watch face revealed a 4-millimeter-diameter lens. It was a successful and widely used spy tool in its day.



1976: Insectothopter

A remotely piloted aerial vehicle disguised as a dragonfly could carry cameras and audio sensors right into the lion's den. This mobile eavesdropping bug never got off the ground.



Monday, May 19, 2008


Some nice Parkour videos..







Parkour (sometimes abbreviated to PK) or l'art du déplacement (English: the art of displacement) is an activity with the aim of moving from one point to another as efficiently and quickly as possible, using principally the abilities of the human body.

It is meant to help one overcome obstacles, which can be anything in the surrounding environment—from branches and rocks to rails and concrete walls—and can be practiced in both rural and urban areas. Parkour practitioners are referred to as traceurs, or traceuses for females.


Founded by David Belle in France, parkour focuses on practicing efficient movements to develop one's body and mind to be able to overcome obstacles in an emergency.



.. read more about Parkour at Wikipedia

Saturday, May 17, 2008

Parkour (free running) ~ first person jumper!



.. a great little video demonstrating the smooth & daring moves in the upcoming game 'Mirror's Edge'. Thegame, from EA DICE studio for Playstation 3, xbox 360 & windows-based PC's, is due to be released late 2008.

Sunday, May 11, 2008



Supercharge Your Canon Camera with Open-Source CHDK Firmware

Digital cameras have powers beyond what is immediately available to the user. On a standard Canon, for example, the fastest shutter speed option offered is 1/1,600 second, but the hardware can handle much more than that -- up to 1/60,000 of a second.

CHDK, the Canon Hacker's Development Kit, is an open-source software project that can be loaded on cameras using Canon's DIGIC II or DIGIC III firmware platforms. It unleashes new features including RAW file format, live histogram display, a battery readout, and the ability to run scripted actions on a camera.

CHDK does not replace the existing firmware on your Canon, so the process is completely reversible. The existing firmware stays intact, while the CHDK software is loaded on demand from an SD card.

  • Unlimited Interval Shooting -- Use your camera for surveillance, or use it to shoot at precise intervals during a lunar eclipse or meteor shower.
  • High-Speed Shutter -- Use this override option in the AllBest firmware to explore life's littler moments. You can also override the camera's slowest shutter speed settings to shoot exposures of a minute or longer.



.. continue reading article here
.. official wiki here

Monday, April 14, 2008

the flaneur

.. the deliberately aimless pedestrian, unencumbered by any obligation or sense of urgency, who wastes nothing, including his time which he spends with the leisurely discrimination of a gourmet, savoring the multiple flavours of his city.



.. wikipedia entry on the flaneur
.. further reading


Wednesday, March 05, 2008

Hack into a Windows PC - no password needed


A security consultant based in New Zealand has released a tool that can unlock Windows computers in seconds without the need for a password.

Adam Boileau first demonstrated the hack, which affects Windows XP computers but has not yet been tested with Windows Vista, at a security conference in Sydney in 2006, but Microsoft has yet to develop a fix.

Interviewed in ITRadio's Risky Business podcast, Boileau said the tool, released to the public today, could "unlock locked Windows machines or login without a password ... merely by plugging in your Firewire cable and running a command".

Boileau, a consultant with Immunity Inc., said he did not release the tool publicly in 2006 because "Microsoft was a little cagey about exactly whether Firewire memory access was a real security issue or not and we didn't want to cause any real trouble".

But now that a couple of years have passed and the issue has not resolved, Boileau decided to release the tool on his website.

To use the tool, hackers must connect a Linux-based computer to a Firewire port on the target machine. The machine is then tricked into allowing the attacking computer to have read and write access to its memory.

With full access to the memory, the tool can then modify Windows' password protection code, which is stored there, and render it ineffective.

Older desktop computers do not come equipped with Firewire ports, which are needed for the hack to work, but many recent models do. Most laptops made in the last few years include Firewire ports.

Paul Ducklin, head of technology for security firm Sophos, said the security hole found by Boileau was not a vulnerability or bug in the traditional sense, because the ability to use the Firewire port to access a computer's memory was actually a feature of Firewire.

"If you have a Firewire port, disable it when you aren't using it," Ducklin said.

"That way, if someone does plug into your port unexpectedly, your side of the Firewire link is dead, so they can't interact with your PC, legitimately or otherwise."

Ducklin also advised people to be careful when giving others physical access to their computer.

"I know people who'd think three times about asking passing strangers to take their photo in front of the Opera House in case they did a runner with the camera, yet who are much more casual with their laptop PC, as long as it's software-locked, even though the hardware alone is worth five times as much as the camera," he said.

Microsoft was unavailable for comment at the time of publication.



.. from smh

Sunday, December 30, 2007

How to make a teddy bear remote control
..


.. instructions here

Friday, December 28, 2007

Crazy Japanese experimental musical instruments

Wednesday, December 05, 2007

Brilliant Rube Golberg machines

Monday, October 15, 2007

click for full-size

Sunday, July 15, 2007


The Athens Affair


On 9 March 2005, a 38-year-old Greek electrical engineer named Costas Tsalikidis was found hanged in his Athens loft apartment, an apparent suicide. It would prove to be merely the first public news of a scandal that would roil Greece for months.

The next day, the prime minister of Greece was told that his cellphone was being bugged, as were those of the mayor of Athens and at least 100 other high-ranking dignitaries, including an employee of the U.S. embassy.

The victims were customers of Athens-based Vodafone-Panafon, generally known as Vodafone Greece, the country's largest cellular service provider; Tsalikidis was in charge of network planning at the company. A connection seemed obvious. Given the list of people and their positions at the time of the tapping, we can only imagine the sensitive political and diplomatic discussions, high-stakes business deals, or even marital indiscretions that may have been routinely overheard and, quite possibly, recorded.

Even before Tsalikidis's death, investigators had found rogue software installed on the Vodafone Greece phone network by parties unknown. Some extraordinarily knowledgeable people either penetrated the network from outside or subverted it from within, aided by an agent or mole. In either case, the software at the heart of the phone system, investigators later discovered, was reprogrammed with a finesse and sophistication rarely seen before or since.

A study of the Athens affair, surely the most bizarre and embarrassing scandal ever to engulf a major cellphone service provider, sheds considerable light on the measures networks can and should take to reduce their vulnerability to hackers and moles.

It's also a rare opportunity to get a glimpse of one of the most elusive of cybercrimes. Major network penetrations of any kind are exceedingly uncommon. They are hard to pull off, and equally hard to investigate.

Even among major criminal infiltrations, the Athens affair stands out because it may have involved state secrets, and it targeted individuals—a combination that, if it had ever occurred before, was not disclosed publicly. The most notorious penetration to compromise state secrets was that of the “Cuckoo's Egg,” a name bestowed by the wily network administrator who successfully pursued a German programmer in 1986. The programmer had been selling secrets about the U.S. Strategic Defense Initiative (“Star Wars”) to the Soviet KGB.

But unlike the Cuckoo's Egg, the Athens affair targeted the conversations of specific, highly placed government and military officials. Given the ease with which the conversations could have been recorded, it is generally believed that they were. But no one has found any recordings, and we don't know how many of the calls were recorded, or even listened to, by the perpetrators. Though the scope of the activity is to a large extent unknown, it's fair to say that no other computer crime on record has had the same potential for capturing information about affairs of state.


Wednesday, July 11, 2007

Mileage Runners hack air travel for maximum miles

Wired News has a great story today about "Mileage Runners" who tweak the airline reservation system to plot insane (and insanely cheap), multi-hop air trips that accumulate bazillions of air miles.


Odd Search