Tuesday, November 27, 2007

Project 3





Watching TV series isn’t my thing. I can’t believe that I didn’t fall asleep while watching this. Maybe it was because we were allowed to critique the parts in the video that were related with computers. It is funny seeing how some video makers exaggerate what technology can do (in that time).

There are some parts of the video which I found interesting. First of which is the part when they have already have the victim’s laptop and they were trying to view the contents of that laptop. First of all, the video was made on 2002, operating systems already implemented “User Logins”. Computer users are required to give a password in order to use the computer, unless it was set to none, but if they said that the computer contained important information, why wouldn’t the owner put a password? Assuming that the owner set a password, it would be hard for them to guess that password or even crack it because they only would have 1 input box for the password and no place where they can type in commands for them to crack in the system. It may still be possible if they have tried several passwords (brute force).

When they opened the laptop and looked at the files, they found that a file was accessed after the victim was killed. For me, the file access timestamp is not that reliable because you can “cheat” it. You can do this by changing the system time and date, then that date and time will be the one used by the system for the timestamp.

The next thing that I found interesting was when the IT girl said that passwords can be easily cracked. My first reaction was, I don’t think so. Not all passwords can be cracked easily, that’s why encryption, and hashing were made so that hackers can’t read passwords in plain text. But if she was referring to the password protection of files like Microsoft Office Documents (*.doc), yes it can be easily cracked, there are a lot of software out there that does this for you and I have tried a couple of them.

It was also mentioned in the movie that deleted files can be retrieved. This thing is true, files are a linked list, and we know how a linked list works. When a file is deleted, the address of the head of the file deleted is forgotten so that the file will be “lost”. If you’ll be able to find the head, you’ll be able to access the deleted file, that is, if the user of the computer isn’t fond of saving big amounts of data all the time which may have overwritten parts of “lost/deleted” files. But this can be said false if the user of the computer used a file shredder.

Another interesting part was when the IT expert discussed how the bad guy knew what the victim was doing in her computer. The IT expert mentioned that it was because of a worm that she opened from her email. At first, I felt that this idea was preposterous because I haven’t encountered a virus that bad, not even something close to that, and second, if that kind of virus was made, and it spread to billions of computers, imagine how much computers the hackers would be able to watch, but for what? I bet that a big percentage of the ones that they can access wont give helpful information. But if the virus was made specifically for her, it can be possible. There are a lot of programs wherein you can watch/control remote computers like VNC and NetOP, if a program can do it, why not a virus? A virus is still a program.

Next thing that they mentioned was, there were not much laws that they can use against the bad guy. I believe that this is true, specially here in the Philippines.

Another thing that they said was they could trace email through the header of the email. This is something that is true, when you read the header of emails, you will see there the IP address of the sender, IP of the recipient, and also the servers & routers where the email passed in order to get from the source to the destination. This thing can still be cheated IF a machine was programmed to do so, whenever a hop is made, that machine adds its identity in the header, that machine if maliciously programmed, can change everything in the header so that it will be impossible to trace the source, but things like these can be easily detected because of discrepancies in the “hops”, time, etc.

It was also mentioned that a deleted email can still be read, I think that it depends on how the system is implemented. If it was really deleted from the disk (cut the link to the head of file), there is a high chance that the email may have been overwritten specially if that server has a lot of users (incoming of mail may have overwritten the deleted mail) but there is still a chance that the mail is still preserved in the disk. But if she was referring to Delete and send to Trash, of course it can be easily found.

Lastly, a company that steals information. When they showed the office of that company, I didn’t believe it at all. First of all, before you can put up a company, the government should approve it, do you think that the government would allow something like that? I think that a lot of underground things like this happens but not like how they showed it in the video. Also, I believe that the US government has their own group of information stealers.

All in all, I think that that episode was well thought of.






Wednesday, November 21, 2007

Piracy ulit..

I've been thinking about the "ways to avoid piracy"

- broken bit
- physical hardware
- online activation

how can this be cheated?
-broken bit, if a copying machine was used (not pc+nero but bit by bit copying) of course that broken bit will be copied because that machine doesnt care if that is an error unlike a computer that will stop copying because it sees an error

-physical hardware, if you know what's needed to be sent by that hardware, you can make it yourself, i bet it's still cheaper

-online activation, point their servers address to a server that you setup(f you know the data being sent by their servers to activate your software)

but i remembered the ps2.. i asked sir jade pabico how sony's anti piracy works, because even if you copy the cd bit by bit, it still doesnt work, he said that it might be the cd/dvd's serial number, sony may have had reserved a range of serial numbers, and then if the ps2 reads that the cd/dvd is within that range, then it should run..

i just dont know if you can cheat that serial number

Wednesday, November 14, 2007

Licensed software..

I went to national bookstore a while ago.. and when i was at the counter paying, i saw something sticking out in the cash register, it was laminated.. they photocopied that cash register's windows license

Windows 98
Genuine License
For distribution with a new pc

I just laughed, i wanted to look at the other cash registers if they had the same photocopied license but people might think i'm weird if i go from one cash register to another and look at that laminated paper.

by seeing that, i just realized that big establishments are really the target of the "anti-piracy team"..or else they wouldnt have placed that in their counters.. but a photocopied license? would that make them more questionable rather than not exposing the license unless when they were asked?

Sunday, November 4, 2007

Spam? or Not?

-----Original Message-----
From: encarnacionadlsc
Sent: Tuesday, October 23, 2007 2:37am
To: ManTech-07-08-2@yahoogroups.com
Subject: [ManTech-07-08-2] Is this spam or not?

Below is an actual email I received this Monday. The question is, is
it spam or not? It is one of the things we'll discuss next lecture.
Don't forget to post on your blogs from last lecture.

P.S. I suggest you don't reply to the email below.

From: "lehcir_21" <lehcir_21@yahoo.com.ph> Add to Address Book
Add Mobile Alert
To: "testwynnewynne" <testing@ph.mensa.org>
Subject: call center vacancy
Date: Mon, 22 Oct 2007 16:49:49 +0800

Call center operator
JHC Inc is looking for intelligent people for this position ready
for a
career growth and hardworking.
Requirements:
- FULL TIME JOB ONLY
- Computer with broadband Internet access (Ability to be online
frequently ).
- Adult people only! (21 plus).
- Solid communication skills.
- Aggressive and insensitive persuasion skills must be as an
advantage
- Working experience in HR management and Call center area are
greeted
Salary:
$200/week
Annual bonuses
Please direct your resumes to blefeb4128aw@hotmail.com

SPAM! Well, my blog isnt about that email. I wanted to talk about an experience of mine with this spam sh*t. I maintain a website with its own mail server, I was paying for that server to run so i had the right to use it by myself (or at least the one with my name). One time, i just got surprised that all the emails that i would send to people using yahoo mail, would go to their spam folder. I soon found out that my mail server wasnt set to require a valid username & password in order to send an email, meaning anyone who accesses it can send an email with the address of the server on it. So i reported it to yahoo and my hosting and they fixed it right away.

DO NOT TRY THIS AT HOME!

one time, nangtrip lang ako sa isang kaibigan. using php's mail function, you can send an email. and by changing the parameters that you put in that function, the contents of the mail will change, including the "sender". So i used my friends email as the "sender" and sent an email to his email, he thought that i got in his mailbox. I just wanted to point out that an email can be spoofed, even if you know that email, it doesnt necessarily mean that it really came from that person/server.. one thing that you can do is to look at the header and check the first hop, then ex, sender:email@yahoo.com, get the ip address of yahoo.com's mail server and compare it to the address of the computer in the first hop..but of course you dont have to do this everytime..I am not "yahoo.com" but i was able to send an email with "email@yahoo.com" using my server..


Wednesday, October 24, 2007

Just a thought on hashing..

Hashing is a really powerful tool that can be used to hide data such as passwords.. Hashing is one way, meaning once you hash it, you can't derive the original word from the hashed word. People might ask why hash it if it can't be brought back? Hashing can really be a good tool for passwords, people may have 1 password for all his/her accounts so if someone gets in the database and sees the password, he might be able to access that person's other accounts (bank, email, etc).. that is why passwords are hashed, then how can you compare a hashed password to a not hashed one? It's simple, just hash the "not hashed one" with the hashing that you used in the "hashed one", then compare the 2, if is equal then the password is correct.

I believe that hashing is really one way..because of the algorithm that it uses, but there is one thing that can "cheat" that. Lets say a password is from 6-10 characters long, so create a script that hashes and saved all possible combinations from 6 characters - 10 characters in a table

ex

Table hashtable

normal hashed(SHA1)
000001 0a620481ca00b00de7eedb407a68b9163dcabae3
000002 86dfb043360b0e9ef7767e6ea7ad09fb7fb81537
... ...
... ...
... ...
d3nn1s 7b7edb6fda80187ac8a3f18b2c2b9bfef7a95acc
... ...
ZZZZZZZZZX 3ae4c15d5da68511a49a6171d0df2f7e51207fa6
ZZZZZZZZZY 27fb26c695b91422e048b7ccd2557209472d7fbc
ZZZZZZZZZZ 5df31df13a3fe267e1ae0a35f71bdc70b0249d35

and if your script saved all these in a table, just search for example..

SELECT normal
FROM hashtable
WHERE hashed="7b7edb6fda80187ac8a3f18b2c2b9bfef7a95acc";

by that, you will surely get the reverse of that hashed word..which is d3nn1s, also, hash functions have a fixed length

MD4 = 32 characters
SHA1 = 40 characters

so it gives you a big clue on what hash function was used..unless if you do character stuffing..
and it is also a proof that hasing is one way (before the brute force), for example you hash this string using SHA1 "ang mantech na subject ay napakasayasayasayasayasaya talaga!", the result would be "5df31df13a3fe267e1ae0a35f71bdc70b0249d35", obviously, the string that you used is longer than 40 characters, and the end result is only 40 characters, so how can you derive a combination of 60 characters from 40 characters..it can only be done by "brute force" (hashtable)

Sunday, October 7, 2007

Attack!

The videos that were shown during our class were very interesting for me because creating web based programs is something that I do and the topics that were discussed in the videos were mostly on web based programs.

I have heard of SQL injection before but I didn't know how much things an attacker can do using SQL injection. For me, there are many ways on how to prevent this, or at least minimize the damage (if ever an attack happens).
  • the most basic thing to do is to create a separate user with limited privileges which the web application will use (only the privileges that the application will need, no more) so that if an attack like DROP TABLES is used, the command wont work, unless a drop privilege is given to that user.
  • Second, to avoid getting information about/from your database from a public page, don't put a code that would print information that your database server returns, because if you do that, and an attacker discovers that he/she can inject an sql code, that page would be like a sql client for him/her.
  • This I think is the safest but i think is not practical (last resort), when getting information from forms, encrypt it before connecting it to the sql code, because if you put a textbox on a page and will directly use the string that will be typed in the text box and will put that in your sql code, a hacker can easily inject a code. Surely, when the information from a form is encrypted before inserting that into the code, an attack would be almost impossible but it is impractical because when you view the contents of the database, it will all be encrypted.
Second, I didn't expect that Javascript can be harmful to a web based system. First of all, javascript is only client side and the code does not run on the server, but i didn't think that it can be used to extract cookies from a client, and use that cookie to appear as if you were that person from whom you stole that cookie from.

Lastly, the thing that the guy from microsoft discussed about the attack on IIS, I think that this is really a problem when running a web server on winows. You can easily access files even from other folders by using "../", so if you use the "../" and know the folders of that server, you can traverse the folders of that server and steal some files. I think that this is not applicable in linux, in linux, you can set the permissions of folders. So if you plan to run your own web server, use linux :)

Wednesday, October 3, 2007

Taking advantage..

Viruses for me are okay. I think that this is the fault of software makers. Viruses can be made by people who know a flaw/bug in a software. If this flaw/bug is not fixed, people can do something and take advantage of that flaw/bug.

It is like leaving a 500 peso bill on the ground, surely someone see it and someone would pick that up. Same with these softwares, if you leave a hole open, in time, people will discover these holes and someone would also create something that can take advantage of that hole... So.. if in time, it will be discovered, I believe that viruses are just one of the ways to speed up the discovery of the bug, and is a great reason why they should fix it right away, thanks to the people who make them.

I think that it is one of the responsibilities of computer users to protect themselves from these viruses.