Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Saturday, March 16, 2013

Anonymous exposing presidential election vulnerabilities

I just found this neat artile on Tom's Hardware and figured it was interesting enogh to share:

Earlier this month, hactivist group Anonymous announced (PDF) that it helped put President Barack Obama back into office for another 4-year term by preventing Republican activist and Fox News anchor Karl Rove from electronically stealing votes from Obama supporters. The group claims that Rove somehow laid tunnels through voter tracking software that would have switched votes from Obama over to Romney in at least three states.

"We began following the digital traffic of one Karl Rove, a disrespecter of the Rule Of Law, knowing that he claimed to be Kingmaker while grifting vast wealth from barons who gladly handed him gold to anoint another King while looking the other way," the group said. "After a rather short time, we identified the digital structure of Karl's operation and even that of his ORCA."

Anonymous said that Rove "left the barn doors wide open", meaning the digital tunnels the Fox News anchor had supposedly established were left unsecured, granting any hacker easy access into the voter tracking system. Thus the group created what it called The Great Oz, a targeted password protected firewall to keep additional hackers, including Karl Rove, out.

"We placed this code on more than one of the digital tunnels and their destinations that Karl's not-so-smart worker bees planned to use on election night," they wrote. "We noticed that these tunnels were strategically placed to allow for tunnel rats to race to the server sewers from three different states. Ah yes, Karl tried to make it appear that there were more than three but we quickly saw the folly of his ploy."

Anonymous said that once the firewall was established, Karl's "speared ORCA whale was beached", as his team of supposed hackers, obviously hired to alter voting in Romney's favor, tried to penetrate the firewall and failed exactly 105 times.

"We have a warning for Karl," the group said. "Sail again at your peril. We may just put all the evidence into a tidy little package and give it to a painfully bored nemesis hanging out in a certain embassy in London."

The announcement claims that Rove's ORCA was discovered at 10am EST on November 6, and then speared by The Great Oz later on at 8pm EST. The group also hints to previously stolen elections which "resulted in terrible destruction across the globe", thus provoking the group into following Rove's data trail. The Examiner also points out that Ohio suffered server problems on November 6 at around 11pm, mirroring an identical situation in Ohio that took place in 2004.

While we won't jump into politics, the claim made by Anonymous poses a good question: can the system used to track votes be fully trusted in an age where servers and firewalls are breached seemingly every week, exposing sensitive data owned by companies and individuals? And if the Anonymous story is true, then how did Rove get into the system and install his pipeline? Did someone give him access or was this an actual hack?
Something tells us that we'll find out soon enough.

--
Here is the original article for anyone interested 

Wednesday, August 22, 2012

Settled on Astrill as my VPN service

For a while I have been looking into different ways to gain a bit more privacy while online. I love the internet, and I do think it is the greatest invention of the 20th century, however, political parties and their archaic outlook on new technologies, slows down the natural progress of it. One of the main problems with the internet is privacy. Laws have not been evolving as quickly as the community, so a lot of them are outdated and infringe on basic freedoms already achieved in the real world. For that reason, I have decided that investing a little bit on a VPN service would be worthwhile.

I did a fair bit of research, and ended up settling on Astrill. I looked at a lot of different services, and as a package I think Astrill's service really suited my needs. One of the other contenders was "Hide my ass", which seems to be one of the most popular services out there. Indeed it was one of the ones I was most interested in. However, HMA made big news at one point when the folks from lulzSec got caught. Apparently HMA did provide authorities with logs that gave away a lot of vital information about its members. So entirely due to principles, in this case being that it makes no sense to pay a fee for privacy, if privacy is not really garanteed. It's not like LulzSec killed anyone.

The other big contender was Strong VPN, which I almost signed up with before I had done more reading. Their prices seem fair, and they do have a lot of options in terms of where their servers are, however, I really was looking for a service that included servers in different countries, freedom to switch servers frequently, the ability to connect via PPTP or OpenVPN. At Strong VPN, the ability to have all those things would cost me quite a lot, so I decided to go with Astrill. They offered pretty much all I wanted for a decent price if you do at least a 3 month contract.

The installation in Ubuntu as well as Windows 7 was easy. On Ubuntu you may need to download OpneVPN through apt-get, but after that you just click to download a small client. Windows just requires the client. I'll use it during the next few months, and I'll post if I encounter any problems.

Tuesday, August 21, 2012

PPTP, OpenVPN, IPSec and L2TP - What's the difference?

I have recently started to look into VPN services to enhance my privacy while using the interwebs. One thing that started to confuse me pretty quickly was the variety of different servers available, and honestly it took me a while to start to understand what the differences are. Well to make this process simpler for other people, here is a nice short summary from zzing123, which was posed at "perfect-privacy.com forum.


On a general level, PPTP was invented by Microsoft as a VPN that could be used with dialup, and is far older than OpenVPN, and as such is practically available from any device that supports a VPN of some description. That and the fact it's easy to use are really the only reasons it's used. In terms of security it's basically crap: at best it uses 128 bit encryption with an RC4 handshake (Handshake is the authentication/login process for setting up the VPN). At worst, 64 bit encryption and a plain-text handshake (so it wouldn't even take 2 weeks: just read the packet!). Naturally, PP uses the better sort.

OpenVPN is - in this league - very new technology. It's basically the amalgamation of several technologies, like SSH, Stunnel, OpenSSL's encryption libraries all of which provide unix with best of breed power and together form OVPN, a best of breed VPN. OVPN allows you to choose the method and algorithm for handshaking as well as for data encryption, plus uses SSL certificates, PSK's or User/Pass (or a combination of) to authenticate clients on top of that. With hardware acceleration, OVPN is easily faster than PPTP. Without acceleration, it's entirely dependent on the algorithms chosen - Blowfish is designed to be the fastest software-only algorithm, so OVPN would be a lot faster than PPTP. Encumbered with a software AES-256 implementation, and PPTP's 128 bit encryption is faster. This ultimate configurability is also OVPN's downfall: it's pretty complicated to set up.

With PP's OVPN service, ideally they should provide a client.crt and client.key unique to every customer, instead of using the auth-user-pass directive for ultimate security, but management of these keys becomes a nightmare. That said PP uses RSA 4096-bit encryption for the handshake and AES-256 for data, which are probably the two most secure algorithms you can use currently in OVPN.

There is also a third technology: L2TP / IPSec. L2TP provides the layer 2 tunnel, and IPSec the encryption, and was invented by Cisco to bridge 2 networks together. IPSec uses either RSA or a Pre-Shared Key (PSK) for the handshake, which uses Diffie-Hellman hashing over and above that. For data, it can use 3DES, DES, Blowfish, AES and CAST-128. IPSec does have pretty good support in clients and is widely regarded as being PPTP sorted out. Because Cisco developed it to sell more routers, a lot of expensive network gear has IPSec support built in, meaning that if you have very expensive network kit using IPSec, your VPN's will be so fast there's practically no latency overhead. Software implementations are as fast as PPTP.

So in summary:
- Choose PPTP: If you want an albeit crusty VPN technology available everywhere
- Choose OVPN: If you want the most powerful, secure and modern VPN
- Choose IPSec/L2TP: If you want high performance between two sites

Monday, October 3, 2011

Anonymous Message - OIWS

After nearly one week of protesting in Wall Street and other areas of the US, it seems that the media is finally unable to ignore the slowly growing movement happening right in their own backyards. The Occupy Wall Street protests have been happening, and including quite a bit of police abusing their power and in some cases even brutality to silence the emerging movement, which seeks to awake America to corporate greed and social injustice that has occurred for a while now, causing the 2008 recession and everything that followed. Personally I've been very frustrated with the lack of repercussion to the disgusting practices of financial institutions, and the seeming nonexistent response from Americans to white collar crimes happening right in front of their eyes. Well, it seems that we may finally see something happen, as broadcasting stations are beginning to show what has been happening and celebrities like Michael Moore have started to get involved. I'm not a big fan of Michael Moore, but I am happy to see support from people of influence. Just now I have also discovered that the hacking group ANONYMOUS will also be launching an attack on Wall Street on Oct 10th, here is their message to the people:



This should be interesting.

They have also sent the following message to the media:

Greetings, Institutions of the Media.
We are Anonymous.
The events transpiring within Wall Street have caught our eye.

It seems that the government and Federal agencies enjoy enforcing the law a little bit too much. They instate unjust laws as mindless automatons, blindly following orders with soulless precision.
We witness the Government enforcing the laws that punish the 99% while allowing the 1% to escape justice, unharmed, for their crimes against the people.
We have observed this same Government failing to enforce even the minimal legal restraints of Wall Street's abuses. This Government who has willingly ignored the greed at Wall Street has even bailed out the perpetrators that have caused our crisis.
We will not stand by and watch the system take over our way of life.
We the people shall stand against the government's inaction.
We the people will not be witnesses to your corruption and ill gotten profits.
We will not labor for your leisure.
We will not assist you in any way.

This is why we choose to declare our war against the New York Stock Exchange. We can no longer stay silent as the population is being exploited and forced to make sacrifices in the name of profit.
We will show the world that we are true to our word. On October 10th, NYSE shall be erased from the Internet. On October 10th, expect a day that will never, ever, be forgotten.

Vox Populi, Vox Anon.
The Voice of The People is The Voice of Anonymous.
We are Legion. We are the 99%.
We do not forgive. We do not forget.
Wall Street: Expect us.

Wednesday, August 3, 2011

Bandwidth test: Rogers (Toronto)

Hello, this is just a small post I figured might be useful for someone maybe. I just tested my Rogers internet connection and figured I would share with the interwebs in case people are curious about Rogers. I live in Toronto and I have the "ROGERS express internet" which is supposed to get up to 12Mbps download and 512Kbps upload with 60Gb of monthly bandwidth.

I tested this at 10:15AM on a Wednesday:
9.96Mbps download
505knps upload

 Wed/18:04 - 10.5M/490K
Wed/18:29 - 5.0M/503K
Tue/09:10 - 7.2M/499K

I'm using a cable so no wifi interference here. Just for kicks I also tested my neighbors wifi which is Bell and got:
414kbps download
372kbps upload

I'm curious to know how come I get such good upload speed on their wifi in proportion to my numbers, I wonder if it has anything to do with the fact the wifi signal is not 100%

jsyk I tested my connection using bandwidthplace.com

Friday, July 15, 2011

New antivirus and anti-malware

After some significant frustrations with my computer in recent days I decided to looks for different ways to protect my machine. I was basically using Norton Antivirus and just whatever comes with windows in terms of firewall and stuff.

 On my desktop now I have been running Microsoft Security Essentials and I have had a good experience so far. I is only using 2.1k of memory compared to the 15k I was using with NAV.

http://download.cnet.com/Microsoft-Security-Essentials/3000-2239_4-10969260.html
http://www.microsoft.com/en-ca/security_essentials/default.aspx

I am now also using malwarebytes to get rid of unwanted malware that isn't picked up by MSE. This is a great little program, that you can use for free if you get a version without live protection. It's not a big deal to use the free version as long as you do regular scans imo.

http://www.malwarebytes.org/

Lastly, I've also been using the Microsoft Safety Scanner on a weekly/biweekly basis. It is a backup way to look for unwanted software and scripts. It helps remove viruses, spyware and other malicious software in conjunction with the AV. It works similarly to malwarebytes, where you have to do scheduled scans, but I've had quite a bit of success using it to get rid of some of those really really annoying ad-wares. Here is where you can pick up a free copy:

http://www.microsoft.com/security/scanner/en-us/default.aspx


*note that this one is updated often, and the software expires in 10 days since it will be outdated already by then. I tend to use this one twice a month or so.

Friday, June 3, 2011

Hackers R Us

There have been a lot of hacker attacks in the news lately, it seems like it's happening more and more frequently now due to an increase in the number of hackers and interest in these services from advertiser and marketing people around the world. We do after all live in the age of information and information is money. Sony was one of the bigger attacks recently, causing PSN to shut down for a while and costing the company a huge stain in their image as well as millions in law suits. Now I hear Honda Canada has just been attacked as well, and I'm not even mentioning Air Miles and all the other North American databases that have had their networks breached for customer data. So what can companies and customers do to prevent being victims of these crimes?

I have been hearing about the end of human biological evolution for a while now. It is believed that biological evolution is too slow to compete with the technological evolution that humans have been experiencing for the past centuries. The mechanics of this evolution in this age of information is way too complex and fast for nations to overlook and control. Networks are faster and more integrated then ever and the trend is not changing anytime soon, and just like copyright issues we've been seeing for a while, privacy is going to continue to be a major area of discussion in the future years. These are issues that will not be countered by governments fast enough and the ignorance of people in these matters will eventually cause one of two things. Governments will enforce much more regulation on networks then necessary just to prevent issues such as these to propagate, or they will attempt to educate people more about vulnerabilities and corporations will eventually see that more attention needs to be paid to hacking and data theft.

I'm not a hacker, but I do find a lot of what hackers do fascinating. For years I've been learning just how vulnerable we really are to people that want to people with knowledge of networks and computers. The best thing to do at this point is to play safe, corporations should not be storing unneeded information and they should invest more in network security. In the end the consumers pay part of the price and companies are damaged as well. More and more technologies like this will be areas heavily explored for crimes and I am still waiting to see a digital act of terrorism. Unfortunately, much like flying nowadays, the Internet may very well be changed for the worst with cyber terrorism, this may be inevitable however.