<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>TekBoss &#187; Security</title>
	<atom:link href="http://www.tekboss.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tekboss.com</link>
	<description></description>
	<lastBuildDate>Thu, 27 Aug 2009 16:52:54 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Hacking with JavaScript</title>
		<link>http://www.tekboss.com/2009/08/hacking-with-javascript/</link>
		<comments>http://www.tekboss.com/2009/08/hacking-with-javascript/#comments</comments>
		<pubDate>Wed, 26 Aug 2009 23:40:15 +0000</pubDate>
		<dc:creator>System Administrator</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Advantage]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Moment Of Truth]]></category>

		<guid isPermaLink="false">http://www.tekboss.com/2009/08/hacking-with-javascript/</guid>
		<description><![CDATA[
SIMPLE HTML FORMS1. Bypassing Required FieldsSurely you have met a webpage that requires you to fill all fields in a form in order to submit it. It is possible to bypass these types of restrictions on any webpage. If you take a look at the webpage&#8217;s source and follow it down to the form&#8217;s code, [...]]]></description>
			<content:encoded><![CDATA[<div style="float:left; padding: 12px"><a href="/wp-content/uploads/2009/08/hacking37.jpg"><img src="/wp-content/uploads/2009/08/hacking37.jpg" title='' alt='' /></a></div>
<div>SIMPLE HTML FORMS<br/><br/>1. Bypassing Required Fields<br/><br/>Surely you have met a webpage that requires you to fill all fields in a form in order to submit it. It is possible to bypass these types of restrictions on any webpage. If you take a look at the webpage&#8217;s source and follow it down to the form&#8217;s code, you will notice the onsubmit form attribute. Hopefully by this time you have experienced the power of javascript and you know that javascript has control over every single element in a webpage, including forms.We can use javascript to our advantage in every page we view for we can modify, delete, or add any element to the webpage. In this case we wish to clear the form&#8217;s onsubmit attribute in order for the form to be submitted successfully.<br/><br/>The onsubmit attribute generally points to a function that checks the form to have the correct format.  A function that does this may look something like this:<br/><br/>function formSubmit(x)<br/><br/>{<br/><br/>if(x.email.value==&#8221;") return false;<br/><br/>return true;<br/><br/>}<br/><br/>&#8230;<br/><br/><br />
<form method=post action="process.php" onsubmit="return formSubmit(this);"><br/><br/>&#8230;<br/><br/></form>
<p><br/><br/>I will not go into great detail about how the formSubmit function works. You should know that if the (textfield/optionfield/option/..) field is left blank, the form will not be submitted to process.php. Now comes the moment of truth, how do we modify the form so that onsubmit returns true everytime? The way we can access the form with javascript and do this is:<br/><br/>document.forms[x].onsubmit=&#8221;return true;&#8221;;<br/><br/>or<br/><br/>document.spamform.onsubmit=&#8221;return true;&#8221;;<br/><br/>Both of these &#8216;queries&#8217; will allow you to submit the form free of restrictions.  The secret is how to execute this.  I do this using my browser&#8217;s Location bar. All you have to do is enter this text into the location bar and press enter:<br/><br/>[removed]document.spamform.onsubmit=&#8221;return true;&#8221;;<br/><br/>The above statement will not work because the &#8216;query&#8217; will return a value javascript doesn&#8217;t know what to do with it so it dumps the returned value on the screen. We need a way to use this value and escape it from passing on to javascript. I know the exact way to do this, with alert&#40;&#41;!<br/><br/>[removed]alert&#40;document.spamform.onsubmit=&#8221;return true;&#8221;&#41;;<br/><br/>You will see an alertbox with &#8220;return true;&#8221; instead of dumping this value out to the webbrowser. Once you have executed this query you will be able to enter whatever value into whatever field in spamform.<br/><br/><strong>Full Article: Hacking with Javascript</strong><br/><br/><br/><br/><em>By: <strong>sandya</strong></em><br/><br/><strong>About the Author:</strong>
<div style="border: thin solid gray; background-color: #E2E089; padding:1em;">
<p>Learning from Conversations&#8230;</p>
</div>
<p><br/><br/></div>
]]></content:encoded>
			<wfw:commentRss>http://www.tekboss.com/2009/08/hacking-with-javascript/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Several Millions of Bank Cards Have Been Hacked</title>
		<link>http://www.tekboss.com/2009/08/several-millions-of-bank-cards-have-been-hacked/</link>
		<comments>http://www.tekboss.com/2009/08/several-millions-of-bank-cards-have-been-hacked/#comments</comments>
		<pubDate>Sat, 15 Aug 2009 10:11:13 +0000</pubDate>
		<dc:creator>System Administrator</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Bank Cards]]></category>
		<category><![CDATA[Heartland]]></category>
		<category><![CDATA[Scotland Group]]></category>

		<guid isPermaLink="false">http://www.tekboss.com/2009/08/several-millions-of-bank-cards-have-been-hacked/</guid>
		<description><![CDATA[
The largest card swindle in the world done by unknown hackers.TJX hackers have lost their doubtful record for data break-in involving card data. Then around 45 million cards were involved.The American bank-credit card payment system company called Heartland has had unwanted visitors in their systems. Heartland is the largest US company within payment systems.Malicious software [...]]]></description>
			<content:encoded><![CDATA[<div style="float:left; padding: 12px"><a href="/wp-content/uploads/2009/08/hacking43.jpg"><img src="/wp-content/uploads/2009/08/hacking43.jpg" title='' alt='' /></a></div>
<div>The largest card swindle in the world done by unknown hackers.<br/><br/>TJX hackers have lost their doubtful record for data break-in involving card data. Then around 45 million cards were involved.<br/><br/>The American bank-credit card payment system company called Heartland has had unwanted visitors in their systems. Heartland is the largest US company within payment systems.<br/><br/>Malicious software has been planted in their systems to sniff card data. Visa and Mastercard reported suspicious activities in their systems and a research was performed and revealed a global effect of this break in.</p>
<p><br/><br/>It is not certain for how long the hackers have been in their systems and collected data.</p>
<p><br/><br/>There is not a certainty to what data the sniffer software has been looking for, but Heartland ensure that no personal information like social security codes, nor addresses or phone numbers have been taken out of their systems. But most likely the hackers have been looking for the track-2 data, which is the information from the magnetic stripe on the cards.</p>
<p><br/><br/>Heartland treats over 100 million transactions every month and this seems therefore to be the largest scam ever done on card thefts.</p>
<p><br/><br/>This means that more that 45 million cards are exposed to this theft.</p>
<p><br/><br/>CardCops reports that there are rumors in the underground that a huge break in has been performed in a company like Heartland.</p>
<p><br/><br/>In addition there has been a 20% increase in activities the hackers utilize to check whether the cards are working or not. They perform small transactions to charity organizations. December 23rd 2008 RBS Worldpay reported on behalf of The Royal Scotland Group that they have also had a break in to their systems. Around 1.5 million cards were leaked this time.</p>
<p><br/><br/>To attack companies like this is more serious than doing a break in to a store as these companies are the nerve centers in any payment transaction through out the world.</p>
<p><br/><br/>Drastic measures have to be taken in order to capture these hackers and at the same time make systems more bullet proof in the future.<br/><br/><br/><br/><em>By: <strong>Stig Kristoffersen</strong></em><br/><br/><strong>About the Author:</strong>
<div style="border: thin solid gray; background-color: #E2E089; padding:1em;">
<p>He has a background as civil engineer and geoscientist. He has worked mainly within the oil and gas industry from the mid 1980s. He has written a few fictional novels as well as being the author of some professional litterature within oil and gas sector, he is now an editor of some web sites.</p>
</div>
<p><br/><br/></div>
]]></content:encoded>
			<wfw:commentRss>http://www.tekboss.com/2009/08/several-millions-of-bank-cards-have-been-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Ethical Hacking?</title>
		<link>http://www.tekboss.com/2009/08/what-is-ethical-hacking-3/</link>
		<comments>http://www.tekboss.com/2009/08/what-is-ethical-hacking-3/#comments</comments>
		<pubDate>Thu, 13 Aug 2009 04:22:50 +0000</pubDate>
		<dc:creator>System Administrator</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Binding Contract]]></category>
		<category><![CDATA[Computer System]]></category>
		<category><![CDATA[Felony]]></category>

		<guid isPermaLink="false">http://www.tekboss.com/2009/08/what-is-ethical-hacking-3/</guid>
		<description><![CDATA[
An Ethical Hacker is an expert hired by a company to attempt to attack their network and computer system the same way a hacker would. Ethical Hackers use the same techniques and tactics as those used by illegal hackers to breach corporate security systems. The end result is the company’s ability to prevent an intrusion [...]]]></description>
			<content:encoded><![CDATA[<div style="float:left; padding: 12px"><a href="/wp-content/uploads/2009/08/hacking21.jpg"><img src="/wp-content/uploads/2009/08/hacking21.jpg" title='' alt='' /></a></div>
<div>An Ethical Hacker is an expert hired by a company to attempt to attack their network and computer system the same way a hacker would. Ethical Hackers use the same techniques and tactics as those used by illegal hackers to breach corporate security systems. The end result is the company’s ability to prevent an intrusion before it ever occurs.<br/><br/>A company can’t know if their security system is solid unless they test it. It’s hard, though, for a company’s IT team to thoroughly ring out the system. Try as they might, the techs can’t go at the system with all the malicious or mischievous motives of a true illegal hacker. To thoroughly uncover vulnerabilities, the theory goes; you must examine your security system through the eyes of an illegal hacker.<br/><br/>The word hacking has strongly negative connotations, and, for the most part, rightly so. But ethical hacking is much different. It takes place with the explicit permission of the company whose system is being attacked. In fact, their “good guy” role is underscored by the nickname “white hat” Ethical Hackers have been given. The nickname is a throwback to old Westerns where the good cowboys could be identified by their white hats.<br/><br/>The company and the Ethical Hacker enter into a legally binding contract. The contract, sometimes called a “get out of jail free card,” sets forth the parameters of the testing. It’s called the “get out of jail free card” because it’s what harbors the Ethical Hacker from prosecution. Hacking is a felony, and a serious one at that. The terms of the agreement are what transform illegal behavior into a legal and legitimate occupation.<br/><br/>Once the hacker has exhausted his attempts, he reports back to the company with a list of the vulnerabilities he uncovered. The list in and of itself, however, is not particularly useful. What’s most valuable is the instructions for eliminating the vulnerabilities that the Ethical Hacker provides.<br/><br/>An Ethical Hacker works to uncover three key pieces of information. First, he determines what information an illegal hacker can gain access to. Next, he explores what an illegal hacker could do with that information once gained. Last, the Ethical Hacker ascertains whether an employee or staff member would be alerted to the break-in, successful or not.<br/><br/>At first it might sound strange that a company would pay someone to try to break into their system. Ethical hacking, though, makes a lot of sense, and it is a concept companies have been employing for years. To test the effectiveness and quality of product, we subject it to the worst case scenario. The safety testing performed by car manufacturers is a good example. Current regulatory requirements including HIPAA, Sarbanes Oxley, and SB-1386 and BS 799 require a trusted third party to check that systems are secure.<br/><br/>In order to get the most out of the assessment, a company should decide in advance the nature of the vulnerabilities they’re most concerned with. Specifically, the company should determine which information they want to keep protected and what they’re concerned would happen if the information was retrieved by an illegal hacker.<br/><br/>Companies should thoroughly assess the qualifications and background of any Ethical Hacker they are considering hiring. This individual will be privy to highly sensitive information. Total honesty and integrity is of the utmost importance.<br/><br/><br/><br/><em>By: <strong>Paul Walsh</strong></em><br/><br/><strong>About the Author:</strong>
<div style="border: thin solid gray; background-color: #E2E089; padding:1em;">
<p>Paul Walsh, of <a href="http://www.protocolsolutions.co.uk" target="_blank">www.protocolsolutions.co.uk</a> asks the scariest question out there: Think your network is safe from malicious attack? Find out for sure – a quick, complimentary chat will help you sleep better. 
</p>
</div>
<p><br/><br/></div>
]]></content:encoded>
			<wfw:commentRss>http://www.tekboss.com/2009/08/what-is-ethical-hacking-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Behind Enemy Lines &#8211; How Exactly do hackers hack a computer?</title>
		<link>http://www.tekboss.com/2009/08/behind-enemy-lines-how-exactly-do-hackers-hack-a-computer/</link>
		<comments>http://www.tekboss.com/2009/08/behind-enemy-lines-how-exactly-do-hackers-hack-a-computer/#comments</comments>
		<pubDate>Sat, 08 Aug 2009 00:08:59 +0000</pubDate>
		<dc:creator>System Administrator</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Behind Enemy Lines]]></category>
		<category><![CDATA[Filthy Hands]]></category>
		<category><![CDATA[Hack Computer]]></category>

		<guid isPermaLink="false">http://www.tekboss.com/2009/08/behind-enemy-lines-how-exactly-do-hackers-hack-a-computer/</guid>
		<description><![CDATA[
So How exactly do hackers strut their stuff? I think it is important to understand the basis of their activity in order to protect our computers from their filthy hands even further. By knowing what they do, we&#8217;ll understand which part of the computer they specifically target thus makes it easier for us to protect [...]]]></description>
			<content:encoded><![CDATA[<div style="float:left; padding: 12px"><a href="/wp-content/uploads/2009/08/hacking27.jpg"><img src="/wp-content/uploads/2009/08/hacking27.jpg" title='' alt='' /></a></div>
<div>So How exactly do hackers strut their stuff? I think it is important to understand the basis of their activity in order to protect our computers from their filthy hands even further. By knowing what they do, we&#8217;ll understand which part of the computer they specifically target thus makes it easier for us to protect our computers by taking measures against that specific part. In a way, the quote, &#8220;Attack is the best form of Defence&#8221; can be applied here and I don&#8217;t mean hacking back the hackers who hacked you. I mean outsmarting them so they can&#8217;t repeat the same process over and over again. Who knows? If everyone gives them a hard time then they may go elsewhere and turn into a new leaf, using hacking for a good cause. So how do hackers hack your computer? Unfortunately, there are many ways in which one can do so. As explained by the following quote.<br/><br/>&#8220;In the Old world, if I wanted to attack something physical, there was one way to get there. You could put guards and guns around it, you could protect it. But a Database &#8211; or a control system &#8211; usually has multiple pathways, unpredictable routes to it, and seems intrinsically impossible to protect. That&#8217;s why most efforts at computer security has been defeated.&#8221; &#8211; <strong>Andrew Marshall, military analyst</strong><br/><br/>That sums it up perfectly. Unfortunately, most efforts at computer security has been defeated because hackers continue to evolve their ideas so it becomes stronger and less detectable. However, these megaviruses and malware only come around once in a while so lets focus on the most common forms of hacking. <strong>Note: If you are looking for ways to hack then you&#8217;re on the wrong site buddy. </strong><br/><br/>Type 1: Brute Force attack<br/><br/>A brute force attack is a method of defeating the encryption which secures a network by systematically trying a large number of possibilities. What it basically does is to guess the possibilities of a password by running through a list of dictionary words, number patterns and symbols until it has found the actual password. This kind of hacking can take up to weeks if the password is complex but can take a matter of minutes if your password is as simple as &#8216;abc&#8217;. How to avoid it? Simple. Make your password as complex as possible and use a secure password manager such as Roboform to remember it. How do you make a complex password? Check my earlier article, &#8216;Impossible for others, possible for you &#8211; designing your password&#8217;.<br/><br/><strong>Type 2: Bogus websites</strong><br/><br/>Unfortunately, many internet users don&#8217;t pay attention a lot of attention on the website they access. For example, there has been two cases of bogus Facebook websites during the last few months when hackers made a replica of Facebook and convinced users to sign in like a normal Facebook website. How? They&#8217;ll first infiltrate a user&#8217;s account and send a convincing message to all his friends. The message could be something like &#8220;Hey. Check out your photo in my Photo Album. Click here to see it&#8217;. The link will lead the user&#8217;s friend to the bogus Facebook website which will request the user to sign in again. Once the user has signed in, all the information goes straight to the hacker and the hacker will then able to infiltrate the user&#8217;s account and repeat the process. There has also been cases like this for eCash websites such as Paypal. So how you do distinguish a genuine and bogus website? First, pay attention at the URL address. Are there any typos? For example, myspace.com and mysspace.com. Most users only take a quick glance at the URL address and I guarantee that they wouldn&#8217;t be able to spot the typo from the previous example. Another thing to look for, especially if you&#8217;re doing online transactions is the https:// sign. All major online businesses should have this to show that any transactions are encrypted and secured. In the end, it really comes down to common sense so always be aware of any websites you visit and don&#8217;t click a link hastily if you come across one.<br/><br/><strong>Type 3: Trojans, spyware and keyloggers</strong><br/><br/>Trojans, spyware and keyloggers can all be classified as malware. What do they do? They basically act as a backdoor in a computer. A Hacker will distribute a legitimate looking installation file around, possibly through emails or P2P networks. What most user wouldn&#8217;t know is that a trojan or spyware would be part of the installation file and they would be installed unnoticed. Once they have been installed, the malware process will run in the background and monitor every move a user makes on his computer. A keylogger for example will record every keystroke a user makes, things like passwords and bank account numbers are at risk. How do you avoid these malware? Download files only from legitimate and reputable websites! Always question the software beforehand by searching about it on Search Engines like Google. You are bound to find many user reviews about the software, helping you decided whether to install the file or not.<br/><br/><strong>Type 4: Software vulnerabilities</strong><br/><br/>Unfortunately, every software and programs out there has flaws and hackers take advantage of them quickly and efficiently. As you may have heard recently, The Conficker Virus was able to spread due to a vulnerability in the Windows Operating System. To reduce the chances of hackers taking advantage of these vulnerabilities, always download the latest updates for your OS as soon as it is released. Windows has its infamous Windows Update which can be quite annoying at times but it is the quickest and most efficient way for Microsoft to distribute updates to fix any security vulnerabilities they find in the system. There are unfortunately many other forms of hacking out there but the above four points cover the most basic of attacks which are performed against common users. Hackers on a large scale may also use attacks such as DDOS (Distributed Denial of Service) which aims to overload a system&#8217;s network by directing many &#8216;puppet&#8217; computers to a site in one go. Sounds scary huh? Don&#8217;t worry. These attacks are not likely to come at you unless you are a high figure profile causing controversy in the underground world. Just be aware of what you do on your computer and always have an antivirus of antispyware program installed to reduce your chances of being hacked.<br/><br/><br/><br/><em>By: <strong>James Millway</strong></em><br/><br/><strong>About the Author:</strong>
<div style="border: thin solid gray; background-color: #E2E089; padding:1em;">
<p>James C is a co-author of the Free Spyware removal blog. Looking for a <a href="http://www.hkactivity.com">free spyware removal tool</a>? No worries. Visit our blog and find what is suitable for you.</p>
</div>
<p><br/><br/></div>
]]></content:encoded>
			<wfw:commentRss>http://www.tekboss.com/2009/08/behind-enemy-lines-how-exactly-do-hackers-hack-a-computer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>how to remove &#8220;hacked by godzilla&#8217;</title>
		<link>http://www.tekboss.com/2009/08/how-to-remove-hacked-by-godzilla/</link>
		<comments>http://www.tekboss.com/2009/08/how-to-remove-hacked-by-godzilla/#comments</comments>
		<pubDate>Fri, 07 Aug 2009 12:01:29 +0000</pubDate>
		<dc:creator>System Administrator</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Machine Software]]></category>
		<category><![CDATA[Names]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.tekboss.com/2009/08/how-to-remove-hacked-by-godzilla/</guid>
		<description><![CDATA[
Many of you might have seen this, especially IE users, on thier IE title after the transfer of some files to a handy drive.Hacked by godzilla- MS32DLL.dll.vbs,a low threat worm(symantec) is also known as VBS.Zodgila worm.It was discovered since Nov 23, 2006How it works1)It firstly creates[****]:\MS32DLL.dll.vbs[****]:\MS32DLL.dll.vbs[****]:\autorun.infNOTE:**** REFERS TO DRIVE NAMES2)Secondly it adds the following Windows [...]]]></description>
			<content:encoded><![CDATA[<div style="float:left; padding: 12px"><a href="/wp-content/uploads/2009/08/hacking15.jpg"><img src="/wp-content/uploads/2009/08/hacking15.jpg" title='' alt='' /></a></div>
<div>Many of you might have seen this, especially IE users, on thier IE title after the transfer of some files to a handy drive.<br/><br/>Hacked by godzilla- MS32DLL.dll.vbs,a low threat worm(symantec) is also known as VBS.Zodgila worm.<br/><br/>It was discovered since Nov 23, 2006<br/><br/>How it works<br/><br/>1)It firstly creates<br/><br/>[****]:\MS32DLL.dll.vbs<br/><br/>[****]:\MS32DLL.dll.vbs<br/><br/>[****]:\autorun.inf<br/><br/>NOTE:**** REFERS TO DRIVE NAMES<br/><br/>2)Secondly it adds the following Windows IE entry level values<br/><br/>“MS32DLL” = “%Windir%\MS32DLL.dll.vbs” to the registry subkey:<br/><br/>HKEY_LOCAL_MACHINE \SOFTWARE \Microsoft \Windows \CurrentVersion \Run<br/><br/>3)Finally it changes the IE title<br/><br/>“Window Title” = “Hacked by[REMOVED]” to the registry subkey:<br/><br/>HKEY_CURRENT_USER \Software \Microsoft \Internet Explorer \Main<br/><br/>to modify title in Internet Explorer.<br/><br/>4)As a result your IE title will end with “Hacked by Godzilla” and You might not able to open<br/><br/>any of your drive by double click<br/><br/>Now i will tell you how can you remove the worm<br/><br/> Open Task Manager ( Right click on your taskbar and click “Task Manager” ) Click on Processes tab and select “wscript.exe” and click “End Process” button. (Remember to remove all wscript.exe) Go to My Computer, Click on <strong>Tools</strong> ->    <strong>Folder Options</strong>, click on <strong>View</strong> tab Under <strong>Advance settings</strong>,<br/><br/>check “<strong>Show Hidden files and folders</strong>“,<br/><br/>uncheck “<strong>Hide extensions for known file types</strong>“,<br/><br/>uncheck “<strong>Hide protected operating system files (Recommended)</strong>”<br/><br/>and click “OK” button Go to C:\WINDOWS or C:\WINNT and delete file <strong>MS32DLL.dll.vbs</strong> Now go to all your drive in your computer, and delete <strong>autorun.inf</strong> and <strong>MS32DLL.dll.vbs</strong>&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;(visit blog below) <br/><br/><strong>TO SEE MUCH MORE ARTICLES OF THE SAME VISIT www.stolentips.blogspot.com</strong><br/><br/><br/><br/><em>By: <strong>prem</strong></em><br/><br/><strong>About the Author:</strong>
<div style="border: thin solid gray; background-color: #E2E089; padding:1em;">
<p><a href="http://www.stolentips.blogspot.com" target="_blank">www.stolentips.blogspot.com</a></p>
</div>
<p><br/><br/></div>
]]></content:encoded>
			<wfw:commentRss>http://www.tekboss.com/2009/08/how-to-remove-hacked-by-godzilla/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Russian Cyber Criminals Hacked Danish Netbanks I January 2009</title>
		<link>http://www.tekboss.com/2009/07/russian-cyber-criminals-hacked-danish-netbanks-i-january-2009/</link>
		<comments>http://www.tekboss.com/2009/07/russian-cyber-criminals-hacked-danish-netbanks-i-january-2009/#comments</comments>
		<pubDate>Thu, 23 Jul 2009 17:43:01 +0000</pubDate>
		<dc:creator>System Administrator</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Card Transactions]]></category>
		<category><![CDATA[Methodologies]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.tekboss.com/2009/07/russian-cyber-criminals-hacked-danish-netbanks-i-january-2009/</guid>
		<description><![CDATA[
 Around 8000 net bank customers in Denmark has been deprived to enter their own net banks lately. The reason is a virus according to F-Secure that has been targeted against Danish net bank customers.
The main task of the virus was to take control over the customers card transactions and let the men behind the scene [...]]]></description>
			<content:encoded><![CDATA[<div style="float:left; padding: 12px"><a href="/wp-content/uploads/2009/08/hacking42.jpg"><img src="/wp-content/uploads/2009/08/hacking42.jpg" title='' alt='' /></a></div>
<div> Around 8000 net bank customers in Denmark has been deprived to enter their own net banks lately. The reason is a virus according to F-Secure that has been targeted against Danish net bank customers.</p>
<p><br/><br/>The main task of the virus was to take control over the customers card transactions and let the men behind the scene empty the accounts for money. There is no information about whether money is lost during this attack or not. The banks have closed several accounts in order to minimize any risks in this case.</p>
<p><br/><br/>The security company F-Secuer has identified the Trojan as Trojan-Banker.Win32.MultiBanker but there remains to make a cure against these.</p>
<p><br/><br/>The Trojans identified in this case were difficult to detect and complicated in construction, as they have used rootkit technology and the consept they have used to sniff information is called Man-in-the-Browser technique.</p>
<p><br/><br/>The way it works is that the Trojan modifies the victims behaviour in true time like in a bank transactions. The method is described as very complicated and expensive routine. Unfortunately we will see more of these types of attacks in the future and the banks will need to ensure more safe routines and methodologies to ensure customers security online as well in other electronic transactions they are involved in.</p>
<p><br/><br/>The challenge is big, however, it remains to see whether the banks will make available enough resources and efforts to solve these issues or not.</p>
<p><br/><br/>At the moment it looks like internet based services are not safe for the users and caution is advised using these at the moment.<br/><br/><br/><br/><em>By: <strong>Stig Kristoffersen</strong></em><br/><br/><strong>About the Author:</strong>
<div style="border: thin solid gray; background-color: #E2E089; padding:1em;">
<p>He has a background as civil engineer and geoscientist. He has worked mainly within the oil and gas industry from the mid 1980s. He has written a few fictional novels as well as being the author of some professional litterature within oil and gas sector, he is now an editor of some web sites.</p>
</div>
<p><br/><br/></div>
]]></content:encoded>
			<wfw:commentRss>http://www.tekboss.com/2009/07/russian-cyber-criminals-hacked-danish-netbanks-i-january-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Network Security/Hacking Contd…</title>
		<link>http://www.tekboss.com/2009/07/network-securityhacking-contd%e2%80%a6/</link>
		<comments>http://www.tekboss.com/2009/07/network-securityhacking-contd%e2%80%a6/#comments</comments>
		<pubDate>Sun, 19 Jul 2009 04:12:56 +0000</pubDate>
		<dc:creator>System Administrator</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Computer Skills]]></category>
		<category><![CDATA[Result Window]]></category>
		<category><![CDATA[Weather]]></category>

		<guid isPermaLink="false">http://www.tekboss.com/2009/07/network-securityhacking-contd%e2%80%a6/</guid>
		<description><![CDATA[
So in my first post on Network Security/Hacking i have told you how to use angryip scanner to find out live computers on your network…..sorry to say this but most of the internet users out there are not concern with their network security and they connect to the internet without using a Firewall, and most [...]]]></description>
			<content:encoded><![CDATA[<div style="float:left; padding: 12px"><a href="/wp-content/uploads/2009/08/hacking17.jpg"><img src="/wp-content/uploads/2009/08/hacking17.jpg" title='' alt='' /></a></div>
<div>So in my first post on Network Security/Hacking i have told you how to use angryip scanner to find out live computers on your network…..sorry to say this but most of the internet users out there are not concern with their network security and they connect to the internet without using a Firewall, and most of them share a folder with important files…..<br/><br/>There are many software based firewalls like Zone Alarm which sit on your PC between your OS and Internet and wheneven some program tries to access the internet they will pop-up a window asking you weather you want to allow the program or not….if you dont have the knowledge about that program you can always google.com to find what the program is….and then you can allow/block them…sounds simple right but it provides the best protection….<br/><br/>Sharing of folders….this is something which is the killer in the cable internet networks….even if you dont have any folders shared but you have File Printing and Sharing enabled you are vunerable to all the Network Virus which spread through network..If you have a cable internet connection remember to remove File Printing and Sharing from Network Connections. Its a service and you dont need it to access the internet….<br/><br/>Angryip scanner result window would display all the live hosts and you can right click a live host and select browse to browse the shared folders….<br/><br/> Another basic mistake people do is they would allow unwanted services enable…for example telnet….have you used telnet before…..most of you would answer no…its a service through which you can remotely connect to a PC and execute commands….by default it comes with a blank password….so you can simply right click the live hosts and select Telnet…if the service is enabled you are in his system and you can use any dos command you have learnt as part of your Basic Computer skills….delete all system files to make his system useless…thats the worst thing to do….<br/><br/> Keep comming back for more….and please post your suggestions and comments…….<br/><br/><br/><br/><em>By: <strong>Sunil Saripalli</strong></em><br/><br/><strong>About the Author:</strong>
<div style="border: thin solid gray; background-color: #E2E089; padding:1em;">
<p><a target="_blank" href="http://www.sunilsaripalli.com">http://www.sunilsaripalli.com</a></p>
</div>
<p><br/><br/></div>
]]></content:encoded>
			<wfw:commentRss>http://www.tekboss.com/2009/07/network-securityhacking-contd%e2%80%a6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Ethical Hacking?</title>
		<link>http://www.tekboss.com/2009/03/what-is-ethical-hacking/</link>
		<comments>http://www.tekboss.com/2009/03/what-is-ethical-hacking/#comments</comments>
		<pubDate>Tue, 10 Mar 2009 00:21:50 +0000</pubDate>
		<dc:creator>System Administrator</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.tekboss.com/2009/03/what-is-ethical-hacking/</guid>
		<description><![CDATA[
An Ethical Hacker is an expert hired by a company to attempt to attack their network and computer system the same way a hacker would. Ethical Hackers use the same techniques and tactics as those used by illegal hackers to breach corporate security systems. The end result is the company’s ability to prevent an intrusion [...]]]></description>
			<content:encoded><![CDATA[<div style="float:left; padding: 12px"><a href="/wp-content/uploads/2009/03/hacking73.jpg"><img src="/wp-content/uploads/2009/03/hacking73.jpg" title='' alt='' /></a></div>
<div>An Ethical Hacker is an expert hired by a company to attempt to attack their network and computer system the same way a hacker would. Ethical Hackers use the same techniques and tactics as those used by illegal hackers to breach corporate security systems. The end result is the company’s ability to prevent an intrusion before it ever occurs.<br/><br/>A company can’t know if their security system is solid unless they test it. It’s hard, though, for a company’s IT team to thoroughly ring out the system. Try as they might, the techs can’t go at the system with all the malicious or mischievous motives of a true illegal hacker. To thoroughly uncover vulnerabilities, the theory goes; you must examine your security system through the eyes of an illegal hacker.<br/><br/>The word hacking has strongly negative connotations, and, for the most part, rightly so. But ethical hacking is much different. It takes place with the explicit permission of the company whose system is being attacked. In fact, their “good guy” role is underscored by the nickname “white hat” Ethical Hackers have been given. The nickname is a throwback to old Westerns where the good cowboys could be identified by their white hats.<br/><br/>The company and the Ethical Hacker enter into a legally binding contract. The contract, sometimes called a “get out of jail free card,” sets forth the parameters of the testing. It’s called the “get out of jail free card” because it’s what harbors the Ethical Hacker from prosecution. Hacking is a felony, and a serious one at that. The terms of the agreement are what transform illegal behavior into a legal and legitimate occupation.<br/><br/>Once the hacker has exhausted his attempts, he reports back to the company with a list of the vulnerabilities he uncovered. The list in and of itself, however, is not particularly useful. What’s most valuable is the instructions for eliminating the vulnerabilities that the Ethical Hacker provides.<br/><br/>An Ethical Hacker works to uncover three key pieces of information. First, he determines what information an illegal hacker can gain access to. Next, he explores what an illegal hacker could do with that information once gained. Last, the Ethical Hacker ascertains whether an employee or staff member would be alerted to the break-in, successful or not.<br/><br/>At first it might sound strange that a company would pay someone to try to break into their system. Ethical hacking, though, makes a lot of sense, and it is a concept companies have been employing for years. To test the effectiveness and quality of product, we subject it to the worst case scenario. The safety testing performed by car manufacturers is a good example. Current regulatory requirements including HIPAA, Sarbanes Oxley, and SB-1386 and BS 799 require a trusted third party to check that systems are secure.<br/><br/>In order to get the most out of the assessment, a company should decide in advance the nature of the vulnerabilities they’re most concerned with. Specifically, the company should determine which information they want to keep protected and what they’re concerned would happen if the information was retrieved by an illegal hacker.<br/><br/>Companies should thoroughly assess the qualifications and background of any Ethical Hacker they are considering hiring. This individual will be privy to highly sensitive information. Total honesty and integrity is of the utmost importance.<br/><br/><br/><br/><em>By: <strong>Paul Walsh</strong></em><br/><br/><strong>About the Author:</strong>
<div style="border: thin solid gray; background-color: #E2E089; padding:1em;">
<p>Paul Walsh, of <a href="http://www.protocolsolutions.co.uk" target="_blank">www.protocolsolutions.co.uk</a> asks the scariest question out there: Think your network is safe from malicious attack? Find out for sure – a quick, complimentary chat will help you sleep better. 
</p>
</div>
<p><br/><br/></div>
]]></content:encoded>
			<wfw:commentRss>http://www.tekboss.com/2009/03/what-is-ethical-hacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Protect your Website With your Ethical Hacking Knowledge</title>
		<link>http://www.tekboss.com/2009/02/protect-your-website-with-your-ethical-hacking-knowledge/</link>
		<comments>http://www.tekboss.com/2009/02/protect-your-website-with-your-ethical-hacking-knowledge/#comments</comments>
		<pubDate>Thu, 19 Feb 2009 15:05:37 +0000</pubDate>
		<dc:creator>System Administrator</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.tekboss.com/2009/02/protect-your-website-with-your-ethical-hacking-knowledge/</guid>
		<description><![CDATA[
The first cause for websites being hacked is the lack of knowledge oftheir webmasters.Hackers or even wannabe hackers can modify your website home page,steal your website profits and fame by just using ready to be downloadedexploits published into trusted and untrusted internet security portals.Wether you have a basic knowledge of web site publishing or you [...]]]></description>
			<content:encoded><![CDATA[<div style="float:left; padding: 12px"><a href="/wp-content/uploads/2009/03/hacking20.jpg"><img src="/wp-content/uploads/2009/03/hacking20.jpg" title='' alt='' /></a></div>
<div>The first cause for websites being hacked is the lack of knowledge of<br/><br/>their webmasters.<br/><br/>Hackers or even wannabe hackers can modify your website home page,<br/><br/>steal your website profits and fame by just using ready to be downloaded<br/><br/>exploits published into trusted and untrusted internet security portals.<br/><br/>Wether you have a basic knowledge of web site publishing or you are<br/><br/>an experienced webmaster the only thing to protect yourself from hackers attacks<br/><br/>is ethical hacking.<br/><br/>Ethical hacking means understanding your enemy mind, skills, intentions and<br/><br/>strength, up to take the successful countermeasures that will save your daily hard job<br/><br/>into developing a successful and trusted web platform.<br/><br/>Image damages causing shareholders and customers complaints, not to mention<br/><br/>6 figures money loss, is what led many big corporations to hire dozens of ethical hackers<br/><br/>to keep their networks and web site safe from &#8220;bad&#8221; hackers.<br/><br/>In this article I am going to focus on the following two questions:<br/><br/>What do ethical hackers do?<br/><br/>What can I do to protect my website if I am not an ethical hacker?<br/><br/>The first step taken by hackers, should they be ethical or evil, is to scan your<br/><br/>web application for known vulnerabilities. This can be achieved through a<br/><br/>penetration testing process that can be manual or automated by some programs<br/><br/>and scripts. This is the most important and crucial task in every attack attempt.<br/><br/>And this is what an ethical hacker can&#8217;t fail.<br/><br/>The second step is to get a working exploit to take advantage of the vulnerablity<br/><br/>found in step 1. Here is where protection and fixes should take place to *prevent* the attack and not<br/><br/>to just cure after the disaster. Ethical hackers in this case would be able to<br/><br/>modify source codes to cover the holes or just reduce the success rate of the attack dramatically.<br/><br/>I would strongly advise to work on the first step since it is the most simple<br/><br/>to master wether you&#8217;re not expert into security field or you just don&#8217;t have enough money to hire<br/><br/>an experienced ethical hacker.<br/><br/>Internet security knowledge is what can save your site with a very cheap price.<br/><br/>At the most basic level this can be achieved by keeping yourself informed on your<br/><br/>websites scripts well-known vulnerabilities, available patches and<br/><br/>security best practices.<br/><br/>Moreover the understanding of basic attacking vectors like Cross site scripting or SQL Injection will<br/><br/>keep you safe from a big number of wannabe hackers that you will be able to<br/><br/>defeat&#8230;with your knowledge!<br/><br/>So next time you will see some suspicious activity in your website log you will be laughing at it,<br/><br/>since not a dummy tool but your own knowledge as ethical hacker will be protecting you.<br/><br/><br/><br/><em>By: <strong>ryan</strong></em><br/><br/><strong>About the Author:</strong>
<div style="border: thin solid gray; background-color: #E2E089; padding:1em;">
<p>Armando Romeo aka Zinho is Computer Science Engineer and founder of Hackers Center security research group <a target="_blank" href="http://www.hackerscenter.com.">http://www.hackerscenter.com.</a> In 2007 has launched the Ethical Hacking kit project located at <a target="_blank" href="http://kit.hackerscenter.com">http://kit.hackerscenter.com</a> &#8211; the only package of papers and tools available for ethical hackers and webmasters to speed up their internet security learning process.</p>
</div>
<p><br/><br/></div>
]]></content:encoded>
			<wfw:commentRss>http://www.tekboss.com/2009/02/protect-your-website-with-your-ethical-hacking-knowledge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Myspace Hack: How to Hack Myspace Account Passwords</title>
		<link>http://www.tekboss.com/2009/02/myspace-hack-how-to-hack-myspace-account-passwords/</link>
		<comments>http://www.tekboss.com/2009/02/myspace-hack-how-to-hack-myspace-account-passwords/#comments</comments>
		<pubDate>Mon, 16 Feb 2009 20:40:45 +0000</pubDate>
		<dc:creator>System Administrator</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.tekboss.com/2009/02/myspace-hack-how-to-hack-myspace-account-passwords/</guid>
		<description><![CDATA[
Have you ever seen your friend post a bulletin on MySpace about how they made a $1,000 on the weekend? It&#8217;s the first sign your friend&#8217;s MySpace account has been hacked. Maybe you&#8217;ve had your MySpace account hacked and would like to know what you can do to prevent it from happening again in the [...]]]></description>
			<content:encoded><![CDATA[<div style="float:left; padding: 12px"><a href="/wp-content/uploads/2009/03/hacking2.jpg"><img src="/wp-content/uploads/2009/03/hacking2.jpg" title='' alt='' /></a></div>
<div>Have you ever seen your friend post a bulletin on MySpace about how they made a $1,000 on the weekend? It&#8217;s the first sign your friend&#8217;s MySpace account has been hacked. Maybe you&#8217;ve had your MySpace account hacked and would like to know what you can do to prevent it from happening again in the future. Then this post is for you.<br/><br/><br/><br/><br/><br/>Phishing<br/><br/>Most people have their account hacked by clicking on a stranger&#8217;s profile only to be taken to what looks like the MySpace login screen. Turns out it&#8217;s not a MySpace login screen and the username and password you just entered is saved for future use by the bad guys(hackers). The biggest thing is if you find yourself suddenly sent to the login page when you haven&#8217;t signed out, look at the url and make sure it says myspace.com in the address bar. If it has happened to you, you should be able to remedy the problem by simply changing your password watching for the proper web address in the future.<br/><br/>For more on Phishing and the method used for hacking Myspace account by Phishing refer:<br/><br/>Hack email accounts by Phishing.<br/><br/>Viruses<br/><br/>Another way people have their account hacked is from <strong>malware installed</strong> on their system that records their keystrokes. This is an uncommon problem for MySpace accounts because people looking to watch your keystrokes wouldn&#8217;t risk the legal trouble for MySpace accounts. They&#8217;d much rather take your bank account or something more valuable. If you change your password repeated times and you keep getting hacked, then you may have a virus and you&#8217;ll need to reinstall your operating system and start over.<br/><br/><strong><br/><br/>Spy Software<br/><br/></strong><br/><br/>Keylogging is the best and most guaranteed way to obtain a myspace password because not only can their myspace password, but you can get the passwords to everything they have and see every piece of information entered on the computer. Keylogging refers to the monitoring of key&#8217;s pressed on a keyboard, but most spy software contain many more usefull features. Some software does not even require you to touch the person&#8217;s computer, which many people find extremely usefull. I have tried many many different software solutions, and here is what I recommend.<br/><br/>If you have physical access to their computer<strong>,</strong> this should be relatively easy. For this situation, we recommend a keylogging software such as Ardamax keylogger . You can simply install it on the computer that they use and it will log all activity on the computer, including capturing the MySpace password. I recommend Ardamax keylogger because it has a unique MySpace capture feature that saves a screenshot of every page visited on the site and also has a great interface.<br/><br/>If there&#8217;s no way you can physically access their computer, it can be a little trickier to pull off. The program i&#8217;ve found that works the best (and gets so close to this ethical line) is a service called SniperSpy. SniperSpy gives you a module that you can send to your target that will allow you to spy on their computer&#8217;s every action. No physical access to the target&#8217;s computer is needed. You can view their computer screen LIVE from anywhere at anytime via your web browser, which means you don&#8217;t need to install anything on your computer either. You will be able to look at chat conversations, web sites visited, and gain access to all the online accounts they log into while being SniperSpyed. It even takes image screenshots of every internet webpage they look at, so that if they are perhaps deleting messages from their email/myspace inbox, you can look at the stored screenshots and read the deleted messages when normally you never could! This is the tool I used to catch my girlfriend and it worked absolutely great. I really believe it&#8217;s the ultimate spying tool (and i&#8217;ve tryed a lot of things). Their Testimonials page shows that they&#8217;ve been on the news and featured in several magazines, so you should feel pretty good that you&#8217;ll accomplish what you&#8217;re after when you buy it.<br/><br/><strong></strong><strong> </strong> I&#8217;ve gotten word of a secret coupon code for <strong>25% off</strong> SniperSpy and/or Acespy! That&#8217;s at least $20 off! Too bad I didn&#8217;t know about it when I bought SniperSpy, haha. At the second purchase page, enter the following code: <strong>RXS-SPY25</strong><br/><br/><strong>Ask them for it</strong><br/><br/>Yeah, that wasn&#8217;t what you wanted to hear. Well, the truth is, an honest partner will let you have it if there is absolutely nothing going on. The reason you should ask is they might be forthcoming. If your partner refuses, it does not necessarily mean they are cheating, but it is a red flag and can indicate they are hiding something<br/><br/>Other<br/><br/>People can also think their account was hacked if they neglect to log out and someone uses the computer after them. So be sure to logout and not just close the window, especially if you&#8217;re at a library, internet cafe, or the like.<br/><br/>So guys, i have provided you with almost all methods used for <strong>hacking Myspace accounts passwords</strong>. If you have any query about hacking myspace account passwords, please let me know.<br/><br/>Enjoy HaCkInG&#8230;.<br/><br/><br/><br/><em>By: <strong>Rajesh</strong></em><br/><br/><strong>About the Author:</strong>
<div style="border: thin solid gray; background-color: #E2E089; padding:1em;">
<p>I m Rajesh, interested a lot in blogging and computer tricks.</p>
</div>
<p><br/><br/></div>
]]></content:encoded>
			<wfw:commentRss>http://www.tekboss.com/2009/02/myspace-hack-how-to-hack-myspace-account-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
