Skip to content

100825 Hackonomics 2010 Book for Sale Now:)



Support independent publishing: Buy this book on Lulu.

If you browse the web and read e-mail in 2010, then this book is for you.

Inside, you may find information about what technologies hackers use, how they work, what kinds of hackers there are, how much things cost, and some simple security techniques.

This book has the following difficulty levels:

Newbie – you should be able to understand most of this book and learn a lot from it, and you can safely skip things that are too complicated, because you probably don’t need them.

Average or Advanced Internet User – you should be able to understand most of this book, except maybe a few things, which you can easily search for.

IT – you should be able to understand most of this book.

Information Security Professional – you should know most of this. There is some technical stuff here to show you that it’s on the level, like the picture on the front – that’s a screenshot of the Zeus control panel.

Hacker – your secrets are revealed. LOL.

It will take a while to get this out to the other distributors, but you can already get it here :)

TABLE OF CONTENTS

INTRODUCTION
TRUST
USERS
WHAT HAPPENS

TECHNOLOGY
PUBLIC VS PRIVATE
BOTNET
EXPLOIT PACK
CRYPT
DENIAL OF SERVICE
BRUTERS
WEB EXPLOITS
LOADER
SKIMMERS

SERVICES
CARDS
MONEY LAUNDERING
PASSWORD CRACKING
MALWARE/HACKWARE
CRYPT
DENIAL OF SERVICE
BULLETPROOF HOSTING
VIRTUAL PRIVATE NETWORKING
DEDICATED SERVERS
TRAFFIC
INSTALLS
EMAIL LISTS
SPAM
SEARCH ENGINE OPTIMIZATION

JOBS
BOTNET OPERATORS
CRACKERS
CARDERS
DROPS
CRYPTERS
CODERS
SKIMMERS
SPAMMERS

EXPLOIT PACKS
EXPLOIT PACK INTRODUCTION
EFFECTIVE EXPLOITS
POPULAR EXPLOIT PACKS

PROTECTION
STRONG PASSWORDS
PATCHING
UNINSTALLING
SEPARATE BROWSERS
VIRTUAL MACHINES
REINSTALLING
SEPARATE OPERATING SYSTEM
AWARENESS
PASSWORD MANAGEMENT
DATA MANAGEMENT
STARTUP MANAGERS
ENCRYPTION
IMAGING
VPN

100902 QuickTime 7.6.7 0Day

http://www.packetstormsecurity.org/1008-exploits/apple_quicktime_marshaled_punk.rb.txt

Apple QuickTime 7.6.7 _Marshaled_pUnk Code Execution

This module exploits a memory trust issue in Apple QuickTime 7.6.7. When processing a specially-crafted HTML page, the QuickTime ActiveX control will treat a supplied parameter as a trusted pointer. It will then use it as a COM-type pUnknown and lead to arbitrary code execution. This exploit utilizes a combination of heap spraying and the QuickTimeAuthoring.qtx module to bypass DEP and ASLR. This module does not opt-in to ASLR. As such, this module should be reliable on all Windows versions.

NOTE: The addresses may need to be adjusted for older versions of QuickTime.

100831 Ghostery Ad Blocker

http://www.ghostery.com/about

Ghostery is your window into the invisible web – tags, web bugs, pixels and beacons that are included on web pages in order to get an idea of your online behavior.

Ghostery tracks the trackers and gives you a roll-call of the ad networks, behavioral data providers, web publishers, and other companies interested in your activity.

100825 Defend from the DLL Injection Vulnerability

There is now a lot of buzz about the DLL Injection vulnerability in Windows. This vulnerability allows remote execution by using WebDAV. To prevent attackers from using this vulnerability remotely, disable the WebClent service by following these simple steps:

1. Run “services.msc”
2. Double click on the “WebClient” service.
3. Select “Disabled” for the Startup Type.
4. Press “Stop”.
5. Press “OK”.

100804 Process Hacker

http://processhacker.sourceforge.net/

Process Hacker is a feature-packed tool for manipulating processes and services on your computer.

100803 Avoid Being Spied On

“The only thing that effectively keeps spy organizations from automatically spying on you is if your total communication profile, and the communication profile of the people in your social environment, are entirely uninteresting to them both now and in the future.”

-Global Spying: Realistic Probabilities in Modern Signals Intelligence, Steve Topletz, Jonathan Logan and Kyle Williams, 2009

100801 The Book Is Complete.

The book is complete…Waiting for publishing samples…

100731 Adblock Plus

http://adblockplus.org/en/

Annoyed by adverts? Troubled by tracking? Bothered by banners? Install Adblock Plus now to regain control of the internet and change the way that you view the web. You can also choose from over forty filter subscriptions to automatically configure the add-on for purposes ranging from removing online advertising to blocking all known malware domains.

100729 OSAM AutoRun Manager

http://www.online-solutions.ru/en/products/osam-autorun-manager.html

“OSAM” provides an easy one-click way of obtaining detailed information about the components that are run automatically at the system start and can potentially affect its operation.

100727 iKAT Interactive Kiosk Attack Tool

http://ikat.ha.cked.net/

iKAT is designed to provide access to the underlying operating system of a Kiosk terminal by invoking native OS functionality.