Monday, 4 December 2017

Social Engineering Tutorial

What The Social Engineering (or social engineering or social manipulation in French)


Social Engineering
The manipulator will often use your emotions to achieve his ends.
It's the art, the science of manipulating people to get something from them without them realizing it. One influences or abuses the trust of a person to obtain a good or information generally about a computer system (password, sensitive data). It is therefore the famous human fault .
This fault is a very fragile piece It can be used by ALL the world without specific knowledge and it is the key of success of 90% of hacker. These techniques are not detected by the antivirus, but it is the human being who can defend himself, easily, when he becomes aware of it and remains vigilant.
We are all already manipulators , everyone has already lied several times in life, in the current month, even the same day. Handling requires no specific degree or age, everyone is able to, and this makes the attack very widespread and vicious. The pirate (or manipulator) will notably play on the psychology, the feeling of the targets, and progress slowly towards the final goal: to hack his victim.

How to counter the attempts of Social Engineering?

This is an interesting subject that directly concerns social psychology applied to computers .
We will therefore seek above all to prevent any attempt at manipulation. We will then try to detect an attempted manipulation, that's 90% of the work done.
  • Prevention:
We start by not leaving too many traces on the Internet and remove a maximum if necessary.
The manipulator loves the e-mail addresses you have left here and there. It seeks to identify your interests , your hobbies , your habits , your friends . It seeks in general to create an ID card on you and more information you give more you him make it easy task. The Secrets on Our Anonymity guide gives you a shocking concrete example.
Tip: you can, knowing this, give false information to trap a manipulator. Do not hesitate to create several different e-mail addresses for different needs.
  • Know who you really are dealing with:
The manipulator will never use his true identity unless he knows you really well and that it does not pose any problem. He will usually be the opposite sex to you , and in a more general way he will often be thought of as a woman .
If he handles very well you will usually see only fire because he will create a completely realistic profile .
So you have to take the time to ask him for information that he does not have in his possession.
The best way is to request a photo of him with your name / nickname written on a piece of paper . A trusted person will always be able to assure you that it is this way and it only takes 2 minutes.
If he gives you photos (for example of attractive women) you can use the TinyEye online service to search for the existence of this photo on the net. You will immediately see where the picture comes from.
  • Fail the attack:
Keep these principles in mind and the attack will fail all the time:
  • Do not give ever your sensitive information over the Internet to a person you do not know physically (and not even to you know).
  • Change your passwords regularly .
  • Be always vigilant and do not believe the very special offers, enticing etc ...
  • Stay informed about computer attacks and scams.
For more details, definitions and practical examples, I invite you to follow the How to Become a Hacker guide.

Tuesday, 28 November 2017

How to hack hotmail account

This article aims to better understand how a hacker can hack our Hotmail / Outlook / Live account , to guard against it properly. We will also talk about a flaw that is now corrected that shows that an implementation error can have disastrous consequences and allow us to draw conclusions about the security of our accounts.
I remind you that this site is not intended to help to hack but to understand the attacks to defend itself .

How could a hacker so easily hack a Hotmail account?

Example with the use of a flaw in Hotmail:

This flaw is now fixed . We will dissect it to better understand what may have happened if you have been hacked. This can also be the cause of hacking your account in the past, in the consequences may fall back in the future!
Here are the steps that were used:
  • Know the e-mail address of the person.
  • Access the password reset page on the mobile version of the site (which at that time was security conscious).
hack hotmail

  • Enter the address of the target as well as the security captcha.
  • A page was displayed asking to enter the secret question or to send the restore instructions to the backup address. This backup address is displayed according to the following model: ou******@hotmail.com.
  • It was therefore necessary to start by finding this address partly hidden. And the flaw was at this level , indeed it was enough to display the source code of the page (CTRL + U under most browsers). And in the source code a value of type hidden was found there or the address appeared in clear, without the stars.
hack hotmail


  • This step required a lot of luck, it was necessary to check if this address of relief was used or not. The hacker went to the registration page HERE and registered with this address of relief.
  • This address is often noted at the pif by people because it is mandatory at registration. Thus, an address put at random is very likely to be unused and it was enough for the pirate to appropriate the secondary account.
Once the hacker had managed to create this secondary account, he clicked on "Send email" and he received all instructions to reset the password of the account he wanted to hack. As simple as that, no programming knowledge required, no need to be a computer engineer, no need to use specialized tools!
Another way to hack a Hotmail account was to wait for the address to be several years old without being used. Hotmail accounts were automatically deleted when they were several years old ! It was therefore possible to hack any account , it was enough that the original owner logs in not for a while.
You'll understand: to hack your Hotmail account the hacker had to wait ...

Conclusion on this flaw and prevention methods

It only took a bit of cunning to test the mobile version and take a look at the source code of the page to find this trick more than formidable.
You now know that you have to pay attention to the backup address of an account, it is as importantas the main address. Also be aware that not logging in for a long time makes your account reusable by anyone else .

How not to be hacked in the future

Never give YOUR own credentials (e-mail addresses and password) to certain websites or programs. If you were actively looking for hacking a hotmail account before coming here you probably came across "specialized sites" and others "give me your IDs, I'll do it in 2 seconds". That's not true, be suspicious !
Now, we will see other hacking opportunities that are not technical this time and against which you must be protected .

Pay attention to keyloggers , who recover purely and directly your passwords

You tell yourself that outlook.com is http s , you use a proxy or VPN and nobody could thus steal your password.
FALSE.
Keyloggers get what you type on your keyboard, no matter the active window, no matter what the encryption of the connection is.

Pay attention to Phishing , which makes you believe that you are addressing an official website

With keyloggers, phishing is one of the most popular attacks to hack into any account. It's simple, you are made to believe that your information is not up to date (or any other technique in this genre) to send you to a fake site that retrieves your password . Phishing software also exists, typically with programs that require you to log in to perform an action while they recover your password.

Be careful to have a valid backup address , not unused or non-existent

Outlook / Hotmail requires to choose at least two identifiers, but for many users, this information is useless, so they fill an address of emergency, the pif!
It's just like sending your password to someone at random. It is also possible for anyone to create this address, which did not necessarily exist before.

Be careful to choose a complicated answer to the security question

In the same vein, users think they never need to use a secret answer, so they give it to the ghost(and do not remember when their account is hacked) or normally answer the question, which seems to be a good thing. But it is not at all , ask directly an individual "What was your first animal? Is enough to get the answer you are looking for is to hack an account!)

Be careful not to show the contents of your inbox and your account information

Seeing e-mails at work or at school seems harmless. But if a bad-minded person takes note of what she sees, she can hack a hotmail account (or whatever). Because by using the recovery form, anyone can pretend to know you a lot of information about your account, and thus reset your account.

Securely secure your accounts upstream

Once you are hacked it is often too late. Think about two-step authentication, the password or emergency phone number, and most importantly: Be suspicious and aware.

Thursday, 23 November 2017

Uber bought the silence of hackers

Security: The VTC service has just revealed to have been the victim of a hacking that has led to the theft of personal data of 57 million users including nearly 7 million drivers. Uber paid the pirates $ 100,000 to keep them quiet.

This is yet another turpitude that Uber would probably have done well. Dara Khosrowshahi, the new boss of the VTC service who is working to restore the company's somewhat damaged image, has just made another sensational revelation . In 2016, cyber criminals hacked a GitHub server and accessed the personal data of 57 million users. They were able to download certain items such as names, email addresses and phone numbers.

uber hacked

About 7 million Uber drivers are among the victims and 600,000 of them based in the United States have had their driver's license number downloaded. Uber ensures that no other sensitive data (credit card, date of birth, social security number, etc.) has been compromised and that measures have been taken immediately to secure this breach.

Security officers transferred; Prevented victims

The perpetrators were quickly identified but Uber chose to smother the case by paying a ransom of $ 100,000 to obtain the silence of the perpetrators. It should be noted that at the time of the incident, Uber was in discussion with the Federal Trade Commission about its management of user data.

Dara Khosrowshahi, who says she learned about piracy recently, took immediate action. Joe Sullivan, the director of security and one of his assistants Craig Clark were fired. The victims have been notified and the drivers concerned benefit from a program of protection against identity theft. This transparency operation falls when Uber is in talks with SoftBank for the sale of part of its capital.

Wednesday, 22 November 2017

The Machine by HP 2018

Technology: No RAM, no storage memory, no copper: the new architectural project presented by HP wants to shake up habits. But for now, The Machine is still just a research project.


the machine by hp



During the HP Discover conference, the R & D department presented the project that has been running the majority of its resources and time for two years now. Soberly named "The Machine", this new architecture is based on highly innovative technologies to meet the new challenges posed by big data and the evolution of uses.
For now, the project is not yet out of labs HP Labs, and nothing concrete is still available at the moment. At the conference, Martin Fink, HP's technical director, presented the different components that will make up The Machine.
Promises only, but beautiful promises: as reported by Bloomberg, The Machine aims to "replace the computer park of a datacenter with a computer the size of a fridge. "
To achieve this feat, HP is focusing its research on two very promising technologies: photonic buses and memristors.
Welcome to the future
Behind these barbaric names lie the two cornerstones of The Machine's architecture. Memristors are passive electronic components, whose existence was theorized in 1971. Since then, their existence was purely theoretical, we thought the thing possible without really knowing how. But in 2008, the HP Labs team managed to make its first physical models of memristors.

These electronic components have the ability to act both as a fast access memory and as a storage memory. HP began developing its first memory modules based on this technology, known as Reram .Other companies including Samsung are currently working on variants of this technology, whose performance is dreaming.
In addition to using these memristors to create a unified memory for the computer, HP also relies on light for information transfer between the various components of The Machine. A technology that has been known for some time, since it is the one implemented in the deployment of optical fiber for internet connections.
HP intends to miniaturize this type of optical connection to incorporate it into the heart of its architecture, increasing the speed of information exchange, and replacing the traditional physical connections in copper.
This radically different new architecture will obviously require a radically different operating system. HP started working on the issue, developing its new OS from a Linux kernel.
Nothing concrete, but figures
According to HP, this new architecture promises performance that has something to think about. The company had fun comparing the specifications of its new architecture to Fujitsu K, the Fujitsu supercomputer. And the comparison is without appeal: for a consumption of 160 kW, about 100 times less than the Fujitsu K, The Machine would benefit from a computing power 6 times higher.
HP could therefore hit a big blow if the reality of The Machine was well up to what the manufacturer advance. But it will take a few more years to judge: according to the firm, the first computers based on this architecture should be delivered by 2020.

Monday, 20 November 2017

The hacker's ethics

The ethics of the hacker was born at the Massachusetts Institute of Technology (MIT ), they are moral and philosophical values ​​that hackers must have to adhere to a standard.
This is what differentiates hackers who seek to defend themselves from pirates who seek to harm others . The nuance is important .
Journalist Steven Levy is the first to use the term ethical hacker in his book called Hackers . He also defined the following rules:

The ethics of hacking (ethical hacking)

  • Access to anything that could teach you something about how the world works should be unlimited and total.
  • The information should be free.
  • Do not trust authority, prefer decentralization.
  • Hackers should be judged on their exploits and not on criteria such as age, origin, sex, diploma etc ...
  • You can create art and beauty with a computer.
  • Computers can improve your life.
He also asks the company to open up its worldview on hackers and expand it to the planet and not just to the little computer genius. He is followed later by hacker  Loyd Blankenship who defines the hacker's manifesto .
More generally, the term "ethical hacker" is used to refer to a real hacker who secures computer systems, not a hacker .

ethical hacker

Why put yourself in the shoes of an attacker?

Hacking helps solve problems in many areas. In programming for example, we do not reinvent the wheel, we access the details of a system to build something useful and effective.
Hacking IT security makes it possible to secure one's own systems and online identity by first understanding how attacks work.
From there, the ethical hacker also known as the hacker in the white hat is thus put in the skin of a pirate to understand how he acts, and protect himself.
We try to "learn the attack to better defend ourselves", and we also use the term "offensive security".
The approach, inspired by fire safety training, is standard in the hacking industry:
We present a technique inspired by a real case, we explain it and put it into practice in order to understand the operating principles, and finally we protect ourselves against it.
Present , understand , protect .
The approach is the same for the police: we learn the techniques of thieves to catch them more easily.
Note: Putting the attacks into practice to understand them in a public way presents a potential danger related to the malicious people who would use the information to their advantage. As a result, The Hacker Blog will not provide public details that could lead to illegal actions.
Besides, I have a revelation for you right now:
It is often thought that a hacker is a person very computer savvy, gifted and nomadic.
In fact, once you know their little secrets, you realize that all this does not require extremely in-depth knowledge, and that you can defend yourself by applying simple and methodical concepts.
This hacker's ethics and these secrets are seen in detail in the guide  How to Become an Ethical Hacker that I invite you to follow right now to become a true hacker and fight computer attacks.