Showing posts with label HACKING. Show all posts
Showing posts with label HACKING. Show all posts

Wednesday, December 2, 2020

Edward Snowden: the whistleblower behind the NSA surveillance revelations | The NSA files | The Guardian

Edward Snowden: the whistleblower behind the NSA surveillance revelations | The NSA files | The Guardian


Edward Snowden: the whistleblower behind the NSA surveillance revelations

This article is more than 7 years old

Tue 11 Jun 2013 09.00 EDT

The individual responsible for one of the most significant leaks in US political history is Edward Snowden, a 29-year-old former technical assistant for the CIA and current employee of the defence contractor Booz Allen Hamilton. Snowden has been working at the National Security Agency for the last four years as an employee of various outside contractors, including Booz Allen and Dell.

The Guardian, after several days of interviews, is revealing his identity at his request. From the moment he decided to disclose numerous top-secret documents to the public, he was determined not to opt for the protection of anonymity. "I have no intention of hiding who I am because I know I have done nothing wrong," he said.

Snowden will go down in history as one of America's most consequential whistleblowers, alongside Daniel Ellsberg and Bradley Manning. He is responsible for handing over material from one of the world's most secretive organisations – the NSA.

In a note accompanying the first set of documents he provided, he wrote: "I understand that I will be made to suffer for my actions," but "I will be satisfied if the federation of secret law, unequal pardon and irresistible executive powers that rule the world that I love are revealed even for an instant."

Despite his determination to be publicly unveiled, he repeatedly insisted that he wants to avoid the media spotlight. "I don't want public attention because I don't want the story to be about me. I want it to be about what the US government is doing."

He does not fear the consequences of going public, he said, only that doing so will distract attention from the issues raised by his disclosures. "I know the media likes to personalise political debates, and I know the government will demonise me."

Despite these fears, he remained hopeful his outing will not divert attention from the substance of his disclosures. "I really want the focus to be on these documents and the debate which I hope this will trigger among citizens around the globe about what kind of world we want to live in." He added: "My sole motive is to inform the public as to that which is done in their name and that which is done against them."

He has had "a very comfortable life" that included a salary of roughly $200,000, a girlfriend with whom he shared a home in Hawaii, a stable career, and a family he loves. "I'm willing to sacrifice all of that because I can't in good conscience allow the US government to destroy privacy, internet freedom and basic liberties for people around the world with this massive surveillance machine they're secretly building."

'I am not afraid, because this is the choice I've made'

Three weeks ago, Snowden made final preparations that resulted in last week's series of blockbuster news stories. At the NSA office in Hawaii where he was working, he copied the last set of documents he intended to disclose.

He then advised his NSA supervisor that he needed to be away from work for "a couple of weeks" in order to receive treatment for epilepsy, a condition he learned he suffers from after a series of seizures last year.

As he packed his bags, he told his girlfriend that he had to be away for a few weeks, though he said he was vague about the reason. "That is not an uncommon occurrence for someone who has spent the last decade working in the intelligence world."

On May 20, he boarded a flight to Hong Kong, where he has remained ever since. He chose the city because "they have a spirited commitment to free speech and the right of political dissent", and because he believed that it was one of the few places in the world that both could and would resist the dictates of the US government.

In the three weeks since he arrived, he has been ensconced in a hotel room. "I've left the room maybe a total of three times during my entire stay," he said. It is a plush hotel and, what with eating meals in his room too, he has run up big bills.

He is deeply worried about being spied on. He lines the door of his hotel room with pillows to prevent eavesdropping. He puts a large red hood over his head and laptop when entering his passwords to prevent any hidden cameras from detecting them.

Though that may sound like paranoia to some, Snowden has good reason for such fears. He worked in the US intelligence world for almost a decade. He knows that the biggest and most secretive surveillance organisation in America, the NSA, along with the most powerful government on the planet, is looking for him.

Since the disclosures began to emerge, he has watched television and monitored the internet, hearing all the threats and vows of prosecution emanating from Washington.

And he knows only too well the sophisticated technology available to them and how easy it will be for them to find him. The NSA police and other law enforcement officers have twice visited his home in Hawaii and already contacted his girlfriend, though he believes that may have been prompted by his absence from work, and not because of suspicions of any connection to the leaks.

"All my options are bad," he said. The US could begin extradition proceedings against him, a potentially problematic, lengthy and unpredictable course for Washington. Or the Chinese government might whisk him away for questioning, viewing him as a useful source of information. Or he might end up being grabbed and bundled into a plane bound for US territory.

"Yes, I could be rendered by the CIA. I could have people come after me. Or any of the third-party partners. They work closely with a number of other nations. Or they could pay off the Triads. Any of their agents or assets," he said.

"We have got a CIA station just up the road – the consulate here in Hong Kong – and I am sure they are going to be busy for the next week. And that is a concern I will live with for the rest of my life, however long that happens to be."

Having watched the Obama administration prosecute whistleblowers at a historically unprecedented rate, he fully expects the US government to attempt to use all its weight to punish him. "I am not afraid," he said calmly, "because this is the choice I've made."

He predicts the government will launch an investigation and "say I have broken the Espionage Act and helped our enemies, but that can be used against anyone who points out how massive and invasive the system has become".

The only time he became emotional during the many hours of interviews was when he pondered the impact his choices would have on his family, many of whom work for the US government. "The only thing I fear is the harmful effects on my family, who I won't be able to help any more. That's what keeps me up at night," he said, his eyes welling up with tears.

'You can't wait around for someone else to act'

Snowden did not always believe the US government posed a threat to his political values. He was brought up originally in Elizabeth City, North Carolina. His family moved later to Maryland, near the NSA headquarters in Fort Meade.

By his own admission, he was not a stellar student. In order to get the credits necessary to obtain a high school diploma, he attended a community college in Maryland, studying computing, but never completed the coursework. (He later obtained his GED.)

In 2003, he enlisted in the US army and began a training program to join the Special Forces. Invoking the same principles that he now cites to justify his leaks, he said: "I wanted to fight in the Iraq war because I felt like I had an obligation as a human being to help free people from oppression".

He recounted how his beliefs about the war's purpose were quickly dispelled. "Most of the people training us seemed pumped up about killing Arabs, not helping anyone," he said. After he broke both his legs in a training accident, he was discharged.

After that, he got his first job in an NSA facility, working as a security guard for one of the agency's covert facilities at the University of Maryland. From there, he went to the CIA, where he worked on IT security. His understanding of the internet and his talent for computer programming enabled him to rise fairly quickly for someone who lacked even a high school diploma.

By 2007, the CIA stationed him with diplomatic cover in Geneva, Switzerland. His responsibility for maintaining computer network security meant he had clearance to access a wide array of classified documents.

That access, along with the almost three years he spent around CIA officers, led him to begin seriously questioning the rightness of what he saw.

He described as formative an incident in which he claimed CIA operatives were attempting to recruit a Swiss banker to obtain secret banking information. Snowden said they achieved this by purposely getting the banker drunk and encouraging him to drive home in his car. When the banker was arrested for drunk driving, the undercover agent seeking to befriend him offered to help, and a bond was formed that led to successful recruitment.

"Much of what I saw in Geneva really disillusioned me about how my government functions and what its impact is in the world," he says. "I realised that I was part of something that was doing far more harm than good."

He said it was during his CIA stint in Geneva that he thought for the first time about exposing government secrets. But, at the time, he chose not to for two reasons.

First, he said: "Most of the secrets the CIA has are about people, not machines and systems, so I didn't feel comfortable with disclosures that I thought could endanger anyone". Secondly, the election of Barack Obama in 2008 gave him hope that there would be real reforms, rendering disclosures unnecessary.

He left the CIA in 2009 in order to take his first job working for a private contractor that assigned him to a functioning NSA facility, stationed on a military base in Japan. It was then, he said, that he "watched as Obama advanced the very policies that I thought would be reined in", and as a result, "I got hardened."

The primary lesson from this experience was that "you can't wait around for someone else to act. I had been looking for leaders, but I realised that leadership is about being the first to act."

Over the next three years, he learned just how all-consuming the NSA's surveillance activities were, claiming "they are intent on making every conversation and every form of behaviour in the world known to them".

He described how he once viewed the internet as "the most important invention in all of human history". As an adolescent, he spent days at a time "speaking to people with all sorts of views that I would never have encountered on my own".

But he believed that the value of the internet, along with basic privacy, is being rapidly destroyed by ubiquitous surveillance. "I don't see myself as a hero," he said, "because what I'm doing is self-interested: I don't want to live in a world where there's no privacy and therefore no room for intellectual exploration and creativity."

Once he reached the conclusion that the NSA's surveillance net would soon be irrevocable, he said it was just a matter of time before he chose to act. "What they're doing" poses "an existential threat to democracy", he said.

A matter of principle

As strong as those beliefs are, there still remains the question: why did he do it? Giving up his freedom and a privileged lifestyle? "There are more important things than money. If I were motivated by money, I could have sold these documents to any number of countries and gotten very rich."

For him, it is a matter of principle. "The government has granted itself power it is not entitled to. There is no public oversight. The result is people like myself have the latitude to go further than they are allowed to," he said.

His allegiance to internet freedom is reflected in the stickers on his laptop: "I support Online Rights: Electronic Frontier Foundation," reads one. Another hails the online organisation offering anonymity, the Tor Project.

Asked by reporters to establish his authenticity to ensure he is not some fantasist, he laid bare, without hesitation, his personal details, from his social security number to his CIA ID and his expired diplomatic passport. There is no shiftiness. Ask him about anything in his personal life and he will answer.

He is quiet, smart, easy-going and self-effacing. A master on computers, he seemed happiest when talking about the technical side of surveillance, at a level of detail comprehensible probably only to fellow communication specialists. But he showed intense passion when talking about the value of privacy and how he felt it was being steadily eroded by the behaviour of the intelligence services.

His manner was calm and relaxed but he has been understandably twitchy since he went into hiding, waiting for the knock on the hotel door. A fire alarm goes off. "That has not happened before," he said, betraying anxiety wondering if was real, a test or a CIA ploy to get him out onto the street.

Strewn about the side of his bed are his suitcase, a plate with the remains of room-service breakfast, and a copy of Angler, the biography of former vice-president Dick Cheney.

Ever since last week's news stories began to appear in the Guardian, Snowden has vigilantly watched TV and read the internet to see the effects of his choices. He seemed satisfied that the debate he longed to provoke was finally taking place.

He lay, propped up against pillows, watching CNN's Wolf Blitzer ask a discussion panel about government intrusion if they had any idea who the leaker was. From 8,000 miles away, the leaker looked on impassively, not even indulging in a wry smile.

Snowden said that he admires both Ellsberg and Manning, but argues that there is one important distinction between himself and the army private, whose trial coincidentally began the week Snowden's leaks began to make news.

"I carefully evaluated every single document I disclosed to ensure that each was legitimately in the public interest," he said. "There are all sorts of documents that would have made a big impact that I didn't turn over, because harming people isn't my goal. Transparency is."

He purposely chose, he said, to give the documents to journalists whose judgment he trusted about what should be public and what should remain concealed.

As for his future, he is vague. He hoped the publicity the leaks have generated will offer him some protection, making it "harder for them to get dirty".

He views his best hope as the possibility of asylum, with Iceland – with its reputation of a champion of internet freedom – at the top of his list. He knows that may prove a wish unfulfilled.

But after the intense political controversy he has already created with just the first week's haul of stories, "I feel satisfied that this was all worth it. I have no regrets."

Since you're here ...

... we have a small favour to ask. You've read in the last year. And you're not alone. Millions are flocking to the Guardian for open, independent, quality news every day. Readers in all 50 states and in 180 countries around the world now support us financially.

As we prepare for what promises to be a pivotal year for America, we're asking you to consider a year-end gift to help fund our journalism.

Donald Trump's presidency is ending, but America's systemic challenges remain. From broken healthcare to corrosive racial inequality, from rapacious corporations to a climate crisis, the need for fact-based reporting that highlights injustice and offers solutions is as great as ever.

We believe everyone deserves access to information that's grounded in science and truth, and analysis rooted in authority and integrity. That's why we made a different choice: to keep our reporting open for all readers, regardless of where they live or what they can afford to pay. Powerful journalism drives change; this is some of the high-impact reporting that Guardian readers funded in 2020.

In these perilous times, an independent, global news organisation like the Guardian is essential. We have no shareholders or billionaire owner, meaning our journalism is free from commercial and political influence.

If there were ever a time to join us, it is now. Your funding powers our journalism. We're asking readers to help us raise $1.25m to support our reporting in the new year. Every contribution, however big or small, will help us reach our goal. Make a gift now from as little as $1. Thank you.

© 2020 Guardian News & Media Limited or its affiliated companies. All rights reserved. (modern)



/ed70

Friday, September 15, 2017

An Open Letter to Anonymous and LulzSec

This is in response to learning that LulzSec (the original AntiSec crew from June 2011) have been the ones deleting my carefully written notes regarding what it is like to have perfect strangers work to discredit and hurt someone for having a different view than Anonymous and it's various incarnations.


Why can't you just suck it up and get the fuck over it already,


You have been fucking with my friends,, my family and my safety since 2010.

You call yourself a "hacktivist?" Hardly. 


You are simply exploiting my vulnerabilites so you can defend you criminal behavior thinking that the worse I look the better you appear.


You have no purpose to be deleting my files and denying me access to information online that would be helpful to prevent future attacks from scumbags like you.


Quit while you're ahead before you wind up getting arrested, raided or jaded by your own dumb stupidity.


My mental health is fragile but clearly not more so than the state of yours.


I try not to make the same mistake twice. Obviously you dotn feel that placing my life and safety was a OK with you.


Perhaps that's because I haven't told the whole story. Yet. But you are alll up in my Google Drive, iCloud and personal fles deleting and inserting exploits so you can be sure no one ever hears the truth as only I can tell it.


I would think you would want to keep me in check so that I can focus on other things that are more enjoyable.


But no. And if you don't know it yet, you got off really easy. 


You don't think I spoke to the Feds? You bet your ass I did.  Did I give them your name? No, I didn't have to. If they don't know who you are by now, than we are truly fucked.


You had 7 long years to reflect on how your actions and behavior affect the lives of others.  That doesn't matter to you. The weaker the individual, the stronger you strike them.


I have no idea why you came back of a sudden. But now that you're here, it seems like a good opportunity to confront some fundamental facts about your so called reign of terror in June and July 2011.


The First fact that you failed to explain was the images from Stratfor and Gregory Evans were fake. They were hosted images on green squirrel's pseudo-intellectual website. When I tried to copy them I learned that this is practice yet engaged in to spread disinformation to the public and the law.


Two: Stop pretending like you did the world a favor by taking down Joe Blacks site. It was Abhaxas who went round for round with Joe. You just like to talk about it.


Third: Despite your repeated claims that you hacked Black & Betg CyberSecurity and that couldn't be further from the truth. You sent a 21 year old Iranian Hacker, Reza Rafarti (from Cyberwarzone.com) who distributes malware and probably Stuxnet and Scada along with Anon Software but he did not HACK Black & Berg. Joe Black gave Reza Rafarti ADMIN privs on the site madness jadedsecurity asked him about and I have the whole conversation from 2011. 


Much like Jaded and crew had a direct entry point into my website since Cliff Sullivan (of PC Insecurities in UK) was hosting my site for Yenmi Agbebi as a favor yet wound up selling me out to be accepted by the cool kids in Anon. He had access to my site, and and appealed to ny genuine concern for Gary McKinnon and other ethical hackers being extradited to the US and charged with serious crimes. 


But the arrests for SOCA and LulzSec were teenage boys like Ryan. Cliff Sullivan is milddle ages has been wannabe with a kid a bad case of severe depression. 


If the US wants to make an example out of overseas hackers I suggest they go after Cliff @cliffsull as

I have more than enough evidence to show that he was the one hosting my site when it went into DDoS and passed malware to unsuspecting visitor. 


So which on of you is redirecting my personal blogs which have NOTHING to do with you but everything to with shady methods and illegal hacking and fraud. 


Over in the land of Lulz Trolls and that damn Nyan cat you and your friends try and think of new ways to torture and torment me cuz the the mentally ill don't already have enough problems.


What kind of man has to use sextortion to get a bitch to drop her panties. And as for the reward you offered to the first one to bring you titty pics. Well, I would like to collect on that and post them myself.


You need to be in a psych ward with the rest of the people you've tormented.


How far will you take this before one of us gets killed. You posted my address and Nazis show up to throw bricks through my window. As I said I said I have no idea what it's going to take for you to just leave me the fuck alone. You know damn well I can't remove any of those posts because you're the one moderating them.


I wish I could finish and put all of this to rest for my own peace of mind but I have to evacuate with $25 bucks in my hand because my PayPal was hacked.


Surely you've crossed the line between a creative quirky Aspie type hacker to just fucking insane.


Wondering if this how if Aaron Swartz has people hunting him down before he took his own life. You pushed Joe Black to the point where he became violent and attacked his mother and his girlfriend and had to be institutionalized for psychosis.


You KNEW that he was having a full blown psychotic break and you continued to put others at risk.
That's where we are different. I don't mind some savage trolling but you enrage people to the point where they act out violently against the world.


Some people go through tremendous situations and come out stronger in the end. They rise to the occasion and learn to give others the support they so desperately needed.


Aaron Swarz left behind a legacy that will live in our hearts for future generations to enjoy.


I have gone through some terrible things and people like yourself are there to remind me daily of every mistake I ever made.


Now you have sunk to a new low. You are actively destroying the living legacy I left behind should they need someone to relate to.


You are violating accepted practices and open source terms of service. This is plain as day.


You have profited off my shame and public humiliation pimping out ElyssaD swag at DefCon and all over the web. You told people you would donate the money to help the mentally ill. I suppose that is closer to the truth since you pocketed the money and you are by far sicker than I realized.


I made a choice not to be a victim. Don't make one anyone else a victim because you want attention.


 You are NO Aaron Swarz, Gary McKinnon or Lauri Love. No one will care if you get extradited or go to jail because I'll be right there in the courtroom to give expert testimony about the depths of your sociopathy.

You are not an ethical hacker doing a pen test. You just lost the only surviving witness to your reign of terror. 


Sure, Sabu, Lamo a few others are home free. But it was Chelsea Manning, Aaron Swarz, Gary McKinnon and Lauri Love who did the heavy lifting. And Abhaxas did yours. 


They would no doubt recognize who the stronger advocate for open source and creative licensing. I may not be able to code but that doesn't give you the right to abuse people who need your skills rather more than you need to flex online for Black Hat community.


I've made many mistakes picking sides before I had adequate information.


I most definitely made the right call when I tossed you to the curb along with the rest of your cronies.


So no matter what you do to humiliate me, it just shows your incredible disregard for the cause you claim to be advocating. I have just as much right to be here as you do. Someone needs to leave notes for historians who will wonder how and where it all went wrong.


P.S. You would think your crew would know better than to impersonate an officer and FORGET to disable his caller ID. Tell Lance Miller and Anthony Freed they're next. Then your whole damn forum. 


That I can do.


Internet Crime Tips 

-- 
Elyssa Durant, Ed.M.

"You may not care how much I know, but you don't know how much I care."



______________________________

Saturday, November 28, 2015

The Paranoid's survival guide: Protect your privacy on social, mobile and more


The paranopid's survival guide, part 2: Protect your privacy on social, mobile and more

by ROBERT L. MITCHELL | 

Is privacy dead? Not by a long shot. While you can't control everything that's out there about you, there's quite a bit you can do to reduce your data footprint -- or at least avoid adding to it. For this series, Computerworld asked nine privacy experts for tips and tricks they use for keeping their own personal data profiles on the down low.

Whether your goal is avoiding tracking by marketers, ensuring your personal safety or protecting yourself from government surveillance, there are steps you can take to minimize your exposure both online and off, these professionals say.

Part 1 of this series covered how to maintain your online privacy and surf the Web without leaving a data trail. Here, in part 2, we offer advice on how to approach social media, messaging and some general rules you should follow when using mobile apps. Part 3 covers how to minimize your offline data footprint, and where to go to opt out. (For more tips, also see our "60-minute security makeover: Prevent your own epic hack.")

3 ways to shape up your social media

Don't sign up for a new service using Facebook or another social networking account

When a website tells you it's easier to register for its service using your Facebook account, what they really mean is that it's easier for them to pull all available information about you from that site and use it to build a profile on you, says Rob Shavell, co-founder and CEO at privacy software vendor Abine. Always choose the "sign up with email" option, and don't use the same email address you use for Facebook or other social media accounts.

Lock down those social network privacy settings

Review and set the privacy settings for every online service you use, and revisit those policies regularly to update them, as the services tend to change their policies frequently, says Jules Polonetsky, executive director of the Future of Privacy Forum. "Make sure you lock down the settings in every social media profile, and test it to see what others can see about you," he suggests.

Think before you post

On social networks nothing is truly private. "Be aware when you post with whom you are sharing," says Sid Stamm, senior engineering manager for security and privacy at Mozilla. What you post can be used against you, either now or in the future -- by snooping government agencies, political operatives, potential employers or online marketers that want to serve up interest-based advertising.

Even when you delete a post it's likely to persist. Your "friends" can copy/paste anything visible to them into other sites or email messages. And with Twitter your posts are part of the public data feed that's routinely captured by data brokers and others interested in analyzing that data. "The act of deleting just means removing the visibility on Twitter," says Robert Hansen, a security researcher and director of product management at the website-security vendor WhiteHat Security. But every data broker or other organization that has consumed your Twitter feed between the time you posted and the time you deleted the message still has the data.

Don't post photos of your kids, your interests or when you'll be going on vacation, he adds. "If it's something I even briefly pause about, I don't put it on social networks. Treat everything in social networks as adversarial, and then you don't have to worry about it."

Online job sites and online dating sites are the two areas where people give up way too much information about themselves, says Casey Oppenheim, co-CEO at anti-tracking software vendor Disconnect. "Your name, address, where you went to school -- all of that information about you can be used to answer challenge questions," he says. Online dating sites may use questionnaires to collect extensive psychological and demographic data in an effort to build very detailed profiles that may be retained even after you close your account.

Page 2 of 3

Manage your messaging

Secure your email

Be sure to enable HTTPS encryption for all email communications in transit. As for email data in your inbox, a hosted private email service that you pay for, from a company such as Rackspace, offers more privacy than does a free, public Webmail service such as Gmail, while hosting your own email server on premises offers the most privacy of all.

There are many exploits out there for compromising Webmail services, says Hansen. What's more, the content of email hosted on free Webmail services may be used to allow advertisers to send interest-based advertising. Also, government agencies can access your data on Webmail or hosted email systems at any time by simply presenting a subpoena -- and the provider may be prohibited from telling you about it. With an internally hosted server, a search warrant would be required, and you would be aware of the action.

Use a privacy-oriented email service

Popular Webmail services such as Gmail and Yahoo Mail offer a free account in exchange for collecting data about you and analyzing your email activity for marketing purposes. If that bothers you, consider a free service not supported by advertising, such as Zoho Mail, or use an email account provided by your ISP.

For even greater protection, use a secure email service that's dedicated to protecting your privacy, such as Riseup or MyKolab. Services like MyKolab, which hosts your email data offshore and out of reach of the Patriot Act, may make your data less prone to U.S. government snooping.

Use a self-destructing text/chat service

Instant messaging/texting services that encrypt your communications and don't retain your chat history have gained critical mass among young people, and for good reason, says Polonestky. "No one records [verbal] chit-chat, but when I have that conversation online it's somehow part of the national archives. It shouldn't be. It's the kind of communication that should work as a shout out and be fleeting," he says.

Polonestky uses Frankly Chat, which he calls "Snapchat for adults," but says other popular services including Snapchat itself or Whisper also work well. Whisper is an anonymous social network, and Snapchat allows users to set time limits for how long their posts will appear.

Oppenheim recommends Silent Text and TextSecure. The downside of these services is that the person you want to message must have the same app installed and running before you can connect. So, depending on which service your friends use, you might need to keep more than one app running.

Mobile protections

Limit tracking on your mobile phone

Mobile phones offer more limited options for minimizing your online footprint, says Justin Brookman, director, consumer privacy at the Center for Democracy & Technology. Your carrier knows your location, the calls you make, the sites you visit, the texts you've sent and received and the apps you use. Unless you turn off your phone, your carrier will always know where you are, he says. And while you can't opt of out all data collection, your carrier may offer options that let you limit how it uses and shares that data.

Password-protect your smartphonestablets and other personal computing devices, and configure the "find me" feature or app for mobile devices. "The first thing to do is to make sure that if you ever lost the device you can get it back and lock it down. This is half security, half privacy," says Chris Babel, CEO at security vendor Truste.

Page 3 of 3

Use a password manager and two-factor authentication

Password managers not only keep track of your online user names and passwords and generate strong passwords, Babel says, but most also have an auto-fill feature that protects your account credentials from key logger malware that may be watching you. (It's especially important to use a strong password for your email account, since it contains a trove of personal information about you, and most online accounts use your email address to allow you to reset forgotten passwords.)

If you already use a password manager -- either on your desktop as a standalone app or in your browser -- check to see if it has a mobile component. Many do.

For additional protection, consider a password manager such as LastPass that supports two-factor authentication. Even if someone guesses your master password they still won't be able to get at your password database without physical access to your device.

Don't share your location information

"You can control who you give location permission to on most mobile devices, but you can't control" with which other apps are given that data. "So choose carefully," says Brookman. Social media updates that include location data also tell people where you are -- and where you aren't. Do you really want everyone on Twitter, or all of your Facebook friends -- and friends of friends -- to know? "Don't turn on location services unless you really need it," says Oppenheim. And turn it off when you're done.

Turn off your Wi-Fi and Bluetooth to avoid retail tracking

Today you walk into a store and the retailer doesn't know much about you. "But stores are installing listening devices to detect mobile phones with Wi-Fi turned on that are actively looking for access points," says Brookman. Before long, it won't just be your mobile carrier and mobile apps that know where you are at all times. Retailers and other businesses want to use the combination of Bluetooth and Wi-Fi signals emanating from your smartphone to track you when you enter a store or other place of business.

"When I walk into the mall they will know I've entered because my device is pinging Wi-Fi. And with Bluetooth they can track me within 30 to 50 feet. They know where I'm walking," says Babel. When your phone queries the store's wireless router to search for connectivity option, the business captures the unique MAC address associated with your phone's Wi-Fi hardware. If you then make a purchase, your MAC address can be combined with other information the store has to identify you. Some consumers might want to announce themselves, Babel says, because they're hoping to receive special offers on their smartphones. But if you're paranoid, says Brookman, turning off Wi-Fi and Bluetooth solves the problem.

If you can't be bothered to toggle those services off every time you leave your home or office, anti-virus software vendor AVG recently rolled out a service called PrivacyFix that automatically turns off your mobile Wi-Fi if the network you're passing by isn't on your whitelist. Mobile apps like Tasker for Android can be configured to use a technique called "geofencing" to turn off Wi-Fi when you leave your home or office and turn it back on when you return.

Soon you may have another option: The Future of Privacy Forum is in the process of creating a service called Do Not Track My Mac -- to be hosted at smartstoreprivacy.org -- that will let users opt out of tracking by retailers that want to capture your smartphone's Ethernet MAC address.

The companies agree not to capture your name or link your information to your MAC address unless you opt in, says Polonetsky. However, they can still track your MAC address anonymously unless you opt out. The data is used for general analysis purposes, such as to determine the average wait time in cashier lines, for example, or to study how traffic moves through the store. So far, 10 companies have signed on, Polonetsky says.

Next: How to minimize your offline data footprint, and where to go to opt out.

This article, The paranoid's online survival guide, part 2: How to protect your personal data, was originally published at Computerworld.com.


^ed 
Sent via iPhone

Wednesday, October 28, 2015

Back in Pastebin October 29, 2015

I started this private site after my name, ID, medical and financial info was stolen, made public in Pastebin, and sold on T-shirts at the DefCon hackers conference. I never got one penny for the T-shirts and apparel sold and was never reimbursed for the damage done to my computer equipment and mobile devices as a result of HARD CORE hackers. I was promised the T-shirts and promo ads would be pulled from the event and the black hat hackers known as Lulz, AntiSec, (Sabu and Co.) would take them down and refrain from using my likeness for promotional purposes. They were not. They used my name, my likeness, my photos, my social security number, my ID, my address and more to create a slew of fake social media accounts to post insane bullshit across a variety of platforms. They even socially engineered my closest friends and family members in various forums to reinforce the charade. They claimed the T-shirts were for charity and that $1.00 would be donated for every ELyssaD garment sold. Not only did I not receive any such monies, I am quite certain these wits have no idea how serious it is to impersonate a 501(c)3. So not only did they make a profit from exploiting every aspect of my life, they harassed my friends, impersonated an ex-cop who has been one of most trusted allies and confidant; threatened friends who dare to speak up on my behalf by calling them on the phone and identifying themselves as law enforcement. ANOTHER felony. They made a profit. They offered a reward for tittie pics, had podcasts, comic books and sold a line of women's apparel to promote their podcasts, show and of course, make money. They created multiple fake identities on various social media platforms. They pwned my website, social media accounts, linked in, private forums, etc... harassed my friends and posted my fathers home address on the internet. They altered personal documents they stole from my private files, altered them, and had the nerve to put the FAKE documents back in to my web albums and made them public. ONE LOGIN = ONE FELONY Destruction of evidence (especially records that pertain to employee benefits is a whole other class of crimes) These individuals are clearly guilty, and have no problem advertising their skills across the hacker community. They destroyed my professional credibility with disinformation writing posting ridiculous website entries that present my professional certifications as a practicing therapist to make them appear as if I was the patient not the provider. 65 "people" impersonating me on social media platforms? My friends, sister, brothers, my mother, and even "Agent Daddy" became targets as well. I started this site hoping for a do-over. My name is ELyssa. ELyssaD and, for he record I've never done midget porn!

image1.PNG


image2.PNG

image3.PNG




I didn't see this one coming. 




^ed 
Sent via iPhone

Sunday, June 7, 2015

Cyber attack hits millions of federal workers


China in focus as cyber attack hits millions


Cyber investigators linked the breach to earlier thefts of healthcare records from Anthem Inc, the second largest U.S. health insurer, and Premera Blue Cross, a healthcare services provider.

In the latest in a string of intrusions into U.S. agencies' high-tech systems, the Office of Personnel Management (OPM) suffered what appeared to be one of the largest breaches of information ever on government workers. The office handles employee records and security clearances.

A U.S. law enforcement source told Reuters a "foreign entity or government" was believed to be behind the cyber attack. Authorities were looking into a possible Chinese connection, a source close to the matter said.

A Chinese Foreign Ministry spokesman said such accusations had been frequent of late and were irresponsible. Hacking attacks were often cross-border and hard to trace, he said.

The FBI said it was investigating and aimed to bring to account those .

Several U.S. states were already investigating a cyber attack on Anthem in February that a person familiar with the matter said is being examined for possible ties to China.

John Hultquist of Dallas-based iSight Partners told Reuters that the latest attack on OPM and the earlier breaches at Anthem and Premera Blue Cross appear to have been the work of cyber espionage hackers working on behalf of a state, not those focused on cybercrime.

He said they may have widened their net to gather personally identifiable information for more elaborate, finely-tuned attacks in the future. "This is usually done by criminals, but based on their behavior, we believe these are espionage actors," said Hultquist.

MALICIOUS ACTIVITY

OPM detected new malicious activity affecting its information systems in April and the Department of Homeland Security said it concluded at the beginning of May that the agency's data had been compromised and about 4 million workers may have been affected.

The agencies involved did not specify exactly what kind of information was accessed.

The breach hit OPM's IT systems and its data stored at the Department of the Interior's data center, a shared service center for federal agencies, a DHS official said on condition of anonymity. The official would not comment on whether other agencies' data had been affected.

OPM had previously been the victim of another cyber attack, as have various federal government computer systems at the State Department, the U.S. Postal Service and the White House.

Chinese hackers were blamed for penetrating OPM's computer networks last year, and hackers appeared to have targeted files on tens of thousands of employees who had applied for top-secret security clearances, the New York Times reported last July, citing unnamed U.S. officials.

"The FBI is working with our inter-agency partners to investigate this matter," the bureau said in a statement. "We take all potential threats to public and private sector systems seriously, and will continue to investigate and hold accountable those who pose a threat in cyberspace."

The U.S. government has long raised concerns about cyber spying and theft emanating from China and has urged Beijing to do more to curb the problem.

Chinese Foreign Ministry spokesman Hong Lei told a regular daily news briefing in Beijing that China hoped the United States would have more trust and cooperate more.

"Without first thoroughly investigating, always saying that 'it's possible', this is irresponsible and unscientific," said Hong.

There was no comment from the White House.

Since the intrusion, OPM said it had implemented additional security precautions for its networks. It said it would notify the 4 million employees and offer credit monitoring and identity theft services to those affected.

RASH OF ATTACKS

"The last few months have seen a series of massive data breaches that have affected millions of Americans," U.S. Representative Adam Schiff, the ranking Democrat on the House Permanent Select Committee on Intelligence, said in a statement.

Tens of millions of records may have been lost in the attacks on Anthem and Premera Blue Cross.

iSight's Hultquist said similar methods, servers and habits of the attackers pointed to one state-sponsored group being responsible for all three breaches.

The largest federal employee union said it was working with the administration to ensure measures were taken to secure the personal information of affected employees. "AFGE will demand accountability," American Federation of Government Employees President J. David Cox Sr. said in a statement.

In April, President Barack Obama responded to a growing rash of attacks aimed at U.S. computer networks by launching a sanctions program to target individuals and groups outside the United States that use cyber attacks to threaten U.S. foreign policy, national security or economic stability.

The move followed indictments of five Chinese military officers who were charged with economic espionage. U.S. officials also pointed the finger directly at North Korea for a high-profile attack on Sony over a film spoof depicting the assassination of North Korea's leader.

China has routinely denied accusations by U.S. investigators that hackers backed by the Chinese government have been behind attacks on U.S. companies and federal agencies.

U.S. military officials have become increasingly vocal about cyber espionage and attacks launched by China, Russia and other rivals. A Pentagon report in April said hackers associated with the Chinese government repeatedly targeted U.S. military networks last year seeking intelligence.

(Additional reporting by Doina Chiacu, Mark Hosenball, Peter Cooney and Jeff Mason; Writing by Matt Spetalnick; Editing by David Gregorio and Alex Richardson)

Saturday, May 9, 2015

Website Hacking 101

Website Hacking 101 : Part II : InfoSec Institute
by Ivan Dimov, resources.infosecinstitute.com
August 28
To view Part I of this article, please visit http://resources.infosecinstitute.com/website-hacking-101/.

In this Part, we are going to briefly introduce Path Traversal, usage of Delimiters, and Information Disclosure attack.

Wee are going to present simple solutions to simplified problems involving the attacks.

Content

Exercise 8: Path Traversal

Figure : A simple webpage in which you choose an article and view it

The website (index.php) in the PathTraversal folder contains a simple form which submits to the same page through the GET request method. Once a choice of article has been made and “View article” has been clicked, the following PHP code executes:

<?php
//If the article GET parameter is set
if (isset($_GET["article"])) {
// Create a div block and fill it with the contents from the file in the GET value.
        echo "<div id='article'>" . file_get_contents($_GET["article"]) . "</div>";
}
?>
The result is the following URL: http://localhost/2/PathTraversal/?article=1.htm

It loads the relevant article file placed in the GET method. The parameter article is formed via:

<select name="article" required=""></select>
And the values are also directly given through the HTML code (the value attribute):

Domain Slamming

Now, legitimate users will use the interface provided in the website to browse it, but with the code as it is we can easily open myriad files they do not want you to open by directly tampering with the URL parameters. Many websites have config directories where they store important data – let’s see if you can do it.

Tasks
Go back one directory and open openme.txt by changing the URL parameters.
We assume that we cannot open the folder config from our computer but only from the local server. Assume you do not know what files there are in the directory. First, you should check whether the directory exists.
The directory exists and now we know that there is HTTPAuth in place. Your task is to somehow find out the username and the hashed password for the folder without using any brute-force or dictionary attacks on the username and password.

Spoiler (Task 2)
If we know that there is a HTTPAuth security mechanism in place, then we can automatically deduce there is an .htaccess file. Therefore, we can open the .htaccess file that we would not be able to open normally via the path traversal vulnerability of the article viewer page.

Figure: Viewing the .htaccess file from the article viewer page

We type http://localhost/2/PathTraversal/?article=config/.htaccess and now we know the path and the file in which accounts and passwords are stored as well as the user that is required to view the folder.

We type the path to the userlist.htpasswd file and get all usernames and passwords:

tomburrows:$apr1$ZF.78h2N$zhAaP2AY6VwxuELizJAwg.

Now, the username is known and we have incredibly reduced our cracking time. HTTPAuth is using UNIX’s “CRYPT” function to encrypt the passwords which is a “one way” encryption method.

Using path traversal, we can also go back several directories and browse to the php.ini and other important configuration files as well.

A sample solution to our path traversal vulnerability
<?php
//If the article GET parameter is set

if (isset($_GET["article"])) {
//Remove any “/” and “.” characters from the GET parameter’s value as this can be used for path traversal 
        $article = str_replace(array("/", "."), "", $_GET["article"]);
// If the file does not exist, print a custom error.
        if (!file_exists($article . ".htm")) {
        echo "<h1>The article does not exist!</h1>";
        }
        else {
//If and only if the file exists – echo out its contents

// Create a div block and fill it with the contents from the file in the GET value.
//Add a mandatory file extension of .htm to the file
        echo "<div id='article'>" . file_get_contents($article . ".htm") . "</div>";
        }
}
The change in the HTML code is that we no longer use the full file name value in the options tags, we just use the name of the file (without its extension so only .htm files would be allowed)

Want to learn more?? The InfoSec Institute Ethical Hacking course goes in-depth into the techniques used by malicious, black hat hackers with attention getting lectures and hands-on lab exercises. While these hacking skills can be used for malicious purposes, this class teaches you how to use the same hacking techniques to perform a white-hat, ethical hack, on your organization. You leave with the ability to quantitatively assess and measure threats to information assets; and discover where your organization is most vulnerable to black hat hackers. Some features of this course include:
Dual Certification - CEH and CPT
5 days of Intensive Hands-On Labs
Expert Instruction
CTF exercises in the evening
Most up-to-date proprietary courseware available
VIEW ETHICAL HACKING

 Keyloggers: How They Work and More
Firstly, checking if the file exists and echoing it out only if it exists prevents another attack – that of information disclosure.

There is a PHP warning thrown out if we type a non-existent file deliberately. Of course, another way to resolve such information disclosure issues is by turning off the display_errors In the php.ini file (this is most desirable if the site is live anyway).

With the above mentioned code we get a clean and neat error that the article does not exist, along with prevention of any path traversal attempts.

Figure: We now receive an error when we try to go back one directory and open the openme.txt file

Note: in old editions of PHP (older than 5.5.3) you could use the %00 marker to end the string abruptly and pass your own file extension in place of the “.htm” one in our solution code.

if (!file_exists($article . “.htm”)) could be exploited in older versions of PHP by typing:

http://localhost/2/PathTraversal/?article=accounts.txt %00

Which is equivalent to:

“accounts.txt.htm” forcing the server to ignore the .htm part of the string.

Exercise 9: Information disclosure

Figure: Comment page

For this exercise, I have created a working but problematic comments page which looks similar to a chat. You have to write a comment, and then you view all the comments up to now. The comments are stored in a .txt file rather than in a database and there is one PHP file that creates new comments and one that displays them on the screen.

//Index.php server-side code

        <?php
                $path = "comments/";
                ?>

                <?php 
                        if ($_SERVER["REQUEST_METHOD"] === "POST") {
                                include("add_comment.php");                   

                        }

//Add_comment.php
<?php 
                        //Open file and create an array with all comment information as indices
                        $comments = file_get_contents($path . "comments.txt");
                        $newcomment = [];
                        $newcomment[] = $_POST["name"];
                        $newcomment[] = $_POST["topic"];
                        $newcomment[] = $_POST["message"];
                        // Convert to string and add a delimiter to store in file
                        $newcomment = implode(":", $newcomment);
                        // Write the string to the file
                        $comments_w = fopen($path . "comments.txt", 'w');

                        fwrite($comments_w, $comments . "n" . $newcomment . ":" ); 
                        // Show all comments
                        include($path . "view_comments.php");

                        ?>
Figure: How the comments file looks

// View_comments.php

        <?php
//Convert to array and echo all out in a certain format within the comments div
$comments = explode(":", file_get_contents($path . "comments.txt"));
echo "<div id='comments'>";
for ($i = 0; $i < count($comments) - 1; $i += 3) {
        echo "<p>User: " . $comments[$i] . "<br> posted about: ".
        $comments[$i + 1] . "<br> and he wrote: " . $comments[$i + 2];
        echo " </p>"; 


}
echo "</div>";

?>
This application works just fine when viewed as is, but imagine if a user enters add_comment.php separately, without the file being included from the index.php. This can easily happen as the name of the service implies the file name, and this particular file name is frequently used, and the fact that add_comment.php is in the same directory facilitates the process.

Figure: Viewing add_comment.php on its own

Now, the attacker would know that we have a variable called $path and he can probably guess that we are setting the path to the comments file as there is a warning that file_get_contents(comments.txt) cannot be opened. Thus, he knows the name of the file that contains all our comments as well. Because the include is failing, he also knows the whole include_path which can also be dangerous. Also, the attacker knows another file in our directory tree (view_comments.php) so he can access it and look for some more errors. He also knows that in this file we are working with the POST values from the form, as he can view the HTML and see they are the same.

This comments form is also vulnerable to diferent code injection attacks. You can easily insert in one of the comment fields to test it out. In that way, the browsers of the users’ will execute any code that you like each time they visit the page.

A probable solution is easy: wrapping the post values in htmlspecialchars() function which converts < and > amongst others as special characters (<, >, etc.) preventing them from being interpreted as code.

$newcomment[] = htmlspecialchars($_POST["name"]);

$newcomment[] = htmlspecialchars($_POST["topic"]);

$newcomment[] = htmlspecialchars($_POST["message"]);

Solution

A simple solution to get rid of all those errors in this example is to wrap the code in add_comment.php and view_comments.php inside the following if statement:

        if (isset($path)) {     
//code here

}
In that way, the code will only execute if the files are included from index.php, presumably.

Of course, that does not handle the issue that users can post the form empty and still view the content and make the application think there is an actual comment, but that can easily be fixed and is not the issue of discussion here.

Displaying errors is good for development purposes but when the application is live and in production – always turn off display_errors from the php.ini

Exercise 10: Delimiters

We will be looking at a vulnerability similar to the one that existed in the old Poster website.

Sometimes, parameters used In the code can be abused by users even when interacting with the interface provided to them.

Open Delimiters folder from your localhost in a browser. There is a users.txt file which contains all the user data. However, access to it is forbidden from the .htaccess file:

<Files "users.txt">
Deny from all
</Files>
Try to open it using the path traversal method of the article viewer, just for practice.

Look at the different data stored there and think about what everything represents.

Try to login with one of the accounts and escalate your privileges to “admin” just by communicating with the website as normal.
Spoiler
http://localhost/2/PathTraversal/?article=../Delimiters/users.txt

//The path in the GET should be valid, but you should fill the path to the index.php.

It should be clear that the “:” character is the delimiter between the different values.

You can test on the login form, but it should be clear that the first word before the first delimiter is the username, the second is the password and the third is the user’s privileges.

The code that extracts the user data one line at a time is the following:

$userlist = fopen('users.txt', 'r');
while (!feof($userlist)) {
        $line = fgets($userlist);
        $acc_details = explode(":", $line);
        $username = $acc_details[0];
        $password = $acc_details[1];
        $access = $acc_details[2];
Then, each line is checked separately with the submitted details to check whether It matches with them:

if ($username === $_POST["name"] && $password === $_POST["pass"]) {
When it find a match, the user can be logged in.

Note that there are many better alternatives than this nowadays, such as using a database and cookies.

When logged in, you have the option to change your username or/and password.

if (isset($_POST["pass"]) && trim($_POST['pass']) !== "") {
                        $userlist = str_replace /* old pass */ ($_POST["userdata-pass"],  */ new pass */$_POST['pass'], $userlist);
                        echo "<em>Password changed to: " . $_POST['pass'] . "</em>
";
And to check the privileges, the script merely checks if there is a substring “admin” in the $access variable.

if (stripos($access, "admin") !== false) {
        echo "<img src="administrator.png" alt="admin" width="480" height="480" /></pre>
<h1>Howdy, admin!</h1>
<pre>
";
}
Thus, it should be clear that you can abuse this mechanism by adding the : delimiter after your password and typing admin after it when you change your password.

Solution to this vulnerability
The solution is easy and is the same as the previous exercise.

We change the code slightly:

                if (isset($_POST["usrname"]) && trim($_POST['usrname']) !== "") {
                        //We remove any delimiters in the new account details an add it to a var
                        $newacc = trim(str_replace(":", "", $_POST["usrname"]));
                        //Then, we replace the old password with the $newacc variable
                        $userlist = str_replace($_POST["userdata-acc"], $newacc, $userlist);
                                echo "<em>Username changed to: " . $_POST['usrname'] . "</em>
";
                }
Besides sniffing and other problems, this website is again vulnerable to probability of information disclosure, as the last iteration of the while loop spills out an empty line and a PHP error would occur each time a wrong password is submitted unless display_errors is set to off.

You can do the following to avoid this as well:

if (trim($line) === "")
                break;
Conclusion

Sometimes the solutions to vulnerabilities are really simple and do not take too much time, you just have to split the application into pieces and test them all apart from the single whole that is the application itself.