Where The Web Is Weak



By Andy Greenberg, Forbes.com

Tolstoy wrote that happy families are all alike, while every unhappy family is unhappy in its own way. Something like the opposite might be said for Web sites. Many of the Web's millions of insecure pages can be hacked with just one or two tricks. But patching the bugs in each of those vulnerable sites requires a unique solution.

Case in point: Last month, a single attack ripped through the Web, infecting more than half a million sites including those of the Department of Homeland Security, the United Nations and the British Government. Using Google (nasdaq: GOOG - news - people ) searches, the attackers' software--written partly in Chinese characters--identified sites vulnerable to a hacking technique called SQL injection and infected them en masse with malware designed to steal the bank codes of the sites' visitors. (See " Google Hacking Goes to China.")

In late April, the sites hosting that malware were identified by security researchers who in turn notified the Chinese Internet service provider and had them disconnected from the Internet. But the job of cleaning up the Web's mess, says Jeremiah Grossman, the chief technology officer of White Hat Security, is far from over.

In fact, Grossman says that the majority of those sites remain vulnerable to the same attack. The typical SQL injection vulnerability, he says, takes a site's owner more than four months to locate and fix. That's because, unlike exploits that affect a typical software program, Web vulnerabilities can't be secured with an update downloaded from a vendor--every site has its own bug to excise.

"We can't issue a mass patch," says Grossman. "Each issue is unique. Together they present an almost catastrophic problem."

In Pictures: Eight Ways To Hack The Web

The 500,000 or so sites compromised in the latest attack are just a fraction of the threat to the Web. In a study released last February by Google, more than 3 million of the 60 million pages analyzed were found to invisibly download malicious software to users' computers. According to the study, about 1.3% of Google searches turned up at least one of those malicious pages, more than triple the percentage of malicious results from just eight months earlier.

The number of legitimate sites vulnerable to being hacked and corrupted with malware that infects visitors is far higher still. According to White Hat Security's most recent analysis of about a thousand major Web sites, 16% were vulnerable to SQL injection, an exploit based on mixing malicious commands with innocent user input to gain access to a site's server. Fully 65% of the sites analyzed were vulnerable to another exploit known as cross-site scripting, which can mix malicious elements into a legitimate site when a user clicks on a carefully crafted link.

Grossman has also repeatedly warned of another common Web vulnerability he calls a "sleeping giant." So-called "cross-site request forgery" can be used to steal information from many password-protected sites. If a Web user logs in to a Web service and then is tricked into visiting a compromised page, the second malicious page can steal the user's "cookies"--files collected by his browser used to verify his identity. Those identifying files give the coders of the malicious page temporary access to whatever sensitive information can be found on the password-protected site.

The persistence of vulnerabilities like these, says Johannes Ullrich, who teaches a class on Web vulnerabilities at the SANS Institute, is partly a cultural problem. To patch a vulnerability before it's exploited, an enterprise's security team has to convince Web developers to devote their resources to what may seem like a minor issue--but a big-time drain. Making fixes often involves wading through thousands of lines of code, Ullrich says, in some cases written by developers who left the company long ago.

Last month's massive round of SQL injections was the largest-ever round of malicious Web hackings, but hardly the first. Last February, the server hosting the Dolphin Stadium Web site was compromised just before the Superbowl began. In June, thousands of Italian-language sites were similarly targeted with SQL injections in an incident that security researchers now refer to as "the Italian Job." The same Internet service provider that hosted those sites was attacked again in early May, infecting another round of sites with malware designed to exploit users.

But securing the Web isn't just about protecting sites' visitors, Ullrich argues. It's also about protecting a company's own data. The attackers who used SQL injections to plant malware on hundreds of thousands of sites last month, for instance, could just as easily have stolen corporate data. "If the attackers hadn't left a trail by inserting malware on the sites, we probably wouldn't even have known that they had gained access to the databases," Ullrich says.

Even for a security conscious business, protecting against Web attacks isn't easy, Ullrich says. Because a Web page has to be accessible by all visitors, keeping out cybercriminals isn't as easy as building a firewall. "You can't block all visitors to your Web site. So quite frankly it comes down to the fact that only the code itself prevents an attacker from accessing your database," he says. "The Web is simply a very thin layer of defense."

Labels: , , ,

Modding and Hacking Your Cell Phone



By M Silvers

So, you own a Motorola V3 Razor. If you are doing what I did you are searching various websites to find how how to change it to be what YOU want. You are reading things like "seems", "flashing", "flexing". What the heck?

You're confused, lost, and ready to pay somebody to do this, or give up. But don't. I am by no means a computer expert or a modding guru but I have figured it out so that means you can to!
Lets talk about modding and or hacking (changing anything from how it came from the manufacturer) Hack? No Im not taking about anything illegal, but the term is used to express the idea. You "hack" into an area of the phone or Ipod the manufacturer didn't want you to access :-) Why mod it at all? Well simple. I paid good money for this and if I want my kids picture as my outer LCD picture then by golly I shall have it! lol..Also there are several menu items locked out by certain carriers which I think is bunk anyway but I digress.. The biggest and most common reason for modding is to unlock the phone.


What is unlocking? Simple. Unlocking allows you to take the AT&T sim card out and put in a T mobile Sim card and use the phone. Sim card? you ask..

If you don't know what a sim card is you should stop now and go bake cookies...lmao..not really, It is the card under the battery usually that only allows you to use the phone on that cards carrier. CDMA phones do not have these. Like Sprint, Verizon. Yes you can still mod but unlocking isnt possible. You can just reactivate with whatever CDMA carrier you want :-)

Back to modding..
You can personalize your phone (change the outer picture, make it louder, use different fonts, change the look of it all, etc). Also, changing the software on the phone can increase your reception, your volume, the menu speed, and much more.


Ok now your hooked. How do I do it you scream!

Slow down Tonto..This is complicated stuff so read read read....I got my 500 buck V9 and it took me 4 days to change the outer LCD because I do NOT want a 500 buck paperweight..Do you?
Other basic terms you should know are..


The Flex:
The flex is the files and branding of the phone. It contains all the carrier specific menus and images, like T-Zones for T-Mobile, or whichever graphic branding and text links your carrier puts in the phone.


The Flash:
The flash is the part we change most often. By now we have several types, but basically, the flash is the software of the phone. When you change the flash, it adjusts features, menus, and more. Also, things like the way your phone handles reception or menu speed are handled by flashes. Flashing your phone will not erase any of your media or settings. Then there's the seem.


The Seem:
The seem is the individual pieces that make up the operating system on the phone. Every individual feature on your phone (SMS on/off, will the call end when you close the flip, can you access the web from your phone, etc) is all editable by changing a seem. More on that in the seem editing section, but basically seems are what you will change when you want to change one feature at a time.


So what should you do?
Go to the downloads page and get all the required files and softwares. Backup. then get connected. For some reason this is the single most pain in the butt thing to do for some reason. It should be easy but it isn't. I will do my best to get everything you need in this one place to get you going but feel free to post any questions you have in the forums. Go to
www.hackitz.com for more info.

Article Source: http://EzineArticles.com/?expert=M_Silvers

Labels: , ,