August 23

Smashing the Web for fun & profit using XSS

“an article that fully explains how to inject a JavaScript key logger. This article is dedicated to all this people that believe XSS is not a serious Web application vulnerability.”

10:14 AM | 0 Comments
August 18

ImgShack Scraper

Scrapes the given imgshack server for uploaded images. Change the img219 to a different hostname for different (newer) results. Inspired by a broken version published in 2600.

10:10 AM | 0 Comments
August 13

DNS Tools

About ready for release, we’ve not got all the fancy tools we want to include, but there are some fun/useful tools in this package. Plus we agree to the Franklin Street Statement, which DNS Stuff don’t.

02:30 PM | 0 Comments
August 9

A few days ago there was some complaint from Climate Camp that there was a lack of mobile phone connectivity. There’s three reasons this can happen, in descending order of likeliness – the current cell is running at capacity, part of the network has gone down, a new fake base station has been introduced. The most interesting reason is the latter, so let’s explore that a little.

According to the GSM specifications, communications between the mobile and the current base unit are generally (but don’t have to be) encrypted, mobiles are authenticated before being allowed to connect to the network, and mobiles connect to the base station with the most powerful signal. This means that in countries where encryption is illegal, GSM can still be used. It also means that anybody can introduce a fake GSM base station in order to monitor communications, you just bring along a base station from the Iraqi network and make sure that the mobile units can’t communicate with the real base stations.

Needless to say getting your hands on an Iraqi cellular base station is easier said than done, especially where you also need the mobiles to be able to communicate with the outside world, but it’s still possible. It certainly seems to make more sense than trying to get all of the uk mobile networks to give you call records, mms/sms records and recordings of everything.

The much more likely reason there’s been problems making calls is simply that there’s a much larger number of people than usual in a somewhat rural part of the country. It may or may not be assisted by the cops restricting communications to make planning actions difficult, but most likely not.

04:19 PM | 0 Comments
August 6

There’s a common misconception that you need to be close to an RFID tag to read it. That’s just not true, you only have to be close to activate it; if somebody else activates it you can read it from the other side of the room.

— Unknown hacker, discuss this statement

09:50 AM | 0 Comments
← Previous Next → Page 2 of 4