<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="http://feedproxy.google.com/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feedproxy.google.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>ClubHack</title>
	
	<link>http://www.clubhack.com/blog</link>
	<description>Making Security a Common Sense</description>
	<pubDate>Wed, 19 Nov 2008 12:35:31 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feedproxy.google.com/Clubhack" type="application/rss+xml" /><item>
		<title>“Free Internet Access” “Free Public WiFi” The Viral SSID</title>
		<link>http://feedproxy.google.com/~r/Clubhack/~3/hOXNa2kk8E8/</link>
		<comments>http://www.clubhack.com/blog/2008/11/08/free-internet-access_viral_ssid/#comments</comments>
		<pubDate>Fri, 07 Nov 2008 19:18:52 +0000</pubDate>
		<dc:creator>Rohit Srivastwa</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Tips &amp; Tricks]]></category>

		<category><![CDATA[Wireless]]></category>

		<category><![CDATA[advisory]]></category>

		<category><![CDATA[free public wifi]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[viral ssid]]></category>

		<category><![CDATA[wifi]]></category>

		<guid isPermaLink="false">http://www.clubhack.com/blog/?p=25</guid>
		<description><![CDATA[Ever wondered what is this &#8220;Free Public WiFi&#8221; or &#8220;Free Internet Access&#8221; wireless network visible in most of the places?

These are known as Viral SSID, don&#8217;t expect it to be a free access to internet  
Is it a virus, why doesn&#8217;t my antivirus detects it?
Its not a computer virus kind of thing which will [...]]]></description>
			<content:encoded><![CDATA[<p>Ever wondered what is this &#8220;Free Public WiFi&#8221; or &#8220;Free Internet Access&#8221; wireless network visible in most of the places?</p>
<p style="text-align: center;"><img style="border: 1px solid black; margin: 0px; vertical-align: baseline;" src="http://clubhack.com/blog/wp-content/uploads/2008/11/free.public.wifi.jpg" alt="Free public wifi" width="447" height="245" /></p>
<p>These are known as <strong>Viral SSID</strong>, don&#8217;t expect it to be a free access to internet <img src='http://www.clubhack.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><strong>Is it a virus, why doesn&#8217;t my antivirus detects it?<br />
</strong>Its not a computer virus kind of thing which will be detected by Anti-virus, but still it is &#8220;Viral SSID&#8221; cause its spreads like virus</p>
<p><strong>What is Viral SSID?</strong><br />
Like virus spread from infected computer to healthy one, a viral SSID spreads from an infected wireless-enabled computer to another. That&#8217;s why Viral SSID is the network name for ad-hoc (laptop to laptop) . See the icon next to it in the window carefully</p>
<p style="text-align: center;"><img style="border: 1px solid black; margin: 0px; vertical-align: baseline;" src="http://clubhack.com/blog/wp-content/uploads/2008/11/adhoc1.jpg" alt="Ad Hoc Network" width="57" height="52" /></p>
<p><strong>How does this Viral SSID Spread?</strong><br />
The culprit here is &#8220;Wireless auto configuration utility&#8221; of Windows.</p>
<p class="bodytext">Whenever a user connects to wireless network, its SSID is added in a list of known network names, this list is called the Preferred Network List (PNL). This list includes the viral SSIDs to which a user may have connected (by greed :P) or in fact, a user need not manually connect to a viral SSID for it to be added to the list. In certain auto-configuration utilities, there are options where a user can choose to connect to any network in vicinity whether it is ad-hoc or belongs to the infrastructure type.</p>
<p class="bodytext">
<p class="bodytext">When the user moves to a different location and starts the computer, the wireless auto configuration utility tries to look for the SSIDs stored in the PNL. When it doesn’t find any infrastructure networks mentioned in this list, it starts looking for ad-hoc networks stored in the PNL. If it finds one, it connects to the host displaying the corresponding SSID.  However, if it does not, it becomes the first node of that ad-hoc network and starts showing the viral SSID.</p>
<p class="bodytext">If an unsuspecting healthy laptop is searching for wireless networks in vicinity, it will see the advertised viral SSID in its list. If the laptop is configured to “Connect to any wireless network” as it comes in range, it will attach itself to the respective network. The connection can also be made when an unsuspecting user manually connects to an advertised viral SSID. As soon as this connection is made, the viral SSID appears in the PNL of the healthy laptop and thus gets infected.</p>
<p><strong>Why tempting names such as &#8220;free internet access&#8221;?</strong><br />
This phenomena of viral SSID started with generic names such as &#8220;default&#8221; or &#8220;&lt;vendor name&gt;&#8221; where the same SSID was in infrastructure mode (access point) as well as ad-hoc mode (peer to peer).</p>
<p class="bodytext">These lucarative named viral SSIDs could have been deliberately created by malicious intent where the attackers knew that the clients would be tempted to connect to this SSID if they didn’t find any infrastructure netowrk. Its a kind of social engineering, attracting the victims.</p>
<p class="bodytext"><strong>Should someone worry?<br />
</strong>Answer is Yes, if your machine is searching for a viral SSID, an attacker may have setup his/her machine to advertise that viral SSID and connect to your machine. The same is true if your machine is advertising it. Once the connection is made, the attacker can use various means to attack your computer and get the information he/she requires.</p>
<p class="bodytext">The mildest form of attack could be stealing information from your hard disk. The attacker can also become a man-in-the-middle routing all your Internet traffic through itself and observing/modifying all your data. Your passwords can also be stolen in this way.</p>
<p class="bodytext">
<p><strong> So how to protect yourself?</strong></p>
<p class="bodytext"><span style="text-decoration: underline;">(a)</span> First and foremost, avoid the temptation to connect to such networks, no one is giving you free internet there<span style="text-decoration: underline;"><br />
(b)</span> Disable auto-connection or advertisement for ad-hoc networks in your wireless auto configuration utility<span style="text-decoration: underline;"><br />
(c)</span> In windows XP, ensure that you have selected the “Access point (infrastructure) network only” in the “Advanced” configuration of Wireless Network Connection Properties.<br />
<span style="text-decoration: underline;">(d)</span> If you ever do connect to such a network (even by mistake), clear it from your PNL.<br />
<span style="text-decoration: underline;">(e)</span> If you need to connect to a peer device, make sure of the identity of that peer device before connecting.</p>

<p><a href="http://feedads.googleadservices.com/~a/KBew5nuqECFaPlwCOynrWv8FdvY/a"><img src="http://feedads.googleadservices.com/~a/KBew5nuqECFaPlwCOynrWv8FdvY/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/blog/2008/11/08/free-internet-access_viral_ssid/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.clubhack.com/blog/2008/11/08/free-internet-access_viral_ssid/</feedburner:origLink></item>
		<item>
		<title>ClubHack2008</title>
		<link>http://feedproxy.google.com/~r/Clubhack/~3/vnE_Tt684pk/</link>
		<comments>http://www.clubhack.com/blog/2008/10/30/clubhack2008/#comments</comments>
		<pubDate>Thu, 30 Oct 2008 07:38:18 +0000</pubDate>
		<dc:creator>team ClubHack</dc:creator>
		
		<category><![CDATA[Event]]></category>

		<guid isPermaLink="false">http://www.clubhack.com/blog/?p=24</guid>
		<description><![CDATA[Friends
Happy diwali to all.
Same time of the year is here when all the hackers come together under one roof.
Come December we&#8217;ll organize our second annual hackers convention.
ClubHack2008 has some changes and some attractions
To name a few
a) This year the event will be of 2 days
b) 6th December : Talks and panel discussion like last year
c) [...]]]></description>
			<content:encoded><![CDATA[<p>Friends<br />
Happy diwali to all.<br />
Same time of the year is here when all the hackers come together under one roof.<br />
Come December we&#8217;ll organize our second annual hackers convention.</p>
<p>ClubHack2008 has some changes and some attractions</p>
<p>To name a few</p>
<p>a) This year the event will be of 2 days</p>
<p>b) 6th December : Talks and panel discussion like last year</p>
<p>c) 7th December : Workshops on security related topics. Yes learning on the spot</p>
<p>d) Chief Guest for the event will be Dr. Satyapal Singh, Commissioner of Police, Pune.</p>
<p>e) We&#8217;ll hold few contests again, details will follow soon</p>
<p>f) One not-so-good news. Due to the financial condition of the country, we are not getting good response from our sponsors, hence we&#8217;ll have to keep a nominal conference fees this time. Proposed amount is Rs 1000 for day 1 and Rs 1000 per workshop on day 2. This is very nominal amount just to cover the convention cost.</p>
<p>g) Before the event we&#8217;ll be doing some awareness exercises, Sshh!! its a surprise as of now <img src='http://www.clubhack.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>To get an regular update subscribe to Google SMS channel [<a href="http://labs.google.co.in/smschannels/channel/ClubHack" target="_blank">1</a>] and/or follow us on twitter [<a href="http://twitter.com/clubhack" target="_blank">2</a>]</p>
<p>[1] <a href="http://labs.google.co.in/smschannels/channel/ClubHack" target="_blank">http://labs.google.co.in/smschannels/channel/ClubHack</a></p>
<p>[2] <a href="http://twitter.com/clubhack" target="_blank">http://twitter.com/clubhack</a></p>
<p>Happy Hacking<br />
team ClubHack</p>

<p><a href="http://feedads.googleadservices.com/~a/srUGJt92wVQkY1FFayBt_9Bm9qg/a"><img src="http://feedads.googleadservices.com/~a/srUGJt92wVQkY1FFayBt_9Bm9qg/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/blog/2008/10/30/clubhack2008/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.clubhack.com/blog/2008/10/30/clubhack2008/</feedburner:origLink></item>
		<item>
		<title>Security related video tutorial website launched</title>
		<link>http://feedproxy.google.com/~r/Clubhack/~3/3JJ8tOsyLqI/</link>
		<comments>http://www.clubhack.com/blog/2008/05/31/security-related-video-tutorial-website-launched/#comments</comments>
		<pubDate>Sun, 01 Jun 2008 06:56:31 +0000</pubDate>
		<dc:creator>Rohit Srivastwa</dc:creator>
		
		<category><![CDATA[Links]]></category>

		<category><![CDATA[Tutorials]]></category>

		<category><![CDATA[hacks]]></category>

		<guid isPermaLink="false">http://www.clubhack.com/blog/?p=19</guid>
		<description><![CDATA[Our good old friend Vivek Ramachandran launched a new website by the name http://securitytube.net
As per Vivek
It&#8217;s a community driven videos website for computer networking and security related fields. Though there are many video sharing websites available online, SecurityTube.Net is strictly focussed on hosting computer networking and security videos only. We have started this site to [...]]]></description>
			<content:encoded><![CDATA[<p>Our good old friend <a href="http://vivekramachandran.com">Vivek Ramachandran</a> launched a new website by the name <a href="http://securitytube.net">http://securitytube.net</a></p>
<p>As per Vivek</p>
<blockquote><p>It&#8217;s a community driven videos website for computer networking and security related fields. Though there are many video sharing websites available online, SecurityTube.Net is strictly focussed on hosting computer networking and security videos only. We have started this site to provide a knowledge sharing platform for security professionals, so that they can reach out effectively to a wider and focused audience</p></blockquote>
<p>The collection is very good and is useful for every learner starting for beginners to experts.</p>
<p>The best part is that one can also embed a video from securitytube.net into his/her blog<br />
Example: </p>
<p><object width="550" height="500"><param name="movie" value="http://videos.securitytube.net/main.swf"></param><param name="allowScriptAccess" value="always"/><param name="FlashVars" value="video=Nmap Usage Basics"><param name="wmode" value="transparent"></param><embed src="http://videos.securitytube.net/main.swf" type="application/x-shockwave-flash" FlashVars="video=Nmap Usage Basics" wmode="transparent" allowScriptAccess="always" width="550" height="500"></embed></object></p>
<p>Good work Vivek!</p>

<p><a href="http://feedads.googleadservices.com/~a/WZiyxB4ePcXiZOh8Ggwtmlqx3OM/a"><img src="http://feedads.googleadservices.com/~a/WZiyxB4ePcXiZOh8Ggwtmlqx3OM/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/blog/2008/05/31/security-related-video-tutorial-website-launched/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.clubhack.com/blog/2008/05/31/security-related-video-tutorial-website-launched/</feedburner:origLink></item>
		<item>
		<title>Fun with Debain SSH key vulnerability</title>
		<link>http://feedproxy.google.com/~r/Clubhack/~3/e6SSJaVSyT8/</link>
		<comments>http://www.clubhack.com/blog/2008/05/15/fun-with-debain-ssh-key-vulnerability/#comments</comments>
		<pubDate>Fri, 16 May 2008 06:21:52 +0000</pubDate>
		<dc:creator>Rohit Srivastwa</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.clubhack.com/blog/?p=18</guid>
		<description><![CDATA[A lot is being said and written about the new vulnerability found in debian/ubuntu and other variants
This post is not to give you the technical explanation or suggest a remedy but to bring together all the fun associated an one place

Source: http://metasploit.com/users/hdm/tools/debian-openssl/

Source: http://xkcd.com/424/
Do let me know if you some across any more on these lines [...]]]></description>
			<content:encoded><![CDATA[<p>A lot is being said and written about the new vulnerability found in debian/ubuntu and other variants</p>
<p>This post is not to give you the technical explanation or suggest a remedy but to bring together all the fun associated an one place</p>
<p><img src="http://clubhack.com/blog/wp-upload/deb-ssl.jpg" alt="" width="608" height="344" /></p>
<p>Source: <a href="http://metasploit.com/users/hdm/tools/debian-openssl/" target="_blank">http://metasploit.com/users/hdm/tools/debian-openssl/</a></p>
<p><img src="http://imgs.xkcd.com/comics/security_holes.png" alt="" width="493" height="527" /></p>
<p>Source: <a href="http://xkcd.com/424/">http://xkcd.com/424/</a></p>
<p>Do let me know if you some across any more on these lines <img src='http://www.clubhack.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>happy hacking</p>
<p>Rohit Srivastwa</p>

<p><a href="http://feedads.googleadservices.com/~a/DOZREqWKFx1ZMgwd9uc4g5vfoPc/a"><img src="http://feedads.googleadservices.com/~a/DOZREqWKFx1ZMgwd9uc4g5vfoPc/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/blog/2008/05/15/fun-with-debain-ssh-key-vulnerability/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.clubhack.com/blog/2008/05/15/fun-with-debain-ssh-key-vulnerability/</feedburner:origLink></item>
		<item>
		<title>Hack windows XP using firewire, no password required</title>
		<link>http://feedproxy.google.com/~r/Clubhack/~3/HT95NDzv4YM/</link>
		<comments>http://www.clubhack.com/blog/2008/03/05/hack-windows-xp-using-firewire-no-password-required/#comments</comments>
		<pubDate>Wed, 05 Mar 2008 11:44:05 +0000</pubDate>
		<dc:creator>team ClubHack</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Tips &amp; Tricks]]></category>

		<category><![CDATA[hacks]]></category>

		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.clubhack.com/blog/2008/03/05/hack-windows-xp-using-firewire-no-password-required/</guid>
		<description><![CDATA[Adam Boileau, a security consultant based in New Zealand has released a tool that can unlock Windows computers in seconds without the need for a password.
Adam uses firewire port (IEEE 1394) to gain a read/write access of the RAM of a locked and password protected computer.
To use the tool, hackers must connect a Linux-based computer [...]]]></description>
			<content:encoded><![CDATA[<p>Adam Boileau, a security consultant based in New Zealand has released a tool that can unlock Windows computers in seconds without the need for a password.</p>
<p>Adam uses firewire port (IEEE 1394) to gain a read/write access of the RAM of a locked and password protected computer.</p>
<p>To use the tool, hackers must connect a Linux-based computer to a Firewire port on the target machine. The machine is then tricked into allowing the attacking computer to have read and write access to its memory.</p>
<p>Checkout Adam&#8217;s website for more details. <a href="http://storm.net.nz/projects/16" target="_blank">http://storm.net.nz/projects/16</a></p>

<p><a href="http://feedads.googleadservices.com/~a/RkmLWr7MqoSrrgBzQ-iVQDi8SP4/a"><img src="http://feedads.googleadservices.com/~a/RkmLWr7MqoSrrgBzQ-iVQDi8SP4/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/blog/2008/03/05/hack-windows-xp-using-firewire-no-password-required/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.clubhack.com/blog/2008/03/05/hack-windows-xp-using-firewire-no-password-required/</feedburner:origLink></item>
		<item>
		<title>Goolag: Google Scanner for web vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/Clubhack/~3/o4k7uJCgkms/</link>
		<comments>http://www.clubhack.com/blog/2008/02/25/goolag-google-scanner-for-web-vulnerabilities/#comments</comments>
		<pubDate>Mon, 25 Feb 2008 17:02:34 +0000</pubDate>
		<dc:creator>team ClubHack</dc:creator>
		
		<category><![CDATA[Toolkit]]></category>

		<category><![CDATA[Web application]]></category>

		<guid isPermaLink="false">http://www.clubhack.com/blog/2008/02/25/goolag-google-scanner-for-web-vulnerabilities/</guid>
		<description><![CDATA[From the announcement:
&#8220;Today CULT OF THE DEAD COW (cDc), the world&#8217;s ost attractive hacker group, announced the release of Goolag Scanner, a web auditing tool. Goolag Scanner enables everyone to audit his or her own web site via Google. The scanner technology is based on &#8220;Google hacking,&#8221; a form of vulnerability research developed by Johnny [...]]]></description>
			<content:encoded><![CDATA[<p>From the announcement:<br />
&#8220;Today CULT OF THE DEAD COW (cDc), the world&#8217;s ost attractive hacker group, announced the release of Goolag Scanner, a web auditing tool. Goolag Scanner enables everyone to audit his or her own web site via Google. The scanner technology is based on &#8220;Google hacking,&#8221; a form of vulnerability research developed by Johnny I Hack Stuff.&#8221;</p>
<p>http://goolag.org</p>
<p>Folks at cDc launched a wonderful tool to do an analysis of your website. Goolag uses Google hacking techniques to scan your website and report vulnerabilities.</p>
<p><strong>Caution:</strong> One might end up blocking his/her IP on Google due to high number of automated search queries. It will result in something like this http://sorry.google.com/sorry</p>

<p><a href="http://feedads.googleadservices.com/~a/-7_7-RKlh6oggVsvOwLeQu8p1M4/a"><img src="http://feedads.googleadservices.com/~a/-7_7-RKlh6oggVsvOwLeQu8p1M4/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/blog/2008/02/25/goolag-google-scanner-for-web-vulnerabilities/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.clubhack.com/blog/2008/02/25/goolag-google-scanner-for-web-vulnerabilities/</feedburner:origLink></item>
		<item>
		<title>Check your browser online for vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/Clubhack/~3/HM-a-AIdawM/</link>
		<comments>http://www.clubhack.com/blog/2008/02/21/check-your-browser-online-for-vulnerabilities/#comments</comments>
		<pubDate>Thu, 21 Feb 2008 07:06:49 +0000</pubDate>
		<dc:creator>Rohit Srivastwa</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Tips &amp; Tricks]]></category>

		<guid isPermaLink="false">http://www.clubhack.com/blog/2008/02/21/check-your-browser-online-for-vulnerabilities/</guid>
		<description><![CDATA[I just stumbled accross this nice website
http://bcheck.scanit.be/bcheck/index.php
You can use the test to scan for vulnerabilities of your browser. As of now they have 13 tests only, but its worth doing a test.
]]></description>
			<content:encoded><![CDATA[<p>I just stumbled accross this nice website</p>
<p><a href="http://bcheck.scanit.be/bcheck/index.php" title="Browser check" target="_blank">http://bcheck.scanit.be/bcheck/index.php</a></p>
<p>You can use the test to scan for vulnerabilities of your browser. As of now they have 13 tests only, but its worth doing a test.</p>

<p><a href="http://feedads.googleadservices.com/~a/O18vjPcH-NWSjhO05hm12OHAnzM/a"><img src="http://feedads.googleadservices.com/~a/O18vjPcH-NWSjhO05hm12OHAnzM/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/blog/2008/02/21/check-your-browser-online-for-vulnerabilities/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.clubhack.com/blog/2008/02/21/check-your-browser-online-for-vulnerabilities/</feedburner:origLink></item>
		<item>
		<title>MetaSploit 3.1 now made public</title>
		<link>http://feedproxy.google.com/~r/Clubhack/~3/ob9OdMzbO0c/</link>
		<comments>http://www.clubhack.com/blog/2008/01/28/metasploit-31-now-made-public/#comments</comments>
		<pubDate>Mon, 28 Jan 2008 11:33:03 +0000</pubDate>
		<dc:creator>Rohit Srivastwa</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Toolkit]]></category>

		<guid isPermaLink="false">http://www.clubhack.com/blog/2008/01/28/metasploit-31-now-made-public/</guid>
		<description><![CDATA[H D Moore and team has released the version 3.1 of MetaSploit.
For those who don&#8217;t know about it, MetaSploit is one of the best and most effective exploit tool which can be used in the comfort of best point-n-click graphics interface as well as real fast and favorite command line shell interface.
&#8220;The latest version features [...]]]></description>
			<content:encoded><![CDATA[<p>H D Moore and team has released the version 3.1 of MetaSploit.</p>
<p>For those who don&#8217;t know about it, <a href="http://metasploit3.com/" title="MetaSploit" target="_blank">MetaSploit</a> is one of the best and most effective exploit tool which can be used in the comfort of best point-n-click graphics interface as well as real fast and favorite command line shell interface.</p>
<p><strong>&#8220;The latest version features a graphical user interface, full support for the Windows platform, and over 450 modules, including 265 remote exploits&#8230;&#8221;</strong><br />
The best part with MetaSpolit 3.1 is the new cool Windows GUI.</p>
<p align="center"><a href="http://www.clubhack.com/blog/wp-content/uploads/2008/01/win-msf-31.png" title="MetaSploit 3.1"><img src="http://www.clubhack.com/blog/wp-content/uploads/2008/01/win-msf-31.thumbnail.png" alt="MetaSploit 3.1" /></a> <a href="http://www.clubhack.com/blog/wp-content/uploads/2008/01/win-msf-31-2.png" title="Xploit Window"><img src="http://www.clubhack.com/blog/wp-content/uploads/2008/01/win-msf-31-2.thumbnail.png" alt="Xploit Window" /></a></p>
<p>For old school shell/CLI lovers, the flavor remains the same &amp; power is increased.</p>
<p>Three cheers to metasploit3 &amp; H D Moore</p>

<p><a href="http://feedads.googleadservices.com/~a/filYDygmeI_WNvc3G-2u-xwFURg/a"><img src="http://feedads.googleadservices.com/~a/filYDygmeI_WNvc3G-2u-xwFURg/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/blog/2008/01/28/metasploit-31-now-made-public/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.clubhack.com/blog/2008/01/28/metasploit-31-now-made-public/</feedburner:origLink></item>
		<item>
		<title>CyberAttack 2008</title>
		<link>http://feedproxy.google.com/~r/Clubhack/~3/D82rGirGqjs/</link>
		<comments>http://www.clubhack.com/blog/2008/01/25/cyberattack-2008/#comments</comments>
		<pubDate>Fri, 25 Jan 2008 12:37:27 +0000</pubDate>
		<dc:creator>team ClubHack</dc:creator>
		
		<category><![CDATA[Event]]></category>

		<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.clubhack.com/blog/2008/01/25/cyberattack-2008/</guid>
		<description><![CDATA[CyberAttack 2008, a first of its kind conference is being held at International Convention   Center, Pune on 27th April 2008. 
Hosted by Asian School of Cyber Laws, CyberAttack 2008 is aimed at knowledge sharing amongst cyber crime investigators and computer emergency response professionals. 
The conference will focus on:

latest trends in cyber crimes
 best [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="text-align: justify; line-height: 14pt"><span style="font-size: 11pt; font-family: Arial">CyberAttack 2008, a first of its kind conference is being held at International Convention   Center, Pune on <strong>27<sup>th</sup> April 2008</strong>. </span></p>
<p class="MsoNormal" style="text-align: justify; line-height: 14pt"><span style="font-size: 11pt; font-family: Arial">Hosted by <strong>Asian School of Cyber Laws</strong>, CyberAttack 2008 is aimed at knowledge sharing amongst cyber crime investigators and computer emergency response professionals. </span></p>
<p class="MsoNormal" style="text-align: justify; line-height: 150%"><u><span style="font-size: 11pt; line-height: 150%; font-family: Arial">The conference will focus on:</span></u></p>
<ol style="margin-top: 0in" start="1" type="1">
<li class="MsoNormal" style="text-align: justify; line-height: 14pt"><span style="font-size: 11pt; font-family: Arial">latest trends in cyber crimes</span></li>
<li class="MsoNormal" style="text-align: justify; line-height: 14pt"> <span style="font-size: 11pt; font-family: Arial">best practices for cyber crime      investigation</span></li>
<li class="MsoNormal" style="text-align: justify; line-height: 14pt"><span style="font-size: 11pt; font-family: Arial">best practices for cyber      forensics.</span></li>
</ol>
<p class="MsoNormal" style="text-align: justify; line-height: 14pt"><span style="font-size: 11pt; font-family: Arial">Original papers are invited from professionals. Authors of short listed Papers will have the option to present the paper <strong>in person</strong> or <strong>in absentia</strong>. All short listed Papers will be published in the conference proceedings.</span></p>
<p class="MsoNormal" style="text-align: justify; line-height: 14pt"><span style="font-size: 11pt; font-family: Arial">Further information can be obtained from:</span></p>
<p class="MsoNormal" style="text-align: justify; line-height: 14pt"><strong><u><span style="font-size: 11pt; font-family: Arial"><a href="http://www.cyberattack.in/">www.cyberattack.in</a></span></u></strong></p>
<p class="MsoNormal" style="text-align: justify; line-height: 14pt"><span style="font-size: 11pt; font-family: Arial">Asian</span><span style="font-size: 11pt; font-family: Arial"> School of Cyber Laws is the pioneer in education and research in cyber law and cyber crime investigation in India. We have assisted the Government of India in framing rules and regulations under the Information Technology Act. We work closely with Governments and law enforcement agencies around the world in the fields of cyber crime investigation and cyber forensics.</span></p>

<p><a href="http://feedads.googleadservices.com/~a/d9dvZHHTHI8dCFQF9ocWVuqLdWo/a"><img src="http://feedads.googleadservices.com/~a/d9dvZHHTHI8dCFQF9ocWVuqLdWo/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/blog/2008/01/25/cyberattack-2008/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.clubhack.com/blog/2008/01/25/cyberattack-2008/</feedburner:origLink></item>
		<item>
		<title>TOP 10 security threat for year 2008 in India</title>
		<link>http://feedproxy.google.com/~r/Clubhack/~3/NYhxiGEnwBI/</link>
		<comments>http://www.clubhack.com/blog/2008/01/15/top-10-security-threat-for-year-2008-in-india/#comments</comments>
		<pubDate>Wed, 16 Jan 2008 06:46:12 +0000</pubDate>
		<dc:creator>team ClubHack</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Tips &amp; Tricks]]></category>

		<category><![CDATA[advisory]]></category>

		<category><![CDATA[cyber crime]]></category>

		<category><![CDATA[hacking]]></category>

		<category><![CDATA[security threat]]></category>

		<category><![CDATA[threats]]></category>

		<category><![CDATA[top10]]></category>

		<guid isPermaLink="false">http://www.clubhack.com/blog/2008/01/15/top-10-security-threat-for-year-2008-in-india/</guid>
		<description><![CDATA[1: Zombie storm attack
Botnet is a group of &#8220;zombie&#8221; computers controlled remotely, to craft attacks. The most common ways to make a computer zombie is by virus, and exploits on unpatched vulnerabilities. Botnets are not a new concept; they have been around for sometime. But attacks from botnets are expected to grow this year. Some [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="text-align: justify"><strong><span style="font-size: 10pt; font-family: Arial">1: Zombie storm attack</span></strong><span style="font-size: 10pt; font-family: Arial"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial">Botnet is a group of &#8220;zombie&#8221; computers controlled remotely, to craft attacks. The most common ways to make a computer zombie is by virus, and exploits on unpatched vulnerabilities. Botnets are not a new concept; they have been around for sometime. But attacks from botnets are expected to grow this year. Some attacks we see from zombie networks include Denial-of-Service attack, Spyware, E-mail spam, and Click frauds.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">2: Web2.0 and SaaS attack<o:p></o:p></span></strong></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial">More and more software-as-a-service websites are coming up these days (like salesforce.com, Google docs, Spreadsheet, and so on). They will get more attention from attackers. Many of these hold your important personal/company information and that&#8217;s juicy information for attackers.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">3: Parasitic attackware<o:p></o:p></span></strong></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial">These might look like legitimate and branded applications, but are infected by attackers and redistributed (similar to Firefox extensions). Fake shareware distribution sites might distribute legitimate but infected programs online. The Victim would, for example, think that they are downloading legitimate Adobe Acrobat Reader from a ‘xyz’ site (not parent site of the product). However, this site might have parasitic attack software patched onto it.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">4: iPhone and smart phones<o:p></o:p></span></strong></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial">iPhone is expected in <st1:place w:st="on"><st1:country-region w:st="on">India</st1:country-region></st1:place> this year. We can anticipate many attacks on the iPhone and other smart phones we see these days. These might get infected over GSM or some other malicious website. With the popularity of smart phones like HTC, Blackberry and so on, people are increasingly using internet on handheld devices. We haven&#8217;t seen antivirus products emphasizing much on theme.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">5: Attack from your pocket<o:p></o:p></span></strong></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial">We can expect attacks being launched from new age phones and handheld devices. Most of the handheld devices these days have wireless connectivity, and Linux or windows as the operating system. We will see a trend of hacking tools on these devices which can be used for attack. Attackers know how easy it is to create an attack toolkit on a Linux based phone. We are also witnessing a trend in tools that can assist malicious acts from handhelds. Normal phones these days are more powerful in processing as compared to the first generation of computers we stared using.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">6: Attack on Govt. websites<o:p></o:p></span></strong></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial">In the recent past, we have observed cybercrooks trying to hack Govt. and bank websites. Latest in series was the ‘Govt. of Maharashtra’ website. We can expect increase in the trend of hacking into Govt. websites. The need of the hour is to secure such websites and manage them properly<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">7: Phishing: Majorly targeting SSO based services<o:p></o:p></span></strong></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial">We are moving towards one username, one password, and many services kind of architecture, just like Google. It’s commonly known as single-sign-on (SSO) in the IT industry. We can expect malicious websites offering some services which pretend to, for example, use Google Auth API where you could avail the service under the Google services umbrella. It will look legitimate but the attacker might get away with your crucial information. This can directly relate to financial loses as well. We have seen a lot of people using Google checkout to shop. Attackers might try to take benefit of this fact.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">8: Social networking websites<o:p></o:p></span></strong></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial">What with the way social networking websites are booming these days, we can expect more and more crime on that front. As of now identity theft is growing through these sites. Pornography might grow a great deal on these channels.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial">Attackers might also use these sites for mining data about people, fetching information that people share and use it to &#8220;authenticate&#8221; their attacks.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">9: Lucrative websites<o:p></o:p></span></strong></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial">Fancy looking websites of greetings, gaming and cyber pornography has been a good source of attacks in the past and the same will continue in 2008 also. It targets the mentality and emotions of people to serve its purpose, and the same will remain a prime method for adversaries in future too. These might be used to spread malwares and steal financial or personal information.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">10: Wireless attacks<o:p></o:p></span></strong></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial">The wireless medium is getting popular in <st1:place w:st="on"><st1:country-region w:st="on">India</st1:country-region></st1:place> these days with cheap and affordable devices. But people are ignorant about the security aspects of the wireless. Wireless attacks are on a high prowl in the west where companies have incurred losses in millions. We will see a rise in wireless attacks in <st1:country-region w:st="on"><st1:place w:st="on">India</st1:place></st1:country-region> too, if people are not educated in time.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">What should a common man do to be safe?<o:p></o:p></span></strong></p>
<p>There are a few things a common man can do to be secure online. Many of these have been told again and again in past, but people do not take it that seriously</p>
<blockquote><p>a) Use genuine software</p>
<p>b) Update all the software with latest patch issued by the vendor</p>
<p>c) Use a good antivirus and antispyware tool</p>
<p>d) Keep antivirus antispyware updated</p>
<p>e) Use a good desktop level personal firewall</p>
<p>f) Abstinence: Avoid temptation of downloading anything and everything.</p>
<p>g) Open email attachment from trusted source only</p>
<p>h) Do not give too much personal information on public websites</p>
<p>i) Double check before using any executable, verify the integrity and the source.</p>
<p>j) Download software from trusted websites only</p>
<p>k) As far as possible use HTTPS and other encrypted protocols.</p>
<p>l) Never ignore any warnings, read them carefully &amp; try to understand the reason behind it</p>
<p>m) Use best security practices to secure your networks, wired or wireless</p>
<p>n) Use smartphones responsibly.</p></blockquote>

<p><a href="http://feedads.googleadservices.com/~a/mSWQKu0fwr0VnZ72xYEX3rk9ayg/a"><img src="http://feedads.googleadservices.com/~a/mSWQKu0fwr0VnZ72xYEX3rk9ayg/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.clubhack.com/blog/2008/01/15/top-10-security-threat-for-year-2008-in-india/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.clubhack.com/blog/2008/01/15/top-10-security-threat-for-year-2008-in-india/</feedburner:origLink></item>
	</channel>
</rss>
