<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DDoSed.com - An IT security information blog &#187; Personal Opinions</title>
	<atom:link href="http://www.ddosed.com/category/personal-opinions/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ddosed.com</link>
	<description></description>
	<lastBuildDate>Sat, 04 Oct 2008 07:21:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>How Crackers Deface Websites? Why They Do It?</title>
		<link>http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/</link>
		<comments>http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/#comments</comments>
		<pubDate>Thu, 09 Aug 2007 01:33:04 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security Articles]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/</guid>
		<description><![CDATA[Through the following post I am not purposing to influence you to start defacing, but to briefly give you a better understanding of how and why it is done. Almost everyday I visit Zone-H&#8217;s archive of special digital attacks, I find that at least 1 or 2 attacks were done against US governmental web servers. The domain suffix [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Through the following post I am not purposing to influence you to start defacing, but to briefly give you a better understanding of how and why it is done.</p>
<p align="justify">Almost everyday I visit Zone-H&#8217;s <a target="_blank" href="http://www.zone-h.org/component/option,com_attacks/Itemid,43/" title="Zone-H.org Digital Attacks Archive">archive</a> of special digital attacks, I find that at least 1 or 2 attacks were done against US governmental web servers. The domain suffix of the defaced websites was *.gov. Does this fact means that they are totally secure? I don&#8217;t think so&#8230; Obviously the web servers may host very confidential data. In this case the web server administrators seemed to have allowed threats against governmental assets. Any unwanted consequences that a breach of security can lead to, are mainly caused by the irresponsibility and lazyness of system administrators and web developers.</p>
<p align="justify"><span id="more-50"></span></p>
<p align="justify">The methodology for defacing a website is pretty standard. Here is the standard sequence of tasks that normally the crackers/defacers would follow: <a target="_blank" href="http://en.wikipedia.org/wiki/Footprinting" title="Wikipedia.org - Footprinting">Footprinting</a>, <a href="http://netsecurity.about.com/cs/hackertools/a/aa030404.htm" title="Introduction to Vulnerability Scanning">scanning</a>, enumeration, penetration, attack, covering of tracks and installation of backdoors. As I mentioned before, the motivations for defacing any website are various, whereas when defacing governmental websites, could be a promotion of an ideology, revenge, or just a challenge.</p>
<p align="justify">I don&#8217;t believe that people who are serial website defacers hold good real-life jobs, or any job at all. This is just my personal opinion which is based on the fact that defacing is illegal in most countries &#8211; thus involving a high risk of getting arrested - and requires some basic knowledge, time, and patience. Advanced knowledge of technical and theoretical network security issues is not always required to deface. I think that understanding IT security theories, enhances intelligently your logical application of related practicalities. Achieving a deface could require the application of a complex exploitation methodology. This is enough reason to give up for some defacers without patience and with incomplete knowledge.</p>
<p align="justify">Tools assisting each step mentioned in the last paragraph are widely available for free on the internet. Most of the authors coded them for ethical, legal and educational use. Of course some were specifically coded for easily generating domain lists, exploiting security vulnerabilities, and mass-defacing websites. These are not easy to find on the web, nor are that difficult to code. Instead, individual defacers and groups exchange them in IRC channels, private forums  and servers, and through instant messengers.</p>
<p>One example of such an IRC server is irc.gigachat.net.</p>
<p align="justify">Script kiddies who deface, prefer to use fancy GUIs for tools rather than command line. Command line tools seem to exceed their learning and memory capabilities, or they don&#8217;t have the will and patience to research and analyze effective methodologies used by professionals in netsec pen-testing. They would be more technically skilled and better exercise their brain to remember simple and complex command sequences in multi-OS environments. Plus they would develop their practical skill-set which may be necessary if they choose to follow an IT career at some point &#8211; if they don&#8217;t end up in jail.</p>
<p align="justify">Depending on their ethical and legal attitudes, usually what they want is to quickly accomplish breaking in a network, maybe lookup for confidential data, download them and deface the home pages of hosted sites. Always counting in exceptions, most probably they didn&#8217;t use their own exploits, but what was already public.</p>
<p>Now I&#8217;m going to quote from another of my posts the following:</p>
<p align="justify">&#8220;In the mind and soul of the crackers who deface high-profiled websites, there is a false sense of pride. They think that it reflects their cracking skills and status in the defacers scene. For them defacing is more like a game. The messages shown in their defacements are more like an excuse for taking part in this game. The real motivation and reasoning behind their attacks, in most of the cases is not political, patriotic or other; but is just to show off themselves and their country to the world…</p>
<p align="justify">They attach a nickname to their personalities and cracking abilities, and they try to raise its status in the scene. They like searching for their nicknames in news websites and showing off the link to other crackers in their IRC channel, other channels, or through their websites.&#8221;</p>
<p align="justify">You will be ignored if you request mentioned tools or help to deface a website. Comments are welcome of course. <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p align="justify">&nbsp;</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F08%2F09%2Fhow-crackers-deface-websites-why-they-do-it%2F';
  addthis_title  = 'How+Crackers+Deface+Websites%3F+Why+They+Do+It%3F';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>High-Profiled Websites Getting Hacked And Defaced</title>
		<link>http://www.ddosed.com/2007/02/22/high-profiled-websites-getting-hacked-and-defaced/</link>
		<comments>http://www.ddosed.com/2007/02/22/high-profiled-websites-getting-hacked-and-defaced/#comments</comments>
		<pubDate>Thu, 22 Feb 2007 17:49:16 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/02/22/high-profiled-websites-getting-hacked-and-defaced/</guid>
		<description><![CDATA[Everyday, the security of many high-profiled governmental, military, educational and corporate websites, is broken into by crackers who deface them. Although some defacers protest against wars and other just send greets to their cyberdudes, I believe that their true motive is to get to the top of the lead in &#8220;special&#8221; defacements. The defacers don&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Everyday, the security of many high-profiled governmental, military, educational and corporate websites, is broken into by crackers who deface them. Although some defacers protest against wars and other just send greets to their cyberdudes, I believe that their true motive is to get to the <a href="http://www.zone-h.org/component/option,com_topatt/Itemid,49/" target="_blank" title="Zone-H.org - Attackers Special Top List">top of the lead in &#8220;special&#8221; defacements</a>. The defacers don&#8217;t want to admit this as the real reason for their attacks.</p>
<p><span id="more-39"></span><br />
<a href="http://www.zone-h.org" target="_blank" title="Zone-H.org - Digital Attacks Archive">Zone-H.org</a> has listed the following reasons in the &#8220;Attacks Notification&#8221; page:</p>
<blockquote><p>- As a challenge<br />
- Heh&#8230;just for fun!<br />
- I just want to be the best defacer<br />
- Not available<br />
- Patriotism<br />
- Political reasons<br />
- Revenge against that website</p></blockquote>
<p>Here is a list of notable hand picked defacements &#8211; archived in <a href="http://www.zone-h.org" target="_blank" title="Zone-H.org - Digital Attacks Archive">Zone-H.org</a>:</p>
<p><strong>US <a href="http://www.zone-h.org/index.php?option=com_attacks&amp;Itemid=44&amp;filter=1" target="_blank" title="Zone-H.org - US Governmental defaces">Governmental</a>:</strong></p>
<p><em>http://dbreports.lanl.gov Win 2003<br />
http://learnlinc.oph.dhh.louisiana.gov Win 2000<br />
http://elbertcounty-co.gov/events.asp Win 2000<br />
http://gis.sedgwick.gov Win 2003<br />
http://gis2.sedgwick.gov Win 2003<br />
http://azdps.gov/inf4z.htm Win 2000<br />
http://csdr-cde.ca.gov/nhst.htm Win 2003<br />
http://join.cio.ca.gov/data/d7j.htm FreeBSD</p>
<p>https://restricted.gov.ca.gov/briefings/files/d7j.htm</p>
<p>http://appointments.ca.gov/3D.htm</em></p>
<p><strong>Famous dot-coms:</strong></p>
<p>http://flightpak.paramount.com Win 2000<br />
http://vassiebel.volvo.com Win 2003<br />
http://ecommercesuite.usbank.com Win 2003<br />
http://panasonickorea.com Linux<br />
http://beta.cmt.msn.com Win 2003</p>
<p><strong>Famous dot-nets:</strong></p>
<p>http://self.wind.it.net/ownz.htm SolarisSunOS<br />
http://korea.net Win 2000</p>
<p>Most defacers of the above websites originate from Turkey, Brazil and Iran.</p>
<p align="justify">The sysadmins of insecure webservers and the developers of insecure web applications are mostly responsible for the cracking incidents. It appears to me that the crackers don&#8217;t have a specific target.</p>
<p align="justify">What they do most of the times, is to use a <a href="http://www.netcraft.com" target="_blank" title="Netcraft.com">Netcraft</a> and a <a href="http://www.google.com" target="_blank" title="Google.com">Google</a> website list generator. After they import the list into a scanner and scan thousands of websites for possible <a href="http://www.securiteam.com/securityreviews/5DP0N1P76E.html" target="_blank" title="SecuriTeam.com - SQL Injection Walkthrough">SQL injections</a>, <a href="http://www.securityfocus.com/columnists/427" target="_blank" title="PHP apps: Security's Low-Hanging Fruit">PHP inclusions</a>, <a href="http://en.wikipedia.org/wiki/Directory_traversal" target="_blank" title="Directory traversal on WikiPedia.org">directory traversals</a>, information leaks and other security <a href="http://www.securityfocus.com/vulnerabilities" target="_blank" title="SecurityFocus.com - Vulnerabilities Archive">vulnerabilities</a>. There have been many cases of crackers using <a href="http://en.wikipedia.org/wiki/Social_engineering_(computer_security)" target="_blank" title="Social Engineering on WikiPedia.org">social engineering</a> techniques, such as <a href="http://en.wikipedia.org/wiki/Social_engineering_(computer_security)#Pretexting" title="What is pretexting?">pretexting</a> and<a href="http://en.wikipedia.org/wiki/Social_engineering_(computer_security)#Phishing" target="_blank" title="What is Phishing?"> phishing</a>, in order to grant access priviledges to confidential information.</p>
<p>Screenshot of a Turkish Googler generating a list of *.gov/s (Click on thumbnail to view it):</p>
<p><a href="http://www.ddosed.com/wp-content/uploads/2007/03/turkish-googler.JPG" title="Turkish Googler" class="imagelink" rel="thumbnail"><img src="http://www.ddosed.com/wp-content/uploads/2007/03/turkish-googler.thumbnail.JPG" alt="Turkish Googler" id="image41" rel="thumbnail" height="119" width="150" /></a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F02%2F22%2Fhigh-profiled-websites-getting-hacked-and-defaced%2F';
  addthis_title  = 'High-Profiled+Websites+Getting+Hacked+And+Defaced';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/02/22/high-profiled-websites-getting-hacked-and-defaced/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>MSN.co.uk Money Related Websites Hacked And Defaced</title>
		<link>http://www.ddosed.com/2007/02/01/msn-uk-money-related-websites-hacked-and-defaced/</link>
		<comments>http://www.ddosed.com/2007/02/01/msn-uk-money-related-websites-hacked-and-defaced/#comments</comments>
		<pubDate>Thu, 01 Feb 2007 00:14:28 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/02/01/msncouk-money-related-websites-hacked-and-defaced/</guid>
		<description><![CDATA[Two websites belonging to MSN (Microsoft Network) in the United Kingdom, were defaced today by an attacker who goes by the nickname &#8220;DARK LORD&#8220;. It looks like someone who is unethically testing his SQL injection skills, and &#8220;feeding&#8221; himself with a false sense of pride, just by leaving the message &#8220;DARK LORD WAZ HERE&#8221;. No. [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Two websites belonging to <a href="http://www.msn.co.uk" target="_blank" title="MSN.co.uk">MSN</a> (Microsoft Network) in the United Kingdom, were defaced today by an attacker who goes by the nickname <em>&#8220;<a href="http://www.zone-h.org/component/option,com_attacks/Itemid,44/filter_defacer,DARK%20LORD/" target="_blank" title="Zone-H.org - ">DARK LORD</a>&#8220;</em>. It looks like someone who is unethically testing  his <a href="http://www.governmentsecurity.org/articles/SQLInjectionModesofAttackDefenceandWhyItMatters.php" target="_blank" title="SQL Injection: Modes of Attack, Defence, and Why It Matters - Stuart McDonald">SQL injection</a>  skills, and &#8220;feeding&#8221; himself with a false sense of pride, just by leaving the message <em>&#8220;DARK LORD WAZ HERE&#8221;</em>.</p>
<p align="justify">No. I am not a defacer psychologist. I am just  expressing my personal opinion on the matter, which is this: If a website defacement doesn&#8217;t convey a meaningful message, then it is done for selfish reasons.</p>
<p>A bit of an embarassment for Microsoft&#8217;s sysadmins&#8230;</p>
<p><span id="more-26"></span></p>
<p align="justify">The cracker exploited an SQL injection vulnerability in the <em>story.asp</em> file and thus was able to deface the following websites:</p>
<p><em>http://whatinvestment.money.msn.co.uk Win 2003<br />
http://personalfinance.money.msn.co.uk Win 2003</em></p>
<p>Screenshot of the defaced website (Click thumbnail to view it):</p>
<p><a href="http://www.ddosed.com/wp-content/uploads/2007/01/msncoukdefaced.JPG" title="MSN.co.uk money websites defaced" class="imagelink" rel="thumbnail"><img src="http://www.ddosed.com/wp-content/uploads/2007/01/msncoukdefaced.thumbnail.JPG" style="width: 140px; height: 103px" alt="MSN.co.uk money websites defaced" id="image27" /></a></p>
<p align="justify">The most surprising thing &#8211; actually not very suprising, judging from past cracking incidents of Microsoft&#8217;s systems &#8211; is that the website remained defaced for more than 8 hours and the <a href="http://www.governmentsecurity.org/articles/SQLInjectionModesofAttackDefenceandWhyItMatters.php" title="SQL Injection: Modes of Attack, Defence, and Why It Matters - Stuart McDonald" target="_blank">SQL injection</a> vulnerability has not been fixed yet.</p>
<p>Screenshot (Click thumbnail to view it):</p>
<p><a href="http://www.ddosed.com/wp-content/uploads/2007/01/msncouksqlinjection.JPG" class="imagelink" title="MSN.co.uk - SQL injection vulnerability" rel="thumbnail"><img src="http://www.ddosed.com/wp-content/uploads/2007/01/msncouksqlinjection.thumbnail.JPG" style="width: 140px; height: 106px" id="image28" alt="MSN.co.uk - SQL injection vulnerability" /></a></p>
<p align="justify">You can view the above website defacements and 2.092.360 &#8211; as for today at 23:00 GMT &#8211; archived digital attacks at <a href="http://www.zone-h.org" title="Zone-H.org - Largest digital attacks archive" target="_blank">Zone-H.org</a>.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F02%2F01%2Fmsn-uk-money-related-websites-hacked-and-defaced%2F';
  addthis_title  = 'MSN.co.uk+Money+Related+Websites+Hacked+And+Defaced';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/02/01/msn-uk-money-related-websites-hacked-and-defaced/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>A Brief Comment On The Saudi Arabian Defacers Of Zone-H</title>
		<link>http://www.ddosed.com/2007/01/28/comment-on-the-saudi-arabian-defacers-of-zone-h/</link>
		<comments>http://www.ddosed.com/2007/01/28/comment-on-the-saudi-arabian-defacers-of-zone-h/#comments</comments>
		<pubDate>Sun, 28 Jan 2007 02:58:34 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Personal Opinions]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/01/28/a-brief-comment-on-the-saudi-arabian-defacers-of-zone-h/</guid>
		<description><![CDATA[Since I read the news about the recent defacement of the digital attacks archive Zone-H.org, many people have commented on how &#8220;professional&#8221; the Saudi Arabian defacers were. I strongly disagree&#8230; They were very &#8220;unprofessional&#8221; kids. Just one confused kid who praises the devil &#8211; Devil Hacker &#8211; with his fellow pal Unix Web. Both from [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Since I read the news about the recent defacement of the digital attacks archive <a href="http://www.zone-h.org" title="Zone-H.org - Largest digital attacks archive" target="_blank">Zone-H.org</a>, many people have commented on how &#8220;professional&#8221;  the Saudi Arabian defacers were. I strongly disagree&#8230; They were very &#8220;unprofessional&#8221; kids.</p>
<p align="justify"> Just one confused kid who praises the devil &#8211; Devil Hacker &#8211; with his fellow pal Unix Web. Both from Jeddah in Saudi Arabia.</p>
<p align="justify">Students with too much time on their hands. They proved that they can use a basic backdoor, change the DNS and use the exploits that come together with some security advisories.</p>
<p><span id="more-19"></span></p>
<p align="justify">If you look at Devil Hacker&#8217;s blog, you will immediately notice some really lame posts and links to lame &#8211; &#8220;im going to show you what my cracking skills are&#8221; &#8211; videos.</p>
<p>Devil Hacker&#8217;s blog (muhahahaha):<br />
<a href="http://www.dev.blogfa.com" title="Devil Hacker's blog" target="_blank">www.dev.blogfa.com</a></p>
<p align="justify">I must admit though&#8230; These guys have skills in following the instructions&#8230;</p>
<p align="justify">&nbsp;</p>
<p align="justify">What were their motives? Publicity. I&#8217;m sure the one went to the other&#8217;s house and searched for their nicknames on a search engine. A few good laughs, a false sense of pride. Now lets go listen to Marilyn Manson!</p>
<p align="justify">Neither hackers or crackers! Just script kiddies &#8211; computer power users.<br />
Real hackers and crackers don&#8217;t post their e-mail addresses, they don&#8217;t say from where they are from, they don&#8217;t say who they are.</p>
<p>Nuff said.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F01%2F28%2Fcomment-on-the-saudi-arabian-defacers-of-zone-h%2F';
  addthis_title  = 'A+Brief+Comment+On+The+Saudi+Arabian+Defacers+Of+Zone-H';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/01/28/comment-on-the-saudi-arabian-defacers-of-zone-h/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>US Government Websites Get Hacked And Defaced Every Month</title>
		<link>http://www.ddosed.com/2007/01/27/us-goverment-websites-get-hacked-and-defaced-every-month/</link>
		<comments>http://www.ddosed.com/2007/01/27/us-goverment-websites-get-hacked-and-defaced-every-month/#comments</comments>
		<pubDate>Sat, 27 Jan 2007 16:43:47 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/01/27/us-goverment-websites-get-defaced-every-month/</guid>
		<description><![CDATA[US government websites are under the spotlight of muslim cracking groups who protest against USA &#8211; this is what they claim as an attack reason. Since the 2nd of January, 17 US governmental websites were defaced, from which 9 were defaced by means of SQL injection. What seems obvious to me &#8211; after viewing most [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">US government websites are under the spotlight of muslim cracking groups who protest against USA &#8211; this is what they claim as an attack reason. Since the 2nd of January, 17 US governmental websites were defaced, from which 9 were defaced by means of <a href="http://www.google.co.uk/search?hl=en&amp;q=%22sql+injection%22&amp;meta=" target="_blank" title="SQL injection - Google Results">SQL injection</a>.</p>
<p align="justify">What seems obvious to me &#8211; after viewing most of those defacements on the <a href="http://www.zone-h.org/component/option,com_attacks/Itemid,44/" target="_blank" title="Zone-H.org - Special Digital Attacks Archive">Zone-H digital attacks archive</a> &#8211; is that their motives are not fully justified. Most of these crackers &#8211; better say &#8220;<a href="http://en.wikipedia.org/wiki/Script_kiddie" target="_blank" title="Script Kiddies on Wikipedia">script kiddies</a>&#8221; &#8211; are using <a href="http://www.milw0rm.com" target="_blank" title="Milw0rm.com - Security Exploits Archive">publicly available exploits</a> for <a href="http://www.securityfocus.com/vulnerabilities" target="_blank" title="SecurityFocus.com - Vulnerabilities ">known vulnerabilities</a>, and by applying logic on how to use them, they succeed in the end at gaining access on webservers.</p>
<p align="justify">The fact that the attacked webservers belong to the US government, doesn&#8217;t necessarily mean that there is adequate security implemented.</p>
<p align="justify"><span id="more-17"></span>Apart from the little warning/disclaimer that they put on their websites as a scare tactic for crackers, there is very little done on tracing and catching the crackers who successfully broke into their webservers. Setting up <a href="http://www.honeypots.net/" target="_blank" title="Honeypots, Intrusion Detection, Incident Response">honeypots</a> on their systems in order to track the techniques and methodologies which are used by crackers, is certainly helpful knowledgewise.</p>
<p align="justify">In the mind and soul of the crackers who deface high-profiled websites, there is a false sense of pride. They think that it reflects their cracking skills and status in the defacers scene. For them, defacing is more like a game. The messages shown in their defacements, are more like an excuse for taking part in this game. The real motivation and reasoning behind their attacks, in most of the cases is not political, patriotic or other; but is just to show off themselves and their country to the world&#8230;</p>
<p align="justify">They attach a nickname to their personalities and cracking abilities, and they try to raise its status in the scene. They like searching for their nicknames in news websites and showing off the link to other crackers in their IRC channel, other channels, or through their websites.</p>
<p>Below is the list of all the *.gov websites that were defaced in the past 27 days,  along with the OS that they run:</p>
<p>(Visit <a href="http://www.zone-h.org" target="_blank" title="Zone-H.org Digital Attacks Archive">Zone-H.org</a> to view the defacements)</p>
<p><em>https://www.cahps.ahrq.gov/content/cahpsOverview/faqanswer.asp Win 2000<br />
http://learnabouteva.dgs.virginia.gov/FAQ Win 2003<br />
http://mail.vi.gov/ibh.html   Win 2003<br />
http://webmail.vi.gov/index.html  Win 2003<br />
http://nd.gov/ndins/communications  Linux<br />
http://hca.montgomerycountymd.gov/govtmpl.asp  Win 2000<br />
http://fairfaxva.gov/personnel/Jobs.asp  Win 2003<br />
http://cstx.gov/home/index.asp  Win 2000<br />
https://ssl.cstx.gov/csjobs/job_list.asp  Win 2000<br />
http://oss.monroecounty-fl.gov/1923tg.htm  Win 2000<br />
http://asc.gov/default.aspx  Win 2003<br />
http://eppcapps.ky.gov/earthday/ideas.aspx  Win 2003<br />
http://tncarefraud.tennessee.gov/newsAndInfo.aspx  Win 2003<br />
http://floydcounty.in.gov  Win 2000<br />
http://radsite.lbl.gov/testhost.htm  FreeBSD<br />
http://hobbes.lbl.gov/ibh.htm  FreeBSD<br />
http://floyd.lbl.gov/ibh.htm  FreeBSD<br />
http://archivesindex.sc.gov  Win 2000<br />
https://fortress.wa.gov/dshs/f2ws03esaapps/stars/newsarchive.asp  FreeBSD</em></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F01%2F27%2Fus-goverment-websites-get-hacked-and-defaced-every-month%2F';
  addthis_title  = 'US+Government+Websites+Get+Hacked+And+Defaced+Every+Month';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/01/27/us-goverment-websites-get-hacked-and-defaced-every-month/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Evolution Of Cybercrime + Personal Opinion</title>
		<link>http://www.ddosed.com/2007/01/22/the-evolution-of-cybercrime-personal-opinion/</link>
		<comments>http://www.ddosed.com/2007/01/22/the-evolution-of-cybercrime-personal-opinion/#comments</comments>
		<pubDate>Mon, 22 Jan 2007 05:41:00 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security Articles]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/01/22/the-evolution-of-cybercrime-personal-opinion/</guid>
		<description><![CDATA[Criminallawyergroup.com is a very interesting read as it gives an account on the evolution of cybercrime. Some good points are made towards the end about the lack of regard for the social aspect of cybercrime with most concentration on the financial side of things. It is worrying that cybercrime is reported to cost $50 billion [...]]]></description>
			<content:encoded><![CDATA[<p align="justify"><a href="http://www.criminallawyergroup.com/" target="_blank" title="Criminal Lawyer Group">Criminallawyergroup.com</a> is a very interesting read as it gives an account on the <a href="http://www.criminallawyergroup.com/criminal-defense/the-evolution-of-cybercrime-from-past-to-the-present.php" target="_blank" title="Evolution of Cybercrime">evolution of cybercrime</a>. Some good points are made towards the end about the lack of regard for the social aspect of cybercrime with most concentration on the financial side of things. It is worrying that cybercrime is reported to cost $50 billion globally per year.</p>
<p align="justify">In my opinion, as technologies advance, there will be always <a href="http://www.securityfocus.com/vulnerabilities" target="_blank" title="SecurityFocus.com Vulnerabilities ">security vulnerabilities</a> and cyber-criminals to <a href="http://www.milw0rm.com" target="_blank" title="milw0rm.com Exploit Archive">exploit</a> them for a <a href="http://www.zone-h.org" target="_blank" title="Zone-H.org - Defacement Archive">variety of motivations</a> (political, religious etc).</p>
<p align="justify">Most of the cyber-criminals are seeking financial gain rather than notoriety for their actions.</p>
<p align="justify"><span id="more-15"></span></p>
<p align="justify">It doesn&#8217;t surprise me that most cyber-attacks originate from countries with poor economies. With just an internet access and publicly disclosed exploits for vulnerabilities and black-hat (unethical) hacking tutorials, is not hard for cyber-criminals to commit their illegal actions.  Even if the security vulnerabilities are patched, human stupidity cannot be patched.  Criminals can still use social engineering techniques such as pretexting and phishing to trick people and get what they want.</p>
<p align="justify">Some countries such as Argentina [1], do not even have laws that cover cyber-crimes. This makes cyber-crimes an open global security threat, meaning that something has to be done with international laws.</p>
<p align="justify">As far as it concerns the international laws; in the article the author states that there is little or no international legislation that contains criminal defense mechanisms against cyber-crimes. [2] However, there are a few multi-jurisdictional legislations such as in the European Union law.[2]</p>
<p>[1] <a href="http://news.bbc.co.uk/1/hi/world/americas/1932191.stm">http://news.bbc.co.uk/1/hi/world/americas/1932191.stm</a></p>
<p>[2] <a href="http://www.criminallawyergroup.com/criminal-defense/the-evolution-of-cybercrime-from-past-to-the-present.php">http://www.criminallawyergroup.com/criminal-defense/the-evolution-of-cybercrime-from-past-to-the-present.php</a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F01%2F22%2Fthe-evolution-of-cybercrime-personal-opinion%2F';
  addthis_title  = 'The+Evolution+Of+Cybercrime+%2B+Personal+Opinion';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/01/22/the-evolution-of-cybercrime-personal-opinion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Would I Hire A Hacker?</title>
		<link>http://www.ddosed.com/2007/01/16/would-i-hire-a-hacker/</link>
		<comments>http://www.ddosed.com/2007/01/16/would-i-hire-a-hacker/#comments</comments>
		<pubDate>Tue, 16 Jan 2007 15:29:57 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security Articles]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/01/21/would-i-hire-a-hacker/</guid>
		<description><![CDATA[If I was a manager recruiting security programmers, prior to the final decision on whether to employee a hacker or not, I would require positive feedback for the psychometric tests that the hacker would be obliged to attend in order to have his motives evaluated. I would also make sure that appropriate controls for hiring [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">If I was a manager recruiting security programmers, prior to the final decision on whether to employee a hacker or not, I would require positive feedback for the psychometric tests that the hacker would be obliged to attend in order to have his motives evaluated.</p>
<p align="justify">I would also make sure that appropriate controls for hiring hackers are in place and that my company&#8217;s policy supports it. Despite the in-depth technical knowledge of the hackers, there are possible significant risks for the companies hiring them and thus many different aspects of the lives of the hackers need to be assessed.</p>
<p align="justify">&nbsp;</p>
<p align="justify"><span id="more-11"></span>I believe that we should give chances to ex-convicted computer hackers. Once a hacker is convicted, will be stigmatized a criminal for the rest of his life. This means fewer doors open for employment and a skill that doesn’t get the reward it deserves&#8230; – that skill got punished though for being used maliciously and with criminal intents.</p>
<p align="justify">The lateral thinking of the hackers is the best way to know how to protect ourselves from certain computer security risks and is definitely useful for companies. Governments, law enforcement agencies and corporations, <a href="http://archives.cnn.com/2000/TECH/computing/08/01/pentagon.at.defcon.idg/index.html" target="_blank" title="For hire: Hackers to help Pentagon prevent attacks">had in the past hired reformed hackers</a>.</p>
<p>What would YOU do? Hire a hacker or not and why?</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F01%2F16%2Fwould-i-hire-a-hacker%2F';
  addthis_title  = 'Would+I+Hire+A+Hacker%3F';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/01/16/would-i-hire-a-hacker/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>A Brief Personal Opinion On Preventing ID Theft</title>
		<link>http://www.ddosed.com/2007/01/08/a-brief-opinion-about-id-theft/</link>
		<comments>http://www.ddosed.com/2007/01/08/a-brief-opinion-about-id-theft/#comments</comments>
		<pubDate>Mon, 08 Jan 2007 14:24:05 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security Articles]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/01/21/a-brief-opinion-about-id-theft/</guid>
		<description><![CDATA[My opinion, for preventing ID theft, is – step 1 &#8211; to research and deal with the roots of the problems caused by it; rather than – step 2 &#8211; trying to make everyone aware on how to protect his or her ID. For example, if a system administrator effectively maintained the security of an [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">My opinion, for preventing ID theft, is – step 1 &#8211; to research and deal with the roots of the problems caused by it; rather than – step 2 &#8211; trying to make everyone aware on how to protect his or her ID. For example, if a system administrator effectively maintained the security of an enterprise server, we wouldn’t have a security breach and thousands of credit card details and personal info would be safe!</p>
<p align="justify"><span id="more-8"></span>The responsibility resides to the individual’s level of awareness of personal security. People must become more vigilant on how to protect their personal information when using technology.</p>
<p align="justify">In my view, as a government or an enterprise, we have to make sure that all of our civilians or employees achieve a higher level of awareness of personal security.</p>
<p align="justify">In UK there are many initiatives that have been set up to face ID theft. Obviously this means that the situation is getting worse and people need to be aware! For this reason the government promotes a yearly campaign aimed to spread out complete information on how to avoid, and eventually expose, ID frauds &#8211; <a href="http://www.stop-idfraud.co.uk/" target="_blank">www.stop-idfraud.co.uk</a>.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F01%2F08%2Fa-brief-opinion-about-id-theft%2F';
  addthis_title  = 'A+Brief+Personal+Opinion+On+Preventing+ID+Theft';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/01/08/a-brief-opinion-about-id-theft/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Strict Laws On DoS/DDoS Attacks + Personal Opinion</title>
		<link>http://www.ddosed.com/2006/12/28/strict-laws-on-dosddos-attacks-personal-opinion/</link>
		<comments>http://www.ddosed.com/2006/12/28/strict-laws-on-dosddos-attacks-personal-opinion/#comments</comments>
		<pubDate>Thu, 28 Dec 2006 12:34:20 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/01/21/strict-laws-on-dosddos-attacks-personal-opinion/</guid>
		<description><![CDATA[Since November 2006, in UK is an offense to launch DoS/DDoS attacks, which experts had previously called &#8220;a legal gray area.&#8221; What follows is my brief personal view on this subject. Such attacks should have been considered illegal for over 10 years now because they cause significant financial losses to businesses as they affect the [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Since November 2006, in UK is an offense to launch DoS/DDoS attacks, which experts had previously called &#8220;a legal gray area.&#8221;</p>
<p>What follows is my brief personal view on this subject.</p>
<p align="justify">Such attacks should have been considered illegal for over 10 years now because they cause significant financial losses to businesses as they affect the availability of data and services &#8211; A very unethical thing to do&#8230;</p>
<p>Causing many problems for all the parties involved in the supply chain&#8230;</p>
<p><span id="more-9"></span></p>
<p align="justify">The end responsibility obviously resides with the attacker, but businesses and individuals are also responsible for not doing anything or very little to prevent such attacks, which are persistent and constantly evolving in increasing frequency and complexity.</p>
<p align="justify">Other than education for awareness on DoS/DDoS attacks, I believe that effective prevention techniques and adequate security management is the goal businesses should aim towards. The reason for striving for this goal is to protect their digital assets as well as the flow of information critical to their successful operation.</p>
<p align="justify">There are several companies worldwide that provide cutting edge solutions which can protect your enterprise network from this type of attacks and thus allow the constant and secure flow of information.</p>
<p>I will list 2 or 3 here:</p>
<p>Prolexic Technologies &#8211; <a href="http://www.prolexic.com/">www.prolexic.com</a></p>
<p>Callaway Alliance &#8211; <a href="http://www.ddosprotection.com" target="_blank" title="Callaway Alliance ">www.ddosprotection.com</a></p>
<p>Cisco&#8230; and many other&#8230; Just google it! <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  Keyword: <a href="http://www.google.com/search?hl=en&amp;lr=&amp;rls=com.microsoft%3Aen-us&amp;q=%22ddos+protection%22" target="_blank">&#8220;ddos protection&#8221;</a></p>
<p align="justify">The other problem is that DoS/DDoS attacking tools and exploits are publicly disclosed on the internet… This means people relatively unskilled in computer knowledge can cause large amount of damage by simply running a DoS/DDoS exploit against an online target.</p>
<p>The new law decreases the frequency of such attacks but doesn’t stop them…</p>
<p>Food for thought&#8230;. I would be happy to know YOUR opinions on this subject.</p>
<p>Read more on this recent law:</p>
<p><a href="http://news.com.com/2100-7348_3-6134472.html">http://news.com.com/2100-7348_3-6134472.html</a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2006%2F12%2F28%2Fstrict-laws-on-dosddos-attacks-personal-opinion%2F';
  addthis_title  = 'Strict+Laws+On+DoS%2FDDoS+Attacks+%2B+Personal+Opinion';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2006/12/28/strict-laws-on-dosddos-attacks-personal-opinion/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Trend That Young &#8220;Wannabe Hackers&#8221; Follow</title>
		<link>http://www.ddosed.com/2006/12/25/the-trend-that-young-wannabe-hackers-follow/</link>
		<comments>http://www.ddosed.com/2006/12/25/the-trend-that-young-wannabe-hackers-follow/#comments</comments>
		<pubDate>Mon, 25 Dec 2006 17:11:49 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security Articles]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/01/21/the-trend-that-young-wannabe-hackers-follow/</guid>
		<description><![CDATA[Both Kevin Mitnick (http://www.defensivethinking.com ) and Kevin Poulsen (http://www.securityfocus.com &#38; http://www.wired.com ) are currently successful in the Information Security field because of their past computer crimes [1] and the attention that they received through the news media. They are not the only ones though! Their professional success that followed after serving jail time, created a [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Both Kevin Mitnick (<a href="http://www.defensivethinking.com" target="_blank" title="DefensiveThinking.com">http://www.defensivethinking.com</a> ) and Kevin Poulsen (<a href="http://www.securityfocus.com" target="_blank" title="SecurityFocus.com">http://www.securityfocus.com</a> &amp; <a href="http://www.wired.com" target="_blank" title="Wired.com">http://www.wired.com</a> ) are currently successful in the Information Security field because of their past computer crimes [1] and the attention that they received through the news media. They are not the only ones though!</p>
<p align="justify">Their professional success that followed after serving jail time, created a trend that young “wannabe hackers” follow: They expect a bright future career and in order to achieve that, they hope to get busted for hacking.</p>
<p align="justify"> <span id="more-13"></span>Obviously there are better ways to establish themselves in the InfoSec field but they attempt to approach professional success with a wrong way. I believe that people shouldn’t generalize from such examples because these examples do not necessarily lead to the fame that Mitnick and Poulsen received, as such it is a hasty generalization from too few cases.</p>
<p align="justify">&nbsp;</p>
<p align="justify">Whenever I ask people if they know Mitnick, they answer: Ah! The famous hacker! Not many people know though that Mitnick’s security company’s website was defaced recently: <a href="http://www.zone-h.org/content/view/14073/31/" target="_blank" title="Zone-H.org - Kevin Mitnick creampied by Pakistani rage ">http://www.zone-h.org/content/view/14073/31/</a>. These defacements indicate the existence of a cyber-war between Black-hat (unethical) and White-hat (ethical) hackers.</p>
<p>Visit the hacker definition controversy and ambiguity page for a better understanding. (<a href="http://en.wikipedia.org/wiki/Hacker_definition_controversy" target="_blank" title="Hacker definition controversy">http://en.wikipedia.org/wiki/Hacker_definition_controversy</a>).</p>
<p>[1]<a href="http://www.takedown.com/bio/mitnick.html" target="_blank" title="Kevin Mitnick - An excerpt from Takedown">http://www.takedown.com/bio/mitnick.html</a></p>
<p><a href="http://en.wikipedia.org/wiki/Kevin_Poulsen" target="_blank" title="Kevin Poulsen on Wikipedia">http://en.wikipedia.org/wiki/Kevin_Poulsen </a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2006%2F12%2F25%2Fthe-trend-that-young-wannabe-hackers-follow%2F';
  addthis_title  = 'The+Trend+That+Young+%26%238220%3BWannabe+Hackers%26%238221%3B+Follow';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2006/12/25/the-trend-that-young-wannabe-hackers-follow/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

