Showing posts with label is. Show all posts
Showing posts with label is. Show all posts

Wednesday, December 27, 2017

Beginners Guide What is Hacking and How to Become a Social Engineer

Beginners Guide What is Hacking and How to Become a Social Engineer


Hacking and How to Become a Social Engineer- picateshackz.com

Social engineering is a non-technical method of intrusion hackers use that relies heavily on human interaction and often involves tricking people into breaking normal security procedures. It is one of the greatest threats that organizations today encounter.Hacking has grown far bigger than anyone could have expected. In the beginning is was about optimizing model trains but today it’s a whole lifestyle. We see “hackers” in the news almost everyday and the business is just getting bigger. If you ask a random person on the street what their view of a hacker is they will probably reply with something like “It’s a person who breaks into systems” but that’s wrong. A true hacker is much more than that and can never be dragged down into something as small as that description, so today i want to explain about what is hacking and how to become a social engineer.



What is hacking?



What do you think of when you hear the term hacker? Most of you guys will probably think of criminal geeks who are butt hurt about something and then decide to take revenge or “hacking” groups like Anonymous. In that case you are wrong. Those people have nothing in common with real hacking and they are using their knowledge for bad things. The correct term for people like Anonymous would be Cracker(lookup the definition if you don’t know why they are called that). The right definition of hacking is “Hacking is the practice of modifying the features of a system, in order to accomplish a goal outside of the creators original purpose.” - www.whatishacking.org. The word hacker originates back from the fifties or the sixties. One of the places that’s commonly known for have started the hacking culture is MIT. Students from Tech Model Railroad Club joined together to create new ways of controlling and building model trains. A great improvement of the train or the system was simply called a hack. It then moved on to phone lines and later on into computers. The reason why it moved on into the phone lines was simply that there wasn’t anything else to hack.


A guy who got very famous for hacking telephones and telephone lines (also called phreaking) is John “Captain Crunch” Draper. The reason why he’s called Captain Crunch was because of a famous hack he did back in the early seventies. From the american breakfast cereal Cap’n Crunch he got a whistle which could make a sound at 2600Hz. Since AT&T’s system was running by tones he could cheat the phone system to dial up pretty much everyone for free. He later on created The Blue Box which made it easier for him to cheat the phone lines. In 1972 he got convicted for cheating the phone company for money and ended up in prison for a short amount of time. According to The Wall Street in 1978 he hand wrote the first word processor for the Apple II computer called EasyWriter. He apparently should have hand written it in prison on paper and then later typed it into a computer. Hacking was also the reason why personal computers was created by guys like Steve Wozniak. Steve Wozniak created a terminal which enabled him to play chess but at the same to lure around on ARPAnet. He then short after joined hacker groups which introduced him to microprocessors. He have later on made great contributions to the development of the microprocessor.

The precursor to Usenet newsgroup and e-mails, the boards with names such as Sherwood Forest and Catch-22 become the venue of choice for phreaks and hacker to talk, trade tips and share stolen credit card information and stolen computer passwords. Hacking groups begin to form and some of the first well known were Legion of Doom from the United States and Chaos Computer Club from Germany.

In 1983 the movie WarGames came out and changed the public view on hacking. Hacking went from being something underground and unnoticed to something big. The movie was about a boy who want’s to crack into a game company’s computer system to play a game but instead end up starting a military catastrophe.

The same year 6 teenagers known as the 414 gang get’s arrested for hacking into 60 computers. It was first in 1986 it was made a crime to break into computer systems.

The morris worm:

In 1988 Robert T. Morris, Jr. created a self-replicating computer worm which he launches on ARPAnet to inspect its effectiveness on UNIX systems. It went out of hand and spread to over 6000 computers. He ended up with probation and a $10.000 fine.

Kevin Mitnick:

As early as the age of 12 he social engineered himself to free bus drives. He’s today known as one of the best social engineers through time. Kevin Mitnick is captured by federal agents and charged with stealing 20,000 credit card numbers. 


I will encourage you to read his biography. It gives you a true sight into his journey to establish himself as one of the greatest social engineers of all time.




How To Become a Social Engineer



Article from Social-Engineer Newsletter Vol 05 Issue 61
I really must admit that one of the most asked questions we get through the website is something like, “I really want to get into social engineering as a career, what should I read/take in college to give me the best chance?” then followed up by “How do I get into this as a job/career?”

It is a serious question that we have spent considerable time trying to come with an appropriate answer for. This month I will answer the education piece, by telling you my own thoughts, what I look for when I hire and also what some of my most trusted friends from large companies look for when hiring. Then next month, I will go into how to make this your career.


So you wanna be a social engineer?


I understand why the question comes in so often. This job is pretty cool sounding. We get paid to phish, vish and break into companies every day. That certainly sounds like the dream job – well at least for a lot of us.


Like most careers, it is logical to think that there may be a clear path to education to help you with a leg up in this field. Some people ask me, if they should study psychology, if they should get sales experience, others wonder if they should skip school all together. What’s the answer?


Lets first ask my good friend Jim. He manages a large team of pentesters that includes red teams, social engineers and some excellent hackers at one of the world’s largest financial institutions. I asked him this question, “If you wanted to hire a young man or woman to be part of your team as a social engineer or pentester what do you look for? Education, experience or a combination?”


Jim says, “First of all I look for experience. But there are certifications that mean something to me like Offensive Security’s certifications (OSCP / OSCE) and the CISSP.


In addition, my mantra is generally: Jack-of-all-trades, master of a couple. I look for folks who have a fairly broad generalist experience, but have taken an interest in deeply diving into one or two.


I also look for mentality; can the candidate think like a bad guy? Is security your job, or a passion? What does your home network look like? And very importantly, does the candidate have the ability to communicate clearly, concisely, and professionally.


Finally, personal references are good, especially when it comes to character, since if you join my team you’re going to have to be a highly trusted individual.”


Thanks Jim, that was very helpful.


I went another very close friend who has been in the industry for a very long time helping run Black Hat and now running the Global Education and Training practice at Accuvant, Ping Look. Jim, “If you wanted to hire a young man or woman to be part of your team as a social engineer or pentester what do you look for? Education, experience or a combination?”

Ping said, “Accuvant does not look for degrees – experience and ability to pass the practical exams that we administer and references, especially industry ones, are more important.

I know that most hackers goals arent to be promoted to management but the reality is that everyone has to make a living and having more responsibility within a company usually means a promotion whether it be to management or not. I do know from anecdotal experience of others that at a lot of larger firms, not having a college degree will make it more difficult to be promoted (initially) to management positions.


HOWEVER in a technical field, smart companies know that InfoSec is still an emerging marketplace and that finding a candidate with a college degree, especially in computer science who is also a good infosec practitioner with the necessary experience will be very difficult. Over time, those who prove themselves technically adept and have good management chops end up having the same chance in getting promotions or running teams or being lead technologist or chief research scientist as the guy with a degree.”


Another excellent answer, that really helps us to get a clear picture.


Finally, I went to my good friend, Dave Kennedy. Dave started his own company just a few years ago, Trusted Sec, and went from just a couple people to over 20 people. He obviously knows a thing or two about hiring pentesters. So I presented him with the same question, “If you wanted to hire a young man or woman to be part of your team as a social engineer or pentester what do you look for? Education, experience or a combination?”


Dave said, “I favor experience over education any day. Although a college degree is important, I am looking for someone who has the experience to handle the type of work that we get.



References are important, but I tend to hire people I’ve known and trust in the industry so I always get individuals I know and trust to do the work.”


All three answers really paint a great picture for anyone thinking and asking.



What about Social-Engineer, Inc?

My company has personally grown over the last couple years so I have had to spend considerable time thinking about what it is that I need in employees. Unlike some of the great minds I asked above, my needs are a tad bit different. But let me pick out the similarities from what we saw above:

  • Experience always wins. Many of my team have degrees, and some, like Michele are not only highly educated but trained educators. Even with that, experience is king. Now with that said there aren’t just slews of people that have tons of experience in phishing, vishing and breaking into buildings without having a criminal record. I will discuss later how we get around this particular hurdle in a bit. Mentality: This is a big one because there are many components to this particular topic.
  1. Can the person think like a bad guy? We have a motto in my company, “Always leave them feeling better for having met you.” We apply that to how we want our customers to feel about our services. So although I need my people to be able to THINK like a bad guy, I need them to care enough about the customer that they don’t revel in the bad side too long.
  2. Desire to learn. We are in a constant state of growth, and part of that is learning how to adapt when the times, attack vectors and methods of the bad guys change. My team has to be willing to do that.
  3. Learn from failure. I have failed so many times I can’t count them, but the important part is learning from each failure. My team has to be willing to have the same attitude.
  4. Is this a hobby or a passion? It is important to me to find people who enjoy the work and don’t just look at it as a “job”.

  • Performance based education. Right now from what I found, Social-Engineer has the only performance based SE Certification around. I also favor the Offensive Security Certifications as they prove fortitude, persistence and critical thinking skills.


  • Critical thinkers. Probably one of the most important aspects of being a social engineer is being able to critically think. To adapt, flex and change your methods on the fly. To be able to think outside the box, as if there is no box.

  • Willingness to try new things. Many times my team will be required to try completely new things, new pretexts, new methodologies and new processes.


Does this mean that education is completely useless? No, not at all. Depending on the role we are looking for a degree can definitely add to usefulness and the position we use the person for.

If you are going to college already and you are thinking of a career in pentesting and maybe even social engineering, then there are some areas of study that can help. Things like computer sciences, psychology and social psychology can all help.

In the end, the fortitude to stick through college, study hard and graduate with good grades can tell a potential employer that you have some great qualities to make a good employee. In the end of the day, social engineering is an exciting and very rewarding career path. Study hard, stay out of trouble and get practical experience where you can and it may just be your career someday too.


Recommended article: Penetration Testing: Basic Guide For Beginners


Available link for download

Read more »

Saturday, November 11, 2017

Belizegial Health Topic Caffeine How Much is Too Much

Belizegial Health Topic Caffeine How Much is Too Much



Hi Friends,

Its been a hectic week on this end. One mostly fueled by sheer determination and several necessary cups of coffee *lol* Which brings to mind. Caffeine: How much is too much? Michelle, if youre visiting today, here is what Mayoclinic.com has to say about this topic.

In less than an hour you start to feel caffeines effects. Youre more alert, energetic and productive. Your mood lifts and that foggy, tired feeling is gone. If you rely on daily doses of caffeine to chase away fatigue and perk up your disposition, you arent alone. Nine out of 10 Americans consume some type of caffeine regularly, making it the most popular behavior-altering drug.

For most people, moderate doses of caffeine — 200 to 300 milligrams (mg), or about two to three cups of brewed coffee a day — arent harmful. But some circumstances, such as caffeine sensitivity or use of certain medications, may warrant limiting or even ending your caffeine routine. Find out if you need to decaffeinate your diet and, if so, how you can do it with minimal distress.

When to cut caffeine use - Certain circumstances call for reducing the amount of caffeine you consume. Evaluate your habits. If any of these situations apply, you may need to cut back. You consume unhealthy amounts. Though moderate caffeine intake isnt likely to cause harm, too much can noticeably affect your health. Heavy daily caffeine use — more than 500 to 600 mg a day, or about four to seven cups of coffee — can cause:

Restlessness
Anxiety
Irritability
Muscle tremors
Sleeplessness
Headaches
Nausea, diarrhea or other gastrointestinal problems
Abnormal heart rhythms
You have caffeine sensitivity if youre susceptible to the caffeines effects. Just small amounts — even one cup of coffee or tea — may prompt unwanted results, such as anxiety, restlessness and irritability. The more sensitive you are to caffeine, the less you need to consume before feeling its influence.Your sensitivity depends on many factors, including:

Body mass. People with smaller body masses feel the effects of caffeine sooner than those with larger body masses.

History of caffeine use. People who dont regularly consume caffeine tend to be more susceptible to its negative effects than are people who do.

Stress. All types of stress — for example, psychological stress or heat stress — can increase a persons sensitivity to caffeine.

Other factors can contribute to variations in caffeine sensitivity as well, including age, smoking habits, drug or hormone use, and other health conditions, such as anxiety disorders.
Most adults need seven to eight hours of sleep each night. But caffeine can interfere with this much-needed sleep. Chronically losing sleep — whether its from work, travel, stress or too much caffeine — results in sleep deprivation. Sleep loss is cumulative, and even small nightly decreases can add up and disturb your daytime function.

Using caffeine to mask sleep deprivation creates an unwelcome cycle. For example, you drink caffeinated beverages because you have trouble staying awake during the day. But the caffeine keeps you from falling asleep at night, shortening the length of time you sleep. Caffeine can also increase the number of times you wake up during the night and can interfere with deep sleep, which makes your night less restful. With less sleep and poor-quality sleep, youre more tired the next day. To battle the fatigue and to feel more energetic, you reach for your morning jolt of Java.

The best way to break this cycle is to limit your caffeine and to add more hours of quality sleep to your day. Also, avoid caffeinated beverages eight hours before your desired bedtime. Your body doesnt store caffeine, but it does take many hours for it to eliminate the stimulant and its effects.

Certain medications and herbal supplements negatively interact with caffeine. The following are some examples - some antibiotics.

Ciprofloxacin (Cipro) and norfloxacin (Noroxin) — types of antibacterial medications — can interfere with the breakdown of caffeine. This may increase the length of time caffeine remains in your body and amplify its unwanted effects.

Theophylline (Theo-24, Uniphyl, others). This medication — which opens up bronchial airways by relaxing the surrounding muscles (a bronchodilator) — tends to have some caffeine-like effects. Taking this drug along with caffeinated foods and beverages may increase the concentration of theophylline in your blood. This can cause ill effects, such as nausea, vomiting and heart palpitations. If you take theophylline, your doctor may advise that you avoid caffeine.

Ephedra (ma-huang). This herbal dietary supplement increases your risk of heart attack, stroke, seizures and death. Combined with caffeine, it becomes especially risky. The Food and Drug Administration has banned ephedra in the marketplace because of health concerns. This ban applies to dietary supplements but not herbal teas, which may still contain the herb. Talk to your doctor or pharmacist about whether caffeine might affect your prescription. He or she can best direct you on whether you need to reduce or eliminate caffeine from your diet.

Caffeine can be habit-forming, so any attempts to stop or lessen the amount you normally consume can be challenging. An abrupt decrease in caffeine can cause withdrawal symptoms, such as headaches, fatigue, irritability and nervousness. These symptoms usually resolve after several days.

To adopt new caffeine habits, try these tips:
Know how much caffeine is in the foods and beverages you consume. You may be consuming more than you think.
Gradually reduce the amount of caffeine you consume. For example, drink one less can of soda or drink a smaller cup of coffee each day. This will help your body get used to the lower levels of caffeine and thereby lessen the withdrawal effects.

Replace caffeinated coffee, tea and soda with their decaffeinated counterparts. Most decaffeinated beverages look and taste the same.
When preparing tea, brew for less time. This cuts down on its caffeine content. Or choose herbal teas, which dont contain this stimulant.

Check the caffeine content in over-the-counter medications that you take. Pain relief or headache medications, such as Excedrin or Anacin, can contain from 65 mg to 130 mg of caffeine in one dose. Switch to caffeine-free versions, if possible.

If youre like most adults, caffeine is a part of your daily routine. And most often it doesnt pose a health problem. But be mindful of those situations in which you need to curtail your caffeine consumption.

© 1998-2006 Mayo Foundation for Medical Education and Research (MFMER). All rights reserved. A single copy of these materials may be reprinted for noncommercial personal use only. "Mayo," "Mayo Clinic," "MayoClinic.com"

Available link for download

Read more »

Tuesday, October 17, 2017

Be it in healthcare or infosec the short term is for losers

Be it in healthcare or infosec the short term is for losers


With all the doctor & hospital visits Ive gone (and am still going) through with family members in the past few years, Ive come to the conclusion that many (most?) healthcare providers - especially those smart doctors society holds on a pedestal - absolutely cannot see the big picture. They cant think past the appointment time slot in which theyre currently working, much less next year and beyond.

Adding to the problem, the left hand never talks to the right so everyone is engaging in their own area of "expertise" yet nothing gets done at a higher level and the patient is the one who ends up suffering because of this approach. Heres an example of what Im talking about...this is the hospital meal that my father received after going in for a suspected heart attack:

The Dinner of Champions

Whats wrong with this picture!? Luckily, for us, it ended up being symptoms from a hiatal hernia. Whew. But still...? Come on healthcare professionals! Hey, at least our beloved Obama is going to fix this...(ha!).

The problem of not seeing the big picture is very common among business execs and even many IT professionals who just dont get what information security is all about. We see it everywhere, especially when data breaches occur...But we also see it when our own peers claim the sky is falling because of the latest Adobe Reader zero day exploit or the Web interface on someones printer is susceptible to CSRF. Amazing....sad.

The desire for immediate gratification leads to a lot of bad choices. Ask any success/achievement expert and he or she will tell you that the lack of time perspective is one of the greatest problems in society - arguably the one thing that holds people back the most. It certainly has an impact on IT and information security.

If you want to stand out among the noise and the ignorance associated with IT and information security, think long-term in all the decisions you make. Dont expect short-term perfection in your security program. Instead, aim for incremental improvements over time.The missing link is actually making those incremental improvements over time...As Henri Frederic Amiel once said “The person who insists upon seeing with perfect clearness before he or she decides, never decides.” This is no doubt the root cause of the problems we cant seem to solve.

Available link for download

Read more »

Sunday, September 10, 2017

Bedwetting ADHD Kids and Depressed Dads Is there a connection

Bedwetting ADHD Kids and Depressed Dads Is there a connection


ADHD and Bedwetting (Nocturnal Enuresis): How are the two related?

There is a relatively recent publication that came out within the last couple of weeks on the relatively high rate of occurrence in bed wetting (enuresis) among ADHD children, which I believe is worth sharing. We have previously investigated this ADHD and bed wetting connection (note that bed wetting may be more likely to be seen alongside the inattentive subtype of ADHD). However, this study offers some additional insight into this strange association between the two disorders. Here are some important points worth mentioning:


  • Overlapping Drug Treatment for ADHD and bedwetting: It stands to reason that if a particular drug or agent is effective in treating multiple disorders, there may be a distinct possibility that those two or more disorders may share some type of underlying cause(s) or defect(s). For example, Tofranil or Imipramine, a drug used to treat enuresis and depressive disorders can possibly be useful as a treatment option for ADHD. We have also investigated the potential role of Reboxetine as a potential ADHD treatment in previous entries. Some work has found Reboxetine to be useful in treating therapy-resistant enuresis as well.

  • Prevalence of Enuresis in ADHD: Enuresis refers to urinary incontinence which is limited to the night-time. Additionally, the term is typically limited to individuals over the age of 5 (i.e. a 3-year-old child who frequently pees in their pants would not be considered as suffering from enuresis, at least in the context of this study). The article cites other studies in which the rate of bedwetting (enuresis) in ADHD is as high as 30%, although other studies have it down around 10-20%. Still, compared to the general population, (factoring in things such as the age of the child, of course)the high rate of bed wetting in ADHD is especially noteworthy. There is some evidence from other studies that ADHD and enuresis may be more intricately linked than previously imagined. For example, one particular study has shown that treating urinary incontinence has a higher rates of failure in children with ADHD vs. non-ADHD children.

  • The role of Oppositional Defiant Disorder (ODD) on Bed wetting: The study examine several different psychiatric disorders which frequently occur alongside of (or are comorbid to) ADHD. These include depression, anxiety disorders, obsessive compulsive disorders, tic disorders, nail biting, bruxism (teeth grinding), conduct disorders and oppositional defiant disorders. However, out of all of these different disorders which often appear alongside ADHD, the only one which exhibited a statistically significant correlation to increases in bedwetting was oppositional defiant disorder. Interestingly, oppositional defiant disorders have been associated with bedwetting in other ADHD studies.

    As its name suggests, Oppositional Defiant Disorder is a disorder in which a child exhibits disobedience, irritability and hostility towards authority figures beyond the range of normal age-appropriate behaviors. Of course there is a significant gray area with regards to what is age appropriate, especially when the childs environment is considered. Nevertheless, Oppositional Defiant Disorder (or ODD) is much more than just routine temper tantrums. Oppositional Defiant Disorders may also be associated with auditory processing issues and ADHD. It is somewhat interesting that anxiety disorders, which have also been correlated to oppositional behaviors, did not elicit a significant positive correlation to bed wetting.

  • The autonomic nervous system as a potential underlying cause of ADHD, bedwetting and Oppositional Defiant Disorders: The autonomic nervous system is the part of the nervous system responsible for involuntary muscle actions such as digestive processes, blood vessel contraction, etc. It is subdivided into the sympathetic and parasympathetic nervous systems, which often act in a sort of "push-pull" opposition to each other. For example, the sympathetic nervous system does things such as boosting heart rate and constricting blood vessels, while the parasympathetic nervous system is in charge of activities such as reducing heart rates and relaxing sphincter muscles (which plays a role in bladder control).

    Typically, the sympathetic and parasympathetic components of the nervous system are kept in balance, but this balance may be thrown out of whack and result in numerous disorders. For example, it is believed that the parasympathetic nervous system is over dominant in cases of Oppositional Defiant Disorders (ODD). The study found that for ADHD and Oppositional Defiant Disordered children, functions such as heart rate were controlled excessively (if not almost exclusively) by the parasympathetic portion of the nervous system (while non-ODD and non-ADHD children had both sympathetic and parasympathetic controls operating on their heart rates. This suggests a common underlying imbalance among the different components of the nervous system which is common to ADHD and ODD individuals and often separates them from the non-ADHDers. Interestingly, other studies have indicated that bedwetting or generalized incontinence problems may also be caused by an overactive parasympathetic nervous system, which suggests that ADHD, ODD and night-time bedwetting may all share some underlying causes within the nervous system.

  • Connection to Parental Depression: I personally found this observation to be interesting. The study found that the prevalence of bedwetting in ADHD children was higher if the father (but not the mother) of the child was suffering from some sort of major depressive illness. The article did not express an opinion as to whether these depressive symptoms were due in part to the childs bed wetting problems or whether there was some underlying mechanism at work.

  • ADHD medications may Influence Enuresis: The authors highlight some other works in which popular ADHD medications may either increase or decrease the risk of bedwetting in ADHD children. For example, the article highlighted a case study (by the same author) in which treatment with methylphenidate induced nocturnal enuresis. Methylphenidate is one of the most common ADHD drugs, and often goes by the common trade names Ritalin, Concerta, Metadate and Daytrana (the patch form of the drug). Of course this is based on only one individual case, but for those of you who have read this blog on a frequent basis, will know that I like to report on some of these abnormal occurrences (for reference sake, here is an earlier blog post I have done on the possible connection between methylphenidate and excessive talking. While based on an isolated case report, I believe that this zany potential side effect was at least worth a mention). On the flip side, however, the non-stimulant alternative ADHD drug, Atomoxetine (Strattera) can be a useful treatment for enuresis. This blogger would personally like to see additional studies on whether ADHD children with a comorbid bedwetting condition actually saw a better reduction in their ADHD symptoms while on Strattera than while on methylphenidate. If this were the case, then bedwetting may actually served as a useful tip-off as to which type of ADHD medication would work best for that particular child.

Available link for download

Read more »

Tuesday, August 1, 2017

Because normal is so boring Ask me questions!

Because normal is so boring Ask me questions!


Leggings from Romwe | Top from Brashy | Shoes from Choies | Sunglasses from Romwe




Catsuit from Black Milk Clothing | Jacket from VJ STYLE | Platforms from Nelly

Hi! :) Love my new platform shoes from the Fanny Lyckman for Estradeur Collection! These babys have unfortunately been sold out so Im happy that I was able to buy one! It isnt hard to walk in them and they are comfortable. 
Ive never thought that a catsuit can look so good but hey they do! 
I also love the melting ice cream leggings, makes me even more excited for hot summer days!






Available link for download

Read more »

Tuesday, July 11, 2017

Being Nice Is Good Business

Being Nice Is Good Business


One of the fundamental truths of writing single-player PC games now is that its so easy to pirate anything that people will only buy your game if they want to. Which means that being honest and forthright and likable is a key business strategy.

For the fifteen years weve been selling games, weve had a suite of generous, customer-friendly policies. However, we havent been clear and forthright about them. Some of them are only known to people who ask us for support privately. The others can only be found by hunting our web site. This is dumb. If youre going to the trouble to be nice, make sure everyone knows about it! So I wrote this little manifesto that will be prominently linked to on our site.


In youre an Indie developer and like one of our turns of phrase, please feel free to borrow it.


Our Spiderweb Software Promises To You

Spiderweb Software is a small company. We read all our e-mail, we love our customers, and if you are sad, we are sad. Were literally a Mom & Pop company, and we believe in the personal touch. So here are our three promises to you ...

1. No Obnoxious DRM!

Pirates exist. Sad, but true. But we wont let hatred of people who rip off our games drive us to annoy our paying customers.

When you order from us, you get a number you can enter into the demo to turn it into the full game. And thats it. No online authentication. No need to keep a disk in the drive.

If your computer dies and you need a new registration key? Were sorry to hear that, and your replacement is free. Register on the Mac and switch to Windows? A new key is free. Your child wants to play the game on his or her own machine? Thats awesome, and an additional key is free.

2. Money-Back Guarantee!

If you dont like our game, we dont want your money.

We have a no-questions-asked One Year Money-back Guarantee. Game stops working? You wake up one morning and realize that it sucks? You decide that you hate us personally, and our adorable children too? Money back within one year.

You might think, "Hmmm. I wonder if people ever buy the game, play it through, and demand a refund." The answer is: No. This has never happened. You know why? Because our customers are awesome people.

3. Big, Free Demos!

Spiderweb Software has the biggest demos in the business. Whats more, the demo is actually the full game. You just need to enter a key to unlock the whole story.

That means that you get a chance to play a bunch of game and make sure that 1. It works, 2. You are having fun, and 3. The retro graphics dont enrage you. If the demo works for you and is fun, you can buy the full game and be confident that it will still work and still be fun. And if it doesnt? Have we mentioned our Money-Back Guarantee?

We love that almost all of our customers played a demo first. It means were earning our pay honestly. Because, again, If you dont like our game, we dont want your money.


Hopefully, we will come across and friendly and honest when this goes up on our web site. And the truth is, we at Spiderweb are pretty friendly, honest people. But make no mistake. At the heart of it, the reason we are putting this up is pure self-interest. Since being nice is a core part of our business plan, when we are nice, we will do it in a loud way.

Available link for download

Read more »

Wednesday, June 28, 2017

Batgirl Being Bad Is Bad

Batgirl Being Bad Is Bad


I have really been enjoying Adam Beechens run on Robin so far, with one notable exception - it deals with a plot point that I think is pretty lame, which is that Cassandra Cain, daughter of the assasins David Cain (the guy who framed Bruce Wayne for murder) and Lady Shiva, is now a villain herself. However lame I think this particular plot point is, though, I know that it is an editorially mandated event, not anything that Adam Beechen came up with (same with the move I actually DID like, which was to remove Greg Ruckas new daughter of Ras Al Ghul from comics), so, when I judge whether Beechen is doing a good job on Robin, I am not going to give him demerits for the lame plot point.

Available link for download

Read more »

Thursday, May 25, 2017

Become A Hacker What Is Denial of Service DoS Attack

Become A Hacker What Is Denial of Service DoS Attack



Denial of Service (DoS) Attack- picateshackz.com

If you are working in the field of computer networks or an enthusiast in the field of network security, you are sure to have come across the term “Denial of Service attack” which is simply referred to as “DoS attack”. Today, this is one of the most common types of network attacks carried out on the Internet. In this post, I will try to explain DoS attack, its variants and methods involved to carry out the same in an easily understandable manner.

What is a DOS Attack?

Denial of Service or DoS attack is a type of network attack designed to flood the target network or machine with a large amount of useless traffic so as to overload it and eventually bring it down to its knees. The main intention behind DoS attack is to make the services running on the target machine (such as a website) temporarily unavailable to its intended users. DoS attacks are usually carried out on web servers that host vital services such as banking, e-commerce or credit card processing.
A common variant of DOS attack known as DDoS (Distributed Denial of Service) attack has become quite popular in the recent days as it is more powerful and hard to detect. A typical DoS attack has a single place of origin while a DDoS attack originates from multiple IP addresses distributed across two or more different network. The working of a DDoS attack is shown in the following diagram:

Unlike a DoS attack where the attacker uses one single computer or a network to attack the target, a DDoS the attack originates from different pre-compromised computers belonging to different networks. As the attacker uses a number of computer systems from different networks each residing in different geographical locations, the incoming traffic looks natural and therefore becomes hard to detect.

Protection Against DoS/DDoS Attacks:

DoS attacks can easily be handled by blacklisting the target IP (or range of IPs) that are found to be making too many requests/connections (in an unnatural way) to the server. However, DDoS attacks are complicated as the incoming requests seem more natural and distributed. In this case it is hard to find the difference between the genuine and malicious traffic. Taking an action at the firewall level to blacklist suspected IPs may result in false positives and therefore may affect the genuine traffic as well.

How to defend against a sync flood attack:

What are some ways to protect against sync flood attacks?
A Sync flood attack, better known as a SYN attack, has its origins as one of the original types of distributed denial-of-service (DDoS) attacks and have not been significant threats to enterprises today. Most CERT advice from 1996 still applies to modern systems, but obviously many improvements have been made in the last 15 years.


A SYN attack is one where an attacker makes an initial connection to a victim computer and the victim computer waits for the completion of the connection. The attack is exploiting part of the three-way handshake in TCP for establishing reliable connections. When the initial connection is left open, it consumes resources on the victim computer until it runs out of connections or has other issues.

To protect against sync flood attacks, you have several options. The attacks can be detected by standard intrusion detection systems (IDS) and could also be blocked or minimized by built-in features in firewalls and other devices. Further protections could include lowering timeouts for how long a system waits for another system to complete the three-way handshake or having your ISP block the attacks.




Methods Involved in DoS Attack

The following are some of the commonly employed methods in carrying out a DoS attack:
  • SYN Flood Attack
  • Ping Flood Attack (Ping of Death)
  • Teardrop Attack
  • Peer-to-Peer Attacks

1. SYN Flood Attack




SYN flooding is an attack vector for conducting a denial-of-service (DoS) attack on a computer server.


The attack involves having a client repeatedly send SYN (synchronization) packets to every port on a server, using fake IP addresses. When an attack begins, the server sees the equivalent of multiple attempts to establish communications. The server responds to each attempt with a SYN/ACK (synchronization acknowledged) packet from each open port, and with a RST (reset) packet from each closed port.


In a normal three-way handshake, the client would return an ACK (acknowledged) packet to confirm that the servers SYN/ACK packet was received, and communications would then commence. However, in a SYN flood, the ACK packet is never sent back by the hostile client. Instead, the client program sends repeated SYN requests to all the servers ports. A hostile client always knows a port is open when the server responds with a SYN/ACK packet.

The hostile client makes the SYN requests all appear valid, but because the IP addresses are fake ones, it is impossible for the server to close down the connection by sending RST packets back to the client. Instead, the connection stays open. Before time-out can occur, another SYN packet arrives from the hostile client. A connection of this type is called a half-open connection. Under these conditions, the server becomes completely or almost completely busy with the hostile client and communications with legitimate clients is difficult or impossible. For this reason, SYN floods are also known as half-open attacks.

The transmission by a hostile client of SYN packets for the purpose of finding open ports and hacking into one or more of them, is called SYN scanning.



2. Ping Flood Attack (Ping of Death)




Ping of Death (a.k.a. PoD) is a type of Denial of Service (DoS) attack in which an attacker attempts to crash, destabilize, or freeze the targeted computer or service by sending malformed or oversized packets using a simple ping command.
While PoD attacks exploit legacy weaknesses which may have been patched in target systems. However, in an unpatched systems, the attack is still relevant and dangerous. Recently, a new type of PoD attack has become popular. This attack, commonly known as a Ping flood, the targeted system is hit with ICMP packets sent rapidly via ping without waiting for replies.
Attack Description
The size of a correctly-formed IPv4 packet including the IP header is 65,535 bytes, including a total payload size of 84 bytes. Many historical computer systems simply could not handle larger packets, and would crash if they received one. This bug was easily exploited in early TCP/IP implementations in a wide range of operating systems including Windows, Mac, Unix, Linux, as well as network devices like printers and routers.
Since sending a ping packet larger than 65,535 bytes violates the Internet Protocol, attackers would generally send malformed packets in fragments. When the target system attempts to reassemble the fragments and ends up with an oversized packet, memory overflow could occur and lead to various system problems including crash.
Ping of Death attacks were particularly effective because the attacker’s identity could be easily spoofed. Moreover, a Ping of Death attacker would need no detailed knowledge of the machine he/she was attacking, except for its IP address.
It is worthy of note that this vulnerability, though best recognized for its exploitation by PoD attacks, can actually be exploited by anything that sends an IP datagram - ICMP echo, TCP, UDP and IPX.
Methods of Mitigation
To avoid Ping of Deatch attacks, and its variants, many sites block ICMP ping messages altogether at their firewalls. However, this approach is not viable in the long term.

Firstly, invalid packet attacks can be directed at any listening port—like FTP ports—and you may not want to block all of these, for operational reasons.

Moreover, by blocking ping messages, you prevent legitimate ping use – and there are still utilities that rely on ping for checking that connections are live, for example.Incapsula mitigates a massive HTTP flood: 690,000,000 DDoS requests from 180,000 botnets IPs.



The smarter approach would be to selectively block fragmented pings, allowing actual ping traffic to pass through unhindered.

Incapsula DDoS Protection services intelligently and preemptively identify and filter out all abnormally large packets, even if they are fragmented—eliminating the threat of PoD and similar packet-based attacks altogether.


3. Teardrop Attack


A teardrop attack is a denial-of-service (DoS) attack that involves sending fragmented packets to a target machine. Since the machine receiving such packets cannot reassemble them due to a bug in TCP/IP fragmentation reassembly, the packets overlap one another, crashing the target network device. This generally happens on older operating systems such as Windows 3.1x, Windows 95, Windows NT and versions of the Linux kernel prior to 2.1.63.

One of the fields in an IP header is the “fragment offset” field, indicating the starting position, or offset, of the data contained in a fragmented packet relative to the data in the original packet. If the sum of the offset and size of one fragmented packet differs from that of the next fragmented packet, the packets overlap. When this happens, a server vulnerable to teardrop attacks is unable to reassemble the packets - resulting in a denial-of-service condition.


Definition - What does Teardrop Attack mean?

A teardrop attack is a denial of service (DoS) attack conducted by targeting TCP/IP fragmentation reassembly codes. This attack causes fragmented packets to overlap one another on the host receipt; the host attempts to reconstruct them during the process but fails. Gigantic payloads are sent to the machine that is being targeted, causing system crashes.

Techopedia explains Teardrop Attack
While much more popular on older versions of Windows, the teardrop attack is also possible on Windows 7 and Windows Vista machines that have SMB enabled. The driver vulnerability on the latter two operating systems was noted in 2009, but Windows 2000 and Windows XP are not vulnerable to this type of teardrop attack, which hones in on TCP ports 139 and 445 on the firewalls of the SMB-enabled machines. If users don’t have patches to protect against this DoS attack, SMBv2 should be disabled, as recommended by Microsoft, and ports 139 and 445 should be blocked.


4. Peer-to-Peer Attacks


The evolution of computing continues to lead to greater decentralization. Mainframes gave way to local area networks (LANS), which provided greater economies of scale. The Internet has allowed for even greater distribution capability; peer to peer computing has grown as a result. Examples of peer to peer networks include the popular Kazaa and Napster file sharing services. These types of networks allow for significant transfers of data, yet they are vulnerable to attack from multiple sources.


Definition

Peer relationship exploitation can be defined in several ways. First, it can be the exploitation of transitive trust relationships created by peer-networking so as to expand privileges to the transitive closure of peer trust. It can also be defined in less technical terms. Exploitation can be when an insider uses the security access of colleagues to gain access to unauthorized information.  This can include physical access or information access. This essay will focus on the first type of attack.



Recommended Articles To Become A Hacker:

How To Become A Hacker - Basic Guide For Beginners 2015

Understand The Hacker Mindset To Become A Real Hacker

Programming Languages For Hackers And Learn It From Most 6 Helpful Websites

Installing Hackers OS Kali Linux In VMware (Beginners Guide With Screenshots)

Easy Steps to Create Web Penetration Testing Lab in Kali Linux

Introduction to using Metasploit in Kali Linux

An Introduction To Hacker’s OS: Kali Linux And Setup Tutorial.

Linux Powerful Distros For Hacking Or Security: Kali, Tails And Qubes

Become A Hacker: What Is Denial of Service (DoS) Attack?



Available link for download

Read more »

Saturday, May 20, 2017

Being a Feminist is Hard and Other Thoughts from a Filmic Female Dreamer

Being a Feminist is Hard and Other Thoughts from a Filmic Female Dreamer


Prepare for a post full of paradoxes. About time I gave meaning to the shitty, nonsensical title I gave this blog when I was 14 and impaired by my Inception obsession.


I swore I would never write a big post on the state of feminism/females in the film industry. But after Ryan, who will forever be the rabbit I chase (not insinuating you are a rabbit, Ryan, but you get the metaphor Im heading for here), posted a piece on Lena Dunham not pushing her case for females being given opportunities in the whole entertainment industry hard enough, I chimed in on the comments section. And hey, in the two hours of lectures that came after that comment, I decided I want to make a post on this ongoing saga.

Ive never seen anything Lena Dunham has done apart from This is 40. Girls has been on my watchlist but considering I still havent seen Game of Thrones season three, I dont think Ill be getting around to it any time soon. So really, I cant judge her standings on anything, but she did raise some valid points at SXSW where she noted that Adam Driver is getting some great role offers, yet the central female cast are not. Ryan said that Lena should aspire to write about more females rather than the ones she knows of. Fair points all round.



This is where I stand on feminism. You probably know by now that I want to be a filmmaker. Its leaning more towards writing screenplays because I want to write about females. The reason that I want to be a filmmaker stems back to the literal moment that Kathryn Bigelow won an Oscar for Best Director in 2010 (though she did win for a largely "male" film, which critics are quick to point out, but AT LEAST IT HAPPENED). Late last year, likely due to procrastination, I found myself reading Indiewire religiously, especially the Women in Hollywood/other pieces on women. Anything else I could find on the internet about this topic, I would read. I still do it. However, as this is inspiring and fuels my aspirations more, its also poisonous.



I dont claim to know what it is like in the film industry for a filmmaker, and maybe in 20 years if I ever do achieve my dream my tune will be changed. But I feel like all we ever do is talk about these problems. Sure, its great to talk. Its what Im doing right now. If I were to ever become famous enough to do a Ted Talk or something (which is one of my many weird aspirations), this is what Id be saying:

Continuing to talk about these problems with a low rate of females in the film industry is like that eight year old girl who begs her parents to let her have a pony but she lives on the 10th floor of an apartment building in the middle of a city. But she wants one just because that’s the thing you want when you’re an eight year old girl. If she were to have the pony, she’d have to go live on a farm, go back to the grassroots, and work hard to look after that pony. What we need to do is go back to the root of the problem and start again. Work hard to preserve what we want if we want it enough. Creating the opportunities instead of settling with the opportunities made available to us. Because that girl is never going to get a pony on that 10th floor. If she really wanted it, she’d have to create her own opportunities and work hard to preserve it. Im not saying that the eight year old girl can go out and buy a farm, but its not entirely impossible either. Her parents may keep telling her no, and then all of a sudden when that girl is able to buy her own farm, she no longer wants to have a pony. If we keep pointing out the flaws in the system, were going to stop wanting to fix them.

Perseverance is key. The uncompromising power that you threaten the normal with is key. Creating the opportunities that you want to see, instead of talking about them for many people to go "hey, cool idea kid", but they dont actually do anything about them.





But hey, who am I to talk? Im not a filmmaker. I dont even fully believe in my dream (thanks to other poisonous ideals that come with the film industry). If I still persevere with this dream, this is the change Id like to see. All I have to do is think back to moments like Kathryn Bigelow winning an Oscar, Cate Blanchett outing the sexism in Hollywood in her Oscar acceptance speech, Jessica Chastains character in Zero Dark Thirty, the filmographies of the likes of Blanchett, Chastain, Katharine Hepburn, Meryl Streep, Amy Adams etc etc etc to see that great stuff has happened, so instead of complaining, lets persevere.





And yet, the biggest flaw in the system is that we constantly have an arrow in the back of these mythical "strong female characters". You wanna know one of the most underrated characters of 2013? Margot Robbie as Naomi in The Wolf of Wall Street. Here we have a film clearly about misogyny, and an extremely misogynistic man, and in the middle of all this we have this woman who fits Jordan Belforts misogynistic ideals. People were quick to comment on the fact that Margot doesnt wear much in the way of clothing, but heres what she has to say:
"As for my character in particular, the nudity and the sexual side to her is her main power over Jordan. She uses that to manipulate men to get what she wants. That’s her form of currency in a world where she’s surrounded by millionaires, and she’s come from nothing. She didnt have any money whatsoever. That’s how she became a millionaire, you know? So she definitely wouldnt see it that way. She wouldnt feel sorry for herself for having to take her clothes off. She would do that willingly. In fact, she would pity the men that are dumb enough to fall for it. It’s her form of power, so it wouldnt feel exploitative for my character at all."
Shes just as materialistic and money-obsessed as Jordan, just in a different way. And at the end of the film, the domestic violence comes into play and that became a big controversy, but does that mean that Naomi loses her power over Jordan? Is she weak? No and no. Shes a fighter, Jordan is a heinous and disgusting man. And yet, all anyone wanted to talk about were all her nude scenes, and how that weakened her "feminist standing". She made a complete fool of Jordan and his stupid ideals! Also, it was a perfect deconstruction of the "trophy wife" being a part of the prized American Dream. We see her right from her introduction into the dream and how she gets out of it.

The "strong female character" is something that makes it so hard to be a feminist. Critics are quick to say that Katniss Everdeen is a great female character because shes strong, but shes weakened by her love triangle. As soon as men come into play, females lose their "strength". Maybe its because of an over-saturation of romantic comedies. But, I dont know, just because Im a female who might be in love with a guy, does that all of a sudden mean that Im a weaker human being? Feminism and the "strong female character" seems bent on erasing males. If its equality youre looking for, you may as well show how they can balance and co-exist and stop trying to have them in a power play thats all based on strength. Weak women are interesting. Powerful women are interesting. Weak women pretending to be powerful are interesting. WOMEN CAN BE INTERESTING. You just need to give them a chance to be interesting.


Also, "strong female character" is basically a synonym for "female character given male qualities to be seen as strong". Can we stop with this notion that males are the end all of strength? MALES AND FEMALES ARE DIFFERENT KINDS OF PEOPLE. This does not mean that they arent equal. Just because a woman puts a lot of effort into her appearance, is scared of breaking her nails, dyes her hair all the time, wears lots of make-up does not mean that she isnt strong. In fact, actresses are the strongest of all because they have to put up with the bullshit Hollywood standards. Thats another post in itself (because the tabloid industry is just ridiculously sexist). Just dont ever think for one second that making a female character with solely male sensibilities will make them a "strong female character". A woman can break down crying if she wants to (case in point: people who didnt understand why Maya was crying at the end of Zero Dark Thirty). A woman can pin all her hopes on a man if she wants to. A woman can yell and scream until she gets what she wants. The moment you start looking for the qualities of a "strong female character", youve lost a good female character.

Lets stop pretending like females dont happen in Hollywood. They have before, they are now. Lets keep persevering and stop poisoning.

Otherwise, people like me wont want to write films about female characters because we dont want them to be so dependent on males. We want to make them appropriations of all of these contradictory feminist ideals, so much so that they arent human. Everyones so quick to say that theres a right and wrong way of writing female characters. And its awfully restricting.

We are never going to have a perfect balance. We are never going to have equal opportunities. But to have people actually trying is better than nothing.

One last thing: it isnt the fault of women that theyre under-represented in films. If we spent all of our energy waiting for the person at fault to fix their wrongs, were going to be waiting an awful long time. Be the change you want to see. Thats all there is to it.

Available link for download

Read more »

Thursday, May 4, 2017

BETWEEN OLIVE OIL VS COCONUT OIL WHICH IS BETTER

BETWEEN OLIVE OIL VS COCONUT OIL WHICH IS BETTER




  1. There is always a debate, always an argument – which oil is heart friendly? Which oil is better for your skin? Which oil makes the hair shinier–olive oil or coconut oil? We are not the ones to take sides! So, this article attempts at an honest comparison of the healthy oils, their nutrient quotient, and their pros and cons.

    Nutritional Information Of Both The Oils:


    Let us first compare the nutrient quotient of both olive oil and coconut oil:
    1 Tbsp. Extra Virgin Olive Oil1 Tbsp. Coconut Oil
    Calories120120
    Total fat (g)1414
    Saturated fat (g)112
    Cholesterol (mg)00

    What Does The Chart Indicate?


    Let’s have a look at the indications, which the above mentioned chart is providing:
    • Going by calories, both olive oil and coconut oil offer same amount of calorie.
    • The difference is the amount of saturated fat. 1 tbsp. of coconut oil contains 12g of saturated fat, whereas olive oil contains just 1g of it. The primary constituent of saturated fat is lauric acid. Other than that, there is no other difference.
    • But, according to the American Heart Association, the daily intake of fat should be within 25 to 35% of the daily calorie intake. And not more than 7% of that should be saturated fat. So, your daily diet should also contain dairy products. Coconut oil provides more saturated fat than the requirement of the body.
    • Olive oil contains more good fats. Monounsaturated fats present in olive oil have more benefits for the body. Oleic acid, one of the monounsaturated fatty oils, is helpful in lowering blood pressure, and preventing cardiovascular diseases.


    • Olive oil also contains antioxidants. We all know the importance of antioxidants in warding off free radicals and protecting us against skin damage, cancer and many bother diseases.

    Health wise, olive oil look better on paper.
    Let’s Compare The Benefits!

    Let’s now compare the benefits of both the oils for skin and health to get a clear idea:
    Coconut Oil Benefits:

    Let’s first look at the benefits of coconut oil:

    1. Coconut oil is beneficial in soothing dry skin. The skin on the face, hand, and feet can get benefits from the moisturizing effects of coconut oil.
    2. It is also used as a replacement for shaving cream.
    3. Coconut oil also serves as deep conditioner for hair. It is one of the nice ways to moisturize dry and dull hair.
    4. Coconut oil can also be used as a makeup remover.

    Olive Oil Benefits:

    Let’s now read on to know the benefits of olive oil:
    1. Olive oil, on the other hand, is more moisturizing than coconut oil. When coconut oil fails, olive oil comes to the picture.
    2. Thick and curly hair gets benefits from olive oil than coconut oil when it comes to moisturizing.
    3. For frizzy hair, olive oil is a good after wash serum.
    4. It also can be used as an alternative to shaving cream.
    5. Olive oil helps cure diaper rashes, little cuts and wounds too.


    We must keep in mind that at the end of the day, both the oils are processed. Both the oils are loaded with calorie. When the oil claims to be ‘heart healthy’, remember that it means to prevent the heart diseases to

    some extent. Also avoid oily food, if you are suffering from a disease. As of now, there is a fad of using both coconut oil and olive oil. Both the oils are regarded best in their own unique ways. But it is important to

    understand that research is still in progress to prove the claims. So, before using any oil in excess, talk to your doctor and choose the oil that best suits your health.

    Which oil rules your kitchen? Why this particular oil? What keeps you away from using coconut and olive oil? Share your views with us in the comments section below.
    Source: 1 , 2 , 3 , 4

Available link for download

Read more »