suck-o.com - mind over matterHacking, coding, web development, lots of high quality downloads and friendly forums. Join our community, we are non-commercial and independent!http://www.suck-o.com/index.php2010-09-07T00:23:08ZJoomla! 1.5 - Open Source Content ManagementWelcome2009-09-03T18:41:39Z2009-09-03T18:41:39Zhttp://www.suck-o.com/index.php/component/content/article/35-frontpage/49-welcomebad_brainbad_brain@suck-o.com<p style="text-align: center;"><span class="option" style="color: #000000;"><strong>Welcome to suck-o.com!</strong></span></p>
<p style="text-align: center;"><br /> <span class="content"><strong><span style="color: #ff0000;">Become a member!</span></strong><br /><br /> Receive help on the forums (no flames, beginners welcome,german and english)<br /> Download free and (mostly) open source software with a hacky touch and general useful programs of any kind!<br /><br />It´s absolutely free, just register as a member...<br /> <strong>We don´t give away user data or send spam to our members.<br /> Guaranteed!</strong><br /><br /> Enjoy your visit!</span></p><p style="text-align: center;"><span class="option" style="color: #000000;"><strong>Welcome to suck-o.com!</strong></span></p>
<p style="text-align: center;"><br /> <span class="content"><strong><span style="color: #ff0000;">Become a member!</span></strong><br /><br /> Receive help on the forums (no flames, beginners welcome,german and english)<br /> Download free and (mostly) open source software with a hacky touch and general useful programs of any kind!<br /><br />It´s absolutely free, just register as a member...<br /> <strong>We don´t give away user data or send spam to our members.<br /> Guaranteed!</strong><br /><br /> Enjoy your visit!</span></p>General says cyber attacks must be stopped2010-08-20T16:58:07Z2010-08-20T16:58:07Zhttp://www.suck-o.com/index.php/the-news/130-cyber-attacks-must-be-stoppedhpprinter100bad_brain@suck-o.com<p>Former NATO commander General Wesley Clark has confirmed a "growing number" of severe cyber attacks against US government and commercial installations.<br />According to Clark, the US currently possesses both the technology and "means" to stop the unrelenting cyber offensive.<br />General says cyber attacks must be stopped"The job now is to deploy these assets as soon as possible," Clark told an audience of security specialists at the National Press Club.</p>
<p>Former NATO commander General Wesley Clark has confirmed a "growing number" of severe cyber attacks against US government and commercial installations.<br />According to Clark, the US currently possesses both the technology and "means" to stop the unrelenting cyber offensive.<br />General says cyber attacks must be stopped"The job now is to deploy these assets as soon as possible," Clark told an audience of security specialists at the National Press Club.</p>
RFID of automobiles, tire pressure sensor2010-08-15T14:32:59Z2010-08-15T14:32:59Zhttp://www.suck-o.com/index.php/the-news/129-rfid-of-automobiles-tire-pressure-sensordnrbad_brain@suck-o.com<p><span style="\">The pressure sensors contain unique IDs, so merely eavesdropping enabled the researchers to identify and track vehicles remotely.</span> Earlier in the year, researchers from the University of Washington and University of California San Diego showed that the ECUs could be hacked, giving attackers the ability to be both annoying, by enabling wipers or honking the horn, and dangerous, by disabling the brakes or jamming the accelerator. The Rutgers and South Carolina research will be presented at the USENIX Security conference later this week.</p>
<p><span style="\">The pressure sensors contain unique IDs, so merely eavesdropping enabled the researchers to identify and track vehicles remotely.</span> Earlier in the year, researchers from the University of Washington and University of California San Diego showed that the ECUs could be hacked, giving attackers the ability to be both annoying, by enabling wipers or honking the horn, and dangerous, by disabling the brakes or jamming the accelerator. The Rutgers and South Carolina research will be presented at the USENIX Security conference later this week.</p>
Dangerous iPhone exploit code goes public 2010-08-13T13:25:51Z2010-08-13T13:25:51Zhttp://www.suck-o.com/index.php/the-news/127-dangerous-iphone-exploit-code-goes-public-dnrbad_brain@suck-o.com<p class="\"first\"">"Comex", the developer of JailbreakMe 2.0, <a href="http://twitter.com/comex/status/20918593762" target="_blank" title="iphone xploit source code"><span style="\"><span style="\">posted source code</span></span></a> for the hacks that leveraged two vulnerabilities in iOS and allowed <span style="\"><span style="\">iPhone</span></span> owners to install unauthorized apps. Minutes after Apple issued a security update Wednesday, the maker of a 10-day-old jailbreak exploit released code that others could put to use hijacking iPhones, iPod Touches and iPads.</p>
<p>The exploits that comex used to jailbreak the iOS could be used for other purposes, including <a href="http://redirectingat.com/?id=803X112722&xs=1&url=http%3A%2F%2Fwww.computerworld.com%2Fs%2Farticle%2F9180099%2FiPhone_jailbreak_exploit_sweet_and_scary_says_researcher&sref=http%3A%2F%2Fwww.macworld.co.uk%2Fnews%2Findex.cfm%3Folo%3Demail%26NewsID%3D3235206" target="_blank" title="iphone malicious payload"><span style="\"><span style="\">delivering malicious payloads</span></span></a> to grab control of iPhones, <a href="http://www.suck-o.com/\"><span style="\"><span style="\">iPads</span></span></a> , and iPod Touches. All that would be necessary is for hackers to dupe users into visiting a malicious Web site or persuading them to click on a link in an e-mail or text message.</p>
<p class="\"first\"">"Comex", the developer of JailbreakMe 2.0, <a href="http://twitter.com/comex/status/20918593762" target="_blank" title="iphone xploit source code"><span style="\"><span style="\">posted source code</span></span></a> for the hacks that leveraged two vulnerabilities in iOS and allowed <span style="\"><span style="\">iPhone</span></span> owners to install unauthorized apps. Minutes after Apple issued a security update Wednesday, the maker of a 10-day-old jailbreak exploit released code that others could put to use hijacking iPhones, iPod Touches and iPads.</p>
<p>The exploits that comex used to jailbreak the iOS could be used for other purposes, including <a href="http://redirectingat.com/?id=803X112722&xs=1&url=http%3A%2F%2Fwww.computerworld.com%2Fs%2Farticle%2F9180099%2FiPhone_jailbreak_exploit_sweet_and_scary_says_researcher&sref=http%3A%2F%2Fwww.macworld.co.uk%2Fnews%2Findex.cfm%3Folo%3Demail%26NewsID%3D3235206" target="_blank" title="iphone malicious payload"><span style="\"><span style="\">delivering malicious payloads</span></span></a> to grab control of iPhones, <a href="http://www.suck-o.com/\"><span style="\"><span style="\">iPads</span></span></a> , and iPod Touches. All that would be necessary is for hackers to dupe users into visiting a malicious Web site or persuading them to click on a link in an e-mail or text message.</p>
DefCon is Over, here is the best...2010-08-08T02:31:39Z2010-08-08T02:31:39Zhttp://www.suck-o.com/index.php/the-news/126-defcon-is-over-here-is-the-bestdnrbad_brain@suck-o.com<p><img src="http://www.suck-o.com/images/stories/users/d41d8cd98f00b204e9800998ecf8427e" border="0" align="left" /></p>
<p>The DefCon conference ended on Sunday, and this year’s edition of the “World’s Largest Hacker Conference” (as many call it) didn’t disappoint. We have news and coverage from a forensic and incident response viewpoint, including news about the Wikileaks incident you might not have seen elsewhere.</p>
<p><img src="http://www.suck-o.com/images/stories/users/d41d8cd98f00b204e9800998ecf8427e" border="0" align="left" /></p>
<p>The DefCon conference ended on Sunday, and this year’s edition of the “World’s Largest Hacker Conference” (as many call it) didn’t disappoint. We have news and coverage from a forensic and incident response viewpoint, including news about the Wikileaks incident you might not have seen elsewhere.</p>
How I met your girlfriend - DefCon Lecture2010-08-03T23:57:23Z2010-08-03T23:57:23Zhttp://www.suck-o.com/index.php/the-news/125-how-i-met-your-girlfriend-defcon-lecturednrbad_brain@suck-o.com<p>{jcomments on}</p>
<p><img src="http://www.suck-o.com/images/stories/users/d41d8cd98f00b204e9800998ecf8427e" border="0" align="left" /></p>
<p><strong>Samy Kamkar</strong>, in an incredibly interesting session at Black Hat titled “<strong>How I Met Your Girlfriend</strong>,” highlighted new types attacks executed from the Web. An interesting hack he demonstrated, was the ability to extract extremely accurate geo-location information from a Web browser, while not using any IP geo-location data.</p>
<p>Kamkar, by convincing the victim to visit his malicious Web site, used remote JavaScript and AJAX to acquire a routers MAC address. When the unsuspecting user visited his malicious Web site, JavaScript remotely scanned for the type of router used, accessed the routers MAC address and sent it directly to him. From there, he was able to utilize Google Street View data to determine the location of a router – in his case, accurate within 30 feet.</p>
<p>Kamkar, author of an XSS worm that hit MySpace and generated over 1mm friends for him in less than 24 hours, demonstrates this hack in the video below.</p>
<p style="\"><span style="\"> </span></p>
<p style="\">
<object id="\"flashObj\"" width="\"480\"" height="\"270\"" type="\"application/x-shockwave-flash\"" data="\"http://c.brightcove.com/services/viewer/federated_f9/275273538001?isVid=1&isUI=1\"">
</object>
</p>
<p style="text-align: center;">Video of Samy Kamkar demonstrating the geolocation hack from his talk at Black Hat 2010 last week in Las Vegas:</p>
<p style="text-align: center;"> </p>
<p style="text-align: center;"> </p>
<p style="text-align: center;">
<object id="flashObj" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" width="480" height="270" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9,0,47,0">
<param name="movie" value="http://c.brightcove.com/services/viewer/federated_f9/275273538001?isVid=1&isUI=1" />
<param name="bgcolor" value="#FFFFFF" />
<param name="flashVars" value="videoId=374584550001&playerID=275273538001&domain=embed&dynamicStreaming=true" />
<param name="base" value="http://admin.brightcove.com" />
<param name="seamlesstabbing" value="false" />
<param name="allowFullScreen" value="true" />
<param name="swLiveConnect" value="true" />
<param name="allowScriptAccess" value="always" /><embed type="application/x-shockwave-flash" width="480" height="270" src="http://c.brightcove.com/services/viewer/federated_f9/275273538001?isVid=1&isUI=1" bgcolor="#FFFFFF" flashvars="videoId=374584550001&playerID=275273538001&&domain=embed&dynamicStreaming=true" base="http://admin.brightcove.com" name="flashObj" seamlesstabbing="false" allowfullscreen="true" allowscriptaccess="always" swliveconnect="true" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></embed>
</object>
</p>
<p style="text-align: center;"> </p><p>{jcomments on}</p>
<p><img src="http://www.suck-o.com/images/stories/users/d41d8cd98f00b204e9800998ecf8427e" border="0" align="left" /></p>
<p><strong>Samy Kamkar</strong>, in an incredibly interesting session at Black Hat titled “<strong>How I Met Your Girlfriend</strong>,” highlighted new types attacks executed from the Web. An interesting hack he demonstrated, was the ability to extract extremely accurate geo-location information from a Web browser, while not using any IP geo-location data.</p>
<p>Kamkar, by convincing the victim to visit his malicious Web site, used remote JavaScript and AJAX to acquire a routers MAC address. When the unsuspecting user visited his malicious Web site, JavaScript remotely scanned for the type of router used, accessed the routers MAC address and sent it directly to him. From there, he was able to utilize Google Street View data to determine the location of a router – in his case, accurate within 30 feet.</p>
<p>Kamkar, author of an XSS worm that hit MySpace and generated over 1mm friends for him in less than 24 hours, demonstrates this hack in the video below.</p>
<p style="\"><span style="\"> </span></p>
<p style="\">
<object id="\"flashObj\"" width="\"480\"" height="\"270\"" type="\"application/x-shockwave-flash\"" data="\"http://c.brightcove.com/services/viewer/federated_f9/275273538001?isVid=1&isUI=1\"">
</object>
</p>
<p style="text-align: center;">Video of Samy Kamkar demonstrating the geolocation hack from his talk at Black Hat 2010 last week in Las Vegas:</p>
<p style="text-align: center;"> </p>
<p style="text-align: center;"> </p>
<p style="text-align: center;">
<object id="flashObj" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" width="480" height="270" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9,0,47,0">
<param name="movie" value="http://c.brightcove.com/services/viewer/federated_f9/275273538001?isVid=1&isUI=1" />
<param name="bgcolor" value="#FFFFFF" />
<param name="flashVars" value="videoId=374584550001&playerID=275273538001&domain=embed&dynamicStreaming=true" />
<param name="base" value="http://admin.brightcove.com" />
<param name="seamlesstabbing" value="false" />
<param name="allowFullScreen" value="true" />
<param name="swLiveConnect" value="true" />
<param name="allowScriptAccess" value="always" /><embed type="application/x-shockwave-flash" width="480" height="270" src="http://c.brightcove.com/services/viewer/federated_f9/275273538001?isVid=1&isUI=1" bgcolor="#FFFFFF" flashvars="videoId=374584550001&playerID=275273538001&&domain=embed&dynamicStreaming=true" base="http://admin.brightcove.com" name="flashObj" seamlesstabbing="false" allowfullscreen="true" allowscriptaccess="always" swliveconnect="true" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></embed>
</object>
</p>
<p style="text-align: center;"> </p>Attack Of the Facebook Snatchers 22010-07-28T23:21:38Z2010-07-28T23:21:38Zhttp://www.suck-o.com/index.php/the-news/123-attack-of-the-facebook-snatchers-2dnrbad_brain@suck-o.com<p><span style="style"><span style="style">@FSLabsAdvisor</span></span> wrote an interesting <a href="https://twitter.com/FSLabsAdvisor" target="_blank"><span style="style"><span style="style">Tweet</span></span></a>:</p>
<p>it turns out, by heading to <span style="style"><span style="style">https://www.facebook.com/directory</span></span>, you can get a list of every searchable user on all of Facebook!</p>
<p>My first idea was simple: spider the lists, generate first-initial-last-name (and similar) lists, then hand them over to <a href="https://twitter.com/ithilgore" target="_blank"><span style="style"><span style="style">@Ithilgore</span></span></a> to use in Nmap's awesome new bruteforce tool he's working on, <a href="http://nmap.org/ncrack/" target="_blank"><span style="style"><span style="style">Ncrack</span></span></a>.</p>
<p> </p>
<p><span style="style"><span style="style">@FSLabsAdvisor</span></span> wrote an interesting <a href="https://twitter.com/FSLabsAdvisor" target="_blank"><span style="style"><span style="style">Tweet</span></span></a>:</p>
<p>it turns out, by heading to <span style="style"><span style="style">https://www.facebook.com/directory</span></span>, you can get a list of every searchable user on all of Facebook!</p>
<p>My first idea was simple: spider the lists, generate first-initial-last-name (and similar) lists, then hand them over to <a href="https://twitter.com/ithilgore" target="_blank"><span style="style"><span style="style">@Ithilgore</span></span></a> to use in Nmap's awesome new bruteforce tool he's working on, <a href="http://nmap.org/ncrack/" target="_blank"><span style="style"><span style="style">Ncrack</span></span></a>.</p>
<p> </p>
5 Pakistani hackers behind the bars2010-07-25T20:53:13Z2010-07-25T20:53:13Zhttp://www.suck-o.com/index.php/the-news/122-5-pakistani-hackers-behind-the-barsBroken Angelbad_brain@suck-o.com<p>The Following news confirms that 7 Pakistani hackers working together against many government organisations and defacing their pages have been caught and been send behind Bars after many and continuous complaints against them.</p>
<p> </p>
<p>The Following news confirms that 7 Pakistani hackers working together against many government organisations and defacing their pages have been caught and been send behind Bars after many and continuous complaints against them.</p>
<p> </p>
Call it Pornistan...2010-07-16T11:23:24Z2010-07-16T11:23:24Zhttp://www.suck-o.com/index.php/the-news/121-call-it-pornistanbad_brainbad_brain@suck-o.com<p><span style="color: #ff0000;">source: Fox News</span></p>
<p style="font-size: 13px;">They may call it the "Land of the Pure," but Pakistan turns out to be anything but.</p>
<p style="font-size: 13px;">The Muslim country, which has banned content on at least 17 websites to block offensive and blasphemous material, is the world's leader in online searches for pornographic material, FoxNews.com has learned.</p>
<p style="font-size: 13px;">“You won’t find strip clubs in Islamic countries. Most Islamic countries have certain dress codes,” said Gabriel Said Reynolds, professor of Islamic Studies at the University of Notre Dame. “It would be an irony if they haven’t shown the same vigilance to pornography.”</p>
<p style="font-size: 13px;">So here's the irony: Google ranks Pakistan No. 1 in the world in searches for pornographic terms, outranking every other country in the world in searches per person for certain sex-related content.</p>
<p style="font-size: 13px;">
<p><span style="color: #ff0000;">source: Fox News</span></p>
<p style="font-size: 13px;">They may call it the "Land of the Pure," but Pakistan turns out to be anything but.</p>
<p style="font-size: 13px;">The Muslim country, which has banned content on at least 17 websites to block offensive and blasphemous material, is the world's leader in online searches for pornographic material, FoxNews.com has learned.</p>
<p style="font-size: 13px;">“You won’t find strip clubs in Islamic countries. Most Islamic countries have certain dress codes,” said Gabriel Said Reynolds, professor of Islamic Studies at the University of Notre Dame. “It would be an irony if they haven’t shown the same vigilance to pornography.”</p>
<p style="font-size: 13px;">So here's the irony: Google ranks Pakistan No. 1 in the world in searches for pornographic terms, outranking every other country in the world in searches per person for certain sex-related content.</p>
<p style="font-size: 13px;">
Symbian malware creates mighty zombie army2010-07-11T09:55:19Z2010-07-11T09:55:19Zhttp://www.suck-o.com/index.php/the-news/120-symbian-malware-creates-mighty-zombie-armyph0bYxph0byx@gmail.com<p><span style="color: blue;">By John Leyden, TheRegister.co.uk</span></p>
<p>Mobile malware that affects Symbian Series 60 handsets is being used to create a botnet.</p>
<p>Security firm NetQin claims as many as 100,000 smartphones have been compromised with the malware, which typically poses as a game and affects Symbian Series 60 3rd edition and 5th edition devices. NetQin said the malware is programmed to send SMS messages from compromised devices.</p>
<p> </p>
<p><span style="color: blue;">By John Leyden, TheRegister.co.uk</span></p>
<p>Mobile malware that affects Symbian Series 60 handsets is being used to create a botnet.</p>
<p>Security firm NetQin claims as many as 100,000 smartphones have been compromised with the malware, which typically poses as a game and affects Symbian Series 60 3rd edition and 5th edition devices. NetQin said the malware is programmed to send SMS messages from compromised devices.</p>
<p> </p>