Monday, June 14, 2010

Metasploit 101  

Metasploit 101 from PaulDotCom

Enjoy!

Wednesday, May 12, 2010

Philippine Securities and Exchange Commission website got defaced!  


Source: www.sec.gov.ph

Saturday, April 10, 2010

Is this your email password?  

The most common account password especially for email is "123456". How did I know? Two years ago, it ranks as top # 1 on whatsmypass.com's list of "Top 500 Worst Passwords of all Time" but people never learned as they still favor on using simple and easily-guessed passwords. And how do free email service providers respond on this? Let's take yahoo and gmail as examples.

I register a new yahoo account using "123456" as the password. It then displays as a "weak" password but still able to register the account (?). Definitely, Yahoo fails on this part.



How about the password "password"?



Good thing it is not accepted.

Another test account using "123456" as the password displays the strength as a "weak" one. Gmail does not accept weak or too short passwords as registration will fail. Same applies to the password "password".





Using simple passwords is not a new phenomenon. Thus experts’ advice not to use most common or easily-guessed passwords nor re-use it on other online accounts as it is vulnerable to hacking. Choose complex passwords. You may also check StaySafeOnline.org's article on Choosing Safe Passwords.

Monday, March 22, 2010

Mannyvillar.com.ph got hacked  

After an alleged rumor circulated via text messages early this month that AFP will carry out poll automation cheating dubbed as "Project Fullmoon" in favor to Senator Manny Villar with the assistance of a certain Korean hacker Martin Leebiong, the mockery towards the senator does not ends there.

Recently, the blog section of Senator Manny Villar's website (www.mannyvillar.com.ph) just got hacked. A blog post entry dated Mar 19, 2010 fictitiously coming from Kris Aquino, bash his campaign tactics and urge readers to vote her brother Noynoy Aquino instead.

Here is the complete message of the hacker before the post was taken down:

"Omigosh kalerky to the max. Imagine, may I gamit pa mga kids sa commercial to make sipsip to the poor. Pano naman kaming mga riichhh! Wala ba candidate na magpapakatotoo “For the rich, because I am rich!” Dapat ganun devah! Love it! So many eklat and whatnot. Why pa magpakahirap sa business kung mas mataas kita sa government di ba? Like I said to Boy regarding sa interview nila, “Taas ng TF, Amiiinin!”. Hay naku, vote for my brother Noynoy na lang, manang mana sa kanya si josh, ang cute di baah! Basta, for my hair magthank you na lang ako sa mga baklush sa pinoyhacking.com. Sila rin nagtina ng buhok ni MannyVillar ever! Greet ko na rin mga tga pinoygreyhat.org, makers ng gown ko, hay naku ang aarte nyo, pwede na kayo maging National Artist! Thanks din sa mga members ng ph****, ang official Kris Aquino fan club! Hug! Kisses!! muah muah muah! At sa mga samu’t saring pinoy hacker group, mga kumare asan na kayo!? Text text nyo naman me at makapag lamierda tayo! Love it!"


Monday, March 8, 2010

Suspicious website of the day --> e-games.com.ph  

From Google SERP:



Update:
(3/8/2010): Warning sign has been removed on SERP.

Suspicious website of the day --> o2jam.com.ph  

From Google SERP:

Wednesday, February 10, 2010

Suspicious website of the day --> computerworld.com.ph  

From Google SERP:

Monday, January 11, 2010

TESDA Website defaced  

The Technical Education and Skills Development Authority (TESDA) was the 5th victim of the continuous government website vandalism after its home page defaced by a hacker, leaving a message of sympathy to a certain "Kimay" addressed to abusive police officers and a picture of a man showing a nasty dirty finger.



This defacement follows the attack on other agencies like Department of Health (DOH), Department of Social Welfare and Development (DSWD), National Disaster Coordinating Council (NDCC), and Department of Labor and Employment (DOLE).

Tuesday, December 15, 2009

DOT PH (.ph) belongs to Top Ten Most Risky Domains  

Philippines dot ph (.ph) domain was recently listed this year by the virus company McAfee as one of the Top Ten Most Risky Domains using its SiteAdvisor and TrustedSource technologies. As summarized on below reports, dot ph (.ph) ranked 6th (overall worldwide risk) and ranked 4th (by country) with 2,272 risky domains.

http://us.mcafee.com/en-us/local/docs/Mapping_Mal_Web.pdf
http://us.mcafee.com/en-us/local/docs/Mapping_Mal_Web_Summary.pdf

Friday, December 4, 2009

Suspicious website of the day --> pinoyfreetxt.com  

Tuesday, November 3, 2009

Computerworld.com.ph website tagged as 'Harmful'  

Computerworld.com.ph website has been tagged as 'harmful' in Google SERP.


Update:
(11/5/2009): Computerworld.com.ph is unlisted in Google SERP as a 'suspicious' site.

Wednesday, October 21, 2009

Twitter's New Feature to Block Spammers  

Twitter introduces a new feature to block spammers. This can be done by clicking the 'Report [profile name] for Spam' button under Actions section of a profile's sidebar. With this, suspicious profile will be blocked on following or replying you.

This feature has not been applied automatically so that it will not be abused by twitterers who will intentionally report profiles as spam for those they don't like. Besides, reported spam profiles will be scrutinized manually by Twitter's Trust and Safety team for authentication.

Wednesday, October 14, 2009

Stay Safe While Online  

I stumbled on this site (StaySafeOnline.org) and it has lot of tips on how to stay safe while online. Protecting oneself while surfing the Internet does not need any technical knowledge. Just learning and applying the basic security practices can make a big difference in keeping oneself safe from Internet threats.

Wednesday, August 5, 2009

Corazon Aquino's Death used to Spread Malware  

While thousands of people lined up the streets in Manila to witness the funeral procession of former Philippine President Corazon C. Aquino, millions of Filipinos here in the country and in other parts of the world are deeply relying on television and mostly on the Internet in keeping them up-to-date on the latest news on the last farewell of the "Icon of Democracy". That is why cybercriminals are taking advantage by exploiting the news from Cory Aquino's death up to her funeral day by poisoning search engine results that leads to malicious links and redirect users to malware distribution sites. These Blackhat SEO attacks are not new as these were used even on the deaths of famous people like Michael Jackson and Farrah Fawcett. Here are some additional search queries or words that I used to locate suspicious websites similar to what Trend Micro Labs has found:


"corazon aquino funeral"
"corazon aquino burial"
"cory aquino funeral"
"cory aquino burial"


Security experts advise users to exercise extreme caution in searching for related news and information. Keep antivirus up-to-date and not to click or try to visit unknown websites even if the links are posted in emails, tweets, live streams and social networking sites.

Thursday, July 30, 2009

Datablitz.com.ph listed as a 'Suspicious' Site  


Google currently listed Datablitz.com.ph - the books, games and software distributor - as a 'Suspicious' site that may harm its visitors' computer. According to the Safebrowsing Diagnostic Page report, the malicious software is hosted on 1 domain, davtraff.com.


On the other hand, the Unmaskparasites report indicates two catalog index pages of Datablitz suspected to have malicious content. Website Administrators should constantly check the site and ask Google for a Malware review if listed as a suspicious site to avoid panic on its visitors.

Update:
(8/17/2009): Datablitz.com.ph is now unlisted in Google SERP as a 'suspicious' site.

Saturday, July 25, 2009

Twitter Clean-up: Strip Down Spam Accounts  

Twitter, the popular social networking and micro-blogging service, has currently took over security by cleaning up spam accounts. With this, you may lose followers who are not 'real people' as these accounts are bots that automatically follow Twitter users expectedly used for spamming, phishing and malware-related distribution.

Wednesday, July 15, 2009

Google tagged PRC.gov.ph website as 'Harmful'  

Yesterday, I have posted that the PRC website was injected with malicious code. And now, Google has tagged the site as 'harmful' as it may hosted malicious software. I can't imagine how risky this will be on its users once the June 2009 Nursing Board Examination Results will be published. AFAIK, there are about 80,000 who took the June 2009 NLE exams.


By looking at Google Safebrowsing Diagnostic report, the malicious code is hosted on two domains -- gamemaill.com and f1y.in. Don't visit these sites.

Updates:

(7/19/2009): Site is currently offline.
(7/25/2009): Site is up and running. However, the malware warning in Google has not yet removed.
(8/27/2009): Malware warning was removed.
(9/2/2009): Site is again listed as 'suspicious'.
(9/4/2009): Malware warning was removed.

Tuesday, July 14, 2009

PRC Hacked Again and Again?  

If you tend to visit the PRC website (www.prc.gov.ph), noticed that you can never get through on the examination results page? Does it mean that it is down? No. The site is hacked again. WTF! Damn, this is the 3rd time (1, 2, 3) that the site was hacked within this year. Looking at the status bar of the screenshot, you will notice a website hosting a script containing malicious codes. This script was injected not only on the exam results page but also on some Quick Access links. See below Google Safebrowsing diagnostic page report.

(Screenshot courtesy of DEFCONPH)

Friday, July 10, 2009

Oishi.com.ph infected with malware  

Don't visit the site as it is currently infected with malware.




Update --
(7/18/2009): It is now safe to visit the site.
(8/8/2009): Oishi.com.ph is listed again in Google as a 'suspicious' site.
(8/22/2009): Warning sign has been removed on SERP.

Monday, July 6, 2009

British spy chief's cover blown on Facebook  

LONDON - The wife of the new head of Britain's spy agency has posted pictures of her husband, family and friends on Internet networking site Facebook, details which could compromise security, a newspaper said on Sunday.

Sir John Sawers is due to take over as head of the Secret Intelligence Service in November. The SIS, popularly known as MI6, is Britain's global intelligence-gathering organization.

In what the Mail on Sunday called an "extraordinary lapse," the new spy chief's wife, Lady Shelley Sawers, posted family pictures and exposed details of where the couple live and take their holidays and who their friends and relatives are.

The details could be viewed by any of the many millions of Facebook users around the world, but were swiftly removed once authorities were alerted by the newspaper's enquiries.

"There were fears that the hugely embarrassing blunder could have compromised the safety of Sir John's family and friends," the newspaper said.

Publishing the story on its front page and the pictures on a double-page spread, the Mail on Sunday said the information "could potentially be useful to hostile foreign powers or terrorists."

It was the latest in a string of security blunders, lapses and leaks by British officials that have embarrassed the government of embattled Prime Minister Gordon Brown.

Source: ABS-CBN News Online

*********************************

A big slap on spy chief's face. Lesson is, Information Security and privacy should have taught to family members when using social networking sites as well as tight secrecy of one's role to avoid security leaks or exposure.

Well, I'm not sure if deleted photos mentioned were really 'deleted' in Facebook.