Archive for November, 2006

An incident !

Tuesday, November 14th, 2006

It was just another ordinary day , a lovely morning .
Was working on some flash project at work and received a call from some friend telling me her email account was stolen and she needs help to retrieve that account .
( that explains why she was quite on MSN last night ) .

Any how after looking at the issue, I figured the following :

The attacker guessed an easy secret question, there by was able to reset the password and change the old secret question.

Any how i saw the contact online once again … tried to communicate, as in for replies the guy was calm, he sent me many “****” “stars” whenever I was talking to him for some reason, then he went offline .

I was like hmmm, so I called my friend back and told her I have to leave now to college , and asked her to send me her full details ( old pass , old secret question , location , name , phone number ) Any thing that she can remember that was added to the Account ID , so I can contact Microsoft & ask them to reset the password .

Wrote an email to Microsoft account services explaining the current situation .

The next day I receive another call from my friend telling me it is someone from the same company I work for , “ And now WTF !!! << that was my reaction “ !
Now why would you say that , I said .

She was able to trace an offline message that lead to one of our IP addresses “ I didn’t know which or what IP address was that , I then asked her to fax me the details … i quickly closed unimportant Temporary ports (ftp , terminal services , telnet & some ranges of ports)

I then had a bright idea , remember the Re-login page ?

hotmail re login

Yes I made one , only I couldn’t embed it in the email I was sending the attacker .

The main concept is when the attacker receives the link it will prompt him to enter his email and password to see the content … and when HE/SHE submits the form , it will send it to a database ( a text file ) and compose an email to me with the Username password & IP address .

Any how I composed an email message to my friend’s stolen email from a different account late at night somewhere about 12 am I received the email . guess were the attacker came from … Cypruss .

I then waited for 15 minutes (“Just incase before I reset the password, ‘The attacker was also able to hijack 2 of her friend’s ID’s, only that I didn’t know what’s the 3rd account ID, I tried calling my friend but her phone was turned off, I just assumed that he might have been using the same password for the 3 accounts “)

Any how I reset the first 2 accounts and had my hands on the 3rd account from one of the 2 accounts and reset its password.
Now what made me think is the IP , it was a mystery , what and how the IP was used , mind that MSN , HOTMAIL & YAHOO are blocked on the employees end , Only way to use those was on some servers !

The next morning she faxed the information about the IP , It was an offline message that was sent to one of her friends from the attacker , and it had the IP of our testing server .

Which had a remote access enabled with a silly password ( my fault , never thought of it this way ) .

( BTW I received an email from Microsoft asking me for more personal details so they can decide on resetting the password “meaning , it works this way too. )

Then I concluded the following:

When the attacker received MY offline message, he was able to scan the range of IPs and he found the remote desktop port enabled, had the password guessed … and used it to do his stuff “some felony”!!!

I closed the port changed the password, checked the access audit log to find out hell yeah , he was in , smart bastard . Thank god he didn’t go further .

Hope this helps other people to understand the security risks of keeping silly easy guessed passwords on their accounts or servers , it demonstrates the fatal error of human being so no need to blame Windows every time :D .

 

 

 

No Terror !!

Monday, November 13th, 2006

http://noterror.info

Our mission is to expose the fallacy of the distorted and politicized Islamic teachings used by ungodly extremists to sanctify and justify terrorism.
It has become crucial to inform the Muslim and Arab people -particularly the Iraqi people- about the deceptions terrorists employ in distorting the peaceful teachings of Islam.
These terrorists, who claim to follow the Islamic Faith, are in truth only drowning in an abyss
of mistaken beliefs.

Spread the site around …

The all new Bahrain Explorer …

Wednesday, November 8th, 2006

Bahrain Explorer Bahrain

We have published/Released the all new BahrainExplorer Design with more usability and easier site Navigation.

Explore Bahrain with interactive maps today .
visit Bahrain Explorer

I would love to hear a feedBack if possible :D
NOTE : REQUIERS INTERNET EXPLORER 6+ .

Netiquette

Sunday, November 5th, 2006

Netiqette

What is it ? its internet etiquette .
Whats that ? Read …

Netiquette (neologism, a morphological blend formed from “Internet etiquette”) is a catch-all term for the conventions of politeness recognized on Usenet, in mailing lists, and on other electronic forums such as Internet message boards. These conventions address group phenomena (such as flaming) with changes in personal behavior, such as not posting in all uppercase, not (cross-)posting to inappropriate groups, refraining from commercial advertising outside the biz groups and not top-posting. RFC 1855 is a fairly lengthy and comprehensive set of such conventions.

The rules of netiquette are slightly different for newsgroups, web forums and IRC (Internet Relay Chat). For example, on Usenet it is conventional to write in standard English and not use abbreviations such as “u” for “you” or “ne1″ for “anyone”. These abbreviations are only slightly more likely to be tolerated on web forums, but are almost universal on IRC where, since discussion is real-time, they serve the practical purpose of speeding the flow of conversation. Many IRC users look down on this form of conversation, though. Issues such as the level of tolerance for off-topic discussion or spoilers may also vary from one newsgroup, forum, or channel to another. The rule of thumb in any of these discussion mediums is to “lurk before you leap”—get a feel for the local conventions before diving into conversation and inadvertently embarrassing oneself. Also, read the FAQ if there is one.

Read more about forums , Usenet and other Netiquette @ wiki

Arabic Version @ Alex 

Free Wi-Fi over Juffair …

Thursday, November 2nd, 2006

So on a Trial & Testing basis , 2connect are now “Airing” free Wi-Fi @ al-Juffair Area .
And that is confirmed already :D
I’ve known them for years now and I know how much they fought to bring a better service to the people of Bahrain!
They ROCK !
Thanks Freddy ;) Okay , so i want all Bahrain to be there and starts OVER-LOADING the connection , you can start with P2P ” lawl” . :D
http://boycottbatelco.com/?p=65