Loading...

SD Tabletwear iPad 2 / iPad 3 LuxFolio Case [REVIEW]

The moment I received my new iPad I was in awe. This is the device I’ve dreamed about since seeing the handheld tablets on Start Trek:TNG when I was a kid. As beautiful as the naked iPad is, having upgraded from the iPad 1 I’m very aware of how easy it is to scrape, dent [...]

More  » 

1 and 1 iOS Apps sloppy coding allows domain theft and email hijacking

In many ways this is much worse than the LinkedIn and Facebook Plist vulnerability exposed last week. Both social apps exposed plain text OAuth Tokens which enable a large amount of personal information to be snaffled from accounts, and in the case of Facebook, access any website or application you’ve authorised via Facebook. What makes [...]

More  » 

Using iOS Keychain for Data Protection and Migration

Given the number of requests I’m currently recieving re using the keychain following my post regarding the use of plain text credientials in plists I’ve decided to reprint an excellent series of articles from Use Your Loaf which helped me get to grips with Keychain access and permissions. Hope this helps out! Remember for maximum [...]

More  » 

AgileBits 1Password Updated OAuth Tokens Moved to Keychain

1Password, a cross platform passwords management solution  by Agile Bits snatched the crown for the first app developers to publicly test their own iOS app, own up to having, and subsequently fix the plist vulnerability discussed on my April 3rd Post Re Facebook Credential Theft Not only is their blog post oozing with professionalism and [...]

More  » 

LinkedIn also Vulnerable to Plist Theft

[UPDATED] LinkedIn update on 26-4-2012 appears to resolve this vulnerability, though no statement or reference to the vulnerability has been made by LinkedIn. Still, they have fixed it, which is a heck of a lot more than Facebook has done! Further testing on popular social apps has revealed that LinkedIn also suffers from the plist [...]

More  » 

Facebook Plist Mobile Security Hole Allows Identity Theft [Updated]

I’ve made posts about various iOS games and the fact that developers, rather than encode add to keychain or save values in the binaries, choose to save those values in plain text plists. The majority of traffic to this site is to the pages relating to using these oversights for cheating in iOS games, but [...]

More  » 

Scramble With Friends Cheats

A week ago I expressed my distaste with Zynga games charging to play games you had already purchased. In doing so, I showed how you could modify configuration files to bypass these charges and play free. Today I’m going to the same to scramble with friends. Scrabble with friends is a boggle type game just [...]

More  » 

Orange 3G and Data Down Nationwide #orangefail

Orange can’t tell me when it’ll be back up. Check out http://orangefail.co.uk for live tweets to see when it comes back up. Use hashtag #orangefail in tweets (if you can get online to tweet) wifi ftw!

More  » 

Dream Heights Cheats Zynga

Need extra coins, fater elevators or free floors?

More  » 

Voicemail “Hacking” isn’t new, it isn’t hard, isn’t clever

This is really starting to wind me up! There’s no hacking involved here at all. The voicemail “hack” is a well known shortcoming of cell voicemail services. When calling your voicemail number from your mobile your caller id is used to put you in the right mailbox, but if you call that voicemail number from [...]

More  » 

Remote CCTV Monitoring

IPM have just launched their new CCTV remote monitoring service from their newly built £20K operations centre in Derbyshire. For more info goto IPM Remote CCTV Monitoring

More  » 

Rather mad google maps directions

Some clever (bored) peeps spotted some rather strange google directions

More  » 

Gone in 60 Seconds Part 1: Your Online Identity on a Platter

Preconfigured Routers, Open WiFi and Session Hacking: In this two parter I hope to explain the dangers of and why most of us are effected though little fault of our own.

More  » 

OrangeFail.co.uk Orange 3G Outage Map Published

Throughout August Orange mobile cellular data suffered a huge loss in connectivity. Initial Orange Customer Service responses stated that outages were limited and service would resume shortly. It became quickly apparent from social network postings that the issue was not limited (unless one counts UK wide as limited). I set up http://orangefail.co.uk to raise awareness [...]

More  » 

OrangeFail

After 3 days of Orange Data failures I’ve set up #OrangeFail at http://orangefail.co.uk to bring together the collective frustrations of our twitter users and hopefully give some idea of where there are still problems occurring. Remember to user hashtag #orangefail to appear on the site!

More  » 

Simultaneous browser testing

Just a quick post as I’ve been sitting on this idea for a while and would like some quick feedback from other designers. As all web designers will tell you, it’s a pain in the proverbial to do any structured testing of sites in multiple browsers, noticing the nuances in each page as they render [...]

More  » 

A Quick Look At The New BBC News iPhone and iPad Apps

The long awaited and much disputed BBC News application is available on your iPod Touch, iPhone and iPad free of charge via the Apple AppStore.
As you would expect from Auntie, I was quickly impressed with the overall user experience.
Those familiar with the Pulse news application will recognise the familiar carousel allowing a simple swipe to reveal other stories in each section.

More  » 

Inception Movie Review – No Spoilers

Sadly it’s not often I feel the urge to post about a movie. In the case of Inception I find it hard not to. There is a good reason this film is seeing a lot of buzz in social media circle. Director Christopher Nolan made his name with the unforgettable Memento (no pun intended) though [...]

More  » 

PHP for Android Development

It’s almost here! For all us Javaphobes out there the PHP for Android project (PFA) was launched on 13/7/2010, the driving force behind which are the Linux specialists IronTec Although you can download and install a build, as of this articles publishing you can’t package your php based app as an APK. PFA say they’re busy [...]

More  » 

Apple to recall iphone4? Stock Market thinks so

There’s been much controversy about Apples latest and ”greatest” mobile offering the iPhone 4. Users (I refuse to brand every Apple user a ‘fanboi’) all over the world have reported serious antenna attenuation fluctuations when bridging the two external antenna (Gray band around the phone), causing varying degrees of signal loss. Facing growing media coverage Apple has announced a media conference this Friday 16th July [...]

More  » 

Corrupted disk

Apologies for the downtime earlier today. At about 7am one of our servers ran a routine filesystem check and found a few problems. Unfortunately/fortunately depending on your outlook,  the system insists on exclusive access to the partition when it restarts to verify all issues have been resolved. Everything is back up and running now! Any [...]

More  » 

Simple Decoding / Deobfuscating javascript with Ultraedit

Combined javascript beautifier and unpacking scripts for deans packer and javascriptobfuscator.com into one nice Ultraedit script

More  » 

Gunnery Template Sold

Many thanks for the kind comments and offers, site design has now been sold to Les Carpet and Tiles in Bromborough. I’ll update the portfolio and images as soon as I’ve complete the required customisations!

More  » 

The Gunnery Website for Sale

Despite the design being nominated for an award, unfortunately our Client doesn’t like the site. As such the design, coding and rights to the site are now up for sale. Please contact us for more information

More  » 

Get your own dynamic twitter signature

Nice eh! You can create your very own by going to our signature generator

More  » 

New Site Design

Currently under construction,please forgive any errors and omissions

More  » 
SD Tabletwear iPad 2 / iPad 3 LuxFolio Case [REVIEW] Apr 24, 2012
1 and 1 iOS Apps sloppy coding allows domain theft and email hijacking Apr 14, 2012
Using iOS Keychain for Data Protection and Migration Apr 13, 2012
AgileBits 1Password Updated OAuth Tokens Moved to Keychain Apr 10, 2012
LinkedIn also Vulnerable to Plist Theft Apr 7, 2012
Facebook Plist Mobile Security Hole Allows Identity Theft [Updated] Apr 3, 2012
Scramble With Friends Cheats Mar 17, 2012
Orange 3G and Data Down Nationwide #orangefail Mar 8, 2012
Dream Heights Cheats Zynga Feb 19, 2012
Voicemail “Hacking” isn’t new, it isn’t hard, isn’t clever Jul 20, 2011
Remote CCTV Monitoring Nov 15, 2010
Rather mad google maps directions Nov 4, 2010
Gone in 60 Seconds Part 1: Your Online Identity on a Platter Nov 2, 2010
OrangeFail.co.uk Orange 3G Outage Map Published Sep 6, 2010
OrangeFail Aug 20, 2010
Simultaneous browser testing Jul 28, 2010
A Quick Look At The New BBC News iPhone and iPad Apps Jul 27, 2010
Inception Movie Review – No Spoilers Jul 20, 2010
PHP for Android Development Jul 16, 2010
Apple to recall iphone4? Stock Market thinks so Jul 15, 2010
Corrupted disk Jul 12, 2010
Simple Decoding / Deobfuscating javascript with Ultraedit Jun 23, 2010
Gunnery Template Sold Mar 10, 2010
The Gunnery Website for Sale Dec 22, 2009
Get your own dynamic twitter signature Dec 21, 2009
New Site Design Dec 18, 2009
mouse wheel active

Gone in 60 Seconds Part 1: Your Online Identity on a Platter

Written by:  Nov 2, 2010

It’s 2010 and 60% of adults in the UK are now accessing the internet on a daily basis, many of which are logging on to use emails and social networks.

In this two parter I hope to explain the dangers and why most of us are effected though little fault of our own.

In part two show you easy ways to improve your online security in a few simple steps

You’ve already heard the privacy warnings associated with Facebook and just how much personal data you put online, and many have started to protect their details by restricting who can see your full profile.

That’s great…but that data is still online and if you can see it so can anyone else who cares to look.

“I’m safe, I always check there is a padlock and my browser says things are secure before I login!”

That’s great!

Unfortunately however, one is assuming that you need a username and password to access your websites.

Meet Chip, the friendly session cookie. Chip makes things easier for you as you browse a website.

Like all good cookies chip is completely unique so once he sits on your computer he can be used to identify your computer.

No-one likes logging in every time they visit a new page so when you log into a site like Facebook good ol’ Chip is sent to your PC so that Facebook can just check if Chip is there. If he is you can look around the site without entering your username and password again.

That’s great but Chip isn’t encrypted like your username and password…he can be copied.

It used to be quite difficult to copy Chip. You had to be on the same PC or at least on the same network.

With the rapid take up of WiFi this is no longer the case.

Wi-Fi Foe FON

Most people are familiar with Wifi.

You use it every day, a lot of us on our mobiles.

Wifi isn’t limited to the home either, now you can access the web for free or for a small charge at pubs, hotels and petrol stations around the country.

The problem is on open WiFi (where no password is required)  all the data is broadcast in the open for anyone to plug out of the air.

So as Facebook looks for Chip, anyone on the same WiFi can take a copy of Chip.

If that same person goes to Facebook, Facebook will see the Copied chip and log that person on as you.

I don’t use FaceBook

Another thumbs up from the author J, but this problem is not just associated with Facebook.

In fact it can be much more dangerous on other sites.

Access to your email means access to any emails for any sites you have joined, particularly those related to usernames, passwords and bills.

The same method can be used on:

  • Windows Live (Mail, Messenger, Calendars, Blog, Webspace and any site which uses the windows live login method)
  • Yahoo (Mail, Apps, Webspace, Messenger etc)
  • Amazon
  • Ebay
  • Digg
  • Gmail
  • Google Apps

And many many more

I only use my own WiFi

Great…(you can see this coming can’t you)…but!

The majority of broadband internet users in the UK use the router supplied by their ISP.

Setting up a router can be tricky for the non-technically minded, so the ISP’s decided that you should be able to plug it in and have it just work.

For this reason the majority of routers are still being used with the default WiFi passwords.

It would be a really bad idea to send out thousands of routers with the same password so cunning ISP’s set the password on each router using a clever bit of math based on each routers unique ID.

Unfortunately some cleverer people quickly figured out what that math was and you can easily figure out the WiFi password of a router using free tools available online.

The most at risk are users with routers who’s names include the text: BTHomeHub, Speedtouch, Thompson,Orange, DLink, Alice, FastWeb, DMAX, WLAN, Infinitum or Eirecom

How is it’s done?

I’m not going to go into detail for obvious reasons, but the basics are as follows.

A = Attacker

U= Normal User

  1. U has a BTHomeHub, he hasn’t changed the default WiFi password
  2. A gets the name of U’s WiFi network and uses free calculator online to generate possible passwords
  3. A checks the passwords and finds one that works
  4. U is happily checking his email
  5. A steals Chip the friendly session cookie and uses it to login to U’s email
  6. U chats to some friends on FaceBook on his phone
  7. A sees that FaceBook has sent another friendly session cookie to U so he copies that too
  8. A logs into FaceBook using U’s cookie and sees that U’s using the Facebook application on his phone. A knows that the FB app uploads the phones contact list so A goes to http://facebook.com/phonebook
  9. A now has a list of all the contacts in U’s mobile phone including U’s mobile number
  10. A is looking through U’s emails and has spotted U’s CV and a few electronic Bills and paypal details
  11. A now has all the information needed to order things online using U’s details
  12. U is unaware that his details have been accessed. A has since looked at U’s ancestry.com emails and downloaded U’s family tree. At this point A probably knows more about U than U’s spouse.

Securing yourself……..Part 2 coming soon


One Response to “Gone in 60 Seconds Part 1: Your Online Identity on a Platter”

Leave a Reply

Please note: Comment moderation is enabled and may delay your comment. There is no need to resubmit your comment.