Ogenstad.net

Security Stories and Help with Network Documentation

Once upon a time this used to be my blog. For current updates head over to Networklore.

About / Stories / Contact

  • GitHub
  • LinkedIn
  • RSS
  • Twitter

Powered by Genesis

A Stock Bubble of His Own – Part 2

May 19, 2006 by patrick.ogenstad

midfr0st had downloaded the website for Meriabeck and was browsing the contents offline, he hardly remembered what it was the company was doing and this knowledge was vital for his plans. There was a lot of material to go through, their website wasn’t too big but there were a lot of pdf reports there. Since it was a publicly traded company there was a lot of information, or rather speculations, to be read in different online forums.

Apparently the company was now creating some sort of RFID chips and there was a lot of talk about a big deal being very close. Backtracking to earlier discussions, midfr0st found out that this had been the situation for the last two years. Perfect, he smiled and inhaled some more smoke from his cigarette. The sun was shining on his balcony and the neighbor’s dog was barking. Business as usual.

midfr0st logged on his Internet bank and signed up for a service which would send a text message to his phone and an email if the stock price for Meriabeck Technologies changed more than 5% in either direction.

Paranoia is good for you, midfr0st mused. He didn’t want it to look suspicious, since he was hardly ever logged on to the bank and hadn’t done any other affairs the last few years, it might look odd if he suddenly managed to sell the stocks during the hours they soared. If the stock crashed a few hours later it would be more suspicious. In reality the amount of stocks he traded would be insignificantly small, but midfr0st prided himself in being careful.

midfr0st obsessed about keeping things organized and had started setting up a project plan for each job he did. At the moment he was using Planner and his task list for the current project contained these entries:

  1. Create online rumor
  2. Find a respectable company to use
  3. Hack Meriabeck
  4. Send an official statement from Meriabeck
  5. Shutdown Meriabecks access to the world
  6. Sell stock
  7. Watch stock crash and do the monkey dance

His target deadline was seven weeks away.

[tags]security, stories, fiction[/tags]

Filed Under: Stories

Donations to the SYDI Project

May 19, 2006 by patrick.ogenstad

The SYDI project has received a $50 donation and would like to thank SEO Company. They have decided to support open source and are donating money to a lot of open source projects.

If you want to donate to the SYDI project there are instructions on the SYDI website.

[tags]sydi, open source, donations[/tags]

Filed Under: SYDI

A Stock Bubble of His Own – Part 1

May 10, 2006 by patrick.ogenstad

The startup company midfr0st had worked for declared bankruptcy when the stock market crashed. Instead of searching for a new job, midfr0st had entered the hacking business and was now breaking into companies for money. Business was going very well, it had in fact made him rich. Compared to his former financial status he would say it had made him very rich. midfr0st was however facing a little dilemma. All the money he had earned didn’t belong to him, instead it belonged to a few online “identities” he had created or bought.

Up to a certain amount, spending money wasn’t a problem, but he was getting more careful and the thought of getting caught didn’t really appeal to him. His biggest problem was that his real identity didn’t have a job and should have been broke.

midfr0st was still thinking about a long term solution to the problem, the life he pictured for himself was a lot more luxurious that living in a small apartment as he did now.

The short term plan was to make his legal assets grow without causing anyone to get suspicious. The best candidate for the job was the stock market, but although midfr0st was interested in shares and bonds he didn’t feel he had time. midfr0st had found an institute offering private banking services. He had been piling up his legal asset but was still about $35 000 short of the $300 000 needed to open up the account he wanted.

Although he had the money elsewhere he couldn’t just transfer it since that kind of trail was exactly what he wanted to avoid. Aside from the money he had on his bank the only other asset to speak of were some stocks in a company he had bought back in ’99. The company, Meriabeck Technologies, hadn’t quite shared the fate of the crashed company midfr0st had worked at, but close enough. It didn’t matter.

midfr0st had invested in Meriabeck after a recommendation from a friend, at first the stocks had soared, before they hit rock bottom. During the years to come midfr0st had more or less forgotten about them, so when he finally checked them he was happy to see that they had in fact increased a lot in value and were now worth 13% more than what he had originally paid for them. Unfortunately he still didn’t have enough money for the private banking account.

Another 16%, midfr0st thought. If he could just increase the value of the stocks he would be set to go. A plan was forming in his mind.

[tags]security, stories, fiction, stock market[/tags]

Filed Under: Stories

The Failure of Information Security

May 10, 2006 by patrick.ogenstad

“They say if you drop a frog in a pot of boiling water, it will, of course, frantically try to scramble out. But if you place it gently in a pot of tepid water and turn the heat on low, it will float there quite complacently. As you turn up the heat, the frog will sink into a tranquil stupor and before long, with a smile on its face, it will unresistingly allow itself to be boiled to death. The security industry is much like that frog; completely and uncontrollably in disarray – yet we tolerated it since we are use to it.”

This paragraph starts of Noam Eppel’s article titled The Complete, Unquestionable and Total Failure of Information Security. I think it’s a very interesting read but I don’t entirely agree on his more or less pitch black view of things. I guess it reminds me to much of Despair Inc..

There are a lot of problems when it comes to IT Security, but this doesn’t differ much from the “real world”. Sure you have click and play rootkits and what not, anybody can learn to break into a computer using tools easily found. You don’t have to be skilled to; grab someone’s purse, steal a car, physically “deface” someone, blackmail, steal from the office and so on.

Ok, so the Internet is a dangerous place. This doesn’t mean consumers or corporations can’t mitigate the risks and stay reasonably secure.

Might I guess that the user who created the screenshot with all the spyware wasn’t logged in as a limited user?

Anyway I’m looking forward to Noam’s next update and make sure you read his article.

[tags]security, cyber crime, hacking[/tags]

Filed Under: Security

Speaking of Stupid Hackers

May 9, 2006 by patrick.ogenstad

Martin McKeay has a post of another brilliant way to get caught. Since this guy actually put people’s life at risk, I hope he gets a harsher punishment than the credit card guy.

[tags]security, hacking[/tags]

Filed Under: Security

  • « Previous Page
  • 1
  • …
  • 9
  • 10
  • 11
  • 12
  • 13
  • …
  • 16
  • Next Page »