<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>hacking &#8211; Yogi IT Blog</title>
	<atom:link href="https://yogit.ro/tag/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>https://yogit.ro</link>
	<description>Yogi&#039;s Info on Technology</description>
	<lastBuildDate>Wed, 11 Jun 2014 20:52:01 +0000</lastBuildDate>
	<language>ro-RO</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://yogit.ro/wp-content/uploads/favicon21.png</url>
	<title>hacking &#8211; Yogi IT Blog</title>
	<link>https://yogit.ro</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Doi pusti au spart un bancomat</title>
		<link>https://yogit.ro/2014/06/doi-pusti-au-spart-un-bancomat/</link>
					<comments>https://yogit.ro/2014/06/doi-pusti-au-spart-un-bancomat/#respond</comments>
		
		<dc:creator><![CDATA[yogi]]></dc:creator>
		<pubDate>Wed, 11 Jun 2014 20:52:01 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[atm]]></category>
		<category><![CDATA[bancomat]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[kids]]></category>
		<guid isPermaLink="false">http://yogit.ro/?p=859</guid>

					<description><![CDATA[Cineva a spus candva ca poti gasi orice pe internet si in prima faza ai crede ca s-a inselat dar mai apare din senin cate un caz ca cel de care vom discuta mai jos care te face sa te intrebi: &#8222;Ma&#8230; nu cumva are dreptate?&#8221; Zilele trecute doi pusti canadieni de 14 ani si-au [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="alignleft  wp-image-868" src="http://yogit.ro/wp-content/uploads/hacked-300x225.jpg" alt="hacked" width="214" height="160" srcset="https://yogit.ro/wp-content/uploads/hacked-300x225.jpg 300w, https://yogit.ro/wp-content/uploads/hacked-600x450.jpg 600w, https://yogit.ro/wp-content/uploads/hacked.jpg 800w" sizes="(max-width: 214px) 100vw, 214px" />Cineva a spus candva ca <span style="text-decoration: underline;">poti gasi orice pe internet</span> si in prima faza ai crede ca s-a inselat dar mai apare din senin cate un caz ca cel de care vom discuta mai jos care te face sa te intrebi: &#8222;Ma&#8230; nu cumva are dreptate?&#8221;</p>
<p>Zilele trecute doi pusti canadieni de 14 ani si-au prelungit mai mult pauza de masa la scoala si cineva a trebuit sa le scrie o hartie de invoire. Pe invoire era scris cam asa:</p>
<blockquote><p><tt>Please excuse Mr. Caleb Turon and Matthew Hewlett for being late during their lunch hour due to assisting [Bank of Montreal] with security.</tt></p></blockquote>
<p>Se pare ca cei doi baieti au dat peste un vechi manual de utilizare al unui bancomat pe internet care le arata cum sa intre in modul de administrare al aparatului. Asa ca cei doi hackeri-deveniti au plecat in pauza de masa de la scoala cu gandul sa puna in aplicare ce descoperisera in manual. Zis si facut! S-au dus la un bancomat din apropiere, au intrat in modul de administrare si cu un noroc chior au nimerit si parola!</p>
<p>Dupa faza asta au fugit la cea mai apropiata reprezentanta a bancii sa se dea mari si tari cu reusita lor. Dar din pacate nimeni d-acolo nu i-a crezut asa ca au trebuit sa le arate si natafletilor ce-si-cum.<br />
S-au dus din nou la bancomat si &#8230;</p>
<blockquote><p><tt>We both went back to the ATM and I got into the operator mode again. Then I started printing off documentation like how much money is currently in the machine, how many withdrawals have happened that day, how much it's made off surcharges.Then I found a way to change the surcharge amount, so I changed the surcharge amount to one cent.<br />
</tt></p></blockquote>
<p>Au schimbat si mesajul de intampinare cu &#8222;Go away. This ATM has been hacked&#8221; si au mai printat vreo 6 documente pe care le-au luat si s-au intors la banca sa le arate.  De data asta natafletii din banca i-au crezut! <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f642.png" alt="🙂" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>Ce e bine in povestioara asta e ca finalul e fericit pentru toti implicati: banca a aflat de problema de securitate si a remediat-o, clientii bancii pot sa stea linistiti ca nu le-a disparut nici un ban din conturi iar cei doi pusti vor fi considerati niste eroi <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Dar ramane totusi problema usurintei cu care a fost spart acel bancomat. Pai daca doi pusti au reusit acest lucru intr-o pauza de la scoala inseamna ca bancomatele in care avem atat de multa incredere au totusi o securitate de doi bani&#8230;  <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f641.png" alt="🙁" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>Gata! M-am hotarat-de maine trec pe cash only <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>sursa: <a href="http://nakedsecurity.sophos.com/2014/06/11/14-year-olds-find-manual-online-hack-an-atm-during-their-school-lunch-hour/" target="_blank">nakedsecurity.sophos.com</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://yogit.ro/2014/06/doi-pusti-au-spart-un-bancomat/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Pentest-Tools si Heartbleed</title>
		<link>https://yogit.ro/2014/04/pentest-tools-security-testing-cloud/</link>
					<comments>https://yogit.ro/2014/04/pentest-tools-security-testing-cloud/#respond</comments>
		
		<dc:creator><![CDATA[yogi]]></dc:creator>
		<pubDate>Sun, 13 Apr 2014 21:13:14 +0000</pubDate>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[heartbleed]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[open ssl]]></category>
		<category><![CDATA[penetration]]></category>
		<category><![CDATA[pentest tools]]></category>
		<category><![CDATA[scan]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[testing]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[website]]></category>
		<guid isPermaLink="false">http://yogit.ro/?p=295</guid>

					<description><![CDATA[Pentru ca de curand am aflat si noi de problema Heartbleed a librariei OpenSSL (dragut din partea lor ca au dat de stire la toata lumea) m-am gandit ca ar fi momentul sa vorbesc intr-un articol si despre tool-urile celor de la Pentest. Asa ca iata-ne 🙂 Si cum sa incep in a descrie aceste [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><a href="http://heartbleed.com/"><img decoding="async" class="alignleft  wp-image-296" src="http://yogit.ro/wp-content/uploads/heartbleed.png" alt="heartbleed" width="164" height="198" srcset="https://yogit.ro/wp-content/uploads/heartbleed.png 341w, https://yogit.ro/wp-content/uploads/heartbleed-247x300.png 247w" sizes="(max-width: 164px) 100vw, 164px" /></a>Pentru ca de curand am aflat si noi de problema <a href="http://heartbleed.com/" target="_blank">Heartbleed</a> a librariei OpenSSL (dragut din partea lor ca au dat de stire la toata lumea) m-am gandit ca ar fi momentul sa vorbesc intr-un articol si despre tool-urile celor de la Pentest. Asa ca iata-ne <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f642.png" alt="🙂" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>Si cum sa incep in a descrie aceste tool-uri cat mai bine posibil decat prin a-i lasa pe ei sa si le descrie singuri:</p>
<p>&nbsp;</p>
<blockquote><p>&#8222;Pentest-Tools.com is a collection of ethical hacking tools for penetration testers and network auditors who need to check the security of networks, public servers, websites or people.&#8221;</p></blockquote>
<p>Si cu asta cred ca s-au facut intelesi nu? Deci la ei pe site gasim urmatoarele jucarii:</p>
<ul>
<li>Google hacking</li>
<li>Find subdomains</li>
<li>Find virtual hosts</li>
<li>DNS Zone Transfer</li>
<li>DNS Lookup</li>
<li>Whois Lookup</li>
<li>Ping Sweep</li>
<li>TCP port scan</li>
<li>UDP port scan</li>
<li>URL Fuzzer</li>
<li>XSS Server</li>
</ul>
<p>si in sectiunea de Vulnerability Scanning avem:</p>
<ul>
<li>Web Server Scan</li>
<li>SSL Heartbleed</li>
</ul>
<p>Fiecare jucarie poate fi folosita in schimbul unor credite si aveti la dispozitie per utilizator neinregistrat (per ip adica) 40 de credite gratuite pe zi. Indeajuns pentru a testa cateva din tool-uri. Mare atentie cu Web Server Scan ca genereaza un trafic destul de mare care poate fi interpretat ca un atac asupra serverului respectiv. Iar ultima jucarie de pe lista, dupa cum probabil v-ati dat deja seama, este testerul de Heartbleed pe care il puteti folosi in schimbul a 20 credite/server.</p>
<p>Have fun!</p>
]]></content:encoded>
					
					<wfw:commentRss>https://yogit.ro/2014/04/pentest-tools-security-testing-cloud/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
