<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:ymaps="http://api.maps.yahoo.com/Maps/V2/AnnotatedMaps.xsd">

<channel>
	<title>Square Galaxy &#187; hackers</title>
	<atom:link href="http://squaregalaxy.com/tag/hackers/feed/" rel="self" type="application/rss+xml" />
	<link>http://squaregalaxy.com</link>
	<description>A blog by Jacob</description>
	<lastBuildDate>Tue, 16 Mar 2010 19:11:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>BYU&#8217;s new website theme fosters identity theft</title>
		<link>http://squaregalaxy.com/tech/byus-new-website-theme-fosters-identity-theft/</link>
		<comments>http://squaregalaxy.com/tech/byus-new-website-theme-fosters-identity-theft/#comments</comments>
		<pubDate>Sat, 10 Feb 2007 20:05:12 +0000</pubDate>
		<dc:creator>Jacob</dc:creator>
				<category><![CDATA[Technical]]></category>
		<category><![CDATA[BYU]]></category>
		<category><![CDATA[Digital Privacy]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[homepage]]></category>
		<category><![CDATA[web sites]]></category>

		<guid isPermaLink="false">http://jacob.peargrove.com/tech/2007/general/byus-new-website-theme-fosters-identity-theft/</guid>
		<description><![CDATA[On February 15th, BYU will launch a new look and feel for its various websites including the BYU homepage, Route Y, and department and college sites.  The administrators for BYU&#8217;s webpages have nicknamed this new look and feel Collage.  The Collage theme sports new colors and new methods for user interaction, but will increase a [...]


Related posts:<ol><li><a href='http://squaregalaxy.com/religion/new-ldsorg-website/' rel='bookmark' title='Permanent Link: New LDS.org website'>New LDS.org website</a> <small>This morning the LDS church launched a new version of...</small></li>
<li><a href='http://squaregalaxy.com/tech/byu-releases-new-web-site-look/' rel='bookmark' title='Permanent Link: BYU releases new web site look'>BYU releases new web site look</a> <small>Today, BYU released a preview of their new look for...</small></li>
<li><a href='http://squaregalaxy.com/education/suggestion-for-computer-science-classes/' rel='bookmark' title='Permanent Link: Better way to timstamp for computer science project pass-offs'>Better way to timstamp for computer science project pass-offs</a> <small>Timestamps are bad, use MD5 Sums!...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>On February 15th, <acronym title="Brigham Young University">BYU</acronym> will launch a new look and feel for its various websites including the <acronym title="Brigham Young University">BYU</acronym> homepage, Route Y, and department and college sites.  The administrators for <acronym title="Brigham Young University">BYU</acronym>&#8217;s webpages have nicknamed this new look and feel <span>Collage</span>.  The Collage theme sports new colors and new methods for user interaction, but will increase a hacker&#8217;s ability to steal student&#8217;s identities.</p>
<p>An essential component to Collage is a login form on the top of every page.  Students can type their username and password into the form to be shown a custom set of Internet links.  Webpage administrators expect that students will frequently enter their password to gain access to their preferred links.  Students will then be trained to frequently type their password on top of any page with the Collage theme.</p>
<p>Within a matter of minutes, anyone with a technical background can set up a page using the Collage theme.  They can make it look like a genuine and legitimate <acronym title="Brigham Young University">BYU</acronym> site.  In particular, hacker&#8217;s can create a fake site that looks like a <acronym title="Brigham Young University">BYU</acronym> site, but it really just a technique to trick student users.  Many student users could be tricked into giving their username and password to a fake site created by a hacker.  The hacker could then gain access to the student&#8217;s personal information, email, and financial accounts.  Once the hacker has access to the student&#8217;s information,</p>

<p>Related posts:<ol><li><a href='http://squaregalaxy.com/religion/new-ldsorg-website/' rel='bookmark' title='Permanent Link: New LDS.org website'>New LDS.org website</a> <small>This morning the LDS church launched a new version of...</small></li>
<li><a href='http://squaregalaxy.com/tech/byu-releases-new-web-site-look/' rel='bookmark' title='Permanent Link: BYU releases new web site look'>BYU releases new web site look</a> <small>Today, BYU released a preview of their new look for...</small></li>
<li><a href='http://squaregalaxy.com/education/suggestion-for-computer-science-classes/' rel='bookmark' title='Permanent Link: Better way to timstamp for computer science project pass-offs'>Better way to timstamp for computer science project pass-offs</a> <small>Timestamps are bad, use MD5 Sums!...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://squaregalaxy.com/tech/byus-new-website-theme-fosters-identity-theft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New type of address encoding</title>
		<link>http://squaregalaxy.com/tech/new-type-of-address-masking/</link>
		<comments>http://squaregalaxy.com/tech/new-type-of-address-masking/#comments</comments>
		<pubDate>Sat, 09 Dec 2006 13:52:30 +0000</pubDate>
		<dc:creator>Jacob</dc:creator>
				<category><![CDATA[Technical]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[url]]></category>

		<guid isPermaLink="false">http://jacob.peargrove.com/tech/2006/security/new-type-of-address-masking/</guid>
		<description><![CDATA[I got this phishing attach in my inbox.  You know, one of those that look like they are from paypal or someone, but they really aren&#8217;t.  They give you links that they ask you to click on, except that the links don&#8217;t go to paypal&#8217;s server, they go to some other site that looks like [...]


Related posts:<ol><li><a href='http://squaregalaxy.com/tech/nbcolympics-gave-away-my-email-address/' rel='bookmark' title='Permanent Link: NBCOlympics gave away my email address'>NBCOlympics gave away my email address</a> <small>Before the 2008 Olympics, I was at NBCOlympics.com looking for...</small></li>
<li><a href='http://squaregalaxy.com/tech/shrink-that-url/' rel='bookmark' title='Permanent Link: Shrink that URL'>Shrink that URL</a> <small>The web is built around addresses to web pages, often...</small></li>
<li><a href='http://squaregalaxy.com/tech/byus-new-website-theme-fosters-identity-theft/' rel='bookmark' title='Permanent Link: BYU&#8217;s new website theme fosters identity theft'>BYU&#8217;s new website theme fosters identity theft</a> <small>On February 15th, BYU will launch a new look and...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>I got this phishing attach in my inbox.  You know, one of those that look like they are from paypal or someone, but they really aren&#8217;t.  They give you links that they ask you to click on, except that the links don&#8217;t go to paypal&#8217;s server, they go to some other site that looks like paypal and tricks you into providing your login credentials.  None of this is new.</p>
<p>What is new is how they are providing the address in the link.  They provided the <acronym title="Internet Protocol">IP</acronym> address in hex.  So if I were to represent the address to my server, it would be: http://0xcf.0&#215;2d.0&#215;41.0&#215;24/</p>
<p>I thought this was very interesting, so I tried it in <a href="http://promote.peargrove.com/firefox">Firefox</a> and Opera on my mac, and neither were tricked.  Both browser&#8217;s didn&#8217;t convert the hex to the real <acronym title="Internet Protocol">IP</acronym> address, so it didn&#8217;t work.   But it makes me wonder if there are browsers out there that might be tricked by such <acronym title="Internet Protocol">IP</acronym> address encoding.</p>

<p>Related posts:<ol><li><a href='http://squaregalaxy.com/tech/nbcolympics-gave-away-my-email-address/' rel='bookmark' title='Permanent Link: NBCOlympics gave away my email address'>NBCOlympics gave away my email address</a> <small>Before the 2008 Olympics, I was at NBCOlympics.com looking for...</small></li>
<li><a href='http://squaregalaxy.com/tech/shrink-that-url/' rel='bookmark' title='Permanent Link: Shrink that URL'>Shrink that URL</a> <small>The web is built around addresses to web pages, often...</small></li>
<li><a href='http://squaregalaxy.com/tech/byus-new-website-theme-fosters-identity-theft/' rel='bookmark' title='Permanent Link: BYU&#8217;s new website theme fosters identity theft'>BYU&#8217;s new website theme fosters identity theft</a> <small>On February 15th, BYU will launch a new look and...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://squaregalaxy.com/tech/new-type-of-address-masking/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Google Blog hacked?</title>
		<link>http://squaregalaxy.com/tech/google-blog-hacked/</link>
		<comments>http://squaregalaxy.com/tech/google-blog-hacked/#comments</comments>
		<pubDate>Tue, 28 Mar 2006 06:18:47 +0000</pubDate>
		<dc:creator>Jacob</dc:creator>
				<category><![CDATA[Technical]]></category>
		<category><![CDATA[blogger]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[hackers]]></category>

		<guid isPermaLink="false">http://jacob.peargrove.com/blog/2006/technical/internet/google-blog-hacked/</guid>
		<description><![CDATA[I was looking through my live bookmarks on Firefox, which is simply the titles of RSS feeds (or in this case, the Atom feed), and I found something unusual.
Where I usually find the latest posts to the Official Google Blog I found instead a title that read:
Google, fix your blog pleeasssee! &#60;3 (P.S. Just t&#8230;
That [...]


Related posts:<ol><li><a href='http://squaregalaxy.com/tech/suggestion-for-google-apps-for-your-domain/' rel='bookmark' title='Permanent Link: Suggestion for Google Apps for Your Domain'>Suggestion for Google Apps for Your Domain</a> <small>Today I read that Google has a service for large...</small></li>
<li><a href='http://squaregalaxy.com/tech/how-do-i-upgrade-the-google-toolbar/' rel='bookmark' title='Permanent Link: How do I upgrade the Google toolbar?'>How do I upgrade the Google toolbar?</a> <small>I was reading various blogs this evening, and I saw...</small></li>
<li><a href='http://squaregalaxy.com/tech/radioclub-server-hacked/' rel='bookmark' title='Permanent Link: radioclub server hacked'>radioclub server hacked</a> <small>The webserver for radioclub.byu.edu recently got hacked through a php...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>I was looking through my live bookmarks on <a href="http://promote.peargrove.com/firefox">Firefox</a>, which is simply the titles of <acronym title="Really Simple Syndication">RSS</acronym> feeds (or in this case, the Atom feed), and I found something unusual.</p>
<p>Where I usually find the latest posts to the <a href="http://www.google.com/url?sa=t&amp;ct=res&amp;cd=2&amp;url=http%3A//googleblog.blogspot.com/&amp;ei=edMoRO_gOqqYYI7-kIMG&amp;sig2=3upZeIWOwJqkTgg9GcLbeQ">Official Google Blog</a> I found instead a title that read:</p>
<p><em>Google, fix your blog pleeasssee! &lt;3 (P.S. Just t&#8230;</em></p>
<p>That was all I could see.  When I clicked on the live bookmark, I was taken to the following URL:</p>
<p><em>http://googleblog.blogspot.com/2006/03/google-fix-your-blog-pleeasssee-3-p.html </em></p>
<p>which turns out to give a &#8220;Not Found&#8221; error.  Furthermore, the Offical Google Blog and its Atom feed also return 404 errors.</p>
<p>So what happened to the blog?  Was it hacked?</p>

<p>Related posts:<ol><li><a href='http://squaregalaxy.com/tech/suggestion-for-google-apps-for-your-domain/' rel='bookmark' title='Permanent Link: Suggestion for Google Apps for Your Domain'>Suggestion for Google Apps for Your Domain</a> <small>Today I read that Google has a service for large...</small></li>
<li><a href='http://squaregalaxy.com/tech/how-do-i-upgrade-the-google-toolbar/' rel='bookmark' title='Permanent Link: How do I upgrade the Google toolbar?'>How do I upgrade the Google toolbar?</a> <small>I was reading various blogs this evening, and I saw...</small></li>
<li><a href='http://squaregalaxy.com/tech/radioclub-server-hacked/' rel='bookmark' title='Permanent Link: radioclub server hacked'>radioclub server hacked</a> <small>The webserver for radioclub.byu.edu recently got hacked through a php...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://squaregalaxy.com/tech/google-blog-hacked/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>radioclub server hacked</title>
		<link>http://squaregalaxy.com/tech/radioclub-server-hacked/</link>
		<comments>http://squaregalaxy.com/tech/radioclub-server-hacked/#comments</comments>
		<pubDate>Sun, 05 Dec 2004 10:20:46 +0000</pubDate>
		<dc:creator>Jacob</dc:creator>
				<category><![CDATA[Technical]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Ham Radio]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[phpbb]]></category>

		<guid isPermaLink="false">http://jacob.peargrove.com/blog/?p=36</guid>
		<description><![CDATA[The webserver for radioclub.byu.edu recently got hacked through a php exploit in urldecode.  I&#8217;m not exactly sure how this all worked, but I found that an irc bot was running on my server, and looking through the apache logs, I found that the exploit recently described as the howdark exploit.  What is left [...]


Related posts:<ol><li><a href='http://squaregalaxy.com/tech/google-blog-hacked/' rel='bookmark' title='Permanent Link: Google Blog hacked?'>Google Blog hacked?</a> <small>I was looking through my live bookmarks on Firefox, which...</small></li>
<li><a href='http://squaregalaxy.com/tech/those-who-dont-want-broadband-internet/' rel='bookmark' title='Permanent Link: Those who don&#8217;t want broadband Internet'>Those who don&#8217;t want broadband Internet</a> <small>According to a Slashdot article, 62% of Americans who access...</small></li>
<li><a href='http://squaregalaxy.com/tech/new-byu-ham-radio-site/' rel='bookmark' title='Permanent Link: New BYU Ham Radio Site'>New BYU Ham Radio Site</a> <small>Today I made a post to the BYUARC (Amateur Radio...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>The webserver for radioclub.byu.edu recently got hacked through a php exploit in urldecode.  I&#8217;m not exactly sure how this all worked, but I found that an irc bot was running on my server, and looking through the apache logs, I found that the exploit recently described as the howdark exploit.  What is left to be determined is if the hacker got root access.  In which case, I would have to reinstall the entire system and examine any migrated files.  If I can determine that he did not get root access, then I can simply delete the files and fix the whole and hope other things like it don&#8217;t happen again.</p>
<p>I&#8217;ve also made sure that any other installations of phpBB2 hanging around on my other servers are either upgraded or deleted.</p>
<p>If anyone is running phpBB2 with a version less than 2.0.11, you really should upgrade immediately.</p>

<p>Related posts:<ol><li><a href='http://squaregalaxy.com/tech/google-blog-hacked/' rel='bookmark' title='Permanent Link: Google Blog hacked?'>Google Blog hacked?</a> <small>I was looking through my live bookmarks on Firefox, which...</small></li>
<li><a href='http://squaregalaxy.com/tech/those-who-dont-want-broadband-internet/' rel='bookmark' title='Permanent Link: Those who don&#8217;t want broadband Internet'>Those who don&#8217;t want broadband Internet</a> <small>According to a Slashdot article, 62% of Americans who access...</small></li>
<li><a href='http://squaregalaxy.com/tech/new-byu-ham-radio-site/' rel='bookmark' title='Permanent Link: New BYU Ham Radio Site'>New BYU Ham Radio Site</a> <small>Today I made a post to the BYUARC (Amateur Radio...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://squaregalaxy.com/tech/radioclub-server-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
