Skip to main content

WATCH OUT!

If you're aware, recently a big ISP have been shut down because it allowed its user to send spam. Because of the closing, spam been have dropped about 40~70% all around the world. But, if you aware, google also been hack recently and there are increased number of spams going in from my personal mail hosted in GMail (well, it's a mailling list anyway). There's something going on to Yahoo! as well and I think they want to attack Yahoo! also.

The mailserver also been flooded with attacks recently from outside, this taught me a valuable lesson:
SASL is not that save!
Just like China's Great Wall, crumbled because of the bad management of the user. You can build a Citadel in your mail appliance, but it still not safe if your user not that precautious. In fact, transparent to user is no longer true to the email safety. Security is not that comfortable! They must know how to secure their login. Now, they need to know that many spammers want to fish their login and password.

There are three technique that exist:

#1 Great Pretender
Pretending as your administrator and sending email notification to ask password. FYI, we, admins, doesn't need your password to access any application that we administer. So, we will never ask any of your confidential including password.

The other reason why we will never ask you password is because we don't need any to access nor modify your personal information. But, we will never do that! we have ethics, fyi.

#2 Fishing Your Password
Using viruses, malwares, etc to setup a website that related to well-known/target services. Take a look at [WARNING: THIS IS A PASSWORD FISHING SITE, NEVER ENTER ANY CONFIDENTIAL NOR ACCESS THE SITE IF USING WINDOZE.] http://holiday-picz.com [/END OF BAD SITE]. The site also viable with yahoo login name subdomain. The look is very like real site, but the site host is not. Watch out for that. If it's HTTPS, read the SSL/TLS certificate.

Impersonating also comes with different model, such as cracking legitimate sites and using XSS to hijack the site.

#3 Social Engineering
Cool? Well, that's the idea, pretend as someone else and persuade user to provide confidential information.


That's for common folks. For admins, watch your HTTP server's access.log, error.log, warn.log. Watch for suspicious request. I assume that you already have iptables handles zero packets and overwhelming connection, no? The bucket thingie, you activate that, don't you?

Watch out your sendmail/postfix/MTA and applications that using it. As I said earlier, SASL is not that save. It only guarantee a legit user that access the email. But, it can't guarantee that the email sent is not spam that have a FROM header not from your domain. So, check your SMTPs and never let them becoming open relays. One note, it's a good practice to have different incoming and outgoing server. It save the regex. Oh, do you have that good ol' SA?

The last thing, take a deep breath. Every user can have the potential to become an ^a*hole$. But, hey, that's life. They want comfort and we want security. Just... hang in there. -_-'


Oh, btw, captcha sucks. Don't you know that it is prone lately? Google for the article.

Comments

  1. Anonymous12:07 AM

    eh phising apa fishing, jep?

    ReplyDelete
  2. situs phising fishing2 (baca: mancing2) orang tuk masuking password =D

    ReplyDelete

Post a Comment

Popular posts from this blog

STAN vs. UI

Ugh, kasihan banget adek gue. Saking kepinteran dia jadi dapet Akuntansi UI dan STAN. Jadi bingung mau masuk yang mana. Beberapa orang (termasuk orang tua gue), menyarankan masuk STAN. Gue malah memperburuk suasana dengan membela memasuki Akuntansi UI, maklum bela almamater. Duh, gue jadi merasa bersalah bikin dia ragu-ragu. Kira-kira enakan masuk mana, yah? Gue juga gak tahu keuntungan masing-masing. Hasil debat sementara: ~ Untuk jangka panjang masuk UI, untuk jangka pendek STAN. ~~Tapi, dia itu kan cewek, ntar pas menikah kemungkinan besar karir terhambat. Eits, ntar, dulu, sekarang kan jamannya emansipasi, bisa aja cowoknya yang jadi BRT. ~ STAN sarang korupsi, kalo masuk STAN jadi pegawai negeri. Kalo mau kaya harus korupsi. Tapi kalo masuk UI, lulus masuk jadi akuntan publik. Sekarang ini, orang membayar akuntan publik untuk memanipulasi nilai pajak dan aset. *SIGH*. Jadi gak ada yang beres ~ dll. Yah, udah gue jadi bingung, apa lagi dia nanya saran gue. Buah, gue gak pengalaman ...

Installing Goodix Fingerprint Reader Driver on Fedora

I currently have a Lenovo Thinkpad L14 laptop equipped with fingerprint. I was `belok` from KDE Neon to use Fedora 40 because of someone. Now I am tempted to enable my fingerprint: lsusb | grep -i fingerprint Bus 001 Device 004: ID 27c6:55b4 Shenzhen Goodix Technology Co.,Ltd. Fingerprint Reader Dump the firmware Assuming this is a fresh install, lets do some magic by getting some dependencies: sudo dnf install gcc git python-pip python-devel openssl Let's get the source code: git clone --recurse-submodules https://github.com/goodix-fp-linux-dev/goodix-fp-dump.git cd goodix-fp-dump Create an isolated Python environment: python -m venv .v source .v/bin/activate Do the magic: sudo su pip install -r requirements.txt python run_55b4.py exit There are some python scripts available. I run run_55b4.py because my device ID is 27c6: 55b4 . It will spell some nonsense, which is a good thing. That nonsense actually the firmware captured by our device. Also, I typed exit becaus...

Chivalry vs Feminism

Throughout these years I constantly making experiment about how our society perceive about the societal changes. The overhaul of sexist strata and the privilege reformations follow. Note that every change could be perceived as progress or detrimental to the society. The foremost subject that I run is about the opposite of manliness perceived by the oldies vs modern women. The modern era allow women go out from the kitchen into the office. They can have career and enjoy the privilege that men were exclusively had in years. And, can men also do the reverse? Can men also enjoy the privilege of what women do in the past? Can men move from office into the kitchen? And the answer on this era is: NO. While women could reverse their role, men are not allowed to do the same in this society. Society will punish you when a man tries to do that. They will put a healthy man who chose to be at home dad as an irresponsible not-a-man person. If a woman's worth could be rewritten, why not...