<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Zoiz Blog &#187; Tips</title>
	<atom:link href="http://zoiz.web.id/category/tips/feed" rel="self" type="application/rss+xml" />
	<link>http://zoiz.web.id</link>
	<description>Was a Web Application Security Blog</description>
	<lastBuildDate>Tue, 17 Aug 2010 05:57:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Selamat Ulang Tahun ke 65 Republik Indonesia</title>
		<link>http://zoiz.web.id/tips/hut-ri-selamat-ulang-tahun-ke-65-republik-indonesi.html</link>
		<comments>http://zoiz.web.id/tips/hut-ri-selamat-ulang-tahun-ke-65-republik-indonesi.html#comments</comments>
		<pubDate>Tue, 17 Aug 2010 05:57:49 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=212</guid>
		<description><![CDATA[HUT RI ke 65 Republi Indonesia]]></description>
			<content:encoded><![CDATA[<p>HUT RI ke 65 Republi Indonesia</p>
<p><a href="http://zoiz.web.id/wp-content/uploads/2010/08/bendera.gif"><img class="alignleft size-full wp-image-213" title="Bendera Merah Putih" src="http://zoiz.web.id/wp-content/uploads/2010/08/bendera.gif" alt="HUT RI 65" width="427" height="404" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/tips/hut-ri-selamat-ulang-tahun-ke-65-republik-indonesi.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Account Security V</title>
		<link>http://zoiz.web.id/tips/account-security-v.html</link>
		<comments>http://zoiz.web.id/tips/account-security-v.html#comments</comments>
		<pubDate>Sat, 23 Jan 2010 10:49:33 +0000</pubDate>
		<dc:creator>r3ck0rd</dc:creator>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[account]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[hotspot]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=181</guid>
		<description><![CDATA[Accounts Security V Concerning Internet use at public spots &#38; Password by Sequence A Password Security Related Article by Calvin Limuel a.k.a. r3ck0rd It&#8217;s been a long time since I last posted in Zoiz&#8217; blog. Still the same topic, and it&#8217;s already the fifth! Covering internet usage at public hotspots and sequenced passwords. Here are [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://reckord.info/password-security/303.account-security-v.html"><span>Accounts Security V</span></a><br />
Concerning Internet use at public spots &amp; Password by Sequence<br />
<span>A Password Security Related Article by <a title="r3ck0rd's Blog" href="../../">Calvin Limuel a.k.a. r3ck0rd</a></span></p>
<p>It&#8217;s been a long time since I last posted in Zoiz&#8217; blog. Still the same topic, and it&#8217;s already the fifth! Covering internet usage at public hotspots and sequenced passwords. Here are the tips for this time:<span id="more-181"></span></p>
<ol>
<li><strong>Log in first before you use it at a public hotspot.</strong><br />
You don&#8217;t know if somebody is ready with his/her Cain&amp;Abel and ready to harvest your usernames and passwords. So, you can log in first at home, put your notebook in standby mode, then bring your notebook where you want to use it.Wonder if somebody thinks of this too.<br />
Note: It&#8217;s not the same as the remember password feature. Remember password feature on your browser just make the username and password appear, it still sends your username and password.</li>
<li><strong>Never do e-transaction such as e-banking or online shopping at a public hotspot. </strong><br />
Crackers still can modify the data sent to the router, so I don&#8217;t recommend this activity.</li>
<li><strong>Use your personal combination. </strong><br />
A friend on Facebook posted a link to here: <a rel="nofollow" href="http://www.linux.com/articles/28057">http://www.linux.com/articles/28057</a>. It&#8217;s a good idea to combine your personal information like this: &#8220;NiKrV@1992!UA-blAcK&#8221;. Assume the password user&#8217;s name is NiKrad KreVchenko, born @1992, born in Ukraine (ISO country code), and his favorite color is black.</li>
<li><strong>Using characters from a random phrase. </strong><br />
Another good idea. Let&#8217;s try from this phrase: &#8220;Lorem Ipsum Dolor Sit Amet. The quick little brown fox jumps over a big lazy dog.&#8221; Take the first letters then you get LIDSATQLBFJOABLD. Or take per two letters, separate words with exclamation mark, then you get LRM!PU!DLR!I!AE! and so forth. Don&#8217;t forget to variate the case, or the symbols. Like changing the exclamation marks to the symbols sequence on your keyboard (~!@#$%^&amp;*()_+`-={}|[]\:&#8221;;&#8217;&lt;&gt;?,./).</li>
<li><strong>Use a Polybius Square. </strong><br />
I&#8217;ve seen this technique somewhere but I forgot it where. Here is one example (you can make this thing by yourself):</p>
<table class="aligncenter" border="0">
<tbody>
<tr>
<td></td>
<td>1</td>
<td>2</td>
<td>3</td>
<td>4</td>
<td>5</td>
<td>6</td>
<td>7</td>
<td>8</td>
<td>9</td>
<td>0</td>
</tr>
<tr>
<td>a</td>
<td>a</td>
<td>s</td>
<td>e</td>
<td>v</td>
<td>e</td>
<td>d</td>
<td>n</td>
<td>e</td>
<td>3</td>
<td>g</td>
</tr>
<tr>
<td>b</td>
<td>!</td>
<td>@</td>
<td>d</td>
<td>3</td>
<td>d</td>
<td>%</td>
<td>e</td>
<td>&amp;</td>
<td>f</td>
<td>3</td>
</tr>
<tr>
<td>c</td>
<td>e</td>
<td>h</td>
<td>*</td>
<td>-</td>
<td>%</td>
<td>d</td>
<td>2</td>
<td>q</td>
<td>F</td>
<td>#</td>
</tr>
<tr>
<td>d</td>
<td>s</td>
<td>!</td>
<td>#</td>
<td>$</td>
<td>%</td>
<td>d</td>
<td>E</td>
<td>2</td>
<td>5</td>
<td>8</td>
</tr>
<tr>
<td>e</td>
<td>f</td>
<td>3</td>
<td>a</td>
<td>S</td>
<td>F</td>
<td>V</td>
<td>#</td>
<td>T</td>
<td>4</td>
<td>A</td>
</tr>
</tbody>
</table>
<p>This works like a <a href="http://en.wikipedia.org/wiki/Polybius_square" target="_blank">Polybius square</a>, one of the ancient cryptography technique. With this, you can only remember two letters for your password, and the length of your. For example, remembering d2 7 letters long, it is: s!#$%dE. Of course you can make this larger on your own. Or just make your own password, then hide it under your own Polybius square</li>
<li><strong>Use the Polybius Square combined with chess moves. </strong><br />
If you like to play chess, and you know some openings, this shouldn&#8217;t be a problem. All you have to do is to make an 8&#215;8 Polybius square, with random letters and captions for chess boards. For example, the Sicilian Dragon Variant: 1. e4 c5 2. Nf3 d6 3. d4 cxd4 4. Nxd4 Nf6 5. Nc3 g6 6. Bg5 Bg7. That&#8217;s enough, a password with 12 characters. If there&#8217;s a repeat of letters it&#8217;s ok, don&#8217;t matter. I hope you understand what I mean.</p>
<table class="aligncenter" border="0" align="center">
<tbody>
<tr>
<td><strong><span> 8</span></strong></td>
<td><strong><span> k</span></strong></td>
<td><strong><span>l</p>
<p></span></strong></td>
<td><strong><span> \</span></strong></td>
<td><strong><span>z</p>
<p></span></strong></td>
<td><strong><span> &#8220;</span></strong></td>
<td><strong><span>{</p>
<p></span></strong></td>
<td><strong><span> +</span></strong></td>
<td><strong><span> </span></strong></td>
</tr>
<tr>
<td><strong><span> 7</span></strong></td>
<td><strong><span> j</span></strong></td>
<td><strong><span> ;</span></strong></td>
<td><strong><span> ]</span></strong></td>
<td><strong><span> x</span></strong></td>
<td><strong><span> ;</span></strong></td>
<td><strong><span> }</span></strong></td>
<td><strong><span> =</span></strong></td>
<td><strong><span>!</p>
<p></span></strong></td>
</tr>
<tr>
<td><strong><span> 6</span></strong></td>
<td><strong><span> h</span></strong></td>
<td><strong><span> &#8216;</span></strong></td>
<td><strong><span> [</span></strong></td>
<td><strong><span> c</span></strong></td>
<td><strong><span> &#8220;</span></strong></td>
<td><strong><span> |</span></strong></td>
<td><strong><span> -</span></strong></td>
<td><strong><span> #</span></strong></td>
</tr>
<tr>
<td><strong><span> 5</span></strong></td>
<td><strong><span> g</span></strong></td>
<td><strong><span> q</span></strong></td>
<td><strong><span> p</span></strong></td>
<td><strong><span> v</span></strong></td>
<td><strong><span> :</span></strong></td>
<td><strong><span> 1</span></strong></td>
<td><strong><span> 0</span></strong></td>
<td><strong><span> $</span></strong></td>
</tr>
<tr>
<td><strong><span> 4</span></strong></td>
<td><strong><span> f</span></strong></td>
<td><strong><span> w</span></strong></td>
<td><strong><span> o</span></strong></td>
<td><strong><span> b</span></strong></td>
<td><strong><span> ?</span></strong></td>
<td><strong><span> 2</span></strong></td>
<td><strong><span> 9</span></strong></td>
<td><strong><span> %</span></strong></td>
</tr>
<tr>
<td><strong><span> 3</span></strong></td>
<td><strong><span> d</span></strong></td>
<td><strong><span> e</span></strong></td>
<td><strong><span> i</span></strong></td>
<td><strong><span> n</span></strong></td>
<td><strong><span> &gt;</span></strong></td>
<td><strong><span> 3</span></strong></td>
<td><strong><span> 8</span></strong></td>
<td><strong><span> ^</span></strong></td>
</tr>
<tr>
<td><strong><span> 2</span></strong></td>
<td><strong><span> s</span></strong></td>
<td><strong><span> r</span></strong></td>
<td><strong><span> u</span></strong></td>
<td><strong><span> m</span></strong></td>
<td><strong><span> &lt;</span></strong></td>
<td><strong><span> 4</span></strong></td>
<td><strong><span> 7</span></strong></td>
<td><strong><span> &amp;</span></strong></td>
</tr>
<tr>
<td><strong><span>1</p>
<p></span></strong></td>
<td><strong><span> a</span></strong></td>
<td><strong><span> t</span></strong></td>
<td><strong><span>y</p>
<p></span></strong></td>
<td><strong><span> ,</span></strong></td>
<td><strong><span>. /</p>
<p></span></strong></td>
<td><strong><span> 5</span></strong></td>
<td><strong><span>6</p>
<p></span></strong></td>
<td><strong><span> *</span></strong></td>
</tr>
<tr>
<td><strong><span> </span></strong></td>
<td><strong><span> a</span></strong></td>
<td><strong><span>b</p>
<p></span></strong></td>
<td><strong><span>c</p>
<p></span></strong></td>
<td><strong><span>d</p>
<p></span></strong></td>
<td><strong><span>e</p>
<p></span></strong></td>
<td><strong><span>f</p>
<p></span></strong></td>
<td><strong><span>g</p>
<p></span></strong></td>
<td><strong><span>h</p>
<p></span></strong></td>
</tr>
</tbody>
</table>
<p>If it based on this square and using the Sicilian Dragon Variant, my password would be: ?p3cbbb|i-0=<br />
Go make your own! Print all your Polybius Squares, make cards of it, and put it into your wallet.</li>
<li><strong>Use On Screen Keyboard.</strong><br />
I always forgot to write this. If you&#8217;re lazy to do the previous tips about copy pasting letters from a text file, just use on screen keyboard. In case there is a keylogger logging coordinate of mouse clicks, before and after you type your password with this tool, move the keyboard to another spot.</li>
<li><strong>Keyboard sequence isn&#8217;t always insecure.</strong><br />
Yeah, it&#8217;s not always insecure. But of course, lame sequence like asdfghjkl, is insecure. Be creative with this one. Like this: !qAz@wSx#eDc. Figure out the sequence yourself. You can switch to another keyboard layout (other than QWERTY, like Dvorak) for awhile for entering passwords.</li>
<li><strong>One-way encrypted password as your password. </strong><br />
Just remember a word, or name, like John Doe. Then, encrypt it to md5. Resulting: 4c2a904bafba06591225113ad17b5cec. If it doesn&#8217;t fit because of the character limit (md5 is 25 character), just cut off the half to the limit character.</li>
<li><img src="http://reckord.info/wordpress/wp-content/uploads/2008/03/4wdevp.gif" alt="For Web Developers and Programmers" width="80" height="20" /> <strong>Using multi-level encryption.<br />
</strong>I found this idea when searching for an encryption tool. If you don&#8217;t get what I say, then I&#8217;ll give you an example:</p>
<pre>$pass = sha1(md5(md5(sha1(sha1(md5(md5(sha1($pass))))))));</pre>
<p>Add salt and different encryption ways if you please:</p>
<pre>$pass= sha1(md5(crypt(str_rot13(base64_encode(md5(1357, sha1($pass)))))))</pre>
<p>I&#8217;m not responsible for any server crash <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </li>
</ol>
<p>That&#8217;s all for now. Enjoy securing.</p>
<p>Thu.1.29.2008<br />
r3ck0rd</p>
<p>©2008 Calvin Limuel a.k.a. r3ck0rd. All rights reserved.<br />
Original Link: <a href="http://reckord.info/password-security/303.account-security-v.html">http://reckord.info/password-security/303.account-security-v.html</a> or <a href="http://reckord.info/?p=303">http://reckord.info/?p=303</a><a href="../../?p=105"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/tips/account-security-v.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>TimeZone / Amazone Hack (Cheat) : Basket Ball Arcade Game</title>
		<link>http://zoiz.web.id/tips/timezone-amazone-hack-cheat-basket-ball-arcade-gtame.html</link>
		<comments>http://zoiz.web.id/tips/timezone-amazone-hack-cheat-basket-ball-arcade-gtame.html#comments</comments>
		<pubDate>Tue, 23 Dec 2008 04:13:27 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[TimeZone]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=165</guid>
		<description><![CDATA[Maybe you like playing in Game Arenas such as Amazone or TimeZone. And I found this vulnerability in those game arenas. Different from the article before, this vulnerability may only be found in some game centers of TImeZone / Amazone (Not all vulnerable to this). When Lebaran Holiday came, my mother suggested my grandma to [...]]]></description>
			<content:encoded><![CDATA[<p>Maybe you like playing in Game Arenas such as Amazone or TimeZone. And I found this vulnerability in those game arenas.</p>
<p>Different from the <a href="http://zoiz.web.id/life-matter/hacking-hack-timezone-game-machine.html" target="_blank">article</a> before, this vulnerability may only be found in some game centers of TImeZone / Amazone (Not all vulnerable to this).</p>
<p>When Lebaran Holiday came, my mother suggested my grandma to go to Bandung and Puncak then asked all of my relatives to join us. On the 3rd day of our trip, we arrived in Puncak and go to one factory outlet that is called Brasco or Kampoeng Brasco. I only went there with my aunties, uncle and cousins.</p>
<p>My aunties asked us (me and my cousin) to just wait in a game center called Space Zone. &#8220;It will only take a few minutes&#8221;, my aunties said. My uncle joined my aunties to buys T-shirts and other things. So, my cousin and I was there, alone.</p>
<p>Ok, so we go around without doing anything (because we had no coin at that time) and just have a chat together. We keep talking and walking until we found two basketball game machines.</p>
<p>When my cousins keep talking, I thought a brilliant idea (because I was fed up with that place). I asked my youngest cousin to push the ball that is inside the web or wall with his small finger and It works! The ball started to move from its place! Here&#8217;s the pic:<br />
<img src="http://img214.imageshack.us/img214/7453/dsc01059ig4.jpg" alt="how to hack a basketball arcade game" width="200" /><br />
Okay so now it has been out from its place then, my cousin that really likes basketball take the ball and throw it. So, we have nothing to do (again). So, I asked my cousin to do the same thing that he had done before. So, it was my turn! I shoot it and yeah, we&#8217;ve nothing to do (again).</p>
<p>Then, a man with his child played that game. We just looked at them who played it happily <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_lol.gif' alt=':lol:' class='wp-smiley' /><br />
They played that game for 2 times. After they had no coin anymore, without asking or did anything, my cousin pushed the wall that protects or keep the ball inside and they had one more chance to play it for free!</p>
<p>Wow! They just surprised then play together (without any thanks <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> () and when I asked to push the wall again, it didn&#8217;t work anymore. I think it&#8217;s all because he didn&#8217;t push the wall on the right time <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_lol.gif' alt=':lol:' class='wp-smiley' />  .</p>
<p>Those vulnerabilities seem won&#8217;t work in all TimeZone (but it may work in other location of TimeZone). By the way, here&#8217;s the pic of my lovely cousin that helped a lot:<br />
<img src="http://img368.imageshack.us/img368/8439/dsc01058sq7.jpg" alt="hacking basketball game" width="200" /></p>
<p>Thanks!<br />
<a href="http://www.ymm0t.co.cc">ymm0t</a></p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/tips/timezone-amazone-hack-cheat-basket-ball-arcade-gtame.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Tips Accounts Security (Safety) Part IV</title>
		<link>http://zoiz.web.id/tips/accounts-security-part-iv.html</link>
		<comments>http://zoiz.web.id/tips/accounts-security-part-iv.html#comments</comments>
		<pubDate>Mon, 13 Oct 2008 05:04:49 +0000</pubDate>
		<dc:creator>r3ck0rd</dc:creator>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[account]]></category>
		<category><![CDATA[Account Safety]]></category>
		<category><![CDATA[ASCII]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[Sandbox]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=117</guid>
		<description><![CDATA[Accounts Security Part IV A Password Security Related Article by Calvin Limuel a.k.a. r3ck0rd Howdy ho! Has it been a loss since my previous post about Accounts Security? Did you enjoy my previous posts about your accounts&#8217; security? Have you done those tips? You haven&#8217;t? OK I haven&#8217;t done those too (some, but not the [...]]]></description>
			<content:encoded><![CDATA[<p><span style="16px;">Accounts Security Part IV</span></p>
<p><span style="10px;">A Password Security Related Article by <a title="r3ck0rd's Blog (4 hits)" href="http://reckord.info">Calvin Limuel a.k.a. r3ck0rd</a></span></p>
<p>Howdy ho! Has it been a loss since my previous post about Accounts Security? Did you enjoy my previous posts about your accounts&#8217; security? Have you done those tips? You haven&#8217;t? OK I haven&#8217;t done those too (some, but not the same mistake hehe  <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  ). Well then, finally the fourth part, eh? And I hope you enjoy this post. Containing, maybe not so fresh, because may be discussed outside somewhere, or taken from a portion of an article in my blog, but helping tips for you to workout. Happy securing!</p>
<p><span id="more-117"></span></p>
<p>1. Non-ASCII Password</p>
<p>Password brute-force(r) usually scan only ASCII characters. Well, if allowed, you can use passwords with Cyrillic or Greek or any other text from other languages. This will be more secure (I suppose) and more memorable.</p>
<p>2. Multi-byte Password</p>
<p>Even better! On the previous post in <a rel=" target=" href="http://th0r.info/?p=98">Th0R&#8217;s blog</a>, he showed an account secured by nature, their own language in Chinese characters. Well I can read Chinese, but I know some of you don&#8217;t. Well then I suppose, even harder to crack, because Kanji/Hanzi/Hangul and Hanja characters are numerous (Chinese Hanzi: more than 80k, Kanji, more than 6000)! I don&#8217;t know for exact how much characters supported by today&#8217;s encodings. What I know that the national encoding CNS (Chinese Standard Interchange Code) contains more than 13,000 Chinese Characters. Don&#8217;t know for UTF encodings.</p>
<p>3. Copy and Paste</p>
<p>Wait! This doesn&#8217;t mean I recommend you to store your password file in a plain text that you can copy paste the passwords! This trick is recommended if you suspect your computer too much, then prepare your notepad, and type all the characters on your keyboard, maybe with those non-ascii or multibyte characters. Then if you want to input passwords, just copy and paste them one by one. And, use your mouse.</p>
<p>4. <img src="http://reckord.info/wordpress/wp-content/uploads/2008/03/4wdevp.gif" alt="4wdevp" /> Maximize robot.txt and .htaccess</p>
<p>It&#8217;s for keeping crawlers out of your restricted directories. You can password your directory too with this. There are tutorials about this in the internet a lot. Do google them <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  (once again, google is a verb).</p>
<p>5. Sandboxes to protect you</p>
<p>Yes, it&#8217;s to protect you from crackers. And why do I insert this general security tips in a password security article? It&#8217;s between two answers, it&#8217;s related of course, and usually crackers hack your computer to steal important things or credentials for their profit. The second, I&#8217;m running out of idea? *take a laugh* OK. If you don&#8217;t know what sandboxes are, you can go to <a rel="external nofollow" href="http://en.wikipedia.org/wiki/Sandbox_(computer_security)">http://en.wikipedia.org/wiki/Sandbox_(computer_security)</a>.</p>
<p>Some may recommend you to use virtual machines like the famous VMWare. Yes for me it&#8217;s useful too if I want to test other OS or a hacking demo. But if it&#8217;s just for securing, just search a good sandbox program like Sandboxie (as recommended by <a rel="external nofollow" href="http://clog.ammar.web.id/2008/06/xxx-hacking-ala-th0r.html">y3dips</a>), you can google that. But you can use other software of course, if you think it&#8217;s better.</p>
<p>6. Updating and Patches are important!</p>
<p>I recommend if a software has an automatic update feature, like Windows, or a browser like Firefox or Opera, turn it on, especially for security patches. If there is none, you can be a little diligent by checking the news from the vendor or security sites that provides advisories, like <a rel="external nofollow" href="http://secunia.com">Secunia</a>, <a rel="external nofollow" href="http://www.milw0rm.com/">milw0rm</a>, <a rel="external nofollow" href="http://www.securityfocus.com/">SecurityFocus</a>, and such.  So you can aware with the new vulnerabilities found for your software.</p>
<p>7. <img src="http://reckord.info/wordpress/wp-content/uploads/2008/03/4wdevp.gif" alt="4wdevp" /> Use salt!</p>
<p>Not that salty salt, but <a href="http://en.wikipedia.org/wiki/Salt_(cryptography)" target="_blank">this salt</a>. To avoid rainbow table attack and other reason. This is the example of usage:</p>
<pre>// syntax: md5($pass, $salt);
$pass="ligx";
$salt=3147;
md5($pass, $salt);<img src="/Users/r3ck0rd/AppData/Local/Temp/moz-screenshot.jpg" alt="" /><img src="/Users/r3ck0rd/AppData/Local/Temp/moz-screenshot-1.jpg" alt="" /></pre>
<p>8. <img src="http://reckord.info/wordpress/wp-content/uploads/2008/03/4wdevp.gif" alt="4wdevp" /> WordPress Secret Keys!</p>
<p>You should know, as this holds the cookie hashing salt. This is the script you should input in your wp-config.php:</p>
<pre>define('SECRET_KEY', 'whateverbebasfree');
// this ones below available in WP 2.6
define('AUTH_KEY', 'totally');
define('SECURE_AUTH_KEY', 'uptoyou');
define('LOGGED_IN_KEY', 'idontknow');</pre>
<p>9. Delete credentials recorded in Google Cache</p>
<p>You may have a little mistake in the past that makes someone or even you, have a page in Googlebot&#8217;s cache containing your passwords. You can do this by removing the URL &#8220;howto&#8221;s <a rel="external" href="http://www.google.com/support/webmasters/bin/answer.py?answer=61062&amp;topic=13511">here</a>.</p>
<p>10. Friendster Security and Privacy</p>
<p>Friendster is known for many user abuse. And that must be one of the reason Th0R wrote &#8220;Friendster Hacking&#8221;. You already know <a href="http://reckord.info/friendster/friendster-bug/81.friendster-logout-problem.html">this</a> and <a href="http://reckord.info/gastrote/178.friendster-acc-safety.html">this</a> article, and about the filter of Friendster is off. So, attackers, can snoop in malicious code again. Yes it&#8217;s the way Friendster Team may want to know how much is the threata and where do they come from. So you can secure yourself by disabling auto-approve comment from your settings page. Still in your settings page, if you want to, disable all the automatics. All manual. And for the &#8220;add to be your friend&#8221;, choose require last name or e-mail address. Only friends can leave comment. Then if you still feel unsafe by just NoScript alone, choose safe mode option on.</p>
<p>For the privacy, yes Friendster is a social networking site, which you can provide your own data about yourself. You may not want other people who don&#8217;t know you to see those things. So all you have to do is to restrict profile views only to your friends. If you want to tolerate more, for 2nd degrees.</p>
<hr />That&#8217;s all for this edition. The 5th part is coming up and I&#8217;ll continue to write soon. I know this edition may look disappointing to you but I hope you&#8217;re happy to see all tips in one article. Enjoy your day!</p>
<p>Thu.10.9.2008</p>
<p>r3ck0rd</p>
<p>©2008 Calvin Limuel a.k.a. r3ck0rd. All rights reserved.</p>
<p>Original Link: <a href="http://reckord.info/password-security/105.account-security-part-4.html">http://reckord.info/password-security/105.account-security-part-4.html</a> or <a href="http://reckord.info/?p=105">http://reckord.info/?p=105 </a></p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/tips/accounts-security-part-iv.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pilih (Perbedaan) Toyota Rush vs Daihatsu Terios vs Toyota Avanza</title>
		<link>http://zoiz.web.id/tips/pilih-perbedaan-kenyamanan-ketahanan-harga-pemakaian-bbm-toyota-rush-vs-daihatsu-terios-vs-toyota-avansa.html</link>
		<comments>http://zoiz.web.id/tips/pilih-perbedaan-kenyamanan-ketahanan-harga-pemakaian-bbm-toyota-rush-vs-daihatsu-terios-vs-toyota-avansa.html#comments</comments>
		<pubDate>Wed, 10 Sep 2008 09:56:40 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[Car]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Avanza]]></category>
		<category><![CDATA[Mobil]]></category>
		<category><![CDATA[Rush]]></category>
		<category><![CDATA[Terios]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=114</guid>
		<description><![CDATA[First of all, this post is for Indonesian therefore will be written in Bahasa Indonesia. Sorry for English readers Para pengunjung blog yang terhormat, pernah merasa bingung tidak pada saat memilih mobil? Misalnya memilih merek, memilih model, dan tentunya memilih harga. Pada saat ini, terdapat banyak sekali merek mobil seperti Toyota, Honda, Mitsubishi, Hyundai, dan [...]]]></description>
			<content:encoded><![CDATA[<p>First of all, this post is for Indonesian therefore will be written in Bahasa Indonesia. Sorry for English readers <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>Para pengunjung blog yang terhormat, pernah merasa bingung tidak pada saat memilih mobil? Misalnya memilih merek, memilih model, dan tentunya memilih harga. Pada saat ini, terdapat banyak sekali merek mobil seperti Toyota, Honda, Mitsubishi, Hyundai, dan lain sebagainya. Tetapi pilihan saya tetap mobil Toyota, selain sparepart gampang didapatkan, juga keawetan mesin sudah teruji. Dan paling penting harga resell (harga seken) juga ga jelek sekali lah <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>4 tahun lalu saya membeli mobil Toyota Corona, harganya sekitar Rp. 58.000.000 dan beberapa saat dulu saya jual, tau ga harga pasarannya berapa? Rp. 74.000.000,- <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  Naik sekitar Rp. 16.000.000,-. Hehehe. Yup, karena pada saat saya membeli FTZ masih berlaku, sedangkan pada saat saya jual kemaren FTZ sementara dicabut, sehingga harga mobil Ex Singapore naik drastis. Lumayan kan? <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p><span style="text-decoration: line-through;">Sekarang bingung juga nih karena ingin meng-kredit atau menyicil mobil baru tapi bingung mau pilih yang mana diantara 3.</span> Ada 3 model mobil yang akan saya bahas disini, yaitu :<span id="more-114"></span></p>
<p>1. Toyota Avanza 2008<br />
2. Toyota Rush 2008<br />
3. Daihatsu Terios 2008</p>
<p>Setelah saya googling sana sini, ternyata banyak juga yang membahas tentang perbedaan Toyota Rush dan Daihatsu Terios.</p>
<p>Dari segi mesin, Toyota Rush dan Daihatsu Terios memiliki engine yang sama yaitu engine KS-VE DOHC VVT-i 1.500 cc (Sama juga dengan engine Toyota Avanza 1.5 S AT/MT). Oke, dari segi mesin ketiga-tiganya sama.</p>
<p>Dari segi keselamatan sih memang Toyota Rush menang dari Daihatsu Terios, dimana Toyota Rush memiliki ABS system dan double air bag, sedangkan Daihatsu Terios tidak. Tapi kalo masalah keselamatan sih saya rasa tergantung dari segi pengemudinya. Kalau karena memiliki double air bag dan ABS system membuat pengemudi berani membawa extra laju, i prefer not <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>Dari segi interior Toyota Rush juga memiliki keunggulan extra dibandingkan dengan Daihatsu Terios, yaitu CD Changer 6 Pcs. Dekorasi interios juga dimenangi oleh Toyota Rush. Cuma kalau Daihatsu Terios memiliki 2 seat extra di belakang dibanding Toyota Rush yang hanya memiliki 5 tempat duduk.</p>
<p>Dari segi kenyamanan sih Toyota Rush menang lagi <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  Haha, tapi setelah saya cari informasi dari para pemilik Daihatsu Terios, mereka menyarankan untuk mengganti Shock Breaker. Kenyamanan Daihatsu Terios akan dapat mengimbangi Toyota Rush.</p>
<p>Sedangkan untuk Toyota Avanza, dari pengalaman saya membawa (mobil kantor), sih memang aga kurang. Tenaga yang kurang memadai beserta Shock Breaker yang kurang bagus, membuat saya memberikan nilai minus buat Toyota Avanza.</p>
<p>Tetapi jika dinilai dari segi pemakaian BBM, toyota Avanza jelas lebh irit dibandingkan dengan Toyota Rush maupun Daihatsu Terios.</p>
<p>Saya sempat tanya-tanya ke second hand market tentang harga Avanza, ternyata harga resell / seken-nya masih sangat tinggi. Kurang tau kalau soal harga re-sell Toyota Rush maupun Daihatsu Terios.</p>
<p>Well, setelah segi-segi kenyamanan, keselamatan, kehemetan BBM, dan ketahanan mesin. Tentu harga akan menjadi faktor yang sangat pending dalam memilih mobil. Informasi harga (hari ini :  10 September 200*) yang saya dapatkan dari situs vendor masing-masing adalah sebagai berikut :</p>
<p>Toyota Avanza 1.5 S AT : Rp. 147.700.000,-<br />
Toyota Rush 1.5 S AT : Rp. 186.150.000,-<br />
Daihatsu Terios 1.5 TX Elegant : Rp. 173.900.000,-</p>
<p>Well, saya masih tetap bingung mau pilih yang mana. Ada saran teman-teman? Hehe. Silahkan berdiskusi <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/tips/pilih-perbedaan-kenyamanan-ketahanan-harga-pemakaian-bbm-toyota-rush-vs-daihatsu-terios-vs-toyota-avansa.html/feed</wfw:commentRss>
		<slash:comments>74</slash:comments>
		</item>
		<item>
		<title>Friendster Logout Problem</title>
		<link>http://zoiz.web.id/tips/friendster-logout-problem.html</link>
		<comments>http://zoiz.web.id/tips/friendster-logout-problem.html#comments</comments>
		<pubDate>Sun, 06 Jul 2008 06:40:09 +0000</pubDate>
		<dc:creator>r3ck0rd</dc:creator>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[cookie]]></category>
		<category><![CDATA[Friendster]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=108</guid>
		<description><![CDATA[It&#8217;s been a while since I last post here about Account Security part III. Now, this is about Friendster. Friendster again? Am I not bored? Of course I do, it’s my fun! Hacking is for fun, don’t you think so? Of course you don’t if you have already made hacking as a job. It’s no [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a while since I last post here about <a href="http://reckord.info/password-security/36.accounts-security-part-iii.html">Account Security part III</a>. Now, this is about <a href="http://www.friendster.com/" target="_blank">Friendster</a>. Friendster again? Am I not bored? Of course I do, it’s my fun! Hacking is for fun, don’t you think so? Of course you don’t if you have already made hacking as a job. It’s no fun anymore, isn’t it? It’s about work. Or if someone still say it’s fun whether it’s a job or not, glad to hear that! <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> <img class="mce_plugin_wordpress_more" src="http://th0r.info/wp-includes/js/tinymce/themes/advanced/images/spacer.gif" alt="More..." width="100%" height="10" /></p>
<p>OK to the point. Monday when I have a trip to Tanah Lot in Bali, my friend <a href="http://www.friendster.com/jinchuu9" target="_blank">ymm0t</a> called <a title="me" href="http://reckord.info/aboutme">me</a> and send me his advisory. It’s about Friendster’s log out problem. Well, I found it earlier than him, but never thought of writing this.</p>
<p>Have you ever given a link by someone, that is, <a href="http://profile.friendster.com/logout.php">http://profile.friendster.com/logout.php</a>? Or it’s after you view someone’s profile (<a href="http://reckord.info/password-security/36.accounts-security-part-iii.html">http://profile.friendster.com/r3ck0rd</a> for example). After you click it, you’ll see the logout page. But when you go to the home page of Friendster, you’ll see you haven’t logged out from Friendster. What’s going on?</p>
<p>This is my deduction, and ymm0t may not know this. You were logged out. But not from www.friendster.com. Only from profile.friendster.com. It’s a fatal fault for the user if they log out after they view someone’s profile by clicking the link above right. It reset the cookie of profile.friendster.com, but did not reset the cookie of www.friendster.com.</p>
<p>So what’s all the babbling about? Haven’t get it? Right here’s a scenario. If you were browsing on Friendster, and viewing someone’s profile, then you were forced by your friend to press the log out link at the top bottom, or you were told by your friend to go to profile.friendster.com/logout.php, because your friend wants to use it. Well after the “You have been logged out” text showed up, then you give your friend turn to use the computer. The fact is, if your friendster… I mean if your friend is naughty, as you haven’t been logged out from www.friendster.com, he can still access your account. And do something bad. Like putting a bad code to your profile maybe to steal your friends’ cookies, and your account may be banned for containing that code.</p>
<p>This short? Yeah this short. Short and easy to take over one’s account right? Lucky you if you access Friendster from your own PC or notebook at home. What if, in the internet café? Where the computers you use are shared computer.  So, here are the problem solver:</p>
<ul>
<li>After you logout anywhere in Friendster, make sure you check out www.friendster.com too. Recheck always.</li>
<li>It’s recommended to log out from the home page. friendster.com.</li>
<li>If it’s not helping, just install a cookie editor plugin for your browser and just delete all the cookies from Friendster.</li>
<li>Remember, &#8220;just click log out and good bye&#8221; may not enough.</li>
</ul>
<p>It’s not reported yet, but I’ll be reporting it to the Friendster Team.</p>
<p>By the way, after Th0R read this, he mentioned about CSRF. I don’t know what he meant but I’m thinking about sending my friends this link or just put a CSRF in my FS Profile like this:<br />
&lt;img src=”http://profiles.friendster.com/logout.php” alt=”logout” /&gt;<br />
It’ll be kinda annoying huh  <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_lol.gif' alt=':lol:' class='wp-smiley' />  (may I implement it here?)</p>
<p>All credits to: ymm0t for reminding me this. And Th0R for the CSRF idea. <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>GreetZ to:<br />
- All SATE, HackingForte, and Ha.ckwith.us members. You’re all my support in growing my hacking activity.<br />
- IndoForum members. You may dislike me or not because I’m still one of them, but this forum is the place where I grow up too.<br />
- BayPas staffs and members, thanks for entrusting me to be the technician.<br />
- Most of all, Jesus for keep giving me my breath.</p>
<p>Original Link: <a href="http://reckord.info/friendster/friendster-bug/81.friendster-logout-problem.html">http://reckord.info/friendster/friendster-bug/81.friendster-logout-problem.html</a></p>
<p>Update 05/07/2008:</p>
<p>Disclaimer: The copyright above is for the text, not the bug. We never claim this as my own bug found. I don&#8217;t know if someone has reported this anywhere, because it&#8217;s an easy thing to found.</p>
<p>Thu.2008.6.19<br />
r3ck0rd</p>
<p>© 2008 <a href="http://reckord.info/">r3ck0rd</a> and <a href="http://www.friendster.com/jinchuu9" target="_blank">ymm0t</a>. Some rights reserved.</p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/tips/friendster-logout-problem.html/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Launching : Hackers.web.id</title>
		<link>http://zoiz.web.id/tips/launching-hackerswebid.html</link>
		<comments>http://zoiz.web.id/tips/launching-hackerswebid.html#comments</comments>
		<pubDate>Fri, 09 May 2008 04:39:30 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=101</guid>
		<description><![CDATA[Hackers.web.id is a newly formed and independent computer security consultant which operates in Indonesia &#38; Australia. They dedicated to Information Technology Security Industries and set their main goal to provide the ultimate security assessment discipline to improve the Web Application Security. Hackers.web.id has a combining of 15 years of experience in IT Security Industries and [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hackers.web.id">Hackers.web.id</a> is a newly formed and independent computer security consultant which operates in    Indonesia &amp; Australia. They dedicated to Information Technology Security Industries and set their main goal to provide the ultimate security    assessment discipline to improve the Web Application Security.</p>
<p>Hackers.web.id has a combining of 15 years of experience in IT Security Industries and their contribution to the security industries is acknowledgeable. Such as internal consulting to Yahoo7 Inc., the Biggest ever Zero-Day Vulnerability Report in Indonesia history, advisories to some of world&#8217;s biggest social community network such as Friendster,  and also Web Application Security Assessment to several International IT Companies.</p>
<p>Hackers.web.id provided an one-stop Web Application Security consultations and services to fit your company needs. Please visit <a href="http://hackers.web.id" target="_blank">their home page</a> for more information.</p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/tips/launching-hackerswebid.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Thousand Ways To Inject SQL</title>
		<link>http://zoiz.web.id/tips/thousand-ways-to-sql-injection-a-tutorial-via-cookie-and-useragent-etc.html</link>
		<comments>http://zoiz.web.id/tips/thousand-ways-to-sql-injection-a-tutorial-via-cookie-and-useragent-etc.html#comments</comments>
		<pubDate>Sun, 27 Apr 2008 06:45:30 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=95</guid>
		<description><![CDATA[SQL Injection sounds outdated? No, SQL Injection is a very common vulnerability that existed long time ago, and also many people know how to do it. But not everyone out there knows where to find all SQL Injectable hole. I&#8217;ll point out some : Cookie SQL Injection Yeah, insert your SQL query through your cookies [...]]]></description>
			<content:encoded><![CDATA[<p>SQL Injection sounds outdated? No, SQL Injection is a very common vulnerability that existed long time ago, and also many people know how to do it. But not everyone out there knows where to find all SQL Injectable hole. I&#8217;ll point out some :</p>
<p><span id="more-95"></span></p>
<p><strong>Cookie SQL Injection</strong></p>
<p>Yeah, insert your SQL query through your cookies editor. This can be done if a web application uses value from cookies without a proper sanitizing. Example of vulnerable code :</p>
<p>&lt;?<br />
$preference = $_COOKIE['pre'];<br />
$color = mysql_query(&#8216;SELECT color FROM settings WHERE color = $pre&#8221;);<br />
?&gt;</p>
<p>Unfiltered cookies will land you to trouble if you use the cookies string in a SQL command.</p>
<p><strong>User-Agent SQL Injection</strong></p>
<p>Some CMS stores their visitor IPs, browsers, and user-agent information to their database. So the problem is, user-agent can be modified easily. Without a proper sanitize, SQL Injection may occurs too via User-Agent Spoofing. The PoC is same as Cookies SQL Injection.<br />
<strong>SQL Injection Via JS Injection</strong></p>
<p>Some sites use javascript to perform data post. Thus, a Javascript + SQL Injection is not impossible.</p>
<p><strong>Update on 2nd May 2008</strong></p>
<p><strong>SQL Injection Via Wap Site</strong></p>
<p>A good security from a company web application doesn&#8217;t means that their WAP application is secure. A SQL Injection on WAP application is as critical as on web application. Some web developers neglected WAP application security as maybe they felt that it&#8217;s not as important as web application security. But once a SQL Injection is launched via WAP application : GAME OVER.</p>
<p>If you have some more techniques of SQL Injection, you can share it here via comments <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/tips/thousand-ways-to-sql-injection-a-tutorial-via-cookie-and-useragent-etc.html/feed</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Account Security Part III &#8211; r3ck0rd</title>
		<link>http://zoiz.web.id/tips/account-security-part-iii-r3ck0rd.html</link>
		<comments>http://zoiz.web.id/tips/account-security-part-iii-r3ck0rd.html#comments</comments>
		<pubDate>Tue, 22 Apr 2008 15:02:20 +0000</pubDate>
		<dc:creator>r3ck0rd</dc:creator>
				<category><![CDATA[Social Life]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[account]]></category>
		<category><![CDATA[address bar]]></category>
		<category><![CDATA[captcha]]></category>
		<category><![CDATA[cc]]></category>
		<category><![CDATA[code injection]]></category>
		<category><![CDATA[cookie stealing]]></category>
		<category><![CDATA[credit card]]></category>
		<category><![CDATA[CSRF]]></category>
		<category><![CDATA[cvv2]]></category>
		<category><![CDATA[filter]]></category>
		<category><![CDATA[guide]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[password security]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[programmer]]></category>
		<category><![CDATA[rfi]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[technical security]]></category>
		<category><![CDATA[technological security]]></category>
		<category><![CDATA[web developers]]></category>
		<category><![CDATA[XSRF]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=100</guid>
		<description><![CDATA[Accounts Security Part III For Web Developers and Programmers Guide and Technological and Technical Security A Password Security Related Article by Calvin Limuel a.k.a. r3ck0rd 2nd Revision, 20080422 &#8211; by r3ck0rd Finally, third episode of this serial! Despite in the middle of home works, school projects, web design preparation for a competition, writing my own [...]]]></description>
			<content:encoded><![CDATA[<p>Accounts Security Part III<br />
For Web Developers and Programmers Guide and Technological and Technical Security<br />
A Password Security Related Article by Calvin Limuel a.k.a. r3ck0rd<br />
2nd Revision, 20080422 &#8211; by r3ck0rd</p>
<p>Finally, third episode of this serial! Despite in the middle of home works, school projects, web design preparation for a competition, writing my own book “Behind the Scenes of XSS, RFI, and SQL Injection”, other Gastrote and hacking projects, Vocal Group Competition preparation, and any other things I have to do. But I still want to write more.</p>
<p>Yes in this third part, I changed the serial name and this is the final name: Accounts Security. And I&#8217;m extending this serial for web developers and programmers (marked with the 4 WDev&amp;P™ or &#8220;For Web Developers and Programmers™&#8221; logo).</p>
<p>1. For Web Developers and Programmers™ Configuration File<br />
Configuration file is where you put your sensitive data for a web application. Such as database login details. Don&#8217;t just save it in *.inc. Because .inc extension is just an extension and a standard, few people still doing this. .ini files too. So it can be downloaded directly, easily. I recommend give a protection like, adding an extra .php extension (like config.inc.php), forbid direct access through .htaccess and PHP, and encode the file.<span id="more-100"></span></p>
<p>2. For Web Developers and Programmers™ Filter, filter, filter!<br />
The word &#8220;filter&#8221;, now, is not always to avoid HTML Injection and XSS only. You may have know how to filter SQL Injection, and so do RFIs. If not, I&#8217;ll write about it some other time. In Zoiz&#8217; advisory page here: http://zoiz.web.id/xss-corner/useragent-xss.html or http://th0r.info/?p=77, he showed us that User Agent data from the browser, in this practice, Mozilla Firefox, can be modified. From Internet Explorer, you can do it from the registry editor. I&#8217;ll write about it in the next episode of Microsoft Windows Tweaks. I haven&#8217;t find out how to do it in Opera, Netscape, Safari, or any other browsers.<br />
Back to that advisory. He found out that User Agent String Data can contain HTML codes. By the &#8220;mighty power&#8221; of XSS, we can even do what Th0R does in his first book: &#8220;Friendster Hacking&#8221;. Yes, we&#8217;re talking about Cookie Stealing. How can we do it? Next time, OK? ^^ Some programmers make programs for logging users. Some still display the raw string of the user agent data. You know what I mean next.<br />
Read more about code injection.</p>
<p>3. For Web Developers and Programmers™ Password File and Database security<br />
About putting passwords to files, it is risky enough. More risky than point 1. Because you know, it can be accessed by public individuals. The safest way I think is to put it into the database. However, these can be accessed if you have SQL Injection vulnerability in your web application. The solution is none other than encrypt it with one-way encryption method. Yes I know your web applications encrypts your passwords by default. And the usual method: Message Digest 5 (MD5). And you know by reading Th0R&#8217;s book, Zero-Knowledge Password, and part two of this serial, it can be cracked. With bruteforce (this is avoidable, not like what you think, the easiest way is through CAPTCHA, available in php class), rainbow table. So how to protect them? Try another encryption like SHA1. Or, use multiple encryption. MD5, SHA1, and ROT13. Or you can add PHPass (Portable PHP Password) hashing framework from www.openwall.com/phpass, a security foundation, that made John the Ripper password cracker, in your list.</p>
<p>4. Remember Password Feature<br />
I forgot to write this in my earlier articles. Yes, don&#8217;t do this, especially if you&#8217;re accessing websites, including your messenger programs, even if it&#8217;s encrypted. It&#8217;s not about knowing your password, but someone can set the settings for not enabling password to be required to get in into his e-mail.</p>
<p>5. VBScript in web pages<br />
Know VBScript? Yes, VBScript can be embedded in a HTML page. Client-side.  But you have to know people can make worms/viruses with this. It&#8217;s not impossible for a coder to code a spyware, trojan horse, even a keylogger, then embed them in a HTML page. Best way I know to anticipate is: disable  tags from your browser. But, it&#8217;ll be more comfortable if you just install Mozilla Firefox (latest one is 2.0.0.13 and 3.0 b5) and install NoScript plugin by Giorgio Maone.</p>
<p>6. For Web Developers and Programmers™ CSRF Attack: for users and WDev&amp;P<br />
Lists of links that may help you preventing CSRF:<br />
- http://www.gnucitizen.org/blog/preventing-csrf/<br />
- http://websecurity.ro/blog/2008/03/28/wordpress-233-probably-a-0day-exploit/<br />
- http://christ1an.blogspot.com/2007/04/preventing-csrf-efficiently.html<br />
- http://www.cgisecurity.com/articles/csrf-faq.shtml<br />
More? Google them <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>7. Your browser&#8217;s address bar<br />
Remember XSS? Right. I think I&#8217;ve told you about this, but if not, here are my tips. First of all, watch the address bar. This will be useful to avoid XSS contain phishing and any other malicious things. Previously, in Friendster, you can put a phising page through redirection, showing you a fake login page. And in World of Warcraft&#8217;s website, Th0R has showed us the p0f of it, in the preious SATE (Security Advisory Team) forum. But it&#8217;s alright when you watch the address closely. But if you don&#8217;t understand, I recommend NoScript plugin, has known to prevent XSS to be executed.</p>
<p>8. Seek secure web pages<br />
This is very important if you&#8217;re messing up with e-banking or e-commerce sites. First, the protocol should be in https:// or port 443 (secure HTTP, HyperText Transfer Protocol). Second, verify the certificate, the encryption method, the digital signature and the certificate maker, like VeriSign or e-trust. Although there maybe a counterfeit, just cross check with the certificate maker&#8217;s site.</p>
<p>9. For Web Developers and Programmers™ PHP5, 6 and MySQL<br />
As an subtopic of point 2, prevent SQL Injection by using magic_quotes. But since the news says it&#8217;ll be removed, you have to manually filter it yourself. Or if you&#8217;re using MySQL, you can use this function: mysql_real_escape_string().</p>
<p>10. Credit Card<br />
It&#8217;s not impossible if someone like a cashier can do a fast remembering or has a photographic memory to remember your bank account number and your CVV2. Just for advice, either when you want to use your credit card to debit, swipe your card to their &#8220;skimmer&#8221; (I don&#8217;t know what&#8217;s its name) yourself, or don&#8217;t let the cashier see your credit card longer. If they want to cross check the signature, you show him/her. Or if you want to apply a new credit card, and the dealer require you to photocopy your current credit card, ask the them to cover the CVV2.</p>
<p>Hah OK, it&#8217;s finished. 2 weeks of work. Haha <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . Actually I suddenly came up with one more point. But let it be in the fourth part <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>This article was made by Calvin Limuel a.k.a. r3ck0rd with a help from Zoiz for few points. Thanks a lot Zoiz! It&#8217;ll be 3 weeks if you don&#8217;t point me some points. <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>Greet fliest to:<br />
- Zoiz, Th0R, badkiddies, JKR, and all HackingForte members.<br />
- Some of my chat friends: PusHm0v, th3sn0wbr4in, yamiza.<br />
- My friends at my school: Arcsanctus, CH.</p>
<p>And thanks to Jesus for making me alive until today, so I can write this article ^^.</p>
<p>April 11, 2008</p>
<p>Calvin Limuel<br />
© 2008 r3ck0rd<br />
See here for more information if you want to copy this article.</p>
<p>Original URL: http://reckord.info/?p=36 or http://reckord.info/password-security/r3ck0rd/2008.04.11/36.accounts-security-part-iii.post</p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/tips/account-security-part-iii-r3ck0rd.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Unable To Access YouTube.com</title>
		<link>http://zoiz.web.id/tips/unable-to-access-youtubecom.html</link>
		<comments>http://zoiz.web.id/tips/unable-to-access-youtubecom.html#comments</comments>
		<pubDate>Sat, 05 Apr 2008 04:03:49 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[Social Life]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[YouTube.com]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=94</guid>
		<description><![CDATA[For Indonesian Visitor : Kenapa pakai Trick saya dari pada menggunakan Web Proxy seperti Anonymouse.Org? Karena Koneksi Melalu HTTP Tunneling memungkinkan kita untuk meng-Kompresi data yang akan ditransfer sehingga bisa browsing lebih cepat. If you are one of the Indonesian ISP users, you might have problem accessing http://youtube.com. I am not sure what actually happened [...]]]></description>
			<content:encoded><![CDATA[<h2>For Indonesian Visitor : Kenapa pakai Trick saya dari pada menggunakan Web Proxy seperti Anonymouse.Org? Karena Koneksi Melalu HTTP Tunneling memungkinkan kita untuk meng-<strong>Kompresi data</strong> yang akan ditransfer sehingga bisa browsing lebih cepat.</h2>
<p> <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>If you are one of the Indonesian ISP users, you might have problem accessing http://youtube.com. I am not sure what actually happened (as I know that YouTube.com have some videos that Indonesian Government ban).</p>
<p><span style="text-decoration: line-through;">From my small research, I found out that Indonesia ISP deletes youtube.com Name Server record from all DNS&#8217;. You can regain your access, of course by changing your secondary DNS into this : 12.127.17.83.</span></p>
<p><span style="text-decoration: line-through;">How to do it :</span></p>
<p><span style="text-decoration: line-through;">Open your Network Setting. Right click and select property. In Internet Protocol list menu, click configure. And type in the DNS I provided into the secondary DNS. Now you can access YouTube.com!</span></p>
<p>Note : Correct me if I am wrong <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Update 8th April 2008 :</p>
<p>The DNS trick seems to be not working anymore, but you can still access those block sites by using HTTP Tunneling. If you don&#8217;t know how to do it, here&#8217;s a simple one :</p>
<p>1. Download PuTTy.exe from here : http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html<br />
2. Open Command Prompt and change your directory to where you save the PuTTy.exe. And type this command :</p>
<blockquote><p><strong>putty -P 222 -N -D 9999 -C net@cepat.abangadek.com</strong></p></blockquote>
<p>3. A windows will pop up, and you are required to type in a password. Enter : cepat123<br />
4. Follow the instruction from the image below : <span id="more-94"></span></p>
<p><a href="http://zoiz.web.id/images/net-cepat-firefox.jpg" target="_blank"><img style="vertical-align: middle;" src="http://zoiz.web.id/images/net-cepat-firefox.jpg" alt="Browser Configuration For PuTTy HTTP TUnneling" width="424" height="357" /></a><br />
The Instruction (Taken from : http://harry.sufehmi.com/)</p>
<p>Jobs Done!</p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/tips/unable-to-access-youtubecom.html/feed</wfw:commentRss>
		<slash:comments>33</slash:comments>
		</item>
	</channel>
</rss>
