<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Zoiz Blog</title>
	<atom:link href="http://zoiz.web.id/feed" rel="self" type="application/rss+xml" />
	<link>http://zoiz.web.id</link>
	<description>Nothing is Secure</description>
	<lastBuildDate>Wed, 17 Mar 2010 04:35:53 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Protected: iPawn3d the Bet!</title>
		<link>http://zoiz.web.id/tips/ip-pawned-the-bet.html</link>
		<comments>http://zoiz.web.id/tips/ip-pawned-the-bet.html#comments</comments>
		<pubDate>Wed, 17 Mar 2010 04:35:15 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=195</guid>
		<description><![CDATA[There is no excerpt because this is a protected post.]]></description>
			<content:encoded><![CDATA[There is no excerpt because this is a protected post.]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/tips/ip-pawned-the-bet.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Account Security V</title>
		<link>http://zoiz.web.id/tips/account-security-v.html</link>
		<comments>http://zoiz.web.id/tips/account-security-v.html#comments</comments>
		<pubDate>Sat, 23 Jan 2010 10:49:33 +0000</pubDate>
		<dc:creator>r3ck0rd</dc:creator>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[account]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[hotspot]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=181</guid>
		<description><![CDATA[Accounts Security V
Concerning Internet use at public spots &#38; Password by Sequence
A Password Security Related Article by Calvin Limuel a.k.a. r3ck0rd
It&#8217;s been a long time since I last posted in Zoiz&#8217; blog. Still the same topic, and it&#8217;s already the fifth! Covering internet usage at public hotspots and sequenced passwords. Here are the tips for [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://reckord.info/password-security/303.account-security-v.html"><span>Accounts Security V</span></a><br />
Concerning Internet use at public spots &amp; Password by Sequence<br />
<span>A Password Security Related Article by <a title="r3ck0rd's Blog" href="../../">Calvin Limuel a.k.a. r3ck0rd</a></span></p>
<p>It&#8217;s been a long time since I last posted in Zoiz&#8217; blog. Still the same topic, and it&#8217;s already the fifth! Covering internet usage at public hotspots and sequenced passwords. Here are the tips for this time:<span id="more-181"></span></p>
<ol>
<li><strong>Log in first before you use it at a public hotspot.</strong><br />
You don&#8217;t know if somebody is ready with his/her Cain&amp;Abel and ready to harvest your usernames and passwords. So, you can log in first at home, put your notebook in standby mode, then bring your notebook where you want to use it.Wonder if somebody thinks of this too.<br />
Note: It&#8217;s not the same as the remember password feature. Remember password feature on your browser just make the username and password appear, it still sends your username and password.</li>
<li><strong>Never do e-transaction such as e-banking or online shopping at a public hotspot. </strong><br />
Crackers still can modify the data sent to the router, so I don&#8217;t recommend this activity.</li>
<li><strong>Use your personal combination. </strong><br />
A friend on Facebook posted a link to here: <a rel="nofollow" href="http://www.linux.com/articles/28057">http://www.linux.com/articles/28057</a>. It&#8217;s a good idea to combine your personal information like this: &#8220;NiKrV@1992!UA-blAcK&#8221;. Assume the password user&#8217;s name is NiKrad KreVchenko, born @1992, born in Ukraine (ISO country code), and his favorite color is black.</li>
<li><strong>Using characters from a random phrase. </strong><br />
Another good idea. Let&#8217;s try from this phrase: &#8220;Lorem Ipsum Dolor Sit Amet. The quick little brown fox jumps over a big lazy dog.&#8221; Take the first letters then you get LIDSATQLBFJOABLD. Or take per two letters, separate words with exclamation mark, then you get LRM!PU!DLR!I!AE! and so forth. Don&#8217;t forget to variate the case, or the symbols. Like changing the exclamation marks to the symbols sequence on your keyboard (~!@#$%^&amp;*()_+`-={}|[]\:&#8221;;&#8217;&lt;&gt;?,./).</li>
<li><strong>Use a Polybius Square. </strong><br />
I&#8217;ve seen this technique somewhere but I forgot it where. Here is one example (you can make this thing by yourself):</p>
<table class="aligncenter" border="0">
<tbody>
<tr>
<td></td>
<td>1</td>
<td>2</td>
<td>3</td>
<td>4</td>
<td>5</td>
<td>6</td>
<td>7</td>
<td>8</td>
<td>9</td>
<td>0</td>
</tr>
<tr>
<td>a</td>
<td>a</td>
<td>s</td>
<td>e</td>
<td>v</td>
<td>e</td>
<td>d</td>
<td>n</td>
<td>e</td>
<td>3</td>
<td>g</td>
</tr>
<tr>
<td>b</td>
<td>!</td>
<td>@</td>
<td>d</td>
<td>3</td>
<td>d</td>
<td>%</td>
<td>e</td>
<td>&amp;</td>
<td>f</td>
<td>3</td>
</tr>
<tr>
<td>c</td>
<td>e</td>
<td>h</td>
<td>*</td>
<td>-</td>
<td>%</td>
<td>d</td>
<td>2</td>
<td>q</td>
<td>F</td>
<td>#</td>
</tr>
<tr>
<td>d</td>
<td>s</td>
<td>!</td>
<td>#</td>
<td>$</td>
<td>%</td>
<td>d</td>
<td>E</td>
<td>2</td>
<td>5</td>
<td>8</td>
</tr>
<tr>
<td>e</td>
<td>f</td>
<td>3</td>
<td>a</td>
<td>S</td>
<td>F</td>
<td>V</td>
<td>#</td>
<td>T</td>
<td>4</td>
<td>A</td>
</tr>
</tbody>
</table>
<p>This works like a <a href="http://en.wikipedia.org/wiki/Polybius_square" target="_blank">Polybius square</a>, one of the ancient cryptography technique. With this, you can only remember two letters for your password, and the length of your. For example, remembering d2 7 letters long, it is: s!#$%dE. Of course you can make this larger on your own. Or just make your own password, then hide it under your own Polybius square</li>
<li><strong>Use the Polybius Square combined with chess moves. </strong><br />
If you like to play chess, and you know some openings, this shouldn&#8217;t be a problem. All you have to do is to make an 8&#215;8 Polybius square, with random letters and captions for chess boards. For example, the Sicilian Dragon Variant: 1. e4 c5 2. Nf3 d6 3. d4 cxd4 4. Nxd4 Nf6 5. Nc3 g6 6. Bg5 Bg7. That&#8217;s enough, a password with 12 characters. If there&#8217;s a repeat of letters it&#8217;s ok, don&#8217;t matter. I hope you understand what I mean.</p>
<table class="aligncenter" border="0" align="center">
<tbody>
<tr>
<td><strong><span> 8</span></strong></td>
<td><strong><span> k</span></strong></td>
<td><strong><span>l</p>
<p></span></strong></td>
<td><strong><span> \</span></strong></td>
<td><strong><span>z</p>
<p></span></strong></td>
<td><strong><span> &#8220;</span></strong></td>
<td><strong><span>{</p>
<p></span></strong></td>
<td><strong><span> +</span></strong></td>
<td><strong><span> </span></strong></td>
</tr>
<tr>
<td><strong><span> 7</span></strong></td>
<td><strong><span> j</span></strong></td>
<td><strong><span> ;</span></strong></td>
<td><strong><span> ]</span></strong></td>
<td><strong><span> x</span></strong></td>
<td><strong><span> ;</span></strong></td>
<td><strong><span> }</span></strong></td>
<td><strong><span> =</span></strong></td>
<td><strong><span>!</p>
<p></span></strong></td>
</tr>
<tr>
<td><strong><span> 6</span></strong></td>
<td><strong><span> h</span></strong></td>
<td><strong><span> &#8216;</span></strong></td>
<td><strong><span> [</span></strong></td>
<td><strong><span> c</span></strong></td>
<td><strong><span> &#8220;</span></strong></td>
<td><strong><span> |</span></strong></td>
<td><strong><span> -</span></strong></td>
<td><strong><span> #</span></strong></td>
</tr>
<tr>
<td><strong><span> 5</span></strong></td>
<td><strong><span> g</span></strong></td>
<td><strong><span> q</span></strong></td>
<td><strong><span> p</span></strong></td>
<td><strong><span> v</span></strong></td>
<td><strong><span> :</span></strong></td>
<td><strong><span> 1</span></strong></td>
<td><strong><span> 0</span></strong></td>
<td><strong><span> $</span></strong></td>
</tr>
<tr>
<td><strong><span> 4</span></strong></td>
<td><strong><span> f</span></strong></td>
<td><strong><span> w</span></strong></td>
<td><strong><span> o</span></strong></td>
<td><strong><span> b</span></strong></td>
<td><strong><span> ?</span></strong></td>
<td><strong><span> 2</span></strong></td>
<td><strong><span> 9</span></strong></td>
<td><strong><span> %</span></strong></td>
</tr>
<tr>
<td><strong><span> 3</span></strong></td>
<td><strong><span> d</span></strong></td>
<td><strong><span> e</span></strong></td>
<td><strong><span> i</span></strong></td>
<td><strong><span> n</span></strong></td>
<td><strong><span> &gt;</span></strong></td>
<td><strong><span> 3</span></strong></td>
<td><strong><span> 8</span></strong></td>
<td><strong><span> ^</span></strong></td>
</tr>
<tr>
<td><strong><span> 2</span></strong></td>
<td><strong><span> s</span></strong></td>
<td><strong><span> r</span></strong></td>
<td><strong><span> u</span></strong></td>
<td><strong><span> m</span></strong></td>
<td><strong><span> &lt;</span></strong></td>
<td><strong><span> 4</span></strong></td>
<td><strong><span> 7</span></strong></td>
<td><strong><span> &amp;</span></strong></td>
</tr>
<tr>
<td><strong><span>1</p>
<p></span></strong></td>
<td><strong><span> a</span></strong></td>
<td><strong><span> t</span></strong></td>
<td><strong><span>y</p>
<p></span></strong></td>
<td><strong><span> ,</span></strong></td>
<td><strong><span>. /</p>
<p></span></strong></td>
<td><strong><span> 5</span></strong></td>
<td><strong><span>6</p>
<p></span></strong></td>
<td><strong><span> *</span></strong></td>
</tr>
<tr>
<td><strong><span> </span></strong></td>
<td><strong><span> a</span></strong></td>
<td><strong><span>b</p>
<p></span></strong></td>
<td><strong><span>c</p>
<p></span></strong></td>
<td><strong><span>d</p>
<p></span></strong></td>
<td><strong><span>e</p>
<p></span></strong></td>
<td><strong><span>f</p>
<p></span></strong></td>
<td><strong><span>g</p>
<p></span></strong></td>
<td><strong><span>h</p>
<p></span></strong></td>
</tr>
</tbody>
</table>
<p>If it based on this square and using the Sicilian Dragon Variant, my password would be: ?p3cbbb|i-0=<br />
Go make your own! Print all your Polybius Squares, make cards of it, and put it into your wallet.</li>
<li><strong>Use On Screen Keyboard.</strong><br />
I always forgot to write this. If you&#8217;re lazy to do the previous tips about copy pasting letters from a text file, just use on screen keyboard. In case there is a keylogger logging coordinate of mouse clicks, before and after you type your password with this tool, move the keyboard to another spot.</li>
<li><strong>Keyboard sequence isn&#8217;t always insecure.</strong><br />
Yeah, it&#8217;s not always insecure. But of course, lame sequence like asdfghjkl, is insecure. Be creative with this one. Like this: !qAz@wSx#eDc. Figure out the sequence yourself. You can switch to another keyboard layout (other than QWERTY, like Dvorak) for awhile for entering passwords.</li>
<li><strong>One-way encrypted password as your password. </strong><br />
Just remember a word, or name, like John Doe. Then, encrypt it to md5. Resulting: 4c2a904bafba06591225113ad17b5cec. If it doesn&#8217;t fit because of the character limit (md5 is 25 character), just cut off the half to the limit character.</li>
<li><img src="http://reckord.info/wordpress/wp-content/uploads/2008/03/4wdevp.gif" alt="For Web Developers and Programmers" width="80" height="20" /> <strong>Using multi-level encryption.<br />
</strong>I found this idea when searching for an encryption tool. If you don&#8217;t get what I say, then I&#8217;ll give you an example:</p>
<pre>$pass = sha1(md5(md5(sha1(sha1(md5(md5(sha1($pass))))))));</pre>
<p>Add salt and different encryption ways if you please:</p>
<pre>$pass= sha1(md5(crypt(str_rot13(base64_encode(md5(1357, sha1($pass)))))))</pre>
<p>I&#8217;m not responsible for any server crash <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </li>
</ol>
<p>That&#8217;s all for now. Enjoy securing.</p>
<p>Thu.1.29.2008<br />
r3ck0rd</p>
<p>©2008 Calvin Limuel a.k.a. r3ck0rd. All rights reserved.<br />
Original Link: <a href="http://reckord.info/password-security/303.account-security-v.html">http://reckord.info/password-security/303.account-security-v.html</a> or <a href="http://reckord.info/?p=303">http://reckord.info/?p=303</a><a href="../../?p=105"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/tips/account-security-v.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Happy Chinese New Year : Gong Xi Fa Cai</title>
		<link>http://zoiz.web.id/life-matter/happy-chinese-new-year-gong-xi-fa-cai.html</link>
		<comments>http://zoiz.web.id/life-matter/happy-chinese-new-year-gong-xi-fa-cai.html#comments</comments>
		<pubDate>Fri, 23 Jan 2009 06:41:17 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[New Year]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=175</guid>
		<description><![CDATA[Before I go back to home town and before I have problems getting internet connection, I wish you all : Happy Chinese New Year, Gong Xi Fa Cai! HUAT AH!!  
]]></description>
			<content:encoded><![CDATA[<p>Before I go back to home town and before I have problems getting internet connection, I wish you all : Happy Chinese New Year, Gong Xi Fa Cai! HUAT AH!! <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div class="wp-caption alignnone" style="width: 430px"><img title="Gong Xi Fa Cai" src="http://www.kuanhoong.com/wp-content/uploads/2008/02/happy-chinese-new-year.jpg" alt="Happy Chinese New Year" width="420" height="330" /><p class="wp-caption-text">Happy Chinese New Year</p></div>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/life-matter/happy-chinese-new-year-gong-xi-fa-cai.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sunset Policy Diundur / Diperpanjang Hingga 31 Maret 2009</title>
		<link>http://zoiz.web.id/social-life/sunset-policy-diundur-diperpanjang-hingga-31-maret-2009.html</link>
		<comments>http://zoiz.web.id/social-life/sunset-policy-diundur-diperpanjang-hingga-31-maret-2009.html#comments</comments>
		<pubDate>Tue, 30 Dec 2008 16:22:17 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[Social Life]]></category>
		<category><![CDATA[Other]]></category>
		<category><![CDATA[Tax]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=173</guid>
		<description><![CDATA[Dirjen Pajak Darmin Nasution dini hari mengemukakan bahwa batas Sunset Policy diundur / diperpanjang hingga 31 Maret 2009.
Dimana seperti yang telah kita ketahui bahwa Sunset Policy adalah sebuah kebijakan dari pemerintah untuk menghapuskan sanksi pajak. Misalnya seorang wajib pajak yang tidak melaporkan / membayar pajak atas penghasilannya di tahun sebelumnya, jika mereka melaporkan dan membayarkan [...]]]></description>
			<content:encoded><![CDATA[<p>Dirjen Pajak Darmin Nasution dini hari mengemukakan bahwa batas Sunset Policy diundur / diperpanjang hingga 31 Maret 2009.</p>
<p>Dimana seperti yang telah kita ketahui bahwa <strong>Sunset Policy</strong> adalah sebuah kebijakan dari pemerintah untuk menghapuskan sanksi pajak. Misalnya seorang wajib pajak yang tidak melaporkan / membayar pajak atas penghasilannya di tahun sebelumnya, jika mereka melaporkan dan membayarkan kewajiban pajak mereka pada masa sunset policy, mereka tidak akan dikenai sanksi ataupun denda.</p>
<p>Dengan diundurnya / diperpanjangnya batas Sunset Policy, para wajib pajak yang berniat melakukan pembetulan namun tidak sempat, sebuah kesempatan yang bagus untuk melakukannya sekarang juga!</p>
<p>Ingat bahwa saja membayar pajak adalah sebuah kewajiban kita sebagai seorang warga negara! Milikilah NPWP Anda dan laporkan penghasilan Anda sekarang juga!</p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/social-life/sunset-policy-diundur-diperpanjang-hingga-31-maret-2009.html/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>TimeZone / Amazone Hack (Cheat) : Basket Ball Arcade Game</title>
		<link>http://zoiz.web.id/tips/timezone-amazone-hack-cheat-basket-ball-arcade-gtame.html</link>
		<comments>http://zoiz.web.id/tips/timezone-amazone-hack-cheat-basket-ball-arcade-gtame.html#comments</comments>
		<pubDate>Tue, 23 Dec 2008 04:13:27 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[TimeZone]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=165</guid>
		<description><![CDATA[Maybe you like playing in Game Arenas such as Amazone or TimeZone. And I found this vulnerability in those game arenas.
Different from the article before, this vulnerability may only be found in some game centers of TImeZone / Amazone (Not all vulnerable to this).
When Lebaran Holiday came, my mother suggested my grandma to go to [...]]]></description>
			<content:encoded><![CDATA[<p>Maybe you like playing in Game Arenas such as Amazone or TimeZone. And I found this vulnerability in those game arenas.</p>
<p>Different from the <a href="http://zoiz.web.id/life-matter/hacking-hack-timezone-game-machine.html" target="_blank">article</a> before, this vulnerability may only be found in some game centers of TImeZone / Amazone (Not all vulnerable to this).</p>
<p>When Lebaran Holiday came, my mother suggested my grandma to go to Bandung and Puncak then asked all of my relatives to join us. On the 3rd day of our trip, we arrived in Puncak and go to one factory outlet that is called Brasco or Kampoeng Brasco. I only went there with my aunties, uncle and cousins.</p>
<p>My aunties asked us (me and my cousin) to just wait in a game center called Space Zone. &#8220;It will only take a few minutes&#8221;, my aunties said. My uncle joined my aunties to buys T-shirts and other things. So, my cousin and I was there, alone.</p>
<p>Ok, so we go around without doing anything (because we had no coin at that time) and just have a chat together. We keep talking and walking until we found two basketball game machines.</p>
<p>When my cousins keep talking, I thought a brilliant idea (because I was fed up with that place). I asked my youngest cousin to push the ball that is inside the web or wall with his small finger and It works! The ball started to move from its place! Here&#8217;s the pic:<br />
<img src="http://img214.imageshack.us/img214/7453/dsc01059ig4.jpg" alt="how to hack a basketball arcade game" width="200" /><br />
Okay so now it has been out from its place then, my cousin that really likes basketball take the ball and throw it. So, we have nothing to do (again). So, I asked my cousin to do the same thing that he had done before. So, it was my turn! I shoot it and yeah, we&#8217;ve nothing to do (again).</p>
<p>Then, a man with his child played that game. We just looked at them who played it happily <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_lol.gif' alt=':lol:' class='wp-smiley' /><br />
They played that game for 2 times. After they had no coin anymore, without asking or did anything, my cousin pushed the wall that protects or keep the ball inside and they had one more chance to play it for free!</p>
<p>Wow! They just surprised then play together (without any thanks <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> () and when I asked to push the wall again, it didn&#8217;t work anymore. I think it&#8217;s all because he didn&#8217;t push the wall on the right time <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_lol.gif' alt=':lol:' class='wp-smiley' />  .</p>
<p>Those vulnerabilities seem won&#8217;t work in all TimeZone (but it may work in other location of TimeZone). By the way, here&#8217;s the pic of my lovely cousin that helped a lot:<br />
<img src="http://img368.imageshack.us/img368/8439/dsc01058sq7.jpg" alt="hacking basketball game" width="200" /></p>
<p>Thanks!<br />
<a href="http://www.ymm0t.co.cc">ymm0t</a></p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/tips/timezone-amazone-hack-cheat-basket-ball-arcade-gtame.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>KoobFace : Facebook and MySpace Virus / Worm</title>
		<link>http://zoiz.web.id/it-news/koobface-myspace-facebook-worm-virus.html</link>
		<comments>http://zoiz.web.id/it-news/koobface-myspace-facebook-worm-virus.html#comments</comments>
		<pubDate>Tue, 16 Dec 2008 04:14:24 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[IT News]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=163</guid>
		<description><![CDATA[If you received this message on your facebook or myspace inbox : &#8220;You look awesome in this new movie, check it out!&#8221;, don&#8217;t click on anything it provided!! It could be the KoobFace worm / virus. KoobFace come through an e-mail sent by one of your social networking site friends (Facebook or myspace) inviting you [...]]]></description>
			<content:encoded><![CDATA[<p>If you received this message on your facebook or myspace inbox : &#8220;You look awesome in this new movie, check it out!&#8221;, don&#8217;t click on anything it provided!! It could be the KoobFace worm / virus. KoobFace come through an e-mail sent by one of your social networking site friends (Facebook or myspace) inviting you to watch a &#8216;nice&#8217; video.</p>
<p>If you clicked on the URL / link it provided, the web browser will prompt you to download a so called &#8220;<span id="lw_1228499535_4" class="yshortcuts">Adobe Systems Inc&#8217;s Flash Player Update&#8221;. Therein the facebook / myspace virus (worm) lies.</span></p>
<p>Once you installed the fake flash player update, your computer will be infected and become a zombie computer that will attempt to infect all your friends in your facebook / myspace friends list.</p>
<p>Facebook posted a notice regarding how to remove / get rid of the Koobface virus (worm) on their <a href="http://www.facebook.com/security">security page</a>. They suggested that infected PC use an up-to-date virus scanner, and then reset their Facebook password. Some of the free online virus scanners suggested are <a href="http://www.kaspersky.com/virusscanner">Kaspersky</a>, <a href="http://security.symantec.com/">Symantec</a>, <a href="http://us.mcafee.com/root/mfs/scan.asp?affid=56">McAfee</a> and <a href="http://onecare.live.com/site/en-us/default.htm">Microsoft Live OneCare</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/it-news/koobface-myspace-facebook-worm-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking (Hack) TimeZone Game Machine : The Hand of God</title>
		<link>http://zoiz.web.id/life-matter/hacking-hack-timezone-game-machine.html</link>
		<comments>http://zoiz.web.id/life-matter/hacking-hack-timezone-game-machine.html#comments</comments>
		<pubDate>Mon, 15 Dec 2008 16:44:07 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[TimeZone]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=160</guid>
		<description><![CDATA[Yesterday was a long day. I am the kind of people that do not enjoy shopping very much. Dragged (or even pulled  ) by my girlfriend, and we went to Nagoya Hill Mall.
After a couple of hours of walking (See that, couple of HOURS!!! Geez &#62;.&#60; you know why I hate shopping now?  [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday was a long day. I am the kind of people that do not enjoy shopping very much. Dragged (or even pulled <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> ) by my girlfriend, and we went to Nagoya Hill Mall.</p>
<p>After a couple of hours of walking (See that, couple of HOURS!!! Geez &gt;.&lt; you know why I hate shopping now? <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  ), feeling bored and so I went to Time Zone (game arena) to see if there&#8217;s anything interesting there.</p>
<p>I noticed a group of teenager surrounding a game machine. Felt something amiss, so I walked closer to take a <span style="text-decoration: line-through;">peep</span> look. And this it what I saw :</p>
<div class="wp-caption alignnone" style="width: 370px"><a href="http://www.hackers.web.id/image199.jpg"><img title="Fire Fighter TimeZone Game Hacking" src="http://www.hackers.web.id/image199.jpg" alt="Fire Fighter TimeZone Game Hacking" width="360" height="480" /></a><p class="wp-caption-text">Fire Fighter TimeZone Game Hacking</p></div>
<p>Went even closer, and this it what I saw :</p>
<div class="wp-caption alignnone" style="width: 370px"><a href="http://www.hackers.web.id/image198.jpg"><img title="Fire Fighter TimeZone Game Hacking" src="http://www.hackers.web.id/image198.jpg" alt="Fire Fighter TimeZone Game Hacking" width="360" height="480" /></a><p class="wp-caption-text">Fire Fighter Time Zone Game Hacking</p></div>
<p>Look at the hand of the guy wearing white shirt and the score board. The score keeps going up when the guy keep holding the censor device. Any player can get the maximum tickets from that machine using this trick.</p>
<p>This Time-Zone Hacking to get maximum tickets from the game machine easily, was tested and working, and only for dummies! <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Cheers</p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/life-matter/hacking-hack-timezone-game-machine.html/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>The Net of Worms &#8211; ClickJacking Delivered Worm</title>
		<link>http://zoiz.web.id/logical/the-net-of-worms-clickjacking-delivered-worm.html</link>
		<comments>http://zoiz.web.id/logical/the-net-of-worms-clickjacking-delivered-worm.html#comments</comments>
		<pubDate>Tue, 09 Dec 2008 07:31:38 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[CSRF]]></category>
		<category><![CDATA[Logical]]></category>
		<category><![CDATA[click-jacking]]></category>
		<category><![CDATA[ClickJacking]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=155</guid>
		<description><![CDATA[When talking about ClickJacking, people will first think how to use it to Hijack Web Cam or microphone. Let&#8217;s forget about webcam jacking thingies this time. Been thinking of how to use iFrame redressing (ClickJacking) techniques to exploit web application security. Finally my mind lands to a word, which is known as &#8216;Worm&#8217;.
Just like the [...]]]></description>
			<content:encoded><![CDATA[<p>When talking about <a href="http://zoiz.web.id/it-news/clickjacking-or-not-proof-of-concept-video-webcam-clickjacking.html" target="_blank">ClickJacking</a>, people will first think how to use it to Hijack Web Cam or microphone. Let&#8217;s forget about webcam jacking thingies this time. Been thinking of how to use iFrame redressing (<a href="http://zoiz.web.id/it-news/clickjacking-or-not-proof-of-concept-video-webcam-clickjacking.html" target="_blank">ClickJacking</a>) techniques to exploit web application security. Finally my mind lands to a word, which is known as &#8216;Worm&#8217;.</p>
<p>Just like the <a href="http://zoiz.web.id/csrf/click-jacking-on-joomla-powered-site-video-poc.html" target="_blank">Click-Jacking style Joomla CMS hijacking</a>. <a href="http://zoiz.web.id/it-news/clickjacking-or-not-proof-of-concept-video-webcam-clickjacking.html" target="_blank"></a><a href="http://zoiz.web.id/category/csrf" target="_blank">CSRF</a> and Automation are needed to infect blogs, CMS, forums, and etc. Possible? Yes indeed!</p>
<p>Scenario :</p>
<ul>
<li>Victim log in to his/her blog, and does not sign out from it.</li>
<li>Victim visits a malicious site with Click-Jacking, any clicks there will trigger a CSRF attack which will attempt to insert a script into victims blog theme. (Just like Wordpress Theme Editor)</li>
<li>The script will generate an iFrame containing Click-Jacking</li>
<li>Now the victim&#8217;s blog become a zombie that will attempt to infect all his/her blog&#8217;s visitors blog.</li>
</ul>
<p>Isn&#8217;t it lovely? Just a thought . . .</p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/logical/the-net-of-worms-clickjacking-delivered-worm.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Smiling Sky &#8211; A Happy Moon Smiling at You</title>
		<link>http://zoiz.web.id/life-matter/smiling-sky-a-happy-moon-smiling-at-you.html</link>
		<comments>http://zoiz.web.id/life-matter/smiling-sky-a-happy-moon-smiling-at-you.html#comments</comments>
		<pubDate>Tue, 02 Dec 2008 03:24:44 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[Smiling Moon]]></category>
		<category><![CDATA[Smiling Sky]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=125</guid>
		<description><![CDATA[There was a rare fenomena last night in our sky. You could see a smiling sky : A Moon and 2 stars &#8211; Scientist said it&#8217;s Venus and Jupiter, forming a smiling face in the sky. If you missed it, I give you this :
Click The Image to Enlarge
See? Even the sky wants you to [...]]]></description>
			<content:encoded><![CDATA[<p>There was a rare fenomena last night in our sky. You could see a smiling sky : A Moon and 2 stars &#8211; Scientist said it&#8217;s Venus and Jupiter, forming a smiling face in the sky. If you missed it, I give you this :</p>
<div class="wp-caption alignnone" style="width: 530px"><a href="http://dailychat.org/langit-tersenyum.jpg"><img title="Smiling Sky" src="http://dailychat.org/langit-tersenyum.jpg" alt="Smiling Sky" width="520" height="388" /></a><p class="wp-caption-text">The Moon Smiles at you</p></div>
<p>Click The Image to Enlarge</p>
<p>See? Even the sky wants you to smile. Cheers <img src='http://zoiz.web.id/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/life-matter/smiling-sky-a-happy-moon-smiling-at-you.html/feed</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>Click-jacking on Joomla Powered Site Video PoC</title>
		<link>http://zoiz.web.id/csrf/click-jacking-on-joomla-powered-site-video-poc.html</link>
		<comments>http://zoiz.web.id/csrf/click-jacking-on-joomla-powered-site-video-poc.html#comments</comments>
		<pubDate>Fri, 28 Nov 2008 06:39:26 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[CSRF]]></category>
		<category><![CDATA[click-jacking]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=121</guid>
		<description><![CDATA[Here is the Click-jacking Proof Of Concept video made by me. On the video, I show you how to pawn or hack a joomla powered site using click-jacking.
How it works :
- First a victim logged into his Joomla Powered site Administration Control Panel
- He didn&#8217;t logged out from the service
- He visited a malicious site
- [...]]]></description>
			<content:encoded><![CDATA[<p>Here is the Click-jacking Proof Of Concept video made by me. On the video, I show you how to pawn or hack a joomla powered site using click-jacking.</p>
<p>How it works :</p>
<p>- First a victim logged into his Joomla Powered site Administration Control Panel</p>
<p>- He didn&#8217;t logged out from the service</p>
<p>- He visited a malicious site</p>
<p>- He clicked on something (anything on the page)</p>
<p>- By the time he clicked, his Joomla Powered site password has been changed without his notice</p>
<p><span id="more-121"></span></p>
<p>Combining <a href="http://zoiz.web.id/it-news/clickjacking-or-not-proof-of-concept-video-webcam-clickjacking.html" target="_blank">Click-jacking</a> &amp; <a href="http://zoiz.web.id/category/csrf" target="_blank">CSRF</a>, the clicked trigger a password change request to the Joomla site using the victim privilege. Thus the attack was success, the victim&#8217;s site admin password changed.</p>
<p>Here is the link : <a href="http://www.hackers.web.id/clickjacking-joomla.rar">http://www.hackers.web.id/clickjacking-joomla.rar</a></p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/csrf/click-jacking-on-joomla-powered-site-video-poc.html/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>
