<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Website Design &#124; Penetration Testing &#124; Crystallized Knowledge</title>
	<atom:link href="http://crystalatatrium.com/feed" rel="self" type="application/rss+xml" />
	<link>http://crystalatatrium.com</link>
	<description></description>
	<lastBuildDate>Thu, 16 Feb 2012 23:49:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Website Design 101</title>
		<link>http://crystalatatrium.com/seo/website-design-101.aspx</link>
		<comments>http://crystalatatrium.com/seo/website-design-101.aspx#comments</comments>
		<pubDate>Wed, 28 Dec 2011 14:20:09 +0000</pubDate>
		<dc:creator>Draco</dc:creator>
				<category><![CDATA[SEO]]></category>
		<category><![CDATA[Website Design]]></category>

		<guid isPermaLink="false">http://crystalatatrium.com/?p=977</guid>
		<description><![CDATA[Today we are going to talk about website design.  We see many bad practices just traveling around the web.  We are always looking for new prospects and when we come across websites with bad design or security errors, we try to let them know.  Although, 90% of the time they do not listen. The most [...]]]></description>
			<content:encoded><![CDATA[<p>Today we are going to talk about website design.  We see many bad practices just traveling around the web.  We are always looking for new prospects and when we come across websites with bad design or security errors, we try to let them know.  Although, 90% of the time they do not listen.<span id="more-977"></span></p>
<p>The most demotivating thing about this job is that most small businesses haven&#8217;t caught up to technology.  Most small businesses believe that having a website means they are online and have an online presence.  Usually, this is not the case, in fact it is the opposite as it gives you the sense of feeling safe when your not.</p>
<p>&nbsp;</p>
<h2>SEO</h2>
<p>SEO the main reason small business websites fail is not because of their design, sometimes they look beautiful.  Having good SEO practices really makes a website shine to people.  It can make a badly designed website have a thousand hits a day and a good design website have less than ten.</p>
<p>&nbsp;</p>
<h2>DESIGN</h2>
<p>SEO can make a bad website have 1,000 hits a day.  Good design will make them want to stay.  This is where graphic designers and the business itself shines in terms of showing off creativity or professionalism.</p>
<p>&nbsp;</p>
<h2>USABILITY</h2>
<p>Usability is not necessarily what makes people stay.  Instead, bad usability will make them leave and good usability means they should never have to think about it.  When you find a link on a website you should never think that it was easy to find, if you did you were probably at some badly designed websites prior.  This is where programmers and designers shine together.</p>
<p>&nbsp;</p>
<h2>Most important!</h2>
<p>The most important thing is to have Good SEO, Good Design, Good Usability and you will have a great website.  Anyone can make a website.  Not everyone can make a good website to hit all 3 points.   Oh, and don&#8217;t forget security, but that is another post.</p>
<p>&nbsp;</p>
<p>So in conclusion having a website doesn&#8217;t mean you have an online presence.  Sometimes if the website is bad it actually pushes clients away.</p>
<p>Think your website is good and want to show us? Call us for your FREE Consultation and let us tell you anything that is wrong.</p>
<p>239-465-3874</p>
]]></content:encoded>
			<wfw:commentRss>http://crystalatatrium.com/seo/website-design-101.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>We Didn&#8217;t Test Sony&#8217;s Security.</title>
		<link>http://crystalatatrium.com/hacking/we-didnt-test-sonys-security.aspx</link>
		<comments>http://crystalatatrium.com/hacking/we-didnt-test-sonys-security.aspx#comments</comments>
		<pubDate>Thu, 30 Jun 2011 19:44:41 +0000</pubDate>
		<dc:creator>Draco</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Website Design]]></category>
		<category><![CDATA[black hats]]></category>
		<category><![CDATA[computer engineering]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[Cracking]]></category>
		<category><![CDATA[deception]]></category>
		<category><![CDATA[remote hacking]]></category>
		<category><![CDATA[web hacking]]></category>
		<category><![CDATA[website security]]></category>

		<guid isPermaLink="false">http://crystalatatrium.com/?p=669</guid>
		<description><![CDATA[OK so we didn't test Sony's security.  If you don't want something like this to happen to your business get your security pentested.  Everyday a business goes down.  This time though it being Sony,  many people are starting to take security a little more seriously....Finally.]]></description>
			<content:encoded><![CDATA[<h2 style="text-align: center; ">Disappointment in Sony.</h2>
<p>OK so we didn&#39;t test Sony&#39;s security. &nbsp;If you don&#39;t want something like this to happen to your business get your security pentested. &nbsp;Everyday a business goes down. &nbsp;This time though it being Sony, &nbsp;many people are starting to take security a little more seriously&#8230;.Finally.</p>
<p><span id="more-669"></span></p>
<h2 style="text-align: center; ">Ok I will Admit..</h2>
<p>OK so I agree Sony was probably pretty arrogant and not checking there security most likely thinking..&quot;Really? &nbsp;I am Sony. I no be hackz.&quot; &nbsp;Which is apparently untrue. &nbsp;I mean they have been hacked 20 times already&#8230;I also read I am not sure if it&#39;s true but they fired some network security people before the breach&#8230;seems like a bad decision to do that&#8230;.also I will put on the list could of been partly inside job, but hey I don&#39;t know maybe they got fired for not securing it very well /wink. &nbsp;(Check out the list of hacks and details <a href="http://attrition.org/security/rants/sony_aka_sownage.html">Here</a>)</p>
<p>&nbsp;</p>
<h2 style="text-align: center; ">Either Way Hacktivist.</h2>
<p>I enjoy hacktivism and hacktivist. &nbsp;I enjoy reading about it. &nbsp;I enjoy it more than the 1000&#39;s of sites I see hacked for no reason other than sport. &nbsp;I also am excited to read these. &nbsp;Just as if I was watching historical events taking place before my eyes. &nbsp;Of course I love Sony products&#8230;..OK I will take that back I really only like there gaming systems and games. &nbsp; Either way I think this will increase the security overall of the computer world in the end.&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://crystalatatrium.com/hacking/we-didnt-test-sonys-security.aspx/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Penetration Testing: The Hacker&#8217;s Mind</title>
		<link>http://crystalatatrium.com/hacking/penetration-testing-the-hackers-mind.aspx</link>
		<comments>http://crystalatatrium.com/hacking/penetration-testing-the-hackers-mind.aspx#comments</comments>
		<pubDate>Wed, 09 Mar 2011 14:57:27 +0000</pubDate>
		<dc:creator>Draco</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[computer engineering]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[deception]]></category>
		<category><![CDATA[information gathering]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[pentesting]]></category>
		<category><![CDATA[social engineering]]></category>

		<guid isPermaLink="false">http://crystalatatrium.com/?p=472</guid>
		<description><![CDATA[Welcome back. &#160;If you have been following along you should know everything there is too know about your client now. &#160;If you haven&#39;t then you should go back and read The Hackers Eyes pt1 and The Hackers Eyes pt2. I Am Drowning in Information! Now What Do I do? Now that you have plenty of [...]]]></description>
			<content:encoded><![CDATA[<h1 style="text-align: center; "><span class="Apple-style-span" style="font-size: 12px; font-weight: normal; ">Welcome back. &nbsp;If you have been following along you should know everything there is too know about your client now. &nbsp;If you haven&#39;t then you should go back and read The Hackers Eyes pt1 and The Hackers Eyes pt2.</span></h1>
<p><span id="more-472"></span></p>
<h1 style="text-align: center; ">I Am Drowning in Information!</h1>
<h2 style="text-align: center; ">Now What Do I do?</h2>
<p>Now that you have plenty of information you would think that the information gathering step is done&#8230;.WRONG information gathering is the whole process of social engineering. &nbsp;You use social engineering to gather more information depending on your goal. &nbsp;Some of the things I do with information is split it up between someones personal information and secure information. &nbsp;For instance pet name and username/passwords. &nbsp;Remember we are a company and we do not go any further than this as information gathering. &nbsp;If I have usernames/passwords I have finished my job with that company and have more than enough information to explain some of there issues to them. &nbsp;Some things you may do if you do not have any secure information and all personal is use it. &nbsp;Using personal information to gather secure information is usually not a hard process.</p>
<p>&nbsp;</p>
<h1 style="text-align: center; ">Personal Information&#8230;I Don&#39;t Care About Spouse Names!</h1>
<h2 style="text-align: center; ">WAIT! Don&#39;t Throw Those Out Yet.</h2>
<p>&nbsp;</p>
<p>Some ways to use personal information:</p>
<p><strong>Infiltration</strong>: Using it to gain further access into the building by social engineering.&nbsp;</p>
<p><strong>Developing Trust</strong>: Using knowledge about other employees to show that you &quot;really&quot; are friends. &nbsp;Before this confuses you let me give you an example:</p>
<p><span style="color:#008000;"><strong>CORRECT</strong> : &nbsp;&quot;Hey, Sally how is Matt&#39;s wife Jasmin doing?&quot;</span></p>
<p><span style="color:#f00;"><strong>WRONG</strong>: &quot;I am really friends with you guys Sally, Matt&#39;s wife is named Jasmin.&quot;</span></p>
<p><strong>Gaining Secure Information</strong>: &nbsp;Some social engineering and you got some passwords and such. For instance after developing trust then go about telling them you need to fix there computer.</p>
<p>&nbsp;</p>
<h1 style="text-align: center; ">OoOoOo Passwords</h1>
<h2 style="text-align: center; ">Keep Reading.</h2>
<p>Some ways to use Secure information:</p>
<p><strong>Give Information</strong>: &nbsp;Give the information you gathered to the person that would be interested in securing it.</p>
<p>Sorry guys. &nbsp;My company stays on the White hat side of things. &nbsp;So we do not use the Secure Information. &nbsp;We would then give it to the person who hired us within the company. &nbsp;(Usually the manager or CEO of the company) &nbsp;So that they could secure the information better.</p>
]]></content:encoded>
			<wfw:commentRss>http://crystalatatrium.com/hacking/penetration-testing-the-hackers-mind.aspx/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Wifi Man-in-the-Middle Attack</title>
		<link>http://crystalatatrium.com/hacking/wifi-man-in-the-middle-attack.aspx</link>
		<comments>http://crystalatatrium.com/hacking/wifi-man-in-the-middle-attack.aspx#comments</comments>
		<pubDate>Mon, 07 Feb 2011 14:49:18 +0000</pubDate>
		<dc:creator>Draco</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[deception]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[information gathering]]></category>
		<category><![CDATA[learning]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[pentesting]]></category>
		<category><![CDATA[remote hacking]]></category>
		<category><![CDATA[security network]]></category>
		<category><![CDATA[social engineering]]></category>

		<guid isPermaLink="false">http://crystalatatrium.com/?p=583</guid>
		<description><![CDATA[While I was contracted out for another company NBC-2 wanted us to do a segment on wifi security or insecurity to be exact.&#160; Here is the end result.&#160; [video src=http://crystalatatrium.com/wp-content/uploads/wifi.mp4] Here is the link to the NBC page. Wifi Warning &#8211; NBC-2.com]]></description>
			<content:encoded><![CDATA[<p>While I was contracted out for another company NBC-2 wanted us to do a segment on wifi security or insecurity to be exact.&nbsp; Here is the end result.&nbsp;</p>
<p><span id="more-583"></span></p>
<p>[video src=http://crystalatatrium.com/wp-content/uploads/wifi.mp4]</p>
<p>
	Here is the link to the NBC page.</p>
<p><a href="http://www.nbc-2.com/Global/story.asp?S=13964485" target="_blank">Wifi Warning &#8211; NBC-2.com<br />
	</a></p>
]]></content:encoded>
			<wfw:commentRss>http://crystalatatrium.com/hacking/wifi-man-in-the-middle-attack.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://crystalatatrium.com/wp-content/uploads/wifi.mp4" length="15287767" type="video/mp4" />
		</item>
		<item>
		<title>Viruses What and Why?</title>
		<link>http://crystalatatrium.com/basic-computer-information/viruses-what-and-why.aspx</link>
		<comments>http://crystalatatrium.com/basic-computer-information/viruses-what-and-why.aspx#comments</comments>
		<pubDate>Fri, 04 Feb 2011 15:37:11 +0000</pubDate>
		<dc:creator>Draco</dc:creator>
				<category><![CDATA[Basic Computer Information]]></category>
		<category><![CDATA[Website Design]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[learning]]></category>
		<category><![CDATA[stealing]]></category>
		<category><![CDATA[web attacks]]></category>
		<category><![CDATA[website security]]></category>

		<guid isPermaLink="false">http://crystalatatrium.com/?p=448</guid>
		<description><![CDATA[You may ask yourself.  Why are viruses made? Why are viruses created? What kind of people make viruses? Well I will explain in this short post. Viruses Is there a cure? Short answer&#8230;No Why are viruses made you ask?  Well mainly 3 reasons. 1. Because someone whether it be a kid or adult was seeking revenge [...]]]></description>
			<content:encoded><![CDATA[<p>You may ask yourself.  Why are viruses made? Why are viruses created? What kind of people make viruses? Well I will explain in this short post.<span id="more-448"></span></p>
<h1 style="text-align: center;">Viruses Is there a cure?</h1>
<h2 style="text-align: center;">Short answer&#8230;No</h2>
<p>Why are viruses made you ask?  Well mainly 3 reasons.</p>
<p>1. Because someone whether it be a kid or adult was seeking revenge or just bored.</p>
<p>2. Making a name for themself&#8230;.this doesn&#8217;t happen as much anymore just because viruses are easy to make and your no better than your peers if you do it.</p>
<p>3. Money. Infecting many people is profitable.</p>
<p>Lets think of an example.  Say you get a virus and it says  &#8220;OH NO your infected we found 1,000,000,000 viruses.  These viruses are taking your identity/credit card information. If you buy this anti-virus we can clean it.&#8221; It looks like an antivirus. Any time you try to do anything on your computer it is running slow.  Many things won&#8217;t open. This &#8220;Anti-Virus&#8221; keeps saying it found stuff.</p>
<p>&nbsp;</p>
<p>So you think your computer will be faster and clean after you pay&#8230;.so you do.  CHA-CHING.  They made money and they have your credit card info&#8230;.also 95% of the time. They do not even remove the fake Anti-Virus so it still is slowing down your computer and causing issues you don&#8217;t even see. This is just one of the many ways viruses can be lucrative. Since viruses make money.  We will never rid ourselves of them. If you infect 100 people 1 or 2 will fall for it.  So what if you infect 100,000? Exactly.</p>
<h1 style="text-align: center;">What Do I Have?</h1>
<h2 style="text-align: center;">Did you use protection?</h2>
<p>In the subject of viruses there are many different types.  Lets go over the basic tree since everything can be branched off from there.  I will give basic explanations.</p>
<p>Virus- Infects one computer and can only spread to another with the help of a human. They use tricks to get you to help them spread.(Like plugging your thumbdrive into multiple computers.)</p>
<p>Worms- They spread with very little human interaction.  Of course they would spread through thumbdrives also but, through the network and through the internet.  This is what there made for. To spread and replicate.</p>
<p>Trojans- Trojans are more like a virus in the sense they usually only infect 1 or 2 machines and are not made to spread without humans.  These try to coin themselves off as something else&#8230;like that game you downloaded yesterday.</p>
<div>These are by far not all the types.  However, most likely they fall into 1 of these categories.  This is more of the basic 3.</div>
<div></div>
<div></div>
<h1 style="text-align: center;">Viruses don&#8217;t break your computer.  People do.</h1>
<h2 style="text-align: center;">So don&#8217;t hate them</h2>
<p>Viruses also help give people jobs such as research and development of anti-virus software&#8230;Real ones. Also though when people buy those SEO services where they bring traffic to your website or when you buy many other SEO services usually they are made from BOTNETS basically a botnet is just a term for many computers who have been infected and can now be controlled with the virus.  Your computer may be part of a spamming botnet and you may never know.  You may just think your computer runs slow.</p>
<h2 style="text-align: center;">OMG I AM INFECTED!! I Guess Ill Burn It</h2>
<h3 style="text-align: center;">Wait!.  Usually you just need an Anti-virus or Anti-Malware</h3>
<p>The following is by no way the best.  In fact there is no such thing as the best.  NOT ONE anti-virus can catch all the viruses.  However, these are my favorite and personal experience best results.  Some of these need some kind of computer knowledge.  Like with HijackThis don&#8217;t just go checking everything and removing it or you will break your computer.</p>
<p>&nbsp;</p>
<p><a href="http://free.antivirus.com/hijackthis/">Hijackthis</a><br />
<a href="http://www.malwarebytes.org/">Malwarebytes</a></p>
<p><a href="http://support.kaspersky.com/faq/?qid=208283363">Kaspersky TDSSKiller</a></p>
<p><a href="http://usa.kaspersky.com/">Kaspersky Anti Virus</a> Or <a href="http://www.avast.com/index">Avast!</a> but not both&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://crystalatatrium.com/basic-computer-information/viruses-what-and-why.aspx/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Penetration Testing: The Hackers Eyes pt 2</title>
		<link>http://crystalatatrium.com/hacking/hacking-the-hackers-eyes-pt-2.aspx</link>
		<comments>http://crystalatatrium.com/hacking/hacking-the-hackers-eyes-pt-2.aspx#comments</comments>
		<pubDate>Mon, 03 Jan 2011 19:06:44 +0000</pubDate>
		<dc:creator>Draco</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Website Design]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[content management system]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[learning]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[penetration]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[SMTP]]></category>
		<category><![CDATA[tutorial]]></category>
		<category><![CDATA[web based information]]></category>
		<category><![CDATA[website security]]></category>

		<guid isPermaLink="false">http://crystalatatrium.com/?p=335</guid>
		<description><![CDATA[Welcome back.  Now if you have not read part one of this series please go read that one first or you may be lost. Here is a link to help you on your way Part 1. So the place that I left off was web based information gathering.  Now that you know some about the [...]]]></description>
			<content:encoded><![CDATA[<p>Welcome back.  Now if you have not read part one of this series please go read that one first or you may be lost. Here is a link to help you on your way <a href="http://crystalatatrium.com/hacking/hacking-the-hackers-eyes.php">Part 1</a>. So the place that I left off was web based information gathering.  Now that you know some about the company let us turn to a more tech related topic.  Lets find out everything about there site. We have done some of this in <a href="http://crystalatatrium.com/hacking/hacking-the-hackers-eyes.php">Part 1</a>, but now we are going deeper. <span id="more-335"></span></p>
<h1 style="text-align: center;">What else is there to know?</h1>
<h2>CMS</h2>
<p>Before I got into that let me explain a few things.  CMS stands for Content Management System.  They are easily deployed and set up.  They provide a way for quick effecient deployments of websites and pretty secure.(By themselves. That is without plugins) Without plugins however they are quickly inefficient.</p>
<p>Well lets see.  You may already know if there on a CMS by certain aspects that stand out. Also some things that are not changed when someone makes a site with a CMS so the default is still sitting there.  Such as if you go to a site and look in the source and see something in the meta &#8220;Just Another WordPress site&#8221; guess what CMS there using?  There are many default configurations to look for and you will learn as you go.  No need to study them or anything.  If there on a CMS find out what plugins there using.  This may take some practice on what to look for but for instance look on the sidebar look for photo galleries.  These things do not usually come with the CMS, but are plugins to give it more functionality.  Ok so that was a quick CMS side.</p>
<h2 style="text-align: center;">I Can&#8217;t Find out the CMS</h2>
<h3 style="text-align: center;">Either you have not learned enough or they are not using one</h3>
<p>So what about the many people that are not on a CMS.  Well getting details is harder however penetration is easier&#8230;..usually. It really depends on your target.  If a huge corporation hired you to do this they probably have website techs who keep up the security.  Although if it is a smaller company usually the security is not up-to-date for websites.  Remember&#8221; there are exceptions to every rule&#8221;&#8230;except for the rule that &#8220;there are exceptions to every rule&#8221;.(I don&#8217;t want to cause a paradox).  Back on topic these websites you will look for extensions, directories, anything you can read.  Javascript is easily opened.  PHP and SQL are usually easily spotted. ASP is used much more often than I anticipated in the past but offers no more security than PHP or SQL and in my experience the websites usually have less security than ASP could give.  Look in the source find different file names.  Such as where a form is posting.  This will usually give some kind of inclination of what the website is built with.</p>
<h2 style="text-align: center;">Lets do some testing</h2>
<h3 style="text-align: center;">Use a proxy and remember have permission</h3>
<p>So first use a proxy because if you get caught while testing it doesn&#8217;t look good. Lets check some ports.  Try to test the different ports for a website. Best ones to test are commonly opened ports.  Try FTP and SMTP.  Try the secured ports.  Try going to the site through 8080.  I have seen a website have the capability for 8080 but not be setup properly.  This was good later when I convinced the IT guy that I was there to help him secure it.  Remember this is an information gathering phase&#8230;no bruteforcing and such.</p>
<h2>Watch for the next part of this long tutorial</h2>
]]></content:encoded>
			<wfw:commentRss>http://crystalatatrium.com/hacking/hacking-the-hackers-eyes-pt-2.aspx/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Penetration Testing: The Hackers Eyes</title>
		<link>http://crystalatatrium.com/hacking/hacking-the-hackers-eyes.aspx</link>
		<comments>http://crystalatatrium.com/hacking/hacking-the-hackers-eyes.aspx#comments</comments>
		<pubDate>Fri, 10 Dec 2010 04:27:07 +0000</pubDate>
		<dc:creator>Draco</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Website Design]]></category>
		<category><![CDATA[basic html]]></category>
		<category><![CDATA[basic knowledge]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[gathering information]]></category>
		<category><![CDATA[html knowledge]]></category>
		<category><![CDATA[human stupidity]]></category>
		<category><![CDATA[information gathering]]></category>
		<category><![CDATA[learning]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[pentesting]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[stealing]]></category>
		<category><![CDATA[weakest link]]></category>

		<guid isPermaLink="false">http://crystalatatrium.com/?p=317</guid>
		<description><![CDATA[So what? we all have eyes. Yea I guess thats true.  Maybe I should of called it the mind.  Anyway it will make more sense as I explain it. This will be a multi-part blog. If this is your first post your reading I would recommend reading my Hacker Roadmap.  If you think your ready [...]]]></description>
			<content:encoded><![CDATA[<h1 style="text-align: center;">So what? we all have eyes.</h1>
<p style="text-align: left;">Yea I guess thats true.  Maybe I should of called it the mind.  Anyway it will make more sense as I explain it. This will be a multi-part blog. If this is your first post your reading I would recommend reading my <a href="http://crystalatatrium.com/hacking/just-another-how-to-hack-tutorial.php">Hacker Roadmap</a>.  If you think your ready or your just too lazy to read the other one then continue on. Before you read on please read the <a href="http://crystalatatrium.com/disclaimer.php">disclaimer</a>. <span id="more-317"></span></p>
<p style="text-align: left;"><strong>What you may need to understand this:</strong></p>
<p style="text-align: left;"><strong>Basic knowledge of how a website is built.</strong></p>
<p style="text-align: left;"><strong>How to view source-code of a webpage.</strong></p>
<p style="text-align: left;"><strong>Some basic HTML knowledge.</strong></p>
<p style="text-align: left;"> </p>
<p style="text-align: left;">So this guy Doug Hotz asked me how I would go about hardening a network. Well Doug the most effective way is not the fastest.  It will take much time.  Best way to do it is to find the area that is the weakest. You will have to think like someone who wants to break into it, not someone who wants to protect it. Most of the time the weakest link of a network are the people who run it.  Remember there is no patch for human stupidity.  Now I can&#8217;t stress this enough.  If you haven&#8217;t practiced this and/or your just getting into the trade do not think for a second that since you couldn&#8217;t trick some guy into giving you his password that it can&#8217;t be done.</p>
<p style="text-align: left;"> </p>
<h1 style="text-align: center;">Information Gathering</h1>
<h2 style="text-align: center;">So should I bring a bucket?</h2>
<p>Information gathering is probably one of the most important steps when doing penetration testing. The more information you have, the more you can get.  The more information you get, the easier it is to get in. i.e. passwords anyone?.  The information gathering step never stops even when you have moved on from this step you will still be gathering information just not so aggressively. Best way to get information is physically. Yes that means getting out of the house and off the computer.</p>
<h1 style="text-align: center;">Where should I start?</h1>
<h2 style="text-align: center;">Right there in front of your Internet capable device.</h2>
<p>I know I said the best way is to be there in person. However you can just walk in a place and expect them to trust you.  Actually you do, but you need some stuff first.  Find out who your target is.  Is it a person or a company or a company personnel. Do a google search, facebook search, domain name search, find out who owns the domain, find out the bosses names, the names of anyone important and there spouses or pets. Use all this information.  </p>
<p>Also a really good way is if it is a company set up an appointment with someone in the building just so you can walk around.  If possible get lost. Take pictures. Take video. Try and find there network room. Look at much of the network. </p>
<p>Need more information? Dumpster diving for trashbags of paper is an old school, but still in some cases effective.  Mainly on smaller companies. Next lets go with people.  People are really handy since the brain can store more information than anything we have.</p>
<p>Now lets go over each one of these individually. </p>
<h1 style="text-align: center;">Searching&#8230;Searching&#8230;</h1>
<h2 style="text-align: center;">404 error rhetorical question not found.</h2>
<p>So the web to search.  I can&#8217;t help much here since it is self explainitory.  I will just go over some sites you can use and what to look for. Start at the website if they have one available.  What do you see? Nice pictures? Pretty colors? What else? </p>
<p>Lets talk about pictures.  Well if you look at each one they have to be stored somewhere right? Now you have a directory or two that you know of.  Does the directory say anything specific? For instance if you saw templates/rt_chromatophore/images/someimage.gif what would that say.  It should say &#8220;rt_chromatophore?&#8221; thats unique. Now you found something that may give you some info.  Lets google &#8220;rt_chromatophore&#8221;.  Before I even finish typing it the helpful google already gave me the answer.  I now know its a joomla site.  The images is not the only thing that would give you information.  What about the directory of the stylesheets, javascript files.</p>
<h1 style="text-align: center;">What else can I look for?</h1>
<h2 style="text-align: center;">Everything and anything means something&#8230;.but here is a couple of tips</h2>
<p>When you see a form such as enter your username and password or even just a contact form. What is the submit button doing? Is it a post? Where is the post going? what page is the form is posting too.  Look if there are any hidden form elements.  Look in the source code are there any comments in the code that will give you any information or meta tags people forget to change often provide you with very good info.  These are all things the attacker will use when profiling the target. What if you find an email address.  Doesn&#8217;t seem like a big deal right? Well is the email going to the same domain as the site. Then you may have just found yourself a username.</p>
<p>Did you find these things when you first looked? </p>
<p>Even after all those little tips we have barely hit the tip of the metaphorical iceberg. So try and find a site that your interested in.  It is not illegal to read source code.  Although it is to try and break into a site without permission so I do not condone that.</p>
<h2>Now Part 2 will also be on information gathering.  I will finish up the web aspect of it and move on to the physical side of gathering information.</h2>
]]></content:encoded>
			<wfw:commentRss>http://crystalatatrium.com/hacking/hacking-the-hackers-eyes.aspx/feed</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>SQL injection Break down</title>
		<link>http://crystalatatrium.com/hacking/sql-injection-break-down.aspx</link>
		<comments>http://crystalatatrium.com/hacking/sql-injection-break-down.aspx#comments</comments>
		<pubDate>Wed, 17 Nov 2010 18:32:13 +0000</pubDate>
		<dc:creator>Draco</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Website Design]]></category>
		<category><![CDATA[basic programming]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[learning]]></category>
		<category><![CDATA[new computer]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[pentesting]]></category>
		<category><![CDATA[programming side]]></category>
		<category><![CDATA[remote hacking]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[web attacks]]></category>
		<category><![CDATA[web hacking]]></category>

		<guid isPermaLink="false">http://crystalatatrium.com/?p=188</guid>
		<description><![CDATA[Inject 2cc of SQL and call me in the morning I know there are many sql injection tutorials.  However I will write this one mostly for the people who do not have much knowledge of SQL or programming.  This tutorial is for people that want to know how it works not how they can use [...]]]></description>
			<content:encoded><![CDATA[<h1 style="text-align: center;"><strong>Inject 2cc of SQL and call me in the morning<br />
</strong></h1>
<p>I know there are many sql injection tutorials.  However I will write this one mostly for the people who do not have much knowledge of SQL or programming. <span id="more-188"></span> This tutorial is for people that want to know how it works not how they can use it. However if you do know basic programming in php and sql then you will also learn the latter.</p>
<h1 style="text-align: center;">Quirky text in bold&#8217; OR 1=1</h1>
<p>Ok so best way to put this in an example is with the english language.  The ending of a sentence is a period (lets keep it simple and forget ! and ?). When someone reads a period the next word begins a new sentence.  In programming it is the same. If someone gave me a document that had some sentences such as <strong>I like computers.  Computers are awesome. I am getting a new computer. </strong>Well an example of injection is if I took that sentence and injected my own statement. So it would read something like <strong>I like computers.  Computers are awesome. I hate you. I am getting a new computer. </strong>Now this document is way different.  Next I will make this example a little closer to injection actually used in programs&#8230;.but this is the gist of it.</p>
<p>So now lets move this to a more programming side.  Lets use a variable called <strong>$USERINPUT. </strong>This variable will be replaced with whatever text you put into the prompt (use your imagination). Now our new sentence will look like this. <strong>I like computers.  Computers are awesome. I am getting a new </strong><strong>$USERINPUT. </strong>Lets say for the sake of argument when it asks you to type in a word you type <strong>Television</strong>. So when it outputs the sentence it will come to you as <strong>I like computers.  Computers are awesome. I am getting a new</strong><strong> Television. </strong>Hmmm.. So if you think about that it means that anything you type when it asks for <strong>$USERINPUT</strong> will go in that spot, however lets say for the sake of argument again that it will not accept broken or sentences that do not end with a period.  So the next time it asks for <strong>$USERINPUT</strong> I type in this <strong>&#8220;Television. I need $2,000,000 dollars sent to 555 street ave fort myers fl&#8221;</strong> notice I added the period after Television but not after <strong>fort myers fl</strong>.  This is because there is already a period in the sentence lets input it. <strong>I like computers.  Computers are awesome. I am getting a new</strong><strong> </strong><strong>Television. I need $2,000,000 dollars sent to 555 street ave fort myers fl. </strong>That will in theory get you $2,000,000&#8230;.ok not really but that is the idea.</p>
<h1 style="text-align: center;">Time For Some SQL</h1>
<h2 style="text-align: center;">SQL?&#8230;Sea Quarks&#8230;Lies</h2>
<p>So if you got this</p>
<form action="http://crystalatatrium.com" method="post">
<h2 id="header_1" class="form-header">Fake login</h2>
<p><label>Username </label></p>
<div>
<input name="username" size="20" type="text" /></div>
<p><label>password </label></p>
<div>
<input name="password" size="20" type="text" /></div>
<p><button class="form-submit-button">Submit Form </button></p>
</form>
<p>This should be a fairly common thing you see.  Username and password and a submit button and such. This form lets you enter information, usually especially nowadays this is pretty secure, but in this example we are going to assume it is not secure and it does not validate your input. Here is the assumed code in the backend</p>
<pre class="php">$username=$_POST['username'];
$password=$_POST['password'];
$result="SELECT * FROM `users` WHERE username='".$username."' AND password='".$password."'";
$result2=mysql_query($result) or die("Wrong username and password");
$result3=mysql_fetch_array($result2);
</pre>
<p>As you can see the username is used straight from whatever is posted in the above form where you would enter your username and password. That is a security flaw.  Now let me say again this is old and probably secure on 99.9% of all websites and it is just an example. So lets look.  What is the last clause that is looks at?  password. that is the last part of the WHERE statement.  So if I type in the username John and the password Doe.  When the code is running it will look like this.</p>
<pre class="php">$username=$_POST['username'];
$password=$_POST['password'];
$result="SELECT * FROM `users` WHERE username='John' AND password='Doe'";
$result2=mysql_query($result) or die("Wrong username and password");
$result3=mysql_fetch_array($result2);
</pre>
<p>Do you see how the whole PHP variable &#8220;.$password.&#8221; was replaced with the info provided?<br />
So what if we were to add our own code into it&#8230;.hmmm what if I typed some thing like the username <strong>John</strong> and for the password something like<strong> blah&#8217; &#8217;1&#8242;=&#8217;1 </strong>well I wonder what that would do&#8230;.lets insert it into the code. (also notice I didn&#8217;t add a <strong>&#8216;</strong> at the end of the code <strong>blah&#8217; &#8217;1&#8242;=&#8217;1 </strong>remember the code already ends it with one so we are going to let it do that for us.</p>
<pre class="php">$username=$_POST['username'];
$password=$_POST['password'];
$result="SELECT * FROM `users` WHERE username='John' AND password='blah OR '1'='1'";
$result2=mysql_query($result) or die("Wrong username and password");
$result3=mysql_fetch_array($result2);
</pre>
<p>As you can see it is going to check the username Oh it found it John is the username.  Then it moves on to the password.  Is the password blah? no but its an OR statement so the password has to be blah or 1 has to equal 1 and it does.  So it says the password is not blah but 1 does equal 1 so you have access. Then it will drop you into the logged in portion of the site.  That is the basics to injection and SQL injection.  Have any questions? feel free to <a href="http://crystalatatrium.com/contact-us.php">email me</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://crystalatatrium.com/hacking/sql-injection-break-down.aspx/feed</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>All your “bases” are belong to us</title>
		<link>http://crystalatatrium.com/basic-computer-information/all-your-%e2%80%9cbases%e2%80%9d-are-belong-to-us.aspx</link>
		<comments>http://crystalatatrium.com/basic-computer-information/all-your-%e2%80%9cbases%e2%80%9d-are-belong-to-us.aspx#comments</comments>
		<pubDate>Sat, 13 Nov 2010 19:51:53 +0000</pubDate>
		<dc:creator>Draco</dc:creator>
				<category><![CDATA[Basic Computer Information]]></category>
		<category><![CDATA[binary]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[digits]]></category>
		<category><![CDATA[hex]]></category>
		<category><![CDATA[hexadecimal]]></category>
		<category><![CDATA[learning]]></category>
		<category><![CDATA[learning computers]]></category>
		<category><![CDATA[Math]]></category>
		<category><![CDATA[mathematical explanation]]></category>

		<guid isPermaLink="false">http://crystalatatrium.com/?p=226</guid>
		<description><![CDATA[Sorry for my long absence, but I am back with the great informational post on Bases i.e. Base-10 and so on. I will explain Bases and positional systems. More of a mathematical explanation but should be learned when learning computers.]]></description>
			<content:encoded><![CDATA[<h1 style="text-align: center;">Bases?</h1>
<h2 style="text-align: center;">You mean where I keep my flag?</h2>
<p>So I spoke to a man today who was pretty well versed in computers.&nbsp; We got on the subject of hexadecimals and binary.&nbsp; I found out he knows hexadecimal for colors and he understands them somewhat and he knows binary is the language computers use and can read them if need be. However here on Crystal Atatrium that is not good enough.&nbsp; So per his request and some others that may want to understand more I will explain Bases and positional systems. More of a mathematical explanation but should be learned when learning computers.<span id="more-226"></span></p>
<h1 style="text-align: center;">2+2=11?</h1>
<h2 style="text-align: center;">No, I am not just being funny, it really can</h2>
<p>So I am by no means a math teacher, however it is one of my loves. Ok so most likely if your reading this you at least know base 10.&nbsp; You probably have never heard it be called by that name before. Base-10 is the system mostly used it goes like this 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11&#8230;.etc etc easy huh.&nbsp; Now why is it called base 10 you ask? Well that would be another much longer answer and also one I am not too sure about.&nbsp; However easier way to remember is if you include 0 there are 10 digits 0-9.&nbsp; Now it is much easier to learn bases visually so here is base-10 counting to 10 and below it base-2 counting to 10 and finally lets go with base-3.</p>
<table border="1" cellpadding="1" cellspacing="1" style="width: 60%;">
<tbody>
<tr>
<td>1</td>
<td>2</td>
<td>3</td>
<td>4</td>
<td>5</td>
<td>6</td>
<td>7</td>
<td>8</td>
<td>9</td>
<td>10</td>
</tr>
<tr>
<td>1</td>
<td>10</td>
<td>11</td>
<td>100</td>
<td>101</td>
<td>110</td>
<td>111</td>
<td>1000</td>
<td>1001</td>
<td>1010</td>
</tr>
<tr>
<td>1</td>
<td>2</td>
<td>10</td>
<td>11</td>
<td>12</td>
<td>20</td>
<td>21</td>
<td>22</td>
<td>100</td>
<td>101</td>
</tr>
</tbody>
</table>
<p>As you can see in base-2 you never write the number 2 instead you treat it like you would if you reached 9 on base 10. Same with Base-3.&nbsp; Once you reach 3 you treat it as if you reached 10 in your everyday base of base-10. If you use the chart on the base-3 (third row) go to 2 and then add 2 too it by moving 2 places over.&nbsp; You get 11! See I told you it can.</p>
<h1 style="text-align: center;">When are these used?</h1>
<h2 style="text-align: center;">I just used them 2+2=11!!</h2>
<p>Now computers use the simplest one of base 2.&nbsp; It is simple because there are only 1&#39;s and 0&#39;s.&nbsp; On or Off. Yes or No.&nbsp; I could go on with these mundane opposites but i assume you get the point. If you wanna know more about that look up programming and compiling programs.&nbsp; Another base used often is Base-16 aka Hexadecimal.&nbsp; If you understand the above figuring out this will be a cinch.&nbsp; so what single character do we use to represent 10, its A. so here is another chart.</p>
<table border="1" cellpadding="1" cellspacing="1" style="width: 80%;">
<tbody>
<tr>
<td>1</td>
<td>2</td>
<td>3</td>
<td>4</td>
<td>5</td>
<td>6</td>
<td>7</td>
<td>8</td>
<td>9</td>
<td>10</td>
<td>11</td>
<td>12</td>
<td>13</td>
<td>14</td>
<td>15</td>
<td>16</td>
<td>17</td>
</tr>
<tr>
<td>1</td>
<td>2</td>
<td>3</td>
<td>4</td>
<td>5</td>
<td>6</td>
<td>7</td>
<td>8</td>
<td>9</td>
<td>A</td>
<td>B</td>
<td>C</td>
<td>D</td>
<td>E</td>
<td>F</td>
<td>10</td>
<td>11</td>
</tr>
<tr>
<td>1</td>
<td>2</td>
<td>3</td>
<td>4</td>
<td>10</td>
<td>11</td>
<td>12</td>
<td>13</td>
<td>14</td>
<td>20</td>
<td>21</td>
<td>22</td>
<td>23</td>
<td>24</td>
<td>30</td>
<td>31</td>
<td>32</td>
</tr>
</tbody>
</table>
<p>Ok the first row is base-10.&nbsp; Second row is base-16 (hexadecimal).&nbsp; and the third row I will let you figure out. So you see how 11 in hexadecimal is 17 in base-10 aka decimal (Our everyday number system). Many times in computers people will use hex-editors to make changes to a program and just what the name says.&nbsp; It opens it up in hex.&nbsp; So you will see things like 44 72 61 63 6f 20 69 73 20 61 20 67 65 6e 69 75 73 Now still on the topic of computers.&nbsp; Hexadecimal correlates to ASCII code.&nbsp; For instance there are 255 ASCII codes.&nbsp; This can be represented in hexadecimal as FF which is equal to 255 in decimal.&nbsp; Now in a hex editor you will see each character represented by a hex-code which pertains to a decimal number which pertains to an ASCII character.&nbsp; Confusing right? Well here is a small chart.&nbsp; If you want another full one just type &quot;ASCII CHART&quot; into google.</p>
<table align="left" border="1" cellpadding="1" cellspacing="1" style="width: 200px;">
<tbody>
<tr>
<td>Decimal</td>
<td>Hexadecimal</td>
<td>ASCII</td>
</tr>
<tr>
<td>65</td>
<td>41</td>
<td>A</td>
</tr>
<tr>
<td>66</td>
<td>42</td>
<td>B</td>
</tr>
<tr>
<td>67</td>
<td>43</td>
<td>C</td>
</tr>
<tr>
<td>68</td>
<td>44</td>
<td>D</td>
</tr>
<tr>
<td>69</td>
<td>45</td>
<td>E</td>
</tr>
</tbody>
</table>
<table align="center" border="1" cellpadding="1" cellspacing="1" style="width: 200px;">
<tbody>
<tr>
<td>Decimal</td>
<td>Hexadecimal</td>
<td>ASCII</td>
</tr>
<tr>
<td>97</td>
<td>61</td>
<td>a</td>
</tr>
<tr>
<td>98</td>
<td>62</td>
<td>b</td>
</tr>
<tr>
<td>99</td>
<td>63</td>
<td>c</td>
</tr>
<tr>
<td>100</td>
<td>64</td>
<td>d</td>
</tr>
<tr>
<td>101</td>
<td>65</td>
<td>e</td>
</tr>
</tbody>
</table>
<p>Notice there are different codes for UPPERCASE and lowercase. Try and decode the message I wrote earlier.&nbsp; Thank you for reading.&nbsp; Remember I really simplified this to be easier to understand.&nbsp; There are more detailed explanations if you so desire, just search for them.</p>
]]></content:encoded>
			<wfw:commentRss>http://crystalatatrium.com/basic-computer-information/all-your-%e2%80%9cbases%e2%80%9d-are-belong-to-us.aspx/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Social Engineering&#8230;Too easy?</title>
		<link>http://crystalatatrium.com/hacking/social-engineering-too-easy.aspx</link>
		<comments>http://crystalatatrium.com/hacking/social-engineering-too-easy.aspx#comments</comments>
		<pubDate>Wed, 29 Sep 2010 15:04:45 +0000</pubDate>
		<dc:creator>Draco</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[computer technician]]></category>
		<category><![CDATA[deception]]></category>
		<category><![CDATA[information gathering]]></category>
		<category><![CDATA[learning]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[pentesting]]></category>
		<category><![CDATA[router switches]]></category>
		<category><![CDATA[security holes]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[stealing]]></category>

		<guid isPermaLink="false">http://crystalatatrium.com/?p=166</guid>
		<description><![CDATA[Social Engineering, No assembly required If you do not know what social engineering is, read here . Put simply, it is hacking people.  Like most of the things on this site, this is about learning.  I do not recommend lying your way into a company. Also, on the topic of learning, if there is a [...]]]></description>
			<content:encoded><![CDATA[<h1 style="text-align: center;">Social Engineering,</h1>
<div style="text-align: center;"><span class="Apple-style-span" style="font-size: medium;"><span class="Apple-style-span" style="font-size: 14px;"><strong>No assembly required</strong></span></span></div>
<p>If you do not know what social engineering is, read <a href="http://en.wikipedia.org/wiki/Social_engineering_(security)">here</a> . Put simply, it is hacking people.  Like most of the things on this site, this is about learning.  I do not recommend lying your way into a company. Also, on the topic of learning, if there is a word you do not know on here, I provided links so you can read about it.</p>
<p>So, back to the issue at hand here, a couple days ago, I got a call at my office to go on-site to a new company. They wanted me to come in and fix any problems that I could find on their computers.  I was happy because I like more hands on work anyways.  When I got to this company, there were security holes everywhere.<span id="more-166"></span> I walked around for a bit and no one even asked me what I was doing or anything.  Finally, I walked up to the front desk and the woman sitting there asked me who I was. She did not even know that someone had called for a computer technician&#8230;..</p>
<h1 style="text-align: center;">What Now?</h1>
<h2 style="text-align: center;">She didn&#8217;t know. She will probably call someone then, right? No.</h2>
<p>She got up and asked me to look at her computer. She gave me the passwords for her everything&#8230;.even email ( Though, I told her I didn&#8217;t need them but whatever.)  So after 5-10 minutes in this company, I had gained access to the <a href="http://en.wikipedia.org/wiki/Computer_Network">network</a> and too much information.  I let her know that her computer had some stuff on the startup and removed it and I moved on (also wrote it down for charging later).</p>
<h1 style="text-align: center;">The I.T. Department</h1>
<h2 style="text-align: center;">Hackers beware&#8230;Oh, he isn&#8217;t an I.T. person</h2>
<p>I finally found the &#8220;Head&#8221; IT guy for the company.  He was really just an employee that they gave the title to so they could say they have one.  I don&#8217;t think he knew much about computers&#8230;but probably more than the rest of the company which is fine because he probably hates it and doesn&#8217;t even really work on it. I understand his pain. I am not a car person so I wouldn&#8217;t want to be stuck with mechanic duties. I asked him where his <a href="http://en.wikipedia.org/wiki/Router">router</a>/<a href="http://en.wikipedia.org/wiki/Network_switch">switches</a> for the company were and he led me to them&#8230;guess where to&#8230;</p>
<h1 style="text-align: center;">Secure Area?</h1>
<h2 style="text-align: center;">In a barrier created by the 7 high wizards?</h2>
<p>Wrong! The bathroom.  They were in the men&#8217;s bathroom to be precise.  This bathroom was a one man bathroom so the door could lock from the inside&#8230;.yet another security flaw.  I was so confused how this idea came about because this isn&#8217;t the first time I have seen a server and/or switch and router in bathrooms.</p>
<h1 style="text-align: center;">What Now?</h1>
<h2 style="text-align: center;">This place is easier than OR &#8217;1=1</h2>
<p>After giving him tips and such about how to secure these problems, I fixed his issue (someone was messing with his switch and a couple of wires were loose).  He didn&#8217;t pay me to secure the place but I let him know that he should get us out there to help him with that. Basically, the moral of this story is that we need to teach people about the value of <a href="http://en.wikipedia.org/wiki/Computer_Security">security</a>.  If someone is walking around the company that you don&#8217;t know and isn&#8217;t usually there&#8230; just stop them and ask them what they need. If that woman would have known to at least ask someone to confirm that they had actually called a computer technician, it would have been OK. Also, most techs should not ask you to just give them YOUR password, instead they will have you type it for them.  Also, switches and routers in a closed bathroom&#8230;&#8230;.Need I say more about that. At least lock it up in there with a padlock (this place sold padlocks by the way).  <span style="color: #ff8c00;">It is amazing what you can get out of people with the &#8220;I am suppose to be here attitude&#8221; and a professional T-shirt. </span></p>
]]></content:encoded>
			<wfw:commentRss>http://crystalatatrium.com/hacking/social-engineering-too-easy.aspx/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 0.664 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2012-04-20 08:58:58 -->

