<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Hacker 10 - Security Hacker</title>
	
	<link>http://www.hacker10.com</link>
	<description>Computer security</description>
	<lastBuildDate>Sat, 18 May 2013 08:18:48 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/hacker10hacker10" /><feedburner:info uri="hacker10hacker10" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>hacker10hacker10</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>The Active Defense Harbinger Distribution</title>
		<link>http://feedproxy.google.com/~r/hacker10hacker10/~3/nYWWMbCejyQ/</link>
		<comments>http://www.hacker10.com/other-computing/the-active-defense-harbinger-distribution/#comments</comments>
		<pubDate>Sat, 18 May 2013 08:18:48 +0000</pubDate>
		<dc:creator>Hacker10</dc:creator>
				<category><![CDATA[Other Computing]]></category>
		<category><![CDATA[Active Defense Harbinger Distribution]]></category>
		<category><![CDATA[Linux ADHD]]></category>
		<category><![CDATA[secure Linux distribution]]></category>

		<guid isPermaLink="false">http://www.hacker10.com/?p=7986</guid>
		<description><![CDATA[The Active Defense Harbinger Distribution is a security Linux distribution based on Ubuntu 12.04 Long Term Support, Ubuntu LTS has 5 years support from Ubuntu developers Canonical, it is useful for enterprises and those who don&#8217;t need to run cutting &#8230; <a href="http://www.hacker10.com/other-computing/the-active-defense-harbinger-distribution/">Continue reading <span class="meta-nav">&#8594;</span></a><div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/other-computing/computer-forensics-linux-distribution-caine/"     class="crp_title">Computer forensics Linux distribution CAINE</a></li><li><a href="http://www.hacker10.com/computer-security/linux-distribution-for-wireless-hacking-xiaopan-os/"     class="crp_title">Linux distribution for wireless hacking Xiaopan OS</a></li><li><a href="http://www.hacker10.com/internet-anonymity/occupyos-anonymous-operating-system-for-activists/"     class="crp_title">OccupyOS anonymous operating system for activists</a></li><li><a href="http://www.hacker10.com/computer-security/the-best-emergency-antivirus-recovery-live-cds/"     class="crp_title">The best emergency antivirus recovery live CDs</a></li><li><a href="http://www.hacker10.com/internet-anonymity/secure-operating-system-with-tor-proxy-quantos/"     class="crp_title">Secure operating system with tor proxy quantOS</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The Active Defense Harbinger Distribution is a security Linux distribution based on Ubuntu 12.04 Long Term Support, Ubuntu LTS has 5 years support from Ubuntu developers Canonical, it is useful for enterprises and those who don&#8217;t need to run cutting edge software and are more interested in an stable operating system that will be supported for a long time without the need to constantly upgrade to another version to patch up security holes.</p>
<p>ADHD announces itself as an active defence distribution with preconfigured strike back tools, able to interfere with an attacker&#8217;s system fingerprinting, the first reconnaissance stage previous to a hacking attack. Just like Ubuntu, you can run ADHD as a live DVD or install it in your computer, when you first boot you will be given the choice of logging in as <em>adhd</em> user or guest user, the login password is <em>adhd</em>. The default window manager is the lightweight XFCE, you could change it using Synaptic package manager, a package management tool for Debian that can be used to install, remove and upgrade software packages.</p>
<div id="attachment_7992" class="wp-caption aligncenter" style="width: 460px"><img class="size-full wp-image-7992" alt="The Active Defense Harbinger Distribution (ADHD)" src="http://www.hacker10.com/wp-content/uploads/2013/05/The-Active-Defense-Harbinger-Distribution-ADHD.jpg" width="450" height="300" /><p class="wp-caption-text">The Active Defense Harbinger Distribution (ADHD)</p></div>
<p>On the surface you will not appreciate too many differences in between The Active Defense Harbinger Distribution and any other end user Linux distribution, it comes with The Gimp and gThumb for image editing, the full LibreOffice suite to work with documents, Thunderbird and Firefox, Catfish to search documents, basic network tools to ping, traceroute, port scan, finger and whois computer IPs, Xchat for IRC, Zenmap scanner, Gigolo, a front end to connect to remote file system, Parole Media player to watch videos, gmusic browser and Gwibber, an open source microblogging tool with access to the most popular social networking services like Twitter and Flickr. The most geeky tool included in ADHD is pgAdmin to edit PostgreSQL databases you will not find any hacking or penetration testing software on the list.</p>
<p>The Active Defense Harbinger Distribution protects you deploying honeypots that waste an attacker&#8217;s time, alert the administrator of the attack while still harmless and gathers information on the sources of the attack.</p>
<p>One of ADHD main defences is The Network Obfuscation and Virtualized Anti-Reconnaissance (Nova), it doesn&#8217;t use signature based detection for malware, instead it creates decoy systems for an attacker to interact with and alert the system administrator via email or logs that someone is attacking a dummy folder, port, etc. You can have infinite recursive directories so the attacker never really gets to his target or you can instruct Nova to automatically shut down a port when someone touches it.</p>
<div id="attachment_8009" class="wp-caption aligncenter" style="width: 460px"><img class="size-full wp-image-8009" alt="The Active Defense Harbinger Distribution system monitor" src="http://www.hacker10.com/wp-content/uploads/2013/05/The-Active-Defense-Harbinger-Distribution-system-monitor.jpg" width="450" height="299" /><p class="wp-caption-text">The Active Defense Harbinger Distribution system monitor</p></div>
<p>ADHD also comes with Honeybadger, able to create a webpage that looks like a Cisco administration interface or something interesting for an attacker to access, the dummy page can run a Java app on the attacker&#8217;s machine, gather his IP address and add it to a report page with Google API showing approximate information about an attacker&#8217;s computer IP location in the world.</p>
<p>The best thing of The Active Defense Harbinger Distribution is that you should not notice it is there until something happens, on the minus side there are no offensive tools other than gathering attacker&#8217;s information but you could add more aggressive digital tools with the package manager.</p>
<p style="text-align: center;"><strong><span style="color: #0000ff;"><a title="Active Defense Harbinger Distribution " href="http://sourceforge.net/projects/adhd/" target="_blank"><span style="color: #0000ff;">Visit ADHD homepage</span></a></span></strong></p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/other-computing/computer-forensics-linux-distribution-caine/"     class="crp_title">Computer forensics Linux distribution CAINE</a></li><li><a href="http://www.hacker10.com/computer-security/linux-distribution-for-wireless-hacking-xiaopan-os/"     class="crp_title">Linux distribution for wireless hacking Xiaopan OS</a></li><li><a href="http://www.hacker10.com/internet-anonymity/occupyos-anonymous-operating-system-for-activists/"     class="crp_title">OccupyOS anonymous operating system for activists</a></li><li><a href="http://www.hacker10.com/computer-security/the-best-emergency-antivirus-recovery-live-cds/"     class="crp_title">The best emergency antivirus recovery live CDs</a></li><li><a href="http://www.hacker10.com/internet-anonymity/secure-operating-system-with-tor-proxy-quantos/"     class="crp_title">Secure operating system with tor proxy quantOS</a></li></ul></div><img src="http://feeds.feedburner.com/~r/hacker10hacker10/~4/nYWWMbCejyQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.hacker10.com/other-computing/the-active-defense-harbinger-distribution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.hacker10.com/other-computing/the-active-defense-harbinger-distribution/</feedburner:origLink></item>
		<item>
		<title>Anonymously submit documents to the press with StrongBox</title>
		<link>http://feedproxy.google.com/~r/hacker10hacker10/~3/sz_OcWC29uk/</link>
		<comments>http://www.hacker10.com/internet-anonymity/anonymously-submit-documents-to-the-press-with-strongbox/#comments</comments>
		<pubDate>Thu, 16 May 2013 14:59:22 +0000</pubDate>
		<dc:creator>Hacker10</dc:creator>
				<category><![CDATA[Internet Anonymity]]></category>
		<category><![CDATA[anonymous document leak]]></category>
		<category><![CDATA[StrongBox review]]></category>
		<category><![CDATA[Wikileaks alternative]]></category>

		<guid isPermaLink="false">http://www.hacker10.com/?p=7967</guid>
		<description><![CDATA[Strongbox is a The New Yorker magazine tool to anonymously submit files and messages to journalist using the tor network, the project was put together by political activist Aaron Swartz, who died a few months ago, and Kevin Poulsen. StrongBox &#8230; <a href="http://www.hacker10.com/internet-anonymity/anonymously-submit-documents-to-the-press-with-strongbox/">Continue reading <span class="meta-nav">&#8594;</span></a><div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/other-computing/remove-files-metadata-with-batchpurifier/"     class="crp_title">Remove files metadata with BatchPurifier</a></li><li><a href="http://www.hacker10.com/other-computing/set-up-your-own-whistleblowing-platform-with-globaleaks/"     class="crp_title">Set up your own whistleblowing platform with Globaleaks</a></li><li><a href="http://www.hacker10.com/other-computing/erase-hidden-data-with-the-metadata-anonymisation-toolkit/"     class="crp_title">Erase hidden data with the Metadata Anonymisation Toolkit</a></li><li><a href="http://www.hacker10.com/encryption-software-2/isafepdf-to-encrypt-and-digitally-sign-pdf-documents/"     class="crp_title">iSafePDF to encrypt and digitally sign PDF documents</a></li><li><a href="http://www.hacker10.com/encryption-software-2/rohos-mini-drive-free-usb-thumbdrive-encryption-without-admin-rights/"     class="crp_title">Rohos Mini Drive free USB thumbdrive encryption without&hellip;</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>Strongbox is a The New Yorker magazine tool to anonymously submit files and messages to journalist using the tor network, the project was put together by political activist Aaron Swartz, who died a few months ago, and Kevin Poulsen. StrongBox code is called DeadDrop and eventually will be released as open source for news agencies and particulars to implement as they wish.</p>
<p>DeadDrop software runs on a hardened Ubuntu environment, it includes set up instructions and scripts, the code is written in Python, accepting document submissions and encrypting them with GPG for storage it then creates a random codename to be able to get back to the submitter anonymously without using email, there are three servers to anonymize the submission process one of them is public containing the interface,  another server stores the encrypted messages and the third server monitors the other two for security breaches.</p>
<div id="attachment_7974" class="wp-caption aligncenter" style="width: 460px"><img class="size-full wp-image-7974" alt="StrongBox anonymous document leak DeadDrop" src="http://www.hacker10.com/wp-content/uploads/2013/05/StrongBox-anonymous-document-submission-DeadDrop.jpg" width="450" height="285" /><p class="wp-caption-text">StrongBox anonymous document leak DeadDropWiki</p></div>
<p>The New Yorker public server is also using a plugged in USB dongle to strenghen encryption entropy helping create a pool of random numbers, their journalists use a VPN to download the encrypted data on to a USB thumbdrive, the information is decrypted using a laptop that has no Internet access, to avoid malware infection, and running a live CD to keep temporary files out of the computer hard drive and make data recovery impossible, GPG private decryption keys are contained in a different USB thumbdrive also plugged in the same laptop prior to viewing the documents.</p>
<p>It is a smart set up that makes it impossible for a New Yorker journalist to learn the submitter computer IP so they can not be compelled to reveal something they don&#8217;t know. The only missing thing is a metadata scrubber, if the documents you are passing on contain metadata, and most government and company files do, the original leak source could be found out, you should use <span style="color: #0000ff;"><a title="BatchPurifier" href="http://www.hacker10.com/other-computing/remove-files-metadata-with-batchpurifier/" target="_blank"><span style="color: #0000ff;">BatchPurifier</span></a></span> first to get rid of hidden data before submitting any file.</p>
<p style="text-align: center;"><strong><span style="color: #0000ff;"><a title="StrongBox" href="http://www.newyorker.com/strongbox/" target="_blank"><span style="color: #0000ff;">Visit StrongBox homepage</span></a></span></strong></p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/other-computing/remove-files-metadata-with-batchpurifier/"     class="crp_title">Remove files metadata with BatchPurifier</a></li><li><a href="http://www.hacker10.com/other-computing/set-up-your-own-whistleblowing-platform-with-globaleaks/"     class="crp_title">Set up your own whistleblowing platform with Globaleaks</a></li><li><a href="http://www.hacker10.com/other-computing/erase-hidden-data-with-the-metadata-anonymisation-toolkit/"     class="crp_title">Erase hidden data with the Metadata Anonymisation Toolkit</a></li><li><a href="http://www.hacker10.com/encryption-software-2/isafepdf-to-encrypt-and-digitally-sign-pdf-documents/"     class="crp_title">iSafePDF to encrypt and digitally sign PDF documents</a></li><li><a href="http://www.hacker10.com/encryption-software-2/rohos-mini-drive-free-usb-thumbdrive-encryption-without-admin-rights/"     class="crp_title">Rohos Mini Drive free USB thumbdrive encryption without&hellip;</a></li></ul></div><img src="http://feeds.feedburner.com/~r/hacker10hacker10/~4/sz_OcWC29uk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.hacker10.com/internet-anonymity/anonymously-submit-documents-to-the-press-with-strongbox/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.hacker10.com/internet-anonymity/anonymously-submit-documents-to-the-press-with-strongbox/</feedburner:origLink></item>
		<item>
		<title>CIA instructions for secure email communications leaked</title>
		<link>http://feedproxy.google.com/~r/hacker10hacker10/~3/ApH4wG5NSbs/</link>
		<comments>http://www.hacker10.com/computer-security/cia-instructions-for-secure-email-communications-leaked/#comments</comments>
		<pubDate>Thu, 16 May 2013 03:02:09 +0000</pubDate>
		<dc:creator>Hacker10</dc:creator>
				<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[CIA email]]></category>
		<category><![CDATA[email security]]></category>
		<category><![CDATA[secret covert communications]]></category>

		<guid isPermaLink="false">http://www.hacker10.com/?p=7912</guid>
		<description><![CDATA[After the recent arrest of CIA agent Ryan Fogle by the Russian counter intelligence agency Federal Security Service one of items they found in his possession and leaked to the press was a letter advising his Russian informer how to &#8230; <a href="http://www.hacker10.com/computer-security/cia-instructions-for-secure-email-communications-leaked/">Continue reading <span class="meta-nav">&#8594;</span></a><div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/computer-security/website-checks-if-your-email-address-has-been-compromised/"     class="crp_title">Website checks if your email address has been compromised</a></li><li><a href="http://www.hacker10.com/computer-security/9-ways-to-protect-your-email-address-from-spambots/"     class="crp_title">9 ways to protect your email address from spambots</a></li><li><a href="http://www.hacker10.com/other-computing/remove-gmail-advertisements-with-gmelius/"     class="crp_title">Remove Gmail advertisements with Gmelius</a></li><li><a href="http://www.hacker10.com/other-computing/review-enlocked-email-encryption-app/"     class="crp_title">Review Enlocked email encryption App</a></li><li><a href="http://www.hacker10.com/other-computing/list-of-the-best-free-webmail-privacy-services/"     class="crp_title">List of the best free webmail privacy services</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>After the recent arrest of CIA agent Ryan Fogle by the Russian counter intelligence agency Federal Security Service one of items they found in his possession and leaked to the press was a letter advising his Russian informer how to conduct secure email communications, this post will scrutinize these instructions to learn why the CIA adopted those particular security measures.</p>
<ul>
<li><strong><span style="color: #ff0000;">CIA Tip 1:</span> <em>&#8220;To get back to us please use an Internet cafe that has Wi-fi&#8221;</em></strong></li>
</ul>
<p>The Central Intelligence Agency is advising Wi-Fi to make sure that their informer does not use someone&#8217;s else computer, when you use a public computer you agree to being monitored by the system administrator, it is impossible to known what kind of surveillance or viruses exist in that computer and any data left behind, like visited and written emails are recoverable from the Internet browser cache even after years.</p>
<p>They are also making sure that if the informer home Internet connection is under surveillance by his ISP and checked by keywords, it will not be a threat.</p>
<ul>
<li><strong><span style="color: #ff0000;">CIA Tip 2:</span> <span style="color: #000000;"><em>&#8220;Open a Gmail account which you will use exclusively to contact us&#8221;</em></span></strong> ; <strong><em>&#8220;As you register do not provide any personal info&#8221;</em></strong></li>
</ul>
<p>They get their informer to use an American email company that can be easily accessible by the US government if needed, they make sure that he is not stupid enough to open the email account using his real name or address or other small details that could be linked to him like his phone number or a real password recovery email address belonging to him.</p>
<div id="attachment_7930" class="wp-caption aligncenter" style="width: 462px"><img class="size-full wp-image-7930" alt="CIA secure email instructions for spies" src="http://www.hacker10.com/wp-content/uploads/2013/05/CIA-secure-email-instructions.jpg" width="452" height="353" /><p class="wp-caption-text">CIA secure email instructions for spies</p></div>
<p>As a side note, there must be something good about Gmail security because former CIA Director General David Petraeus also decided to use a Gmail account for cheating on his wife last year, something I can think of is that Gmail login is with SSL and username and password can not be captured over insecure Wifi.</p>
<ul>
<li><strong><span style="color: #ff0000;">CIA Tip 3: </span>&#8220;<em>Once you register send a message to unbacggdA@gmail.com</em>&#8220;</strong>: &#8220;<strong><em>In exactly one week, check this mailbox for a response from us</em>&#8220;</strong></li>
</ul>
<p>The CIA gets his informer to email to another Gmail address from the same company, with this they make sure that email content will not have to travel over the Internet from one provider to another, if you send an email from Gmail to Gmail, presumably data never leaves Gmail servers.</p>
<p>The confusing email address the CIA is using makes it very difficult for a similar one to exist, so even if their informer makes a typo, the email will not be sent to someone else by mistake, it should bounce to his inbox instead.</p>
<ul>
<li><strong><span style="color: #ff0000;">CIA Tip 4:</span> &#8220;If you use a Netbook or any other device (i.e. tablet) to open the account at a coffee shop please don&#8217;t use a device with personal data on it&#8221;</strong></li>
</ul>
<p>The CIA wants to avoid cross contamination, if the tablet is lost, stolen or hacked and accessed without permission, a third party could link the email exchange with the informer&#8217;s real job exposing him as an American spy.</p>
<ul>
<li><strong><span style="color: #ff0000;">CIA Tip 5:</span></strong> <strong>&#8220;If possible buy a new device (paying in cash) which you will use to contact us&#8221;</strong></li>
</ul>
<p>The best way to avoid mixing real life data with underground activities is using a dedicated device for illegal actions that will not be touched by anything else, this greatly reduces chances of a mistake and the device can be quickly disposed of if needed. The CIA also makes sure that the informer&#8217;s credit card can not be linked to the purchase of a new tablet, if the informer is investigated someone could notice in the financial transactions that he has spent money buying a new tablet nowhere to be found.</p>
<p style="text-align: center;"><strong><span style="text-decoration: underline; color: #ff0000;">Other spy items</span></strong></p>
<p>Other seized items showed to the press include a couple of wigs, three pair of sunglasses and a baseball cap, all of those items make facial recognition difficult if the Russians have that kind of software installed in their CCTV network (public transportation, street cameras, etc) to automatically flag people of interest. The British government has trialled facial recognition software on CCTV street cameras and Germany is known to employ it in Frankfurt international airport.</p>
<p>Another interesting item found in his possession was an RFID shield that prevents reading of RFID chips embedded in passports and ID cards, this indicates that the CIA does not trust those chips otherwise there would be no need to protect them from unauthorized reading.</p>
<div id="attachment_7955" class="wp-caption aligncenter" style="width: 460px"><img class="size-full wp-image-7955" alt="CIA money bundle 500 Euro bank notes" src="http://www.hacker10.com/wp-content/uploads/2013/05/CIA-money-bundle-500-Euro-bank-notes.jpg" width="450" height="255" /><p class="wp-caption-text">CIA money bundle 500 Euro bank notes</p></div>
<p>Allegedly the CIA spy was also carrying a large bundle of €500 Euro bank notes, these are ideal for money smuggling and corruption. China for example limits its bank notes value to small amounts to make bribery more difficult, to carry a very large amount of money in Yuan would have required the CIA agent a box full of bank notes instead of a bundle, this could explain why the CIA wanted to pay the informer&#8217;s bribe in Euros and not dollars or Russian roubles.</p>
<p>Computer savvy people will wonder why encryption and proxies are not mentioned at all, I am guessing here that the CIA instructions are addressed to someone who is a total computer knob and even an old grandma could follow.</p>
<p>Read the full letter on the <a title="CIA agent arrested" href="http://www.washingtonpost.com/blogs/worldviews/wp/2013/05/14/heres-the-spy-recruitment-letter-allegedly-found-on-cia-agent-in-moscow/" target="_blank">WashingtonPost article</a></p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/computer-security/website-checks-if-your-email-address-has-been-compromised/"     class="crp_title">Website checks if your email address has been compromised</a></li><li><a href="http://www.hacker10.com/computer-security/9-ways-to-protect-your-email-address-from-spambots/"     class="crp_title">9 ways to protect your email address from spambots</a></li><li><a href="http://www.hacker10.com/other-computing/remove-gmail-advertisements-with-gmelius/"     class="crp_title">Remove Gmail advertisements with Gmelius</a></li><li><a href="http://www.hacker10.com/other-computing/review-enlocked-email-encryption-app/"     class="crp_title">Review Enlocked email encryption App</a></li><li><a href="http://www.hacker10.com/other-computing/list-of-the-best-free-webmail-privacy-services/"     class="crp_title">List of the best free webmail privacy services</a></li></ul></div><img src="http://feeds.feedburner.com/~r/hacker10hacker10/~4/ApH4wG5NSbs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.hacker10.com/computer-security/cia-instructions-for-secure-email-communications-leaked/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.hacker10.com/computer-security/cia-instructions-for-secure-email-communications-leaked/</feedburner:origLink></item>
		<item>
		<title>Penetrate Voice over IP servers with Viproy</title>
		<link>http://feedproxy.google.com/~r/hacker10hacker10/~3/xASiX6gu-Qk/</link>
		<comments>http://www.hacker10.com/other-computing/penetrate-voice-over-ip-servers-with-viproy/#comments</comments>
		<pubDate>Tue, 14 May 2013 23:01:53 +0000</pubDate>
		<dc:creator>Hacker10</dc:creator>
				<category><![CDATA[Other Computing]]></category>
		<category><![CDATA[Viproy review]]></category>
		<category><![CDATA[VoIP hacking]]></category>
		<category><![CDATA[VoIP penetration testing]]></category>

		<guid isPermaLink="false">http://www.hacker10.com/?p=7892</guid>
		<description><![CDATA[Viproy is a tool for testing SIP servers security, the Session Initiation Protocol is widely used for voice and video calls over IP, the software comes with different modules performing specific tasks, all of the modules support debugging and verbose &#8230; <a href="http://www.hacker10.com/other-computing/penetrate-voice-over-ip-servers-with-viproy/">Continue reading <span class="meta-nav">&#8594;</span></a><div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/computer-security/jitsi-the-encrypted-chat-software-with-voip-and-video/"     class="crp_title">Jitsi the encrypted chat software with VoIP and video</a></li><li><a href="http://www.hacker10.com/encryption-software-2/3-ways-to-encrypt-your-voip-calls/"     class="crp_title">3 ways to encrypt your VoIP calls</a></li><li><a href="http://www.hacker10.com/computer-security/linux-distribution-for-wireless-hacking-xiaopan-os/"     class="crp_title">Linux distribution for wireless hacking Xiaopan OS</a></li><li><a href="http://www.hacker10.com/mobile-phone/kryptos-voice-encryption-mobile-phone-applet/"     class="crp_title">Kryptos: Voice encryption mobile phone applet</a></li><li><a href="http://www.hacker10.com/other-computing/cain-abel-windows-password-cracker/"     class="crp_title">Cain &#038; Abel Windows password cracker</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>Viproy is a tool for testing SIP servers security, the Session Initiation Protocol is widely used for voice and video calls over IP, the software comes with different modules performing specific tasks, all of the modules support debugging and verbose mode, this is a Linux only command line tool, instructions are included and it should not be difficult for a Linux beginner to understand them.</p>
<p>Software modules consist of options, register, invite, enumerator, brute force, trust analyzer and SIP proxy, you can set target networks and port numbers. Before carrying out any attack you should fingerprint and enumerate SIP services first, after that you should register with the server and start intercepting, making calls or create havoc at will.</p>
<p>Viproy VoIP penetration tests include targeting a local client address and port, discovering SIP services with valid credentials, setting username and password in Asterisk PBX, issuing direct invites and spoofing without credentials, enumerating all users, launching a denial of service to all valid users so that nobody can accept calls and brute forcing a target account or numeric range using a dictionary list to test users password strength.</p>
<div id="attachment_7899" class="wp-caption aligncenter" style="width: 460px"><img class="size-full wp-image-7899" alt="Viproy VoIP penetration testing and hacking tool" src="http://www.hacker10.com/wp-content/uploads/2013/05/Viproy-VoIP-hacking-penetration-test.jpg" width="450" height="275" /><p class="wp-caption-text">Viproy VoIP penetration testing and hacking tool</p></div>
<p>Viproy homepage lists a vulnerable VoIP server where you can evaluate your hacking skills without harming anybody, in a real life scenario after successful hacking a VoIP server you can listen in or record inbound and outbound calls as well as setting up usernames and passwords, the damage that can be done will depend no how many vulnerabilities exist, not all of the modules will be necessary successful penetrating the server.</p>
<p>Another tool you might want to add to your VoIP hacking arsenal is SIPVicious suite you can use it to audit VoIP systems scanning SIP devices IP range and cracking SIP PBX. VPN services protect VoIP calls in transit but the first and last point remain vulnerable, it is possible to listen in to a VoIP encrypted call by hacking into a server before encryption takes place or when the call is decrypted at the end of the line.</p>
<p style="text-align: center;"><strong><span style="color: #0000ff;"><a title="Viproy VoIP hacking" href="http://viproy.com/voipkit/" target="_blank"><span style="color: #0000ff;">Visit Viproy homepage</span></a></span></strong></p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/computer-security/jitsi-the-encrypted-chat-software-with-voip-and-video/"     class="crp_title">Jitsi the encrypted chat software with VoIP and video</a></li><li><a href="http://www.hacker10.com/encryption-software-2/3-ways-to-encrypt-your-voip-calls/"     class="crp_title">3 ways to encrypt your VoIP calls</a></li><li><a href="http://www.hacker10.com/computer-security/linux-distribution-for-wireless-hacking-xiaopan-os/"     class="crp_title">Linux distribution for wireless hacking Xiaopan OS</a></li><li><a href="http://www.hacker10.com/mobile-phone/kryptos-voice-encryption-mobile-phone-applet/"     class="crp_title">Kryptos: Voice encryption mobile phone applet</a></li><li><a href="http://www.hacker10.com/other-computing/cain-abel-windows-password-cracker/"     class="crp_title">Cain &#038; Abel Windows password cracker</a></li></ul></div><img src="http://feeds.feedburner.com/~r/hacker10hacker10/~4/xASiX6gu-Qk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.hacker10.com/other-computing/penetrate-voice-over-ip-servers-with-viproy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.hacker10.com/other-computing/penetrate-voice-over-ip-servers-with-viproy/</feedburner:origLink></item>
		<item>
		<title>Intercept communications with data tampering tool HookME</title>
		<link>http://feedproxy.google.com/~r/hacker10hacker10/~3/VQbBnsSMphk/</link>
		<comments>http://www.hacker10.com/other-computing/intercept-communications-with-data-tampering-tool-hookme/#comments</comments>
		<pubDate>Sun, 12 May 2013 10:35:29 +0000</pubDate>
		<dc:creator>Hacker10</dc:creator>
				<category><![CDATA[Other Computing]]></category>
		<category><![CDATA[HookME review]]></category>
		<category><![CDATA[Penetration testing software]]></category>
		<category><![CDATA[TCP data tampering]]></category>

		<guid isPermaLink="false">http://www.hacker10.com/?p=7871</guid>
		<description><![CDATA[HookME is a free open source Windows tool to intercept network communications hooking up desired processes and API calls, including SSL clear data, the unencrypted SSL headers. The software download is initially tiny (125Kb), when you try to install it &#8230; <a href="http://www.hacker10.com/other-computing/intercept-communications-with-data-tampering-tool-hookme/">Continue reading <span class="meta-nav">&#8594;</span></a><div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/computer-security/how-to-detect-and-remove-rootkits-with-gmer/"     class="crp_title">How to detect and remove rootkits with Gmer</a></li><li><a href="http://www.hacker10.com/computer-security/free-alternative-to-windows-task-manager-currports/"     class="crp_title">Free alternative to Windows Task Manager: CurrPorts</a></li><li><a href="http://www.hacker10.com/other-computing/penetrate-voice-over-ip-servers-with-viproy/"     class="crp_title">Penetrate Voice over IP servers with Viproy</a></li><li><a href="http://www.hacker10.com/computer-security/closethedoor-lists-all-udptcp-open-ports/"     class="crp_title">CloseTheDoor lists all UDP/TCP open ports</a></li><li><a href="http://www.hacker10.com/other-computing/sandcat-browser-for-website-penetration-testing/"     class="crp_title">SandCat browser for website penetration testing</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>HookME is a free open source Windows tool to intercept network communications hooking up desired processes and API calls, including SSL clear data, the unencrypted SSL headers.</p>
<p>The software download is initially tiny (125Kb), when you try to install it you will get a message saying it requires supplemental <em>.dll</em> and <em>.db</em> files to work, over 30MB of files will be automatically downloaded by HookME from a third party site, you will also be asked to register the new <em>.dll</em> dependencies giving administrative rights to Windows Command Processor, the installation process could make some people feel uneasy about this tool containing malware, the only guarantee you have is that HookME is developed by well known OSINT FOCA creators.</p>
<p>Every time you start the software you will be shown a small Netkra Deviare unregistered license splash screen, you don&#8217;t have to buy a license but it will get rid of the initial screen if you do.</p>
<div id="attachment_7877" class="wp-caption aligncenter" style="width: 460px"><img class="size-full wp-image-7877" alt="TCP data tampering tool HookME " src="http://www.hacker10.com/wp-content/uploads/2013/05/HookME-TCP-data-tampering-hacking-tool.jpg" width="450" height="286" /><p class="wp-caption-text">TCP data tampering tool HookME</p></div>
<p>The software has a tabbed user interface that can be used to intercept any hooked API call and read the data that is being sent and received, you can change intercepted packets in real time, dropping or forwarding them, a Python plugin system allows for anyone to create their own custom addon, there are some templates for that. HookME developer showed in BlackHat Europe 2013 conference how to easily intercept MySQL data and inject a backdoor on the fly with a few clicks executing remote commands.</p>
<p>Real time intercepted data can be seen in the user interface Hex editor showing you hexadecimal numbers and their corresponding text meaning, you can highlight data packets and click on the &#8220;<em>Drop</em>&#8221; or &#8220;<em>Forward</em>&#8221; buttons, a small window below the program lets you know what process is hooked, for example it will show <em>firefox.exe</em> if you are eavesdropping on a Firefox browser session.</p>
<p>This tool can be used for penetration testing creating malware and backdoors in network protocols or to uncover rootkits hooking up API calls, the main challenge for an attacker to use HookME against you would be getting access to your network first.</p>
<p style="text-align: center;"><strong><span style="color: #0000ff;"><a title="HookME TCP data tampering" href="http://code.google.com/p/hookme/" target="_blank"><span style="color: #0000ff;">Visit HookME homepage</span></a></span></strong></p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/computer-security/how-to-detect-and-remove-rootkits-with-gmer/"     class="crp_title">How to detect and remove rootkits with Gmer</a></li><li><a href="http://www.hacker10.com/computer-security/free-alternative-to-windows-task-manager-currports/"     class="crp_title">Free alternative to Windows Task Manager: CurrPorts</a></li><li><a href="http://www.hacker10.com/other-computing/penetrate-voice-over-ip-servers-with-viproy/"     class="crp_title">Penetrate Voice over IP servers with Viproy</a></li><li><a href="http://www.hacker10.com/computer-security/closethedoor-lists-all-udptcp-open-ports/"     class="crp_title">CloseTheDoor lists all UDP/TCP open ports</a></li><li><a href="http://www.hacker10.com/other-computing/sandcat-browser-for-website-penetration-testing/"     class="crp_title">SandCat browser for website penetration testing</a></li></ul></div><img src="http://feeds.feedburner.com/~r/hacker10hacker10/~4/VQbBnsSMphk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.hacker10.com/other-computing/intercept-communications-with-data-tampering-tool-hookme/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.hacker10.com/other-computing/intercept-communications-with-data-tampering-tool-hookme/</feedburner:origLink></item>
		<item>
		<title>Portable hardware VPN device Färist Micro</title>
		<link>http://feedproxy.google.com/~r/hacker10hacker10/~3/zMmgQR0kM54/</link>
		<comments>http://www.hacker10.com/other-computing/portable-hardware-vpn-device-farist-micro/#comments</comments>
		<pubDate>Tue, 07 May 2013 00:11:32 +0000</pubDate>
		<dc:creator>Hacker10</dc:creator>
				<category><![CDATA[Other Computing]]></category>
		<category><![CDATA[Färist Micro]]></category>
		<category><![CDATA[portable VPN]]></category>
		<category><![CDATA[VPN hardware]]></category>

		<guid isPermaLink="false">http://www.hacker10.com/?p=7849</guid>
		<description><![CDATA[Färist Micro from Swedish company Tutus is a tiny VPN device that fits in the palm of your hand and sits in between your computer and Internet connection. The A100 model has a shock resistant case made of aluminium and &#8230; <a href="http://www.hacker10.com/other-computing/portable-hardware-vpn-device-farist-micro/">Continue reading <span class="meta-nav">&#8594;</span></a><div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/computer-security/use-a-vpn-on-a-computer-without-admin-rights/"     class="crp_title">Use a VPN on a computer without admin rights</a></li><li><a href="http://www.hacker10.com/internet-anonymity/how-to-stop-your-ip-being-exposed-after-vpn-disconnection/"     class="crp_title">How to stop your IP being exposed after VPN disconnection</a></li><li><a href="http://www.hacker10.com/computer-security/types-of-virtual-private-network-protocols-explained/"     class="crp_title">Types of Virtual Private Network protocols explained</a></li><li><a href="http://www.hacker10.com/internet-anonymity/review-free-vpn-provider-hotspotshield/"     class="crp_title">Review free VPN provider HotSpotShield</a></li><li><a href="http://www.hacker10.com/computer-security/create-your-own-virtual-private-network-with-neorouter/"     class="crp_title">Create your own Virtual Private Network with NeoRouter</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>Färist Micro from Swedish company Tutus is a tiny VPN device that fits in the palm of your hand and sits in between your computer and Internet connection. The A100 model has a shock resistant case made of aluminium and carbon fibre, with two Ethernet RJ45 ports, the standard port for a wired Internet connection, Färist Micro can be powered with an USB cable or via a separate power supply, both included, the A200 model is slightly bigger but it has better performance and status LED indicators showing VPN activity, the product security core is based on other evaluated Färist products and compatible with their suite of network security solutions, like a firewall.</p>
<p>The user interface has basic administrative functions accessible via web browser, with this tiny portable VPN device company employees can safely communicate over untrusted networks in hotels and airport Wifi access points, of course for real security a company fully encrypted laptop would have to be used at all times, using a portable VPN like Färist Micro on someone&#8217;s else computer would nullify all security since it won&#8217;t protect you against key-loggers and malware.</p>
<div id="attachment_7856" class="wp-caption aligncenter" style="width: 460px"><img class="size-full wp-image-7856" alt="Portable VPN Färist Micro" src="http://www.hacker10.com/wp-content/uploads/2013/05/Färist-Micro-portable-VPN.jpg" width="450" height="300" /><p class="wp-caption-text">Portable VPN Färist Micro</p></div>
<p>Once Färist Micro has been configured it requires no interaction from the end user, plugging it in will secure all communications routing traffic over the company VPN, this portable VPN has been jointly developed by Tutus, the Swedish Armed Forces and Swedish Defence Administration, it has been approved by the European Union to protect classified EU information up to the EU Restricted level, Tutus products are also sold under other brands like SecuriGateway, with the same specs, it only changes the brand name.</p>
<p>The VPN case looks extremely resistant, I wish there was something like this for home users configurable with a consumer grade VPN like <span style="color: #0000ff;"><a title="IPVanish" href="http://www.ipvanish.com?a_aid=privacy" target="_blank"><span style="color: #0000ff;">IPVanish</span></a></span>, Färist Micro is targeted at companies and government agencies, I don&#8217;t know how easy it would be to buy a single unit through a reseller, the ones I visited do not list price and ask interested parts to contact them instead.</p>
<p style="text-align: center;"><strong><span style="color: #0000ff;"><a title="Färist Micro" href="http://www.tutus.se/products/farist-micro.html" target="_blank"><span style="color: #0000ff;">Visit Färist Micro homepage</span></a></span></strong></p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/computer-security/use-a-vpn-on-a-computer-without-admin-rights/"     class="crp_title">Use a VPN on a computer without admin rights</a></li><li><a href="http://www.hacker10.com/internet-anonymity/how-to-stop-your-ip-being-exposed-after-vpn-disconnection/"     class="crp_title">How to stop your IP being exposed after VPN disconnection</a></li><li><a href="http://www.hacker10.com/computer-security/types-of-virtual-private-network-protocols-explained/"     class="crp_title">Types of Virtual Private Network protocols explained</a></li><li><a href="http://www.hacker10.com/internet-anonymity/review-free-vpn-provider-hotspotshield/"     class="crp_title">Review free VPN provider HotSpotShield</a></li><li><a href="http://www.hacker10.com/computer-security/create-your-own-virtual-private-network-with-neorouter/"     class="crp_title">Create your own Virtual Private Network with NeoRouter</a></li></ul></div><img src="http://feeds.feedburner.com/~r/hacker10hacker10/~4/zMmgQR0kM54" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.hacker10.com/other-computing/portable-hardware-vpn-device-farist-micro/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://www.hacker10.com/other-computing/portable-hardware-vpn-device-farist-micro/</feedburner:origLink></item>
		<item>
		<title>Moscrack wireless WPA cracking with cluster computers</title>
		<link>http://feedproxy.google.com/~r/hacker10hacker10/~3/1MhdY-Wlq60/</link>
		<comments>http://www.hacker10.com/other-computing/moscrack-wireless-wpa-cracking-with-cluster-computers/#comments</comments>
		<pubDate>Sun, 28 Apr 2013 04:18:24 +0000</pubDate>
		<dc:creator>Hacker10</dc:creator>
				<category><![CDATA[Other Computing]]></category>
		<category><![CDATA[cluster computer cracking]]></category>
		<category><![CDATA[Moscrack review]]></category>
		<category><![CDATA[wireless hacking]]></category>
		<category><![CDATA[WPA cracking]]></category>

		<guid isPermaLink="false">http://www.hacker10.com/?p=7823</guid>
		<description><![CDATA[The Multifarious On-demand Systems Cracker is a Perl application based on Aircrack-NG to crack wireless WPA keys using cluster computers, it can be deployed in Mosix, an operating system distributed across multiple Linux machines taking advantage of conglomerated computer processors &#8230; <a href="http://www.hacker10.com/other-computing/moscrack-wireless-wpa-cracking-with-cluster-computers/">Continue reading <span class="meta-nav">&#8594;</span></a><div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/computer-security/linux-distribution-for-wireless-hacking-xiaopan-os/"     class="crp_title">Linux distribution for wireless hacking Xiaopan OS</a></li><li><a href="http://www.hacker10.com/computer-security/brute-force-advanced-password-recovery-with-hashcat/"     class="crp_title">Brute force advanced password recovery with HashCat</a></li><li><a href="http://www.hacker10.com/computer-security/how-to-crack-a-zip-or-rar-password-protected-file/"     class="crp_title">How to crack a .zip or .rar password protected file?</a></li><li><a href="http://www.hacker10.com/mobile-phone/run-a-ssh-server-in-android/"     class="crp_title">Run a SSH server in Android</a></li><li><a href="http://www.hacker10.com/computer-security/free-windows-ssh-server-mobassh/"     class="crp_title">Free Windows SSH server MobaSSH</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The Multifarious On-demand Systems Cracker is a Perl application based on Aircrack-NG to crack wireless WPA keys using cluster computers, it can be deployed in Mosix, an operating system distributed across multiple Linux machines taking advantage of conglomerated computer processors or run in collective SSH nodes, clusters can be build up with any Unix operating system, including the iPhone, MacOSX, or Windows and Cygwin, it has also been tested on an Android phone running as a SSH node, best of all you can run Moscrack on the cheap from the Amazon EC2 cloud computing platform.</p>
<p>The program splits a word list into chunks and processes them in parallel in between all of the nodes. If you don&#8217;t have access to a computer cluster it is possible to use Moscrack with CUDA,  an NVIDIA parallel computing platform implemented in graphics cards, you will need to install  <em>aircrack-ng-cuda</em> and adjust <em>moscrack.conf </em>(configuration file).</p>
<div id="attachment_7834" class="wp-caption aligncenter" style="width: 460px"><img class="size-full wp-image-7834" alt="Moscrack cloud wireless WPA cracking" src="http://www.hacker10.com/wp-content/uploads/2013/04/Moscrack-cloud-WPA-wireless-cracking.jpg" width="450" height="270" /><p class="wp-caption-text">Moscrack cloud wireless WPA cracking</p></div>
<p>Moscrack command line interface shows a word list progress expressed in percentage, estimated completion time, running time, server status, cluster speed and other very complete verbose data, GUI interface is optional, it will be more suitable that you run the command line version to feel comfortable from the shell helping you to understand how concepts work, the GUI is pretty basic.</p>
<p>The program has been designed to run for weeks or months, you can leave it on and forget about the program until the job is done, functions go beyond WPA cracking, adding the Dehasher plugin will compare SHA256/512, DES, MD5 and Blowfish hashes to crack them, if you don&#8217;t wish to install this tool in your computer, a Moscrack Live CD running Suse Linux is available for download.</p>
<p style="text-align: center;"><strong><span style="color: #0000ff;"><a title="Moscrack" href="http://moscrack.sourceforge.net/" target="_blank"><span style="color: #0000ff;">Visit Moscrack homepage</span></a></span></strong></p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/computer-security/linux-distribution-for-wireless-hacking-xiaopan-os/"     class="crp_title">Linux distribution for wireless hacking Xiaopan OS</a></li><li><a href="http://www.hacker10.com/computer-security/brute-force-advanced-password-recovery-with-hashcat/"     class="crp_title">Brute force advanced password recovery with HashCat</a></li><li><a href="http://www.hacker10.com/computer-security/how-to-crack-a-zip-or-rar-password-protected-file/"     class="crp_title">How to crack a .zip or .rar password protected file?</a></li><li><a href="http://www.hacker10.com/mobile-phone/run-a-ssh-server-in-android/"     class="crp_title">Run a SSH server in Android</a></li><li><a href="http://www.hacker10.com/computer-security/free-windows-ssh-server-mobassh/"     class="crp_title">Free Windows SSH server MobaSSH</a></li></ul></div><img src="http://feeds.feedburner.com/~r/hacker10hacker10/~4/1MhdY-Wlq60" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.hacker10.com/other-computing/moscrack-wireless-wpa-cracking-with-cluster-computers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.hacker10.com/other-computing/moscrack-wireless-wpa-cracking-with-cluster-computers/</feedburner:origLink></item>
		<item>
		<title>Encrypted chat for iPhone and iPad with ChatSecure</title>
		<link>http://feedproxy.google.com/~r/hacker10hacker10/~3/empWAJOR2tU/</link>
		<comments>http://www.hacker10.com/mobile-phone/encrypted-chat-for-iphone-and-ipad-with-chatsecure/#comments</comments>
		<pubDate>Sat, 20 Apr 2013 20:25:17 +0000</pubDate>
		<dc:creator>Hacker10</dc:creator>
				<category><![CDATA[Mobile Phone]]></category>
		<category><![CDATA[ChatSecure review]]></category>
		<category><![CDATA[iPhone data encryption]]></category>
		<category><![CDATA[iPhone encrypted chat]]></category>

		<guid isPermaLink="false">http://www.hacker10.com/?p=7799</guid>
		<description><![CDATA[ChatSecure is a free iOS app for end to end encrypted chat with the Off The Record messaging system able to communicate with any chat software based on XMPP, like Google Talk, Jabber, Facebook, Oscar IM and Gibberbot in Android, &#8230; <a href="http://www.hacker10.com/mobile-phone/encrypted-chat-for-iphone-and-ipad-with-chatsecure/">Continue reading <span class="meta-nav">&#8594;</span></a><div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/mobile-phone/android-phone-encrypted-im-chat-with-gibberbot/"     class="crp_title">Android phone encrypted IM chat with Gibberbot</a></li><li><a href="http://www.hacker10.com/computer-security/create-an-encrypted-private-chat-room-with-privytalks/"     class="crp_title">Create an encrypted private chat room with PrivyTalks</a></li><li><a href="http://www.hacker10.com/computer-security/retroshare-p2p-encrypted-chat-and-filesharing/"     class="crp_title">Retroshare P2P encrypted chat and filesharing</a></li><li><a href="http://www.hacker10.com/other-computing/encrypted-chat-software-bitwise-im/"     class="crp_title">Encrypted chat software Bitwise IM</a></li><li><a href="http://www.hacker10.com/mobile-phone/armortext-android-app-to-encrypt-smsmms-messages/"     class="crp_title">ArmorText  Android app to encrypt SMS&#038;MMS messages</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>ChatSecure is a free iOS app for end to end encrypted chat with the Off The Record messaging system able to communicate with any chat software based on XMPP, like Google Talk, Jabber, Facebook, Oscar IM and <span style="color: #0000ff;"><a title="Gibberbot Android" href="http://www.hacker10.com/mobile-phone/android-phone-encrypted-im-chat-with-gibberbot/" target="_blank"><span style="color: #0000ff;">Gibberbot in Android</span></a></span>, it will not work with Yahoo Messenger or Skype contacts.</p>
<p>The app settings are simple but effective, you can change chat font size, set to autodelete chats on disconnect and get a warning before automatic sign out, your friends (Buddy list) chat accounts are accessible with a single tab on the side bar, each account has a logo indicating the messaging system your they are using, when you first establish a connection you will be shown the encryption key fingerprint and ask to verify it, this stops man in the middle attacks where someone injects a fake encryption key in between you and the other end to be able to listen in.</p>
<div id="attachment_7809" class="wp-caption aligncenter" style="width: 460px"><img class="size-full wp-image-7809" alt="ChatSecure encrypted iPad chat" src="http://www.hacker10.com/wp-content/uploads/2013/04/ChatSecure-encrypted-iPad-chat-fingerprint.jpg" width="450" height="295" /><p class="wp-caption-text">ChatSecure encrypted iPad chat</p></div>
<p>With this app there is no central server to store or monitor your data and third party eavesdropping is not possible because ChatSecure encrypts communications but you would still need to make sure that your acquaintance mobile device has not been stolen and he is who he claims to be, you also need to be aware that you are not anonymous in ChatSecure, the app will encrypt messaging but not hide the IP behind them, for anonymity add a VPN provider before starting the chat.</p>
<p>ChatSecure offers perfect forward secrecy, this means that temporary private encryption keys are generated for each session so if you lose them the keys can not be used to decrypt past chat logs or linked to you.</p>
<p style="text-align: center;"><strong><span style="color: #0000ff;"><a title="ChatSecure iPhone" href="https://itunes.apple.com/us/app/chatsecure-encrypted-secure/id464200063?mt=8" target="_blank"><span style="color: #0000ff;">Visit ChatSecure iTunes homepage</span></a></span></strong></p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/mobile-phone/android-phone-encrypted-im-chat-with-gibberbot/"     class="crp_title">Android phone encrypted IM chat with Gibberbot</a></li><li><a href="http://www.hacker10.com/computer-security/create-an-encrypted-private-chat-room-with-privytalks/"     class="crp_title">Create an encrypted private chat room with PrivyTalks</a></li><li><a href="http://www.hacker10.com/computer-security/retroshare-p2p-encrypted-chat-and-filesharing/"     class="crp_title">Retroshare P2P encrypted chat and filesharing</a></li><li><a href="http://www.hacker10.com/other-computing/encrypted-chat-software-bitwise-im/"     class="crp_title">Encrypted chat software Bitwise IM</a></li><li><a href="http://www.hacker10.com/mobile-phone/armortext-android-app-to-encrypt-smsmms-messages/"     class="crp_title">ArmorText  Android app to encrypt SMS&#038;MMS messages</a></li></ul></div><img src="http://feeds.feedburner.com/~r/hacker10hacker10/~4/empWAJOR2tU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.hacker10.com/mobile-phone/encrypted-chat-for-iphone-and-ipad-with-chatsecure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.hacker10.com/mobile-phone/encrypted-chat-for-iphone-and-ipad-with-chatsecure/</feedburner:origLink></item>
		<item>
		<title>Internet Relay Chat encryption with Dirt</title>
		<link>http://feedproxy.google.com/~r/hacker10hacker10/~3/thjlDDvsU6k/</link>
		<comments>http://www.hacker10.com/other-computing/internet-relay-chat-encryption-with-dirt/#comments</comments>
		<pubDate>Mon, 01 Apr 2013 07:14:50 +0000</pubDate>
		<dc:creator>Hacker10</dc:creator>
				<category><![CDATA[Other Computing]]></category>
		<category><![CDATA[dirt IRC encryption]]></category>
		<category><![CDATA[IRC chat encryption]]></category>
		<category><![CDATA[psyBNC alternative]]></category>

		<guid isPermaLink="false">http://www.hacker10.com/?p=7774</guid>
		<description><![CDATA[Dirt is an open source project adding FiSH compatible chat encryption to any IRC client, it can be used as Socks4 proxy or bouncer. Dirt only allows localhost (127.0.0.1) connections, this is to make sure that encrypted text will not &#8230; <a href="http://www.hacker10.com/other-computing/internet-relay-chat-encryption-with-dirt/">Continue reading <span class="meta-nav">&#8594;</span></a><div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/other-computing/how-the-fbi-used-computer-mac-addresses-against-lulzsec-hackers/"     class="crp_title">How the FBI used computer MAC addresses against Lulzsec&hellip;</a></li><li><a href="http://www.hacker10.com/internet-anonymity/occupyos-anonymous-operating-system-for-activists/"     class="crp_title">OccupyOS anonymous operating system for activists</a></li><li><a href="http://www.hacker10.com/mobile-phone/android-phone-encrypted-im-chat-with-gibberbot/"     class="crp_title">Android phone encrypted IM chat with Gibberbot</a></li><li><a href="http://www.hacker10.com/internet-anonymity/anonymous-messenger-chat-with-jtorchat/"     class="crp_title">Anonymous messenger chat with jTorchat</a></li><li><a href="http://www.hacker10.com/mobile-phone/encrypted-chat-for-iphone-and-ipad-with-chatsecure/"     class="crp_title">Encrypted chat for iPhone and iPad with ChatSecure</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>Dirt is an open source project adding FiSH compatible chat encryption to any IRC client, it can be used as Socks4 proxy or bouncer. Dirt only allows localhost (127.0.0.1) connections, this is to make sure that encrypted text will not leak out of your machine, the listening port for Socks4 is 1088 and the 6666 port is used when acting as a bouncer, settings can be changed modifying &#8220;<em>dirt.ini&#8221;</em> with a text editor.</p>
<p>After installation you will notice a Dirt icon in your system tray, to use Dirt in mIRC, a popular Windows IRC chat client, you need to access <em>Tools&gt;Options&gt;Connect&gt;Firewall</em> and enter the appropriate hostname (127.0.0.1) and port number. Once connected you can type <em>/dirt</em> to see a list of all possible commands,</p>
<div id="attachment_7775" class="wp-caption aligncenter" style="width: 460px"><img class="size-full wp-image-7775" alt="mIRC dirt encryption IRC chat" src="http://www.hacker10.com/wp-content/uploads/2013/03/mIRC-IRC-encryption-chat.jpg" width="450" height="299" /><p class="wp-caption-text">mIRC dirt encryption IRC chat</p></div>
<p>For those not aware, FiSH is a widely available IRC plugin providing Blowfish encryption grade to IRC chat, you can find it in the Linux command line irssi IRC client and many others. If you use a Mac computer or Debian Linux you could try FiSHLiM, a plugin for FiSH IRC encryption working in XChat and HexChat IRC chat clients.</p>
<p>Dirt works in Windows, Linux and BSD but it is still in development, another alternative could be using psyBNC, an IRC bouncer that replaces your computer IP with a virtual host (vHost) and supports channel encryption with Blowfish and IDEA algorithm, you will need a shell account to manage psyBNC, there are many companies offering them at cut-prize with easy configuration instructions, they are normally used by channel administrators to handle abuse.</p>
<p style="text-align: center;"><strong><span style="color: #0000ff;"><a title="IRC dirt encryption" href="http://dirtirc.sourceforge.net/" target="_blank"><span style="color: #0000ff;">Visit Dirt IRC encryption homepage</span></a></span></strong></p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/other-computing/how-the-fbi-used-computer-mac-addresses-against-lulzsec-hackers/"     class="crp_title">How the FBI used computer MAC addresses against Lulzsec&hellip;</a></li><li><a href="http://www.hacker10.com/internet-anonymity/occupyos-anonymous-operating-system-for-activists/"     class="crp_title">OccupyOS anonymous operating system for activists</a></li><li><a href="http://www.hacker10.com/mobile-phone/android-phone-encrypted-im-chat-with-gibberbot/"     class="crp_title">Android phone encrypted IM chat with Gibberbot</a></li><li><a href="http://www.hacker10.com/internet-anonymity/anonymous-messenger-chat-with-jtorchat/"     class="crp_title">Anonymous messenger chat with jTorchat</a></li><li><a href="http://www.hacker10.com/mobile-phone/encrypted-chat-for-iphone-and-ipad-with-chatsecure/"     class="crp_title">Encrypted chat for iPhone and iPad with ChatSecure</a></li></ul></div><img src="http://feeds.feedburner.com/~r/hacker10hacker10/~4/thjlDDvsU6k" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.hacker10.com/other-computing/internet-relay-chat-encryption-with-dirt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.hacker10.com/other-computing/internet-relay-chat-encryption-with-dirt/</feedburner:origLink></item>
		<item>
		<title>Android and iPhone Radio Police Scanner</title>
		<link>http://feedproxy.google.com/~r/hacker10hacker10/~3/dPlWGj8dIPc/</link>
		<comments>http://www.hacker10.com/mobile-phone/android-and-iphone-radio-police-scanner/#comments</comments>
		<pubDate>Wed, 20 Mar 2013 11:58:49 +0000</pubDate>
		<dc:creator>Hacker10</dc:creator>
				<category><![CDATA[Mobile Phone]]></category>
		<category><![CDATA[free radio police scanner]]></category>
		<category><![CDATA[Radio Police Scanner Lite]]></category>
		<category><![CDATA[smartphone police scanner]]></category>

		<guid isPermaLink="false">http://www.hacker10.com/?p=7752</guid>
		<description><![CDATA[Radio Police Scanner Lite is a free app preconfigured with a list of emergency services radio frequencies, it can listen in to firefighters, ham radio, aircraft and live police radio, each feed comes from a person owning a police scanner &#8230; <a href="http://www.hacker10.com/mobile-phone/android-and-iphone-radio-police-scanner/">Continue reading <span class="meta-nav">&#8594;</span></a><div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/mobile-phone/android-ssh-tunnel-hides-your-smartphone-ip/"     class="crp_title">Android SSH Tunnel hides your smartphone IP</a></li><li><a href="http://www.hacker10.com/computer-security/scan-for-other-wireless-connections-with-netsurveyor/"     class="crp_title">Scan for other wireless connections with NetSurveyor</a></li><li><a href="http://www.hacker10.com/internet-anonymity/review-free-vpn-provider-hotspotshield/"     class="crp_title">Review free VPN provider HotSpotShield</a></li><li><a href="http://www.hacker10.com/mobile-phone/android-truecrypt-compatible-app-eds-lite/"     class="crp_title">Android Truecrypt compatible app EDS Lite</a></li><li><a href="http://www.hacker10.com/computer-security/list-of-free-online-antivirus-scanners/"     class="crp_title">List of free online antivirus scanners</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>Radio Police Scanner Lite is a free app preconfigured with a list of emergency services radio frequencies, it can listen in to firefighters, ham radio, aircraft and live police radio, each feed comes from a person owning a police scanner in that geographical zone and sharing it via the Internet. Stations are classified by region and country with a built-in emergency services code to interpret what they are talking about, you can add any radio frequency broadcasted over the web in the RSS feeds link, it will automatically reconnect to the feed if it loses connection, favourites can be pinned to the front screen and accessible with a single tap.</p>
<p>There is only a delay of a couple of seconds in between the real talking and the broadcasting, you can browse the Internet while listening to a feed in the background, the only thing not guaranteed is that your country will be covered but the app is continuously expanding radio feeds, the paid for version of this app comes with thousands more of radio frequencies.</p>
<div id="attachment_7756" class="wp-caption aligncenter" style="width: 460px"><img class="size-full wp-image-7756" alt="Radio Police Scanner smartphone" src="http://www.hacker10.com/wp-content/uploads/2013/03/Radio-Police-Scanner-smartphone.jpg" width="450" height="300" /><p class="wp-caption-text">Radio Police Scanner smartphone</p></div>
<p>Many of the radio frequencies will be silent, the best way to spot what are the most active channels is by looking at the popularity of each feed, the more listeners the more likely it is that there is something going on or talking.</p>
<p>Investigation departments use encrypted radios to communicate during surveillance operations you won&#8217;t be able to listen to those, the radio will broadcast a routine police or firefighters working day. Police radio scanners are legal in many US states but is best that you check your local laws before using it as there are some restrictions like for example using a police scanner to impersonate a police officer, alternatively you can also listen to live emergency services online via your browser at Broadcastify.</p>
<p style="text-align: left;"><strong><span style="color: #0000ff;"><a title="Radio Police Scanner Lite" href="https://play.google.com/store/apps/details?id=com.berobo.android.scanner" target="_blank"><span style="color: #0000ff;">Visit Radio Police Scanner Lite in GooglePlay</span></a></span></strong></p>
<p style="text-align: left;"><strong><span style="color: #0000ff;"><a title="Radio Police Scanner Lite" href="https://itunes.apple.com/us/app/5-0-radio-police-scanner-lite/id356336433?mt=8" target="_blank"><span style="color: #0000ff;">Visit Radio Police Scanner Lite in iTunes</span></a></span></strong></p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.hacker10.com/mobile-phone/android-ssh-tunnel-hides-your-smartphone-ip/"     class="crp_title">Android SSH Tunnel hides your smartphone IP</a></li><li><a href="http://www.hacker10.com/computer-security/scan-for-other-wireless-connections-with-netsurveyor/"     class="crp_title">Scan for other wireless connections with NetSurveyor</a></li><li><a href="http://www.hacker10.com/internet-anonymity/review-free-vpn-provider-hotspotshield/"     class="crp_title">Review free VPN provider HotSpotShield</a></li><li><a href="http://www.hacker10.com/mobile-phone/android-truecrypt-compatible-app-eds-lite/"     class="crp_title">Android Truecrypt compatible app EDS Lite</a></li><li><a href="http://www.hacker10.com/computer-security/list-of-free-online-antivirus-scanners/"     class="crp_title">List of free online antivirus scanners</a></li></ul></div><img src="http://feeds.feedburner.com/~r/hacker10hacker10/~4/dPlWGj8dIPc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.hacker10.com/mobile-phone/android-and-iphone-radio-police-scanner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.hacker10.com/mobile-phone/android-and-iphone-radio-police-scanner/</feedburner:origLink></item>
	</channel>
</rss>
