<body><script type="text/javascript"> function setAttributeOnload(object, attribute, val) { if(window.addEventListener) { window.addEventListener('load', function(){ object[attribute] = val; }, false); } else { window.attachEvent('onload', function(){ object[attribute] = val; }); } } </script> <div id="navbar-iframe-container"></div> <script type="text/javascript" src="https://apis.google.com/js/platform.js"></script> <script type="text/javascript"> gapi.load("gapi.iframes:gapi.iframes.style.bubble", function() { if (gapi.iframes && gapi.iframes.getContext) { gapi.iframes.getContext().openChild({ url: 'https://www.blogger.com/navbar/9515291?origin\x3dhttp://dosshell.blogspot.com', where: document.getElementById("navbar-iframe-container"), id: "navbar-iframe", messageHandlersFilter: gapi.iframes.CROSS_ORIGIN_IFRAMES_FILTER, messageHandlers: { 'blogger-ping': function() {} } }); } }); </script>

Friday, September 09, 2005

All About The Ladies

Well I'm not quite sure what to do for this post. I recently was emailed by someone from a prominent University wondering if I could figure out how to get into the directory for his University. It's hard for me since I don't have direct access to the system at hand, but for you, it should be much easier. You simply need to work in the science that hackers have worked for ages. Reverse Engineering, Troubleshooting, and Social Engineering. By combining these three things then you should be able to find your way into the directories.

If we go the troubleshooting path then we would have to look at the setup. Not much in depth searching here. Figure out the mail system, use google (it always helps), learn how student web pages offered by the school are set up.

In reverse engineering you could learn the security setup and do research on how to bypass it. Figure out it's weaknesses. Perhaps even saving the entire website onto your hd and modifying the html in the document itself. This can be useful in getting to limited parts of the site and is commonly overlooked as a technique that could be used. This is one of my favorites personally.

Finally social engineering, you'll have to use this to con the tech people into telling you what you want and need to know about the system's security. If they're stupid enough they'll let you log in with their password and username. Plus if you talk a bit of tech with them they'll usually open up to ya. The best way around this is to never volunteer information. NEVER! this blog is MY personal exception to the rule.

I'll post again in a few days since this one kinda sucked.

AK

0 Comments:

Post a Comment

<< Home