International Journal of Network Security & Its Applications (IJNSA), Vol.5, No.4, July 2013
DOI : 10.5121/ijnsa.2013.5402 23
Marc A. Rader1 and Syed (Shawon) M. Rahman2, *
1CapellaUniversity, Minneapolis, MN, USA and Associate Faculty, Cochise CollegeAZ, USA
Mrader3@CapellaUniversity.edu
Associate Professor of Computer Science at the University of Hawaii-Hilo, Hawaii,
USA and Part-time Faculty at Capella University, Minneapolis, USA
*SRahman@hawaii.edu
ABSTRACT
Organizations invest heavily in technical controls for their Information Assurance (IA) infrastructure.
These technical controls mitigate and reduce the risk of damage caused by outsider attacks. Most
organizations rely on training to mitigate and reduce risk of non-technical attacks such as social
engineering. Organizations lump IA training into small modules that personnel typically rush through
because the training programs lack enough depth and creativity to keep a trainee engaged. The key to
retaining knowledge is making the information memorable. This paper describes common and emerging
attack vectors and how to lower and mitigate the associated risks.
KEY WORDS
Security Risks, Phishing, Social Engineering, Cross Site Scripting, Emerging Attack Vectors, DNS poising.
1. INTRODUCTION
Phishing is a social engineering technique that is used to bypass technical controls implemented
to mitigate security risks in information systems. People are the weakest link in any security
program. Phishing capitalizes on this weakness and exploits human nature in order to gain access
to a system or to defraud a person of their assets.
A 19-year-old hacker who published provocative photos of teen queen Miley Cyrus earlier this year was raided by the FBI Monday morning in Murfreesboro, Tennessee.
The hacker, Josh Holly, repeatedly bragged online about breaking into the Disney star’s e-mail account and stealing her photos. He also gave interviews to bloggers and others and boasted that authorities would never find him because he moved so often. [Last month, Holly contacted Threat Level seeking to have an article written about him here.]
But this morning the FBI did find him and, after talking with him for more than an hour about his exploits, served him with a search warrant and a list of items to be seized (which was posted at the hacking site digitalgangster.com after Holly showed it to a friend).
FEDERATION – GUIDANCE FOR OVERHEAD AND STAFF USERS
————————————————–
July 23 1995
Introduction
~~~~~~~~~~~~
Hi! – and welcome to Federation. This document is intended to provide
guidance for overhead and staff account holders on AOL who are playing
Federation (referred to as OHs in this document).
As an OH playing Federation you are in a privileged position, because
we do not get paid for your usage. Because you are in a position of
privilege, you have obligations to AOL and the Federation team that paying
players do not.
At the moment, we allow any OH to play Fed, but bear in mind that if your
presence in Fed starts to cause us problems then you will be locked out of
the game, and if we get too many problems with OHs we will simply stop all
OHs from playing.
AppName: Mini Oblivion
Versin: 0.1
Coder: Stan
Group: The Ratpack
Website: http://oblivionrat.cjb.net
–=Disclaimer=–
Mini Oblivion is meant to be used for legal purposes only. Since it is beyond the author’s control of what Mini Oblivion is used for, the author of Mini Oblivion can not be held accountable for anything you do with this program.
–=About Mini Oblivion=–
Mini Oblivion is a RAT(Remote Administraton Tool) coded in C by Stan.
Stealth Proxy for Windows 95/98/NT/2000
OK. Neccesity is the mother of invention and this was something I needed a while back and finally got around to making. Basically, it’s a SOCKS 4/5 proxy server that runs in the background with no obvious signs that it’s doing so. The idea is, if you have access to a machine and want do ‘stuff’ anonymously and don’t trust public ‘anonymous’ proxy servers this might be for you.
farm9 README.txt for cryptcat
09-22-2000
Thanks for downloading cryptcat
This is a simple modification to netcat to add twofish encryption.
netcat was origianally written by the l0pht (hobbit and weld pond).
The portion of the code written by farm9 is being released as Open Source.
See the file ‘farm9 Public License Agreement.txt’ for info on Open Source licensing.
[Disclaimer]
–==LEET LINK AdvancedAccess Absolute Edition==–
This is FREE Software!
Author: c4rn3vil/NeophytesnVisualBasiX/Chris
Completed: September 24th – 2004
:—This MIGHT* work for DIALUP USERS – one of my buddies’ is using dialup and it worked for him, but however for the longterm extension …This DOES NOT work for DIALUP users!’
This is now fully equiped/ (coded internal with mstcp/ip+winsock/lan, data flows)
It runs now with a EVEN More sufficient encryption.
I’ve added a MP3 Player, [Tight]
I also Plugged in a ‘POPUP Blocker’ You’ll atleast need to have the screen open, ‘POPUP BLOCKER’ atleast.
You may minimize the pop up blocker. to leave the hastle of it getting infront of you.
This is the last Version of the LEET LINKS I’m doing!
I hope you enjoy this fine release by c4rn3vil/neophytesnvisualbasix/Chris.
Note: known error is that when you attempt to load proxies and you do not load them, it’ll call an arguement and program will fail, just reoping the program and do load the proxies, that’s what this program is for!






