Early Phishing

Early Phishing

Koceilah Rekouche krekouche@pushstart.info

The history of phishing traces back in important ways to the mid-1990s when hacking
software facilitated the mass targeting of people in password stealing scams on America
Online (AOL). The first of these software programs was mine, called AOHell, and it was
where the word phishing was coined. The software provided an automated password
and credit card-stealing mechanism starting in January 1995. Though the practice of
tricking users in order to steal passwords or information possibly goes back to the
earliest days of computer networking, AOHell’s phishing system was the first automated
tool made publicly available for this purpose. 1 The program influenced the creation of
many other automated phishing systems that were made over a number of years. These
tools were available to amateurs who used them to engage in a countless number of
phishing attacks. By the later part of the decade, the activity moved from AOL to other
networks and eventually grew to involve professional criminals on the internet. What
began as a scheme by rebellious teenagers to steal passwords evolved into one of the
top computer security threats affecting people, corporations, and governments.

Exploring Historical & Emerging Phishing Techniques

Exploring Historical & Emerging Phishing Techniques

International Journal of Network Security & Its Applications (IJNSA), Vol.5, No.4, July 2013
DOI : 10.5121/ijnsa.2013.5402 23

Marc A. Rader1 and Syed (Shawon) M. Rahman2, *
1CapellaUniversity, Minneapolis, MN, USA and Associate Faculty, Cochise CollegeAZ, USA
Mrader3@CapellaUniversity.edu
Associate Professor of Computer Science at the University of Hawaii-Hilo, Hawaii,
USA and Part-time Faculty at Capella University, Minneapolis, USA
*SRahman@hawaii.edu
ABSTRACT
Organizations invest heavily in technical controls for their Information Assurance (IA) infrastructure.
These technical controls mitigate and reduce the risk of damage caused by outsider attacks. Most
organizations rely on training to mitigate and reduce risk of non-technical attacks such as social
engineering. Organizations lump IA training into small modules that personnel typically rush through
because the training programs lack enough depth and creativity to keep a trainee engaged. The key to
retaining knowledge is making the information memorable. This paper describes common and emerging
attack vectors and how to lower and mitigate the associated risks.
KEY WORDS
Security Risks, Phishing, Social Engineering, Cross Site Scripting, Emerging Attack Vectors, DNS poising.
1. INTRODUCTION
Phishing is a social engineering technique that is used to bypass technical controls implemented
to mitigate security risks in information systems. People are the weakest link in any security
program. Phishing capitalizes on this weakness and exploits human nature in order to gain access
to a system or to defraud a person of their assets.

Miley Cyrus Hacker Raided by FBI

Miley Cyrus Hacker Raided by FBI

A 19-year-old hacker who published provocative photos of teen queen Miley Cyrus earlier this year was raided by the FBI Monday morning in Murfreesboro, Tennessee.

The hacker, Josh Holly, repeatedly bragged online about breaking into the Disney star’s e-mail account and stealing her photos. He also gave interviews to bloggers and others and boasted that authorities would never find him because he moved so often. [Last month, Holly contacted Threat Level seeking to have an article written about him here.]

But this morning the FBI did find him and, after talking with him for more than an hour about his exploits, served him with a search warrant and a list of items to be seized (which was posted at the hacking site digitalgangster.com after Holly showed it to a friend).

mileycyrus2

 

Inside-AOL.com

Inside-AOL.com

2014-10-24 00_06_19-Welcome To The Insider.

 

Inside-AOL was started in 1998.intro3

If you have already read the disclaimer and agree with it you may enter here.
 
Some artwork, logos, and information are Copyright 1997, America Online, inc. ALL Information on this site is legal in its original content. This site is legal under U.S. fair use copyright law, which states anyone can use copyrighted materials in criticism, review, or parody. Use of AOL artwork and screen shots are used in the content of criticism of America Online’s service and security. This site does not wish to encourage any illegal activity.
 
Inside-AOL is a private operation, My Internet Service Provider is not responsible for ANYTHING found on this site. If you have questions or comments about Inside-AOL, you must contact the webmaster.
If you Agree, Click to enter Inside-AOL

Adrian Lamo and FBI Cyber Squad computer scientist Russell Handorf

Adrian Lamo and FBI Cyber Squad computer scientist Russell Handorf

10/18/12 Update: 2006 posting at forum - where Russell Handorf still contributes using his "grey hat hacker" handle "satanklawz" - suggests he has been working for FBI three years earlier than his resume claims; Adrian Lamo admits being "friends" with Handorf but still won't answer any real questions; Chet Uber offers to have Lamo "interview" me - Neal Rauhauser, who claims he has nothing to.....

‘Kryogeniks’ hacker sentenced for Comcast hacking


No PII involved in this one, but since many may remember the case, I thought I’d post the follow-up. James Robert Black, Jr., a.k.a. “Defiant,” was sentenced yesterday in U.S. District Court in Tacoma to four months in prison, four months of electronic home monitoring, 150 hours of community service, three years of supervised release and $128,557 in restitution for conspiring to damage a protected.....

Kryogeniks Hacker Who Took Comcast Offline Pleads Guilty to Crime

Kryogeniks Hacker Who Took Comcast Offline Pleads Guilty to Crime

Christopher Allen Lewis, the hacker from a telephone hacking group called Kryogeniks, has pleaded guilty for taking Comcast's web site offline in May of 2008. Lewis is facing a charge that could land him in prison for five years and a $250,000 fine after his guilty plea to one count of conspiracy to intentionally damage a protected computer system. The case is being tried in.....

Flashback to 1995

Flashback to 1995

Flashback to 1995: AOL Proggies By Marco on April 19, 2004 Inspired by a discussion on the Something Awful Forums, I remembered the time I spent using AOL in middle school. There were these programs ("proggies") that would hook into the AOL software and allow you to do special things, like easily type using color-faded text or extended ASCII characters. I had one of these.....

Jaguar32.bas

Jaguar32.bas

'Jaguar32.Bas Silver Edition FIXED '(For Visual Basic Versions 4, 5, 6) 'For use with Aol (95 and 4.0) 'Release Date: Christmas of '98 'Please note disclaimer at bottom along with Fader notes from monk-e-god 'Do NOT copy bas file under any conditions. See disclaimer. ' Use Jaguar32 at your own risk. We are not responsible for anything 'made using or while using jaguar32. 'Creators contact.....

GUIDANCE FOR OVERHEAD AND STAFF USERS [Doc]


FEDERATION – GUIDANCE FOR OVERHEAD AND STAFF USERS
————————————————–
July 23 1995
Introduction
~~~~~~~~~~~~
Hi! – and welcome to Federation. This document is intended to provide
guidance for overhead and staff account holders on AOL who are playing
Federation (referred to as OHs in this document).

As an OH playing Federation you are in a privileged position, because
we do not get paid for your usage. Because you are in a position of
privilege, you have obligations to AOL and the Federation team that paying
players do not.

At the moment, we allow any OH to play Fed, but bear in mind that if your
presence in Fed starts to cause us problems then you will be locked out of
the game, and if we get too many problems with OHs we will simply stop all
OHs from playing.