Subj: Fwd: º^º^( InSide WaReZ Issue #2 (Part 1)^º^º
Date: 97-07-27 15:21:53 EDT
From: SPYER2000
To: BeAwareX1
Forwarded Message:
Subj: º^º^( InSide WaReZ Issue #2 (Part 1)^º^º
Date: 97-07-27 14:35:28 EDT
From: BuBBLe HoP
«–¥(TRauMaTiZeD MassMailer²·º ßy: ßaNiCKuLa)¥–»
«–¥(This one is Dedicated to TaSHa, BaNiCKuLa’s True Love!)¥–»
«–¥(This Mail took 33.61719 Seconds to send)¥–»
«–¥(There are 69 out of 73 people on the MM)¥–»
«–¥(There have been: 0 Un-Retrievable Mails on This MM)¥–»
«–¥(This is Mail Number: 6 of 19 Mails)¥–»
Subj: ¥—¤(J.a.W.)¤—(CaTwAtCh NaMeS)¤—¥)”UPDATED”
Date: 97-08-01 23:11:27 EDT
From: Bo0gYmAn
BCC: BeAwareX1
«–=•º|[ TRauMaTiZeD MassMailer ]|º•=–»
«–=•º|[ ßý: ßaÑiÇKuLa ]|º•=–»
«–=•º|[ Dedicated to Jenny in Heaven ]|º•=–»
«–=•º|[ Mail Number: 103 of 283 ‘]|º•=–»
«–=•º|[ Maybe Bo0gYmAn’s last MMs! ]|º•=–»
Forwarded Message:
Subj: ¥—¤(J.a.W.)¤—(CaTwAtCh NaMeS)¤—¥)”UPDATED”
Date: 97-07-24 03:25:15 EDT
From: BuBBLe HoP
ACK Tunneling Trojans
– Arne Vidstrom, arne.vidstrom@ntsecurity.nu
Summary
Trojans normally use ordinary TCP or UDP communication between their client and server parts. Any firewall between the attacker and the victim that blocks incoming traffic will usually stop all trojans from working. ICMP tunneling has existed for quite some time now, but if you block ICMP in the firewall you’ll be safe from that. This paper describes another concept, that I call ACK Tunneling. ACK Tunneling works through firewalls that don’t apply their rule sets on TCP ACK segments (ordinary packet filters belong to this class of firewalls).
Extracting Web Server Information using Telnet / by R a v e N
<===========================================================>
http://blacksun.box.sk
Welcome to yet another BSRF tutorial. This time, I will teach you most basic command in the HTTP protocol, and how it is possible to extract tons of web server information and other pieces of info using this command only and a telnet client.
Okay, you are about to learn what your browser does when you type in, say, blacksun.box.sk. First of all, it connects to blacksun.box.sk on port 80. If there is an answer on the other hand, which means that the port is open (the port is not closed or blocked by any filtering software, such as a firewall) and a TCP session can start, your browser would usually type this:
get url HTTP/1.1
(followed by a blank line)
T H E H A C K E R ‘ S H A N D B O O K
Copyright (c) Hugo Cornwall
All rights reserved
First published in Great Britain in 1985 by Century Communications Ltd
Portland House, 12-13 Greek Street, London W1V 5LE.
International Journal of Network Security & Its Applications (IJNSA), Vol.5, No.4, July 2013
DOI : 10.5121/ijnsa.2013.5402 23
Marc A. Rader1 and Syed (Shawon) M. Rahman2, *
1CapellaUniversity, Minneapolis, MN, USA and Associate Faculty, Cochise CollegeAZ, USA
Mrader3@CapellaUniversity.edu
Associate Professor of Computer Science at the University of Hawaii-Hilo, Hawaii,
USA and Part-time Faculty at Capella University, Minneapolis, USA
*SRahman@hawaii.edu
ABSTRACT
Organizations invest heavily in technical controls for their Information Assurance (IA) infrastructure.
These technical controls mitigate and reduce the risk of damage caused by outsider attacks. Most
organizations rely on training to mitigate and reduce risk of non-technical attacks such as social
engineering. Organizations lump IA training into small modules that personnel typically rush through
because the training programs lack enough depth and creativity to keep a trainee engaged. The key to
retaining knowledge is making the information memorable. This paper describes common and emerging
attack vectors and how to lower and mitigate the associated risks.
KEY WORDS
Security Risks, Phishing, Social Engineering, Cross Site Scripting, Emerging Attack Vectors, DNS poising.
1. INTRODUCTION
Phishing is a social engineering technique that is used to bypass technical controls implemented
to mitigate security risks in information systems. People are the weakest link in any security
program. Phishing capitalizes on this weakness and exploits human nature in order to gain access
to a system or to defraud a person of their assets.





