kakku
Max Output Level: -59 dBFS
- Total Posts : 1646
- Joined: 2014/08/31 21:37:39
- Location: Finland
- Status: offline
Phone hack
I have been hacked twice now that I used s hospital's open WLAN. The hacker got my pæssword to Google twice. I cha nged two times and have not used the WLAN since. Any ideaa why he was able to do that? Google uses secure pæges.
Sonar X1 Studio, Duo-capture and Steinberg's UR22 mk2 interfaces, super fast (read snail like) dual core computers, Arturia the Player 25 and Goldstar midi keyboards, Samsung Galaxy Ace 2 phone kakku
|
bapu
Max Output Level: 0 dBFS
- Total Posts : 86000
- Joined: 2006/11/25 21:23:28
- Location: Thousand Oaks, CA
- Status: offline
Re: Phone hack
2015/12/06 17:49:17
(permalink)
☄ Helpfulby kakku 2015/12/06 21:03:59
clear text intercept is my best guess.
|
kakku
Max Output Level: -59 dBFS
- Total Posts : 1646
- Joined: 2014/08/31 21:37:39
- Location: Finland
- Status: offline
Re: Phone hack
2015/12/06 17:53:16
(permalink)
I wish I knew what that meantmeant but I csn find out. Thanks.
Sonar X1 Studio, Duo-capture and Steinberg's UR22 mk2 interfaces, super fast (read snail like) dual core computers, Arturia the Player 25 and Goldstar midi keyboards, Samsung Galaxy Ace 2 phone kakku
|
robert_e_bone
Moderator
- Total Posts : 8968
- Joined: 2007/12/26 22:09:28
- Location: Palatine, IL
- Status: offline
Re: Phone hack
2015/12/06 20:49:07
(permalink)
☼ Best Answerby kakku 2015/12/06 21:04:41
It's a means of intercepting supposedly encrypted packets of network traffic, by essentially fooling some travel points in the middle that you are to be trusted, and then all the encryption falls by the wayside. I have discovered on multiple occasions, folks camping out in airports using fake networks, to get unsuspecting business travelers to think they were getting onto free WiFi from the airport, or one of the shops, like a Starbucks or whatever, when they were really sucking up all kinds of network ID and password info. Bob Bone
Wisdom is a giant accumulation of "DOH!" Sonar: Platinum (x64), X3 (x64) Audio Interfaces: AudioBox 1818VSL, Steinberg UR-22 Computers: 1) i7-2600 k, 32 GB RAM, Windows 8.1 Pro x64 & 2) AMD A-10 7850 32 GB RAM Windows 10 Pro x64 Soft Synths: NI Komplete 8 Ultimate, Arturia V Collection, many others MIDI Controllers: M-Audio Axiom Pro 61, Keystation 88es Settings: 24-Bit, Sample Rate 48k, ASIO Buffer Size 128, Total Round Trip Latency 9.7 ms
|
kakku
Max Output Level: -59 dBFS
- Total Posts : 1646
- Joined: 2014/08/31 21:37:39
- Location: Finland
- Status: offline
Re: Phone hack
2015/12/06 21:01:26
(permalink)
Thank you Bob. That was enlighting.
Sonar X1 Studio, Duo-capture and Steinberg's UR22 mk2 interfaces, super fast (read snail like) dual core computers, Arturia the Player 25 and Goldstar midi keyboards, Samsung Galaxy Ace 2 phone kakku
|
robert_e_bone
Moderator
- Total Posts : 8968
- Joined: 2007/12/26 22:09:28
- Location: Palatine, IL
- Status: offline
Re: Phone hack
2015/12/06 21:10:57
(permalink)
☄ Helpfulby kakku 2015/12/06 21:23:59
Here is a link to just one method that recently worked - don't know if it still does or not, and I don't use gmail: https://sites.google.com/site/darkzonehackers/documents/_draft_post The above method uses a design/processing flaw in the password retrieval process that Gmail uses, and shows how easily poor quality review of code can be exploited with someone intent on defeating security systems. Many, if not most, of a kind of web hack attack called an SQL Injection Attack, works simply because of sloppy code release procedures and lazy coders that leave gaping holes in the security of their databases because of crappy editing and processing on web pages that access databases. And now, every company that makes an appliance wants to be able to connect it to the internet - why my TOASTER or refrigerator needs access to my home network I will never know - and never allow. Bob Bone
Wisdom is a giant accumulation of "DOH!" Sonar: Platinum (x64), X3 (x64) Audio Interfaces: AudioBox 1818VSL, Steinberg UR-22 Computers: 1) i7-2600 k, 32 GB RAM, Windows 8.1 Pro x64 & 2) AMD A-10 7850 32 GB RAM Windows 10 Pro x64 Soft Synths: NI Komplete 8 Ultimate, Arturia V Collection, many others MIDI Controllers: M-Audio Axiom Pro 61, Keystation 88es Settings: 24-Bit, Sample Rate 48k, ASIO Buffer Size 128, Total Round Trip Latency 9.7 ms
|
kakku
Max Output Level: -59 dBFS
- Total Posts : 1646
- Joined: 2014/08/31 21:37:39
- Location: Finland
- Status: offline
Re: Phone hack
2015/12/06 21:17:30
(permalink)
Thanks again Bob. You are like a superhero of it.
Sonar X1 Studio, Duo-capture and Steinberg's UR22 mk2 interfaces, super fast (read snail like) dual core computers, Arturia the Player 25 and Goldstar midi keyboards, Samsung Galaxy Ace 2 phone kakku
|
robert_e_bone
Moderator
- Total Posts : 8968
- Joined: 2007/12/26 22:09:28
- Location: Palatine, IL
- Status: offline
Re: Phone hack
2015/12/06 23:33:51
(permalink)
Nope - I did enjoy life as a computer programmer, but a lot of the security flaws are new - though based on fairly simple concepts. The best advice I give folks is to pay attention, and if you encounter something you are not sure about - don't click on the scary message - look it up on a different computer - reboot without calling the phone number that is threatening you with some blue screen of death - READ each install screen prior to clicking on Next. If you don't know who the email is from, don't trust it. And, NO banks EVER will ask you to click on a link to validate any information. ALWAYS type in your bank's web site info yourself, or store the site name as a bookmark/favorite, and I NEVER store passwords anywhere but in my head. MILLIONS of people fall for really obvious scams, all the time, simply because they don't pay attention. Bob Bone
Wisdom is a giant accumulation of "DOH!" Sonar: Platinum (x64), X3 (x64) Audio Interfaces: AudioBox 1818VSL, Steinberg UR-22 Computers: 1) i7-2600 k, 32 GB RAM, Windows 8.1 Pro x64 & 2) AMD A-10 7850 32 GB RAM Windows 10 Pro x64 Soft Synths: NI Komplete 8 Ultimate, Arturia V Collection, many others MIDI Controllers: M-Audio Axiom Pro 61, Keystation 88es Settings: 24-Bit, Sample Rate 48k, ASIO Buffer Size 128, Total Round Trip Latency 9.7 ms
|
kakku
Max Output Level: -59 dBFS
- Total Posts : 1646
- Joined: 2014/08/31 21:37:39
- Location: Finland
- Status: offline
Re: Phone hack
2015/12/07 04:49:34
(permalink)
Thanks again Bob. I have a habit of storing my passwords in just about everywhere out of reach. Though I do not always know which place is out of reach. For example I store passwords in my phones because it is so handy. Probably shouldn't do that.
Sonar X1 Studio, Duo-capture and Steinberg's UR22 mk2 interfaces, super fast (read snail like) dual core computers, Arturia the Player 25 and Goldstar midi keyboards, Samsung Galaxy Ace 2 phone kakku
|
robert_e_bone
Moderator
- Total Posts : 8968
- Joined: 2007/12/26 22:09:28
- Location: Palatine, IL
- Status: offline
Re: Phone hack
2015/12/07 09:24:57
(permalink)
Well, I think that phones are most likely the most likely exposure point to hacking attempts - they are ripe for exploitation and theft of personal data. If I am not mistaken, there have been cases where police were able to do a warrantless search of people's phone data, REQUIRING the phone owner to give them access, simply because the courts looked at a fingerprint ID mechanism on a phone differently than a more traditional password. But again, the real exposure is that your phone is exposed by potential flaws in ever-rapidly changing OS code for phones, as well as exposed because of web site flaws that allow things like Clear Case Intercepts to happen, AND, when you connect your phone through a public network, you have an even more insidious exposure. I would urge you to rethink the notion of keeping passwords stored on your phone. When I have some site I sign up for, where I need a user name and password, and I don't access that site frequently, I will often send an email to myself, with a subject line saying something like: Billy Bob's Crab Shack and Auto Detailing site account info, and then in the body of the email, I will add text that will clue me in to the user ID I used, and I will also add a password hint sentence that gives me and only me enough info to where I will understand what I used for a password. So, even if my email gets hacked, nobody would be able to figure out any of my user ID's and passwords for any of the sites I have set up accounts on. Best of it all for you - stay secure, Bob Bone
Wisdom is a giant accumulation of "DOH!" Sonar: Platinum (x64), X3 (x64) Audio Interfaces: AudioBox 1818VSL, Steinberg UR-22 Computers: 1) i7-2600 k, 32 GB RAM, Windows 8.1 Pro x64 & 2) AMD A-10 7850 32 GB RAM Windows 10 Pro x64 Soft Synths: NI Komplete 8 Ultimate, Arturia V Collection, many others MIDI Controllers: M-Audio Axiom Pro 61, Keystation 88es Settings: 24-Bit, Sample Rate 48k, ASIO Buffer Size 128, Total Round Trip Latency 9.7 ms
|
kakku
Max Output Level: -59 dBFS
- Total Posts : 1646
- Joined: 2014/08/31 21:37:39
- Location: Finland
- Status: offline
Re: Phone hack
2015/12/07 10:56:53
(permalink)
Thanks for the tips. I will rethink my password policy. Only problem is I have so complex password that I would need to renew them almost all.
Sonar X1 Studio, Duo-capture and Steinberg's UR22 mk2 interfaces, super fast (read snail like) dual core computers, Arturia the Player 25 and Goldstar midi keyboards, Samsung Galaxy Ace 2 phone kakku
|
Karyn
Ma-Ma
- Total Posts : 9200
- Joined: 2009/01/30 08:03:10
- Location: Lincoln, England.
- Status: offline
Re: Phone hack
2015/12/07 11:08:27
(permalink)
☄ Helpfulby craigb 2015/12/07 11:52:03
Bob, how do you know when your toast is ready if you don't allow your toaster to email you?
Mekashi Futo. Get 10% off all Waves plugins.Current DAW. i7-950, Gigabyte EX58-UD5, 12Gb RAM, 1Tb SSD, 2x2Tb HDD, nVidia GTX 260, Antec 1000W psu, Win7 64bit, Studio 192, Digimax FS, KRK RP8G2, Sonar Platinum
|
bapu
Max Output Level: 0 dBFS
- Total Posts : 86000
- Joined: 2006/11/25 21:23:28
- Location: Thousand Oaks, CA
- Status: offline
Re: Phone hack
2015/12/07 11:44:22
(permalink)
☄ Helpfulby Bert Guy 2015/12/07 12:06:31
Karyn Bob, how do you know when your toast is ready if you don't allow your toaster to email you?
He sends an email to the coffee maker to confirm the toast is ready. DUH!! Every Juan knows coffee makers are the most secure device on the internetz.
|
bapu
Max Output Level: 0 dBFS
- Total Posts : 86000
- Joined: 2006/11/25 21:23:28
- Location: Thousand Oaks, CA
- Status: offline
Re: Phone hack
2015/12/07 11:44:37
(permalink)
Welcome back Karyn. Where u b?
|
craigb
Max Output Level: 0 dBFS
- Total Posts : 41704
- Joined: 2009/01/28 23:13:04
- Location: The Pacific Northwestshire
- Status: offline
Re: Phone hack
2015/12/07 11:47:19
(permalink)
kakku Thanks for the tips. I will rethink my password policy. Only problem is I have so complex password that I would need to renew them almost all.
One way is to come up with a pattern you can remember, perhaps using a couple of words that allow you to change an "S" to a $ or an "O" to a 0 (zero). Then include an incremental number somewhere (some things won't let you start a password with a number, some won't let you end with a number, so consider putting it in-between two words). This way you can use all the usual requirements (capital letter, lowercase letter, special character and a number) without having to write anything down. Whenever you need to change it, just increment the middle number then, if you enter an incorrect password, you'll know what to try next. Examples: $ome01Word $ome02Word Etc.
Time for all of you to head over to Beyond My DAW!
|
bapu
Max Output Level: 0 dBFS
- Total Posts : 86000
- Joined: 2006/11/25 21:23:28
- Location: Thousand Oaks, CA
- Status: offline
Re: Phone hack
2015/12/07 11:49:13
(permalink)
|
Karyn
Ma-Ma
- Total Posts : 9200
- Joined: 2009/01/30 08:03:10
- Location: Lincoln, England.
- Status: offline
Re: Phone hack
2015/12/07 11:54:17
(permalink)
I use "Incorrect" as my standard password. If I ever forget it, or type it wrong, any system will respond with "Your password is incorrect" ...
Mekashi Futo. Get 10% off all Waves plugins.Current DAW. i7-950, Gigabyte EX58-UD5, 12Gb RAM, 1Tb SSD, 2x2Tb HDD, nVidia GTX 260, Antec 1000W psu, Win7 64bit, Studio 192, Digimax FS, KRK RP8G2, Sonar Platinum
|
Karyn
Ma-Ma
- Total Posts : 9200
- Joined: 2009/01/30 08:03:10
- Location: Lincoln, England.
- Status: offline
Re: Phone hack
2015/12/07 11:55:32
(permalink)
bapu Welcome back Karyn. Where u b?
Nowhere, just been quiet and busy.
Mekashi Futo. Get 10% off all Waves plugins.Current DAW. i7-950, Gigabyte EX58-UD5, 12Gb RAM, 1Tb SSD, 2x2Tb HDD, nVidia GTX 260, Antec 1000W psu, Win7 64bit, Studio 192, Digimax FS, KRK RP8G2, Sonar Platinum
|
robert_e_bone
Moderator
- Total Posts : 8968
- Joined: 2007/12/26 22:09:28
- Location: Palatine, IL
- Status: offline
Re: Phone hack
2015/12/07 13:12:03
(permalink)
kakku Thanks for the tips. I will rethink my password policy. Only problem is I have so complex password that I would need to renew them almost all.
All the password complexity in the world does you ZERO good if the device or manner they are stored in/on is NOT secure enough to prevent someone from bypassing flawed security measures, or a single failure of you not paying attention when either surfing or installing. Bob Bone
Wisdom is a giant accumulation of "DOH!" Sonar: Platinum (x64), X3 (x64) Audio Interfaces: AudioBox 1818VSL, Steinberg UR-22 Computers: 1) i7-2600 k, 32 GB RAM, Windows 8.1 Pro x64 & 2) AMD A-10 7850 32 GB RAM Windows 10 Pro x64 Soft Synths: NI Komplete 8 Ultimate, Arturia V Collection, many others MIDI Controllers: M-Audio Axiom Pro 61, Keystation 88es Settings: 24-Bit, Sample Rate 48k, ASIO Buffer Size 128, Total Round Trip Latency 9.7 ms
|
robert_e_bone
Moderator
- Total Posts : 8968
- Joined: 2007/12/26 22:09:28
- Location: Palatine, IL
- Status: offline
Re: Phone hack
2015/12/07 13:31:45
(permalink)
bapu
Karyn Bob, how do you know when your toast is ready if you don't allow your toaster to email you?
He sends an email to the coffee maker to confirm the toast is ready. DUH!! Every Juan knows coffee makers are the most secure device on the internetz.
Come on now, Bapu. I guess you missed the security bulletin on the Home Shopping Network, where they demonstrated that coffee makers are only secure IF you used the coupon code 'HotCoffee' when you purchased it, and further, Professor Juan Valdez from Columbian University (he is a DA - Doctor of Agriculture), has discovered that if either the coffee was secretly switched out to Taster's Choice OR he only drank half a cup on a regular basis, that indeed the coffee maker was then wide open to hacking. Nope - I have switched over to storing all of my passwords in my brand new Ronco Popeil's Bass-O-Matic. It stores everything as puree, and because I use the WHOLE password, it retains all the essential vitamins and minerals. In fact, 5 out of 4 cooking show judges recommend it. AND, because when I bought it, it was before midnight that night, I was able to set it up as RAID, because they gave me a SECOND Bass-O-Matic for FREE - I just had to pay a separate $68.53 for processing and handling. (That was kind of weird, actually, since they both came in the same box). I can even shoot cannon balls through my Bass-O-Matic, and it still floats! See, the product uses a revolutionary micro-fine polymer font, so nobody can read the fine print, and wait - there's MORE! Bob Bone
Wisdom is a giant accumulation of "DOH!" Sonar: Platinum (x64), X3 (x64) Audio Interfaces: AudioBox 1818VSL, Steinberg UR-22 Computers: 1) i7-2600 k, 32 GB RAM, Windows 8.1 Pro x64 & 2) AMD A-10 7850 32 GB RAM Windows 10 Pro x64 Soft Synths: NI Komplete 8 Ultimate, Arturia V Collection, many others MIDI Controllers: M-Audio Axiom Pro 61, Keystation 88es Settings: 24-Bit, Sample Rate 48k, ASIO Buffer Size 128, Total Round Trip Latency 9.7 ms
|
ampfixer
Max Output Level: -20 dBFS
- Total Posts : 5508
- Joined: 2010/12/12 20:11:50
- Location: Ontario
- Status: offline
Re: Phone hack
2015/12/07 14:32:04
(permalink)
I have Malwarebytes on my phone as well as AVG. If you use open wifi you don't know what you will be exposed to.
Regards, John I want to make it clear that I am an Eedjit. I have no direct, or indirect, knowledge of business, the music industry, forum threads or the meaning of life. I know about amps. WIN 10 Pro X64, I7-3770k 16 gigs, ASUS Z77 pro, AMD 7950 3 gig, Steinberg UR44, A-Pro 500, Sonar Platinum, KRK Rokit 6
|
SteveStrummerUK
Max Output Level: 0 dBFS
- Total Posts : 31112
- Joined: 2006/10/28 10:53:48
- Location: Worcester, England.
- Status: offline
Re: Phone hack
2015/12/07 19:51:39
(permalink)
bapu Brilliant cra1gb.
Phyxed
|
57Gregy
Max Output Level: 0 dBFS
- Total Posts : 14404
- Joined: 2004/05/31 17:04:17
- Location: Raleigh, North Carolina
- Status: offline
Re: Phone hack
2015/12/08 09:50:32
(permalink)
Karyn
bapu Welcome back Karyn. Where u b?
Nowhere, just been quiet and busy.
Why didn't you come and visit? Everybody knows this is nowhere.
|
bitflipper
01100010 01101001 01110100 01100110 01101100 01101
- Total Posts : 26036
- Joined: 2006/09/17 11:23:23
- Location: Everett, WA USA
- Status: offline
Re: Phone hack
2015/12/08 10:03:44
(permalink)
Karyn I use "Incorrect" as my standard password. If I ever forget it, or type it wrong, any system will respond with "Your password is incorrect" ...
If that's original, it's brilliant. OK, it's brilliant even if you didn't come up with it yourself. I keep my hundreds of passwords in an encrypted Word document in an encrypted, hidden folder. My computer is in a locked room with alarms, video surveillance and bars on the windows (no I'm not in prison, just paranoid). This superseded my previous method, which was sticky notes on the side of my monitor. I had to abandon that method when we went to flat-screens, which didn't have enough space on the sides for dozens of postits.
 All else is in doubt, so this is the truth I cling to. My Stuff
|
Moshkito
Max Output Level: -37.5 dBFS
- Total Posts : 3765
- Joined: 2015/01/26 13:29:07
- Status: offline
Re: Phone hack
2015/12/08 10:09:02
(permalink)
kakku I have been hacked twice now that I used s hospital's open WLAN. The hacker got my pæssword to Google twice. I cha nged two times and have not used the WLAN since. Any ideaa why he was able to do that? Google uses secure pæges.
I would go talk to a manager in the hospital? Either someone does not trust you, or someone is abusing the privilege. Nowadays, I'm not surprised, but you really should not be using the hospital lan for anything except football scores, cnn, or news ... for example. I wouldn't do email, either!
Music is not about notes and chords! My poem is not about the computer or monitor or letters! It's about how I was able to translate it from my insides!
|