Showing posts with label facebook. Show all posts
Showing posts with label facebook. Show all posts

Monday, 6 January 2014

#OpExposeHeatherChua - Uncovering 'Her' McLaren

Here's another analysis of a picture Heather Chua posted claiming that 'she' owns a McLaren.



Let's take a look at this picture. Notice anything? Well, let's look closer shall we?



The First Two Mishaps




The 3rd and 4th Mishaps



Verdict

The plate number that we see here is NOT the original plate. The image of the plate number was deliberately taken, copied and pasted over the God knows whose McLaren... And again, 'she' cropped the picture to a point the whole car could not be seen so that it cant be searched online for similar images. You can fool many but not to those who have eyes for details...


Saturday, 4 January 2014

#OpExposeHeatherChua - Uncovering 'Her' Bentley

So the self declared rich, elite, well to do 'girl' Heather Chua who has been posting hate messages on 'her' Facebook account criticizing and insulting the Malays, the ITE students, the Middle class and the Poor is now the talk of the town. SMRT Ltd (Feedback), the page made famous from its constant awesome trolling of others has gone on a personal vendetta to find out who this person actually is. 

While i did my fair share of recon on this person, i realized that there have been many others who posted about their findings on 'her'. I already suspected 'her' to be a fake profile ever since i came across 'her' profile. To cut the story short, i did my part for the curious Singaporeans to analyze some of the photos 'she' posted and here is one of my analysis.

So on the 29th December, 'she' posted about her Bentley proudly talking about it on Facebook. Something just caught my eye and aroused myself to launch a 30 minute investigation/analysis on this picture she posted.

The Facebook Post and the Picture of 'her' Bentley.

Looks Normal? Well Look Closer....


Focus on the Plate Number and i found 3 mishaps


Now that's not all. 'Her' statement below also aroused my suspicion when she said "not only did i shade the number off but i also changed the background colour to another effect so don't bother asking." 


The only reason why she changed the color of the background is because she might not want others to do a cross image reference using online forensic image cross referencing tools. Google has the ability to allow users to upload any pic and Google will search, based on the color, background image, density, tone of the image uploaded and search its database to see whether similar photos are uploaded or located elsewhere. This could also be a reason why 'she' cropped her photos to a point where Image finder couldnt reference it with other pics. Well played 'Heather'. You might be able to fool some but you can't trick a trickster. 

Oh and 1 last thing. For a pretty woman who have it all, its weird for someone like 'her' to spend 80% of her time insulting others on Facebook. 





Friday, 3 January 2014

Like Dominoes they Fall One by One

Recently i received an email from my wife asking to help her as she was having financial problem in Norway. The moment i saw that, i knew it was a Spam. However, when i looked closer, i realized that when i clicked 'Reply', it was addressed to my wife's yahoo email address. I took a snapshot and sent it to my wife and informed her to quickly change her password. That's when my wife told me that she couldnt log in to her email account. Something was fishy.

The next thing i know, people started calling and messaging her on Facebook. According to the private messages, she was asking people in her friendlist for help and money. She got bombarded with calls of concern. To make matters worse, she could not log in to her Facebook as well as her Hotmail account.

30 minutes later, we realized that she was hacked! And she was not the only one. Over the last few weeks, i received news on my newsfeed how my other friends got their email accounts hacked and unable to log in as well. 

Thus, i went into a hunt for the hacker... (but this will be another story to post)

So i asked her whether her passwords were the same as the other accounts to which she replied No. All her 3 accounts have 3 different set of passwords which is a good thing. Then i asked her about the complexity of her passwords. With that i know why. 

Surprising Find

I went on a recon to find other victims to which the accounts were hacked. To my shocking surprise, i saw THOUSANDS of Yahoo, Hotmail, Gmail, Facebook accounts with passwords leaked out in the deep web! And they all have one thing in common: simple passwords! 

These are some of the accounts that was leaked.


I looked closely at the passwords combination used and i could tell that these passwords are easily guessed, simple combinations of alphabets and numbers. This is what we in the security community as WEAK passwords. 

10 years ago, a complex password would be at least 8 characters with a combination of alphabets and numbers. At that time, the technology for password cracking isn't as awesome and as fast as now hence the previous requirements was sufficient. But now, 8 characters is easily cracked especially when it is not complex enough. Another mistake that most of us make is using the same password for all other accounts. Thus it is not surprise when one account is hacked after another by using a single password. 

How Did the Hackers Hacked Then?

There are many ways a hacker could hack into our accounts. One of the ways i know is by collecting email addresses gathered by automatic scavengers tool and save it into a database. Once all these email addresses are collected, the hacker will run a cracker against a huge dictionary file or by other sophisticated crackers. All the hacker needs to do is to play the waiting game. Once the accounts are hacked, the hacker will publish it online, in forums and if they want to make a profit out of it, sell them to potential buyers and scammers. These scammers will then use the compromised account and start their phishing emails to the contacts in the email's address books. 

So How Can we Prevent this?

1. Use at least 16 characters long! Remember, the longer the better!
2. Raise the complexity of the passwords by using words that only YOU will know and not from the dictionary.
3. Use Uppercase and Lowercase alphabets
4. Use numbers
5. Use special characters such as &^%
6. Use different password for each account
7. Do not login to sites from public Wifi networks or LAN 
8. Do not provide your passwords from emails asking you to provide.
9. Provide contact number to the account for password reset. This is very important and a secure way to do password reset as only YOU would have your mobile phone/number and not the one in Nigeria.

A good example of a password is : UzuM@k!@P0C@l%p$3



Friday, 23 August 2013

Deleted Facebook Pictures: Are they really deleted?

We all love uploading photos to our Facebook wall and albums but sometimes we just wanna get rid of them for whatever reasons we have.. so we delete them and wash our hands...but the question is, are your deleted photos truly been deleted from the Facebook server?

Lets test it out...

Upload any pic to your Facebook wall.


Uploaded a pic and set the privacy to 'Only Me'


 Right Click on your newly uploaded pic and open the image in new tab.


 The new uploaded pic in a new tab.

Now, on the FB wall, delete the pic


Now go back to your pic that opened in a new tab and click refresh or reload. Still there? Now log out your FB account and refresh the pic. Still there?



In an article published in 2012, deleted photos was still online for 3 years!!

Scary isn't it? 


Here's the link to it, let's see how long it will take before the image/link expires.

Saturday, 29 June 2013

SET on BT5r3 - Stealing Facebook Credentials

In this tutorial, we will show you how to steal Facebook credentials using the Social Engineering Toolkit on BackTrack Linux.


Fire up the Social Engineering Toolkit from BackTrack.  Select 1 for the SET Attack.

 For this tutorial, we will use the Website Attack Vectors as our mechanism

Since we are going to steal the credential, we proceed to select 3

We will choose 2 to clone the site we are going to dupe.
Enter the IP address of where the clone site be hosted.
Enter the link of the website. In this case, we will clone the facebook login page.

 Once the site is cloned, provide the link/IP for the victim to enter. The victim will get the Facebook login page website.

And when the victim type in the username and password, the credentials will be sent to the attacker's console.