Slyr0x's Posts
Nairaland Forum › Slyr0x's Profile › Slyr0x's Posts
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 (of 81 pages)
Luedave: really u think i know a 12year old coding 4rm his head not a joke nd he's a 9jerianHow old are you now and what have you done since you started? |
This picture describes perfectly what SSL does https://edge1.digicert.com/images/public-key.jpg Does SSL Prevent Hacking? [size=14pt]NO![/size] SSL simply encrypts the data in transit. .and protects users of your site from having their communications intercepted by a 3rd party. An SSL certificate does not validate the content of your site, nor does it prevent anyone from breaking into your site as a result of poor coding. So let's say a web app vuln like SQL Injection exists on your website/ web app, having a SSL certificate WON'T stop the hacker from dumping your database. . People tend to have that misconception and feel they are HACK-PROOF the moment they install SSL cert. Moving forward, even the sole function the SSL has been known to do i.e. encrypt connection in transit has been compromised. In 2009, a hacker g0tmi1k released a Proof Of Concept where he stripped the SSL (i.e. Stripped off the S behind https:// and then sniffed the connection). Nothing is safe out there folks! |
https://saharareporters.com/sites/default/files/imagecache/news-page-images-480-wide/page_images/news/2013/ar%205_0.jpg https://saharareporters.com/sites/default/files/imagecache/news-page-images-480-wide/page_images/news/2013/ar%206_0.jpg https://saharareporters.com/sites/default/files/imagecache/news-page-images-480-wide/page_images/news/2013/ar%201_0.jpg |
^^^Nice one. .Very comprehensive and well detailed. Kudos |
www..net looks distorted on my mobile device |
GTBank == Joomla; |
Check your spam folder |
Yinksey: When u are using PDO Extension with php to deal with mysql, you dont need to worry about sql injection.This is not entirely true. Using the PDO prepared statement is sufficient to prevent 1st order injection (i.e. it takes this input and filters it before inserting into the DB). . However, for 2nd order injection, let's look at this scenario : We have an ecommerce web application that has the "wish list" enabled. .Imagine the user types in '; DELETE Users;-. .Using prepared statement, the initial apostrophe gets deleted however the seemingly innocent-looking text gets inserted like this INSERT Wishlist (ID, Item, City, Country) Now, 1st order injection has been prevented. .However, when the user decides to display his wishlists with the query SELECT * FROM Wishlist WHERE ID = '', Item);becomes SELECT * FROM Wishlist WHERE ID = '', DELETE Users;--); This innocent-looking query just deleted the Table "Users". . Having said this, Using only prepared statements is not sufficient to protect against sql injection attacks. .however, it's a step in the right direction |
brushesz: //Have you successfully injected via data fields or "?" edit before?Yes. brushesz: if (true){It was an enlightening experience ![]() |
brushesz: Feel free to share your experience and knowledgeHow do you mean? |
flexpro: @ OP, to be honest with you, i hate paypal for exempting Nigeria from the list of countries on its platform.+ 1000000. The intriguing part is countries like Russia, USA, China, Britain, Germany, Brazil, Spain, India, France, Turkey top the Cybercrime list yet Paypal won't discontinue its service(s) in such countries. We are only being unnecessarily victimised. |
GraphicsPlus: I will rather allow US government to intercept my data than to think that Snowden is a hero. Snowden is a traitor and US government means well for its citizens.In revealing the colossal scale of the U.S. government’s eavesdropping on Americans and other people around the world, Snowden has performed a great public service that more than outweighs any breach of trust he may have committed. Thanks to Snowden, the whole world now knows “The N.S.A. has built an infrastructure that allows it to intercept almost everything. With this capability, the vast majority of human communications are automatically ingested without targeting.” Snowden lived a "very comfortable" life earning a salary of roughly US$200,000. .about #32million naira per annum. .Point out a man that'ld give away all that + his privacy + his freedom + his family . . So what exactly is Snowden’s real crime? Why is he being haunted? All 'cos he uncovered questionable activities that those in power would rather have kept secret. In my humble opinion, Snowden is a man of conscience! In his words, “I don’t want to live in a society that does these sort of things. .I do not want to live in a world where everything I do and say is recorded. That is not something I am willing to support or live under.” I still insist that Snowden is a hero!!! |
Slyr0x: "This experience," Levinson wrote, "has taught me one very important lesson: without congressional action or a strong judicial precedent, I would strongly recommend against anyone trusting their private data to a company with physical ties to the United States." ®Food for thought! |
Lavabit, the security-conscious email provider that was the preferred email service of NSA leaker Edward Snowden, has closed its doors, citing US government interference. "I have been forced to make a difficult decision: to become complicit in crimes against the American people or walk away from nearly ten years of hard work by shutting down Lavabit," founder Ladar Levinson said in a statement posted to the company's homepage on Thursday. "After significant soul searching, I have decided to suspend operations." Prior to its closure, Lavabit was a dedicated email service that offered subscribers "the freedom of running your own email server – without the hassle or expense." In addition to a variety of flexible configuration options, the service boasted that all email stored on its servers was encrypted using asymmetric elliptical curve cryptography, in such a way that it was impossible to discern the contents of any email without knowing the user's password. As a whitepaper posted to the company's website (now removed, but available from the Internet Archive) observed: Our goal was to make invading a user's privacy difficult, by protecting messages at their most vulnerable point. That doesn't mean a dedicated attacker, like the United States government, couldn't intercept the message in transit or once it reaches your computer. Our hope is the difficulty associated with those strategies means they will only be used by governments on terrorists and scammers, not on honest citizens. It now seems, however, that Levinson's hope was just wishful thinking. Without going into details, his statement on Thursday made plain that pressure from the US government was behind his decision to shutter Lavabit. "I feel you deserve to know what's going on – the first amendment is supposed to guarantee me the freedom to speak out in situations like this," Levinson wrote. "Unfortunately, Congress has passed laws that say otherwise. As things currently stand, I cannot share my experiences over the last six weeks, even though I have twice made the appropriate requests." Under current US law, requests for information by US intelligence agencies often carry a gag order that forbids the party receiving the request from disclosing what information was requested, or even that a request was made at all. The gag orders can be challenged by appealing to the shadowy Foreign Intelligence Surveillance Court (FISC), which operates in complete secrecy, but such appeals are seldom granted. Not even Google or Microsoft – each of which, it must be said, has far deeper pockets than Lavabit – has managed to challenge the surveillance orders. Both companies were named by Snowden as having turned over user data to government spies under the secretive PRISM program, but the FISC won't allow them to reveal to the public what they may or may not have actually disclosed. Little wonder, then, that Levinson's "appropriate requests" have similarly been denied. The Lavabit founder says he next plans to challenge the government's ruling in the US Fourth Circuit Court of Appeals. A favorable ruling, he says, would allow him to "resurrect Lavabit as an American company" – though he doesn't appear to hold out much hope. "This experience," Levinson wrote, "has taught me one very important lesson: without congressional action or a strong judicial precedent, I would strongly recommend against anyone trusting their private data to a company with physical ties to the United States." ® http://www.theregister.co.uk/2013/08/08/lavabit_shuts_down/ |
CreativeWeb: Hello NairaLanders, thank you all for the good works you are doing here. I am new here and my name is Decency.Decent approach ![]() |
databoy247: Boss i have always suspected that you are a wordpress guruOga me, I dey try small |
greenmouse: Pls downlaod, listen and review our latest jingle on radios.link |
antontech: its not thereIf you don't mind, send me your wp login details |
Guy, you no try at all oo. .I actually prefer the former website |
Great Initiative. You have our support |
onajo2000 Thank you oo. .I don taya to dey explain |
spikes C: So, i can only assume that there's something reading and resaving the files on my server. Antiviruses can do that, backups and server changes does that, if you have a load balancer, you'll definitely experience it. So, like i said, it would be a total waste of resources for me.Reading and Writing are TOTALLY different. Antivirus scanners can scan your files, read the content for signatures etc. . .but they will NEVER write to your files. Any attempt to edit/change your files without your knowledge is termed "malicious". spikes C: So, like i said, it would be a total waste of resources for me.Better safe than sorry bro ![]() |
naturalwaves: When I had the problem too, I thought it will be that easy. The last process says you should follow the sign in process after getting the verification on your mobile device. When the code was sent to me then, it came with a link to continue, after I did that, it still asked for the security question which was surprising to me cos I didn't know it will ask that again after chosing the mobile option. I had to eventually think and think well before I could get my answer and I was good to go. Same thing applies to gmail except if yahoo just changed the process which I doubt. Why not do the practicals and stop quoting links.I told you something from my own personal experience, you didn't believe. I went ahead to give you a direct link posted on yahoo's website to further buttress my point http://help.yahoo.com/kb/index?locale=en_US&page=content&id=SLN2694 but you said it's just theory. I give up. |
naturalwaves: Like I said, I have been through the process before so I know what I am saying. You only stated the start process without finishing it. The question is......did you change your password? I guess NO. Well, I have changed my password through that feature like two times in the past so let me start from where you stopped. When you get that verification through your mobile device, you will go back to the net link and put it there. When you submit, it will take you to the final verification process in which the security question prompts up. If you cannot provide a correct answer to that question, there is no way and it will be better you just open a new email addy cos it will never be succesful.Calm down oga and Learn. . Yahoo has 3 options : 1.) Send a verification link to an alternate email address 2.) Send a verification code to your phone number 3.) Answer your secret questions. Using your mobile phone number for password recoveryhttp://help.yahoo.com/kb/index?locale=en_US&page=content&id=SLN2694 |
Samoo01: Since when did Yahoo begin to accept Nigerian phone numbers in its password recovery page?Find attached the screenshot (I'm sure you can see the +234)
|
naturalwaves: This story looks like an Abracadabra and it is difficult to believe. Even if it is that easy getting a sim swapped on Airtel, when the supposed cracker wanted to contact Yahoo, did he just get a Password just like that from Yahoo? Impossible! Getting your password changed on Yahoo isn't that easy. Okay? And the Domain Name Registrer too gave out another Password on sighting just a note for a change of password? I haven't read something as hilarious and ridiculous as this claim in a long while even if you go to court with this crap, you will outrightly lose the case on the first day.1. Click on Yahoo's Forgot My Password feature >> Yahoo asks for your phone number (one of the security options you opted for) >> You put in the phone number >> Yahoo sends you a verification code or they call you >> You type in the 6characters verification code and voila. .you are in. 2. For the Domain Name Registrar, that part is quite simple. The only email account connected to them is the hacked one. So basically, the forgot my password feature comes to play again. Request for a new password and a link gets sent to your mail. |
Duplicate thread. Continue here https://www.nairaland.com/1381159/naijaloaded-com-been-hacked |

