₦airaland Forum

Welcome, Guest: RegisterLoginWith GoogleTrendingRecentNew

Stats: 3,331,042 members, 8,448,341 topics. Date: Monday, 20 July 2026 at 08:37 AM

Toggle theme

Slyr0x's Posts

Nairaland ForumSlyr0x's ProfileSlyr0x's Posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 (of 81 pages)

WebmastersRe: I Started Webdesign And Brute Force Hacking Since I Was 14 by Slyr0x: 10:41am On Aug 20, 2013
Luedave: really u think i know a 12year old coding 4rm his head not a joke nd he's a 9jerian
How old are you now and what have you done since you started?
WebmastersRe: SSL In A Nutshell. by Slyr0x: 10:30am On Aug 16, 2013
This picture describes perfectly what SSL does

https://edge1.digicert.com/images/public-key.jpg

Does SSL Prevent Hacking?

[size=14pt]NO![/size]

SSL simply encrypts the data in transit. .and protects users of your site from having their communications intercepted by a 3rd party.

An SSL certificate does not validate the content of your site, nor does it prevent anyone from breaking into your site as a result of poor coding.

So let's say a web app vuln like SQL Injection exists on your website/ web app, having a SSL certificate WON'T stop the hacker from dumping your database. .

People tend to have that misconception and feel they are HACK-PROOF the moment they install SSL cert.

Moving forward, even the sole function the SSL has been known to do i.e. encrypt connection in transit has been compromised.

In 2009, a hacker g0tmi1k released a Proof Of Concept where he stripped the SSL (i.e. Stripped off the S behind https:// and then sniffed the connection).

Nothing is safe out there folks!
PoliticsRe: Female Officers Join Rally For Jonathan In Abuja by Slyr0x: 9:40am On Aug 16, 2013
WebmastersRe: Please Review This Simple Theme And Website by Slyr0x: 2:49pm On Aug 15, 2013
^^^Nice one. .Very comprehensive and well detailed. Kudos
WebmastersRe: Please Review This Simple Theme And Website by Slyr0x: 9:58am On Aug 15, 2013
www..net looks distorted on my mobile device
WebmastersRe: GTB Website- Joomla, Wordpress Or Dreamweaver? by Slyr0x: 9:40am On Aug 15, 2013
GTBank == Joomla;
WebmastersRe: Pls Help, Can't View My Nairaland Pm's by Slyr0x: 6:56pm On Aug 14, 2013
Check your spam folder
WebmastersRe: SQL Injection by Slyr0x: 11:13pm On Aug 12, 2013
Yinksey: When u are using PDO Extension with php to deal with mysql, you dont need to worry about sql injection.
This is not entirely true.

Using the PDO prepared statement is sufficient to prevent 1st order injection (i.e. it takes this input and filters it before inserting into the DB). .

However, for 2nd order injection, let's look at this scenario :

We have an ecommerce web application that has the "wish list" enabled. .Imagine the user types in
'; DELETE Users;-
. .Using prepared statement, the initial apostrophe gets deleted however the seemingly innocent-looking text gets inserted like this

INSERT Wishlist (ID, Item, City, Country) 
VALUES(1, ''';DELETE Users;--', 'Lagos', 'Nigeria')


Now, 1st order injection has been prevented. .However, when the user decides to display his wishlists with the query

SELECT * FROM Wishlist WHERE ID = '', Item);
becomes
SELECT * FROM Wishlist WHERE ID = '', DELETE Users;--);

This innocent-looking query just deleted the Table "Users". .

Having said this, Using only prepared statements is not sufficient to protect against sql injection attacks. .however, it's a step in the right direction
WebmastersRe: SQL Injection by Slyr0x: 10:12pm On Aug 12, 2013
brushesz: //Have you successfully injected via data fields or "?" edit before?
Yes.

brushesz: if (true){
then post a light comment about it;
}
else{ ignore_thread();
}
It was an enlightening experience grin
WebmastersRe: SQL Injection by Slyr0x: 4:02pm On Aug 12, 2013
brushesz: Feel free to share your experience and knowledge
How do you mean?
WebmastersRe: Paypal Tests Mobile Payments Using Your Face For Verification by Slyr0x: 3:25pm On Aug 11, 2013
flexpro: @ OP, to be honest with you, i hate paypal for exempting Nigeria from the list of countries on its platform.
+ 1000000.

The intriguing part is countries like Russia, USA, China, Britain, Germany, Brazil, Spain, India, France, Turkey top the Cybercrime list yet Paypal won't discontinue its service(s) in such countries. We are only being unnecessarily victimised.
WebmastersRe: Ed Snowden's Secure Email Provider Shuts Down Under Gag Order by Slyr0x(op): 11:18am On Aug 09, 2013
GraphicsPlus: I will rather allow US government to intercept my data than to think that Snowden is a hero. Snowden is a traitor and US government means well for its citizens.
In revealing the colossal scale of the U.S. government’s eavesdropping on Americans and other people around the world, Snowden has performed a great public service that more than outweighs any breach of trust he may have committed.

Thanks to Snowden, the whole world now knows “The N.S.A. has built an infrastructure that allows it to intercept almost everything. With this capability, the vast majority of human communications are automatically ingested without targeting.”

Snowden lived a "very comfortable" life earning a salary of roughly US$200,000. .about #32million naira per annum. .Point out a man that'ld give away all that + his privacy + his freedom + his family . .

So what exactly is Snowden’s real crime? Why is he being haunted? All 'cos he uncovered questionable activities that those in power would rather have kept secret.

In my humble opinion, Snowden is a man of conscience! In his words, “I don’t want to live in a society that does these sort of things. .I do not want to live in a world where everything I do and say is recorded. That is not something I am willing to support or live under.”

I still insist that Snowden is a hero!!!
WebmastersRe: Ed Snowden's Secure Email Provider Shuts Down Under Gag Order by Slyr0x(op): 10:52am On Aug 09, 2013
Slyr0x: "This experience," Levinson wrote, "has taught me one very important lesson: without congressional action or a strong judicial precedent, I would strongly recommend against anyone trusting their private data to a company with physical ties to the United States." ®
Food for thought!
WebmastersEd Snowden's Secure Email Provider Shuts Down Under Gag Order by Slyr0x(op): 10:51am On Aug 09, 2013
Lavabit, the security-conscious email provider that was the preferred email service of NSA leaker Edward Snowden, has closed its doors, citing US government interference.

"I have been forced to make a difficult decision: to become complicit in crimes against the American people or walk away from nearly ten years of hard work by shutting down Lavabit," founder Ladar Levinson said in a statement posted to the company's homepage on Thursday. "After significant soul searching, I have decided to suspend operations."

Prior to its closure, Lavabit was a dedicated email service that offered subscribers "the freedom of running your own email server – without the hassle or expense."

In addition to a variety of flexible configuration options, the service boasted that all email stored on its servers was encrypted using asymmetric elliptical curve cryptography, in such a way that it was impossible to discern the contents of any email without knowing the user's password.

As a whitepaper posted to the company's website (now removed, but available from the Internet Archive) observed:

Our goal was to make invading a user's privacy difficult, by protecting messages at their most vulnerable point. That doesn't mean a dedicated attacker, like the United States government, couldn't intercept the message in transit or once it reaches your computer.

Our hope is the difficulty associated with those strategies means they will only be used by governments on terrorists and scammers, not on honest citizens.

It now seems, however, that Levinson's hope was just wishful thinking. Without going into details, his statement on Thursday made plain that pressure from the US government was behind his decision to shutter Lavabit.

"I feel you deserve to know what's going on – the first amendment is supposed to guarantee me the freedom to speak out in situations like this," Levinson wrote. "Unfortunately, Congress has passed laws that say otherwise. As things currently stand, I cannot share my experiences over the last six weeks, even though I have twice made the appropriate requests."

Under current US law, requests for information by US intelligence agencies often carry a gag order that forbids the party receiving the request from disclosing what information was requested, or even that a request was made at all.

The gag orders can be challenged by appealing to the shadowy Foreign Intelligence Surveillance Court (FISC), which operates in complete secrecy, but such appeals are seldom granted.

Not even Google or Microsoft – each of which, it must be said, has far deeper pockets than Lavabit – has managed to challenge the surveillance orders. Both companies were named by Snowden as having turned over user data to government spies under the secretive PRISM program, but the FISC won't allow them to reveal to the public what they may or may not have actually disclosed.

Little wonder, then, that Levinson's "appropriate requests" have similarly been denied.

The Lavabit founder says he next plans to challenge the government's ruling in the US Fourth Circuit Court of Appeals. A favorable ruling, he says, would allow him to "resurrect Lavabit as an American company" – though he doesn't appear to hold out much hope.

"This experience," Levinson wrote, "has taught me one very important lesson: without congressional action or a strong judicial precedent, I would strongly recommend against anyone trusting their private data to a company with physical ties to the United States." ®


http://www.theregister.co.uk/2013/08/08/lavabit_shuts_down/
Web MarketRe: I Want To Build Up My Portfolio - Let Me Design A Website For You by Slyr0x: 10:20am On Aug 09, 2013
CreativeWeb: Hello NairaLanders, thank you all for the good works you are doing here. I am new here and my name is Decency.
Decent approach smiley
WebmastersRe: Wordpress Help Zone - Tutorials, Answers, and Tricks. by Slyr0x: 3:47pm On Aug 05, 2013
databoy247: Boss i have always suspected that you are a wordpress guru grin
Oga me, I dey try small
WebmastersRe: Download And Listen To This Radio Jingle Created By A Webmaster. by Slyr0x: 3:00pm On Aug 05, 2013
greenmouse: Pls downlaod, listen and review our latest jingle on radios.

Pls comment will be appreciated.
link
WebmastersRe: Wordpress Help Zone - Tutorials, Answers, and Tricks. by Slyr0x: 1:11pm On Aug 05, 2013
antontech: its not there
If you don't mind, send me your wp login details
WebmastersRe: Help! Webmasters Pls Assess This Site, My Client Rejected It!!! by Slyr0x: 10:25am On Aug 05, 2013
Guy, you no try at all oo. .I actually prefer the former website
WebmastersRe: Learn Web Design LIVE On Nairaland!!! by Slyr0x: 9:57am On Aug 04, 2013
Great Initiative. You have our support
WebmastersRe: How Airtel Security Flaw Led To Epic Hacking by Slyr0x(op): 11:50pm On Aug 03, 2013
onajo2000

Thank you oo. .I don taya to dey explain
WebmastersRe: How To Monitor File Changes On Web Server by Slyr0x(op): 3:26pm On Aug 02, 2013
spikes C: So, i can only assume that there's something reading and resaving the files on my server. Antiviruses can do that, backups and server changes does that, if you have a load balancer, you'll definitely experience it. So, like i said, it would be a total waste of resources for me.
Reading and Writing are TOTALLY different.

Antivirus scanners can scan your files, read the content for signatures etc. . .but they will NEVER write to your files.

Any attempt to edit/change your files without your knowledge is termed "malicious".

spikes C: So, like i said, it would be a total waste of resources for me.
Better safe than sorry bro smiley
WebmastersRe: How Airtel Security Flaw Led To Epic Hacking by Slyr0x(op): 2:30pm On Aug 02, 2013
naturalwaves: When I had the problem too, I thought it will be that easy. The last process says you should follow the sign in process after getting the verification on your mobile device. When the code was sent to me then, it came with a link to continue, after I did that, it still asked for the security question which was surprising to me cos I didn't know it will ask that again after chosing the mobile option. I had to eventually think and think well before I could get my answer and I was good to go. Same thing applies to gmail except if yahoo just changed the process which I doubt. Why not do the practicals and stop quoting links.
I told you something from my own personal experience, you didn't believe.
I went ahead to give you a direct link posted on yahoo's website to further buttress my point http://help.yahoo.com/kb/index?locale=en_US&page=content&id=SLN2694 but you said it's just theory.

I give up.
WebmastersRe: How Airtel Security Flaw Led To Epic Hacking by Slyr0x(op): 2:03pm On Aug 02, 2013
naturalwaves: Like I said, I have been through the process before so I know what I am saying. You only stated the start process without finishing it. The question is......did you change your password? I guess NO. Well, I have changed my password through that feature like two times in the past so let me start from where you stopped. When you get that verification through your mobile device, you will go back to the net link and put it there. When you submit, it will take you to the final verification process in which the security question prompts up. If you cannot provide a correct answer to that question, there is no way and it will be better you just open a new email addy cos it will never be succesful.


Moreover, by your argument, it means that once I know a person's phone number, I can quickly change his mail password anytime I have a little access to his phone like when the person is bathing , sleeping, charging etc. Does that make any sense to you? Though your DNR DNS explanation is well understood, the mail own remains an Abracadabra.
Calm down oga and Learn. .

Yahoo has 3 options :

1.) Send a verification link to an alternate email address
2.) Send a verification code to your phone number
3.) Answer your secret questions.

Using your mobile phone number for password recovery

Mobile password recovery is a fast and safe way to get a new password for your account.
Recovering your password using your mobile number

Go to the Yahoo! Password Helper and select I have a problem with my password.
Enter your Yahoo! ID and the CAPTCHA word verification code.
Enter your mobile number | click Next.
Follow the instructions, and a text message [SMS] will be sent to the mobile number you've provided.
-In some cases, the text message may take up to 30 minutes to be received.
Once you receive the text message, follow the sign-in steps and change your password.
http://help.yahoo.com/kb/index?locale=en_US&page=content&id=SLN2694
WebmastersRe: How Airtel Security Flaw Led To Epic Hacking by Slyr0x(op): 1:56pm On Aug 02, 2013
Samoo01: Since when did Yahoo begin to accept Nigerian phone numbers in its password recovery page?
Find attached the screenshot (I'm sure you can see the +234)

WebmastersRe: How Airtel Security Flaw Led To Epic Hacking by Slyr0x(op): 1:00pm On Aug 02, 2013
naturalwaves: This story looks like an Abracadabra and it is difficult to believe. Even if it is that easy getting a sim swapped on Airtel, when the supposed cracker wanted to contact Yahoo, did he just get a Password just like that from Yahoo? Impossible! Getting your password changed on Yahoo isn't that easy. Okay? And the Domain Name Registrer too gave out another Password on sighting just a note for a change of password? I haven't read something as hilarious and ridiculous as this claim in a long while even if you go to court with this crap, you will outrightly lose the case on the first day.
1. Click on Yahoo's Forgot My Password feature >> Yahoo asks for your phone number (one of the security options you opted for) >> You put in the phone number >> Yahoo sends you a verification code or they call you >> You type in the 6characters verification code and voila. .you are in.

2. For the Domain Name Registrar, that part is quite simple. The only email account connected to them is the hacked one. So basically, the forgot my password feature comes to play again. Request for a new password and a link gets sent to your mail.
WebmastersRe: Almighty Naijaloaded Has Been Hacked by Slyr0x: 11:31am On Aug 02, 2013

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 (of 81 pages)