₦airaland Forum

Welcome, Guest: RegisterLoginWith GoogleTrendingRecentNew

Stats: 3,331,050 members, 8,448,399 topics. Date: Monday, 20 July 2026 at 10:05 AM

Toggle theme

Slyr0x's Posts

Nairaland ForumSlyr0x's ProfileSlyr0x's Posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 (of 81 pages)

WebmastersHow Airtel Security Flaw Led To Epic Hacking by Slyr0x(op):
In the space of one hour, the entire webmaster board was overloaded with several threads titled " got hacked". On checking one of the threads, I hurriedly fired up my browser, checked the Naijaloaded site and poof, I had a defaced webpage before me.

Next thing I did was to send Naijaloaded's owner a mail informing him of the hack which he then replied to this morning saying "They Swapped my SIM, Used the Forgot Password Features and Yahoo Sent the Guy my Code, he then Changed my Yahoo Password and Requested for a Password Changing Note from my Domain Registrar, Then he finally Changed my DNS".

At first, I didn't understand the swapping part. So I fired up my browser again and started crawling through webpages with the dork "Airtel Nigeria instant swap". After much crawling, I learnt that to swap your airtel sim (i.e. to hijack another person's airtel sim), all you need is

1. An airtel swap sim which goes for just N300 and offered for sale here
2. Four (4) most dial'd no
3. The serial number on the new airtel swap sim


. .and in 20mins max, d new Sim will be ready.

That easy yeah?!

After the "hacker" swapped Naijaloaded's owner SIM, he went on to use Yahoo's Forgot Password Features which yahoo then sent the hacker a code (to the swapped sim), he then Changed his Yahoo Password after which the hacker requested for a Password Changing Note from Domain Registrar and ended up changing 's DNS.

A brilliant social engineering attack it was!

This clearly exposes vital security flaws in several customer service systems.

All a malicious person need know to hijack your SIM is your 4 most dial'd nos (your dad, mom, girlfriend, line manager, direct subordinate, etc).

You know what this means? You can directly intercept that scheduled business call by hijacking that Big Oga's sim.

The guy that perpetrated this act not only digitally hacked the owner but they socially hacked him too as he could receive calls on his behalf.

It's quite upsetting that the ecosystem that we’ve placed so much of our trust in(In this case Airtel) has let some of us down so thoroughly.

Even the online Internet banking can be easily compromised. .call the customer care line, tell them you forgot your internet banking password, they will then ask 2/3 questions (1.) Your Date of Birth (2.)Your Account number (3.) Your Phone number and poof. .you have them reeling out all the infos you need (another story for another day)


Social Engineering, albeit a new one in the Nigerian space, is here to stay. .Folks Are You Ready?
WebmastersRe: Naijaloaded Has Been Panatrated By Cyber Guru Hacker by Slyr0x: 9:02am On Aug 02, 2013
WebmastersRe: Naijaloaded As Been Hijack by Slyr0x: 8:58am On Aug 02, 2013
WebmastersRe: Naijaloaded .com Has Been redeemed by Slyr0x: 11:47pm On Aug 01, 2013
Not surprised though. Exactly 2months ago, I informed him of the backdoors planted on his server but he wouldn't listen. SMH.
WebmastersRe: Has Been Hacked by Slyr0x: 11:41pm On Aug 01, 2013
WebmastersRe: Naijaloaded .com Has Been Hacked by Slyr0x: 11:40pm On Aug 01, 2013
WebmastersRe: NAIJA LOADED HACKED!!! (next Gen Laughs) by Slyr0x: 11:40pm On Aug 01, 2013
WebmastersRe: How To Monitor File Changes On Web Server by Slyr0x(op): 3:45pm On Aug 01, 2013
spikes C: I don't know but script changes occurs almost every time on servers's i've worked with.
I thought it would probably be anti-virus scans or something but i am sure that getting email alerts when ever a files changes last modification time is a total waste of resources.
No, it's not.

Please educate me: Are there scripts that Auto-change?
WebmastersRe: How To Monitor File Changes On Web Server by Slyr0x(op): 3:42pm On Aug 01, 2013
ActiveMan: Great!!!

not everyone can use the command line though

Their is a PHP script that you can install on you site. It notifies you if there are any changes to your site -- sending an email with a list of changed files. This at least tells you where to look. it also has a wordpress plugin

Read more
www.webchicklet.com/tools/monitorhackdfiles-tool-helps-fight-site-hackers/


You could set up a Google Alert http://www.google.com/alerts to search your site for probable junk. For example, you might have the alert search for "viagra site:example.com". Google alerts will email you if it ever finds the target of your search.
Nice one. Thanks for your contribution
WebmastersHow To Monitor File Changes On Web Server by Slyr0x(op): 1:11pm On Aug 01, 2013
Yesterday, I was trying to help a client fix a hacked site and one of the controls I put in place was to monitor changes to files on the web server. . So I'll just explain how you can also do same (either you are on a shared-hosting or dedicated server provided it's a LINUX box).

Over time when malicious hackers hit your site, they've been known to drop a backdoor somewhere on your server. It could be the /css , /images , /admin/images, /js , /includes directories . .somewhere far hidden from you.

To check for recent file changes on your webserver, you can do this

1. If you have SSH access, fire up Putty and run this command

find /home/xxxxxxxxx/public_html -type f -ctime -1 -exec ls -ls {} \;
Make sure /home/xxxxxxxxx/public_html is the full path to your public_html,www, httpdocs directory

2. Setup a cron job

- Login to your cPanel
- Under "Advanced" submenu, you will see "Cron Jobs". Click it
- Tweak the settings to suit you (either you want alerts hourly/daily/weekly)
- There is a section for "Commands", type in
find /home/xxxxxxxxx/public_html -type f -ctime -1 -exec ls -ls {} \;
- Click "Add New Cron Jobs"


This will NOT prevent files from being changed without your knowledge. However, if a file is added or changed, you will get an email alert telling you which file was changed.


Cheers.
WebmastersRe: EXCLUSIVE: Nairaland Is Launching Its New Offices In Ota Soon [PHOTO] by Slyr0x: 10:39am On Aug 01, 2013
WebmastersRe: EXCLUSIVE: Nairaland Is Launching Its New Offices In Ota Soon [PHOTO] by Slyr0x: 10:00am On Aug 01, 2013
Nice one
WebmastersRe: I Can't Imagine This! Is CSS This Crazy? by Slyr0x: 8:13am On Jul 31, 2013
miracle4: greenmouse?
cheesy cheesy grin
WebmastersRe: A Client Offered Him 1 Million For Three Websites. Should He Take It? by Slyr0x: 8:07am On Jul 31, 2013
WebmastersRe: Wordpress Help Zone - Tutorials, Answers, and Tricks. by Slyr0x: 8:02am On Jul 31, 2013
Esiri111: Databoy , i have a bp site www.gcliqq.tk how can i redirect users to another page on the site ! eg gcliqq.tk/ to gcliqq.tk/activity using htaccess.
To redirect the whole domain to just the /activity directory, add this to your .htaccess

Redirect / http://gcliqq.tk/activity
WebmastersRe: A Client Is Forcing Me To Use Asp.net For His Website Project. by Slyr0x: 2:51pm On Jul 30, 2013
Hmmn. . .You finally got the commercial bank website job yeah?
Jobs/Vacancies[urgent] Vacancy For Serving Female NYSC Corps Member In Lagos by Slyr0x(op): 11:57am On Jul 26, 2013
An asset management firm located in Ikoyi, Lagos is in need of a Female NYSC Corps member serving in Lagos with a degree in Computer Science.

Please if you know any Female NYSC Corps member serving in Lagos that has a degree in Computer Science, inform them of this opening.

Any interested individual should send me a mail slyrox2 [at] gmail [.] com

Please help disseminate this information .

Thanks

@MODS, Sorry I posted this in this section. The targeted audience is here. Thanks
Jobs/VacanciesRe: tx by Slyr0x(op): 11:24am On Jul 25, 2013
chigodo: I thought corps memebers are no longer allowed to have their PPA any where else apart from the classroom..?
True. .but there's always a workaround..especially for those smart corpers that are not ready to waste the 1yr.
WebmastersRe: The Best Bank Website In Nigeria by Slyr0x: 8:49am On Jul 23, 2013
Standard Chartered is not a Nigerian bank per se. .as they only have license to operate in Nigeria. .That site you posted up there covers their international audience.

@Topic, IMHO, http://www.gtbank.com/ tops the list followed by http://diamondbank.com/
WebmastersRe: Is Your Site Hosted On Nulled/stolen Whmcs Find Out Before Your Site Get Hacked! by Slyr0x: 3:53pm On Jul 22, 2013
Great thread.

You can get a comprehensive list here
WebmastersRe: E-topup.com.ng Just Closed My Account For His Own Bad Customer Service. by Slyr0x: 12:43pm On Jul 19, 2013
ActiveMan: see Slyr0x you can say all what you like, but you just lost my respect and i really don't know what your intentions are, as a moderator your JOB is to moderate the forum which includes moderation of grammatical errors too and not mockery.
Dude stop shooting unnecessary missiles around and get your acts right!

In less than a month, I've read 2 tragic & inappropriate customer-service lines from Etopup staffs.

The first was when an Etopup customer service guy told a customer "DO YOU WANT OGUN AND SANGO TO KILL YOU?".

In my twenty something years sojourn on earth, that line tops the most unprofessional line used on a customer irregardless of the situation at hand.

Notwithstanding, rather than comment on that particular thread, I emailed this young man giving him unsolicited customer service tips.

What do I stand to gain in pulling you down?

Last time I checked, I still have an active account on etopup ([size=4pt]if uve not closed my account like you did the Op's[/size]). .I even transacted like 2days back sef. .

Having said this, the reason why I still use Etopup is not cos they've got a superb service running, neither is it 'cos there are no other coys doing what they do, but cos of the owner's accessibility (and because ure an active Nairaland member too).

Get your act right so we don't go wagon-hopping the moment another active member comes up with something similar.

Cheers man. Wish you all the best
WebmastersRe: Truecaller Hacked, 1 Million Indians’ Data At Risk by Slyr0x: 11:51am On Jul 19, 2013
In addition, the title is a bit misleading. .shoulda been "Truecaller Hacked, User's Data At Risk" considering that the Truecaller app is not only being used in India but other countries too. .

The hackers claimed to have downloaded the following databases
truecaller_ugc(459GB), truecaller (100GB),truecaller_profiles( 4GB), truecaller_api(123KB), truecaller_PushMe(2.2KB), tc_admin(7MB), tc_wwwsad70MB)
Anyways, what do we have to fear? NSA's PRISM done did it grin grin
WebmastersRe: Truecaller Hacked, 1 Million Indians’ Data At Risk by Slyr0x: 11:43am On Jul 19, 2013
[img]http://timesofindia.indiatimes.com/photo/21144887.cms[/img]

This is very very very scary. . .

Every time a user downloads the truecaller app, it asks your permission to "securely send your phone book contacts to our servers".

When you grant this permission, the app harvests the phone's contact list which then becomes part of a publicly searchable database.

The app has about 1.6 million Indian users. Let's assume we have an average of 100 contacts per phone book, this means the truecaller company now owns a database of 50-80 million Indian phone numbers. shocked shocked . .Considering that the app has Nigerian users too, you can be rest assured that your phone number/name might be in their database too embarassed

Technology is very useful but it can also jeopardize your personal information if not protected. .

Any online data is always at risk of being hacked. This is the bitter truth of the internet age. .but then, do we because of this stop posting our information online?

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 (of 81 pages)