Slyr0x's Posts
Nairaland Forum › Slyr0x's Profile › Slyr0x's Posts
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 (of 81 pages)
In the space of one hour, the entire webmaster board was overloaded with several threads titled " got hacked". On checking one of the threads, I hurriedly fired up my browser, checked the Naijaloaded site and poof, I had a defaced webpage before me. Next thing I did was to send Naijaloaded's owner a mail informing him of the hack which he then replied to this morning saying "They Swapped my SIM, Used the Forgot Password Features and Yahoo Sent the Guy my Code, he then Changed my Yahoo Password and Requested for a Password Changing Note from my Domain Registrar, Then he finally Changed my DNS". At first, I didn't understand the swapping part. So I fired up my browser again and started crawling through webpages with the dork "Airtel Nigeria instant swap". After much crawling, I learnt that to swap your airtel sim (i.e. to hijack another person's airtel sim), all you need is 1. An airtel swap sim which goes for just N300 and offered for sale here 2. Four (4) most dial'd no 3. The serial number on the new airtel swap sim . .and in 20mins max, d new Sim will be ready. That easy yeah?! After the "hacker" swapped Naijaloaded's owner SIM, he went on to use Yahoo's Forgot Password Features which yahoo then sent the hacker a code (to the swapped sim), he then Changed his Yahoo Password after which the hacker requested for a Password Changing Note from Domain Registrar and ended up changing 's DNS. A brilliant social engineering attack it was! This clearly exposes vital security flaws in several customer service systems. All a malicious person need know to hijack your SIM is your 4 most dial'd nos (your dad, mom, girlfriend, line manager, direct subordinate, etc). You know what this means? You can directly intercept that scheduled business call by hijacking that Big Oga's sim. The guy that perpetrated this act not only digitally hacked the owner but they socially hacked him too as he could receive calls on his behalf. It's quite upsetting that the ecosystem that we’ve placed so much of our trust in(In this case Airtel) has let some of us down so thoroughly. Even the online Internet banking can be easily compromised. .call the customer care line, tell them you forgot your internet banking password, they will then ask 2/3 questions (1.) Your Date of Birth (2.)Your Account number (3.) Your Phone number and poof. .you have them reeling out all the infos you need (another story for another day) Social Engineering, albeit a new one in the Nigerian space, is here to stay. .Folks Are You Ready? |
Duplicate thread. Continue here https://www.nairaland.com/1381159/naijaloaded-com-been-hacked |
Duplicate thread. Continue here https://www.nairaland.com/1381159/naijaloaded-com-been-hacked |
Not surprised though. Exactly 2months ago, I informed him of the backdoors planted on his server but he wouldn't listen. SMH. |
Duplicate thread. Please continue here https://www.nairaland.com/1381159/naijaloaded-com-been-hacked |
Duplicate thread. Please continue here https://www.nairaland.com/1381159/naijaloaded-com-been-hacked |
Duplicate thread. Please continue here https://www.nairaland.com/1381159/naijaloaded-com-been-hacked |
spikes C: I don't know but script changes occurs almost every time on servers's i've worked with.No, it's not. Please educate me: Are there scripts that Auto-change? |
ActiveMan: Great!!!Nice one. Thanks for your contribution |
Yesterday, I was trying to help a client fix a hacked site and one of the controls I put in place was to monitor changes to files on the web server. . So I'll just explain how you can also do same (either you are on a shared-hosting or dedicated server provided it's a LINUX box). Over time when malicious hackers hit your site, they've been known to drop a backdoor somewhere on your server. It could be the /css , /images , /admin/images, /js , /includes directories . .somewhere far hidden from you. To check for recent file changes on your webserver, you can do this 1. If you have SSH access, fire up Putty and run this command find /home/xxxxxxxxx/public_html -type f -ctime -1 -exec ls -ls {} \;Make sure /home/xxxxxxxxx/public_html is the full path to your public_html,www, httpdocs directory 2. Setup a cron job - Login to your cPanel - Under "Advanced" submenu, you will see "Cron Jobs". Click it - Tweak the settings to suit you (either you want alerts hourly/daily/weekly) - There is a section for "Commands", type in find /home/xxxxxxxxx/public_html -type f -ctime -1 -exec ls -ls {} \;- Click "Add New Cron Jobs" This will NOT prevent files from being changed without your knowledge. However, if a file is added or changed, you will get an email alert telling you which file was changed. Cheers. |
Duplicate thread. Please continue here https://www.nairaland.com/1379603/nairaland-launching-new-offices-ota |
Nice one |
miracle4: greenmouse? ![]() |
Esiri111: Databoy , i have a bp site www.gcliqq.tk how can i redirect users to another page on the site ! eg gcliqq.tk/ to gcliqq.tk/activity using htaccess.To redirect the whole domain to just the /activity directory, add this to your .htaccess Redirect / http://gcliqq.tk/activity |
Hmmn. . .You finally got the commercial bank website job yeah? |
An asset management firm located in Ikoyi, Lagos is in need of a Female NYSC Corps member serving in Lagos with a degree in Computer Science. Please if you know any Female NYSC Corps member serving in Lagos that has a degree in Computer Science, inform them of this opening. Any interested individual should send me a mail slyrox2 [at] gmail [.] com Please help disseminate this information . Thanks @MODS, Sorry I posted this in this section. The targeted audience is here. Thanks |
chigodo: I thought corps memebers are no longer allowed to have their PPA any where else apart from the classroom..?True. .but there's always a workaround..especially for those smart corpers that are not ready to waste the 1yr. |
Standard Chartered is not a Nigerian bank per se. .as they only have license to operate in Nigeria. .That site you posted up there covers their international audience. @Topic, IMHO, http://www.gtbank.com/ tops the list followed by http://diamondbank.com/ |
ActiveMan: see Slyr0x you can say all what you like, but you just lost my respect and i really don't know what your intentions are, as a moderator your JOB is to moderate the forum which includes moderation of grammatical errors too and not mockery.Dude stop shooting unnecessary missiles around and get your acts right! In less than a month, I've read 2 tragic & inappropriate customer-service lines from Etopup staffs. The first was when an Etopup customer service guy told a customer "DO YOU WANT OGUN AND SANGO TO KILL YOU?". In my twenty something years sojourn on earth, that line tops the most unprofessional line used on a customer irregardless of the situation at hand. Notwithstanding, rather than comment on that particular thread, I emailed this young man giving him unsolicited customer service tips. What do I stand to gain in pulling you down? Last time I checked, I still have an active account on etopup ([size=4pt]if uve not closed my account like you did the Op's[/size]). .I even transacted like 2days back sef. . Having said this, the reason why I still use Etopup is not cos they've got a superb service running, neither is it 'cos there are no other coys doing what they do, but cos of the owner's accessibility (and because ure an active Nairaland member too). Get your act right so we don't go wagon-hopping the moment another active member comes up with something similar. Cheers man. Wish you all the best |
In addition, the title is a bit misleading. .shoulda been "Truecaller Hacked, User's Data At Risk" considering that the Truecaller app is not only being used in India but other countries too. . The hackers claimed to have downloaded the following databases truecaller_ugc(459GB), truecaller (100GB),truecaller_profiles( 4GB), truecaller_api(123KB), truecaller_PushMe(2.2KB), tc_admin(7MB), tc_wwwAnyways, what do we have to fear? NSA's PRISM done did it ![]() |
[img]http://timesofindia.indiatimes.com/photo/21144887.cms[/img] This is very very very scary. . . Every time a user downloads the truecaller app, it asks your permission to "securely send your phone book contacts to our servers". When you grant this permission, the app harvests the phone's contact list which then becomes part of a publicly searchable database. The app has about 1.6 million Indian users. Let's assume we have an average of 100 contacts per phone book, this means the truecaller company now owns a database of 50-80 million Indian phone numbers. ![]() Technology is very useful but it can also jeopardize your personal information if not protected. . Any online data is always at risk of being hacked. This is the bitter truth of the internet age. .but then, do we because of this stop posting our information online? |

70MB)