WEBVTT

00:00.000 --> 00:09.460
This is dedicated to all the hackers and the crackers, to the hackers and the crackers.

00:09.760 --> 00:15.520
I see in binary, I speak source code, step on my toes, I'll post a million jpegs of you

00:15.520 --> 00:20.780
and a fag pwned, in your digital stance getting firewalled ho, cause I'm riding the net in

00:20.780 --> 00:26.440
my six-fold, I was a dick with my 56, now with my cable I'm able to get that stable,

00:26.440 --> 00:31.740
on the out, my name is Ace and I'm a Leo, on the digital highway, my name is Neo and

00:31.740 --> 00:37.240
I'm a hero, in a flash, I'll screw you on burning dreamcast, you need some ISO, let me through

00:37.240 --> 00:42.680
my hard drive rifle, our exchange you could never stifle, in a digital hug, you just caught

00:42.680 --> 00:48.940
the love bug, I bootlegged your CD, I caused a fight between Un and Jay-Z, your CG, it's

00:48.940 --> 00:53.460
all gonna be free, whether we take it by force or we take it nicely, you feel that rattling

00:53.460 --> 00:58.040
your phones, when I tell you we just hacked out Jones, and NASDAQ leaves your fight on

00:58.040 --> 01:03.100
your back, cause I am he who loves to hack and crack, cause I am he who loves to hack and

01:03.100 --> 01:09.460
crack, this is dedicated to the hackers and the crackers, serial codes, source codes, ISOs,

01:10.120 --> 01:16.560
RANs, SIFs, SIFs, this is dedicated to the hackers and the crack, we are back once again

01:16.560 --> 01:22.820
this week ladies and gentlemen with Binary Revolution Radio, I am Stank Dog, fully recovered from

01:22.820 --> 01:29.180
my off week last week, I had the bird flu or something, I don't know what I had last

01:29.180 --> 01:35.360
week, but we did not get a show out last week, however today, March 6, 2007, you are going

01:35.360 --> 01:41.840
to get two episodes for the price of one, and considering that one is free, so are two, double

01:41.840 --> 01:46.080
header episode this week, that will keep us back on the path, keep us on track as far

01:46.080 --> 01:50.140
as keeping a weekly release of the show out, even though we all know that that's an out

01:50.140 --> 01:53.200
and out lie, and I am a son of a bitch for even saying that on the air, but what are

01:53.200 --> 01:57.680
you going to do, and this is actually going to be kind of an interesting week for the

01:57.680 --> 02:02.980
show, because the back to back episodes that we are going to do, again this is 188, and

02:02.980 --> 02:08.940
we have a new first time co-host on episode 188 with me, and that co-host is Mubix, welcome

02:08.940 --> 02:16.180
to the show, and Mubix and I have been chatting with, chatting in IRC and actually here on Bell's

02:16.180 --> 02:21.340
line quite a bit lately, and we came up with some cool stuff to talk about for the show

02:21.340 --> 02:27.760
tonight, so we are going to get into that a little bit later on, but the other reason

02:27.760 --> 02:33.640
this double header is a little bit interesting is this is kind of a Hack 5 double header spectacular,

02:33.860 --> 02:39.520
if you will, because the second episode, episode 189 coming up, is from our good friend Droops

02:39.520 --> 02:46.160
who recorded an episode with the gang over at Hack 5, so stay tuned for that in about

02:46.160 --> 02:47.460
an hour and a half from now.

02:48.820 --> 02:50.300
What else do we have in housekeeping?

02:50.660 --> 02:56.380
We are going to, oh we made some forum changes, once again controversial forum changes, it seems

02:56.380 --> 03:02.000
to be anything I ever change is controversy, but made some changes to the forums, basically

03:02.000 --> 03:07.940
we've, you know, I think a lot of our regular listeners and regular visitors to the forum

03:07.940 --> 03:13.520
know that we've had some problems where we've just outgrown our hardware, we've upgraded to

03:13.520 --> 03:18.440
new hardware, and I'd rather not have to upgrade again, so what I'm doing is kind of cracking

03:18.440 --> 03:23.980
down and getting a little bit more efficient with the system and the hardware that we have,

03:24.660 --> 03:30.520
so every little minor change along the way that can help me keep the server running smoothly

03:30.520 --> 03:35.320
for our actual registered users, the users that we want to serve most, the users that

03:35.320 --> 03:39.680
actually care and show support, we want to try to provide the best experience that we

03:39.680 --> 03:48.340
can, so to that end, we have basically taken the biggest forums that we have and still kept

03:48.340 --> 03:51.960
them publicly available, we want information to be free, we want people to be able to find

03:51.960 --> 03:56.540
it, Google and that sort of thing, which is great, so we put all of the big forums out

03:56.540 --> 04:00.340
there, the top five forums, and made them publicly available just as they always have

04:00.340 --> 04:06.680
been, anybody can browse and read that information, but what we've done is we've taken all of

04:06.680 --> 04:11.040
the other forums, the smaller ones, the more focused forums where they're actual members

04:11.040 --> 04:16.340
working on things together and sharing information on specific topics, and we've made it so that

04:16.340 --> 04:22.380
you have to register with the forums to get access to those, so even to browse them or read

04:22.380 --> 04:22.640
them.

04:23.300 --> 04:28.420
Now, I don't see why that's a big deal, it's not like we're charging money, anybody can register

04:28.420 --> 04:32.260
for free, that's not a big deal in my opinion, but there's some people out there, ironically

04:32.260 --> 04:38.760
registered members, who don't seem to like this, so I'm not sure what to tell you about

04:38.760 --> 04:42.520
that, but in the long run, it's going to help a lot of different things, it's going to have

04:42.520 --> 04:47.700
less traffic from people that are finding some of the code that we're working on, a lot of

04:47.700 --> 04:52.980
the projects down there are being discovered while they're still in progress, while there's

04:52.980 --> 04:58.680
work going on, so they're getting shut down quickly and they don't work anymore, so a lot

04:58.680 --> 05:02.120
of these projects are getting ruined because people are coming from nowhere, finding them

05:02.120 --> 05:06.920
or stealing the work and taking it somewhere else, which is something we don't want to

05:06.920 --> 05:13.000
do, so it's just kind of like, I don't know, there's several different reasons in my mind

05:13.000 --> 05:18.060
to do it, and the bottom line is, you know, if you're visiting the site so much that you're

05:18.060 --> 05:22.620
frequenting all of those other forums, then I don't see why it's a big deal to register,

05:22.760 --> 05:28.220
I mean, show some support, register for the site, doesn't really change anything, it's

05:28.220 --> 05:32.080
just, basically, it's what it is, showing support, I've seen a lot of other forums out

05:32.080 --> 05:38.040
there that require registration to access anything at all, period, so, you know, we're

05:38.040 --> 05:44.000
still giving out the majority of information in the top five forums, which is easily 75% of

05:44.000 --> 05:48.080
the content of the site, still out there for anybody to access anywhere, anytime, which

05:48.080 --> 05:54.120
is great, the only other thing that was brought to my attention is that somebody said they

05:54.120 --> 05:59.080
don't like to log into the servers from a public location, they don't want to send their

05:59.080 --> 06:02.720
password, plain text, or any of that kind of stuff, so that I certainly understand, and

06:02.720 --> 06:07.800
that's a valid concern, we are in the process of putting a self-signed SSL certificate, actually

06:07.800 --> 06:12.000
we already have one, we're just in the process of slapping that on the forums so that people

06:12.000 --> 06:17.340
can log in securely from anywhere as well, so that should alleviate that problem, so

06:17.340 --> 06:22.040
if that's the only concern, that is something that is certainly fixable, but if you want

06:22.040 --> 06:26.420
to access all those other forums, hey, just register and everything's fine, everything's

06:26.420 --> 06:30.700
honky dory, so the information's free, no matter, you know, either way you do it, just

06:30.700 --> 06:34.520
register and show a little support, I'm tired of seeing at the bottom of the forums, we

06:34.520 --> 06:41.700
have 120 users, or 120 people browsing the forums, but only, you know, 14 registered, you

06:41.700 --> 06:45.400
know, we've got all these people that are just putting a load on the server, well those

06:45.400 --> 06:49.440
14 people that are registered to me deserve a little bit more respect and support from

06:49.440 --> 06:53.360
us, so I want to make their experience as good as possible, as fast as possible, I'm

06:53.360 --> 06:57.400
not going to let those other hundred and some people slow the server down for them, they're

06:57.400 --> 07:00.800
welcome to come browse the information in the top five forums, but I'm not going to let

07:00.800 --> 07:04.840
them go in there and research and get down to the details, if they're not even going to

07:04.840 --> 07:08.700
show the courtesy to register for the site, so I understand some people aren't going to

07:08.700 --> 07:14.460
like it, but, hey, what can I tell you, deal with it, what do you, I got a real quick

07:14.460 --> 07:21.400
point, for the person who doesn't have, doesn't want to send their password over clear text

07:21.400 --> 07:27.880
to the server, until you have SSLs there, later on in the school, that's a really easy

07:27.880 --> 07:34.220
way to do that from a public location, cool, very cool, well then that's a good timing to

07:34.220 --> 07:39.100
do the show, we'll talk about this subject, which is a bunch of useful applications that

07:39.100 --> 07:42.860
you can put on your USB tool, that's going to be our main topic, a USB key, a bunch of

07:42.860 --> 07:47.480
useful tools that you can carry around with you, and that serve purposes just like that,

07:47.520 --> 07:53.440
a very specific purpose, and that you can use from anywhere, anytime, but, if you didn't,

07:53.520 --> 08:00.620
unless you had some housekeeping as well, no, no housekeeping, first time, so, why don't

08:00.620 --> 08:28.620
we move into some email, and our first email this week comes from NJAC, I guess that's a

08:28.620 --> 08:34.620
name, is that an acronym, N-J-A-K, N-J-A-K, N-J-A-K, I'm going to call him N-J-A-K, all right,

08:34.700 --> 08:42.820
N-J-A-K, I have, or N-J-A-K, no, it's just N-J, whatever, N-J-A-K, who says, I wish to

08:42.820 --> 08:47.680
ask, I love, I love just trying to figure out the names of people that are right in, N-J-A-K,

08:47.720 --> 08:52.400
it can't be that hard, but I'll make it complicated, because that's what I do, N-J-A-K says, I wish

08:52.400 --> 08:58.780
to ask the question, why don't computers encrypt using images, sound, touch, taste, and even

08:58.780 --> 09:06.260
smell, figure that in a key, you don't have to use any characters and symbol, what takes

09:06.260 --> 09:14.560
the place of characters, can look like, wait a minute, what, look like the same to the human

09:14.560 --> 09:21.180
eye, can look like this, can look like the same to the human eye, so why not just assign

09:21.180 --> 09:34.860
A to Y equals M, and then give it a color value, pound 0000XX, where XX is 1Z to 33Z, Z is a

09:34.860 --> 09:40.740
random integer between 1 and 3. Next, do the same with B and so on, every character in theory

09:40.740 --> 09:48.120
could be Y equals M, with a color value of, pound 000001, then a picture could then be

09:48.120 --> 09:55.580
displayed with an interval based on character. So, if you encrypted the name StankDog, quote

09:55.580 --> 10:04.020
unquote StankDog, to a computer, would read it as Y equals M, comma, pound 000001, comma,

10:04.020 --> 10:20.560
at X equals X plus 0.3 seconds, that would be the T, I guess, if I'm following him here,

10:20.560 --> 10:29.180
Y equals M, comma, pound 000001, at X equals X plus 1 second, and I'm not going to read all

10:29.180 --> 10:37.780
these so on as Sunforth, but to an end user, that is just one black line. I see there being

10:37.780 --> 10:42.380
a lot of possibles given this mode of thinking. Now, I could go way deeper into this, but for

10:42.380 --> 10:51.660
now, why can't StankDog equal 12 pixels, bark, quote bark, smooth, bitter, and mint? Just throwing

10:51.660 --> 10:58.140
out an idea in Jack. I think you're, you're saying that you're smooth, you're bitter, and

10:58.140 --> 11:07.120
you're minty. And minty? Yeah. And stank at the same time somehow. Yeah. Well, I'm not, I've

11:07.120 --> 11:13.080
got to be honest, I'm not quite sure I'm exactly following you. I mean, let's, okay, let's back

11:13.080 --> 11:17.840
up a little bit. We've talked about a topic, steganography, on the show a few times in the

11:17.840 --> 11:25.080
past. So, anytime that you're hiding information inside of other file types, most commonly images,

11:25.220 --> 11:30.100
but it can certainly be a music video or anything like that, the term is steganography, and you can

11:30.100 --> 11:36.920
hide data in there in multiple different ways. Usually, it's a, it's a matter of, of least

11:36.920 --> 11:43.300
significant bits, but, gosh, I can't go, I don't want to go into too much detail, because it would

11:43.300 --> 11:46.940
take a whole show in and of itself again, and I think, again, we've done that before.

11:47.840 --> 11:53.220
Um, but, there are a lot of ways that you can hide data in images, and the person on

11:53.220 --> 11:57.400
the other end would have to know the algorithm, or the way that you put that data in there,

11:57.400 --> 12:03.260
and it's something that you can't really see. It does not sound like that's what you're

12:03.260 --> 12:09.000
describing here in Jack. It sounds like what you're describing is, I don't know, I'm not

12:09.000 --> 12:14.680
quite sure I can see how the computer could easily encode, and then subsequently decode

12:14.680 --> 12:20.060
this. I can see how a human might be able to decode this if they know the pattern or

12:20.060 --> 12:26.340
if they know the detail of it, but I'm not sure how easy this would be to, to automate

12:26.340 --> 12:31.260
and write a program to do this. Am I, am I interpreting this email right? Are you, are

12:31.260 --> 12:33.520
you on the same page as me, or do you, are you seeing something different here?

12:33.520 --> 12:40.280
Obviously computers can't tell smells, and tastes, and touch, and things like that, so

12:40.280 --> 12:44.860
those are kind of sort of out of the question. I'd use the graphics example that he talks

12:44.860 --> 12:51.520
about. I mean, you could say if this pixel has this color in it, then it represents this

12:51.520 --> 12:59.040
letter, and things like that, but I'm just not sure. You still would have to have a pattern

12:59.040 --> 13:03.160
to know, you'd have to have some kind of key to tell it which pixel is worth which value,

13:03.280 --> 13:07.520
so you'd have to have some sort of key. So in that aspect, it's not really any different

13:07.520 --> 13:14.040
than simple or basic public key encryption. So I'm just not quite sure I understand it.

13:14.140 --> 13:21.380
So in Jack, I guess the best thing, I'm not sure really. I would think that this is a little

13:21.380 --> 13:27.160
bit too complicated to answer in an email, especially with the specifics that you're talking about

13:27.160 --> 13:30.680
here. I think this might be something good to open up on the forums, start a thread in

13:30.680 --> 13:36.280
the forums, because it is definitely an interesting idea. And let's see maybe if it'll come across

13:36.280 --> 13:39.780
better with a little bit more detail, typed out in a little bit more detail, maybe some

13:39.780 --> 13:47.620
examples. So I think that's probably the best way to go with that one. Let's see, how about

13:47.620 --> 13:56.800
we move on to email number two from, actually from Wiccan2, W-I-C-C-A-N-2. Oh, that would

13:56.800 --> 14:01.380
be my Windows Vista box over there blinking at me in the background, if anybody heard that.

14:01.760 --> 14:06.440
But they're going to have to wait. Wiccan2 says, just thank Dog and co-host, you said in

14:06.440 --> 14:11.860
episode 187 that technology such as body enhancements is going to be available generations

14:11.860 --> 14:17.780
from now, but it is actually closer than we think. I saw a seminar last November called

14:17.780 --> 14:24.740
Upgrading Humans, where Professor Kevin Warwick had designed and built an implant that allows

14:24.740 --> 14:31.040
him to interface his nervous system to a computer. During his experiments, he was able to use

14:31.040 --> 14:36.460
ultrasound to detect objects by using a baseball cap fitted with ultrasound sensors, and he was

14:36.460 --> 14:41.680
able to remotely control a robotic hand across the internet. His nervous system was assigned

14:41.680 --> 14:48.320
an IP address, hand, he was situated in America, and the hand was situated, and he was situated

14:48.320 --> 14:53.420
in America, and the hand was situated in the UK. Just by thinking about moving the hand, the

14:53.420 --> 14:59.040
hand would respond. He was also able to use a limited form of communication with his wife

14:59.040 --> 15:04.540
on a nervous system to nervous system level. Through his work, he claims to be the world's

15:04.540 --> 15:09.280
first cyborg and believes that computer, that human computer enhancements will be available

15:09.280 --> 15:15.200
in the not-too-distant future. From the work that is being done around the world, body hacking could

15:15.200 --> 15:20.560
become reality sooner than we think. And he gives a couple links at the end of this email,

15:21.120 --> 15:31.040
kevinwarwick.com, Professor Warwick's site, it's K-E-V-I-N-W-A-R-W-I-C-K.com, and there is also a

15:31.040 --> 15:37.360
Wikipedia entry for Kevin Warwick as well. Keep up the good work at the DDP Wiccan 2.

15:38.560 --> 15:42.920
Well, thank you for the email, Wiccan 2. I appreciate it. Just to clarify, though, I don't

15:42.920 --> 15:48.760
think I said, I know I said last week that it is generations off, but just to clarify, I'm saying

15:48.760 --> 15:54.900
that it's not going to be publicly available for a few generations. It's going to be quite a while

15:54.900 --> 15:59.460
before this is something that's rolled out and you can go into the hospital and get. It's going to be at

15:59.460 --> 16:05.480
least a full generation, if not probably even more. That's not a comment on the technology. I

16:05.480 --> 16:10.000
think there's actually several people out there. All right, maybe not several, but a few, a handful,

16:10.480 --> 16:15.700
that are doing things like this to themselves and volunteers on a very small scale and developing a

16:15.700 --> 16:19.240
lot of this stuff. I think we said that a lot of this stuff is actually garage development type stuff.

16:19.780 --> 16:26.140
But what I was really more commenting on was the price of doing these things and the relationship

16:26.140 --> 16:30.220
with our health care system and our insurance system, which is a horribly, horribly corrupt

16:30.220 --> 16:36.960
system. And the prices are mandated and controlled by the American government anyway, has got their

16:36.960 --> 16:42.480
hands tied into this. So what I was trying to say anyway was that this is probably generations

16:42.480 --> 16:49.080
off before any normal everyday person is able to go into a hospital because they have headaches

16:49.080 --> 16:53.020
and get a chip in their brain that's going to prevent headaches in the future or something

16:53.020 --> 16:59.100
like that or permanent vision correction by putting like a cybernetic chip or some kind

16:59.100 --> 17:03.780
of lens in their eye to permanently correct their vision. These type of things, I think,

17:03.820 --> 17:08.100
are still a ways off because there's just too many hoops that you have to jump through in

17:08.100 --> 17:13.520
this country to get those things rolled out. But I mean, that's my opinion. But what do

17:13.520 --> 17:18.920
I know? I mean, Mubix, have you heard any stories of people like this or do you know any

17:18.920 --> 17:28.060
cyborgs? That's a funny question. You know, I do not know anybody, but this scares me. It

17:28.060 --> 17:35.840
brings back flashbacks of Johnny Mnemonic and like people going crazy with this stuff. And

17:35.840 --> 17:42.240
you know, I don't even have any tattoos because I don't like changing my body because I think

17:42.240 --> 17:52.740
it does stuff. But you know, putting technology in you is not something I am looking forward to at

17:52.740 --> 17:57.320
all. Just personal opinion there. Well, and you know, there's a whole nother topic that we won't go

17:57.320 --> 18:02.780
down this road of, you know, hacking the human body that's been upgraded in cyborg. I mean,

18:03.560 --> 18:09.140
planting a virus and controlling. What if I hacked into this guy's, whatever is the IP address of the

18:09.140 --> 18:15.080
hand? And I start choking. Or a virus system. Yeah. Or I grab this remote hand over the internet

18:15.080 --> 18:20.740
and start choking his wife with it. I mean, I mean, there's a lot of, I don't know, it's all kind

18:20.740 --> 18:25.220
of fiction right now. And it's funny to say, but you just don't know what the future holds. I mean,

18:25.660 --> 18:29.340
and that's again, another reason that it's going to take a long time before this stuff kind of rolls

18:29.340 --> 18:35.760
out to the public. All of these things have to be taken into consideration. But yes, I'm with you on

18:35.760 --> 18:41.780
the, I don't have any tattoos. And yeah, I'm not, I don't know. I mean, there's, there's,

18:42.120 --> 18:45.680
who knows what the future holds as far as that stuff goes and what decisions you'll make. If

18:45.680 --> 18:51.700
there's a technological solution, make me a cyborg if it'll save my life or if it'll enhance my life

18:51.700 --> 18:57.180
when I'm, you know, in some extraordinary way. I'm not completely opposed to it, but I'd have to be

18:57.180 --> 19:01.600
convinced pretty hard. I'm not going to get my, this LASIK surgery or anything to cut my eyes open with

19:01.600 --> 19:05.240
either because I don't feel comfortable with it. So, so I feel you on that part of things.

19:05.240 --> 19:14.280
Yeah, don't get me wrong. I'm not completely against it. I just, I'm afraid, like, I would

19:14.280 --> 19:20.240
love to jack into the internet and see it visually and all that stuff, but I definitely am not

19:20.240 --> 19:23.040
looking forward to the hacking aspect of it.

19:23.720 --> 19:29.740
Right. Of course, we could get like an implant for Savant and Black Ratchet where, put a little

19:29.740 --> 19:31.000
chip in their brain so that when they're...

19:31.000 --> 19:31.580
Can they tell a difference?

19:31.580 --> 19:35.780
Well, probably. Well, they got nowhere to go but up, if you know what I'm saying.

19:37.740 --> 19:41.720
Oh, come on. I love you guys. Give me a break. No, but we got to, we got to put a chip in

19:41.720 --> 19:45.820
there that does nothing but synchronizes to IMDB so they have that movie database in their

19:45.820 --> 19:50.260
head so they don't screw up any more movie quotes. If they ever on the spot and they're

19:50.260 --> 19:53.240
recording the show and they want to do a movie quote, they can just kind of real quickly

19:53.240 --> 19:59.400
hit imdb.com or look up on the global interweb, if you will, or Wikipedia, even better, a better

19:59.400 --> 20:03.360
source of misinformation. But I digress.

20:04.420 --> 20:08.980
All right. Our last email this week is actually, it's one of my favorite emails in a long time.

20:09.440 --> 20:15.860
Email is from Bushwick. Bushwick says, well, first of all, the following demonstration was

20:15.860 --> 20:20.580
crafted by a listener of BinRev Radio. The host nor the co-host, that would be you, condone

20:20.580 --> 20:26.600
any activities of this nature. This demonstration is for educational purposes only. So, first

20:26.600 --> 20:30.920
of all, he put that disclaimer in the top of the email, so I'm going to go ahead and read

20:30.920 --> 20:31.820
it and put it out there.

20:33.020 --> 20:36.920
Well, I don't know anything that doesn't get me in trouble, so you're fine there.

20:37.020 --> 20:41.360
There you go. There you go. And we'll address this email. We'll address this email specifically

20:41.360 --> 20:47.260
because it is actually very interesting. And there's still nothing illegal in this country

20:47.260 --> 20:54.320
yet, thank God, about talking and discussing things. You know? Luckily, education is still

20:54.320 --> 20:54.780
not banned.

20:55.000 --> 21:00.320
Exactly. So, and truthfully, this is not really, there's nothing necessarily bad. This is an

21:00.320 --> 21:03.720
interesting idea that, well, let me go into the email.

21:04.860 --> 21:09.340
Greetings, Stank Dog, Black Ratchet, and or other co-hosts. Okay, let me start again.

21:09.440 --> 21:11.140
Greetings, Stank Dog, and Muvix. There we go.

21:11.140 --> 21:16.260
I'm a noob to BinRev Radio and IRC Chat, and I just got done listening to episode number

21:16.260 --> 21:21.720
186. With a discussion about responsible disclosure, something came to mind, and I wanted to see

21:21.720 --> 21:27.660
what you two thought about this thought process. Companies, financial institutions, and various

21:27.660 --> 21:32.260
universities don't want their security flaws disclosed to the public, obviously, and various

21:32.260 --> 21:36.620
hackers, let's say black hats, don't want to follow in the footsteps of the two geniuses

21:36.620 --> 21:42.640
who thought they could extort News Corp by going to MySpace in person to reveal a hack

21:42.640 --> 21:47.600
for money. Now, that's brilliant. Assuming that the exploit allows the black hat access

21:47.600 --> 21:52.860
to private information, name, phone number, social security number, etc., etc., what could

21:52.860 --> 21:58.640
stop a black hat from maybe not disclosing it to the companies themselves, or to try extort

21:58.640 --> 22:04.420
them directly, but maybe disclose the information to someone who could be directly affected negatively

22:04.420 --> 22:10.000
if the information were to fall in the wrong hands. A black hat could say, you know, you

22:10.000 --> 22:15.580
could profit from my discovery. A good case could be made for negligence here, and you

22:15.580 --> 22:21.820
can sue XYZ blank blank blank company here for a good chunk of change. Maybe if I reveal

22:21.820 --> 22:26.240
this to you and you take them to court, you could cut me in on a portion of the judgment.

22:27.300 --> 22:32.000
Let's go one step further. Let's assume that a group of black hats were working together

22:32.000 --> 22:36.940
who would intentionally go out and register personal information on a myriad of websites,

22:37.500 --> 22:41.180
and a few of them intentionally go out and exploit those same sites to see if they could

22:41.180 --> 22:45.980
retrieve that same personal information. Then the black hat themselves go after the businesses,

22:46.200 --> 22:51.540
schools, individuals, etc., for obvious negligence. Assuming that it could be proven in a court

22:51.540 --> 22:55.740
of law, that could be a pretty hefty payday. How long would it take for companies, schools,

22:55.860 --> 23:01.400
individuals to change their policies regarding having security flaws disclosed? Great show, guys,

23:01.400 --> 23:05.740
and thanks to the BinRev IRC community for welcoming me in with open arms, even though my thought

23:05.740 --> 23:13.720
process is out there. Well, thank you for the email, Bushwick. I appreciate that. It's actually,

23:13.960 --> 23:22.800
this is a very good topic, a very interesting scenario, if you will. So, I'm actually with you.

23:23.180 --> 23:27.520
You know, let's throw out the disclaimer earlier. I'll just come out and say, I'm with you up to the

23:27.520 --> 23:34.400
part about disclosing privately to the affected companies and individuals. Okay, and let me, let me,

23:34.780 --> 23:38.880
I need some story time music or something to throw in here. Let me, let me share a little story here

23:38.880 --> 23:45.060
that I've never shared before. I'm going to keep it as pretty vague as possible, though. I found

23:45.060 --> 23:52.120
actually a flaw one time on the particular credit card company's website that gave me access to one

23:52.120 --> 23:56.920
person's account. It wasn't like it was a big widespread problem where I could access everybody's

23:56.920 --> 24:01.920
account and all these docs are dropped or anything like that, luckily. But it was a flaw that basically

24:01.920 --> 24:08.780
it was someone else at that credit card company that had a same, a similar real name to mine. So

24:08.780 --> 24:13.560
their, their, the name on their account was very similar to mine. So it was just a kind of a silly,

24:13.760 --> 24:19.940
simple flaw and it was easy to fix. I actually knew exactly how to fix the flaw. So going back to 186,

24:19.940 --> 24:23.200
what he's referring to here is we talked about disclosure, you know, how do you go about

24:23.200 --> 24:29.500
disclosing something like that? And, you know, again, my tendency is to keep my mouth shut and

24:29.500 --> 24:35.200
not say anything to anybody because of the fear of, of legal repercussions and I don't know,

24:35.260 --> 24:42.100
judicial, you know, repercussions, going to jail or anything like that. But in this case, I, again,

24:42.140 --> 24:47.940
I was hesitant to bring it up, but what I finally did was I chose to go ahead and call since it was one

24:47.940 --> 24:54.340
customer. It was totally accidental how I stumbled across this and I knew how to fix it. I decided to

24:54.340 --> 24:59.260
go ahead and contact this person. So what I did is I chose to call that individual customer whose

24:59.260 --> 25:05.980
account I had accessed accidentally. I called him from a safe phone, which means basically that I

25:05.980 --> 25:14.380
dialed in from my own caller ID spoofed phone. And even with that, I did a pass through through

25:14.380 --> 25:20.340
another caller ID spoofing service and did an out dial to this customer. And again, I had that

25:20.340 --> 25:24.600
customer's private information in front of me. That's where the phone number came from, along with

25:24.600 --> 25:29.600
a lot of other information, as you can imagine. So I kind of routed through, you know, back in the

25:29.600 --> 25:34.080
old days, they used to call it telnet hopping from one box to another. I phone hopped through a couple

25:34.080 --> 25:41.720
different boxes, spoofing different numbers along the way. I called him up and basically explained to

25:41.720 --> 25:49.880
him what had happened and in as little detail as possible. And obviously he was very shocked at

25:49.880 --> 25:53.840
first. I mean, he was just, he didn't even know if this was a prank or a joke or whatever. So I,

25:53.900 --> 26:00.800
you know, I basically told him what the situation was and how he could easily fix it. I gave him some

26:00.800 --> 26:04.480
of the information from his account to prove that it was, you know, that I was really seeing it.

26:04.920 --> 26:08.740
And I even told him, you know, call the credit card company and complain about it because this is a

26:08.740 --> 26:13.060
pretty serious thing. I showed, you know, I told him that I hadn't changed anything, you know,

26:13.100 --> 26:16.380
it was nothing like that. And I was logged out of it, never going to do it again. I walked him

26:16.380 --> 26:21.560
through changing it and everything. And that was the end of the story. I never followed up. I never

26:21.560 --> 26:27.980
heard anything more from it. That was it. End of story, as far as I know anyway. So why did, why do I

26:27.980 --> 26:34.460
bring that story up? Well, the point of the story is going back to what, um, Bushwick said in his

26:34.460 --> 26:40.620
email, disclosing the information to a third party who was affected. In this case, this individual

26:40.620 --> 26:44.960
person, he was a third party person who was affected by this. His docs were dropped, a privacy

26:44.960 --> 26:49.960
violation. Well, some people would say that that's actually the whole point of disclosure. That's who

26:49.960 --> 26:55.780
you're serving when you disclose this information. You're not necessarily, I mean, it's noble that you

26:55.780 --> 27:01.100
want to help the company. That's great. But I don't think that's really so much, at least in my

27:01.100 --> 27:09.260
opinion, my motivation, it's to help prevent all of those innocent, let's use, I don't, I guess I can

27:09.260 --> 27:16.640
use the word victims safely here. Those victims who didn't know that their, their identity is being

27:16.640 --> 27:23.260
so easily dropped out there or so poorly protected. So that's who you're serving. You know, keep in mind

27:23.260 --> 27:28.200
the goal. The goal is not to save the company from getting sued. The goal is to save people's

27:28.200 --> 27:33.680
privacies, at least in this case, you know, enhance people's security. That's the ultimate goal. So,

27:34.440 --> 27:40.060
you know, disclosure, depending on how you look at it, you're always helping a third party, whether

27:40.060 --> 27:44.500
it's an individual or a group. Did that make sense at all? Are you following me there?

27:44.500 --> 27:52.640
Yeah, I'm following you. You know, this discussion, in general, has been a big buzz across the net.

27:53.640 --> 28:02.240
And as we did a Spoilcast episode on it, there's been numerous talks everywhere, just on every

28:02.240 --> 28:09.640
level of this topic. And I put my brain power to it. And the only thing that I can think of

28:09.640 --> 28:17.300
to effectively solve this problem so that you can disclose something without having repercussions

28:17.300 --> 28:25.520
is having an intermediary. Basically, having a non-profit organization that everybody submits to,

28:26.060 --> 28:32.180
they check it, and they submit it to the company. That way, they have like a non-disclosure agreement

28:32.180 --> 28:38.580
so they don't disclose who submitted it, and they don't submit it, or they don't disclose it to the world

28:38.580 --> 28:46.620
as full disclosure. The company has to react on it in, say, 30 days, or a year, or whatever.

28:46.960 --> 28:49.560
And then it goes public, or something like that.

28:49.940 --> 28:51.700
Yeah, that's not a bad idea at all.

28:51.700 --> 28:53.060
I just don't think the one-on-one works.

28:53.460 --> 28:58.880
Yeah, that's not a bad idea at all, actually. The problem with that would be finding third-party,

28:59.080 --> 29:06.760
independent companies that are trusted by both parties. If they're going to be basically puppets

29:06.760 --> 29:09.520
of the corporations or the companies, then the hackers are going to be like,

29:09.600 --> 29:13.400
why should we participate and disclose to you? We're going to do it the same way we've always

29:13.400 --> 29:20.480
been doing it. And if it's an organization set up by hackers, programmers, open source people,

29:20.580 --> 29:25.120
whatever, whatever you want to call them, the companies probably aren't going to trust and

29:25.120 --> 29:29.300
support it, because to them, they're not getting any necessary benefit out of it. There's a lot of

29:29.300 --> 29:35.660
trust going on. So it's a good idea. I would love to see that idea pursued, and see if they

29:35.660 --> 29:40.320
could pull something off that's at least some sort of compromise in between. The other thing,

29:40.480 --> 29:44.640
Jennifer Granik, I know, has spoken about this from the Cyberlaw, Cleveland Cyberlaw Connects,

29:44.660 --> 29:50.800
talked about easing up some of the laws to make it not as dangerous for people to disclose things.

29:50.900 --> 29:54.660
But that's a touchy subject, too. I mean, the whole subject's touchy. And again, go back to

29:54.660 --> 30:01.140
episode 186, it was all about this topic, and it's something that comes up on multiple episodes of

30:01.140 --> 30:04.480
the radio show over the past four years that we've been doing it. It's come and we've touched

30:04.480 --> 30:10.780
on it so many different times. So it's basically, at this point, it's a personal decision. Everybody's

30:10.780 --> 30:16.960
going to have to find their own line at this point. Now, speaking of that line, to get back

30:16.960 --> 30:22.080
to this email, this is where I kind of start to disagree with the email, is when it crosses

30:22.080 --> 30:26.340
from that line, you know, disclosing to third parties that people are affected, that's great.

30:26.340 --> 30:31.260
I support that. I agree with that in most cases. I can't think of any cases where I

30:31.260 --> 30:36.900
would not support that. But you cross a different line when you amount, when you cross, you cross

30:36.900 --> 30:41.820
a different line when you basically commit what is extortion or blackmail, which is the

30:41.820 --> 30:47.460
scenario he described. Anytime you ask to be cut in on money of any kind, whether lawsuit

30:47.460 --> 30:54.160
or asking to be paid to not disclose or selling information, information that could be used

30:54.160 --> 30:58.680
in a bad way, selling it to someone whom you know is going to use it for ill intent.

30:59.720 --> 31:07.820
You're crossing a whole different, and to me, very clear and simple ethical line there.

31:08.380 --> 31:13.080
The second, and here it is, it's very simple in my eyes, and by all means, I would welcome

31:13.080 --> 31:17.840
any email that wants to say otherwise. I'm not saying it's right, but to me, it's so clear

31:17.840 --> 31:23.500
cut. The second that you try to profit off of any of the information, you've committed

31:23.500 --> 31:30.160
a crime. It's extortion, it's blackmail, it's so many different names to it, and ethically

31:30.160 --> 31:35.220
speaking, it's wrong. That is not what the hacker ethic is all about. The hacker ethic

31:35.220 --> 31:40.260
is about releasing that information and trying to help the people involved. It's not about

31:40.260 --> 31:49.100
using it to make money or using it to your own ends. So, and frankly, legally, that's ethically

31:49.100 --> 31:52.720
speaking. Legally speaking, the second you committed a crime, the second you access the site

31:52.720 --> 31:56.420
without permission, or the second you started doing the research. Again, that's a whole

31:56.420 --> 32:00.640
other topic for another time. You know, we've beaten that horse to death, actually, on the

32:00.640 --> 32:05.700
show, of why is it necessarily illegal just because you did this, just because you poked

32:05.700 --> 32:09.640
around there. The way the laws are written now, they're unfortunately not in our favor for

32:09.640 --> 32:19.000
doing basic research. But I don't see that changing. I completely agree with you there. I mean, there is

32:19.000 --> 32:26.160
that, you know, we, most people don't understand this like normal population, but hackers do have

32:26.160 --> 32:34.560
lines where they have a set of ethics. Sure, there is a hacker ethic. So that definitely goes beyond even the

32:34.560 --> 32:41.840
hacker set of ethics. Yeah, there is definitely a hacker ethic. And it's, that's this whole

32:41.840 --> 32:46.800
misconception. I mean, I wish, I would love to see a local news story instead of doing some story about

32:46.800 --> 32:51.800
hackers committing ATM fraud, or hackers stealing your credit card information, or hackers blah, blah,

32:51.880 --> 32:56.740
blah, which of course is basically they're using the word hacker as thief. I would love for them to do a

32:56.740 --> 33:01.860
story saying about hacker ethics. Maybe if they did one story like that and understood hacker ethics,

33:01.860 --> 33:05.960
they'd not make so many of those other stories. But anyway, I'm going to get off the soapbox on

33:05.960 --> 33:10.500
that one. We've beaten that horse to death too, and you're getting me fired up now, and I'm running

33:10.500 --> 33:17.400
out of iced tea. And actually, that's the last scenario that he poses in the email is a very

33:17.400 --> 33:24.740
interesting one. Insofar, from a research standpoint as well, and that is registering for a bunch of

33:24.740 --> 33:28.700
sites. Now, he's saying a black cat group or something. I'm just going to leave the terminology out of

33:28.700 --> 33:34.900
it. But registering for a bunch of sites to see or prove, if you already know, if they're vulnerable

33:34.900 --> 33:42.460
raises a whole other interesting issue. Anytime you find an exploit, you have to be able to prove

33:42.460 --> 33:46.620
it. You have to be able to recreate it and show that it wasn't a fluke or an accident, that it's

33:46.620 --> 33:50.880
something that can be reproduced over and over again. And the term for that is usually a proof of

33:50.880 --> 33:55.780
concept, whether that's a bit of code, whether that's an outline of a process that you go through to

33:55.780 --> 34:01.080
get from A to B. So making a proof of concept is something that's very common. When we find an

34:01.080 --> 34:05.420
exploit and you want to prove it to everybody, you release all this exploit code out there, this

34:05.420 --> 34:10.080
proof of concept code. And that's probably the most common when you think exploit. That's the most

34:10.080 --> 34:14.700
common thing you see out there. It's people who've written a script to take advantage of the exploit

34:14.700 --> 34:23.580
or the vulnerability. Now, it's, again, back to the hacker ethic. It's kind of morally against that

34:23.580 --> 34:30.220
hacker ethic if you do this under the intent to somehow make money or capitalize on this information.

34:30.520 --> 34:35.960
Once again, it's about releasing the information and helping and saving people. If you go, if you have

34:35.960 --> 34:40.260
the intent to sue someone or start a class action lawsuit against someone, to use the example from the

34:40.260 --> 34:46.380
email, yes, you've crossed a whole different ethical line. But I think all of our listeners

34:46.380 --> 34:53.180
probably are knowing right now that not only is it ethically wrong, but you don't have a legal leg

34:53.180 --> 35:01.260
to stand on a case like this because, well, and maybe people don't know this, but it's different

35:01.260 --> 35:06.380
when you are an innocent third-party victim who had no knowledge or understanding that this could

35:06.380 --> 35:11.560
happen. You have an expectation of privacy with these companies, like let's say a credit

35:11.560 --> 35:16.360
card company, for example. You have an expectation of privacy that they're going to do their due

35:16.360 --> 35:25.240
diligence to protect your personal information. But if you go in there and create accounts and put

35:25.240 --> 35:32.240
your information out there with the intent and the goal to release an exploit later on only so that

35:32.240 --> 35:37.340
you can get caught up in a class action lawsuit or so that you can sue somebody using an exploit

35:37.340 --> 35:42.540
that you were aware of or you discovered, you're not an innocent third-party victim getting caught

35:42.540 --> 35:48.340
up in a negligence case. You knew the system was negligent and you chose, willingly chose to

35:48.340 --> 35:54.160
participate. I don't think that would last 10 seconds in court. Now, I think, now to go back to the email,

35:54.160 --> 36:00.440
I think he said, he does say, assuming that it could be proven in a court of law. So I'll give

36:00.440 --> 36:04.240
you, I mean, he did say that in his statement, but I don't think that would be all that difficult

36:04.240 --> 36:08.760
to prove in a court of law because all this stuff is logged on these servers. As soon as it happened,

36:08.820 --> 36:13.300
they could easily go back in there and find out where did this come from, who did it, oh, isn't it

36:13.300 --> 36:17.660
interesting that he created an account two weeks before the exploit happened or something like

36:17.660 --> 36:23.640
that. There's a lot of ways that they could find this kind of stuff. So, again, totally unethical.

36:23.640 --> 36:32.140
Just a second. Yeah. I do forensics on computers all the time and users are amazed every day

36:32.140 --> 36:40.460
at what I can find and dig up on servers, logs, computers, just to point out to the listeners

36:40.460 --> 36:46.040
that even though you might think you're being really sneaky with what you're doing, you can

36:46.040 --> 36:47.420
get caught just as easy.

36:47.680 --> 36:51.400
Oh, yeah. I think all of our users are well aware of that. That's why we've done episodes

36:51.400 --> 36:57.840
of wiping your hard drive out with how many passes, seven passes DOD standard and 21 passes

36:57.840 --> 37:03.440
and all that kind of good stuff. We've definitely made it clear. Now, of course, it's not something

37:03.440 --> 37:07.100
I'm going to wipe my drive every single time I use it either. That's kind of ridiculous.

37:07.340 --> 37:15.900
So, you know, it's plausible deniability comes into play and so you might want to make some

37:15.900 --> 37:20.660
sort of a pattern of it so that you can maintain that excuse. And, well, anyway, I digress.

37:20.760 --> 37:26.060
We could, again, go into that on another show sometime that we have in the past. So, again,

37:26.180 --> 37:30.760
thanks for the email. That was really, I think that was really in-depth. No disclaimer necessary

37:30.760 --> 37:34.740
because, again, learning and understanding and discussing these things. And hopefully we'll,

37:34.740 --> 37:39.260
you know, hopefully people agree with me. I mean, people who really understand and get

37:39.260 --> 37:44.240
the hacker ethic that are real hackers, I think should agree with that or understand

37:44.240 --> 37:49.000
that. And there's nothing wrong with thinking from a different point of view or thinking

37:49.000 --> 37:53.400
from the other side, if you will, because that helps you understand where you might be missing

37:53.400 --> 37:57.500
something, where holes might be, et cetera, et cetera. So, Bushwick, thank you very much.

37:57.540 --> 38:00.920
That was one of the most interesting emails in a long time. And everybody, actually, really

38:00.920 --> 38:06.180
good feedback on the show this week. However, in lieu of making an entire email show again,

38:06.240 --> 38:11.460
let's move on and do our main topic for the week, if you're ready, sir.

38:12.680 --> 38:13.820
I am, actually.

38:13.840 --> 38:18.020
All right. Well, and we kind of alluded to it earlier. We talked about the main topic is

38:18.020 --> 38:23.260
going to be, we're going to kind of go through a list of several and discuss several different

38:23.260 --> 38:28.840
software packages that you can throw on a USB key, stuff that's useful to hackers and in

38:28.840 --> 38:33.460
some cases useful to anybody. And that's something that you have some experience with, right?

38:34.660 --> 38:42.000
Right. I actually am quite popular for my USB applications, the ones that I think I don't

38:42.000 --> 38:53.040
write them, at work and across the net. So, the first one that I want to talk about is

38:53.040 --> 38:55.260
TCP view. It's by Sysinternals.

38:55.260 --> 38:58.020
Well, wait a minute. Wait, wait, wait, wait. Hold on. Before we go into some of the detail

38:58.020 --> 39:01.620
of it, let's talk about, let's talk about just some general, like, I mean, obviously

39:01.620 --> 39:07.160
our users are technically savvy. They know what a USB key is, right? And, you know, the

39:07.160 --> 39:12.480
most useful feature, at least for me, is just moving files from one system to the other.

39:12.580 --> 39:19.400
That's mainly what I used it for. But, not only can you keep handy and useful software

39:19.400 --> 39:23.400
on there, there's some software that's even designed these days to be portable, to be

39:23.400 --> 39:27.080
run from a CD or a floppy disk or a USB key, right?

39:29.160 --> 39:36.120
A lot of applications, believe it or not, don't make any registry changes. Don't make

39:36.120 --> 39:41.040
anything like that. So, you can actually turn them portable. They're not already made that

39:41.040 --> 39:46.820
way. Now, portableapps.com has all kinds of portable applications that are made to do

39:46.820 --> 39:54.640
it, like portable Firefox, portable Thunderbird. But, there's also any executable that only

39:54.640 --> 40:01.220
has maybe a configuration file in the same folder, or just this simple executable can

40:01.220 --> 40:05.400
be made portable, and you can take on your USB stick wherever you want.

40:05.580 --> 40:10.080
Right. The Unix way of doing things, where all your files are right there in the folder,

40:10.260 --> 40:14.860
self-contained for the most part, with, you know, exceptions, obviously. But, just a comp

40:14.860 --> 40:18.400
file, or an INI file, or whatever you want to call it, in the same directory with your

40:18.400 --> 40:20.540
executable, and you're off and running.

40:22.060 --> 40:22.420
Yeah.

40:23.040 --> 40:28.440
Now, the other question, though, is, like, and I know from experience, I can say, I've

40:28.440 --> 40:33.120
had problems with USB drives where I've pulled it out of my laptop bag, and it was just completely

40:33.120 --> 40:38.100
DOA. I'd lost everything that was on it. You've been using these quite a bit, like you

40:38.100 --> 40:41.280
said, at work. You're a popular guy at work. It sounds like when somebody wants to recover

40:41.280 --> 40:47.060
or needs anything, have you had any USB drives go bad? And, is it a matter, like, the brand

40:47.060 --> 40:52.100
of USB drive? Are any better than the others? I mean, generally speaking, I mean, can you

40:52.100 --> 40:56.160
recommend one over the other, or is there any handling tips? I mean, have you ever had

40:56.160 --> 40:58.020
one die on you, I guess, as a place to start?

40:59.340 --> 41:01.320
I've actually had many die on me.

41:01.320 --> 41:11.480
The thing that makes them die, I guess, easier is the environment or how you use them. If

41:11.480 --> 41:19.380
you're looking for a USB thumb drive and it has, like, a flip-top stick where the USB

41:19.380 --> 41:25.840
comes out, or basically the dongle is what dies the most, not the data on it. All it is

41:25.840 --> 41:32.060
is flashed. There's no moving parts. So, you've got to get one that, it's kind of ruggedized.

41:32.060 --> 41:42.560
It doesn't have something that, if you look at it, easily break. That's the most easy way,

41:42.780 --> 41:49.240
or the way that my USBs have died the most. One time I went swimming with one. I guess that

41:49.240 --> 41:56.720
would be considered dying. Yeah. But, not a good idea to go along with USB sticks.

41:57.720 --> 42:04.880
Hmm. I wonder if they, someone probably invented a waterproof USB stick, but I digress. So,

42:05.040 --> 42:11.660
so, that being said, then, would you recommend, because the, because they are volatile and because

42:11.660 --> 42:15.440
it may crash, it's like anything else. I guess you probably should have a backup somewhere,

42:15.580 --> 42:19.200
throw it to a CD or something, so if you ever buy a new USB, when one dies, you can

42:19.200 --> 42:26.840
restore easily, or? I actually use a, one of my, um, applications, one of my, uh, USB

42:26.840 --> 42:34.060
applications is Dursync, D-I-R-S-Y-N-C. And what I do is, it's running on my computer all

42:34.060 --> 42:39.980
the time. So, whenever I have my iPod, which is where I back up all my, um, USB sticks to,

42:39.980 --> 42:44.200
mm-hmm, and they're numbered, like, this is my one gig, this is my eight gig, whatever,

42:44.440 --> 42:52.000
512. Right. Um, it goes, as soon as I plug in both, it sees that both are plugged in as

42:52.000 --> 42:57.800
it backs up to my iPod. So, I always have a backup of my USB sticks at all times, if one

42:57.800 --> 43:01.760
goes back. Well, and this also makes it easy, like, if we meet up, you can give me a copy

43:01.760 --> 43:06.500
of one of them easily, too. That's true. Restore it over to someone else's drive, so that's

43:06.500 --> 43:10.400
kind of handy. That's a cool thing to take to the BINREV meetings or 2600 meetings or

43:10.400 --> 43:14.760
whatever and swap some of this stuff with other people. That's pretty awesome. All

43:14.760 --> 43:19.160
right, so, also then, yeah, and in that same mindset, then, would you recommend people just

43:19.160 --> 43:22.720
get the cheapest one they can get because they're all volatile in some way? Would you

43:22.720 --> 43:27.180
just say get the cheapest one? Don't invest a lot of money in a, you know, some particular

43:27.180 --> 43:33.340
name brand? I mean, they're all, for the most part, the same? Yeah, I would definitely

43:33.340 --> 43:39.020
get the cheapest one, and again, just make sure, however you plug it in, the USB part

43:39.020 --> 43:45.140
of it, the end of it, make sure that it's not easily broken because I put these through

43:45.140 --> 43:52.140
a lot of strength tests, basically, from day-to-day use, and I'm sure other people who do as well,

43:52.200 --> 43:56.540
they don't take care of them. So, that would be the one point that I would look for in a

43:56.540 --> 44:02.420
USB stick. Okay, cool. All right, well, now that we kind of talked about that a little

44:02.420 --> 44:07.940
bit, let's go into the details of some of the apps that you have found useful in your

44:07.940 --> 44:14.720
experience. All right, the first application that I got is a TCP view, which is from system

44:14.720 --> 44:19.280
channels, which, you know, got bought out by Microsoft. Microsoft, right. I got the app

44:19.280 --> 44:31.020
before, they got bought out, so it's still, I guess, tarnished. Un-Microsoft. So, un-Microsoft,

44:31.020 --> 44:33.820
there's a good term. Yeah, un-Microsofted.

44:35.960 --> 44:42.720
If you've ever been doing troubleshooting on a computer and you do a net stat just to

44:42.720 --> 44:48.940
or you have a virus and you want to know where it's going or what it's doing, basically, net

44:48.940 --> 44:57.520
stats real time is what TCP view is. And so, I can watch as connections get established or

44:57.520 --> 45:04.360
put into time weight or what ports I'm listening on, all kinds of stuff. And it shows me what

45:04.360 --> 45:11.560
application is doing that at the time, what protocol, what the local address is, or what

45:11.560 --> 45:15.980
the remote address is. It even does a DNS lookup on the remote address to tell me exactly where

45:15.980 --> 45:24.140
I'm going. All on the fly. Great tool. All actively and real time. And this particular

45:24.140 --> 45:28.600
tool is this one we referred to earlier where it's just having pretty much an executable and

45:28.600 --> 45:34.240
a configuration file and you can just execute it from the USB drive? It's a zip file that

45:34.240 --> 45:42.240
you get from Microsoft now. But, um, you just export it and you're set. I'm curious, did

45:42.240 --> 45:48.060
you, have you tried the Microsoft one yet? I have not. I refuse. I wonder how, I just,

45:48.140 --> 45:53.080
just from the curiosity of how much, how different they are. Well, you're going to have to wait

45:53.080 --> 45:59.400
for a listener to try because I refuse. All right. All right. Well, and Sysinternals

45:59.400 --> 46:03.080
actually made quite a few cool things before they were bought. Well, maybe that's why they

46:03.080 --> 46:08.800
were bought out. But, um, and that's also, we, we've, we've talked about in the past on

46:08.800 --> 46:12.580
the shows too. And it's, this is definitely worth bringing back up. Like I know one of the

46:12.580 --> 46:18.420
sites I used to like was, was called oldversions.com, but I'm sure there are several others now

46:18.420 --> 46:26.140
and probably just through word of mouth and, and, uh, bin rev forums, places like that finding

46:26.140 --> 46:31.180
older versions of software before they get destroyed or back when they were freeware,

46:31.300 --> 46:37.320
but when they've now become, you know, charge or shareware or pay for, you know, however,

46:37.500 --> 46:41.440
whatever their pricing scheme has changed, but it might've been free at first. So there's

46:41.440 --> 46:47.420
certainly a reason to keep older versions. There are, there's reasons not to keep them,

46:47.420 --> 46:50.800
obviously, if there's security problems or bugs or flaws, but there's certainly some

46:50.800 --> 46:56.520
reasons to keep these old, stable, good, useful applications around for a period of time.

46:56.600 --> 47:00.600
You don't always have to upgrade to the latest and greatest thing all the time.

47:01.580 --> 47:06.000
Oh, definitely. And there's, there's a couple of tools that I've kept around for a long time,

47:06.520 --> 47:14.160
um, coming up shortly, but to get onto our next tool, it's called Smart Sniff and it's by the

47:14.160 --> 47:23.680
NER, uh, NER CMD or NER soft guys. And this was really helpful to me because I was constantly

47:23.680 --> 47:33.280
going through ethereal captures and, or doing an ethereal capture on a computer. And I know I'm

47:33.280 --> 47:38.720
going to get flamed for this, but it's difficult going down packet by packet and looking and trying

47:38.720 --> 47:44.600
to, trying to sort them and filter it how you want it. Well, what Smart Sniff does is basically,

47:44.600 --> 47:52.780
um, it groups your packets together. It says this local, there's this remote address in this port

47:52.780 --> 47:57.920
is the same. So we're going to put it on. And it even has a quick preview on the bottom

47:57.920 --> 48:08.060
in ASCII. So I can say this, uh, local address, this remote address, and here's the git statement.

48:08.060 --> 48:15.400
Oh, it's an HTTP. Got it. And I see the git statement, the accept language all visually right there in

48:15.400 --> 48:23.620
front of me, even the packets going right after it. Great tool. I mean, I can, I can not say enough

48:23.620 --> 48:29.520
about how easy this makes my life. Right. And, and ethereal, of course, now known as Wireshark,

48:30.460 --> 48:34.720
it, it does, there's a little bit of a learning curve to that. And you, once you get the hang of

48:34.720 --> 48:38.720
it, you can, of course, combine the, the streams together. It'll put all the packets together

48:38.720 --> 48:45.040
for one request or one, uh, communication. So, you know, it's got some power there, but it is

48:45.040 --> 48:50.700
definitely got a, a bit of a learning curve to it. And Smart Sniff, again, is, is very portable.

48:50.700 --> 48:59.560
Very portable. Um, it's a single executable, no configuration, you know, uh, I mean, you can

48:59.560 --> 49:09.080
configure it and it, it stores the options on a file or registry setting, but, um, no extra files

49:09.080 --> 49:16.520
initially. And actually, yeah, you, you kind of bring up a good point there too. Earlier we talked

49:16.520 --> 49:19.940
about, you know, they don't always have to write registry entries and stuff like that,

49:20.000 --> 49:25.480
but it's actually worth mentioning and keeping in mind, you actually should watch to make sure

49:25.480 --> 49:31.400
that, that it does not create registry entries. That's a thought to keep in mind as well, because

49:31.400 --> 49:36.560
let's say that your goal is to slip in a USB key, and I think we might talk about this later

49:36.560 --> 49:41.380
if we have time as well, to execute something covertly, quietly, without being discovered. You

49:41.380 --> 49:46.900
want to swap a, slap a USB key into someone's computer, run something, and then get out of

49:46.900 --> 49:51.420
there and not leave any signs. You want to be careful that your app isn't quietly, without

49:51.420 --> 49:55.760
your knowledge, writing a, a, a registry key out there, so that when you leave and think

49:55.760 --> 50:00.580
you've left no footprint, that it might have, in fact, put something out there in the registry.

50:00.760 --> 50:05.340
And hopefully nothing too incriminating or, or personal or anything like that, but even

50:05.340 --> 50:10.980
if you leave, I don't, can't think of an example, if let's say Ethereum, which is not

50:10.980 --> 50:18.240
the case, but throws a, a, a, a key out there for Ethereum or Smart Sniff or TCP or any of

50:18.240 --> 50:21.700
these, which again, they're bad examples, because I can't think of one, but if you leave a key

50:21.700 --> 50:27.020
there, that's going to potentially draw interest from somebody saying, wait a minute, something's

50:27.020 --> 50:29.160
fishy here, I've never heard of this software before.

50:29.160 --> 50:35.480
Actually, there is a program that you can use, that I use all the time, which is in

50:35.480 --> 50:39.840
our show notes, so we can add it later, registry monitor by sysinternals.

50:40.900 --> 50:51.720
Every time I get a new application, USB, the application, say it again, is, I throw it in, run

50:51.720 --> 50:58.820
it, and using registry monitor with the filtering on for that specific executable, it tells me

50:58.820 --> 51:05.580
exactly what query, what set value, what create value, everything that it does in the registry,

51:05.720 --> 51:11.960
I can see what it does, and I audit that before I start using it, because I don't like my registry

51:11.960 --> 51:13.460
all gunked up.

51:14.220 --> 51:14.700
Right.

51:15.980 --> 51:21.000
Yeah, and there's lots of registry cleaner things out there on an unrelated note, but yes, that

51:21.000 --> 51:22.580
was another cool sysinternals tool.

51:22.580 --> 51:26.140
All right, what else you got on there?

51:27.480 --> 51:32.360
All right, now, I might get flamed for this, but the next one up is PSPAD.

51:32.560 --> 51:39.020
The thing I like about PSPAD, again, I'm a very lazy person, so anything that makes life

51:39.020 --> 51:40.800
easy is what I use.

51:40.800 --> 51:49.280
The reason I use PSPAD is I can drag and drop any executable I want, and it's now turned

51:49.280 --> 51:50.180
into a hex editor.

51:50.720 --> 51:56.620
I can drag and drop any HTML document, and it's turned into an HTML editor.

51:56.620 --> 52:04.860
And the thing that's nice about it, to add on to it, is that on the left-hand side, I

52:04.860 --> 52:10.100
can open up a FTP client right there.

52:10.100 --> 52:18.960
I can have my favorite directories and folders, and I can save my settings locally so that

52:18.960 --> 52:25.100
I can bring this whole thing around to on my USB key and have my settings have where

52:25.100 --> 52:28.280
my FTP server is located.

52:28.720 --> 52:33.800
All this just makes life easy.

52:34.200 --> 52:35.560
Again, I can't say enough about it.

52:35.560 --> 52:42.360
Yeah, and it will, is it context-sensitive insofar as you said, like if you wanted to

52:42.360 --> 52:48.280
edit HTML or Perl, is it context-sensitive or syntax-sensitive so that it would actually

52:48.280 --> 52:53.240
highlight and colorize so it makes it a little bit easier to edit, or is it pretty much just

52:53.240 --> 52:55.040
black and white plain text type editing?

52:55.500 --> 52:58.220
No, it does do colorization and highlighting.

52:58.880 --> 53:04.260
It's not as good as it doesn't do all the ones that are available out there.

53:04.260 --> 53:09.960
I've seen other tech centers that can do a myriad of ones, but they have the majority

53:09.960 --> 53:11.520
in PSPAD.

53:12.060 --> 53:12.640
Okay, well that's good.

53:12.760 --> 53:16.760
I was kind of curious why you put that one on there, because I do use a lot of different

53:16.760 --> 53:21.260
ones, and they're certainly better out there from a programming standpoint that I use frequently,

53:21.480 --> 53:27.040
but for overall ease of use and portability, PSPAD, PSPAD, right?

53:28.100 --> 53:28.540
Correct.

53:28.960 --> 53:30.260
Okay, cool, cool.

53:30.260 --> 53:33.740
So where do we go from there?

53:33.960 --> 53:39.700
Now the next one up is System Information for Windows, or SIW.

53:40.160 --> 53:44.700
Now this one doesn't really, it's like the Space Monger of information.

53:45.160 --> 53:53.020
Space Monger was a tool that really didn't get much media, because it was released really

53:53.020 --> 53:55.460
not very much.

53:55.580 --> 53:58.720
I'm sorry, can't find the words today, but...

53:58.720 --> 54:00.420
Hey, my world, and welcome to it.

54:01.760 --> 54:06.600
It's like every episode of BinRev Radio I've ever done, I stumble over everything I say,

54:06.720 --> 54:07.780
so it's not like...

54:07.780 --> 54:11.500
Our listeners are definitely used to hearing it from me, so you're doing pretty darn good.

54:15.020 --> 54:18.800
Okay, since it just doesn't get that much media attention, but it should.

54:18.800 --> 54:21.780
It is a must.

54:21.980 --> 54:31.340
I give it to all my other admins where I work, and in order to operate efficiently, you have

54:31.340 --> 54:32.160
to use this tool.

54:33.500 --> 54:37.240
What it does is it gives you so much information on the computer you're currently on.

54:37.240 --> 54:48.660
Everything from a breakdown of your system information, what ActiveX modules are installed, any open files

54:48.660 --> 54:52.580
currently, even your LSA secrets, it dumps those.

54:53.620 --> 54:54.860
Now, from Windows, of course.

54:55.700 --> 55:00.040
Now, this is not picked up by any virus scanner or anything, because it's not a virus.

55:00.140 --> 55:01.240
It just tells you all your...

55:01.760 --> 55:03.500
Basically, it's not a hack tool.

55:03.500 --> 55:08.940
It tells you the information about this computer that you're currently on, and it needs administrative

55:08.940 --> 55:09.320
reps.

55:11.760 --> 55:12.200
So...

55:12.200 --> 55:13.940
But that's not it.

55:14.040 --> 55:15.060
That's not all it does.

55:15.820 --> 55:21.120
Down in the network section, it has a hardware or software and a network section on this information.

55:22.080 --> 55:28.640
In the network section, you can issue a network neighborhood scan.

55:28.640 --> 55:33.860
So I can find out all the computers in my network neighborhood.

55:34.360 --> 55:42.080
I can then, after that, scan that network neighborhood for FTP clients, HTTP clients, NetBios clients, Oracle.

55:43.080 --> 55:44.940
And it goes on.

55:44.940 --> 55:59.100
So what I can also do, the same thing with TCP view is, it's a lie, but it shows me a dump of all the NetStat information.

56:01.260 --> 56:02.240
A dump of it?

56:02.240 --> 56:03.380
You can also, with this...

56:03.380 --> 56:09.600
I'm sorry, with this tool, you can export all the information into an HTML document.

56:09.600 --> 56:18.560
So, this is just basically your quick and easy audit of a computer, and it's free.

56:19.520 --> 56:27.680
Yeah, and that's a utility designed for, you know, people that are running labs or in charge of maintaining computers and stuff like that.

56:27.720 --> 56:32.840
It's probably who it's originally designed for, but it does a great job of footprinting, it sounds like, and telling you a lot of information.

56:32.840 --> 56:33.840
Definitely.

56:36.560 --> 56:42.180
And have you ever had a computer where you had to rebuild it and drivers were?

56:43.040 --> 56:43.700
Of course.

56:43.760 --> 56:44.840
Or couldn't find the...

56:45.680 --> 56:48.280
Well, this thing outputs the driver as well.

56:48.880 --> 56:52.860
So, I do this on any new computer I get.

56:52.860 --> 57:02.040
I really quick open up SIW, hit export, about two minutes later, because it does all these nice little utilities on the computer itself.

57:03.320 --> 57:11.120
I export it, I save it to my USB stick, and I'll never have to try and guess what's in my computer again.

57:12.320 --> 57:13.120
Cool, cool.

57:13.220 --> 57:20.420
Now, just to re-clarify, because it pretty much says it right in the description, it's called software information for Windows.

57:20.640 --> 57:21.480
So, this is a Windows.

57:21.480 --> 57:24.300
Is it bound to any specific versions?

57:24.480 --> 57:26.380
I mean, does it work all the way up to XP?

57:26.660 --> 57:28.460
I'm assuming it's not supporting Vista yet?

57:30.300 --> 57:32.140
I have not tried it on Vista.

57:32.840 --> 57:36.740
However, I have tried it on XP and 2000 and Oryx on both.

57:37.000 --> 57:37.340
Okay.

57:38.700 --> 57:39.600
So, that's something...

57:39.600 --> 57:44.580
See, that's one of the ones where you probably would want to update it as new releases come out,

57:44.580 --> 57:50.320
because it's going to have more information about different versions of the operating systems that you want to deal with,

57:50.320 --> 57:51.840
or pulling more information.

57:52.100 --> 57:54.840
So, that sounds like a pretty useful one as well.

57:57.100 --> 58:01.040
And this next one actually is very familiar in name anyway.

58:01.220 --> 58:02.300
And what is that one?

58:03.940 --> 58:04.740
Bear Grip.

58:04.980 --> 58:09.600
And this is another one that's little known to the community.

58:10.800 --> 58:12.800
Grip is known across the world.

58:12.980 --> 58:13.200
Right.

58:13.200 --> 58:14.260
Everybody knows what Grip is.

58:14.900 --> 58:20.600
But, when it comes to Windows, you really don't have a Grip solution.

58:20.860 --> 58:21.620
You got Fine.

58:22.420 --> 58:24.260
Does Fine really do what you want it to do?

58:24.660 --> 58:25.300
Not really.

58:26.640 --> 58:28.160
Say I have a log file.

58:28.280 --> 58:30.780
I'm trying to find who hacked my website.

58:31.200 --> 58:32.280
And I'm all pissed off.

58:32.280 --> 58:35.040
Ha-ha, your website got hacked.

58:36.180 --> 58:36.580
Yep.

58:36.800 --> 58:37.980
I'm on Zone H.

58:38.980 --> 58:39.860
I'm defaced.

58:40.200 --> 58:40.800
I'm pissed.

58:41.000 --> 58:41.860
I want to find out who.

58:42.280 --> 58:43.840
Well, these hackers aren't smart enough.

58:44.140 --> 58:45.820
They didn't erase the logs or whatever.

58:45.920 --> 58:46.940
They didn't have access to them.

58:48.660 --> 58:55.240
And I have a 200 megabyte text file of logs I have to go through.

58:55.240 --> 59:01.340
Now, Grip on a Windows Linux machine would do this without sweating.

59:02.200 --> 59:08.220
But, find or opening a notepad and doing Control-F, not going to happen.

59:09.340 --> 59:11.240
Bear Grip solves this.

59:11.460 --> 59:14.700
It even allows you to do multiple files very easily.

59:15.520 --> 59:17.480
Right now, I have it open.

59:18.500 --> 59:22.660
And I have the old folder or old drive selected.

59:22.660 --> 59:24.700
Files are star dot star.

59:24.940 --> 59:26.580
And I can just start typing.

59:27.080 --> 59:30.760
So, I start typing, like, smart or Mubix.

59:30.840 --> 59:41.280
If I start typing Mubix, it will start finding, before I even finish, any file or folder with Mubix in it.

59:41.800 --> 59:45.880
Now, say I want to audit my whole network.

59:46.360 --> 59:50.720
For anybody who stores their password on their My Documents or whatever,

59:50.720 --> 59:58.300
I can set up my folder to say, hey, this shared drive or this computer or these sets of computers

59:58.300 --> 01:00:02.760
and search for any text with password in it.

01:00:04.040 --> 01:00:04.600
Right.

01:00:04.880 --> 01:00:05.660
And I've done that.

01:00:05.660 --> 01:00:12.800
I mean, very, very fast, very useful.

01:00:13.200 --> 01:00:16.900
And the output is file-based.

01:00:17.120 --> 01:00:20.720
So, it says, in this file, on this line, and it shows you the line.

01:00:21.600 --> 01:00:28.580
You can use full regular expression support, invert match, and ignore case.

01:00:28.580 --> 01:00:32.580
I love it.

01:00:34.900 --> 01:00:35.540
All right.

01:00:35.760 --> 01:00:42.260
Well, we're, you know, we're talking about a lot of these are, like, useful from multiple viewpoints and things like that.

01:00:42.820 --> 01:00:50.520
What about some other things that are a little bit more specific in purpose, I guess, for lack of a better word, a little bit darker?

01:00:50.520 --> 01:00:51.520
All right.

01:00:52.180 --> 01:00:52.700
All right.

01:00:53.040 --> 01:00:58.540
So, most people have used or heard of Netcat.

01:00:58.860 --> 01:01:02.300
It's a Swiss Army knife of TCPIP, basically.

01:01:02.640 --> 01:01:02.960
All right.

01:01:03.040 --> 01:01:10.000
Well, what people don't know or don't realize very much is it's portable completely.

01:01:10.000 --> 01:01:24.640
I have it on my USB stick, and for those who don't know, Netcat can't listen or talk on any port or protocol with simple, and it works under Windows.

01:01:26.580 --> 01:01:33.940
And I hate Windows, but it's just industry standard, so it's easier to use anywhere.

01:01:33.940 --> 01:01:40.760
But I use Netcat for all kinds of file transfers.

01:01:41.140 --> 01:01:52.760
I can use it for file transfers or trying to fuzz a specific attack or protocol or traffic.

01:01:54.400 --> 01:02:01.300
It's just a great tool that you can use for anything, basically.

01:02:01.700 --> 01:02:03.740
Well, it is what it is.

01:02:03.740 --> 01:02:08.440
I mean, it's Netcat, but, yeah, just the idea of using it portably is kind of interesting.

01:02:11.360 --> 01:02:16.180
And, actually, you and I were talking about this next thing you had on here.

01:02:16.940 --> 01:02:17.400
I'm sorry.

01:02:17.480 --> 01:02:17.640
Go ahead.

01:02:17.680 --> 01:02:25.060
I was saying the next thing that you were going to talk about here, we were talking about offline before for protecting the information on there.

01:02:25.060 --> 01:02:26.140
So, I'm sorry.

01:02:26.200 --> 01:02:34.040
Go ahead with what you were going to say and apply it to what we were talking about, how you kind of protect your own USB stick with it.

01:02:34.040 --> 01:02:35.820
All right.

01:02:35.820 --> 01:02:45.940
So, I might – so, TrueCrypt is a way of making encrypted volumes either in a single file.

01:02:45.940 --> 01:02:57.640
I mean, I can encrypt a load of data or applications or whatever and put them encrypted and it will look like a single file.

01:02:57.640 --> 01:03:04.980
But, I mount it just like Linux and it will look like a drive to Windows.

01:03:05.340 --> 01:03:05.980
Right.

01:03:06.120 --> 01:03:06.540
Or Linux.

01:03:07.060 --> 01:03:09.160
TrueCrypt is both Linux and Windows.

01:03:09.160 --> 01:03:14.540
So, how I use this is more to the point.

01:03:16.040 --> 01:03:20.820
When, like I said before, Portable Apps has something called Portable Thunderbird.

01:03:21.180 --> 01:03:23.400
Well, with Thunderbird, you have Enigma.

01:03:24.080 --> 01:03:30.000
Enigma is a plug-in that adds on PTP or GPG to be precise.

01:03:31.320 --> 01:03:35.760
So, being with that, there's keys.

01:03:36.320 --> 01:03:37.980
You have your public and private key.

01:03:37.980 --> 01:03:45.080
Well, I don't want to be without my public and private key so I can send and receive email.

01:03:46.080 --> 01:03:52.440
Well, am I going to keep two USB keys and drag them around everywhere just so I can be portable with my email?

01:03:53.460 --> 01:03:57.860
Not very efficient way of doing things.

01:03:58.720 --> 01:04:06.200
Well, how I tie TrueCrypt into this is I make a file, which is a TrueCrypt volume on my USB key,

01:04:06.200 --> 01:04:12.160
and I put my keys inside that TrueCrypt volume.

01:04:12.160 --> 01:04:22.400
So, when I take my USB key around, I don't have to worry about losing it and then my keys are invalid

01:04:22.400 --> 01:04:26.560
because I know that, one, I have it backed up on my iPod.

01:04:26.560 --> 01:04:37.080
One, two, anything that I have that's important that can get those keys or my private keys available to them

01:04:37.080 --> 01:04:43.000
is encrypted beyond the point that a normal person without a supercomputer can get at.

01:04:43.000 --> 01:04:44.800
Right.

01:04:47.100 --> 01:04:51.900
So, point being, if you lose it, you're not necessarily in any trouble, really.

01:04:53.000 --> 01:04:53.280
Right.

01:04:53.340 --> 01:04:54.640
I don't have to worry about it at all.

01:04:54.900 --> 01:05:02.400
I don't like losing USB keys, but I'm not scared that any information on there is going to be disseminated.

01:05:02.400 --> 01:05:06.360
Right, but, you know, if it fell out of your trunks while you were swimming or something like that.

01:05:07.460 --> 01:05:08.340
Hey, hey, hey.

01:05:09.800 --> 01:05:15.220
Somebody grabs your USB key, somehow dries it off, they can't completely own you.

01:05:16.560 --> 01:05:17.000
Correct.

01:05:17.600 --> 01:05:26.220
And I store all kinds of information, like any keys that I get for Windows or valid keys for Windows

01:05:26.220 --> 01:05:35.980
or games or stuff like that, I store in there just so I can keep my keys private to me and always have them.

01:05:36.720 --> 01:05:37.080
Right.

01:05:38.000 --> 01:05:39.820
No, that's actually a really good tip.

01:05:40.220 --> 01:05:42.040
That's why I said you and I talked about that earlier,

01:05:42.160 --> 01:05:44.920
and that's actually something I can see myself doing as well.

01:05:49.180 --> 01:05:51.560
Well, it's a lifesaver.

01:05:51.920 --> 01:05:53.920
I'll tell you what, you learn after you get burned.

01:05:56.220 --> 01:05:57.800
All right, and what else you got?

01:05:59.040 --> 01:06:07.180
All right, this is an actually agitating subject for me, this next set of applications.

01:06:07.340 --> 01:06:17.900
I find it very angering, if that's a word, when I see on dig.com or news or any other forum,

01:06:19.020 --> 01:06:24.100
how do I get around my firewall at work or school or whatever?

01:06:24.100 --> 01:06:30.480
I mean, there are so many times where I've gone, just fucking Google it or ours.

01:06:31.480 --> 01:06:40.340
Just, you know, and I get mad because they don't, people just don't see that it's everywhere.

01:06:40.920 --> 01:06:41.480
Right.

01:06:41.480 --> 01:06:52.700
So, this application is, this set of applications is how I would suggest users get around their firewall,

01:06:53.020 --> 01:06:54.620
which I don't suggest they do at work.

01:06:55.580 --> 01:06:57.240
Well, we're not going to tell them where, yeah.

01:06:57.440 --> 01:07:00.060
We're not authorizing or telling anybody.

01:07:00.240 --> 01:07:02.040
We're just throwing out the possibilities here.

01:07:02.040 --> 01:07:04.680
So, with that, I'll go into it.

01:07:05.000 --> 01:07:12.740
Portable Firefox, again, from portableapps.com, is the portable version of Firefox, obviously.

01:07:13.200 --> 01:07:19.460
Well, you have that option of adding all those add-ons and plug-ins and extensions, if you will,

01:07:19.460 --> 01:07:22.780
like, normally install a Firefox.

01:07:23.240 --> 01:07:25.140
Well, Foxy Proxy is one of those.

01:07:25.760 --> 01:07:26.080
Mm-hmm.

01:07:26.760 --> 01:07:33.420
Now, before Foxy Proxy, I had to use, or I, how do I say this?

01:07:33.500 --> 01:07:34.620
Well, implicating myself.

01:07:35.100 --> 01:07:46.340
I've suggested using other tools, such as Provoxy and another proxy tool, or Switch Proxy for Firefox.

01:07:46.340 --> 01:07:47.940
Right, I've used Switch Proxy.

01:07:48.800 --> 01:07:59.980
Now, the problem with a Sox Proxy, which is what SSH or PuTTY, using SSH, sets up when you port forward.

01:08:01.820 --> 01:08:03.300
So, let's start from the beginning.

01:08:03.600 --> 01:08:03.880
Okay.

01:08:04.500 --> 01:08:10.120
I have an SSH server at home, a Linux install, or a SigWin on Windows space,

01:08:10.120 --> 01:08:18.440
and I port forward on my firewall so that it's, port 22 is available on my local or home network.

01:08:18.920 --> 01:08:19.240
Right.

01:08:19.240 --> 01:08:28.680
I use PuTTY from whatever, my laptop at, say, Panera Bread, and I SSH to my home computer.

01:08:29.160 --> 01:08:29.520
Right.

01:08:30.040 --> 01:08:33.960
Now, I log in, and I change the settings on it.

01:08:35.500 --> 01:08:37.480
Let me get this right.

01:08:37.940 --> 01:08:40.320
Under Connection, under SSH, under Tunnels.

01:08:40.320 --> 01:08:49.100
I turn on local and remote port, and I add the source port as 8000 or whatever you want.

01:08:49.700 --> 01:08:54.380
And what this is basically saying is I'm going to listen on this port on your local machine,

01:08:54.640 --> 01:09:04.740
and I'm going to set the destination to blank because it's going to assume that the destination machine is the machine you're SSH into,

01:09:05.040 --> 01:09:06.760
and I'm going to change it to dynamic.

01:09:06.760 --> 01:09:13.500
Now, what this is doing is saying that anything that I see coming in on port 8000,

01:09:13.620 --> 01:09:16.100
I'm going to tunnel through my SSH.

01:09:17.040 --> 01:09:17.560
Right.

01:09:17.660 --> 01:09:18.880
My SSH connection.

01:09:20.640 --> 01:09:28.020
So now that I've tunneled port 8000 or opened up port 8000 on my computer

01:09:28.020 --> 01:09:37.640
and anything that goes to it is going through to my SSH server, I use Foxy Proxy.

01:09:38.000 --> 01:09:49.600
Foxy Proxy, I set that up to basically set up a, I don't know how many of your users or listeners might know what a SOX server is,

01:09:49.600 --> 01:09:52.880
but it's basically a proxy server.

01:09:53.220 --> 01:10:00.740
Now, the problem with SOX is that any DNS requests will still go out through the normal means.

01:10:00.820 --> 01:10:01.780
It won't get proxied.

01:10:02.000 --> 01:10:02.420
Right.

01:10:02.420 --> 01:10:11.420
So that's kind of loud still because you're still saying, I want to go here, but once I get DIP, I'm going to go.

01:10:11.840 --> 01:10:19.940
And it's easy to see on a log file where there's 30 DNS requests but no connections out once those DNS requests are made.

01:10:20.180 --> 01:10:20.980
Right, right.

01:10:21.000 --> 01:10:22.440
And they will see the destinations.

01:10:22.440 --> 01:10:27.700
They may not be able to see your packets and what's contained within them, but they'll see where you're going.

01:10:28.620 --> 01:10:28.880
All right.

01:10:28.980 --> 01:10:39.160
So your computer is going to say, whatever the Panera Reds DNS server, I want to go to binrev.com.

01:10:39.280 --> 01:10:39.600
Right.

01:10:41.180 --> 01:10:41.700
Okay.

01:10:42.020 --> 01:10:47.920
The DNS server will say, binrev.com is this IP address.

01:10:47.920 --> 01:11:02.560
After that, your computer will tunnel any further through that IP or through your SSH tunnel out through your SSH server's ISP connection to binrev.com IP.

01:11:02.920 --> 01:11:03.300
Right.

01:11:03.420 --> 01:11:08.260
So all that's going to get logged on that DNS server is a request for an IP.

01:11:08.640 --> 01:11:08.920
Right.

01:11:09.160 --> 01:11:14.080
That DNS server is going to reflect that somebody looked up binrev.com.

01:11:15.000 --> 01:11:15.460
Correct.

01:11:15.620 --> 01:11:15.800
Right.

01:11:15.800 --> 01:11:16.560
That's what I was saying.

01:11:16.560 --> 01:11:17.920
That's going to still show up.

01:11:18.720 --> 01:11:20.680
But everything else subsequently is not.

01:11:21.340 --> 01:11:21.600
Right.

01:11:21.780 --> 01:11:22.000
Okay.

01:11:22.160 --> 01:11:22.400
Okay.

01:11:22.480 --> 01:11:23.160
So we're on the same page.

01:11:23.280 --> 01:11:23.460
That's a problem.

01:11:24.240 --> 01:11:26.500
You don't want people knowing where you were going.

01:11:26.700 --> 01:11:32.780
I mean, that defeats the point of tunneling unless you're just doing it so that you can log in securely.

01:11:33.280 --> 01:11:33.560
Right.

01:11:33.620 --> 01:11:35.460
And it depends on what your motives are, of course.

01:11:35.680 --> 01:11:37.580
You may or may not care about that.

01:11:37.660 --> 01:11:38.960
But yeah, go ahead with what you're saying.

01:11:39.020 --> 01:11:39.760
You're absolutely right.

01:11:41.260 --> 01:11:43.180
Well, with FoxyPoxy, there's a setting.

01:11:43.180 --> 01:11:46.360
And it's kind of obfuscated.

01:11:46.840 --> 01:11:49.120
It's down in the settings.

01:11:49.240 --> 01:11:49.880
You have to find it.

01:11:50.840 --> 01:11:56.920
And it says tunnel DNS traffic as well or something of that nature.

01:11:57.300 --> 01:11:57.680
I'm sorry.

01:11:57.740 --> 01:11:58.940
I don't have it right in front of me.

01:11:58.940 --> 01:12:03.100
But you click that on, hit okay, and you're set.

01:12:03.600 --> 01:12:11.300
All the DNS traffic will, from then on, be going through your proxy, your SSH tunnel.

01:12:12.120 --> 01:12:12.340
Right.

01:12:12.340 --> 01:12:23.580
And that is the best way to securely, from, say, Panera Bread, tunnel all your traffic home and out through your firewall, which you know is secure.

01:12:23.800 --> 01:12:28.740
And none of your traffic is going to be able to get sniffed.

01:12:28.740 --> 01:12:35.740
Exactly, because it can't see what the traffic is, so it can't filter anything out or stop anything.

01:12:36.540 --> 01:12:39.420
Now, actually, I think we're probably running short on time here.

01:12:39.540 --> 01:12:43.900
We kind of had a little hiccup in the recording, so my timing is a little off here.

01:12:44.760 --> 01:12:50.100
But before we wrap up, are there any other things we wanted to mention here?

01:12:50.100 --> 01:12:56.480
I know we talked about updating software when versions come out, whether you should or shouldn't, and sometimes you don't want to.

01:12:56.980 --> 01:12:59.680
We talked about maintaining and backup and things like that.

01:13:01.660 --> 01:13:05.000
We talked about carrying around your PGP and GPG keys.

01:13:05.000 --> 01:13:08.600
It's very handy, but a good way to protect them using TrueCrypt.

01:13:10.360 --> 01:13:15.080
Are there any others quickly, like in a minute or two, that you wanted to mention before we get out of here?

01:13:15.120 --> 01:13:18.000
I hate to rush you, but...

01:13:18.000 --> 01:13:22.220
The only two we had left was PT Lookup and PT Hasher.

01:13:22.580 --> 01:13:29.520
Both you can check out at karenware, that's K-A-R-E-N-W-A-R-E dot com.

01:13:30.000 --> 01:13:34.680
And they're both good tools, and we don't have time to go through them, but check them out.

01:13:34.900 --> 01:13:36.960
That's PT Lookup and PT Hasher.

01:13:37.640 --> 01:13:42.240
Okay, and then the only other one I wanted to mention was what I've done in the past,

01:13:42.300 --> 01:13:47.740
is I've used the distributed .NET clients and Folding at Home or any sort of distributed computing,

01:13:48.000 --> 01:13:50.440
programs, if you will.

01:13:51.040 --> 01:13:56.840
They are usually very portable, and pre-configuring those with putting all the configuration files

01:13:56.840 --> 01:14:01.260
to put your name and join group, DDP group or whatever, for folding at home.

01:14:01.260 --> 01:14:06.620
And I have had that on a USB key, and when I'm out somewhere, if I'm in a computer lab,

01:14:06.700 --> 01:14:11.780
I'm on a school campus somewhere, I'm in a public lab, coffee house, whatever,

01:14:12.020 --> 01:14:16.020
where they have computers available, you can throw that bad boy on there and put that machine to work,

01:14:16.480 --> 01:14:18.080
pounding out some packets.

01:14:18.080 --> 01:14:22.500
So that's always been pretty handy as well.

01:14:23.460 --> 01:14:29.280
And I think also worth mentioning as we kind of close up the show is there are already a couple of projects

01:14:29.280 --> 01:14:31.480
worth mentioning over on the Hack5 forums.

01:14:31.580 --> 01:14:32.020
Is that right?

01:14:33.520 --> 01:14:33.980
Oh, yes.

01:14:34.520 --> 01:14:35.360
Pimp those quickly.

01:14:35.360 --> 01:14:38.380
The Hacksaw and the Switchblade.

01:14:38.980 --> 01:14:45.260
These are two projects that are on the Hack5 forums and put in Hack5 episodes

01:14:45.260 --> 01:14:52.860
that allow a USB key to be auto-run and do some interesting things.

01:14:52.860 --> 01:14:55.600
Very cool.

01:14:55.700 --> 01:14:56.840
So go check that out.

01:14:57.900 --> 01:15:04.020
And speaking of closing out the show, I think we should probably do some shouts here.

01:15:04.140 --> 01:15:08.480
So I'll go ahead and go first and stall for you to think of any shouts you want to give out.

01:15:08.480 --> 01:15:13.540
I want to give shouts out to E-Man for helping me out with doing some encoding for me.

01:15:14.060 --> 01:15:19.440
To Enigma, of course, good friend over there in the Tampa 813, BR813 meeting.

01:15:19.440 --> 01:15:23.600
And I guess anybody whose handle begins with E is the theme tonight.

01:15:23.700 --> 01:15:25.580
If your handle begins with an E, you get a shout-out tonight.

01:15:26.480 --> 01:15:32.120
And I've got to give congratulations to Mr. and Mrs. Droops for their birth of their healthy baby girl.

01:15:32.300 --> 01:15:34.100
So congratulations to them for that.

01:15:34.760 --> 01:15:36.020
And what do you got for shouts?

01:15:37.360 --> 01:15:40.120
I got just one shout-out to Cyber Eagle.

01:15:40.980 --> 01:15:44.600
Again, his nick kind of starts with Eagle or an E.

01:15:44.880 --> 01:15:45.540
There you go.

01:15:46.080 --> 01:15:47.560
That's the only one I could think of.

01:15:47.560 --> 01:15:50.440
So Cyber Eagle, if you're out there, shout-out to you.

01:15:51.000 --> 01:15:51.400
Okay.

01:15:51.600 --> 01:15:54.000
And our site of the week comes from our co-host.

01:15:54.120 --> 01:15:55.640
It's centralops.net.

01:15:55.740 --> 01:16:01.280
That's C-N-T-R-A-L-O-P-S, centralops, all one word, dot net.

01:16:01.280 --> 01:16:05.060
There's some handy little apps over there that you can play around with.

01:16:05.960 --> 01:16:13.520
Email us if you have any kind of feedback, if you want to talk about that whole disclosure topic we had at the beginning of the show.

01:16:13.520 --> 01:16:17.120
If you have any other tools or any other software packages you want to mention.

01:16:18.080 --> 01:16:26.800
Now, I'll go ahead and preface this saying that we had to draw a line and cut off of how many things we could talk about on this episode of the show.

01:16:26.960 --> 01:16:36.000
We might have some subsequent shows with a little bit more specific areas and types of tools that we may go into some more detail about.

01:16:36.000 --> 01:16:47.880
But we picked some of our favorites on this one, but if anybody has any they'd like to recommend, by all means, contact us, radio at binrev.com, or come to forums.binrev.com.

01:16:47.960 --> 01:16:58.300
Start a thread, any information that you have on anything to do with the show, like how much you hate me and how much you love Mubix and you want me off the show and you want him to run the show from now on.

01:16:58.640 --> 01:17:00.000
Email us, radio at binrev.com.

01:17:00.640 --> 01:17:01.160
There you go.

01:17:01.160 --> 01:17:03.360
See, I'm going to put you to work, man.

01:17:03.860 --> 01:17:06.560
You didn't think you were going to get away doing one episode and that was it.

01:17:06.620 --> 01:17:07.860
You're on for life now.

01:17:08.320 --> 01:17:09.540
You're in the family now.

01:17:10.960 --> 01:17:12.060
Closing music this week.

01:17:12.580 --> 01:17:16.280
The closing music this week is We Have the Technology by ADD.

01:17:17.540 --> 01:17:19.580
And I think that is going to do it.

01:17:20.440 --> 01:17:22.580
Mubix, thank you for being on the show with me.

01:17:22.920 --> 01:17:25.560
And joking aside, we will have to do some episodes in the future.

01:17:25.560 --> 01:17:30.320
I know we've got some other tools to talk about, some other topics in general to talk about.

01:17:30.320 --> 01:17:34.680
But we will have to save them for a future episode.

01:17:35.100 --> 01:17:37.460
But until then, we will see everybody next week.

01:17:37.980 --> 01:17:39.080
Same Hack Time.

01:17:40.020 --> 01:17:41.320
Same Hack Channel.

01:17:41.320 --> 01:17:50.740
So start a fire

01:17:50.740 --> 01:17:55.080
If it gets too tall

01:17:55.080 --> 01:17:59.480
When you can't take it anymore

01:17:59.480 --> 01:18:02.820
You have to take it all

01:18:02.820 --> 01:18:06.640
If luck has been filled

01:18:06.640 --> 01:18:11.240
You'll come out and leave

01:18:11.240 --> 01:18:14.360
But if you're sinful

01:18:14.360 --> 01:18:18.820
You ought to cut your losses and leave

01:18:18.820 --> 01:18:24.400
We have ideas

01:18:24.400 --> 01:18:29.320
We have energy to run

01:18:29.320 --> 01:18:33.160
We have energy to run

01:18:33.160 --> 01:18:36.640
We are duty-bound

01:18:36.640 --> 01:18:40.420
We have follow-through

01:18:40.420 --> 01:18:42.420
We have energy to run

01:18:42.420 --> 01:18:44.420
We have energy to run

01:18:44.420 --> 01:18:47.420
We have the technology

01:18:47.420 --> 01:18:53.420
But you waited all night

01:18:53.420 --> 01:18:55.420
And he never came home

01:18:55.420 --> 01:18:57.420
And he never came home

01:18:57.420 --> 01:19:02.280
Was it the blue and yellow lights

01:19:02.280 --> 01:19:04.780
That confused him

01:19:04.780 --> 01:19:06.780
And he never came home

01:19:06.780 --> 01:19:09.780
And I'll keep it in mind

01:19:09.780 --> 01:19:13.440
If we get the chance

01:19:13.440 --> 01:19:17.920
To change things for the better

01:19:17.920 --> 01:19:21.920
I want to change things for the better

01:19:21.920 --> 01:19:26.920
We have ideas

01:19:26.920 --> 01:19:31.920
We have energy to run

01:19:31.920 --> 01:19:35.920
We have energy to run

01:19:35.920 --> 01:19:38.920
We are duty-bound

01:19:38.920 --> 01:19:42.920
I will say we have follow-through

01:19:42.920 --> 01:19:46.920
We have energy to run

01:19:46.920 --> 01:19:48.920
We have ourselves

01:19:48.920 --> 01:19:50.920
We have energy to run

01:19:50.920 --> 01:19:51.920
We are duty-bound

01:19:51.920 --> 01:19:53.920
We have junior-bound

01:19:53.920 --> 01:19:55.920
We have follow-through

01:19:55.920 --> 01:19:57.920
We have energy to run

01:19:57.920 --> 01:19:59.920
We have energy to run

01:19:59.920 --> 01:20:01.920
We have energy to run

01:20:01.920 --> 01:20:03.920
We have energy to run

01:20:03.920 --> 01:20:13.920
We switch from ourerves

01:20:13.920 --> 01:20:24.980
It's only what happened to us, and it's only what happened to us, and it's only what happened to us, and it's only what happened to you, two, three, four.

01:20:43.920 --> 01:21:13.900
Thank you.

01:21:13.920 --> 01:21:43.900
Thank you.

01:21:43.920 --> 01:22:13.900
Thank you.

01:22:13.920 --> 01:22:15.920
Thank you.

