Showing posts with label HiR Info. Show all posts
Showing posts with label HiR Info. Show all posts

2010-03-01

0x0d - Happy Birthday, HiR!

HiR ca. Late 1997

March 1st, 1997. That's the day I uploaded the first volume of HiR e-Zine (then called "Hackers Information Report") to a few local BBSes. This included pushing it out to a small inter-BBS forum with world-wide reach, and finding its way onto some "hacking" web sites within a matter of weeks.

The first issue was penned by me alone, and almost entirely on a road-trip with my parents, on my old NEC Versa 550D while sitting in the back seat of a powder-blue 1989 Ford Aerostar for hours on end. I was just a kid. Going back and reading some of my older stuff is sometimes embarrassing.

A few months later, I had friends from local BBSes submitting content - Frogman being one of them. Soon thereafter, I'd run into a reader of HiR in a college class -- Asmodian X, who also had plenty of fascinating things to add. Contributors came and went, and I'd answer some e-mail questions. I still keep in touch with some of the past contributors and commenters.

From 2001-2007, HiR faded in and out and was mostly dormant. I got busy. We all got busy. The core contributors all grew up, in one way or another. We'd come up with one or two interesting articles, and think maybe we should put together a new "issue" of HiR.

Even though we all live fairly close, that never happened.

In early 2007, we decided to go with a "blog" format. I think it works better. We write when we get a chance, and the comments section gets us closer to our readers. We changed the name, mostly to shed the "hacker" from our name -- I think most of us have long given up hope of completely reclaiming "hacker" as a good word in all use cases. Now it's just a recursive acronym: HiR Information Report. Why the lower-case i? Partially to encourage HiR to be spelled (like H. i. R.) and partially as a throwback to the uBiQuiToUS LoWeRVoWeLiNG of the 1990s. Can we leave that part behind us?

Some months, we really hammer out the content and muster up a post nearly every single day. Other months, we're all but silent. We're still busy, but we are still passionate. Also, in the last year, we've had a pair of really great guest posts. We hope to have more of these, and maybe even land a few more regular contributors.

At any rate, this is me saying "thanks" to those who've contributed to our journey, on behalf of the entire HiR crew. The co-writers. The guest posters. The commenters. The friends who have been around with us for what seems like an eternity in Internet years -- tossing us link-love even back in the 90s. (Lookin' at you, HNNCast), the folks who still archive our mess of old text files (yes you can find us there, no I'm not linking to it), the folks who have kicked it with us at meetups, cons and user groups. And, of course, the readers, without whom we'd probably have given up on this little project long ago.

2009-12-12

HiR's Best of 2009

Well, it's almost the end of 2009, so it's time once again for the best of HiR!

Top content
#1: Still reigning the top of the chart for the second year in a row: the DIY Lock Picks Series.

Using commonly available tools and materials such as a few pairs of pliers, a dremel or bench grinder, hack-saw blades, old windshield wipers, and even street-sweeper bristles, we went through and showed you how to make your own set of reliable lock picks and tension wrenches. Most of the hits seemed to come from Google Image Search, where people were looking for lock pick templates.


In the #2 spot this year: The Evil WiFi Series of articles.

The greedy access point stuff has been around for a while, and it's known as "karma" in the infosec industry. Digininja brought easy karma to the La Fonera with Jasager. Browser exploits are nothing new but Metasploit is boss. Hamster and Ferret were a bit of a game changer, introduced last year by Errata Security. They made it easy to import cookies from network traffic.

I'm pretty sure I'm the first one to have tied them all together into a portable system so evil and sinister that it even schooled some of the most paranoid and wary hackers at DefCon 17. I gathered more than 1,000 live session cookies from hundreds of different machines over the course of the weekend.

This was probably my favorite project of 2009. It's too bad that DefCon is the only real time I've used it on live targets. I just don't have it in me to take over a coffee shop or an office park with this rig. It'd be too easy, and morally wrong. Makes me wish I was a pentester again. I'd wreak havoc with it.

Many other outlets picked up the story. Among them: Dark Reading, Hak 5, Daily Radar and Remote-Exploit. From there, it started hitting the social bookmarking sites as well.



I don't know why, but they seem to spike on occasion from StumbleUpon. For instance, this last week, I got about 2,000 hits on the series in two days and then its hits went back down to normal again. Strange. And it's not the first "viral" spike like this in 2009. That's how the series made its way to #3.

Perhaps more people are using OpenBSD to host web-apps than I'd thought?


#4: Testing an ATX power supply - Again. It was on the 2008 list as well.

I wasn't even spot-on accurate in my article, but plenty of the information there is useful enough to get you started.

Some of our more knowledgeable readers picked up the slack and left some more really good advice in the comments of this post.

It seems to have gotten its share of traffic because ATX power supplies go out frequently, and the first place that do-it-yourselfers turn to is Google. This article is read many times per week.


#5: Open Letter from Geeks to IT Recruiters and Hiring Managers

There were tons of mixed reactions to this. Almost all non-managerial geeks cheered me on. Several hiring managers raised their glass and linked to the post. Others scoffed and told me to get a life, since there's no way I'll ever understand what it's like until I am in charge of hiring people. Some even went as far as to say I wouldn't make it as a hiring manager. What bleeds leads, and this controversial diatribe picked up some serious hits when I first put it out.


Down to #6 from our #2 spot in 2008: Tethering.

Even if it is against the terms-of-service agreement, tethering rocks and people everywhere know it! It's a fundamental way to bypass the web filter at the office, school or library, and it's a way to stay off of hostile networks at conventions like DefCon, although it by no means grants you a shield of immunity at such events. It's also great for instilling envy into my fellow transit riders when I-35 turns into a parking lot. I should probably dig out my notes from the September '09 2600 meeting, where I discussed tethering in a bit more detail.


Up two spots from last year to #7: Jornada WiFi Scanning

It's smaller than any NetBook, but more powerful than some of the ultra-tiny gadgets like the ZipIt. It's a great balance of form and function, and despite the fact that these relics have been out of production for nearly a decade, people are still searching for ways to make good use of them. This is another useful series that didn't really go viral, but people keep finding it via search.


#8: CHDK

CHDK is practically essential for anyone who owns a Canon camera. It unlocks potential that's great for HDR photography or just getting the most out of your relatively inexpensive camera.




Everyone loves a good holy war. Among geeks, few get as heated as the ones over which software is better. I tried to take a balanced approach to this one, as I'm generally an operating system agnostic. I come off as a BSD zealot sometimes, because I'd like more people give the underdog a chance once in a while.

Of the underdogs, I feel OpenBSD's probably one of the most useful, particularly for those interested in security.

DefCon is usually kind of a big deal among hackers. It's a good show every year, and this was my second year in a row. Some of the HiR crew made it to DC6, 7, 8 and 9, but we took a break. Here's hoping I can make it again next year. With Blizzcon happening the same weekend as DefCon 18 (my wife's kind of a WoW nerd) it should be interesting.


Top Referrers:
Of course, we have to thank others who found our content useful enough to link to us. The top 10 NON-Search referrers in 2009, listed in order of most referrals were:

#3: Hak5
#10: Some guy whose spanish readers really loved our whiteboard hack (wtf?)

Top HiR search terms of 2009:
This is what people searched for that landed them here one way or another. Most of these are no surprise. #9 boggles me but I know what article it refers to, I just don't know why it got searched for so often.

#1: epoch fail
#2: bsd vs. linux
#3: make your own lock picks
#4: lock pick templates
#5: jasager ferret
#6: hir
#7: information report
#8: jasager
#9: comment: a revocation certificate should follow
#10: luggage zipper pulls

It's also worth mentioning that our RSS feed is on fire lately, and those don't even count as website hits.

2009-08-30

** Czzhzzzht ** Is this thing on?

We are testing a new commenting engine powered by Disqus. All the old comments should remain on the site, but going forward, Disqus will handle the discussions.


This means that Blogger's relatively anemic commenting system gets gutted and replaced with a shiny new toy that allows threaded discussion and a bunch of other goodies. It seems to be working just fine, so take it for a spin and let us know what you think. You do not need to sign up for any services (even OpenID) to leave comments. Signing up for Disqus will allow you to edit your posts and interact with other commenters on many sites that use it though.

2009-06-26

Busy Busy!

Between SOX Audit stuff (which is a month-long process of data gathering), other demanding projects at work and the more important things in life, I really haven't had a lot of time to both tinker AND post stuff. Keep an eye on our RSS Feed, though, and I'll try to get to posting more Delicious Links. I run across dozens of cool infosec, UNIX and programming links every week. I've just been really lax on sharing them via Delicious.

In the meantime, bow before Mubix's inspiring display of creativity. This is seriously awesome. Room362: Metasploit Framework as a Payload for Metasploit Framework

2009-04-01

Now and Then: Anatomy of a buffer overflow

Today, Kevin Poulsen posted "How A Buffer Overflow Works" on Threat Level. It includes a simplistic flash animation that kind of helps one grasp what's going on with a buffer overflow... although I'd hesitate to call it "kid-friendly".

In the hacking culture, exploiting buffer overflow vulnerabilities was known as "Smashing The Stack", as stack-based overflow exploits were (and likely still are) the most common buffer overflow vulnerability and among the easiest to exploit.

Kevin's article and the accompanying animation reminded me of a piece of work that is both antique (as far as computer history is concerned) and relevant. Phrack 49 was published in 1996, and it included an article by Elias Levy (under the handle of Aleph One) entitled "Smashing The Stack For Fun And Profit"

It's practically required reading for people dealing with application security; It's just as useful for developers as it is for penetration testers and security researchers. Seriously, go give it a read. It's a long one. All the while, keep in mind that it was released nearly 13 years ago. That even puts my own work into perspective. Phrack 49 was released just as I was myself trying to rally the writers who put together the very first bits of content that got HiR off the ground in its original eZine format.

Damn, I feel old now.

2008-12-15

Most popular articles of 2008

2008 has been a good year for HiR Information Report. This marks eleven years of HiR, which started as a text-file e-zine in 1997. The core crew is still around and writing, although we spent quite a few years dormant.

2008's our first full year with the new blog format. It's time to highlight the most popular articles of 2008. This goes by hits acquired in 2008, so some of the posts may be older than 2008.

10) Shimming a cable lock
This article went somewhat viral in the lockpicking and bicycling community. It sees inconsistent waves of high traffic from forums and blog links, then goes weeks without a hit.

9) jLime Linux - Wifi Scanning
Jornada 6xx and 7xx-series handheld PCs seem to be getting cheaper and more popular. jlime is a viable alternative to the built-in WinCE OS.

8) Sysadmin Sunday: Pure-FTPd configuration
Pure-FTPd is a security-enhanced FTP server. It takes a little bit of elbow grease to get it working properly under Ubuntu, but Asmodian X outlined it clearly. Most people find the article while looking for configuration specifics such as quotas and virtual users.

7) Series: Web Filter Evasion
After the last post in the series was (finally!) completed, the series started getting links. The series was featured on The Edge of i-Hacked and recieved mention in the PaulDotCom Security Weekly Podcast #132

6) Sysadmin Sunday: OpenBSD/Apache/MySQL/PHP (OAMP)
The security and stability of OpenBSD meets the flexibility of an AMP server environment. It's a match made in heaven.

5) Sysadmin Sunday: Process Accounting
Are you seeing a trend? As a general rule, a lot of Sysadmin Sunday and UNIX-Specific content gets linked to. Process accounting is a relatively simple procedure, but it's a good one to know.

4) Testing an ATX Power Supply
This is one of those posts where I feel the HiR Community did a better job in the comments than I did in the article. There's a lot of useful info in there. They picked up where I left off and had some great suggestions for better testing methods.

3) Epoch posts - perl Epoch time and Epoch Fail
I have these two grouped together because they're tied on hits.
Epoch time is just a pain in the butt. It makes sense on a computer, but it doesn't help much in your log files. A quick perl one-liner was just what the world needed, and a lot of sysadmins search for it and find my epoch time post.

Epoch Fail took off for purely viral reasons, because very few people understood the xkcd cartoon. "What is an epoch fail?" and similar terms were the heavy-hitting keywords that linked to this post. Thanks for the traffic, Randall!

2) Unofficial Tethering Guide: LG Chocolate
Verizon is notoriously pesky when it comes to tinkering with phones they sell. Bluetooth OBEX, tethering, and things of that nature are made intentionally difficult. The relative affordability of the LG Chocolate vx8550 made it a popular one among geeks, and this article has remained very popular throughout 2008, with quite a few hits on a seemingly daily basis.

1) Series: Make your own lock picks
This was the most popular content on HiR this year. After my TSA/Lockpick post on i-Hacked got minor mainstream exposure, links to this series took off. Also, the final article on pick templates gets frequent hits from image search engines. I guess there are a lot of locksport enthusiasts out there, looking for templates!

2008-11-28

We've got cards, yo! (and 2600 This Friday)



It's hard to tell, but there's green source code in the background of the front of the card. These are MiniCards by Moo.com. They've got a nice finish. I'll be handing them out to the HiR crew soon. We were all sick of being at conventions and events without being able to hand anyone some contact info. The e-mail address on the back will spam the whole team (so please don't abuse it?) Note: AsmodianX@, Frogman@, tmib@ and ax0n@ will get to individual writers at h-i-r.net.

Also, the KC 2600 meeting is coming up in one week. Same time and place. Oak Park Mall food court at 5:00PM.

2008-09-23

Adding a favicon to your hosted blog (New HiR Logo)

I thought it was about time for a logo and a favicon.


I'm no graphics designer, so it's pretty simple. Just not as simple as a block of text. 

Just because you've got a blog hosted at Blogger or even Wordpress, it doesn't mean you can't have a custom favicon logo as pictured left.  Simply make a 16x16 pixel image then use GIMP or another image tool to save it in Windows ICON format (with a .ico extension) and then find a place to host the image. Flickr works, for example.  Then, in the blog HTML template, add the following block of code near the top of the template, after <head>  and before </head> , replacing the URL to the HiR favicon to the URL of your image hosted elsewhere. 

<link rel="shortcut icon" type="image/ico" href="http://stuff.h-i-r.net/favicon.ico">

2008-06-18

Kansas City: Fridays might be a little odd for a while...

I don't know about Asmo, but I can't make the Friday Geek-Out at the Daily Dose this week. I've got another event to go to.

Also, the July 4th 2600 Meeting and geek-out might be sparse as well, as most (if not all) of the KC HiR Crew will be out of town blowing stuff up.

The Geek-Out is still on for July 27th. Otherwise, I suppose we'll see you at the August 2600 meeting, if you attend.

2008-04-29

IT Security World 2008

It looks like I'm headed to IT Sec World this year. This is a convention with seminars for Health, financial and government IT workers.

The seminars appear to be a re-hash of things I'm always familiar with, but I figure I'll be using this as a network opportunity as well as a way to get my finger back on the pulse of financial services InfoSec.

Does anyone else plan on attending?

2008-04-25

Weekend Blurbs

Sorry I haven't finished up my series on Web Filter Evasion yet. I had most of the articles pre-written except this last one and life's been kind of busy this week. I don't even know if I'll get around to Sysadmin Sunday the way this weekend looks.

Speaking of which, we could use more writers for security, electronics, or other geeky topics. You don't need to be in the KC area, but it would help. Feel free to drop us a line in the comments.

Tonight's The Friday Geek-Out at Daily Dose in Overland Park, KS. I'll probably be there around 11:00PM.

Darren published meetup details so maybe we'll see you there. If you're around KC and want to convoy or car pool, let us know in the comments. We'll probably roll out from KC around 3:00 tomorrow (Saturday) afternoon.

Pics will follow, I'm sure.

2008-03-11

Shared Links

I'm not sure if I'm ready to go putting del.icio.us daily RSS feed splices in the HiR RSS Feed yet, but for the time being, we're taking interesting links that show up in our Google Reader feeds and sharing them via the navbar on the right under HiR Shared Links.  You can also add our shared items to your RSS reader.  We'll probably still write commentary on interesting newsworthy articles that we find, but this is a way for us to show you some of what's keeping us interested.


Thanks for reading!
--ax0n
HiR Editor

2007-08-06

Some new stuff

We're adding some new stuff!

First, we added a link to the HiR Blog RSS feed. This works well with Mozilla Thunderbird's news reader, Firefox live bookmarks, Google Reader or any other RSS Reader that supports ATOM XML feeds. This way, you can stay up-to-date on new articles that we post.

Next, we went ahead and created an HiR community portal via Google Groups. Feel free to browse or join in. Discuss security and technology topics, suggest new articles, or talk to us about becoming a guest writer or regular HiR contributor.

We are going to be making subtle changes to the site's look and feel. Also, we're probably going to start cranking out some more content soon. Keep your eyes peeled and your RSS readers open!