Security Thread

I forgot to mention. Another great add-on/extension? to use when surfing sketchy things, is NoScript.
Blocks scripts from executing once you hit a website. It can be annoying if it's on and you're just trying to live your life,
but if you're going to a sketchy site, you should enable it.
 
What can a website track about their visitors and is it something you should stay caution about or not,what is your opinion?
 
What can a website track about their visitors and is it something you should stay caution about or not,what is your opinion?
Great question! Websites can track a lot of information now a days. I'm sure people on here know way more than I do. Here's a screenshot of an example of the most basic tracking a websites does.

1599951443345.png
This is an apache access.log file. Highlighted, you can see it tracks your IP, what request method you used, what page you requested, and your user-agent which has your OS, its version, your browser, and its version, along with some more additional data. It's also timestamped.

More modern tracking can track how long you look at certain parts of a webpage, how long you've been on the website, what site you came from, and sometimes what other sites you been traveling to. Anyone with more information on this, please share!

As to if it's something one should stay cautious to, idk. It's gonna happen. You can take steps to prevent much of it, but we're all consumers in the end. The amount of steps it takes to obfuscated yourself for the purpose of people not collecting it, is moot. imo.
 
Great question! Websites can track a lot of information now a days. I'm sure people on here know way more than I do. Here's a screenshot of an example of the most basic tracking a websites does.

View attachment 146023
This is an apache access.log file. Highlighted, you can see it tracks your IP, what request method you used, what page you requested, and your user-agent which has your OS, its version, your browser, and its version, along with some more additional data. It's also timestamped.

More modern tracking can track how long you look at certain parts of a webpage, how long you've been on the website, what site you came from, and sometimes what other sites you been traveling to. Anyone with more information on this, please share!

As to if it's something one should stay cautious to, idk. It's gonna happen. You can take steps to prevent much of it, but we're all consumers in the end. The amount of steps it takes to obfuscated yourself for the purpose of people not collecting it, is moot. imo.
As you are aware of the bots being made for account creations of social media,why do they produce lower quality accounts if they can spoof user agent,browsers and bypass everything to make it look like a normal user?

Also do you think the quality of IP plays a role here?
How do they exactly track because softwares produce lower quality accounts and manually made ones,they produce higher quality always.Why is this the case other than the reason that IP plays a big role here?
 
And if you're running Windows 7, update that shit right fucking now to 10. Windows 7 has been depreciated for years now, and you can download free exploits and start getting full access to windows 7 devices online within a few hours

I'm using a pirated copy of Win 7 right now and I'm not upgrading to anything despite of any of so-called experts' advice. I don't give a shit. If you're such a good hacker go on and hack into my system, and see how much I care... that you steal all of my porn LOL, GTFO with that big advice like update your windows, create quality content and all that bullshit
 
I'm using a pirated copy of Win 7 right now and I'm not upgrading to anything despite of any of so-called experts' advice. I don't give a shit. If you're such a good hacker go on and hack into my system, and see how much I care... that you steal all of my porn LOL, GTFO with that big advice like update your windows, create quality content and all that bullshit

He´s talking about people with really important information on their systems...
 
I'm using a pirated copy of Win 7 right now and I'm not upgrading to anything despite of any of so-called experts' advice. I don't give a shit. If you're such a good hacker go on and hack into my system, and see how much I care... that you steal all of my porn LOL, GTFO with that big advice like update your windows, create quality content and all that bullshit
Just because you don't like OP's opinion,you have no right to insult OP.

You better start respecting people for what they provide which you are unaware about:)
 
He´s talking about people with really important information on their systems...

me, too. I have 100 GB of porn, including my favorite - lezzies. It can't get more important than that
 
Just because you don't like OP's opinion,you have no right to insult OP.

You better start respecting people for what they provide which you are unaware about:)

that's not even me insulting. You don't want me to insult you, trust me. Also, I don't recall to have asked for your opinion. I was talking to OP, so let him/her respond to my "insult"
 
Why aren't hackers targeting internet marketers? It would certainly be the most profitable ones to target?
 
About ad-blocking, you really need to use Pi-Hole on your entire network, then you don't have to worry about running adblockers on individual devices! Plus, there is no 'ad blocker' for a Samsung TV or other smart devices. A pi-hole is the solution. There is remarably little discussion about pi-hole here, I tried starting a thread on it last month but nobody cared :)
You're saying I could block ads on the TV? :O
 
As you are aware of the bots being made for account creations of social media,why do they produce lower quality accounts if they can spoof user agent,browsers and bypass everything to make it look like a normal user?

Also do you think the quality of IP plays a role here?
How do they exactly track because softwares produce lower quality accounts and manually made ones,they produce higher quality always.Why is this the case other than the reason that IP plays a big role here?
Great question! This happens for a few reasons.
1. Most people do the minimum.
When writing code to bypass or obfuscate something, most people will be happy if it works, then stop. While they can fine tune their software, most don't so long as it works and they can sell it. This happens in most companies, regardless of the product. This is why security usually takes a backbone and is only handled AFTER something happens. Devs teams get pushed with deadlines, and when they provide the option to release tomorrow, or spend a few weeks testing for security, managers always say, let's get it out as quickly as possible. Leads to many holes in security, but in this discussion, it means people will just write tools to trick social media platform algorithms but won't make it as 'good' as it could be. But MORESO, is that social media platforms have the budgets and a massive amount of data to determine what's considered 'fake' and what isn't.

The biggest social media platforms can use industry-level Machine Learning, or some confuse it with "AI", and can find outliers a lot easier. Or they can just pay another company to handle it for them, and give them the analytics. Never impossible to trick a system, but it takes more work.

2. IPs do play a big role here. I can't say the weight of IPs in their algorithm, but it definitely plays a vital role. People selling RDP access, and possibly proxy sellers, can provide more insight on this than I, but depending on location, and the type of IP, depends on how the website or social media platform will treat you traffic. Some websites don't allow any VPN or proxy users and block them immediately. Some only allow 'residential' IPs, and some block by country.

I'm using a pirated copy of Win 7 right now and I'm not upgrading to anything despite of any of so-called experts' advice. I don't give a shit. If you're such a good hacker go on and hack into my system, and see how much I care... that you steal all of my porn LOL, GTFO with that big advice like update your windows, create quality content and all that bullshit
You think of me as an 'expert'? how sweet. :p
I really don't care what OS you run. It's your shit, not mine. :D

Why aren't hackers targeting internet marketers? It would certainly be the most profitable ones to target?
They do, but idk if they're the most profitable. The recent types of attack include ransomware. It's been easier for hackers to, let's say write some worm that can infect people like @monere who run outdated OS, encrypted all their data, and sell them a decryption key like $100. It's a numbers game, so if you target a few million systems, and even if only 1% pays $100, you'll make a good chunk of change. More sophisticated hackers will turn these into botnets and sell access to them....like IPs and Proxies. But it's a lot to manage such a business and is difficult to keep up. Takes a lot of work, knowledge, and skill.

Other things people can do is dump bitcoin. Or collect PII from these machines, then sell that. Credit card info as well. There's a million ways to make a million dollars. Some people have very valuable information on their computers. Some just have 100GB of porn.
 
1. What are the best methods to be as anonymous online as you can if one don't have money to buy a VPN? TOR?
2. What is the best OS for privacy, security, anonymity etc.? Is it Qubes?
3. What someone can do with your IP?
4. What resources/books/courses/websites etc. do you recommend if someone wants to learn and become a (white) hacker?
5. If I make a website like a search engine or social media, what attacks can I expect from hackers?

By any chance, do you have the book of Michael Bazzell about OSINT? :D I've been trying to find a pdf version for some time but no luck.

Thanks
 
1. What are the best methods to be as anonymous online as you can if one don't have money to buy a VPN? TOR?
2. What is the best OS for privacy, security, anonymity etc.? Is it Qubes?
3. What someone can do with your IP?
4. What resources/books/courses/websites etc. do you recommend if someone wants to learn and become a (white) hacker?
5. If I make a website like a search engine or social media, what attacks can I expect from hackers?

By any chance, do you have the book of Michael Bazzell about OSINT? :D I've been trying to find a pdf version for some time but no luck.

Thanks
1. Some VPN services aren't too expensive, like $6/month. But if you can't, yeah Tor is your best bet. You can configure which relays your connections does as well. This can help if you want the exit relay to be outside your country. Warning though, your ISP will know you're on Tor. They won't know what you're looking at, but they'll know. It usually matters more if you're high profile.
2. I would say Qubes is one of the best, yes.
3. They could scan it, see if you have any ports open, and exploit any vulnerable services you have. Having someone's home IP, there's not TOO many things. It's easier and quicker to get them to click a link and exploit their computer that. I couldn't do much with a home IP, but others can. Most hackers can't.
4. ALL of them. Any website online gets hit with a bunch of attacks constantly. Let's say I figured out how to use an exploit for IIS 10.0. I could scan the entire internet for websites running IIS 10.0, and then exploit them all. It's not that I target one system, but all systems. So long as you keep your software up-to-date, and protect against the OWASP 10, you'll be alright. Persistent hackers can get into any webapp. It just takes practice and once you do enough engagements, you know what to look for. There's always a door somewhere.
 
Happy to answer any security questions if anyone has any.
If I don't know the answer, I can point you to some resources that should be very useful.
What do you think about any . run ?
It seems to be a very good tool to detect malware right?
 
1. Some VPN services aren't too expensive, like $6/month. But if you can't, yeah Tor is your best bet. You can configure which relays your connections does as well. This can help if you want the exit relay to be outside your country. Warning though, your ISP will know you're on Tor. They won't know what you're looking at, but they'll know. It usually matters more if you're high profile.
2. I would say Qubes is one of the best, yes.
3. They could scan it, see if you have any ports open, and exploit any vulnerable services you have. Having someone's home IP, there's not TOO many things. It's easier and quicker to get them to click a link and exploit their computer that. I couldn't do much with a home IP, but others can. Most hackers can't.
4. ALL of them. Any website online gets hit with a bunch of attacks constantly. Let's say I figured out how to use an exploit for IIS 10.0. I could scan the entire internet for websites running IIS 10.0, and then exploit them all. It's not that I target one system, but all systems. So long as you keep your software up-to-date, and protect against the OWASP 10, you'll be alright. Persistent hackers can get into any webapp. It just takes practice and once you do enough engagements, you know what to look for. There's always a door somewhere.
Oh I missed one of your questions!
4. HackTheBox is a great website if you want to learn how to hack websites. They provide servers you can learn and test stuff at. Hop in the discord and make friends.
And Michael Bazzell is the man. He knows his shit, and his websites is a GREAT source. If you use some Google-fu, you should be able to find his book. ;)

What do you think about any . run ?
It seems to be a very good tool to detect malware right?
. run? I'm not familiar with it, so I couldn't speak on it. If you download something, you can check it with VirusTotal online. It's free and runs like 55 different AVs against the file.
 
Oh I missed one of your questions!
4. HackTheBox is a great website if you want to learn how to hack websites. They provide servers you can learn and test stuff at. Hop in the discord and make friends.
And Michael Bazzell is the man. He knows his shit, and his websites is a GREAT source. If you use some Google-fu, you should be able to find his book. ;)


. run? I'm not familiar with it, so I couldn't speak on it. If you download something, you can check it with VirusTotal online. It's free and runs like 55 different AVs against the file.
No the website is called any.run :-)
 
Back
Top