Friday, August 27, 2010

Stupidonkey.com: IQ test

I always wanted to know why people like to advertise online IQ tests through internet ads, so I tried one. It was from a site called stupidonkey.com.
a screenshot of the website just before I submitted my information
Wow! Notice, the terms and conditions:
Did you enter valid information?
Yes, the information that I have entered is valid and I am 18 yeas or older or I have permission of my parents or guardian and I have checked if my mobile phone supports WAP and I have enabled WAP and I accept the costs of 17.50 AUD per week and I accept the terms and conditions.

Gosh! "I accept the costs of 17.50 AUD per week". That must be an extremely accurate IQ test. Also, an interesting thing is it charges weekly. Do people like taking IQ tests every week? Does IQ change that much in a short interval of time?

I had too much time on my hands. 

Note: for people that got suck in, well, I guess its bad luck. I doubt you can get your money back, but the according to the provider's terms and conditions, you can cancel the service and stop paying weekly fees:

Provider allows the user the possibility to interrupt the flow of information received via the SMS service. We offer you information on the Sites that correspond with the Service and/or via the SMS service. Also, in the free welcome message from Provider you will find information on how to cancel the Service. Generally, information received via the SMS service can be interrupted by sending an SMS message with the word STOP. You can send this message to the abbreviated number (the short code) you used for entry. For example you can send the message STOP to the applicable short code and cancellation shall become effective immediately upon receipt of termination request. See for more details the Specific Terms, the landing page of the Site and/or click the flag for your country. Charges may still appear on your mobile phone bill the following month as carriers bill retrospectively. At its own discretion, Provider may, without prior notice to you, suspend or terminate use of the Service by you and destroy and remove Registered Information within the Service for any reason. You agree that Provider may erase or deactivate your account and all information connected with it as well as any lists or files contained by it without delay, and/or deny you further access to the Service.

Saturday, June 19, 2010

Quickcashkit.net automated agents

I accidently clicked an banner on a website and was sent to the site where I browsed around and eventually was brought to a site: Quickcashkit.net (Conclusion: I reckon its a scam. Its my opinion but I warn those interested to proceed with caution).

Anyway, when I was about to leave, a window popped up where I could chat with a (supposedly) live agent. I decided to play along and found out that it was an automated computer (too bad). Here is the log so you can see:

Summer Says:Hey Wait! Before you go, I should make you aware that there's now just 4 places left in your area (estimated to be gone in 2 minutes). If you CLICK HERE I have secured a position for you.
Summer Says:When you are ready just type 'Hi' to let me know you're there....
You:Hi
Summer Says:Hi thanks for visiting QuickCashKit.net today!
Summer Says:We now only have 3 positions left, one just went, so you must act fast, so would you like to get started earning money online?
Summer Says:Just CLICK HERE to go straight to the join page as I have secured your position for the next 5 minutes.
You:Do I have to enter my credit card
Summer Says:We only accept Visa, Mastercard, American Express, and Discovery card as payment.
You:Are you a real person
Summer Says:I am a live virtual agent
Summer Says:So do you want to take advantage of this great limited time offer?
You:credit card
Summer Says:We only accept Visa, Mastercard, American Express, and Discovery card as payment.
Summer Says:You will receive your own automated money making website which will earn you commission 24/7, so you dont need to know anything about the internet.
You:real person
Summer Says:I am a live virtual agent
Summer Says:So do you want to take advantage of this great limited time offer?
You:scam
Summer Says:This is definitely not a con or scam, this is a legitimate home business opportunity.
Summer Says:We will supply you with all the tools you need to make money online, all you need to do is follow the methods and apply the techniques.
You:real person
Summer Says:I am a live virtual agent
Summer Says:So do you want to take advantage of this great limited time offer?

My guess is that the automated computer agent responds to words like "real person" and "credit card" and gives an automated response.

http://www.amazon.com/gp/product/B00ZDWGF7W/ref=as_li_tl?ie=UTF8&camp=1789&creative=9325&creativeASIN=B00ZDWGF7W&linkCode=as2&tag=truesciencity-20&linkId=Y6VXTO4V4TONZYLN

Saturday, April 17, 2010

Types of attacks

From Microsoft Encyclopedia of Security (direct quote)

Types of attacks
Access attacks: The intruder tries to gain access to resources on your network by exploiting flaws in software such as buffer overflows and information leakage and by elevating the intruder’s privileges to execute arbitrary code.

Denial of service (DoS) attacks: The intruder tries to deny legitimate users access to resources on your network.

Reconnaissance attacks
: The intruder ties to map your network services in order to exploit vulnerabilities detected.

Effects on systems being attacked
Active attacks: These involve trying to modify data either during transmission or while stored on the target system. Examples include inserting backdoors and Trojans, deleting or modifying log files, disrupting services or communication, and so on.

Passive attacks: The goal here is not to modify the target system but rather to capture data being transmitted by eavesdropping or by using a packet sniffer in order to obtain sensitive or confidential information such as passwords or credit card numbers. Passive attacks are also used for capturing information that can help the attacker create a map of the target network’s hosts and services, which
usually forms the preamble of an active attack.

Saturday, April 10, 2010

Salient Ads

I seem to be getting many emails from a company called Salient Ads. They are a email advertising company. It follows the format, where the email contains a link advertising a service with image promoting the service.
So if you receive any of these emails below, it probably is because a company you have given your email to has sold you out and I do not recommend you get caught up in the hype of the email. I do not know the sender and you probably don't too.

Example of spam emails

Email: College Loans (FinancialAid@largeperiod.com)
Subject: Education is expensive. Get a student loan now.‏
Message: Student loans help finance further study.

Email: LearnAccounting (AccountingSchools@chrismaspeace.com)
Subject: A Chance To Switch Careers
Do your own taxes and charge others

Email: GI Bill Express (MilitaryBenefits@mysnowballfight.com)
Subject: Legislative Alert for the Military‏
Message: Legislative Alert for the Military

Email: Cash Department (Loans@first9949.com)
Subject: Quick Loans! Up to $500 in 1hr! Approval in minutes!‏
Message: Up to $500 in hour..approval in minutes!

It supposedly not spam messages, because it states at the bottom of each email: "You are receiving this advertisment because you have opted-in to receive third-party marketing messages If you do not want to receive this type of emails from us, please unsubscribe here.
Salient Ads Ltd: 8171 Yonge Street Suite 136, Thornhill ON, L3T 2C6, Canada"

Salient Ads is an online marketing company and you can opt out there email service by clicking the link at the bottom of the email or by visiting their website.

Thursday, April 8, 2010

Ethical Hacking cont. (2)- Finding public information

This is a continuation of the post: Introducing Ethical Hacking.

One of the important steps to ethical hacking is to assume you have no information about company (in other words, to forget everything you know about your corporation) and start from ground up. So let's start with only your corporation's name (you have to know which organisation to hack).

Gathering information from public sources
1- Google: "Google" your company and see what information you can gather.
2- Hoovers and Yahoo! Finance: Detailed information about companies available to the general public.
3- U.S Securities and Exchange Commission: SEC filings that the company has made.
4- United States Patent and Trademark Office: For patent and trademark information.
5- Whois- DNS Servers responsible for hosting.

What information to look for:
1- Employee's Names/Contact Information.
2- Key Dates
3- SEC filings
4- Patents
5- Presentations, Articles, Webcasts

I'll stop there. There's plenty of work there for you to do. In the meantime, I will be writing up the next section.

For more information (detailed information) check out Hacking: The Art of Exploitation:

Apple introduces iAds to the mobile platform

iAds enable software engineers and corporate advertisers a new road to advertising.
From CNET: But this sets up a battleground for how advertising evolves on mobile platforms. Apple is declaring that the best way for marketers to reach mobile users is through iPhone applications, rather than the Web at large. Google and AdMob, on the other hand, are much more focused on ads delivered in the browser on mobile Web pages. And Apple made some compelling arguments Thursday about why its plan could be more effective.

Jobs said that the average iPhone owner spends 30 minutes a day using applications. So there's an awful lot of potential ad impressions at play, but mobile ads inside iPhone apps are even more annoying than desktop ads because should you happen to click on one, you're taken away from the app and into the browser.

My experience with advertisement in the sides of screens are normally not clicked by end users. The users are focused on the middle of the screen where most of the "action", one could say, is happening. However, my opinion applies to computer screens about 17 inches or wider. This may be different with 3.5 inch display screen, as the focal point is closer to the ads.

Also, users probably will not like the idea as in reality, 3.5 inch (diagonal) display is not really that large. iPhone users would like to use their screen to maximum capacity, and not have some of their precious screen space be taken up by an advertisement.

For developers/business owners reading this and wondering whether it is a business opportunity:

iAds work on a simple revenue split. 60% of revenue is given to the developer (10% lower than iPhone apps). However, apple will host and deliver all the ads to the end users.

Mac4Lin: Make Windows Look Like Mac the easy way

Even since I have entered the linux world, I have seen many skins that attempt to replicate the look of Mac/Windows XP/Windows Vista/Windows 7 with the use of themes and skins with specific desktop managers (and programs).

But for those who are not technically capable, Mac4Lin is a linux distribution that can make your PC look like a Mac. Of course, there are programs that are exclusive to Mac and have not been ported to linux. I have never been a fan of making one OS look like another. However people do things just because they can. So, if this is your thing, try it. (My thoughts: looks like Mac in some ways, but does not "feel" like it though)

The Inquirer: Designed by Anirudh Acharya of San Diego, California, Mac4Lin looks like the real thing. Only instead of a fully blessed by Steve Jobs Leopard OS X under the bonnet, it runs something which is not proprietary and is free.

Mac4Lin supports GNOME 2.26 and is backwards compatible. It is unlikely to appeal to the Linux purist, who probably wouldn't stoop to stick anything like a Windows 7 look on Linux either.

Maybe it is just the fact that one has a OS that resembles a proprietary for free that makes people want to do things like this. I would like to hear your thoughts if you do like to skin your operating system.