dimanche 17 avril 2011

☠ Bahreiny Night البحرين



WARNING : PLEASE, DO NOT EXPLOIT !

You might have follow us yesterday night doing a bunch of tourism in the wonderful Syrian Internet. As we had pretty much fun playing with Bachar, we thought Hamad could get jealous.
This pad is dedicated to you Hamad.

You can kill your people and shit on freedom in Bahrein... but never forget hackers are watching at you... we're close... even closer.

We do not attack, we're just tourists. Then we take pictures to show them to our friends from the Internets.

Hope you'll enjoy our journey as we did

/-)

Leak it Baby :


First step : asking a good friend the best way to have a nice touristic journey :

http://tinyurl.com/4ymbzsu


Second step : Dropping some small stones to get sure we won't get lost

9 ix-3-2-1.core1.JSD-Jeddah.as6453.net (195.219.153.94) 118.911 ms if-6-0.core1.JSD-Jeddah.as6453.net (80.231.165.78) 101.096 ms 101.239 ms
10 85.158.130.225 (85.158.130.225) 117.310 ms ix-3-2-1.core1.JSD-Jeddah.as6453.net (195.219.153.94) 119.919 ms 120.602 ms
11 85.158.130.225 (85.158.130.225) 116.242 ms 115.735 ms 119.568 ms
12 85.158.131.10 (85.158.131.10) 100.865 ms * 105.516 ms
.....
.....
social.gov.bh has address 89.31.192.132 http://www.social.gov.bh/


Third step : you will have to visit the customs

inetnum:85.158.128.0 - 85.158.135.255
netname:BH-EXCHANGE-20050110
descr:Bahrain Internet Exchange
country:BH

Nothing to declare ? Ok let's jump to the next step, enjoying the journey and taking pictures.
Ok it's time for getting change with local currency, http://www.gosi.gov.bh/calc/military/


The most beautiful places in the country

<HTML dir=rtl><head><meta http-equiv="Content-Type" content="text/html; charset=windows-1256" /><title>:: وزارة الداخلية | شرطة خدمة المجتمع | التبليغ الإلكتروني ::</title><META http-equiv=Content-Type content="text/html; charset=windows-1256"><META content="MSHTML 6.00.2800.1106" name=GENERATOR><META content=FrontPage.Editor.Document name=ProgId><META http-equiv=Content-Language content=ar-bh><style type="text/css"><!-- body {
Staying in touch with Hamad :<

rDNS record for 89.31.192.137: www.moh.gov.bh
PORT STATE SERVICE
12/tcp open unknown
23/tcp open telnet
80/tcp open http
1025/tcp open NFS-or-IIS
1080/tcp open socks
8080/tcp open http-proxy

websrv.municipality.gov.bh
PORT STATE SERVICE
21/tcp open ftp
23/tcp open telnet
80/tcp open http
139/tcp filtered netbios-ssn
445/tcp filtered microsoft-ds
1025/tcp open NFS-or-IIS
1080/tcp open socks
8080/tcp open http-proxy


... We're not snipers, we did not shoot, we did not hack, we did not deface...what about your security forces ?

From Paris with Love

Fo0 & Bluetouff

dimanche 24 octobre 2010

Samsung GalaxyS : Android made comfortable


Even if i did not get the time play with my new phone, a Samsung Galaxy S, i must say i feel quite excited to plan some hacky stuff with it and Android OS that it runs. Android is a really cool platform that lets advanced users play with modified firmwares to extends its features. Officials and beta firmware for the Galaxy S can be found here, this page could save your life if something goes wrong with the following hacks. Consider having a look on the new Samsung Flash wiki page and on the i9000 official flashing guide. If your are not familiar with flashing devices or running tools that could brick your phone, please, do not even try.

Here is my first impression for this device :
  • Effortless root ;
  • Multitask ;
  • Android has many useful apps that just works for a professional use (excellent email app, SIP, tethering that actually works for no money ...) ;
  • Android makes your phone highly hackable, and some apps like Touiteur a very good surprise.
Issues :
  • No SSHd by default, I just recommend QuickSSHd, an inexpensive but useful app ;
  • A strange behavior with GPS, Samsung USA recently admitted an issue and was planning to fix it in september. Did not see such a (official) fix yet;
  • Memory acces may sometimes be slow which is a software issue but a lag fix can be applied once the phone rooted. The 1Ghz CPU should be fast enough.
  • Last point that is not related to the phone itself, but to operators that filter http requests from a tethered computer browser, but should I need more than a ssh term ? Well, a browser might be useful so you will easily find a way to cheat them by modify the user agent parameter of your browser, using this plugin for Chrome or this one for Firefox.
What could be improved
  • The default factory firmware with the GPS bug but I recently moved to Froyo, not an official firmware, but the GPS works perfectly on this one.
  • There are not as much great 3D games on Android. If you're a gamer, excepting being an absolute fan of Asphalt 5 you should consider using an iPhone. I hope some companies like Gameloft or Electronic Arts will launch more 3D games on Android.


dimanche 8 août 2010

Tunneblick quick and dirty configuration

I had few troubles with adding a new configuration in Tunneblick, a cool free VPN software for OSX. The documentation of my provider was not so clear and a small mistake took me some time get started.

I had already a previous configuration and when i read the documentation of my new VPN provider, i was told to drop the config files in the openvpn folder located in the Library folder, in my Home directory. Of course, i had no "openvpn" folder located here. After a few greps, i found the good place : on Snow Leopard, you have to put your configuration files in /Users/yourname/Library/Application\ Support/Tunnelblick/Configurations/

So here's the trick :

First clean the configurations folder from your previous VPN provider config files :

$ cd /Users/yourname/Library/Application\ Support/Tunnelblick/Configurations/
$ rm *


Move to the folder where your new VPN provider configuration files are :

$ cd /User/yourname/Desktop/MyConfFiles

Check that you have copied your .pem, .crt and .key with others config files, then copy your new configuration files to to the Tunnelblick configuration folder :

$ cp * /Users/yourname/Library/Application\ Support/Tunnelblick/Configurations/

If you have some .ovpn you get an error launching Tunnelblick, you might have to rename the .ovpn extension to .conf

mercredi 21 juillet 2010

Dell puts Firefox in jail

Applicative virtualization is now a security oriented feature implemented by Dell for Mozilla Firefox web browser. The french website PCInpact explains that only Internet Explorer 8 and Chrome have implemented a sandbox to prevent the risk of a browsing security exploitation that could compromise the whole system.
Firefox is now so popular that Dell decided to provide it's own secured environment with Kace (a Dell subsidiary). Kace not only prevents Firefox vulnerabilities, it also protects users from the use of critical plugins like Flash and Adobe Reader.
Anyway, this won't protect users against malicious plugins use.

Here's a small demo of Kace secure browsing.


mardi 20 juillet 2010

Swedish Pirate Party becomes an ISP


The Piratpartiet (Swedish Pirate Party) seems about to become an ISP. It's the first known initiative of that kind for a politic party to provide a connexion to the Internets, but it seems to be a very good way to deliver a service that ethically gives an answer to the fight for Net Neutrality. Pirateisp will provide soon connexions from 10mb to 1gb, you can check the pricelist here (prices are from 26 to 55€).

Two months ago, Arstechnica wrote that the Piratpartiet was considering being ISP for the Pirate Bay.

The domain name Pirateisp.net has been registered to Rene Malmgren.

vendredi 16 juillet 2010

Fiber for communities by Google


Google has just launched Fiber for Communities, a website. A few month after Google revealed its plans about optical fiber deployment. Today it concerns 1100 lucky beta testers (some US municipalities) but Google goal is to provide a gigabit connectivity to 50 000 persons, then 500 000. Google should deploy it's own ultra-high speed broadband networks as an experimentation that could "benefits all communities". But for now in Europe, we are just jealous about it.

We should probably expect some news broadband services by Google, more than having Google becoming an ISP in Europe, but who knows ? One day maybe..


jeudi 15 juillet 2010

OpenBSD : Running a homebrewed web server with Zope and Plone


Did you ever consider running your own hombrewed webserver ? Here is a small tutorial to run a Plone website on OpenBSD, it's quite simple and funny. Home hosting is a good practice :
  • it's no expensive
  • you have the perfect control on your datas
  • you become a node of the Internet
  • this lets you grant skills
Step one : let's create an OpenBSD install media

$ mkdir OPENBSDISO
$ cd OPENBSDISO/
$ wget -r -np ftp://ftp.arcane-networks.fr/pub/OpenBSD/4.6/amd64/
$ mv ftp.arcane-networks.fr/pub/OpenBSD/4.6 .
$ cp 4.6/amd64/cd46.iso OpenBSD-4.6.iso
$ growisofs -M OpenBSD-4.6.iso -R -iso-level 3 -graft-points 4.6=4.6
$ ls
4.6 ftp.arcane-networks.fr OpenBSD-4.6.iso

Ok now we got an iso ready to burn. Once done, we can start with the installation.

Step two : OpenBSD install

Boot on your fresh cdrom, just follow the instructions, the OpenBSD install is very simple, you just will have to answer few questions. Auto partitioning is perfect for running Zope/Plone (everything is stored in /home) so just use it. As we're installing a web server, the good practice is to avoid the installation of the X server.

Step three : post install tunings

Edit your /root/.profile and add this line (consider choosing a mirror in your country or nearby) :

export PKG_PATH=ftp://ftp.arcane-networks.fr/pub/OpenBSD/4.6/packages/`machine -a`/

Once saved, launch this command :

# export PKG_PATH=ftp://ftp.arcane-networks.fr/pub/OpenBSD/4.6/packages/`machine -a`/

It's should now be easier for you to install software with pkg_add

Step four : Plone installation

Let's install Python first :

# pkg_add -v python-2.4.6p0

# ln -sf /usr/local/bin/python2.4 /usr/local/bin/python

Then we create a Zope user with restricted permissions :

$ adduser zope

We can now install Plone :

$ wget http://launchpad.net/plone/3.3/3.3.1/+download/Plone-3.3.1-UnifiedInstaller.tgz

$ cd Plone-3.3.1-UnifiedInstaller

$ ./install.sh standalone --target=/home/zope/z8080 --user=admin --instance=mysite.com --password=mypassword --with-python=/usr/local/bin/python

$ cd ../z8080/mysite.com && bin/buildout


If everything is ok, you should obtain something looking like this :

$ cd ../z8080/monsite.com/ && bin/buildout

Updating zope2.

Updating fake eggs

Updating productdistros.

Updating instance.

Updating zopepy.

Updating zopeskel.

Updating chown.

chown: Running chmod 600 .installed.cfg

Updating backup.

Updating unifiedinstaller.

Updating precompile.

precompiling python scripts in /home/zope/z8080/monsite.com/products

precompiling python scripts in /home/zope/z8080/monsite.com/parts/productdistros


By default, Zope is running the port 8080. You can launch you Zope instance with the following command :

bin/instance start

or in debug mode :

bin/instance fg

You can now edit you buildout.cfg and add your extensions products in the egg ans zcml slugs section as described in the products readme, or add old style product in the /product directory.

After editing the buildout.cfg Just remember to run the command

bin/buildout -v