Posts

The good and the bad about Sierra's online Quests

Originally Ken & Roberta Williams began their Sierra Quests while trying to invent a new Genre - Interactive books. Roberta loved the idea of having kids play a fairy tale book thus King's Quest I was created. Her inspirations were text games which were games without any graphical trace, so on the screen you would see a description of where you are now and you could try doing things using your imagination and the text parser. Roberta thought to upgrade these games by adding graphics and having the player move the main character over the screen (yes, without a mouse) in order to move between screens or moving in the same screen getting to various objects, while still sending commands using her text parser (move rock, climb tree [Spoilers?] etc). Sierra quests were massive success and actually were a beginning of a genre, but as with many genre inventers (except Steve Jobs as he was perfect) she tried her hand in inventing these types of games, and many game des...

How to hack a wordpress site

Just as an example - how would one go to hack a wordpress site. You go to the site you want to hack, use a siffer to find the framework the site was built with, I use a chrome plugin for this task ( Wappalyzer ). Now that we know we stand before a wordpress site, we need to find the login page, for that we will begin with a google search to find the " default wordpress login url " (http://example.com/wp-admin or http://example.com/wp-login.php) If the site owner was clever (be clever!) and changed the default url for the login, we will use a tool like DirBuster (unix only?) to crawl the site in order to find all urls (from them you will recognize the login url) Now that we have the login page we will want to attempt to brute force our way in, but a bruteforce where we try to guess the username AND the password is hopeless as the number of tries is HUGE, so we will try to find the username. In wordpress there is a "feature" called author enumeration where ...

The many hurdles of cracking a WEP network

Goal: To obtain the password of a wifi network encrypted using WEP. I thought this to be an easy task as I read around the web, but it became a huge task consuming way too much of my time and money, for this task which was actually totally unneeded for me, just a curiosity, well, I may as well write about it. While crawling around I naturally searched for a windows based solution, early on I found out that there is a consensus about the best wifi cracking suite of programs called aircrack-ng . While going to their site I found that they say that cracking under windows is much less stable, robust and will never be as good as cracking from linux as windows adds layers of protection which prevent some of the cracking techniques. Ok, so I will do it using a linux distribution. I went back to my research and found out about the kali linux dist, it is a distribution based on Debian linux which already contains lots and lots of hacking/cracking utilities. Which wil...

Single Java App a Day

This idea popped into my head several days ago and doesn't leave me, so although I know I won't have time to implement it in the near future I am writing it down - feel free to steal this idea and implement it! Basic idea - for an extensive amount of time (a month? two months?) build every day a new java application, as follows: Think thoroughly about the design of the applications as they should have common componnets spanning over all of the applications, where each app will add it's added benefit (the main business login) on top of the common grounds For example, I want to have all of my applications as javafx gui applications, so I should build a common component with a main content area, a log area below that one, a menu with all common menu items already there (file->save, file->exit, help->help, help->about, help->exit) etc Each application will do an atomic action (KISS) All applications should be open sourced and on github All the commo...

Hacking Tips

You have an encrypted Password and you want to find what it is A good practice is to encrypt a password using a one way encryption, then when the user uses his password, you just encrypt it with the same algorithm and compare the stored encrypted value to the new value, if they are the same then he user entered the right password. Having the password as encrypted strings is a good measure of security, if you want to find the original password then it is not simple as the encryption works one way only. But still, in order to find the original password you can try the following: Throw the hashed string to google - you will be amazed Dumb brute-force , by hashing every keyboard sequence using a computer algorithm, the problem with this one is that it is very CPU intensive and it might take a verrrry long time Dictionary attack , doesn't use random keys, but uses real words in order to try and guess the password - this is a much faster method, but if the password wasn...

Run your Java app as an EXE

My current task is deploying my JavaFX app as an EXE application Why? Because, unfortunately, "jar" files aren't looked upon (by windows) as executables which one should only double click in order to run, as if jar files are less legitimate than exe applications. This is not fair! People don't like running java applications because they need then to install a Java Virtual Machine, but they forget that in order to run those precious C# applications they need to install the .NET virtual machine, because windows does that automatically with windows updates so it is treansparent, but fundamentally they are the same, both need a virtual machine installed (JRE for java and .NET for .net apps), and a file association in order to run. Well, as I won't change the world (although I would love to see microsoft having a JRE installed using microsoft [optional] updates), I searched for a solution which will enable me to "convert" my jar file to an E...

Technical list of things to do to create a new PODCAST

You want to start your own Podcast?  Here is my technical list of steps for you Recording hardware is highly advised: Blue Yeti microphone with a pop filter is a good choice Recording software: Audacity to record, edit and finally export as mp3 Save the mp3 file using 56kb bitrate for human voice best size/quality ratio Save the mp3 on a dedicated server for best long term results or just throw it unto your hosting service for quick and dirty results (if you ever become very popular, your hosting might tell you to pay for the bandwith) Create a wordpress site for your podcast , where each show will have a link to your mp3 file somewhere in it Use the  Seriously Simple Podcasting plugin for much nicer podcasting look in your site After recording and publishing a show or two, submit your podcast RSS feed to: The biggest podcast sites - Manually All the other smaller sites - automatically