Wednesday, January 27, 2016

Ethics Assignment #1

Anonymous got it's roots from 4chan which is an image board website, but anonymous as we know it today is a collective of like minded people standing up for their beliefs. Anonymous is able to disrupt their targets by Ddos, Hacking, and protest. They have had many famous operations over the years but the operation that caught my eye the most in the documentary was Operation Payback. Julian Assange, a hacker, programmer and Journalist started Wikileaks. Wikileaks was created to expose secret and classified information. Paypal, Visa, MasterCard, and Amazon removed their services from Wikileaks so that it would not receive donations from supporters, Even the Swiss bank froze certain funds and this infuriated Anonymous to its core. Anonymous found out that Visa, MasterCard, and Paypal all still allowed their services to the KKK and other hate groups, and that just fueled the fire even more. Anonymous swiftly moved into action and started Ddos (Distributed Denial of Service) attacks on Visa, PayPal, MasterCard. and Swiss Bank Post finance. Soon there after Tunisia blocked Wikileaks and Anonymous ddosed Tunisian sites. As a result of the massive attacks 13 participants of Operation Payback were raided and arrested. In the words of many anons "information wants to be free". The government isn't very transparent with its citizens so it can make people uneasy and uncomfortable; Wikileaks is a repercussion of that isolation. when government atrocities or wrong doing's are brought to light people tend to either get angry or want change and anonymous beliefs lean towards change. At first I was definitely conflicted with the good and bad of this operation. I sat and thought about it for a while and I feel like the anons beliefs and intentions were in the right place. The government needs to more explicit, Wikileaks in my opinion is merely a necessity in modern day society. people have a right to know whats going on. and when anonymous saw that threatened they took action. I believe this operation was for the better good.








Tuesday, January 26, 2016

Social Engineering Task #1

My mission was to slip my assignment card into someone's book bag or pocket.

I slipped the assignment card into Dr. Blu Ninja's left jacket pocket. I didn't get a chance to see a book bag, so I did what was closest to me: the jacket.




It was fairly easy to execute. I performed it as soon as the social engineering assignment was given to me. I took advantage of the fact that Dr. Blu Ninja was looking at his/her own assignment. I even took the card in and out of his their pocket a total of 3 times.

It could be considered an invasion of someone's private space as I was inserting something into their personal property. In a worst case scenario one can frame someone by inserting stolen goods or illegal drugs.

By learning to take advantage of someone's lack of alertness or focus, one can retrieve documents or electronics containing information.

It was a pretty straight-forward task that involved dropping a card into someone's jacket pocket. I thought *afterwards* about how I had no apprehension in executing the task as I seem to compartmentalize the mission and the ethics of it. It makes we wonder if that compartmentalization applies to people doing illegal things.

Structure for Social Engineering Report

Here is a structure for your social engineering posts:

1.  What was your task?
2.  What did you do? 
3.  How effective was your strategy?
4.  What are the moral stakes?
5.  Now that you have done this, what could you do with the information or skills you obtained?
6.  Reflect on how you felt when you were doing this.

Please don't forget to use hacker identities only within blog posts(including your own identity from which you are posting).

Ethics Assignment (due Feb. 1)

You've watched the documentary "We Are Legion", about Anonymous.  Please select a case referenced in the documentary and analyze it.  You might choose, for instance, the DDoS against Lufthansa in 2001, the response to Hal Turner's radio show, Operation Chanology (Scientology), Operation Titstorm (Australia's government), Operation Payback (Wikileaks/Mastercard/Paypal), Anonymous' involvement in resistance in Tunisia, their response to the Sony PlayStation incident, or something else you saw in the documentary.  You'll probably need to do a little Google research to learn more about the case you have selected.

In your post, briefly summarize the situation, and then stake a claim: were the actions of Anonymous right or wrong?  Explain your reasoning: why or why not?

Make your post no later than 9pm on Monday, February 1.  Between 9pm on Monday and when class begins on Tuesday afternoon, read your classmates' posts, and come to class ready to discuss them.


Welcome (Spring 2016)

Welcome to the course blog for Ethical Hacking, as taught by Jaime Mahoney and Monica Poole, at Bunker Hill Community College in spring 2016!  This blog will document some of the work of the course.  There will be posts written by students analyzing issues in moral philosophy as related to hacking, a running chronicle of a social engineering game played by students in the course, and other resources.

Monday, May 4, 2015

Drrrrrrrruuuuuuuuuuuuuummmmmmmmmmmmm Rrrrrrrrrrrrrrrooooooooooooooooooooooooooolllllllllllllllllllllll Pppppppppppppllllllllllllleeeeeeeeaaaaaaaaaaaassssssssssssssssssssssseeeeeeeeeee!

The final tally is in!  ADMIRAL THISTLE TAKES IT ALL!!!!

Leaderboard
Final
Name
Points
Admiral Thistle 
59
Captain Black X31
55
Admiral Aquamarine
45 (1 ethical exclusion)
Pink Mystery    
44
MzQueen Green
30 (2 Failed Attempt)
Agent Raven Blue
27 ( 1 Failed Attempt)
InspectorGreen2013     
22 (3 Failed Attempts)
TheBlack Capo  
19 (2 Failed Attempts)


Saturday, May 2, 2015

Final Blog Post – Albert Gonzalez vs TJXX Companies

It is so much easier to pay with a credit/debit card.  Most of us have one, or a few of them. A lot of people don’t like to carry cash with them anymore, and if you need cash, you can easily find an ATM close by, since there are so many around. We also love shopping, and a lot of us use our credit/debit cards to pay for the items we purchase. In order to obtain a Credit/Debit card you have to provide your name, address, social security number, among other personal information to the Bank. So since it’s your personal information, wouldn't you want Companies to protect it when you use your Credit/Debit card to purchase items from them? I would like them to keep my information secure, I hope you would too. But unfortunately when it comes to information security, not all companies and industries are alike.  

Albert Gonzalez was accused of masterminding the combined credit card theft and subsequent reselling of more than 170 million cards and ATM numbers from 2005 through 2007. The biggest such fraud in history. He stole card information from TJX Companies like T.J Maxx, BJ’s Wholesale Club, DSW, Office Max, Boston Market, Barnes & Nobles, and Sports Authority. He hacked stores in different states like New York, Massachusetts, and New Jersey. Gonzalez was arrested on May 7, 2008 and On March 25, 2010, he was sentenced to 20 years in federal prison.

I believe that Albert Gonzalez actions were wrong, and he is guilty as charged, but I have to ask, do you think Albert Gonzalez was the only one at fault? Many would say yes, he was, but I would argue the opposite.

One of the Companies he hacked was T.JX Companies, he hacked T.J Maxx and Marshalls, and these are retail clothing store owned by T.JX that sells designer clothes for a discounted price. Therefor a lot of customers walk in to theirs stores and purchase their items. I am not talking about a small store I am talking about a very big company that is making a very good amount of money. But surprisingly they were using out of date and vulnerable security encryption for their machines and networks. I believe that if a person uses their Credit/Debit card at a store for instance, it is the store’s responsibility to keep the information safe. Once the costumer swipes their card thought the store’s credit machine, the card information is stored, so it becomes the store’s property. Probably more than 90% of the customers affected were not aware that their Credit/Debit card information was compromised. There is a quote by Luke that says ‘to whom much is given, much will be required’ (Luke 12:48). I believe that this quote backs up my argument because when the customer uses their credit/debit card, they are giving the store money in exchange for the items they are purchasing, the company stores the data into their data centers, so therefor there is that required or expected responsibility to keep the data secure.

So I ask, why weren't they protecting their costumer’s private information with up to date security? T.JXX was using WEP security encryption for their network. Almost every hacker out there likes a challenge, but when the security is outdated and weak is like a day at the park for them. I believed that T.JXX Companies did not took the necessary security measures to maintain the data they were responsible to secure. I hope that they learned from this security breach and they can provide better security for their customers.


Sources:
http://www.gotquestions.org/much-given-required.html