Thursday, October 15, 2009

Anti-Phishing: The Definitive RapidShare Account Protection Guide

Anti-Phishing: The Definitive RapidShare Account Protection Guide



Hey guys. I'm back again with another comprehensive guide. This time, I'm going to go over something that's absolutely rampant on today's warez forums: RapidShare account phishing.



So this is what happens. You're just browsing through your usual favorite forums, downloading as you please, and then suddenly, on one of the topics, someone points out that a post has phishing links, and then a moderator closes it. Well, that's great for them and all, but how about you? How do YOU know it's a phishing link? How do you protect your account in the future when there's no one else to say if it's a phishing link or not? Of course, our awesome Mods here at WS tend to catch these links, but they need your help to make it a safer forum for everyone!

Fear not! . I have quite a few precautions that I'm going to lay out for you guys that I can promise will make sure you don't get your account stolen/phished, and I guarantee a 100% success rate. Why am I spending so much time doing this? Because I love
Cyberwarez, and enjoyed the community since the day I joined, and I'll be damned before I see this place go down the drain to scammers and phishers. You'll see me posting a lot on topics, spotting the phishing links and reporting them. How do I know so well what's phishing and what isn't? You'll find out as you read, and soon, you'll be able to spot and report them just like me!



So first off. Let's analyze what exactly phishing is. Phishing (pronounced "fishing") is the process by which someone makes a complete visual copy of a website and puts it up on a different server( anyone can access it like a regular website), so that unsuspecting users not paying close attention will input their personal data, which gets sent to the scammer. This is commonly used on banking/credit card/PayPal-like sites, in which someone logs into to what they think is the real site, but their details are sent to the scammer. These people don't suspect anything, because once the scammer has the login credentials, he can have his phished website redirect the person to the real site, and have them automatically logged in using the credentials he just stole. It's an ingenious idea, but is utterly dangerous and very angering to us unsuspecting users. The biggest flaw of RS that scammers exploit is the ability to be logged into an account from multiple computers. I'll explain more as to how this related to RapidShare as we go on.

So, now that you know what phishing is, here's the ways you can successfully fight it. I'll include both Pro's and Con's of each method, but using them all together is the absolute best way to prevent any sort of phishing, 100% guaranteed. I'll also include a section at the bottom to help you out if your account has already been compromised/stolen, and what you can do about it.

As usual with my guides, it requires no third-party software (which I rarely ever trust) and no hacking.


So, let's begin.



1. Lock Your Account (No, Really)
RapidShare recently launched a new safety feature called the Security Lock, which is giving account-stealers quite a headache . Essentially, what this does, when you enable it from your online RapidShare account, is lock down your account to unauthorized use. It sends the email account registered to your account a confirmation number, which locks the account. What does this do? This prevents from anyone changing the password/email address, or using your hard earned RapidShare Points. This essentially locks down the ONLINE account (the one you login to through RapidShare.com). If it locks them out, how can you change those details and use your Points? Easy. All you have to do is log in to your account through the web site, click Unlock, and another confirmation code is sent to your email, which allows you to change those details or use your points. My suggestion? Use it! You won't notice a thing when you're downloading, and it's really easy to do!




* Stops intruders who have compromised your account from changing the password, or the registered email address
* Stops intruders from using up your hard earned RapidShare Points to create themselves a free account
* Intruders cannot Unlock the account themselves without access to your email account (which they of course don't)



* Doesn't stop an intruder who's already compromised your account from blowing through your daily bandwidth. If your account has already been stolen/compromised, please proceed to the bottom of this post.
-----------------------------------------------------------


2. Set Your Account Up To Directly Download:
What does this mean? It essentially means that you don't go through the screen that asks you if you'd like to download as a Free or a Premium user. This shows up by default, whether or not you're logged in as a Premium user. You've all seen it, but here's a quick screenshot of what it looks like, just so you know which page I'm talking about:



This is so that you can thank people by downloading a small file (uploaded by them) as a free user to earn them points. As good-natured as it is for you to do that, it poses a security threat. The most common form of roping people into giving away their account details is to use a "Link Protector" to mask their phishing URL so that you don't suspect anything. the so called link-protectors actually don't do shit to stop people from leeching other people's RapidShare links for forum posts. There is nothing stopping me from copying and pasting your links just because you used a "link-protector". Because a phishing site obviously cannot have the same URL as the original site it's phishing, it poses a problem for scammers as to how to get your login details without you suspecting anything. So under the pretense of a "link-protector" the URL of the phishing link is hidden, and it will take you to the Free or Premium download page, at which even if you're logged into RapidShare, clicking the Premium download page will ask you to enter your login/password, just like the official site would do if you weren't logged in. Don't fall for this! So what are my suggestions? First, go into your account settings for RapidShare and enable Direct Download. It's under settings, as shown here:


This eliminates that Free or Premium Download page, and always downloads premium the instant it's clicked. This way you can be sure you're clicking on a genuine RS link because the moment you click on it, it will initiate the download, since you are inititating a direct download. Second, if that page DOES show up, even after turning on Direct Downloading, then something is definately up. Check the URL of the link you clicked on. If it says ANYTHING other than

Code:
RapidShare: 1-CLICK Web hosting - Easy Filehosting

Where the *'s are numbers and a file extension, it's a phishing link.

Here's a few visual examples of real and fake links.

Fake (These were taken from actual phishing links. Although the URL's are obviously wrong, don't scoff at people for falling for it. The screen they saw at this URL was the exact same as the Free or Premium Download page above. Would you have spotted the difference if you weren't looking at the URL?




A REAL Genuine RapidShare URL:

If it still shows the screen but it's a genuine RapidShare link, then it's a possibility that you logged out. Log back in. When you log in, RS saves a cookie on your computer to tell the site that you don't need to log in as you've already provided the correct credentials.

Logging out deletes this cookie from your computer:


Power users may search through their Cookies folder to see if it's there or not.

* 100% absolute fool-proof way to avoid being phished
* Makes it even easier to download from RapidShare by removing that intermediate step of having to pick which download type

* If you'd like to thank someone by download a file as a free user, you cannot do that in this scenario. You need to log out of RS first, then download it, and log back in, or go into your settings and uncheck the Direct Download each time you want to thank somebody. It's not quite a bad thing, it's just a lot of steps.
--------------------------------------------------------


3. Keep an Eye on Your Traffic Logs!
RapidShare has given you many tools to watch for abusive activity on your account. One tool is an IP Logger found in "Premium Zone>View Logs", which logs the IP Address of the downloader each time a file was download on your account. So how can this help you? It's all numbers to you, right? Doesn't make sense? Fear not! Essentially, what an IP Address is a household-specific address that identifies your internet connection. It's kind of like a family name that identifies who you are. Each computer has their own IP provided by their ISP. All you have to do is use a free web service to find out what your IP Address is. I personally prefer
Code:

What Is My IP Address? - Lookup IP, Hide IP, Change IP, Trace IP and more...

Write that down, and compare it to your traffic log. Each time you see that same number on your log, it means the download came from your computer. If you see an IP that doesn't match the number you wrote down, it can mean one of two things. One, it could mean you downloaded something yourself from a different computer in someone else's house/work. Two, it could also mean somebody has already compromised your account and has been using it to download for themselves. How can you tell the difference? Use the site mentioned above, and paste the unknown person's IP into the box. and click "Lookup IP Address". You'll get a pretty decent explanation as to where the person's IP is based, such as Country/State/City, so if it's at someone's house you know or is at work, you know it was you. If it isn't either and is from some place you know you've never even been too, it means your account has been compromised and is being used. Use that information as well as the information from the IP Lookup to report it to RapidShare for fraudulent use.


Here's a picture comparison of a clean account and a "dirty" account.
In this account, you see that all logs of downloading are from my IP Address, which is 67.***.***.***. It all checks out.

Find it in Word 2007: Change Case

Word’s Change Case feature has long been one of its handiest devices. It’s not smart enough to apply true title case (where articles and prepositions are left uncapitalized), but it will still save you a significant amount of time.
So now that you’re using Word 2007, how do you make the feature work? If you’re a keyboard shortcut person, nothing has changed: Shift + F3 will toggle selected text from one style of capitalization to the next. But if you like menus better… DOH. No menus in Word 2007. Here’s a quick feature recap and a look at how it works in the new version.
Note: This information is also available as a PDF download.
The old way

In Word 2003, you select your text, pull down the Format menu, and choose Change Case. Word displays a dialog box with options for:
  • Sentence Case
  • Lowercase
  • Uppercase
  • Title Case
  • Toggle Case
Just choose the desired format and click OK to apply it.
The new way

In Word 2007, you have to readjust your thinking a little bit. Click the Home tab on the Ribbon and then find the Change Case button in the Font group. Click it, and you get what’s billed as a Change Case “gallery” (Figure A), although it doesn’t give you a live preview of your selection as other galleries do. It’s really just a menu, but don’t tell Microsoft.
Figure A


Choose the format you want from the list — you’ll notice the options are identical to the ones in Word 2003, except that we now have the more honest and accurate Capitalize Each Word instead of Title Case. Same thing. As soon as you choose an option, Word will apply the change.
Additional possibilities

If you decide that Change Case belongs on your Quick Access Toolbar (so that you don’t have to go tab-hopping looking for it), it’s easy to put a button on there. In fact, you can put THREE Change Case buttons on there: One is called Change Text Case, and it acts just like the Shift + F3 shortcut, toggling from one format to another with no lists or dialog boxes presented. Another one displays the Change Case gallery shown above (ChangeCaseGallery). And the third one displays an old-fashioned Change Case dialog box similar to previous versions of Word (ChangeCaseDialogClassic).
To add one of these buttons, first click the Customize Quick Access Toolbar button at the end of the toolbar and choose More Commands. Select All Commands from the Choose Commands From drop-down list. Scroll down to Change Text Case, if that’s the one you want, and select it, as shown in Figure B. Just click Add to place it on the Quick Access Toolbar and click OK.
Figure B


If you want the gallery or the classic dialog box button, locate the two Change Case items on the list, as shown in Figure C. You can use the tooltip description to determine which one you want before selecting it and clicking Add.
Figure C


For those of you who are curious, Figure D shows the Change Case dialog box you can access if you put the ChangeCaseDialogClassic item on your Quick Access Toolbar.
Figure D

One final note: Everything discussed here works exactly the same way in PowerPoint 2007, except that it gives you only one Change Case command (ChangeCaseGallery) in the All Commands list for customizing your Quick Access toolbar. And that’s probably plenty.

RapidShare Point Generator By Ws 100% Works

RapidShare Point Generator By Ws 100% Works



Tutorial by Mohan
Here is a image with steps to make it work. Hope it helps with problems some have.



Download Link

Code:
http://www.easy-share.com/1908112293/New_Rapidshare_Points_Generator_100__works.rar

Hack a Gmail account with the GX Hack a Gmail account with the GX cookie

This is not one of my own tut i read this from other site anyway it looks usefull read and see

Quote:
Tutorials

Assumption:

You are in Local Area Network (LAN) in a switched / wireless environment : example : office , cyber café, Mall etc.
You know basic networking.

Tool used for this attack:
Cain & Abel Downlaod
Network Miner Download
Firefox web browser with Cookie Editor add-ons Download

Details:

We assume you are connected to LAN/Wireless network. Our main goal is to capture Gmail GX cookie from the network. We can only capture cookie when someone is actually using his gmail. I’ve noticed normally in comp classes, neat the start people normally check their emails. If you are in cyber café or in Mall then there are more chances of catching people using Gmail.

We will go step by step,
If you are using Wireless network then you can skip this Step A.

A] Using Cain to do ARP poisoning and routing:

Switch allows unicast traffic mainly to pass through its ports. When X and Y are communicating eachother in switch network then Z will not come to know what X & Y are communicating, so inorder to sniff that communication you would have to poison ARP table of switch for X & Y. In Wireless you don’t have to do poisoning because Wireless Access points act like HUB which forwards any communication to all its ports (recipients).

Start Cain from Start > Program > Cain > Cain
Click on Start/Stop S(Report to Staff)(Report to Staff)(Report to Staff)(Report to Staff)(Report to Staff)(Report to Staff) tool icon from the tool bar, we will first scan the network to see what all IPs are used in the network and this list will also help us to launch an attack on the victim.
Then click on Sniffer Tab then Host Tab below. Right click within that spreadsheet and click on Scan Mac Addresses, from the Target section select
All hosts in my subnet and then press Ok. This will list all host connected in your network. You will notice you won’t see your Physical IP of your machine in that list.
How to check your physical IP ?
> Click on start > Run type cmd and press enter, in the command prompt type
Ipconfig and enter. This should show your IP address assign to your PC.
It will have following outputs:


Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . : xyz.com
IP Address. . . . . . . . . . . . : 192.168.1.2
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
Main thing to know here is your IP address and your Default Gateway.

Make a note of your IP Address & default gateway. From Cain you will see list of IP addresses, here you have to choose any free IP address which is not used anywhere. We assume IP 192.168.1.10 is not used anywhere in the network.


Click on Configure > APR > Use Spoof ed IP and MAC Address > IP
Type in 192.168.1.10 and from the poisoning section click on “Use ARP request Packets” and click on OK.


Within the Sniffer Tab , below click on APR Tab, from the left hand side click on APR and now click on the right hand top spreadsheet then click on plus sign tool from top. The moment you click that it will show you list of IP address on left hand side. Here we will target the victim IP address and the default gateway.

The purpose is to do ARP poisoning between victim and the default gateway and route the victim traffic via your machine. From the left side click on Victim IP address, we assume victim is using 192.168.1.15. The moment you click on victim IP you will see remaining list on the right hand side here you have to select default gateway IP address i.e. 192.168.1.1 then click on OK.

Finally, Click on Start/Stop Sniffer tool menu once again and next click on Start/Stop APR. This will start poisoning victim and default gateway.

B] Using Network Miner to capture cookie in plain text

We are using Network miner to capture cookie, but Network miner can be used for manythings from capturing text , image, HTTP parameters, files. Network Miner is normally used in Passive reconnaissance to collect IP, domain and OS finger print of the connected device to your machine. If you don’t have Network miner you can use any other sniffer available like Wireshark, Iris network scanner, NetWitness etc.

We are using This tool because of its ease to use.


Open Network Miner by clicking its exe (pls note it requires .Net framework to work).
From the “---Select network adaptor in the list---“ click on down arrow and select your adaptor If you are using Ethernet wired network then your adaptor would have Ethernet name and IP address of your machine and if you are using wireless then adaptor name would contain wireless and your IP address. Select the one which you are using and click on start.
Important thing before you start this make sure you are not browsing any websites, or using any Instant Mesaging and you have cleared all cookies from firefox.

Click on Credential Tab above. This tab will capture all HTTP cookies , pay a close look on “Host” column you should see somewhere mail.google.com. If you could locate mail.google.com entry then in the same entry right click at Username column and click on “copy username” then open notepad and paste the copied content there.
Remove word wrap from notepad and search for GX in the line. Cookie which you have captured will contain many cookies from gmail each would be separated by semicolon ( GX cookie will start with GX= and will end with semicolon you would have to copy everything between = and semicolon
Example : GX= axcvb1mzdwkfefv ; ßcopy only axcvb1mzdwkfefv

Now we have captured GX cookie its time now to use this cookie and replay the attack and log in to victim email id, for this we will use firefox and cookie editor add-ons.

C] Using Firefox & cookie Editor to replay attack.


Open Firefox and log in your gmail email account.
from firefox click on Tools > cookie Editor.
In the filter box type .google.com and Press Filter and from below list search for cookiename GX. If you locate GX then double click on that GX cookie and then from content box delete everything and paste your captured GX cookie from stepB.4 and click on save and then close.
From the Address bar of Firefox type mail.google.com and press enter, this should replay victim GX cookie to Gmail server and you would get logged in to victim Gmail email account.
Sorry! You can’t change password with cookie attack.

How to be saved from this kind of attack?
Google has provided a way out for this attack where you can use secure cookie instead of unsecure cookie. You can enable secure cookie option to always use https from Gmail settings.
Settings > Browser connection > Always use https

Ad-Aware's 2010 security bid

One by one, the major Windows security vendors have been updating their antivirus apps and suites to protect against malware. Lavasoft is the latest, but you'll likely know this company better by its flagship product, Ad-Aware.

Like many of the other security apps that have updated for 2010, Ad-Aware 8.1 (download) boasts faster speeds and an engine that detects malware not just by definitions, but by suspicious behavior, too. As with its competitors, Ad-Aware has a three-tiered setup that includes a free version and two premium levels.

Speaking of security, the Google Chrome browser received a new extension aimed at keeping Chrome surfers from wandering to dodgy sites. The free Web of Trust add-on, which is already in use on Firefox and Internet Explorer browsers, isn't quite ready for prime time yet, but the adventurous can try it out on the developer preview version of Chrome.

Best of the best: High-performance HDTVs

It's been more than a year since we awarded our first and only "10" in performance to the Best TV we've ever reviewed, Pioneer's Kuro PRO-111FD. Since then, we've reviewed more than 50 other HDTVs, none of which were capable of matching its picture quality. Since the Kuro has been discontinued, and is quickly gaining the status of legendary collector's item as it disappears from store shelves, it's time to crown a new "Best" for each category of TV we review.

Best plasma: Panasonic's TC-PV10 series blends great black levels with accurate-enough color and that uniform plasma picture to leap past any of the other plasmas we've tested this year, and nearly all of the LCDs.

Best LCD: The Samsung UNB8500 series takes LCD picture quality to a new level. This local-dimming, LED-based display costs a bundle, but makes up for it with the deepest black levels you can get without springing for a Kuro.

Best non-LED-based LCD: Sure LED-based models get all the ink these days, but we thought that for completeness' sake, LCDs with conventional backlights should get a category to themselves. Yes, the winner is another Samsung, but not because if its 240Hz processing.

Best projector: Samsung's improved Joe Kane projector delivers the most accurate color in the business and better black levels than ever, making it the hands-down winner in this category.

Best picture quality overall, flat-panel TV: It's basically a tie between the best plasma and the best LCD. As long as you sit in the sweet spot directly in front of the screen, The Samsung 8500 delivers better picture quality than the Panasonic V10. But if you move to either side, the 8500's black levels wash out and the V10's picture slides into first place.

Barring a better-performing model coming out between now and the end of the year--an unlikely scenario in our opinion--these sets will remain atop the HDTV picture-quality heap until the flagship 2010 models arrive.

More Resources
Best 5 HDTVs,
Best HDTVs overall,
CNET's HDTV World,
Four styles of HDTV,
'Should I buy a Kuro before it's too late?',
LED-based LCDs explained
Product name
Price$4,499.99$1,818.18 to $2,099.00$3,998.00 to $4,049.00$1,749.00 to $2,799.99Check Prices
CNET editors' rating
Average user rating
Review dateSeptember 30, 2008June 08, 2009October 06, 2009May 14, 2009September 14, 2009
The Bottom LineThe Pioneer Elite PRO-111FD represents the pinnacle of flat-panel HDTV picture quality.The high-end Panasonic TC-PV10 series of plasmas delivers the overall best picture quality of any flat-panel HDTV we've tested so far this year.It costs a mint, but Samsung's local dimming, LED-based UNB8500 series delivers the best picture quality of any LCD we've tested.The Samsung LNB750 series can't beat the picture quality of the best plasmas and LED-based LCDs, but for a conventional LCD, it's one of the best we've tested.The new chip in Samsung's SP-A900B helps it to outperform every projector in its class, including its step-down Joe Kane-designed brother, and to compete favorably against significantly more-expensive three-chip DLP projectors.
Similar ProductsCompare more productsCompare more productsCompare more productsCompare more productsCompare more products
Features
Weight88 lbs
79.4 lbs
Info unavailable67.5 lbs
21.6 lbs
Resolution1920 x 1080
1920 x 1080
1920 x 1080
1920 x 1080
Info unavailable
Sound Output ModeStereo
Stereo
Stereo
Stereo
Info unavailable
DVDNone
None
None
None
Info unavailable
Remote ControlRemote control - Infrared
Standard remote control - infrared - Infrared
Remote control - Infrared
Remote control - Infrared
Info unavailable
VCRNone
None
None
None
Info unavailable
TechnologyPlasma (PDP)
Plasma (PDP)
TFT active matrix
TFT active matrix
Info unavailable
Diagonal Size50 in - Widescreen
50 in
55 in - Widescreen
52 in - Widescreen
Info unavailable
Additional FeaturesCrystal emissive layer
Still picture capability
Room light sensor
Microsoft PlaysForSure protected content
Screen coating filter
Viera image viewer
Viera Link
Viera Cast
Motion pattern noise reduction
Ultra clear panel
Auto Motion Plus frame interpolation technology
Ultra clear panel
Info unavailable
Product DescriptionPioneer PRO 111FD - 50 in Plasma TV
50 in
Samsung UN55B8500 - 55 in LCD TV
Samsung LN52B750 - 52 in LCD TV
Info unavailable
Full specificationsFull specificationsFull specificationsFull specificationsFull specificationsFull specifications
Buying choices

This product is available exclusively through approved dealers.