Howto reinstall diablo n800 in linux
http://wiki.maemo.org/Updating_the_tablet_firmware
Official maemo page: Other HOWTOs
http://wiki.maemo.org/?highlight=%252528CategoryFlashing%252529
Reset nokia n800 password
i was able to find the password in /dev/mtd* ...
Install KDE
http://geekpenguin.blogspot.com/2007/09/kde-on-it.html
Descubrimientos de una inteligencia artificial que supera el test de Turing
On the Internet, everybody knows you're a chatbot.
Buscar en Mind w/o Soul
Mostrando entradas con la etiqueta seguridad. Mostrar todas las entradas
Mostrando entradas con la etiqueta seguridad. Mostrar todas las entradas
lunes, julio 13, 2009
miércoles, julio 01, 2009
Estrategias para evaluar la credibilidad de un sitio web
Crap Detection 101
"Every man should have a built-in automatic crap detector operating inside him."Ernest Hemingway, 1954
martes, junio 30, 2009
Hash: Password checkword
Métodos y código/programas javascript para generar códigos hash a partir de claves.
Puede servir para programar una extensión Firefox para la usabilidad de formularios de login (mostrando la checkword para comprobar si ha habido errores al teclear)
http://wijjo.com/PasswordHasher
http://hashapass.com/
http://wijjo.com/passhash/passhash.html
Puede servir para programar una extensión Firefox para la usabilidad de formularios de login (mostrando la checkword para comprobar si ha habido errores al teclear)
http://wijjo.com/PasswordHasher
http://hashapass.com/
http://wijjo.com/passhash/passhash.html
jueves, junio 25, 2009
Security vs usability in login passwords
Jakob Nielsen has a recent Alertbox against obscuring passwords with ****asterisks****. Some people has proposed several solutions, but none of them is both secure and usable. I think I've found a solution that is both.
Thinking of this as an information problem instead of (just) a security one,
what is needed to solve it is something like the hash codes as used in
cryptography.
You don't really need to show the *whole* password, just enough
information derived from it so that the user will notice if there was
an error. For an example on how it could work:
- Say, the chosen password is HOMELAND.
- As a simple hash, remove every second letter: HMLN
- Shift each letter one character down: GLKM
- For this result to be usable, combine each obtained letter with the
nearest vowel: GILOKOMO
If the user mistypes the password, a different check-word will be produced.
For example: HOPELAMD -> HPLM -> GOKL -> GIOUKOLO *error, the
password is wrong.
Of course, a real hash function should be used that utilizes *all* the
information in the original password, not half of it! The important
property of a hash function is that the original information can't be
recovered from it, so the password is safe. Much better for security
than a plain-text exposed password, isn't it?
This process has a small usability problem in that you'll have to
learn the check-word for every new used password, but login is such a
repetitive procedure that this learning should happen quickly.
Thinking of this as an information problem instead of (just) a security one,
what is needed to solve it is something like the hash codes as used in
cryptography.
You don't really need to show the *whole* password, just enough
information derived from it so that the user will notice if there was
an error. For an example on how it could work:
- Say, the chosen password is HOMELAND.
- As a simple hash, remove every second letter: HMLN
- Shift each letter one character down: GLKM
- For this result to be usable, combine each obtained letter with the
nearest vowel: GILOKOMO
If the user mistypes the password, a different check-word will be produced.
For example: HOPELAMD -> HPLM -> GOKL -> GIOUKOLO *error, the
password is wrong.
Of course, a real hash function should be used that utilizes *all* the
information in the original password, not half of it! The important
property of a hash function is that the original information can't be
recovered from it, so the password is safe. Much better for security
than a plain-text exposed password, isn't it?
This process has a small usability problem in that you'll have to
learn the check-word for every new used password, but login is such a
repetitive procedure that this learning should happen quickly.
lunes, agosto 11, 2008
Ingeniería social - cómo estar sobre aviso
Social engineering warnings. Comentario slashdot comment
Meta Moderation
Meta Moderation
Some warning signs that you may be subjected to social engineering:
- The person starts using your first name without you having ever met.
- The person refers to an authority figure in a jocular/friendly way, in order to make you draw the conclusion that the authority figure knows and trusts this person.
- They will try to appeal to your vanity. E.g. they may imply that they called YOU because you're so friendly and helpful. Ask yourself whether, if it really was this urgent, they would be calling you instead of those whose job it is to deal with this sort of situation. If you believe for one second that it's because of your demeanor, you're not only stupid but vain too.
- They mention a common foe. "You know how accounting is..." Yeah, everyone knows that accounting are bastards to anyone not in accounting, in every company in every country. That doesn't lend credence to you being on the same side.
- They mention an interest of yours. "I had planned to take my son fishing this weekend, but I guess I'll be working, trying to fix this". Why would they tell that to a stranger? (Especially if you have a sticker saying "BITE MY BASS" on your car.)
- If face to face, the person smiles a lot. Nothing disarms suspicion as easily as a smile.
miércoles, julio 30, 2008
Seguridad en tarjetas de crédito
Análisis de los contratos
Seguridad de las tarjetas de crédito (Dinero y Derechos nº 106) - Newsletter OCU Informa Contenido Global
Seguridad de las tarjetas de crédito (Dinero y Derechos nº 106) - Newsletter OCU Informa Contenido Global
Consejos para evitar problemas
• Firme la tarjeta cuando la reciba.
• No lleve encima el número secreto, y tampoco lo apunte en un sitio accesible. Es mejor que lo memorice, aunque debe evitar fechas muy significativas, como su fecha de nacimiento, números del DNI o de teléfono, etc.
• Sea cuidadoso con extractos de cajeros, recibos de compra y otros documentos donde pueda aparecer el número de su tarjeta. Piense que el número y la fecha de caducidad bastan para hacer una compra por teléfono o Internet.
• Si observa algún dispositivo sospechoso en el cajero, no lo use. Evite abrir la puerta para acceder a cajeros situados en el interior del banco, pues ése es un sitio habitual para colocar grabadores de tarjetas. Si quiere usar esa terminal, intente abrir la puerta con otra tarjeta de banda magnética (tarjeta sanitaria, de un club, etc.).
• Cuando use la tarjeta para pagar una compra o servicio, procure no perderla de vista.
• Plantéese la posibilidad de usar medidas de seguridad adicionales, como el envío de SMS al móvil cada vez que se use su tarjeta.
• Si aun así le roban o duplican la tarjeta, avise a la entidad cuanto antes, y confirme la comunicación por escrito, para que quede constancia. Denúncielo también en comisaría. Pida que le devuelvan el importe defraudado y exija los justificantes de todas las operaciones realizadas con la tarjeta: si los resguardos están sin firmar o si la firma es muy diferente, reclame, el banco está obligado a devolverle todas las cantidades defraudadas, incluso las que no superen el límite de responsabilidad. Si se trata de una compra a distancia (por teléfono o Internet), puede exigir que anulen el cargo, pues el titular no es responsable si el medio de pago no se presentó físicamente.
• A veces las pólizas de seguros de hogar cubren el robo o pérdida de tarjetas: compruébelo.
lunes, julio 21, 2008
Cómo desactivar el DRM de tu juego (legalmente comprado)
Y evitar bajarse cracks llenos de virus.
Ubisoft Steals 'No-CD Crack' To Fix Rainbow 6: Vegas 2
Ubisoft Steals 'No-CD Crack' To Fix Rainbow 6: Vegas 2
download mini images (on gamecopyworld.com as "fixed images"). These are disc images for the games, with copy protection intact, that are only a few megabytes large as they only have the crucial bits.
In the very rare cases when Alcohol can't manage a working image, I go to Game Copy World
[gamecopyworld.com] and download the no-CD crack. I don't like doing
that, though, simply because it makes it hard to apply official game
patches.
domingo, junio 08, 2008
Acceso WEP
crack
http://www.smallnetbuilder.com/content/view/24244/98/
http://www.governmentsecurity.org/archive/t15149.html
http://www.smallnetbuilder.com/content/view/24244/98/
http://www.governmentsecurity.org/archive/t15149.html
miércoles, abril 23, 2008
HOW TO: Recuperar la contraseña maestra de Firefox
La contraseña de seguridad de Firefox se puede crackear con este programa.
Recover Firefox Master Password with FireMaster Recovery Tool » My Digital Life
Recover Firefox Master Password with FireMaster Recovery Tool » My Digital Life
Security Xploded releases a password recovery tool named FireMaster to recover the Firefox master password. FireMaster is an open source software that able to recover the Firefox master password from the Firefox key database file by generating password on-the-fly using combination of various password guessing (cracking) techniques such as dictionary, hybrid and brute force method, utilizing the same password matching and verification algorithm used by Firefox itself described above, but in an optimized way. FireMaster calculates the hash of the generated password and uses the hash to decrypt the known encrypted string for the password, until it get one that matched the known string, which is the correct master password.
jueves, abril 17, 2008
Darse de baja de los anuncios
Cookies para darse de baja del seguimiento personalizado, en las dos mayores redes de anuncios en internet
Consumer Groups Advocate for 'Do Not Track' Registry
Consumer Groups Advocate for 'Do Not Track' Registry
They have a "opt-out" cookie value.
http://www.doubleclick.com/privacy/dart_adserving.aspx [doubleclick.com]
The catch being that if you do clear your cookies, you'll have to re-set the opt out cookie as well.
If you care, here's the URL to opt-out of the other big ad network:
http://www.atlassolutions.com/optout.aspx [atlassolutions.com]
I don't have all of them, but Doubleclick and Atlas cover something like 75-80% of the market.
martes, abril 08, 2008
Compras online: cómo investigar al vendedor
How To: How To Research An Unknown Online Retailer
- Do they have a toll free customer service number and published hours of operation?
- Do they take credit cards? It is no guarantee of quality if they
do, but it is one step up. I think you should generally avoid any place
that only takes Western Union money transfers. - Do they have a security/hacker prevention or testing certificate?
- Does the checkout process use an encrypted HTTPS page?
- Are the company Privacy and About pages blank, or do they look like
they are from a default template for an online shopping cart that was
just set up the day before? - Search Google for the store name and words like "scam" and
"customer service." It is not a good thing if all the entries are for
people asking if a site is a scam in Yahoo Answers.
viernes, abril 04, 2008
Paypal scams
I Was Scammed
With this particular auction I felt a little concerned about the funds and have heard about possible chargebacks after items were sent, so I called Paypal to verify my security on this situation. I talked with a representative about the situation and they assured me that once the money was cleared into my account that the buyer couldn't charge back the purchase.
I called in twice and asked the same questions but the second time I was in more detail with the questions. This time I was put through to someone higher up that assured that the money was safe in my account and could not be removed. They failed to tell me that they would just put my account at a negative balance and I would have to be the one to take the money out of bank account.
Timo a traves de Royal Mail
EOS 5D - Royal Mail Scam - The Photo Forum - Photography Discussion Forum
I had found an EOS 5D in mint condition + vertical grip for 1300$ on Craig's List. I contacted the seller, asking him a lots of questions to be sure everything is as mint as he said it was, well, so far everything was good, i was convinced that I was doing an excellent deal ! Then I received an invoice from the Liverpool Royal Mail post office saying that the package was ready to be shipped and that now I had to make the payment so that it can be shipped. The payment had to be done thanks to Wester Union to the account of a pretented employe of the Post Office. The invoice can be found here. You can actualy try the tracking number, it's working.
lunes, marzo 17, 2008
Undelete para Windows
Gratuito para recuperar ficheros borrados
The Reviews 4 U - Free Recover Tool
The Reviews 4 U - Free Recover Tool
Restoration is a File Recovery Freeware by Brian Kato intended to recover any deleted file in Windows 9x, 2000, XP on FATs or NTFS partitions.
Qué debe tener un buen Antispyware
Spyware Exposed: What To Look For In Anti-Spyware Solutions
Your antispyware must not only detect and remove spyware and adware but also be able to prevent spyware from getting into your computer. It must be able to remove the maximum kinds of spyware and adware. Above all, you must find the antispyware easy to use. The language used must not be so complicated that you spend your time just figuring out what they mean. The antispyware scan must be quick and run in the background. Customization should be easy. You should be able to scan specific parts of your computer. You should also be able to choose which items to exclude from scanning. While setting up and installing the antispyware software should be easy and quick to download and install.
viernes, marzo 14, 2008
Software de recuperación de datos corruptos
Sin backups!
Data Recovery: How Data Get Lost and means to recover
Data Recovery: How Data Get Lost and means to recover
Data recovery software is designed for any one to use. Using the data recovery software you simply choose what you want to do, and the software does the work, with no technical knowledge required at all.
lunes, marzo 10, 2008
Limpiadores de registro de Windows gratuitos
The Most Downloaded Registry Cleaners -2
Lets continue our review of the most downloaded cleaners with registry cleaner software number two and three…
domingo, febrero 10, 2008
Revisión anual del coche - consejos de taller
REVISIÓN DEL COCHE: RECOMENDACIONES PARA ELEGIR UN TALLER en Supermotor.com
REVISIÓN DEL COCHE: RECOMENDACIONES PARA ELEGIR UN TALLER
Si tienes que llevar tu coche a revisión te interesa leer las recomendaciones que da CECU para escoger un taller y conocer todos tus derechos. Para que no te den 'gato por liebre'. ¡Buen viaje!
Powered by ScribeFire.
Revision semanal del coche
Cómo hacer una pequeña revisión al coche antes de iniciar un viaje
elementos básicos que se deben revisar antes de iniciar un viaje en coche.
Son comprobaciones que no nos llevan mucho tiempo (en 15 o 20 minutos podemos tener todo listo) y que nos pueden dar bastante tranquilidad en el viaje.
A continuación os incluyo los principales puntos que se tratan en el video, podéis imprimir la lista y llevarla para hacerle una pequeña revisión, que si bien hay que hacer durante todo el año, en viajes como los de Semana Santa es más recomendable todavía.
- Comprobar el desgaste de los neumáticos
- Comprobar la presión de los neumáticos, en frío, teniendo en cuenta si vamos a llevar más carga de la habitual
- Comprobar los flancos de los neumáticos por si tienen algún golpe
- Comprobar si se nota una fricción metálica en los frenos al pisarlos
- Aceite: revisar la fecha de cambio. Si hay que añadirlo, hacerlo en frío.
- Comprobar niveles de líquido de dirección asistida, frenos, anticongelante y limpiaparabrisas
- Comprobar que las todas luces funcionan y asegurarse que llevamos el juego de recambio
- Revisar que llevamos el gato, la llave y la presión de la rueda de repuesto
- Comprobar que llevamos a mano la documentación del vehículo, incluida la póliza del seguro y el justificante de pago
- Comprobar que llevamos el chaleco reflectante
(obligatorio, en la guantera o accesible desde el puesto del
conductor), los dos triángulos de avería homologados
(obligatorios) y una linterna (recomendado)- Estudiar la colocación de la carga,
situando las maletas más pesadas en la parte inferior del
maletero. Nunca dejar objetos sueltos, a 50 km/h un paraguas impactando
contra nuestra cabeza pesa más de lo que parece.
Powered by ScribeFire.
viernes, febrero 08, 2008
Análisis de seguridad al navegar a un sitio web
Esta página avisa si un sitio web es seguro o sospechoso.

SiteAdvisor - Análisis
SiteAdvisor - Análisis
SiteAdvisor Análisis
Éste es el lugar ideal para profundizar un poco más y explorar los detalles de nuestro análisis, unirse a nuestra red de revisores o tener más información sobre nuestra metodología de comprobación.
Suscribirse a:
Entradas (Atom)