Tuesday, May 1, 2018

Spammer can ruin my life! Or can he now?

Recently, I got a message from a spammer (order (at) creativegrowers.com) who claimed he or she could ruin my life. Here is the message for your enjoyment.
Good day...

Do not regard on my English, Im from Japan.I installed the virus onto your device.At present I thiefted all privy background from your device. Furthermore I got some more evidence.The most important evidence that I received- its a videotape with your self-abusing.I put virus on a porn web site and after you downloaded it. As soon as you picked the video and clicked on a play, my malware at once set up on your system.
After adjusting, your web camera made the video with you wanking, additionally software captured exactly the video you chose. In next few days my deleterious soft found all your social media and email contacts.

If you need to delete the records- pay me 540 usd in BTC(cryptocurrency).
I provide you my Bitcoin wallet address - 1Ph5bArH1nN2HVKLLnKE3UB4ZstoEb8Gfc

You have 24 h. to go after reading. As soon as I receive transfer I will destroy the compromising forever. Other way I will send the video to all your colleagues and friends.

The source of the message is 167.99.44.161, which is on Digital Ocean. Furthermore, the message headers tend to indicate that the site "creativegrowers[.]com" got compromised and is spewing spam.

Blockchain.info shows that at least one payment was made to that address, for a total of 0.03 BTC on 2018-04-30, which represents a bit short of $300. Has someone fell for that scam? Is this something else? Anyway, I will keep an eye on the transaction to and from that address.

Thursday, April 12, 2018

Alienvault and Squid-Access logs

While playing with OSSIM and Squid, I found that the logs were not processed: though they were correctly received by the sensor and they appeared in /var/log/alienvault/agent/agent.log, I did not see any event being created or appearing in the server.

Whenever ossim-agent was restarted on the sensor, a message appeared in /var/log/alienvault/agent/agent.log at the first event received. This message ended with "Plugin sid not a number". In the line above that one, which contained the event as parsed by ossim-agent, indeed the plugin sid value was "TCP_TUNNEL".

In /etc/ossim/agent/plugins/squid.cfg, there is a translation table between the status (TCP_HIT, TCP_MISS, ...) and a numerical value. This translation does not exist for TCP_TUNNEL.

After adding it with the next available value to the translation table in squid.cfg and restarting the agent, the TCP_TUNNEL events generated by Squid appear as "Generic event" in Alienvault OSSIM. The rest of the data (source IP, destination IP, hostname et al.)

The same happened with the message TAG_NONE. Adding it to the corresponding plugin fixed the issue.

Thursday, January 18, 2018

Landscape

Brand Luther (book)

Here is a review by Jean: https://www.goodreads.com/review/show/2137840523

Sunday, May 14, 2017

Web Application Hacker's Handbook

Here is a review by Jean: https://www.goodreads.com/review/show/1896919107

Monday, March 27, 2017

Machine Learning, Donald Trump and Reddit

An excellent article by Trevor Martin on using Latent Semantic Analysis on the Reddit r/The_Donald comments.

(Source: Data Elixir)






Tuesday, January 31, 2017

My review of "Le Dé d'Einstein et le Chat de Schrödinger: Quand Deux Génies s'Affrontent"

Le dé d'Einstein et le chat de Schrödinger : Quand deux génies s'affrontent (Hors collection)Le dé d'Einstein et le chat de Schrödinger : Quand deux génies s'affrontent by Paul Halpern
My rating: 4 of 5 stars

Einstein is known as the father of Relativity, as well as of the famous formula that links mass to energy. Schrödinger is known for his cat "thought experiment" and for his wave equation. But did you know that Einstein was also one of the fathers of quantum mechanics? And that both men looked at finding an equation to unify gravity and electromagnetism?

This book is not a biography of either men, though aspects of their lives are presented. It presents how both collaborated, how their friendship fell and how they resumed their collaboration, as well as how their beliefs fitted the evolving physics.

View all my reviews