28 december 2010

27 december 2010

Phishing: Account beveiliging update mij ING

Onderwerp: Account beveiliging update mij ING
Afzender: "ING BANK" <customerservic@Ing.nl>


Betreft: ING Beveiligingscontrole!

Geachte heer/mevrouw,

Afgelopen woensdag is onze server mijn.ING.nl aagevallen door hackers.Wij zijn bezig met ons onderzoek dat onlags is ingesteld en hopen binnenkort deze hackers te ontmaskeren.Tijdelijk is het noodzakelijk dat alle ING Klanten die gebruik maken van mijnING.nl nu momenteel op de onderstaande website inloggen. U kunt inloggen met uw oorspronkelijke inloggegevens. Als u eenmaal met uw bestaande gegevens heft ingelogd, ontvangt u na 5 werkdagen een Activeringscode per post. Ook ontvangt u over 5 werkdagen een e-mail met een link naar een andere website waar uw inloggegevens weer zal moeten invullen en dit keer samen met uw Activeringscode.Let op dit Activeringscode ontvangt u allen als u al een keer op de nieuwe website bent ingelogd.

Wij raden u aan om na het openen van deze e-mail zo snel mogelijk op nieuwe en gevens beveilig de website in te loggen met uw huidige inloggegevens.

klik hier in te loggen,en om deze beveiliging update te bevestigen.

(Het kan zijn dat sommige computers het moeilijk hebben met de capaciteit van de website en niet alles meer zichtbaar is) (Het kan zijn dat sommige computers het moeilijk hebben met de capaciteit van de website en dat enkele dingen niet zichtbaar zijn)

Bij voorbaat dank voor het medewerking van dit process.

Let op!

Bewaar deze brief/e-mail bij uw andere bankpapieren. Zo heft u belangrijke informatie over uw ING bij de hand.


Hoogachtend.


ING Bank N.V

Afdeling Fraude
De spel- en grammaticafouten in de mail ('aagevallen', 'onlags', 'klik hier in te loggen', 'gevens beveilig de website' e.d.) zouden al voldoende moeten zijn om alle waarschuwingsbellen te laten afgaan. De URL achter 'Klik hier' verwijst naar 1gintl.com, niet bepaald een officieel ING-adres, maar als je daar aankomt, lijkt de site wel officieel. Geen gegevens invullen dus. (Als je gefingeerde gegevens invult, word je daarna naar de echte ING-site doorgesluisd.)

(whois)


Open Source Jihad

Klik:

مفاجأة # الملاحم للإنتاج # تقدم # [ العدد الثاني من المجلة Inspire باللغة الانجليزية

ARE YOU REA

Heinecken in Retrospect


Voorbij, voorbij die tijd

Via


liegen


Net doen alsof
... is ook ...

Uit:

Net doen alsof is ook liegen
Dominique Goblet
Vertaald uit het Frans door Ernst van de Hemel
(Oorspronkelijke titel: Faire semblant c'est mentir)
Oog & Blik | De Bezige Bij
ISBN 978-90-5492-259-9


The Internet connection ap...

Ken de beperkingen van je interface:

the internet connection ap...
Twitter for iPhone, iPad, Twitter, Inc.


25 december 2010

It's pixels, stupid



... is ook ...


Net doen alsof

Uit:

Net doen alsof is ook liegen
Dominique Goblet
Vertaald uit het Frans door Ernst van de Hemel
(Oorspronkelijke titel: Faire semblant c'est mentir)
Oog & Blik | De Bezige Bij
ISBN 978-90-5492-259-9


The Smart Card Detective (SCD)

Van de site van Omar Choudary, PhD-opleiding in Computer Science, Universiteit van Cambridge:

--

The Smart Card Detective (SCD)

The SCD is a card-size device that can intercept, monitor and modify the data of an EMV transaction (EMV is the protocol used in Europe for smartcard payments). This device and the associated software are the result of my MPhil project. The main goal of the SCD was to offer a trusted display for anyone using credit cards, to avoid scams such as tampered terminals which show an amount on their screen but debit the card another (usually larger) amount.

However, the final result is a more general and open EMV framework that can basically do anything a card or a terminal might do. That is, the SCD can act as both a card or a terminal (or even a CAP device), and it can relay, monitor and modify a transaction between a card and a terminal.

We have successfully tested the SCD with many CAP readers and terminals. Among the applications implemented I mention: confirmation of requested amount before authorising a transaction, log of transaction data, PIN modification. We have been able to test also the No PIN vulnerability using the SCD. There is also a French reportage on this.

The hardware consists of an ATMEL AT90USB1287 microcontroller, with several features: 3 power supplies (USB, DC, battery), ISP, USB and JTAG connectors, 2 ISO-7816 (smartcard) interfaces. Most of the software (targetted for the AVR architecture) is written in C with some small parts in assembler.

All the details about the SCD can be found on my MPhil thesis.

Reden van deze post: UK Bankers Try Gag of Student's Research.

De link naar het pdf-bestand hierboven verwijst naar een gemirrorde locatie. Andere mirror hier. Het motto: alles waar je aandacht aan besteedt, wordt groter.


Even uitleggen? (2)

Beginscherm Pulse


Even uitleggen?

Beginscherm Control Magazine
(alleszins de moeite waard overigens)