How I plan on stealing your password, and how you will stop me.

In the past few years people have become more aware of the danger of having their passwords stolen. Email, facebook, and twitter passwords are especially easy to acquire without any “crazy hacks” and by simply using some good old fashioned detective work and a little social engineering.  I’m going to outline some things that most people overlook.

235453953_b565f23939

THEN, I’m going to show you how to protect yourself from these types of attacks. A slight disclaimer, however, is that if someone really knows what they are doing and is determined enough, they can get just about anything they want from you – regardless of how aware you are of these attacks. Let’s hope no one hates you that much!

A lot of people might disagree with me showing people how to break into these accounts. I, however, feel if you don’t know how people get in, how can you properly protect yourself?

If you have a strong technical background or tinker with computers you already know everything in this article; I am not going to show you any complicated hacks this time around. This article is geared towards the everyday computer user to hopefully make them more aware of the silly things we often overlook when we set up our accounts.
Read more

Faking it: How to pretend to be someone else using their email address, and how to spot if it happens to you.

Email addresses, much like the caller-id on a phone, are something most people just take for granted as being correct. What if I was to tell you that with 30 seconds of time someone could change their email address to yours (or anyone’s, for that matter) and email whomever they wanted? It’s called Email Spoofing, and I am going to show you that this can (and does) happen.

Hotmail, Yahoo, Aol, Gmail Email Spoofing.

What is email spoofing? Wikipedia defines it asa term used to describe (usually fraudulent) e-mail activity in which the sender address and other parts of the e-mail header are altered to appear as though the e-mail originated from a different source”

In this article I will show you how to make your email address appear to be whatever you want it to be. I will also show you how to identify spoofed emails and protect yourself from becoming a victim of this form of attack.
Read more

Secura Obscura: Two clever ways to securely & secretly hide your data in plain sight.

Data security is something most people take for granted even though our computers and the Internet are inherently insecure. This insecurity is heightened even further if other people have physical access to our computers. With enough time, anyone can break into our windows/linux/Mac accounts, copy our internet history, our saved passwords and much  more. I am going to show you two ways to securely hide your data through trickery, obscurity and encryption.

top secret by alamosbasement's

First, I am going to show you how to hide your data  on a simple USB flash key. Doesn’t sound secure? Well we are going to pull a switch-a-roo: We are going to take a 1gb USB key and put the insides of it into a 256mb USB key’s casing, then edit the partitions so when people plug it into their computer it will appear to be 256mb.  The remaining portion of the drive will be hidden so no one will be aware you actually have another 700+ mb’s of hidden data.  As a backup the hidden portion will be secured with Government Top-Secret Level AES encryption and hidden behind another dummy hidden portion. So, even if it is discovered that there is a secret area on your USB key it will be almost impossible to break. Welcome to the Obscura USB swap.

Second, I’m going to explain how you can place a USB key into a spare phone jack in your wall. Not only will no one think to look there, but a special cable (that I’ll tell you how to construct out of an old USB cord and an old phone cord) are required to access the data. Afterward, you can encrypt it with the same level of encryption as your other drive making it obscure and secure.

Read more

A Public Apology to Boingo.

I previously wrote an article on a bug with Boingo. This article contained information I was sent by a third party.  I trusted the story of someone and wrote an article based on it. That information ended up being incorrect. No bug actually exists and Boingo does not broadcast user information in plain-text. The methods in that article were flawed and do not work.

Read more

Quick Tutorial: Installing Backtrack 4 Pre-Final (BT4) to a Dvd or USB key

Backtrack 4 BT4

This tutorial is a quick break down on how to install a bootable version of Backtrack 4 Pre-Final (BT4) to a USB key or DVD. It’s part of the Tutorial Series for Myfriendjosh.com. I plan on using Backtrack 4 for quite a few articles in the future. Instead of writing the installation procedures into every article, I will instead refer to the Tutorial Series in the future to cut down on redundancy. This article is in fact a re-hash of the previous article “Quick Tutorial: Installing Backtrack 4 Beta (BT4) to a Dvd or USB key”

What is Backtrack 4?

From Remote-Exploit.org, “BackTrack is the most top rated Linux live distribution focused on penetration testing. With no installation whatsoever, the analysis platform is started directly from the CD-ROM and is fully accessible within minutes.” Don’t let the name Linux scare you off though, it’s incredibly easy to use and very intuitive.

Read more

Reader Question: How do I turn on Wifi in Back Track 4?

First of all, I would like to thank my readers for their support. I have been receiving a decent amount of email about the site. We are averaging around 200 unique hits a day while also  been getting a lot of repeat visitors. For a new blog with only social media as advertising (Facebook, Twitter, Digg) this is great news! However, this is my first reader submitted question that warranted its own article and I hope it answers everything.

Reader X submitted: I can’t access the internet with wireless on Backtrack 4, how do I fix this?

Hit the jump for the answer.

No Wifi with Backtrack 4

Read more

Random Myfriendjosh.com Factoids

Here are a couple random interesting facts about MyFriendJosh.com I thought I would put together for anyone interested.

eating brains

Read more

Secrets of Google 411: Free 411, Free Payphone Calls to Businesses, Unlimited Long Distance Calling and More.

google411Directory Assistance, or as most of you know a $1.99 call to 411 or 555-1212. It’s a multi-million dollar industry based on catching people when they need a phone number in a hurry. Directory Assistance costs you anywhere from $0.50 to $2.99+  for a business listing. Even though all directory assistance  information is available for free online or from a phone-book they think the ‘convenience’ of a telephone based automated assistance is worth the price gouge.  Google is aiming to change the way you look at this service. They offer a 411 style business-listing-only service that you can access from any phone in North America for free! Google also gives you the ability to search by business category. If you need a bookstore but don’t know the name, Google will provide you with the top 8 listings. Google 411 also gives you the option to receive the business’s address. There are rumours that they will be expanding Google 411 Directory to home phones in the future, but not for right now.

In this article I will highlight how to use the Google 411 service. Enabling you to never have to pay for a 411 call again, how to get maps to businesses on the fly for free, how to use Google 411 to call any business (local or long distance) for free, How to use Google 411 from a payphone to call any business for free and save yourself the quarter, Lastly, I will show you how to add your (or your friends) personal phone number to the Google business directory allowing you or your friends to call each other for free from any phone in North America.
Read more