<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Aten Labs &#187; dan</title>
	<atom:link href="http://atenlabs.com/blog/tag/dan/feed/" rel="self" type="application/rss+xml" />
	<link>http://atenlabs.com/blog</link>
	<description>San Diego&#039;s Premier IT Security Consultancy</description>
	<lastBuildDate>Tue, 07 Feb 2012 19:48:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Post Toorcon Talk Sushi!</title>
		<link>http://atenlabs.com/blog/post-toorcon-talk-sushi/</link>
		<comments>http://atenlabs.com/blog/post-toorcon-talk-sushi/#comments</comments>
		<pubDate>Mon, 03 Oct 2011 18:39:16 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[2011]]></category>
		<category><![CDATA[dan]]></category>
		<category><![CDATA[lunch]]></category>
		<category><![CDATA[outing]]></category>
		<category><![CDATA[sushi]]></category>
		<category><![CDATA[talk]]></category>
		<category><![CDATA[tentler]]></category>
		<category><![CDATA[toorcon]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=204</guid>
		<description><![CDATA[If you know me at all, then you know I love sushi, and you know that I go on and on about this place in town called &#8216;Love Boat&#8217;. Well, there&#8217;s a convergence of people who love sushi, elements of Love Boat and hackers all happening at the same time. They moved my favorite chef [...]]]></description>
			<content:encoded><![CDATA[<p>If you know me at all, then you know I love sushi, and you know that I go on and on about this place in town called &#8216;Love Boat&#8217;. Well, there&#8217;s a convergence of people who love sushi, elements of Love Boat and hackers all happening at the same time.</p>
<ul>
<li>They moved my favorite chef and waitress to a different location (closer to the Toorcon venue)</li>
<li>My Toorcon talk is right before lunch on Sunday</li>
<li>I get special treatment at Love Boat because I have a reputation for bringing in a ton of people &#8211; this translates to &#8220;my party gets special treatment&#8221;.</li>
</ul>
<p>TL;DR &#8211; Come to sushi with me after my talk for Sundays lunch instead of some place in dirty old gaslamp.</p>
<p><a href="http://g.co/maps/4m82p">http://g.co/maps/4m82p</a> &#8211; Google map for Love Boat</p>
<p>Directions!<br />
<iframe src="http://maps.google.com/maps?f=d&amp;source=s_d&amp;saddr=E+Harbor+Dr&amp;daddr=32.77194,-117.16021+to:W+Fashion+Valley&amp;hl=en&amp;geocode=FcUT8wEdskEE-Q%3BFWQP9AEd7kYE-SnXQQ8gOlXZgDHgOkUwwOfSdg%3BFYAC9AEdMC0E-Q&amp;sll=32.706892,-117.157388&amp;sspn=0.030008,0.048709&amp;vpsrc=6&amp;mra=dme&amp;mrsp=0&amp;sz=15&amp;via=1&amp;ie=UTF8&amp;ll=32.706892,-117.157388&amp;spn=0.030008,0.048709&amp;t=m&amp;output=embed" frameborder="0" marginwidth="0" marginheight="0" scrolling="no" width="425" height="350"></iframe><br />
<small><a style="color: #0000ff; text-align: left;" href="http://maps.google.com/maps?f=d&amp;source=embed&amp;saddr=E+Harbor+Dr&amp;daddr=32.77194,-117.16021+to:W+Fashion+Valley&amp;hl=en&amp;geocode=FcUT8wEdskEE-Q%3BFWQP9AEd7kYE-SnXQQ8gOlXZgDHgOkUwwOfSdg%3BFYAC9AEdMC0E-Q&amp;sll=32.706892,-117.157388&amp;sspn=0.030008,0.048709&amp;vpsrc=6&amp;mra=dme&amp;mrsp=0&amp;sz=15&amp;via=1&amp;ie=UTF8&amp;ll=32.706892,-117.157388&amp;spn=0.030008,0.048709&amp;t=m">View Larger Map</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/post-toorcon-talk-sushi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>(almost) 90 days with the Motorola Xoom</title>
		<link>http://atenlabs.com/blog/almost-90-days-with-the-motorola-xoom/</link>
		<comments>http://atenlabs.com/blog/almost-90-days-with-the-motorola-xoom/#comments</comments>
		<pubDate>Tue, 17 May 2011 05:27:34 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[3.1]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[dan]]></category>
		<category><![CDATA[honeycomb]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[motorola]]></category>
		<category><![CDATA[oped]]></category>
		<category><![CDATA[overview]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[talbet]]></category>
		<category><![CDATA[tentler]]></category>
		<category><![CDATA[xoom]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=197</guid>
		<description><![CDATA[Just about three months ago I wrote a quick post about having the Motorola Xoom for approximately 12 hours. First I&#8217;d like to address some of the points I made in my last post: I can now control my AR.Parrot drone with my Xoom (ad-hoc wifi access points work now, with a small tweak) though [...]]]></description>
			<content:encoded><![CDATA[<p>Just about three months ago I wrote a quick post about having the Motorola Xoom for approximately 12 hours.</p>
<p><strong>First I&#8217;d like to address some of the points I made in my last post:</strong></p>
<ul>
<li><a href="https://market.android.com/search?q=ar+drone&amp;so=1&amp;c=apps" target="_blank">I can now control my AR.Parrot drone with my Xoom</a> (<a href="http://forum.xda-developers.com/showthread.php?t=1078447" target="_blank">ad-hoc wifi access points work now</a>, with a small tweak) though now I think that my drone has some physical damage to it, it doesn&#8217;t take off correctly. Must fix.</li>
<li>I&#8217;m able to get interesting widgets and buttons using <a href="https://market.android.com/details?id=de.devmil.minimaltext&amp;feature=search_result" target="_blank">minimalistic text</a> and <a href="https://market.android.com/details?id=com.jim2&amp;feature=search_result" target="_blank">widgetsoid</a></li>
<li>the <a href="https://market.android.com/details?id=ws.plattner.cifsmanager&amp;feature=search_result" target="_blank">cifs client</a> works like a champ, and I can stream everything I&#8217;d like, though the best player i&#8217;ve found (<a href="https://market.android.com/details?id=com.redirectin.rockplayer.android.unified.lite&amp;feature=search_result" target="_blank">rockplayer</a>) doesnt support mkv or certain types of divx.</li>
<li>There are ad-block apps, but I cant tell if they&#8217;re working or not.</li>
<li>Skype lags, still no video. Them being bought by MS is also likely not going to help things.</li>
</ul>
<p><strong>Now the TODO list:</strong></p>
<ul>
<li>I have both ubuntu and <a href="http://www.backtrack-linux.org/forums/backtrack-5-how-tos/40376-%5Bhow-%5D-backtrack-5-motorola-xoom-gnome-ui-via-tightvncserver.html" target="_blank">backtrack5 running on this thing</a> in chroots. While I now have access to tools like nmap, skipfish and other command line tools, some of the interesting ones (ettercap, aircrack) do not yet function due to lack of the proper kernel modules. I&#8217;ve contributed to the Tiamat kernel thread on the XDA forums asking if adding that kind of functionality was feasible.</li>
</ul>
<p>&nbsp;</p>
<p><strong>Verdict:</strong></p>
<p>Everywhere I go, I get asked &#8220;is that the new ipad?&#8221; and I answer &#8220;no, its better&#8221;. People look confused. I used to get into debates about it, but now I just dont care. I&#8217;ve accepted the fact that the vast majority of people prefer a snappy UI and pretty pictures over functionality and an open attitude. I&#8217;ve recently figured out how to get my eye-fi to work with the thing, and I&#8217;ve been out a few times while taking pictures and having them zip from my leica directly over the xoom (this is a REALLY cool party trick &#8211; I intend on utilizing this somehow combined with a projector at this years ninjapenguin party.).</p>
<p>This platform does everything I need that doesn&#8217;t require massive horsepower including simple security tasks &#8211; like portscanning and browsing open fileshares, nmapping, and running metasploit. I can watch movies on it, get directions (chrome to phone is awesome on this thing), watch full-screened high-res episodes of southpark from southparkstudios.com and other flash sites (since it supports flash) browse full HTML5 and flash websites, and even set it up like a mini entertainment set &#8211; with the jawbone jambox speakers setup as bluetooth speakers.</p>
<p>It&#8217;s overclocked from 1ghz to 1.6 ghz with little to no impact on the battery. The modified kernel allows me to have external SD storage enabled and PTP and USB OTG modes so that I can plug in external devices and storage (though I have not yet tried a mouse or keyboard, usb sticks and my leica d-lux 4 work like a champ &#8211; for some reason the d3s isn&#8217;t properly recognized, so <a href="http://www.google.com/support/forum/p/Google+Mobile/thread?fid=04c45ddea708fcdb0004a358ce65dead&amp;hl=en" target="_blank">I&#8217;ve opened a ticket with google</a>). I hope to use it in a photography sense as well (in Vegas this year, if I&#8217;m lucky) with the square reader and <a href="https://market.android.com/details?id=com.squareup&amp;feature=search_result" target="_blank">squareup app</a> &#8211; which lets me accept credit cards as an individual. I can torrent from the thing, as well as use it as a backup phone by way of a skype-in number and a bluetooth headset. The list just goes on and on!</p>
<p>I&#8217;ve been tapped to use it as a support tool &#8211; once at drinkup a friend had a need to use a variety of basic linux tools such as traceroute, ping and telnet &#8211; I was able to hand him my xoom in an ubuntu chroot and tell him &#8216;go to town&#8217;. I can use it to remote control any of my computers as well, even remotely &#8216;hamachi style&#8217; using a tool called neorouter.</p>
<p>I intend for this to be my &#8220;computer&#8221; while I&#8217;m at Defcon/Blackhat this year. I can easily offload all my photos to it, and it does everything I need while I&#8217;m on the go. Someday I hope to actually give a talk from this thing, completely without a laptop.</p>
<p><strong>tl;dr: If you just want a toy, buy an ipad. If you want a tool? Buy the xoom.</strong></p>
<p>&nbsp;</p>
<p><strong>Wishlist: </strong></p>
<ul>
<li>I still want a site survey tool. Especially <a href="http://forum.xda-developers.com/showthread.php?t=978013" target="_blank">overclocked past %50</a>. this thing screams.</li>
<li>Having the jambox speakers helps when I want other people to hear stuff, otherwise I want a case that has little &#8216;ears&#8217; to funnel the speakers forward.</li>
<li>Having backtrack5 on this thing is badass, but some of the more impressive stuff is unavailable &#8211; I cant send arp traffic and I cant put the wifi interface into monitor mode or inject traffic. I&#8217;ve asked about it on the <a href="http://forum.xda-developers.com/showpost.php?p=13866253&amp;postcount=2030" target="_blank">xda thread</a>.</li>
<li>I really wish someone would port VLC over to android. This hardware has so much still untapped potential &#8211; I want to be able to watch a 720p mkv. Standard dvd rips work fine, highres stuff chokes &#8211; because the players don&#8217;t leverage the GPU</li>
<li>I want to find out why the hell it doesn&#8217;t work with my Nikon D3s. It sees the camera, but never sees any photos. <a href="http://www.google.com/support/forum/p/Google+Mobile/thread?fid=04c45ddea708fcdb0004a358ce65dead&amp;hl=en" target="_blank">wtf?</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/almost-90-days-with-the-motorola-xoom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>12 hours with the motorola xoom</title>
		<link>http://atenlabs.com/blog/12-hours-with-the-motorola-xoom/</link>
		<comments>http://atenlabs.com/blog/12-hours-with-the-motorola-xoom/#comments</comments>
		<pubDate>Fri, 25 Feb 2011 08:23:02 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[dan]]></category>
		<category><![CDATA[first]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[impression]]></category>
		<category><![CDATA[impressions]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[motorola]]></category>
		<category><![CDATA[overview]]></category>
		<category><![CDATA[tab]]></category>
		<category><![CDATA[tablet]]></category>
		<category><![CDATA[tentler]]></category>
		<category><![CDATA[xoom]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=183</guid>
		<description><![CDATA[I was the first person in the door to pick up the new xoom at my local verizon retail store. They mentioned they only had 15, and I jokingly laughed asking &#8220;what the hell is this? no line out the door and around the building? dont people know whats going on?&#8221; I&#8217;ve been watching the [...]]]></description>
			<content:encoded><![CDATA[<p>I was the first person in the door to pick up the new xoom at my local verizon retail store. They mentioned they only had 15, and I jokingly laughed asking &#8220;what the hell is this? no line out the door and around the building? dont people know whats going on?&#8221;</p>
<p>I&#8217;ve been watching the xoom for a few months now, smiling, grimacing, laughing, complaining &#8211; as the rumors and news dribbled out.</p>
<p><strong>First Impressions from the first 12 hours:</strong></p>
<p><strong>PROS</strong></p>
<ul>
<li>its FAST. I mean FAST.</li>
<li>Angry birds goes very very fast. I presume I&#8217;ll be spending a lot of my bored-time screwing with it.</li>
<li>I&#8217;m now in something like a dozen concurrent games of words with friends.</li>
<li>The first thing I noticed was that it supports full-disk encryption. I turned that on right away.</li>
<li>The calendar app is awesome, very fluid and easy to use.</li>
<li>I can very nearly type two handed on the keyboard as if it were a regular computer keyboard. I&#8217;m certain this will improve with time, I&#8217;m making a ton of typos.</li>
<li>I can video-call my fiance in england from ANYWHERE using google voice chat. Its glorious and awesome. I propped the thing up between the shifter and the dash in my car to test it, and sitting in traffic it was high res and clear, high frame rate. We&#8217;re finally in the future &#8211; I can internationally video call from the car for free.</li>
<li>I love that in video-chat you can switch back and forth between the forward facing and the rear cameras. That right there will be EPIC for any instance where you need someone to show you something, and they want to see where the camera is pointing. Normally (like on laptops) this means having to point the screen away from you, so you&#8217;re filming but you can&#8217;t see what you&#8217;re filming.</li>
<li>There was a root howto up less than 6 hours after I bought it.</li>
<li>Using it as navigation in the car is BEAUTIFUL. That alone makes me want to build a mount for it so its held properly.</li>
<li>Using it as a giant touchpad for my windows/gaming box which is plugged into my 50&#8243; tv is GLORIOUS. It works as a giant touchpad (<a href="https://market.android.com/details?id=org.pierre.remotedroid.client&amp;feature=search_result" target="_blank">link</a>). I will be using this A LOT.</li>
<li>It supports multiple google accounts, allowing one to use personal and multiple &#8216;other&#8217; accounts at once. This is particularly useful for me as I&#8217;m a contractor/consultant and I often have to manage multiple accounts.</li>
<li>Its been said this thing will support usb host mode, meaning I should be able to plug</li>
<li>One chief complaint I&#8217;ve read was that apps that were &#8216;made for phones&#8217; look &#8216;stretched and bad&#8217;. Well, the ones I use actually look BETTER. Like wifi analyzer, tweetdeck and antennas. GPS test plus looks RAD!</li>
<li>Another complaint people had were that the speakers faced back &#8211; I just hold it cupping the speakers and it channels the sound towards me. I&#8217;m half tempted to make a couple little &#8216;ears&#8217; for the thing out of hard plastic that channel the sound forward, and double as an angular stand. Maybe one whole thing that does that plus has a kickstand (HINT HINT PEOPLE WHO HAVE MANUFACTURING CONTRACTS)</li>
<li>I feel a lot less constrained &#8211; I imagine my phone now will not need to be checking twitter/email/gtalk/etc and I&#8217;ll be doing that on the xoom, so my phones battery should last longer.</li>
</ul>
<p><strong>CONS</strong></p>
<ul>
<li><del>It cant see my jawbone jambox for some reason. It can see my laptop and my phone, but not the bluetooth speakers (!?!?! no idea. I&#8217;ll wait until I get my ubertooth zero to find out wtf.) </del> No Idea what I did differently this time, I got it working. *shrug* &#8211; sounds badass too <img src='http://atenlabs.com/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </li>
<li>I can&#8217;t control my parrot ar.drone with it (yet) because I need to find a hack allowing the xoom to associate to ad-hoc networks &#8211; though theres another way around this by making the ar.drone associate to an infrastructure AP</li>
<li>Skype doesnt support video calls (yet)</li>
<li>I really like the HTC clock on my incredible. I want it on the tablet!</li>
<li>Now that its rooted, I want to stream movies from my drobo &#8211; I can do that on my phone by using cifsmanager, which drops a kernel module in enabling cifs client support &#8211; so apps simply think theyre pulling from local storage. After installing it, the xoom said &#8216;this application isn&#8217;t installed&#8217; when I tried to run it. Weird.</li>
<li>I cant shake the feeling that I absolutely need to find a way to block the in-app ads. Even on a tablet, they take up a lot of real estate.</li>
</ul>
<p><strong>TODO</strong></p>
<ul>
<li>Try to get nmap running</li>
<li>Try to install debdroid, see what happens</li>
<li>Look into seeing what it would take to get pyrit or the aircrack suite running on this thing</li>
<li>I WANT DRIFTNET FOR THIS PLATFORM \o/</li>
<li>I want to setup ettercap + sslstrip + daemonlogger on this platform</li>
<li>I want to see a REAL site survey tool for this platform, like visiwave. That would be EPIC. I&#8217;d buy that in a heartbeat.</li>
<li>A good &#8216;dual pane&#8217; (like email) google reader app</li>
<li>Need to see if I can turn it into a remote display for my mac or another computer.</li>
</ul>
<p>More to come as I learn!</p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/12-hours-with-the-motorola-xoom/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Kinesics Training / Peoplehacking Class</title>
		<link>http://atenlabs.com/blog/kinesics-training-peoplehacking-class/</link>
		<comments>http://atenlabs.com/blog/kinesics-training-peoplehacking-class/#comments</comments>
		<pubDate>Mon, 24 Jan 2011 03:07:58 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[training]]></category>
		<category><![CDATA[class]]></category>
		<category><![CDATA[dan]]></category>
		<category><![CDATA[kinesics]]></category>
		<category><![CDATA[peoplehacking]]></category>
		<category><![CDATA[tentler]]></category>
		<category><![CDATA[viss]]></category>
		<category><![CDATA[vissago]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=178</guid>
		<description><![CDATA[For the last several barcamps, and the last two toorcons I&#8217;ve been presenting to large and small groups about the neat things that can be done with kinesics. I keep all the historic material (yes, including that spreadsheet) HERE. I&#8217;ve found an organization out of San Francisco that does kinesics training, and based on all [...]]]></description>
			<content:encoded><![CDATA[<p>For the last several barcamps, and the last two toorcons I&#8217;ve been presenting to large and small groups about the neat things that can be done with kinesics. I keep all the historic material (yes, including that spreadsheet) <a href="http://www.atenlabs.com/peoplehacking" target="_blank">HERE</a>.</p>
<p>I&#8217;ve found an organization out of San Francisco that does kinesics training, and based on all the feedback I&#8217;ve gotten from doing my talks over the last few years &#8211; people really dig this stuff. I thought it would be cool to have the pros come down and drop some knowledge on us all.</p>
<p>I&#8217;ve managed to arrange a training scenario with <a href="http://www.humintell.com">Humintell</a> &#8211; 4 hours of clasroom training for $250 per person. We need at least 20 people to nail everything down so they&#8217;ll come see us down here in San Diego. Currently I have 13 people who have expressed interest in the class.</p>
<p>The idea is that I&#8217;ll arrange for the location (going to aim for Intuit, where we do barcamp) and the interested people, and they come to the location to do a 4 hour talk/workshop on a Saturday.</p>
<p>If this sounds in any way interesting, please <a href="mailto:dan@atenlabs.com">email me</a> or leave a comment! We&#8217;re getting really close to the target figure!</p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/kinesics-training-peoplehacking-class/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Android Phone = rogue access point!</title>
		<link>http://atenlabs.com/blog/android-phone-rogue-access-point/</link>
		<comments>http://atenlabs.com/blog/android-phone-rogue-access-point/#comments</comments>
		<pubDate>Thu, 22 Jul 2010 08:45:43 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[training]]></category>
		<category><![CDATA[802.11]]></category>
		<category><![CDATA[802.11a]]></category>
		<category><![CDATA[802.11b/g]]></category>
		<category><![CDATA[802.11n]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[auditing]]></category>
		<category><![CDATA[dan]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[incredible]]></category>
		<category><![CDATA[pen]]></category>
		<category><![CDATA[penetration]]></category>
		<category><![CDATA[point]]></category>
		<category><![CDATA[rogue]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[tentler]]></category>
		<category><![CDATA[test]]></category>
		<category><![CDATA[testing]]></category>
		<category><![CDATA[viss]]></category>
		<category><![CDATA[vissago htc]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=167</guid>
		<description><![CDATA[So when I get a new phone, I immediately want to try to get as much access on it as possible (read: root it). Custom roms are wonderful, but in the case of the HTC Incredible I don&#8217;t think there are custom roms (yet). After I rooted my HTC Incredible I started doing searches in [...]]]></description>
			<content:encoded><![CDATA[<p>So when I get a new phone, I immediately want to try to get as much access on it as possible (read: root it). Custom roms are wonderful, but in the case of the HTC Incredible I don&#8217;t think there are custom roms (yet).</p>
<p>After I rooted my HTC Incredible I started doing searches in the market for interesting things. I found some neat wireless utilities, I found a file manager that lets you browse SMB fileshares on the lan (NEAT.), I found a packetsniffer, and some more interesting tools.</p>
<p>The light came on over my head when I realized &#8220;Wait, a packet sniffer AND a wireless access point? .. can .. I sniff.. the wifi with this?!&#8221;. As it turns out the answer is yes &#8211; it takes some fenagling, and if you do it in the wrong order one application stomps the other (I&#8217;ve already written the author of the packet capture application about this but have not gotten a response yet).</p>
<p>Here is a quick walkthrough on how to turn an HTC Incredible into a rogue wireless access point:</p>
<ol>
<li>Root the phone. This can be done by visiting <a href="http://unrevoked.com/recovery/" target="_blank">http://unrevoked.com/recovery/</a>, downloading the app, and running it.</li>
<li>Once the phone is rooted, go to the market, and install the wifi tether application: Be aware though, that with the HTC incredible there are additional steps to get this application to work (see their wiki page: <a href="http://code.google.com/p/android-wifi-tether/" target="_blank">http://code.google.com/p/android-wifi-tether/</a>)
<p style="text-align: center;"><a href="http://atenlabs.com/blog/wp-content/uploads/2010/07/wifi-tether.png"><img class="aligncenter size-medium wp-image-169" title="wifi-tether" src="http://atenlabs.com/blog/wp-content/uploads/2010/07/wifi-tether-180x300.png" alt="" width="180" height="300" /></a></p>
</li>
<li>Install the packet capture application. This also will need additional steps after the installation. (<a href="http://sites.google.com/site/androidarts/packet-sniffer" target="_blank">http://sites.google.com/site/androidarts/packet-sniffer</a>)</li>
<li>Once you have the packet sniffer installed, configure it to log to a file instead of a sql database. I wasn&#8217;t able to find the actual database this thing logs to, but the text file appears right at the root of the sdcard. It looks just like the &#8216;live&#8217; output though, which I don&#8217;t think is a proper format. It doesn&#8217;t log raw traffic at all.</li>
<li>Don&#8217;t start the sniffer or wifi tether yet &#8211; they must be configured beforehand.</li>
<li>Go back to wifi-tether and configure the SSID. Name it something which will attract people in search of free wifi. Linksys. Dlink. Netgear. 2WIRE858. The SSID of a target network, perhaps. Again, do not turn on tethering here yet.</li>
<li>Open up the packet sniffer again, and go to the &#8216;wifi capture&#8217; section, then enable the capture, and if you&#8217;d like, enable logging packets to the screen.</li>
<li>Hit the phones &#8216;home&#8217; button to exit without stopping the packet capture tool, and re-open the wifi tethering tool. Once in the tethering tool, enable tethering.</li>
<li>Hit home again, and go re open the packet capture tool. If anybody connects, wifi tether will tell you in the status bar at the top of the display, and you will start seeing arp traffic and dhcp traffic scroll in the live feed window as you would with any other packet sniffer.<br />
<a href="http://atenlabs.com/blog/wp-content/uploads/2010/07/capture1.png"><img class="aligncenter size-medium wp-image-168" title="capture1" src="http://atenlabs.com/blog/wp-content/uploads/2010/07/capture1-180x300.png" alt="" width="180" height="300" /></a></li>
</ol>
<p>There are several caveats to this though:</p>
<ol>
<li>This tool appears to not capture raw packets. You can do this from a terminal using TCPdump if you feel so inclined &#8211; the packet capture tool installation instructions have you install a new version of tcpdump. You should be able to use this to capture raw traffic and not just clear text</li>
<li>Packet capture has to be running before wifi tether &#8211; if you try to do it the other way around wifi tether will hang and you&#8217;ll have to kill it.</li>
<li>This will also capture all the traffic from your phone to the internet, so if you&#8217;re trying to do a bunch of stuff on your phone while running a rogue access point, it will  muddy your results.</li>
</ol>
<p>This has been a fairly simple howto &#8211; you creative types will easily be able to find more interesting things to do with this.</p>
<p>My wishlist after figuring this out? &#8211; An app that acts like airodump &#8211; I want to see clients probing for networks so that I can &#8220;give them what they want&#8221;. I also want this packet capture tool to log raw data, not just plaintext stuff.  Now that this is possible, I wish for tools like drifnet, dsniff, and others of that sort to become available on the android platform. The objective here would be to use this during a pen test as a tool to capture data, then bring it back to the labs for analysis.</p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/android-phone-rogue-access-point/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to steal Facebook Authentication cookies</title>
		<link>http://atenlabs.com/blog/how-to-steal-facebook-authentication-cookies/</link>
		<comments>http://atenlabs.com/blog/how-to-steal-facebook-authentication-cookies/#comments</comments>
		<pubDate>Thu, 17 Jun 2010 00:09:51 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[dan]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hijacking]]></category>
		<category><![CDATA[how]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[lennox]]></category>
		<category><![CDATA[mrb0t]]></category>
		<category><![CDATA[nick]]></category>
		<category><![CDATA[penetration]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[session]]></category>
		<category><![CDATA[stealing]]></category>
		<category><![CDATA[tentler]]></category>
		<category><![CDATA[testing]]></category>
		<category><![CDATA[to]]></category>
		<category><![CDATA[viss]]></category>
		<category><![CDATA[vissago]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=136</guid>
		<description><![CDATA[How to hack a facebook account &#8211; or, basically how to hijack php sessions. Yes &#8211; this is old news &#8211; yes its a common vulnerability &#8211; but you get a better idea for what it is and how it works when things are explained in detail (with screenshots!). Before we begin, however, I want [...]]]></description>
			<content:encoded><![CDATA[<p>How to hack a facebook account &#8211; or, basically how to hijack php sessions. Yes &#8211; this is old news &#8211; yes its a common vulnerability &#8211; but you get a better idea for what it is and how it works when things are explained in detail (with screenshots!).</p>
<p>Before we begin, however, I want to re-emphasize that it is <strong>VERY EASY</strong> to protect yourself against this sort of attack. Facebook supports HTTPS, so when you browse facebook (or twitter for that matter) or if you have it bookmarked &#8211; please make sure you&#8217;re using <strong>HTTPS://</strong> rather than <strong>HTTP://</strong> in the URL at the very least, if not using a <a href="http://atenlabs.com/zipline">VPN solution</a> for further encryption. Also, if the &#8216;victim&#8217; logs out of facebook, the attackers session becomes invalid &#8211; so it&#8217;s a good practice to actually log out of facebook and log back in again rather than using the &#8216;remember me&#8217; checkbox.</p>
<p>Facebook like many sites operates using authentication cookies. Their auth cookies contain a variety of information, but for our purposes this is irrelevant. Here is a sanitized cookie for reference:</p>
<p><code>Cookie: datr=1276721606-b7f94f977295759399293c5b0767618dc02111ede159a827030fc; lsd=Xesut; lxe=greg.evans%40****************; c_user=100001230367821; lo=wl9fcGXMhPfoT4bAhKFP3Q; lxs=1; sct=1276721745; xs=a615cfe596448194d6e2a8d062a90e4e</code></p>
<p>You can see the &#8216;lxe&#8217; field is the login. We haven&#8217;t done any further research into what the various other fields mean, but using facebook without any kind of security you&#8217;re both leaking the email address used for your login and the session cookie.</p>
<p>First thing you&#8217;ll want to do is fire up your favorite packet capture application. For this example we&#8217;ve used Wireshark:</p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/06/wireshark1.jpg"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/wireshark1-300x180.jpg" alt="" title="wireshark1" width="300" height="180" class="aligncenter size-medium wp-image-151" /></a></p>
<p>Next, set the filter in the top left to &#8221; <strong>http.cookie contains &#8220;datr&#8221;</strong> &#8220;. This should show you only packets captured which contain the cookie we&#8217;re looking for. You can see that in this screenshot we&#8217;ve already captured a cookie.</p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/06/wireshark2.jpg"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/wireshark2-300x140.jpg" alt="" title="wireshark2" width="300" height="140" class="aligncenter size-medium wp-image-150" /></a></p>
<p>Once you&#8217;ve found a suitable cookie, you can copy it into the buffer by right clicking on the cookie line, and clicking Copy -> Bytes (Printable Text Only)<br />
<a href="http://atenlabs.com/blog/wp-content/uploads/2010/06/wireshark3.jpg"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/wireshark3-300x139.jpg" alt="" title="wireshark3" width="300" height="139" class="aligncenter size-medium wp-image-149" /></a></p>
<p>Next you&#8217;ll want to open up firefox. You&#8217;ll need both <a href="https://addons.mozilla.org/en-US/firefox/addon/748/">greasemonkey</a> and the <a href="http://dustint.com/archives/12">cookieinjector script</a>.</p>
<p>Simply browse to facebook &#8211; make sure you are not logged in:</p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox.jpg"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox-300x175.jpg" alt="" title="firefox" width="300" height="175" class="aligncenter size-medium wp-image-156" /></a></p>
<p>Hit ALT-C to bring up the cookie injector dialog box:</p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox2.jpg"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox2-300x175.jpg" alt="" title="firefox2" width="300" height="175" class="aligncenter size-medium wp-image-155" /></a></p>
<p>Then paste in the cookie!</p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox3.jpg"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox3-300x175.jpg" alt="" title="firefox3" width="300" height="175" class="aligncenter size-medium wp-image-154" /></a></p>
<p>Hit refresh and &#8211; VIOLA! you&#8217;re now logged in as your victim! Now this doesn&#8217;t give you access to their credentials, this is about the equivalent to walking up to their workstation while they&#8217;re away from their desk and using facebook. </p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox4.jpg"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox4-300x175.jpg" alt="" title="firefox4" width="300" height="175" class="aligncenter size-medium wp-image-153" /></a></p>
<p>Neat huh? Pretty easy too. I smiled big when we demo&#8217;ed the attack in our lab &#8211; its old, sure, but being successful is always a good feeling!</p>
<p><em>P.S: This isnt REALLY Gregory Evans account. We setup this account because .. well.. the name was available! We thought it was in good taste as the No #1 hacker&#8217;s twitter feed got hacked the other day, <a href="http://attrition.org/errata/charlatan/gregory_evans/ligatt06/">his site is riddled with XSS exploits</a>, and his book is copypasta from a variety of certification exam prep books. Thanks to <a href="http://whoneedscrypto.ordonomicon.net/">Nick</a> and <a href="http://blog.skeptikal.org/">mckt</a> for the work and tootilage, respectively. No noobs were harmed in the making of this film.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/how-to-steal-facebook-authentication-cookies/feed/</wfw:commentRss>
		<slash:comments>29</slash:comments>
		</item>
		<item>
		<title>Adding context</title>
		<link>http://atenlabs.com/blog/adding-context/</link>
		<comments>http://atenlabs.com/blog/adding-context/#comments</comments>
		<pubDate>Sun, 06 Jun 2010 23:24:25 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[dan]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[ligatt]]></category>
		<category><![CDATA[poor security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[tentler]]></category>
		<category><![CDATA[tsk tsk]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=120</guid>
		<description><![CDATA[However good or bad you think you are at security, this may put a few details into perspective for you: In the last few weeks Ligatt Security has been &#8220;making headlines&#8221; with their 90&#8242;s-esque hackers-style commercials and advertisements &#8211; the three most notable of which advertise that large black men, 12 year old boys, and [...]]]></description>
			<content:encoded><![CDATA[<p>However good or bad you think you are at security, this may put a few details into perspective for you:</p>
<p>In the last few weeks <a href="http://www.ligattsecurity.com/">Ligatt Security</a> has been &#8220;making headlines&#8221; with their 90&#8242;s-esque hackers-style commercials and advertisements &#8211; the three most notable of which advertise that large black men, 12 year old boys, and &#8220;hackers&#8221; with what appear to be ethernet-enabled projectorgoggles are &#8220;out to get you&#8221;. Their fear-based marketing campaign slants the average computer users security experience using the standard &#8220;if you don&#8217;t hire us, your life is pretty much over&#8221; routine.</p>
<p>It&#8217;s a pretty huge bag of fail &#8211; I really hope this is a learning experience for them. One of the more important &#8216;scout badges&#8217; I&#8217;ve earned in my time as a contractor so far is &#8220;practice what you preach&#8221;. A &#8220;large&#8221;, publicly traded &#8220;information security company&#8221; probably should have taken the time to do some <a href="http://en.wikipedia.org/wiki/Cross-site_scripting"><strong><em>BASIC SECURITY</strong></em></a> on their own website &#8211; <a href="http://tinyurl.com/2cxv2d8">CLICKY!</a></p>
<p><a href="http://tinyurl.com/2cxv2d8"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/Screen-shot-2010-06-06-at-4.05.54-PM-300x244.png" alt="virtually lol-inducing. wow, i actually typed that." title="Ligatt Security isnt very secure" width="300" height="244" class="aligncenter size-medium wp-image-122" /><br />
</a><br />
<strong><em>EDIT</em>: After a couple of twitter posts about this they&#8217;ve firewalled me off of the host. Firewalling one guy isn&#8217;t gonna help guys, I&#8217;m certain I&#8217;m not the only person to have found a CORNUCOPIA of publicly available vulnerabilities on your site.<em></p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/adding-context/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Language and Security</title>
		<link>http://atenlabs.com/blog/language-and-security/</link>
		<comments>http://atenlabs.com/blog/language-and-security/#comments</comments>
		<pubDate>Wed, 19 May 2010 21:40:26 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[training]]></category>
		<category><![CDATA[brown]]></category>
		<category><![CDATA[dan]]></category>
		<category><![CDATA[derren]]></category>
		<category><![CDATA[examples]]></category>
		<category><![CDATA[hypnosis]]></category>
		<category><![CDATA[hypnotism]]></category>
		<category><![CDATA[language]]></category>
		<category><![CDATA[neuro linguistic programming]]></category>
		<category><![CDATA[nlp]]></category>
		<category><![CDATA[tentler]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[videos]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=108</guid>
		<description><![CDATA[Every time I mention using language in security folks assume I&#8217;m talking about social engineering. Social engineering has historically been things like calling the front desk of an organization claiming that you&#8217;re, say, a new fedex delivery driver and you need to be let into their shipping/receiving department, so you ask who you need to [...]]]></description>
			<content:encoded><![CDATA[<p>Every time I mention using language in security folks assume I&#8217;m talking about social engineering. Social engineering has historically been things like calling the front desk of an organization claiming that you&#8217;re, say, a new fedex delivery driver and you need to be let into their shipping/receiving department, so you ask who you need to talk to for that to happen.</p>
<p>Language can be used for a lot more than simply convincing a part time employee to let you have more access than you should somewhere &#8211; Language can be used to full on exploit &#8220;memory corruption&#8221; in the mind. The use of the right language is powerful enough to overwrite peoples memories if even temporarily. </p>
<p>Below I&#8217;ve linked some information pertinent to the techniques employed when language is the tool used to achieve things like memory corruption, buffer overflows, execution of arbitrary code &#8211; except on people. In particular, pay attention to the cognitive biases &#8211; see if you think any of them apply to you <img src='http://atenlabs.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Then combine the cognitive biases with things like NLP anchoring and subliminal suggestion and you quickly end up with a recipe for gaining someones trust, convincing them to give you access somewhere or to something, or telling you secrets &#8211; all without having to don a fedex uniform and pretend you&#8217;re someone else. You can even have someone give you their phone and car keys &#8211; willingly.</p>
<p>Language is a very very powerful tool and put in the hands of information security professionals (or attackers) it becomes even more weaponized. </p>
<p>Apologies for the videos that wont embed &#8211; if you click through you can view them on their youtube page.</p>
<p><center><br />
<a style="margin: 12px auto 6px auto; font-family: Helvetica,Arial,Sans-serif; font-style: normal; font-variant: normal; font-weight: normal; font-size: 14px; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none; display: block; text-decoration: underline;" title="View Cognitive Biases - A Visual Study Guide by the Royal Society of Account Planning on Scribd" href="http://www.scribd.com/doc/30548590/Cognitive-Biases-A-Visual-Study-Guide-by-the-Royal-Society-of-Account-Planning">Cognitive Biases &#8211; A Visual Study Guide by the Royal Society of Account Planning</a> <object id="doc_176870327813558" style="outline: none;" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="100%" height="600" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="name" value="doc_176870327813558" /><param name="data" value="http://d1.scribdassets.com/ScribdViewer.swf" /><param name="wmode" value="opaque" /><param name="bgcolor" value="#ffffff" /><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="FlashVars" value="document_id=30548590&amp;access_key=key-16z0xj5qe5jejhknehs9&amp;page=1&amp;viewMode=slideshow" /><param name="src" value="http://d1.scribdassets.com/ScribdViewer.swf" /><param name="allowfullscreen" value="true" /><param name="flashvars" value="document_id=30548590&amp;access_key=key-16z0xj5qe5jejhknehs9&amp;page=1&amp;viewMode=slideshow" /><embed id="doc_176870327813558" style="outline: none;" type="application/x-shockwave-flash" width="100%" height="600" src="http://d1.scribdassets.com/ScribdViewer.swf" flashvars="document_id=30548590&amp;access_key=key-16z0xj5qe5jejhknehs9&amp;page=1&amp;viewMode=slideshow" allowscriptaccess="always" allowfullscreen="true" bgcolor="#ffffff" wmode="opaque" data="http://d1.scribdassets.com/ScribdViewer.swf" name="doc_176870327813558"></embed></object></p>
<p><object width="500" height="300" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/J67ykNNelt8&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="500" height="300" src="http://www.youtube.com/v/J67ykNNelt8&amp;hl=en_US&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="500" height="300" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/YGnYvUCIeJk&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="500" height="300" src="http://www.youtube.com/v/YGnYvUCIeJk&amp;hl=en_US&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p><object width="500" height="300"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/watch?v=3Vz_YTNLn6w" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="500" height="300" src="http://www.youtube.com/v/3Vz_YTNLn6w&amp;hl=en_US&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p><object width="500" height="300"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/watch?v=7tCfGfUUe2g" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="500" height="300" src="http://www.youtube.com/v/7tCfGfUUe2g&amp;hl=en_US&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p><object width="500" height="300"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/watch?v=f-TURhK90_8" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="500" height="300" src="http://www.youtube.com/v/f-TURhK90_8&amp;hl=en_US&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object><br />
</center></p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/language-and-security/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Hacking someones personal brand</title>
		<link>http://atenlabs.com/blog/hacking-someones-personal-brand/</link>
		<comments>http://atenlabs.com/blog/hacking-someones-personal-brand/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 20:53:21 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[branding]]></category>
		<category><![CDATA[dan]]></category>
		<category><![CDATA[daniel]]></category>
		<category><![CDATA[dave]]></category>
		<category><![CDATA[david]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[kaiser]]></category>
		<category><![CDATA[personal]]></category>
		<category><![CDATA[rog]]></category>
		<category><![CDATA[roger]]></category>
		<category><![CDATA[rustad]]></category>
		<category><![CDATA[tentler]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=75</guid>
		<description><![CDATA[I know two trolls. Roger Rustad, and David Kaiser &#8211; they run socallinux.org. If you read anything these two post on socallinux.org you can quickly determine they use this mailing list to defame whomever they choose &#8211; and because their mailing list gets both spidered by google, and mirrored by list-serv they get pretty much [...]]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter size-full wp-image-76" title="Troll definition" src="http://atenlabs.com/blog/wp-content/uploads/2009/12/Screen-shot-2009-12-10-at-12.27.07-PM.png" alt="Troll definition" width="473" height="111" />I know two trolls. Roger Rustad, and David Kaiser &#8211; they run socallinux.org.</p>
<p>If you read anything these two post on socallinux.org you can quickly determine they use this mailing list to defame whomever they choose &#8211; and because their mailing list gets both spidered by google, and mirrored by list-serv they get pretty much automatic SEO. Multiple domain names replicating messages. And if the mailing list gets any activity for any reason the SEO goes up.</p>
<p>This is like a troll sniper rifle. You want someone to go down in flames, or you just want to make them real miserable? Talk smack about them somewhere that gets spidered by google and replicated to other sites. If anyone googles them, they&#8217;ll find listserv messages, mail-archive.com and google cache results all parroting the original messages.</p>
<p>Google is like the force. It can be used for good and evil. In this example, we&#8217;re looking at using it for evil.</p>
<p><span id="more-75"></span></p>
<p>I never really took personal branding seriously until it bit me &#8211; and upon this realization immediately found a pretty blatant &#8216;vulnerability&#8217;. Well, it&#8217;s not REALLY a vulnerability, it preys on peoples inclination to believe what they read as fact and not take any time to check up on it &#8211; so it&#8217;s more like a social hack, or social engineering. This presents an attack vector that historically could only be used by larger media outlets.</p>
<p>Now, we have google, and google cache &#8211; these tools can be used to make someone miserable for a long period of time, or sway peoples opinion on things &#8211; or to make people believe whatever you choose.</p>
<p>Google your name. Seriously &#8211; open a new tab and type your name into google &#8211; see what comes up. Go at least 3-5 pages deep.</p>
<p>Is there anything in there that would prevent a company from hiring you, or a new client from signing a contract with you?</p>
<p>There isnt? &#8211; well thats a good sign!</p>
<p>What if I started writing emails on a tiny, but public email list (like listserv, or google groups), or wrote a few blog posts talking about how evil you were, and some evil things you&#8217;ve done &#8211; even if you&#8217;d done no such evil? That might not fare so well for you the next time someone does their homework on you.</p>
<p><em>&#8220;But thats libel&#8221; </em>you say. True, that is in fact libel. People lying about you in print.</p>
<p><em>&#8220;You can sue for that!&#8221;</em> Yep &#8211; you can! It&#8217;ll cost you, probably in excess of 5 or 10 grand and you&#8217;ll end up with a court order to the defendants issuing them to take down whatever needed to be taken down (Unless you sue for damages &#8211; for example if you can prove that clients walked away from you and companies won&#8217;t hire you because they found this stuff on google).</p>
<p><em>&#8220;Wow thats a headache&#8221;</em> It absolutely is.</p>
<p>The bottom line is unless you&#8217;re prepared to throw 5-10 thousand dollars at the problem you won&#8217;t be able to do much other than ask nicely, and if asking nicely doesn&#8217;t get the job done you&#8217;re sorta boned. If you do have the money though, libel is libel &#8211; and if you can prove in court its libel, you win. Period.</p>
<p>So in summation: Using google to attack people, hurt brand names and generally troll has a VERY high success rate &#8211; but  you&#8217;re liable to get sued.</p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/hacking-someones-personal-brand/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

