<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DigitalFiz &#187; Security</title>
	<atom:link href="http://digitalfiz.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://digitalfiz.com</link>
	<description>php is my kungfu...</description>
	<lastBuildDate>Mon, 30 Aug 2010 01:37:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Lets go phishing!</title>
		<link>http://digitalfiz.com/2009/11/lets-go-phishing/</link>
		<comments>http://digitalfiz.com/2009/11/lets-go-phishing/#comments</comments>
		<pubDate>Sat, 28 Nov 2009 02:16:27 +0000</pubDate>
		<dc:creator>DigitalFiz</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.digitalfiz.com/?p=81</guid>
		<description><![CDATA[I want to show everyone how easy it is to be faked into giving your information away to a phishing site. To do so I will fake the secondlife login page since its most relevant to recent events. I will give the link after I explain a few things. First off to play with it don&#8217;t put [...]]]></description>
			<content:encoded><![CDATA[<p>I want to show everyone how easy it is to be faked into giving your information away to a phishing site. To do so I will fake the secondlife login page since its most relevant to recent events. I will give the link after I explain a few things. First off to play with it don&#8217;t put your real SecondLife login information in please. I wont be logging information or collecting logins but I don&#8217;t expect or want you to trust me on that. This page I will post is what I call a transparent phish. It will take your login information and forward it directly to secondlife and put you on the proper page as if you logged in for real and you wont even know the information was stolen. This page took me all of 30 seconds to make so you should know its easy for hackers to make these pages to get your information. <span id="more-81"></span></p>
<p><a href="http://www.digitalfiz.com/hax/secondlife.php" onclick="pageTracker._trackPageview('/outgoing/www.digitalfiz.com/hax/secondlife.php?referer=');">http://www.digitalfiz.com/hax/secondlife.php</a></p>
<p>Now normally a phisher would setup sub domains so you would see something like https://secure.secondlife.com.phishingsite.com/login.php or something similar to fool people who pay a little more attention. If you went to that site and tried to login you should have seen the page that told you when the information was stolen. Again I didnt log any information you may have put in that fake login page but I would hope you didnt use your real information anyways.</p>
<p>The best most secure way to make sure you never fall victim to a phishing site is to go to the site directly. Like if your logging into secondlife go to secondlife.com and login then try the page you clicked on again. If its the correct and safe site it will notice you logged in elsewere and redirect accordingly. You should NEVER EVER put your information into a page that comes up from a link given to you by anyone or anything. It is easy to spoof urls in emails and messengers and make you think its the right site when its not. Also you can check the sites security certificate to validate that its actually secondlife or whatever place your trying to login to. Like if you go to https://secure-web20.secondlife.com/my/account/login.php you should see a lock either in the bottom right corner or up but the url bar you can click on to see the security certificate and who it belongs to. Also make sure that the url in the url bar starts with https:// if it doesn&#8217;t then its more then likely a fake site. I don&#8217; know many sites anymore that dont make you login via a secure connection.</p>
<p>One thing I would like to point out about friendships and security. You have to remember that just because a link in an email or messenger or any other type of message from a friend ISN&#8217;T safe. You always have to think &#8220;what if they have been hacked already&#8221; because thats how these things spread. People think oh its from johnny he is my best friend its safe and BAM they are a victim too and it spreads like wild fire. Thats why I said never login to pages you clicked from anyone or anything. Always ALWAYS go to the site directly and login first. I would also suggest reading my older post about <a href="http://www.digitalfiz.com/2008/12/lazy-passwords/" onclick="pageTracker._trackPageview('/outgoing/www.digitalfiz.com/2008/12/lazy-passwords/?referer=');">lazy passwords </a>to learn more about sand boxing incidents and protecting yourself from to much damage. I wrote something on <a href="http://www.digitalfiz.com/2008/12/check-the-friggin-url-before-you-login/" onclick="pageTracker._trackPageview('/outgoing/www.digitalfiz.com/2008/12/check-the-friggin-url-before-you-login/?referer=');">checking the URL</a> awhile back too I would recommend reading its a long the same lines as this.</p>
]]></content:encoded>
			<wfw:commentRss>http://digitalfiz.com/2009/11/lets-go-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lazy passwords</title>
		<link>http://digitalfiz.com/2008/12/lazy-passwords/</link>
		<comments>http://digitalfiz.com/2008/12/lazy-passwords/#comments</comments>
		<pubDate>Wed, 10 Dec 2008 23:43:49 +0000</pubDate>
		<dc:creator>DigitalFiz</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.digitalfiz.com/?p=76</guid>
		<description><![CDATA[I decided to write this because of the recent event of Stickam being hacked and everyones information being compromised. It is a very good example of how safe your information is on a social network. I am not going to be one of those people that says passwords should be 20 letters and numbers long [...]]]></description>
			<content:encoded><![CDATA[<p>I decided to write this because of the recent event of <a title="STICKAM HACKED!" href="http://digitalfiz.com/2007/12/08/stickam-hacked/">Stickam being hacked</a> and everyones information being compromised. It is a very good example of how safe your information is on a social network. I am not going to be one of those people that says passwords should be 20 letters and numbers long with upper and lower case, while it is better and more secure the longer your password is. <span id="more-76"></span>Instead we will talk about using the same password for multiple places. Because in all reality even if your password is the most secure password on the net if you use it everywhere and someone hacks stickam or myspace the length and complication of your password does you no good and that hacker now has your password WHICH you use on every place you have one on. I think that even the laziest users should split there passwords up into a few groups or levels.</p>
<blockquote><p><strong>Group 1</strong> &#8211; would be for financial sites. This is your most important information and should be separate from anything else you do. In all reality you should have a different password for each financial site you are on. But if your a lazy user separating financial sites should be good enough.</p></blockquote>
<blockquote><p><strong>Group 2</strong> &#8211; this group would be for social networks. Since social networks get hacked a lot and people often fall victim to phishing pages/emails it is a good idea to keep the password for those separate. These are probably the most dangeous places because they are so insecure. Now again it is still good practice to keep a different password for every place you go to keep things the most secure.</p></blockquote>
<blockquote><p><strong>Group 3</strong> &#8211; Pretty much everyplace else. After the previous 2 groups all other sites are up to your discretion those are just the 2 main ones.</p></blockquote>
<p>Now remember that I am in no way saying that this is the way people should do things but if  your not going to do it right at least do it in a &#8220;safer&#8221; manner to prevent yourself from getting totally fucked.  Really it is best to have a different password for each place you go and the password should be 8-10 characters long (the longer the better) and have at least 1 uppercase letter and at least 1 number. Now remember there is no such thing as a full proof password. Any password with time can be cracked but the harder you make it the more chances that hacker will give up out of bordom. Unless you really pissed someone off then you really don&#8217;t have to worry unless the database is cracked which goes back to why its a good idea to use a different password for each place you go to.</p>
<p><em>/end/</em></p>
]]></content:encoded>
			<wfw:commentRss>http://digitalfiz.com/2008/12/lazy-passwords/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
