Insurgency Mod Scum: cheaters, hackers, wallhackers, aimbotters, griefers, teamkillers, micspammers, spawncampers, exitcampers, and everything else Insurgency.
Blogger.com policy on personal information: Personal and confidential information: It's not ok to publish another person's personal and confidential information. For example, don't post someone else's credit card numbers, Social Security numbers, unlisted phone numbers, and driver's license numbers. Also, please keep in mind that in most cases, information that is already available elsewhere on the Internet or in public records is not considered to be private or confidential under our policies.
All information posted on Insurgency Mod Scum is publicly available.
Showing posts with label OT-OPSEC / Anonymity. Show all posts
Showing posts with label OT-OPSEC / Anonymity. Show all posts

[NOTED] Qubes R2 Hash

2015-05-30

0 comments
 File: Qubes-R2-x86_64-DVD.iso
CRC-32: 9b1ad5e1
   MD4: a852f54e95bd9442b0a92a4990ebc03e
   MD5: 6f6ff24f2edec3a7607671001e694d8e
 SHA-1: 0344e04a98b741c311936f3e2bb67fcebfc2be08

[LINK][NOTED] GPG (GNU Privacy Guard) 1.4.19 (Windows Binaries)

0 comments
ftp://ftp.gnupg.org/gcrypt/binary/

It is ridiculously difficult to download GPG command line executable for Windows. Either Google Search is fucked up to the point of unusability or there's some kind of NSA - Google conspiracy. Probably the former.

https://www.gnupg.org/documentation/manpage.html

--homedir
--symmetric
--armor
--no-version

Also see:
http://insurgencymod.blogspot.com/2015/05/rant-google-deleted-my-gmail-address.html

Quotes: Beating the NSA

2014-03-01

0 comments
http://it.slashdot.org/comments.pl?sid=6579519&cid=48701589

Your choice of OS, if you have something worth encrypting and hiding, is the least of your worries.

If you have any brains at all, all key generation is done offline on a clean machine and then that machine destroyed. Only a specific, purpose-built target on YOU would stop that working as intended without informing the NSA, and then they may as well just listen in to the room anyway.

What you are falling into is the "movie hackers" fallacy - "Gosh, everything hackable therefore everything is hacked all the time". If you have a clean, from-disk OS, and keep it off the net, and sign your messages with your pre-generated private key on a device that goes NOWHERE and only gets turned on when you need to use it - fuck 'em. Quite what power do you think they have over that?

Don't get me wrong, if you're targeted by the NSA, I'm sure they can get to you somehow. But I can assure you they were targeting Bin Laden and he survived, what, a decade with the whole world looking for him? He was found to be couriering USB keys down to the local Internet cafe.

Targeted malware only works if you're stupid enough to expose the machine to the net, or run programs that aren't verifying content. It's all Hollywood tripe.

If there's a terrorist with a brain out there, and they are trying to avoid the NSA's glare, I'd be quite annoyed at their stupidity if they aren't using read-only boot media, a bunch of random devices bought in shops, PKE, and programs that aren't mainstream enough to have exploits written for them.

If you're targeted, malware is the fucking least of your worries, and easily countered by not allowing your PC to come into contact with it. Even that stuff about some malware making computers "talk" over audio channels to cross air-gaps only works when computers are infected in the first place.

We even have double-compilation-verification built operating systems, and you can boot some old shit off a floppy image from pre-Windows days if you're really paranoid.

The problem is not that - it's not encrypting, generating, or securing your message. It's how do you get your message to the wider net from there, and that identifies your location quite quickly.

It lacks in imagination to think that the NSA, or indeed any intelligence agency, is really as good as you think they are. I'm a massive fan of GCHQ history, for instance, and I quite believe that today's GCHQ is a shadow of it's former self forced to resort to asking Facebook for copies of its data. Given that they invented this type of stuff to prevent EXACTLY what they are trying to do now, it's hilarious that it's backfired to the point where they are having to convince you they really can listen to everything, everywhere, always.
If they could do that, you would never hear of it. Because, you see, they'd know about all the leaks and be able to stop them in their tracks - legally or illegally.

Pro Tip: TOR Through VirtualBox/VirtualBox Through TOR?

2013-03-18

0 comments
VirtualBox and TOR

Tor Browser Bundles can crash, AdvOR can crash, Proxifier can crash. We don't want Alan Harvey, TeamCRG owner and manager, protector of a shitload of cheaters to sue us so...

They say having seperate machines/devices/appliances is the most secure, fail-proof option. But if you are not into that, consider VirtualBox or VMWare and...

Whonix

http://sourceforge.net/projects/whonix/

Don't forget to...

sudo apt-get update
sudo apt-get dist-upgrade
sudo apt-get autoremove
sudo apt-get autoclean

or

Tor Gateway AKA Incognito Gateway

http://ra.fnord.at (info)
https://github.com/ra--/Tor-gateway (info)
https://bitbucket.org/ra_/tor-gateway (download)

There's some confusion with the version numbers, download...

Incognito Gateway 0.6.1
Tor Fast Gateway 0.1.3

You can use any OS with Whonix/Tor AKA Incognito Gateway, but don't forget to fake your HTTP headers AKA browser fingerprint.

http://sourceforge.net/p/whonix/wiki/OtherOperatingSystems/

IP address 192.168.0.50
Subnet netmask 255.255.255.0
Default gateway 192.168.0.10
Preferred DNS server 192.168.0.10

Pro Tip: Block Ads in Google Chrome Like a Pro Checklist (Ad Blocking System)

2013-02-03

0 comments
  1. Windows Hosts file.
    AdBlock Chrome


  2. AdBlock lists (EasyList & FanBoy lists).
  3. NoScript AKA ScriptSafe "unwanted content" & "unwanted cookies" & "anti-social mode".
    Google Chrome leak.


  4. Check Google Chrome/Firefox Extensions for leaks  

Also see "Rogue Browser Extensions/AddOns":
http://insurgencymod.blogspot.com/2013/03/pro-tip-firefox-adblock-without.html
http://insurgencymod.blogspot.com/2012/11/pro-tip-rogue-browser-extensions.html

PROTIP: TrueCrypt vs DiskCryptor (Windows)

2012-11-24

0 comments
TrueCrypt is better for files since it cannot decrypt already encrypted disks. TrueCrypt encrypted files can be accessed in Linux.

http://www.truecrypt.org/
http://en.wikipedia.org/wiki/TrueCrypt 

DiskCryptor is better for encrypting disks. DiskCryptor encrypted disks cannot be accessed in Linux.

http://diskcryptor.net/wiki/Main_Page
http://en.wikipedia.org/wiki/DiskCrypto

Book: "Security Engineering" (PDF Chapters)

2012-10-22

0 comments
http://www.cl.cam.ac.uk/~rja14/book.html

Security Engineering

Security Engineering — The Book

‘I'm incredibly impressed that one person could produce such a thorough coverage. Moreover, you make the stuff easy and enjoyable to read. I find it just as entertaining — and far more useful — than novels (and my normal science fiction). When I first got it in the mail, I said to myself "I'm never going to read all of that." But once I started reading I just kept going and going. Fantastic: well done. Now, let's hope that all those in charge of security for information technology will also read the book and heed the lessons.’
Don Norman

‘The book that you MUST READ RIGHT NOW is the second edition of Ross Anderson's Security Engineering book. Ross did a complete pass on his classic tome and somehow made it even better...’
Gary McGraw

‘It's beautiful. This is the best book on the topic there is’
Bruce Schneier

All chapters from the second edition now available free online!

Table of contents
Preface
Acknowledgements
Chapter 1: What is Security Engineering?
Chapter 2: Usability and Psychology
Chapter 3: Protocols
Chapter 4: Access Control
Chapter 5: Cryptography
Chapter 6: Distributed Systems
Chapter 7: Economics
Chapter 8: Multilevel Security
Chapter 9: Multilateral Security
Chapter 10: Banking and Bookkeeping
Chapter 11: Physical Protection
Chapter 12: Monitoring and Metering
Chapter 13: Nuclear Command and Control
Chapter 14: Security Printing and Seals
Chapter 15: Biometrics
Chapter 16: Physical Tamper Resistance
Chapter 17: Emission Security
Chapter 18: API Security
Chapter 19: Electronic and Information Warfare
Chapter 20: Telecom System Security
Chapter 21: Network Attack and Defence
Chapter 22: Copyright and DRM
Chapter 23: The Bleeding Edge
Chapter 24: Terror, Justice and Freedom
Chapter 25: Managing the Development of Secure Systems
Chapter 26: System Evaluation and Assurance
Chapter 27: Conclusions
Bibliography
Index
When I wrote the first edition, we put the chapters online free after four years and found that this boosted sales of the paper edition. People would find a useful chapter online and then buy the book to have it as a reference. Wiley and I agreed to do the same with the second edition, and now, four years after publication, I am putting all the chapters online for free. Enjoy them – and I hope you'll buy the paper version to have as a conveient shelf reference:

Buy from Amazon.com
Buy from Wiley
Buy from Amazon.co.uk (Kindle version)
Here are the errata for the second edition, and here's a page of notes and links concerning relevant topics that I've come across since publication.

Supplementary materials: If you're a college professor thinking of using my book in class, note that we use my book in three courses at Cambridge:

the first part in second-year Introduction to Security (course material and past exam questions)
the second in third-year Security (course material and questions), and
the third part in our second-year Software Engineering (course, questions and still more questions).
I hope you find these useful. You're welcome to use and adapt any of my slides if you wish under this Creative Commons license. Also, if you're an instructor at an accredited institution, you can request an evaluation copy via Wiley's website.
The first edition (2001)

You can also download all of the first edition for free:

The foreword, preface and other front matter

What is Security Engineering?
Protocols
Passwords
Access Control
Cryptography
Distributed Systems
Multilevel Security
Multilateral Security
Banking and Bookkeeping
Monitoring Systems
Nuclear Command and Control
Security Printing and Seals
Biometrics
Physical Tamper Resistance
Emission Security
Electronic and Information Warfare
Telecom System Security
Network Attack and Defense
Protecting E-Commerce Systems
Copyright and Privacy Protection
E-Policy
Management Issues
System Evaluation and Assurance
Conclusions
Bibliography
Finally, here's a single pdf of the whole book. It's 17Mb, but a number of people asked me for it.
My goal in making the first edition freely available five years after publication was twofold. First, I wanted to reach the widest possible audience, especially among poor students. Second, I am a pragmatic libertarian on free culture and free software issues; I think that many publishers (especially of music and software) are too defensive of copyright. (My colleague David MacKay found that putting his book on coding theory online actually helped its sales. Book publishers are getting the message faster than the music or software folks.) I expect to put the whole second edition online too in a few years.

If you own the first edition of my book, I hope you liked it enough to upgrade to the second edition. I also have online errata for the first edition here.

Following enquiries from blind students, Jose C. Lacal has contributed these MP3 files of the first edition: preface, chapter 1, chapter 2, chapter 3, chapter 4, chapter 6, and chapter 7.

Where to buy the second edition

Amazon.com
Buy from Wiley
Amazon.co.uk
BestBookBuys (for secondhand)
There are reviews of the first edition, which was translated into Japanese, Chinese and Polish.

OPSEC/Anonymity: "The Gentleman's Guide To Forum Spies"

2012-07-10

0 comments
http://cryptome.org/2012/07/gent-forum-spies.htm
http://pastebin.com/irj4Fyd5

1. COINTELPRO - Techniques for dilution, misdirection and control of a internet forum
2. Twenty-Five Rules of Disinformation
3. Eight Traits of the Disinformationalist
4. How to Spot a Spy (COINTELPRO Agent)
5. Seventeen Techniques for Truth Suppression

Pro Tip: MediaMonkey Alternative - MusicBee

2012-07-05

0 comments
I'm fed up with MediaMonkey Portable. It is NOT portable. All the paths are absolute, and it constantly leaves empty folders and Windows Registry entries behind.

MediaMonkey developers also refuse to address an annoying UI bug, the final strike.

Consider MusicBee, again it's not truly portable because it creates shit in your "Music" folder on first launch, but it's way more portable than MM.

Good:
  • MusicBee splits FLAC images, MM doesn't. You might still have to convert them to individual tracks for transfer to Ipods, not sure on this.
  • More portable than MM.

Bad:
  • Written in VB.NET (according to Wikipedia). Requires .NET. Uses more memory than MediaMonkey.
  • Can't browse library by folder, only by artist, genre, album, etc. 
  • Frequent errors, but handles them elegantly with no crashes.  


INSMODSCUM haven't yet tested MusicBee with Ipods, but never the less until MediaMonkey developers fix their software, MusicBee would serve well as a viable alternative.