CategoryMisc

Just a collection of stuff (mostly from my old blog)

Sayakenahack architecture

S

I know the picture is a bit hard to read, but I wanted to make sure I had a detailed enough picture to understand the ‘innards’ of sayakenahack. Sometimes when you’re building stuff on the fly, and bottom-up, it’s good to take a step back, and have a top-down view. I’ll be expanding this post over time, wanted to get my thoughts down quickly on paper before I moved...

Sayakenahack.com answering the questions

S

OK, this is my last post on sayakenahack.com, and I’ve got a script scheduled to run at Sunday midnight to tear down the database. So if you wanna check, you better do it now, cause in 3 days time, it’ll be gone. *poof* But here are my thoughts on this whole debacle — and it’s going to get emotional, so don’t say I didn’t warn you. So let’s start with the...

#PotongSteam

#

I haven’t blogged in a while because I’m busy studying (yes, studying) for my OSCP certification. But what happened over the week, was just to mind-blowingly stupid to ignore. Here’s what happened…. A Taiwanese company released a game titled Fight of Gods, which as the name implies, has Gods fighting among themselves. But the developers didn’t ‘just’ use...

JJPTR wasn’t hacked

J

The fact that this RM2 company manage to raise RM500 million should be news enough, but claims that it lost all it’s money to ‘hackers’ is too hilarious for me to ignore. If you haven’t heard, a get-rich-quick scheme called JJPTR, claimed it lost RM500 million to hackers, which even with today’s depreciating ringgit would exceed a value of USD100 million. For...

Writing a WordPress Restoration script

W

WordPress sites get hacked all the time, because the typical WordPress blogger install 100’s of shitty plugins and rarely updates their site. On the one hand, it’s great that WordPress has empowered so many people to begin blogging without requiring the ‘hard’ technical skills, on the other it just gives criminals a large number of potential victims. Two years ago, when I...

Publishing Government Algorithms

P

On the 1st of February, Malaysians experienced yet another fuel price increase. Which was surprising because the price of oil and the ringgit conversion rate seemed to be favoring a drop. You see in Malaysia, the fuel prices are controlled and subsidized by the government, and it sets the price for petrol at the pump. In the past, fuel price changes were few and far between, but since 2007...

How the StarHub DDOS (possibly) happened

H

Customers of Singaporean ISP StarHub, suffered two major disruptions to their service over the past week, in what the telco said was a result of a “intentional and likely malicious distributed denial-of-service (DDoS) attacks”. Oh the humanity!! In what appears to be a copycat of the Dyn attack we saw (at roughly the same time), the attack signals the first local salvo in the war of...

Hotline Jais is a terrible idea!

H

Jais recently launched anew mobile app to allow the public to easily report any crimes that contravene syariah laws. Obviously there’s social and legal implications here, which I won’t go into, but we need to understand just how stupid this idea is. When you ask amateurs to give you security, what you eventually end up with is amateur security. It’s the reason why Maths...

All you eggs in one basket

A

Is it wise to use an online password manager? After all, putting your passwords on the cloud seems like a really dumb idea. But I use password manager because while storing stuff on the cloud may present risk, it’s far riskier and dumber to re-use passwords. Why you need a password manager? Despite the sexiness of zero-day exploits and hardcore state-sponsored hacking groups we see on the...

Random thoughts

R

You’ve probably heard of the hackers who almost got away with $1 billion, only to be thwarted by a typo. (if it weren’t for those meddling keyboards!) What you probably didn’t hear was that they had already wired $100 million to themselves, are assumed to have pocketed anywhere from $21 million to $81 million in cold hard cash. Sure, Billions is more than millions, but one a...