<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Elliott C. Back &#187; Hacking</title>
	<atom:link href="http://elliottback.com/wp/category/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://elliottback.com/wp</link>
	<description>Internet &#38; Technology</description>
	<lastBuildDate>Tue, 03 Nov 2009 23:59:21 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>MacWorld MacRumors Live Feed Hacked</title>
		<link>http://elliottback.com/wp/macworld-macrumors-live-feed-hacked/</link>
		<comments>http://elliottback.com/wp/macworld-macrumors-live-feed-hacked/#comments</comments>
		<pubDate>Wed, 07 Jan 2009 05:14:07 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://elliottback.com/wp/?p=2941</guid>
		<description><![CDATA[I was watching the MacWorld 2009 Apple Keynote live when a message appeared in the feed&#8211;&#8221;STEVE JOBS JUST DIED&#8221;&#8211;surprising everyone.  In a few minutes, the MacRumors feed was full of coordinated hacked spam:

Highlighted is the beginning of the spam
MacRumors apologized for the incident: &#8220;Our MacRumorsLive keynote coverage was hacked today, inserting inappropriate content into [...]]]></description>
			<content:encoded><![CDATA[<p>I was watching the <a href="http://macrumorslive.com">MacWorld 2009 Apple Keynote</a> live when a message appeared in the feed&#8211;&#8221;STEVE JOBS JUST DIED&#8221;&#8211;surprising everyone.  In a few minutes, the MacRumors feed was full of coordinated hacked spam:</p>
<p><a href="http://elliottback.com/wp/wp-content/uploads/2009/01/macworld09.jpg"><img src="http://elliottback.com/wp/wp-content/uploads/2009/01/macworld09-450x365.jpg" alt="" title="macworld09" width="450" height="365" class="alignnone size-medium wp-image-2943" /></a><br />
<small>Highlighted is the beginning of the spam</small></p>
<p>MacRumors <a href="http://www.macrumors.com/2009/01/06/macrumorslive-hacked/">apologized for the incident</a>: &#8220;Our MacRumorsLive keynote coverage was hacked today, inserting inappropriate content into the text and photo feeds. We apologize for the inconvenience and are working to restore our services.&#8221;  However, it was simply negligence on their part for having a control panel which was publicly accessible rather than some kind of nefarious hack.  One of the nicer 4chan readers took this screenshot of it before it was taken offline:</p>
<p><a href="http://elliottback.com/wp/wp-content/uploads/2009/01/macrumors-admin-panel.png"><img src="http://elliottback.com/wp/wp-content/uploads/2009/01/macrumors-admin-panel-450x168.png" alt="" title="macrumors-admin-panel" width="450" height="168" class="alignnone size-medium wp-image-2946" /></a></p>
<p>See also <a href="http://www.techcrunch.com/2009/01/06/when-livestreams-go-wrong/">When Livestreams Go Wrong</a> and <a href="http://zip.4chan.org/g/imgboard.html">4chan&#8217;s /g board</a> where the chaos originated.  Hopefully this will teach bloggers and web startups to pay more attention to the security of their websites, as hacking websites is growing more and more popular with savvy internet pranksters.</p>
]]></content:encoded>
			<wfw:commentRss>http://elliottback.com/wp/macworld-macrumors-live-feed-hacked/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>World of Warcraft Phishing Spam Email</title>
		<link>http://elliottback.com/wp/world-of-warcraft-phishing-spam-email/</link>
		<comments>http://elliottback.com/wp/world-of-warcraft-phishing-spam-email/#comments</comments>
		<pubDate>Sun, 23 Nov 2008 03:57:33 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[Games]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Warcraft]]></category>
		<category><![CDATA[WoW]]></category>

		<guid isPermaLink="false">http://elliottback.com/wp/?p=2889</guid>
		<description><![CDATA[Just got this lovely email, pretending to be from Blizzard:
Subject: Warning : World of Warcraft Account Notice
From: donotreply@blizzard.com
To: arfenhousetoo@gmail.com
An investigation of your World of Warcraft account has found strong evidence that the account in question is being sold or traded.  As you may not be aware of, this conflicts with Blizzard&#8217;s EULA under section [...]]]></description>
			<content:encoded><![CDATA[<p>Just got this lovely email, pretending to be from Blizzard:</p>
<blockquote><p><strong>Subject:</strong> Warning : World of Warcraft Account Notice<br />
<strong>From:</strong> <a href="mailto:donotreply@blizzard.com" title="mailto:donotreply@blizzard.com">donotreply@blizzard.com</a><br />
<strong>To:</strong> <a href="mailto:arfenhousetoo@gmail.com" title="mailto:arfenhousetoo@gmail.com">arfenhousetoo@gmail.com</a></p>
<p>An investigation of your World of Warcraft account has found strong evidence that the account in question is being sold or traded.  As you may not be aware of, this conflicts with Blizzard&#8217;s EULA under section 4 Paragraph B which can be found here:</p>
<p><a href="http://www.worldofwarcraft.com/legal/eula.html">WoW -&gt; Legal -&gt; End User License Agreement</a></p>
<p>and Section 8 of the Terms of Use found here:</p>
<p><a href="http://www.worldofwarcraft.com/legal/termsofuse.html">WoW -&gt; Legal -&gt; Terms of Use</a></p>
<p>The investigation will be continued by Blizzard administration to determine the action to be taken against your account.  If your account is found violating the EULA and Terms of Use, your account can, and will be suspended/closed/or terminated.</p>
<p>In order to keep this from occurring, you should immediately verify that you are the original owner of the account.</p>
<p>To verify your identity please visit the following webpage:</p>
<p><a href="http://www.blizzard.com.login.xml.mcnewvision.com/Refferhttps3A2F2Fwww.worldofwarcraft.com2Faccount2F&#038;loginType=wow&#038;rhtml=y&#038;rhtml=true0check/" rel="external nofollow">http://www.worldofwarcraft.com/account</a></p>
<p>Only Account Administration will be able to assist with account retrieval issues.</p>
<p>Thank you for your time and attention to this matter, and your continued interest in World of Warcraft.</p>
<p>Sincerely,<br />
Account Administration<br />
Blizzard Entertainment</p></blockquote>
<p>See, the thing is that the first two links go to real Blizzard pages, but the last one secretly goes <a href="http://towww.blizzard.com.login.xml.mcnewvision.com" title="http://towww.blizzard.com.login.xml.mcnewvision.com" target="_blank">towww.blizzard.com.login.xml.mcnewvision.com</a>, which is clearly a moronic phishing attempt.  This leaves me with two questions:</p>
<ol>
<li>Did they target me as a Wow user specifically by harvesting my WoW-associated email address somehow?  A Blizzard partial hack?</li>
<li>What would they do with my account if they got it?  Sell my lousy lvl 45 char on ebay?  LOL&#8230;.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://elliottback.com/wp/world-of-warcraft-phishing-spam-email/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>MySpace Hacked Phishing Error Message</title>
		<link>http://elliottback.com/wp/myspace-hacked-phishing-error-message/</link>
		<comments>http://elliottback.com/wp/myspace-hacked-phishing-error-message/#comments</comments>
		<pubDate>Fri, 26 Sep 2008 00:10:44 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Errors]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://elliottback.com/wp/archives/2008/09/25/myspace-hacked-phishing-error-message/</guid>
		<description><![CDATA[I was somewhat scared when I noticed this list of usernames / passwords for MySpace.  Yeah, someone actually managed to hack my MySpace account, which is more incredible given that I don&#8217;t ever log into it:
Myspace hacked accounts 3/20/08
Here a list of myspace accounts and passwords
Example:
Username : Passwords get it  

MySpace is pretty [...]]]></description>
			<content:encoded><![CDATA[<p>I was somewhat scared when I noticed <a href="http://gabbytay2000.blogspot.com/2008/03/simple-my-space-hacking.html" rel="nofollow">this list of usernames / passwords for MySpace</a>.  Yeah, someone actually managed to hack my MySpace account, which is more incredible given that I don&#8217;t ever log into it:</p>
<blockquote><p>Myspace hacked accounts 3/20/08<br />
Here a list of myspace accounts and passwords</p>
<p>Example:<br />
Username : Passwords get it <img src='http://elliottback.com/wp/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p></blockquote>
<p><img id="image2753" src="http://elliottback.com/wp/wp-content/uploads/2008/09/myspace-hacked-password.png" alt="myspace-hacked-password.png" /></p>
<p>MySpace is pretty advanced in this regard; somehow they detected that my account had been compromised and when I logged in now to change the password, I received this neat message warning me:</p>
<p><img id="image2755" src="http://elliottback.com/wp/wp-content/uploads/2008/09/myspace-phishing-warning.png" alt="myspace-phishing-warning.png" /></p>
<blockquote><p>MySpace Announcement:  <strong>Your account has been phished!</strong></p>
<p><strong>What can I do?</strong><br />
Change your password. And don&#8217;t use your current password ever again.  Why do I care?  We&#8217;ve blocked your account until you change your password. This means you can&#8217;t send a message, post a bulletin, send a comment or add a friend until you&#8217;ve changed your password.</p>
<p><strong>What does &#8220;phished&#8221; mean?</strong><br />
&#8220;Phished&#8221; means that someone stole the email address &#038; password that you use to login to MySpace. They might be sending out messages, comments or bulletins as you!</p>
<p><strong>How did this happen?</strong><br />
You went to a fake page that asked for your MySpace login email and password, and you gave them your info. Only login to <a href="http://www.myspace.com" title="http://www.myspace.com" target="_blank">www.myspace.com</a>. Learn more</p></blockquote>
<p>I&#8217;ve changed all my users and passwords now, but still it&#8217;s a tiring experience&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://elliottback.com/wp/myspace-hacked-phishing-error-message/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Sarah Palin&#8217;s Emails</title>
		<link>http://elliottback.com/wp/sarah-palins-emails/</link>
		<comments>http://elliottback.com/wp/sarah-palins-emails/#comments</comments>
		<pubDate>Thu, 18 Sep 2008 00:54:15 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Politics]]></category>

		<guid isPermaLink="false">http://elliottback.com/wp/archives/2008/09/17/sarah-palins-emails/</guid>
		<description><![CDATA[Gawker is running an interesting story, Sarah Palin&#8217;s Personal Emails, about how Sarah Palin&#8217;s personal emails were leaked to Wikileak&#8217;s Sarah Palin Yahoo inbox 2008.  Apparently an unknown individual loosely associated with the anti-Scientology movement Anonymous obtained access to gov.sarah@yahoo.com, Sarah Palin&#8217;s email address, and took some screenshots of the emails he found there:
It [...]]]></description>
			<content:encoded><![CDATA[<p>Gawker is running an interesting story, <a href="http://gawker.com/5051193/sarah-palins-personal-emails">Sarah Palin&#8217;s Personal Emails</a>, about how Sarah Palin&#8217;s personal emails were leaked to <a href="http://wikileaks.org/wiki/Sarah_Palin_Yahoo_inbox_2008">Wikileak&#8217;s Sarah Palin Yahoo inbox 2008</a>.  Apparently an unknown individual loosely associated with the anti-Scientology movement <em>Anonymous</em> obtained access to <a href="mailto:gov.sarah@yahoo.com" title="mailto:gov.sarah@yahoo.com">gov.sarah@yahoo.com</a>, Sarah Palin&#8217;s email address, and took some screenshots of the emails he found there:</p>
<blockquote><p>It looks legit! The offending posts, screenshots, heretofore unseen family photos, and emails have all been deleted from Imageshack and 4Chan. But we have them. You want to read Sarah Palin&#8217;s email?</p></blockquote>
<p><img id="image2752" src="http://elliottback.com/wp/wp-content/uploads/2008/09/sarah-palin-email.png" alt="sarah-palin-email.png" /></p>
<p>It&#8217;s kind of sad to see Palin&#8217;s email only has 174 total messages.  I&#8217;ve been using email for hopefully less time than her, yet my gmail account has 48,163 email messages in it (say three years worth.  Perhaps John McCain picked a running mate for VP as technically inept as he is.</p>
<p>Disclosure:  I think <a href="http://elliottback.com/wp/archives/2008/09/07/sarah-palin-sucks/">Sarah Palin sucks</a> for a VP pick.</p>
<p><strong>Update:</strong>  The suspect who allegedly hacked Sarah Palin&#8217;s email is University of Tennessee student David Kernell.  His father is democratic state representative Mike Kernell.  Interesting&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://elliottback.com/wp/sarah-palins-emails/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Apple Pulling iPhone Apps from the App Store</title>
		<link>http://elliottback.com/wp/apple-pulling-iphone-apps-from-the-app-store/</link>
		<comments>http://elliottback.com/wp/apple-pulling-iphone-apps-from-the-app-store/#comments</comments>
		<pubDate>Mon, 01 Sep 2008 18:34:52 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Errors]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[iPhone]]></category>

		<guid isPermaLink="false">http://elliottback.com/wp/archives/2008/09/01/apple-pulling-iphone-apps-from-the-app-store/</guid>
		<description><![CDATA[Apple has become notorious for removing applications from the iPhone app store, generating huge amounts of controversy as each application is removed.  This post aims to aggregate the controversy into a single page, for reference.

The infamous I am Rich application sold 8 copies of the above glowing jewel for $999 a pop.  The [...]]]></description>
			<content:encoded><![CDATA[<p>Apple has become notorious for removing applications from the iPhone app store, generating huge amounts of controversy as each application is removed.  This post aims to aggregate the controversy into a single page, for reference.</p>
<p><img id="image2727" src="http://elliottback.com/wp/wp-content/uploads/2008/09/i-am-rich.jpg" alt="i-am-rich.jpg" /></p>
<p>The infamous <strong>I am Rich</strong> application sold 8 copies of the above glowing jewel for $999 a pop.  The author, <a href="http://www.audio-sandwich.com/">Armin Heinrich</a>, said &#8220;I am sure a lot more people would like to buy it, but currently can&#8217;t do so,&#8221; Heinrich said. &#8220;The App is a work of Art and included a <a href="http://www.youtube.com/watch?v=noZcgSTmDA4">secret mantra</a>; that&#8217;s all.&#8221;  The application was pulled from the iTunes store on August 7th after reviews like</p>
<blockquote><p>&#8220;I saw this app with a few friends and we jokingly clicked &#8216;buy&#8217; thinking it was a joke, to see what would happen. &#8230; THIS IS NO JOKE&#8230;DO NOT BUY THIS APP AND APPLE PLEASE REMOVE THIS FROM THE APP STORE&#8221;</p></blockquote>
<p>began to appear for the application.  There is still no official comment from Apple as to why they removed the expensive, artsy application.  According to <a href="http://latimesblogs.latimes.com/technology/2008/08/iphone-i-am-ric.html">the L.A. Times</a>, Heinrich is also baffled: &#8220;I have no idea why they did it and am not aware of any violation of the rules to sell software on the App Store.&#8221;</p>
<p><img id="image2728" src="http://elliottback.com/wp/wp-content/uploads/2008/09/slasher.jpg" alt="slasher.jpg" /></p>
<p><strong>Slasher</strong>, an iPhone app which &#8220;displays a common kitchen knife on the screen and plays a horror sound when you make a stabbing motion&#8221; was pulled from the App Store for <a href="http://blog.artsiness.com/2008/08/pictures-of-knives-are-offensive.html">violating section 3.3.12</a> of the iPhone SDK agreement covering objectionable content:</p>
<blockquote><p>3.3.12 Applications must not contain any obscene, pornographic, offensive or defamatory content or materials of any kind (text, graphics, images, photographs, etc.), or other content or materials that in Apple&#8217;s reasonable judgment may be found objectionable by iPhone or iPod touch users.</p></blockquote>
<p>The <a href="http://www.artsiness.com/Artsiness/Slasher.html">Author</a> is still trying to get clarification about what this means and get his application back into the App store.  However, it sets an unfortunate precedent that any application (think about Religious apps, bound to offend other Religions&#8230;) can be pulled simply because someone, somewhere claims to be offended.</p>
<p><img id="image2729" src="http://elliottback.com/wp/wp-content/uploads/2008/09/ipint.jpg" alt="ipint.jpg" /></p>
<p>Carling Brewery&#8217;s <a href="http://www.carling.com/ipint_details.html"><strong>iPint</strong> application</a> was removed from the Apple store after a mistake in classification caused the enormously popular application to be listed internationally, instead of in the local UK market.  iPint is still available for UK iTunes users.</p>
<p><img id="image2730" src="http://elliottback.com/wp/wp-content/uploads/2008/09/light.jpg" alt="light.jpg" /></p>
<p><a href="http://ericasadun.com/">Erica Sadun&#8217;s</a> light-making application apparently made the iPhone&#8217;s LCD brighter than the default brightness. Somehow this was a violation of Apple SDK, and the App has vanished from the App Store.  If you know more about &#8220;Light&#8221;, please leave a comment.  I can find little on it.</p>
<p><img id="image2731" src="http://elliottback.com/wp/wp-content/uploads/2008/09/phonesaber.jpg" alt="phonesaber.jpg" /></p>
<p><a href="http://themacbox.co.uk/phonesaber/">PhoneSaber</a> was an iPhone application to emulate swinging a Star Wars lightsaber around.  As you swing your phone, it would emit various sound effects.  According to <a href="http://themacbox.co.uk/2008/08/phonesabers-future/">this post</a>, Mac Box took down the app voluntarily after a THQ rep communicated that they violated Lucasfilm&#8217;s mobile licensing.</p>
<p><img id="image2732" src="http://elliottback.com/wp/wp-content/uploads/2008/09/netshare.jpg" alt="netshare.jpg" /></p>
<p>As you all know, <strong><a href="http://www.nullriver.com/products/netshare">Netshare</a></strong>, the innovative app that let you use your edge or 3G cellular as a local wifi router, essentially tethering for the iPhone, was pulled by Apple after AT&#038;T leaned on them.  Nullriver notes that &#8220;we&#8217;ve received no communication from Apple thus far. NetShare did not violate any of the Developer or AppStore agreements.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://elliottback.com/wp/apple-pulling-iphone-apps-from-the-app-store/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
