INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Ukukhokela: manene namanenekazi, le ntetho ihlekisa kakhulu kwaye inomdla kakhulu, namhlanje siza kuthetha ngezinto zokwenyani ezibonwa kwi-Intanethi. Le ncoko yahluke kancinane kwezo siziqhelileyo kwiinkomfa ze-Black Hat kuba siza kuthetha ngendlela abahlaseli abayenza ngayo imali ekuhlaselweni kwabo.

Siza kukubonisa uhlaselo olunomdla olunokwenza inzuzo, kwaye sikuxelele malunga nohlaselo olwenzeka ngokwenene ngobusuku esaya ngaphaya kweJägermeister kwaye sicebisana ngengqondo. Kwakumnandi, kodwa xa sithe nca kancinci, sathetha nabantu be-SEO kwaye eneneni safunda ukuba abantu abaninzi benza imali kolu hlaselo.

Ndingumphathi ophakathi ongenangqondo, ngoko ke ndiza kuncama isihlalo sam kwaye ndinazise kuJeremy noTrey, abakrelekrele kakhulu kunam. Kufanele ukuba ndibe nentshayelelo ekrelekrele neyonwabisayo, kodwa andiyenzi, ngoko ke ndiza kubonisa ezi zilayidi endaweni yoko.

Izilayidi ezibonisa uJeremy Grossman kunye noTrey Ford ziboniswa kwiscreen.
UJeremy Grossman ungumseki kunye negosa eliyintloko leteknoloji ye-WhiteHat Security, ebizwa ngokuba yi-CTO ephezulu ye-2007 ngu-InfoWorld kwi-25, umseki we-Web Application Security Consortium, kunye no-co-author we-cross-site scripting attack.

I-Trey Ford nguMlawuli weZisombululo ze-Architectural kwi-WhiteHat Security, onamava angama-6 eminyaka njengomcebisi wezokhuseleko kwiinkampani ze-Fortune 500 kunye nomnye wabaphuhlisi bekhadi lokuhlawula i-PCI DSS yomgangatho wokhuseleko lwedatha yedatha.

Ndicinga ukuba le mifanekiso yenza ukuba ndingabi naburharha. Kuyo nayiphi na imeko, ndiyathemba ukuba uyonwabele intetho yabo kwaye uqonde ukuba olu hlaselo lusetyenziswa njani kwi-Intanethi ukwenza imali.

UJeremy Grossman: Molo emva kwemini, enkosi nonke ngokuza kwenu. Le iya kuba yincoko emnandi kakhulu, nangona awuyi kubona uhlaselo lweentsuku zero okanye itekhnoloji entsha epholileyo. Siza kuzama nje ukuyenza yonwabise kwaye sithethe ngezinto zokwenyani ezenzeka mihla le ezivumela abantu ababi ukuba benze imali eninzi.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Asizami kukuchukumisa ngoko kuboniswe kwesi silayidi, kodwa cacisa ngokulula ukuba yintoni eyenziwa yinkampani yethu. Ke, i-White Hat Sentinel, okanye "i-Guardian White Hat" yile:

  • inani elingenamkhawulo lovavanyo - ulawulo kunye nolawulo lweengcali kwiindawo zabaxhasi, ukukwazi ukuskena iisayithi kungakhathaliseki ubungakanani babo kunye nokutshintsha rhoqo;
  • indawo ebanzi yokugubungela - ukuskena okugunyazisiweyo kweziza ukukhangela ubuthathaka bobugcisa kunye novavanyo lomsebenzisi ukuchonga iimpazamo ezinengqiqo kwiindawo zoshishino ezingafunyaniswanga;
  • ukuphelisa ukuchaneka kobuxoki - iqela lethu elisebenzayo liphonononga iziphumo kwaye linike ubukhali obufanelekileyo kunye nenqanaba lokusongela;
  • uphuhliso kunye nolawulo lomgangatho - inkqubo ye-WhiteHat Satellite Appliance ivumela ukuba sisebenzise iinkqubo zabathengi ngenkonzo ngokufikelela kwinethiwekhi yangaphakathi;
  • ukuphuculwa kunye nokuphuculwa - ukuskena okunokwenyani kukuvumela ukuba uhlaziye ngokukhawuleza nangokufanelekileyo inkqubo.

Ke, siphicotha indawo nganye emhlabeni, sinelona qela likhulu leepentesters zewebhu, senza uvavanyo lwe-600-700 veki nganye, kwaye yonke idatha oya kuyibona kule nkcazo iphuma kumava ethu okwenza olu hlobo lomsebenzi. .
Kwisilayidi esilandelayo ubona i-10 yeentlobo eziqhelekileyo zokuhlaselwa kwiiwebhusayithi zehlabathi. Oku kubonisa ipesenti yokuba sesichengeni kuhlaselo oluthile. Njengoko ubona, i-65% yazo zonke iisayithi zisengozini kwi-scripting ye-cross-site, i-40% ivumela ukuvuza kolwazi, kwaye i-23% isengozini kwi-spoofing content. Ukongeza kwi-scripting ye-cross-site, ii-injection ze-SQL kunye ne-notorious cross-site application forgery, engabandakanywanga kwishumi lethu eliphezulu, liqhelekileyo. Kodwa olu luhlu luqulethe uhlaselo olunamagama e-esoteric, achazwe kusetyenziswa ulwimi olungacacanga kunye neyona nto ijoliswe kuyo kwiinkampani ezithile.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Ezi ziziphene zokuqinisekisa, iziphene zenkqubo yogunyaziso, ukuvuza kolwazi, njalo njalo.

Isilayidi esilandelayo sithetha ngohlaselo kwingqiqo yeshishini. Amaqela e-QA abandakanyekayo ekuqinisekiseni umgangatho adla ngokungawahoyi. Bavavanya into ekufuneka yenziwe yisoftware, hayi into enokuyenza, emva koko unokubona nantoni na oyifunayo. I-scanners, zonke ezi Bhokisi eziMhlophe / eziMnyama / eziMpuvu, zonke ezi bhokisi ezinemibala emininzi azikwazi ukuzibona ezi zinto kwiimeko ezininzi, kuba zilungiswa ngokulula kumxholo wokuba uhlaselo lunokuba yintoni okanye kwenzeka ntoni efanayo xa isenzeka. Baswele ubukrelekrele kwaye abazi nokuba kukho into esebenzileyo kwaphela okanye hayi.

Okufanayo kuya kwi-IDS kunye ne-firewall yesicelo se-WAF, ekwasilelayo ukufumanisa iziphene zengqiqo yezoshishino kuba izicelo ze-HTTP zibukeka ziqhelekileyo ngokupheleleyo. Siza kukubonisa ukuba uhlaselo olunxulumene neziphene zengqiqo yezoshishino zivela ngokwemvelo ngokupheleleyo, akukho bahlaseli, akukho metacharacters okanye ezinye izinto ezingaqhelekanga, zibukeka njengeenkqubo ezenzeka ngokwemvelo. Eyona nto iphambili kukuba abantu ababi bayazithanda ezi zinto kuba iziphene kwingcinga yeshishini zibenza imali. Basebenzisa i-XSS, SQL, CSRF, kodwa ezi ntlobo zohlaselo ziya zisiba nzima ukwenza, kwaye sibonile ukuba ziye zehla kule minyaka mi-3-5 idlulileyo. Kodwa aziyi kunyamalala ngokwazo, kanye njengokuba isithinteli esiphuphumayo singayi kumka. Nangona kunjalo, abantu ababi bacinga malunga nendlela yokusebenzisa uhlaselo oluyinkimbinkimbi kuba bakholelwa ukuba "abantu ababi ngokwenene" bahlala bejonge ukwenza imali ekuhlaselweni kwabo.

Ndifuna ukukubonisa amaqhinga okwenene onokuwathatha ebhodini kwaye uwasebenzise ngendlela efanelekileyo ukukhusela ishishini lakho. Enye injongo yenkcazo-ntetho yethu kukuba usenokuba uyazibuza ngokuziphatha.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Ukuvota kwi-Intanethi kunye nokuvota

Ke, ukuqalisa ingxoxo yethu yeentsilelo zengqiqo yeshishini, makhe sithethe ngophando lwe-intanethi. Uvoto lwe-Intanethi yeyona ndlela ixhaphakileyo yokufumana okanye ukuphembelela uluvo loluntu. Siza kuqala ngenzuzo ye-0 yeedola kwaye emva koko sijonge umphumo we-5, 6, 7 iinyanga zezicwangciso zobuqhetseba. Masiqale ngokwenza uphando olulula kakhulu. Uyazi ukuba yonke iwebhusayithi entsha, ibhlog nganye, yonke i-portal yeendaba iqhuba uphando kwi-intanethi. Oko kwathiwa, akukho niche inkulu kakhulu okanye imxinwa kakhulu, kodwa sifuna ukubona uluvo loluntu kwiindawo ezithile.

Ndingathanda ukutsalela ingqalelo yakho kolunye uphando olwenziwe eAustin, eTexas. Ngenxa yokuba i-beagle yase-Austin iphumelele i-Westminster Dog Show, i-Austin American Statesman yagqiba ekubeni iqhube i-intanethi ye-Austin's Best in Show poll yabanini bezinja zase-Central Texas. Amawakawaka abanini angenise iifoto kwaye avotela abo babathandayo. Njengolunye uphando oluninzi, kwakungekho bhaso ngaphandle kwamalungelo okuqhayisa ngesilo-qabane sakho.

Isicelo se-Web 2.0 sisetyenziselwe ukuvota. Ucofe u-"ewe" ukuba uyayithanda inja kwaye wafumanisa ukuba yeyona nja ilungileyo kuhlobo okanye hayi. Ngoko uvotele amakhulu aliqela ezinja eziposwe kwisiza njengabagqatswa bophumeleleyo kumboniso.

Ngale ndlela yokuvota, iintlobo ezi-3 zokuqhatha zazinokwenzeka. Eyokuqala yivoti engapheliyo, apho uvotela inja enye ngokuphindaphindiweyo. Ilula kakhulu. Indlela yesibini luvoto oluninzi olubi, apho uvotela inani elikhulu lamaxesha ngokuchasene nenja ekhuphisanayo. Indlela yesithathu yayikukuba, ngokoqobo ngomzuzu wokugqibela wokhuphiswano, ubeke inja entsha, ivotele, ukwenzela ukuba ithuba lokufumana iivoti ezibi lincinci, kwaye uphumelele ngokufumana iivoti ezilungileyo ze-100%.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Ngaphezu koko, uloyiso lunqunywe njengepesenti, kwaye kungekhona ngenani elipheleleyo leevoti, oko kukuthi, awukwazi ukugqiba ukuba yeyiphi inja efumene inani eliphezulu lemilinganiselo emihle, kuphela ipesenti yokulinganisa okulungileyo kunye nokubi kwinja ethile. . Inja enomlinganiselo wamanqaku alungileyo/angalunganga iphumelele.

Ugxa wakhe uRobert "RSnake" Umhlobo kaHansen wamcela ukuba amncede uChihuahua Tiny aphumelele ukhuphiswano. Uyazi uRobert, usuka eAustin. Yena, njenge-hacker ephezulu, walungisa i-proxy ye-Burp kwaye walandela indlela yokuchasana okuncinci. Wasebenzisa indlela yokukopela #1, eyiqhuba ngeBurp loop yamakhulu aliqela okanye amawaka ezicelo, kwaye oku kwezisa inja iivoti ezingama-2000 kwaye yamzisa kwindawo yokuqala.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Emva koko, wasebenzisa ubuchule bokuqhatha iNombolo yesi-2 ngokuchasene nalowo wayekhuphisana noTiny, ogama linguChuchu. Kwimizuzu yokugqibela yokhuphiswano, wenze iivoti ezingama-450 ngokuchasene noChuchu, nto leyo yomeleza ngakumbi indawo kaTiny kwindawo ye-1 ngomlinganiselo wevoti ongaphezulu kwe-2:1, kodwa ngokwepesenti yokuphononongwa okuhle nokubi, uTiny usalahlekile. Kwesi silayidi ubona ubuso obutsha be-cybercriminal, edanyazwe sesi siphumo.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Ewe, yayiyimeko enomdla, kodwa ndicinga ukuba umhlobo wam akazange ayithande le ntsebenzo. Ubufuna ukuphumelela ukhuphiswano lweChihuahua e-Austin, kodwa kukho umntu ozame ukukugezela kwaye enze into efanayo. Ewe, ngoku ndidlulisela umnxeba kuTrey.

Ukudala imfuno yokwenziwa kunye nokwenza imali kuyo

UTrey Ford: Ingqikelelo "ye-DoS yokwenziwa" ibhekisa kwiimeko ezininzi ezahlukeneyo ezinomdla xa sithenga amatikiti kwi-Intanethi. Umzekelo, xa ugcina isihlalo esikhethekileyo kwinqwelomoya. Oku kungasebenza kulo naluphi na uhlobo lwetikiti, elifana nomsitho wezemidlalo okanye ikonsathi.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Ukuze kuthintelwe ukuthengwa ngokuphindaphindiweyo kwezinto ezinqabileyo ezifana nezihlalo ze-airline, izinto eziphathekayo, amagama omsebenzisi, njl. Kwaye apha kuza ubuthathaka obunxulumene nokukwazi ukugcina into kwangaphambili.

Sonke siyazi malunga nexesha lokuvala, sonke siyazi malunga nokuphela kweseshoni. Kodwa esi siphene sisengqiqweni sivumela ukuba sikhethe isihlalo kwinqwelomoya kwaye sibuye sikhethe kwakhona ngaphandle kokuhlawula nantoni na. Ngokuqinisekileyo uninzi lwenu luhlala lusiya kuhambo lweshishini, kodwa kum le yinxalenye ebalulekileyo yomsebenzi. Siyivavanye le algorithm kwiindawo ezininzi: ukhetha inqwelomoya, ukhethe isihlalo, kwaye kuphela xa ulungile ufaka iinkcukacha zakho zentlawulo. Oko kukuthi, emva kokuba ukhethe indawo, igcinelwe ixesha elithile - ukusuka kwimizuzu emininzi ukuya kwiiyure ezininzi, kwaye ngeli xesha akukho mntu unokubhukisha le ndawo. Ngenxa yeli xesha lokulinda, unethuba lokwenyani lokugcina zonke izihlalo kwinqwelomoya ngokubuyela nje kwindawo kwaye ubhukishe izihlalo ozifunayo.

Ngaloo ndlela, ukhetho lokuhlasela lwe-DoS luvela: phinda ngokuzenzekelayo lo mjikelo kwisihlalo ngasinye kwinqwelomoya.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Sikuvavanyile oku kwiinqwelomoya ezinkulu ezimbini. Ungafumana ubuthathaka obufanayo nalo naluphi na olunye ubhukisho. Eli lithuba elihle lokunyusa amaxabiso amatikiti akho kwabo bafuna ukuwathengisa kwakhona. Ukwenza oku, abaqikeleli kufuneka babhukishe amatikiti aseleyo ngaphandle komngcipheko welahleko yemali. Ngale ndlela, unokwenza “ukuphazamiseka” kwe-e-commerce ethengisa iimveliso ezifunwa kakhulu-imidlalo yevidiyo, iikhonsoli zomdlalo, ii-iPhones, njalo njalo. Oko kukuthi, impazamo ekhoyo kwi-intanethi yokubhukisha okanye inkqubo yogcino ivumela umhlaseli ukuba enze imali kuyo okanye enze umonakalo kubakhuphisana nabo.

Ukucima ukuntsonkotha kweCaptcha

UJeremy Grossman: Ngoku makhe sithethe nge-captcha. Wonke umntu uyayazi loo mifanekiso ikruqulayo elahla i-Intanethi kwaye isetyenziselwa ukulwa ne-spam. Ngokunokwenzeka, unokwenza inzuzo kwi-captcha. I-Captcha luvavanyo lwe-Turing oluzenzekelayo oluzenzekelayo olukuvumela ukuba uhlukanise umntu wangempela kwi-bot. Ndifumene izinto ezininzi ezinomdla ngelixa ndiphanda ukusetyenziswa kwe-captcha.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

I-Captcha yaqala ukusetyenziswa malunga ne-2000-2001. Abagaxekile bafuna ukuphelisa i-captcha ukuze babhalisele iinkonzo ze-imeyile zamahhala ze-Gmail, i-Yahoo Mail, i-Windows Live Mail, i-MySpace, i-FaceBook, njl. kwaye uthumele ispem. Ekubeni i-captcha isetyenziswa ngokubanzi, imarike yonke yeenkonzo ibonakala inikezela ukudlula i-captcha yonke indawo. Ekugqibeleni, oku kuzisa inzuzo - umzekelo uya kukuthumela ispem. Kukho iindlela ezi-3 zokudlula i-captcha, masizijonge.

Eyokuqala yiziphene ekuphunyezweni kwengcamango, okanye iintsilelo ekusebenziseni i-captcha.
Ke, iimpendulo zemibuzo ziqulathe i-entropy encinci kakhulu, njengokuthi "bhala ukuba u-4+1 ulingana nantoni." Imibuzo efanayo inokuphinda iphindwe kaninzi, kwaye uluhlu lweempendulo ezinokubakho zincinci kakhulu.

Ukusebenza kwe-captcha kujongwa ngolu hlobo:

  • uvavanyo kufuneka lwenziwe phantsi kweemeko apho umntu kunye nomncedisi bekude omnye komnye,
    uvavanyo akufanele kube nzima kumntu ngamnye;
  • umbuzo kufuneka ube ngowokuba umntu angawuphendula kwimizuzwana embalwa,
    Kuphela ngulowo ubuzwa kuye umbuzo ekufuneka aphendule;
  • ukuphendula umbuzo kufuneka kube nzima kwikhompyuter;
  • ulwazi lwemibuzo yangaphambili, iimpendulo okanye ukudibanisa kwabo akufanele kuchaphazele ukuqikelelwa kovavanyo olulandelayo;
  • uvavanyo akufunekanga lucalule abantu abangaboni kakuhle okanye abangeva kakuhle;
  • uvavanyo kufuneka lungakhethi cala ngokwejografi, ngokwenkcubeko okanye ngokolwimi.

Njengoko kuvela, ukwenza i-captcha "echanekileyo" kunzima kakhulu.

I-disadvantage yesibini ye-captcha yinto enokwenzeka yokusebenzisa i-OCR yokuqaphela umlingiswa obonakalayo. Isiqwenga sekhowudi siyakwazi ukufunda umfanekiso we-captcha kungakhathaliseki ukuba ingakanani ingxolo ebonakalayo equlethwe kuyo, jonga ukuba zeziphi iileta okanye iinombolo ezizenzayo, kwaye zizenzele inkqubo yokuqaphela. Uphando lubonise ukuba uninzi lwe-captchas lunokuqhekeka ngokulula.

Ndiya kunika ucaphulo kwiingcali ezivela kwiSikolo seNzululwazi yeKhompyutha kwiYunivesithi yaseNewcastle, e-UK. Bathetha ngokukhululeka kokuqhawula i-Microsoft captcha: "uhlaselo lwethu luye lwakwazi ukufikelela kwinqanaba le-segmentation ye-92%, oko kuthetha ukuba i-skim ye-MSN ye-captcha inokuchithwa kwi-60% yamatyala ngokuhlula umfanekiso kwaye emva koko uyayiqonda. ” Ukukrazula i-captcha ye-Yahoo kwaba lula: “uhlaselo lwethu lwesibini luzuze impumelelo yecandelo lama-33,4%. Ngaloo ndlela, malunga ne-25,9% ye-captchas inokuqhekeka. Uphando lwethu lucebisa ukuba i-spammers akufuneki basebenzise abasebenzi abancinci ukudlula i-Yahoo's captcha, kodwa endaweni yoko baxhomekeke kuhlaselo oluzenzekelayo olubiza ixabiso eliphantsi.

Indlela yesithathu yokudlula i-captcha ibizwa ngokuba yi "Mechanical Turk", okanye "iTurk". Sayivavanya ngokuchasene ne-Yahoo's captcha kwangoko emva kokupapashwa, kwaye kude kube namhlanje asazi, kwaye akukho mntu waziyo, indlela yokukhusela kuhlaselo olunjalo.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Le yimeko apho unomntu ombi oya kuqhuba indawo "yabantu abadala" okanye umdlalo we-intanethi apho abasebenzisi bacela umxholo othile. Ngaphambi kokuba babone umfanekiso olandelayo, i-website ye-hacker engumnikazi iya kwenza isicelo sokugqibela kwisistim ye-intanethi oqhelene nayo, yithi Yahoo okanye iGoogle, bamba i-captcha ukusuka apho kwaye uyifake kumsebenzisi. Kwaye ngokukhawuleza ukuba umsebenzisi uphendule umbuzo, i-hacker iya kuthumela i-captcha eqikelelweyo kwindawo ekujoliswe kuyo kwaye ibonise umsebenzisi umfanekiso oceliwe kwindawo yakhe. Ukuba unendawo ethandwa kakhulu enomxholo onomdla kakhulu, unokuhlanganisa umkhosi wonke wabantu abaza kuzalisa ngokuzenzekelayo ii-captchas zabanye abantu kuwe. Le yinto enamandla kakhulu.

Nangona kunjalo, ayingobantu kuphela abazama ukudlula i-captchas; amashishini asebenzisa obu buchule. URobert "RSnake" uHansen wayekhe wathetha kwiblogi yakhe kunye noRomanian "captcha solver" owathi wayenokusombulula ukusuka kwi-300 ukuya kwi-500 captchas ngeyure kwizinga le-9 ukuya kwi-15 yeedola ngewaka elixazululwe i-captchas.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Uthi ngokuthe ngqo ukuba amalungu eqela lakhe asebenza iiyure ze-12 ngosuku, ukuxazulula malunga ne-4800 captchas ngeli xesha, kwaye kuxhomekeke kubunzima be-captchas, banokufumana ukuya kwi-$ 50 ngosuku ngomsebenzi wabo. Le yayiyisithuba esinomdla, kodwa ngakumbi umdla ziinkcazo ezishiywe ngabasebenzisi beblogi phantsi kwesi sithuba. Umyalezo wavela ngokukhawuleza uvela eVietnam, apho uQuang Hung othile wabika malunga neqela lakhe labantu be-20, abavuma ukusebenzela i-$ 4 nge-1000 captchas eqikelelwayo.

Umyalezo olandelayo wawuvela eBangladesh: “Molo! Ndiyathemba ukuba ulungile! Siyinkampani ehamba phambili yokucubungula evela eBangladesh. Okwangoku, abaqhubi bethu be-30 bayakwazi ukusombulula ngaphezu kwe-100000 captchas ngosuku. Sinikezela ngeemeko ezigqwesileyo kunye nezinga eliphantsi - i-$ 2 ye-1000 eqikelelweyo ye-captchas evela kwi-Yahoo, i-Hotmail, i-Mayspace, i-Gmail, i-Facebook, njl. Sijonge phambili kwintsebenziswano."

Omnye umyalezo obangel’ umdla wathunyelwa ngomnye uBabu othi: “Ndinomdla kulo msebenzi, ndicela unditsalele umnxeba.”

Ngoko ke inika umdla kakhulu. Sinokuxoxa ngendlela esemthethweni okanye engekho mthethweni ngayo lo msebenzi, kodwa inyaniso kukuba abantu ngokwenene benza imali ngayo.

Ukufumana ukufikelela kwiiakhawunti zabanye abantu

UTrey Ford: Imeko elandelayo esiza kuthetha ngayo kukwenza imali ngokuthatha iakhawunti yomnye umntu.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Wonke umntu uyalibala amagama ayimfihlo, kwaye kuvavanyo lokhuseleko lwesicelo, ukusetha kwakhona igama lokugqitha kunye nokubhaliswa kwe-intanethi kubonisa iinkqubo ezimbini ezicacileyo, ezigxilwe zoshishino. Kukho umsantsa omkhulu phakathi kokulula ukuseta kwakhona igama eligqithisiweyo kunye nokubhalisa lula, ngoko ke kufuneka uzame ukwenza inkqubo yokusetha ngokutsha i-password ibelula kangangoko. Kodwa ukuba sizama ukuyenza lula, ingxaki ivela kuba kulula ukuseta kwakhona igama eliyimfihlo, kokukhona likhuseleke kancinci.

Enye yezona meko ziphezulu zibandakanya ukubhaliswa kwe-intanethi usebenzisa inkonzo yokuqinisekisa umsebenzisi we-Sprint. Amalungu amabini eqela le-White Hat asebenzise i-Sprint yokubhalisa kwi-intanethi. Kukho izinto ezimbalwa ekufuneka uziqinisekise ukuze ungqine ukuba nguwe, uqale ngento elula njengenombolo yeselfowuni yakho. Udinga ukubhaliswa kwi-intanethi kwizinto ezifana nokulawula i-akhawunti yakho yebhanki, ukuhlawulela iinkonzo, njalo njalo. Ukuthenga iifowuni kulula kakhulu ukuba ungayenza kwiakhawunti yomnye umntu kwaye emva koko uthenge kwaye wenze okungakumbi. Enye yeenketho zobuqhetseba kukutshintsha idilesi yentlawulo, ukuyalela ukuhanjiswa kweqela lonke leefowuni eziphathwayo kwidilesi yakho, kwaye ixhoba liya kunyanzeleka ukuba lihlawule. I-Stalking maniacs ikwaphupha ngeli thuba: ukongeza ukusebenza kokulandela umkhondo weGPS kwiifowuni zamaxhoba kunye nokulandela yonke intshukumo yabo kuyo nayiphi na ikhompyuter.

Ke, iSprint ibonelela ngeyona mibuzo ilula yokuqinisekisa ukuba ungubani. Njengoko sisazi, ukhuseleko lunokuqinisekiswa nokuba luluhlu olubanzi kakhulu lwe-entropy, okanye yimiba ekhethekileyo kakhulu. Ndiza kukufundela inxalenye yenkqubo yokubhaliswa kwe-Sprint kuba i-entropy iphantsi kakhulu. Ngokomzekelo, kukho umbuzo: "khetha i-brand yemoto ebhaliswe kule dilesi ilandelayo," kwaye ukhetho lwe-brand yi-Lotus, i-Honda, i-Lamborghini, i-Fiat, kwaye "akukho nanye kwezi zingasentla." Khawutsho, ngowuphi kuni onayo kwezi zingasentla? Njengoko ubona, le iphazili icela umngeni lithuba nje elihle lokuba umfundi wasekholejini afumane iifowuni ezitshiphu.

Umbuzo wesibini: “Ngowuphi kwaba bantu balandelayo uhlala nawe okanye ohlala kule dilesi ingezantsi”? Kulula kakhulu ukuphendula lo mbuzo, nokuba awumazi kwaphela lo mntu. UJerry Stifliin - eli gama lokugqibela linama "ays" amathathu kuyo, siya kufika kuloo nto ngesibini - uRalph Argen, uJerome Ponicki noJohn Pace. Yintoni enika umdla kolu luhlu kukuba amagama anikiweyo awafaneli, kwaye onke axhomekeke kwipateni efanayo. Ukuba uyabala, ngoko awuyi kuba nobunzima ekuchongeni igama lokwenyani, kuba lihluke kumagama akhethiweyo ngokungaqhelekanga kwinto ethile, kulo mzekelo iileta ezintathu "i". Ke, i-Stayfliin ngokucacileyo ayililo igama elingaqhelekanga, kwaye kulula ukuqikelela, lo mntu ujolise kuye. Ilula kakhulu.

Umbuzo wesithathu: "kwesiphi kwezi zixeko zidwelisiweyo ongazange uhlale okanye awuzange usisebenzise esi sixeko kwidilesi yakho?" — Longmont, North Hollywood, Genoa okanye Butte? Sineendawo ezintathu ezixineneyo ezijikeleze iWashington DC, ke impendulo ecacileyo yiNorth Hollywood.

Kukho izinto ezimbalwa ekufuneka uzilumkele malunga nokubhaliswa kwe-Sprint kwi-Intanethi. Njengoko benditshilo ngaphambili, ungenzakala kakhulu ukuba umhlaseli uyakwazi ukutshintsha idilesi yokuthumela ngokuthenga kwiinkcukacha zakho zentlawulo. Eyona nto eyoyikisayo kukuba sinenkonzo ye-Mobile Locator.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Ngayo, unokulandelela iintshukumo zabasebenzi bakho, njengoko abantu basebenzisa iiselfowuni kunye ne-GPS, kwaye ungabona kwimephu apho bakhoyo. Ke kukho ezinye izinto ezintle ezinomdla ezenzeka kule nkqubo.

Njengoko usazi, xa useta kwakhona igama lokugqitha, idilesi ye-imeyile ithatha indawo yokuqala ngaphezu kwezinye iindlela zokuqinisekisa umsebenzisi kunye nemibuzo yokhuseleko. Isilayidi esilandelayo sibonisa iinkonzo ezininzi ezinikezela ngokubonisa idilesi ye-imeyile ukuba umsebenzisi unobunzima bokungena kwiakhawunti yakhe.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Siyazi ukuba abantu abaninzi basebenzisa i-imeyile kwaye bane-akhawunti ye-imeyile. Ngequbuliso abantu bafuna ukufumana indlela yokwenza imali ngayo. Uya kusoloko ufumanisa idilesi ye-imeyile yexhoba, ngenisa kwifomu, kwaye uya kuba nethuba lokuphinda umise igama lokugqitha kwi-akhawunti ofuna ukuyilawula. Emva koko uyisebenzise kuthungelwano lwakho, kwaye loo bhokisi yeposi iba yindlu yakho yegolide, eyona ndawo unokuthi ube zonke ezinye iiakhawunti zexhoba. Uya kufumana umrhumo wonke wexhoba ngokuthatha ibhokisi yeposi enye nje. Yeka ukuncuma, inzulu le!

Isilayidi esilandelayo sibonisa ukuba zingaphi izigidi zabantu abasebenzisa iinkonzo ze-imeyile ezihambelanayo. Abantu basebenzisa ngokukhutheleyo i-Gmail, i-Yahoo mail, i-Hotmail, i-AOL Mail, kodwa akufuneki ube yi-hacker ephezulu ukuze uthathe ii-akhawunti zabo, unokugcina izandla zakho zicocekile ngokukhuphela ngaphandle. Unokuhlala uthi akukho nto yakwenza nayo, awuzange wenze into enjalo.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo lesi-1

Ngoko ke, inkonzo ye-intanethi "yoBuyiselo lwephasiwedi" isekelwe e-China, apho uhlawula khona ukuba baqhekeze i-akhawunti "yakho". Nge 300 yuan, malunga ne-$43, ungazama ukuseta kwakhona igama lokugqitha lebhokisi yemeyile yangaphandle nge 85% izinga lempumelelo. Kuba 200 yuan, okanye $29, uya kuba 90% impumelelo ekusetheni kwakhona igama lokugqitha lebhokisi yemeyile yenkonzo yakho yasekhaya. Kubiza iwaka leeyuan, okanye i-$143, ukugqekeza kuyo nayiphi na ibhokisi yeposi yenkampani, kodwa impumelelo ayiqinisekiswanga. Unako kwakhona outsource iinkonzo password cracking 163, 126, QQ, Yahoo, Sohu, Sina, TOM, Hotmail, MSN, njl.

INkomfa EMNYAMA UMnqwazi USA. Yiba sisityebi okanye ufe: yenza imali kwi-intanethi usebenzisa iindlela ze-Black Hat. Icandelo 2 (ikhonkco liza kufumaneka ngomso)

Ezinye iintengiso 🙂

Enkosi ngokuhlala nathi. Ngaba uyawathanda amanqaku ethu? Ngaba ufuna ukubona umxholo onomdla ngakumbi? Sixhase ngokufaka iodolo okanye ngokucebisa abahlobo, ifu VPS kubaphuhlisi ukusuka $4.99, I-30% isaphulelo kubasebenzisi beHabr kwi-analogue ekhethekileyo yeeseva zomgangatho wokungena, eyenzelwe wena: Inyaniso yonke malunga neVPS (KVM) E5-2650 v4 (6 Cores) 10GB DDR4 240GB SSD 1Gbps ukusuka kwi-$ 20 okanye indlela yokwabelana ngomncedisi? (ifumaneka nge-RAID1 kunye ne-RAID10, ukuya kuthi ga kwi-24 cores kunye ne-40GB DDR4).

I-Dell R730xd 2 amaxesha aphantsi? Kuphela apha 2 x Intel TetraDeca-Core Xeon 2x E5-2697v3 2.6GHz 14C 64GB DDR4 4x960GB SSD 1Gbps 100 TV ukusuka $199 eNetherlands! Dell R420 - 2x E5-2430 2.2Ghz 6C 128GB DDR3 2x960GB SSD 1Gbps 100TB - ukusuka $99! Funda malunga Ulwakha njani umbutho weziseko zophuhliso. iklasi ngokusetyenziswa kwe-Dell R730xd E5-2650 iiseva ze-v4 ezixabisa i-9000 yee-euro ngepeni?

umthombo: www.habr.com

Yongeza izimvo