Jump to content

Gouki

Member
  • Posts

    1,131
  • Joined

  • Last visited

  • Donations

    0.00 USD 
  • Country

    Portugal

Posts posted by Gouki

  1. People can get a better understanding of what CAPTCHA is by reading this wiki page.

    For a couple of years (?) now, implementations of CAPTCHA were ugly and funless. Allot of sites have been implementing this technology to verify that in fact, there is a user behind the computer and not just a bot trying to spam some Digg articles or registering on MSFN. The implementation was fairly simple and basic. A image that would be hard for a computer (computer as in bot) to 'dechiper' but easy for a human being.

    A new form of this security measure has been invented, involving cats. You can test it here.

    Older versions (and the ones that are implemented now), are easy to break. Different IPs addresses could be trying different combinations until one finnaly is correct. The different IP addresses would allow the attacker not to be blocked for abusing the service. Experts believe that this new form of human verification will give much better results, however, I dont think that's the case.

    If only one person uses this (wich is not going to happen), he will be really 'safe'. However, as people start to adpot this new verification process, attacks will start to appear.

    The method used is a 3x3 grid with 3 kittens. On the total of 9 available images, only 3 are the correct ones. That makes a total combination number of 84 possible correct 'answers'.

    Something that the author forgot was that, if the kittens database (never thought I used db and kittens on the same sentence) has a small number of kittens, a user could educate a computer and tell him (him as in PC) wich ones are the kittens). Of course having a 10.000+ database of kittens is not a option, so we can expect some major hacks on this method.

    To make things even more fun, consider adding some sort of image recognition to the bot. :)

    I know some people will take this is allot more than what we actually need to protect spam on Digg (for i.e), but maybe having some sort of sound would be a nice idea. A rock sound was played, and the user would have to click Ozzy Osbourne image.

    So, what do you think about this new 'brilliant' method?

    Speaking of Digg, I just found this submitted. Digg it ;)

  2. Welcome to MSFN.

    Asking questions here is not a good idea. I suggest you post your questions/problems on the appropriate forum.

    Before you do, consider reading the rules (link on my sig).

    Once again, welcome to MSFN. Enjoy ;)

  3. Thanks. I have been reading allot about TOR, since I want to know exactly what I am doing before I make my server another node on the network.

    Going threw the code is *not* an option. Like you said, being OSS, if there was anything suspicious there, they would have found it. However, I doubt it. After all the problems JAR had, wich backdooring, I don't think TOR will make the same mistake.

    As for Mrs. Peel ... I searched but I did not find her account. It would be good to have an expert on TOR to discuss it with us.

  4. A recent post by RogueSpear on the F/OSS List thread reminded me of TOR. I was really into it a couple of months ago, I actually started to build a server that would be on the TOR network, however, time passed and I completly forgot (I will finish the server and make it a TOR node).

    Now that it came to my mind, I was wondering if MSFN users, like/use TOR, and their impressions about it.

    I have read many articles saying TOR is a Honeyspot, however, and looking at their host (eff.org), I dont think that's possible. Having a backdoor is something that I dont believe also, however, I could be wrong.

    So, what do you think about it people?

  5. Well, I'm not gonna try it, because I have no use for it, still I like the idea of having a Live CD Distribution that enables us to use all of our home computers to make a cluster.

    More information can be found on this site and a tutorial on how to make your own cluster here.

    Downloads here.

    Go ahead and tell NASA who is the boss!

  6. Hello and Welcome to MSFN.

    As for your Vista problems, I have to remember you that Vista is still in BETA phase, therefor, there will be erros and bugs.

    Vista is not intended to be the main OS of a computer, but a sneak peak of a future OS from Microsoft.

    I hope you enjoy MSFN. Take care mate.

  7. Hello Fulvian and Welcome to MSFN :)

    Yes, you are correct. Gouki, also known as Akuma, is a Street Fighter character's name, my favorite along with Ryu ... I know, big SF geek.

    His post count is 0 because posting on this Forum (Introduce Yourself) does not count towards post count. (All other forums do)

    I would also like to ask you to please change your signature, otherwise a SMOD will have to edit it for you.

    Images in signatures shall NOT exceed a total of 300x100 and 80kb. Flash and animated sigs are not permitted. You can enter max 4 lines of text in signature or signature image. Advertising and/or affiliates are not allowed in signatures nor avatars. Avatars are to be a maximum of 100x100 pixels. If your avatar or signature goes above these guidelines they will be taken off without notice. Any signatures found to be attached to a thread and used as a signature host is not allowed on MSFN and will be removed. Members with slow connection can disable other members signatures when reading posts by going to: My Control - Options - Board Settings.

    Take care and enjoy MSFN.

  8. Well, I hope your opinion about Microsoft and Windows changes in the days/months or even years to come here at MSFN.

    Allot of people like to trash talk Windows ... Most of the time, is their fault that it doesn't work the way it should.

    I hope you enjoy MSFN! See you in the forums.

  9. Yes. That would help, allot. However, that would not make it completly secure (Well, *nothing* is totally secure).

    Implementing an on screen keyboard would help allot, however, there are 'keyloggers' for mouse movements. Randomly changing the buttons from the on screen keyboard, every time it starts, would be a solution to this.

    My bank has it and it works like a charm.

  10. I was doing my daily reading (wich is allot), and I found this article explaining how Bill Gates works.

    *Allot* of people don't like him. For X, Y and Z reasons, however, I really appreciate his work and admire him. (Let the 1337 comments begin!)

    It was an interesting reading.

    P.S: Definatly not MSFN first page material, still, interesting.

  11. First, PLEASE read this forum rules.

    As for your 'problem' ...

    Physical access to machines (no need to Operating System access), is a pretty good problem. Big part of Keyloggers can be connected between the keyboard and the computer. Invisable to the 'distracted' eye, since they are really small 'gadgets'.

    As for software based keyloggers, I think the best idea is to instruct users (in a company scenario) to be carefull with eMails and IM. Other than that, maybe keeping an eye open on the services running.

    Take care.

    P.S: Please try and follow the rules the next time.

×
×
  • Create New...