ukgent2's comments

ukgent2 | 13 years ago | on: The Olympics' Greatest Feat: An Unpaid, Highly Engaged Workforce

Maybe it’s the "I am doing this for free so I can be myself"

All personal option below, Friday afternoon ramble Example when starting a new job, most people purposely hold back expressing themselves, they just want to fit in and keep people happy. There is a fear of over stepping boundaries, saying something that someone might take offensive all contribute to this “shut up and do your job”. The issue is that it’s hard to get a job, and people don’t want to rock the boat so heads down and work because the job is tied to their ability to live.

The People at the games have nothing to lose, no expectations, they are free to enjoy and present themselves as they wish. Someone in a job at a desk in a call centre for a bank does not get that freedom and never will. The bank needs that person answering phones as quickly as possible to make their wall board stats look good so their managers can get bonuses.

This whole article was interesting from the point of a small company and how a smaller company could empower its staff to enjoy their roles more and in turn the new hire staff they bring in would follow the same patterns. For main street corporates this is the last thing they want, cutting away efficiency for what? Staff that enjoy their jobs, ha-ha don’t be foolish drones are easier to control, also the people attracted to upper management jobs are generally in it for the money more than the “lets make a warm and happy team and all live happily ever after”

The guy writing this bit was getting excited over the idea of an energized work force for free, everyone likes the personal touch however in customer service roles they are given scripts and told what to say and how they should say it and told that if they step out of line or say something that is wrong they could lose their incoming and in turn the ability to live their life (who has savings anymore?) until they get another hard to find job.

If you do something for free you can do what you like, worse case you get sent home, in a job you can lose your job over expressing an option or spending too much time trying to help a single customer and in turn you lose your incoming (ability to live). No wonder people are more held back and reserved in their paying jobs than when they offer to do something for free.

/ramble

ukgent2 | 13 years ago | on: NSA Careers for DEF CON Attendees

Because its all doublespeak, protect and serve, while attacking and exploiting, just word games, trying to spin the NSA in to a good light. The Defcon talk by the NSA head guy was pretty much the same, doublespeak all the way. In the UK we have GHCQ trying to do the same things their advert was a little more interactive http://www.canyoucrackit.co.uk/

ukgent2 | 13 years ago | on: Beware of blind elitism

funny I go to the website and get Access Denied

The owner of this website (www.tnl.net) has banned your access based on your browser's signature

Seems he does not like browsers that strip all their headers. Is this an Ironic joke that I am not getting?

ukgent2 | 13 years ago | on: Dissecting the SSL handshake

My Approach is not very scintific I am very new to all this magic, I used the following websites http://www.google.co.uk/search?q=whats+my+ip this should bring up Googles view of your IP http://www.whatsmyip.org/ A classic view of IPaddy http://www.xhaus.com/headers For a view of the headers currently being leaked by the browser

Now I was setting up my proxy as I was doing these said tests so it was work in progress, First checked it all out with no changes to the headers. Then I started stripping the headers a few at a time to see the differences between the above websites and a few others. Now my IP changed as soon as I did an x-forward no change in the proxy configration. At this stage 99% of websites get the IP of the proxy, I was happy. however Google still was giving me my real IP. More header striping later and pinned it down to the user_agent. I know the user agent does not contain any IP information but I think google must be using it as part of the IDing of the broswer profile

My main point today was that this SSL handshaking leaks lots of information that appears to be able to see real IP behind a proxy. The bad man in side of myself now wonders if I could knock up a script like https://p0f.popcnt.org/ that can see passed a proxy to get real IP addresse not that I would have anywhere interesting to put it, guess it is just the fun of doing it.

Now I completely believe that my proxy could be just badly setup, so I also tested the p0f page on a number of elite proxies (public not private or paid) and the p0f page gives up the real IP every time.

As i said, I will try the tor broswers to night (sidenote I only really test firefox because Chrome and IE lift proxy settings from the local system where as firefox is customizable

Oh i used your header page, very nice http://my-addr.com/ip (thank you), all headers are empty and it has the correct IP (proxyed)

Sorry for spelling, :/ notepad lacks a spell:checker

ukgent2 | 13 years ago | on: Dissecting the SSL handshake

Interesting,

This method of fingerprinting bypasses "elite" anon proxies and gives away IP addresses and OS of the host. Google currently employs a number of tricks to get real IP addresses, you can run a connection via a proxy and 99% of websites you visit will only get the Proxy IP, Google has a way of getting IP from User_Agent (not sure how but I was building my own proxy last week and found this out).

Will check the tor bundle later (as they are better configured) but I believe they will be harden against this, I dont know how I could make firefox in a default configuration stop leaking this information without cripping my install, anyideas?

ukgent2 | 13 years ago | on: Setting out plans to monitor all Internet use in the UK

Lets add my 2 centz

I dont consider myself any form of hacker, I dont think i do anything illegal on the interweb. However i am very for privacy on the internet and against goverment monitoring.

When SOPA and CISPA etc all came about my first port of call was to get off gmail and on to my own webserver on a VPS. 2 weeks ago i deicded it was time to create my own elite anon proxy using squid. Took a few days of tinkering (sidenote did you know that google can get your IP via user_agent header? took me ages to work out why all the sites but google were getting my VPS IP and yet google could see right passed it and get my orignal IP)

now I am posting to this topic using said proxy. I can bet that once all these systems go live I will be one of the first pulled up as a terroist. I have VPNs to 2 countries, and 2 machines route out over those, i have very little standard traffic going via my ISP, and i use external DNS (currently in the process of setting up my own bind server).

I am even in the process of setting up my own jabber server (what did google rename it to xxmp?) and using that as a replacement for MSN/Skype interaction thing with my friends.

All of the above will classify me as a terroist under the UKs ever watchful eyes, I think now I am going to route my proxy in to tor for extra funz

ukgent2 | 14 years ago | on: If you think O2 headers are bad, check this out.

Sorry but this is a null issue, I have Text message APIs that allow me to specify the sender ID. I understand your app is sexy in that it works off the phone but anyone with a few pounds can do this.

Text message spoofing is easy, CLI spoofing is the "cool" thing todo, and if you can spoof the Passert ID then you are gold

ukgent2 | 14 years ago | on: UK network o2 send your number to every site you visit

UK South Iphone 4s Headers in plain sight

Called o2 support, stating I believe this is a breach of contract and wish to cancel my contract. The guy on the phone was not really sure how to handle this. Does anyone had any luck forcing o2 to cancel their contract based on this information? I kinda like Orange, no headers, and orange wednesdays

ukgent2 | 14 years ago | on: Over 40% of cancers due to lifestyle, says review

It depends on the person,

I got a nan, 96, walks to town 3 times a week, still rides her bike, been smoking 60 a day for 40 years, and recently cut back to 40. If i compare her to my other nan 86 frail and pretty much falling apart, now guess which one has had the better lifestyle? the second, very well off always comfortable.

At 96 i think she gets up to keep smoking, and if that keeps her alive then keep doing it.

ukgent2 | 14 years ago | on: WikiLeaks Posts Spy Firm Videos Offering Tools For Hacking iTunes, Gmail, Skype

I work with gamma as a UK telephone operator. The divsion of gamma that was involed with this was gamma international. Where as Gamma for UK is a pretty much a seperate company. One of those things where the right hand does not know what the left hand is doing.

looking at their website, they dont seem linked in anyway :/ https://www.gammagroup.com/Default.aspx maybe they are not part of each other but just share a name.

page 1