Showing posts with label TUTORIALS. Show all posts
Showing posts with label TUTORIALS. Show all posts

Monday, 17 October 2011

0

Cool Fake Viruses to Make Your Friends Freak Out!!!!!!

  • Monday, 17 October 2011
  • PRABH KARAN SINGH
  • I love it because it looks the most like an actual attack.
    Copy and paste the following into an open Notepad window, then save the file with any name you choose and an extension of “.bat”

    Here’s the code:

    cls
    :A
    color 0a
    cls
    @echo off
    echo Wscript.Sleep
    echo Wscript.Sleep 5000>C:sleep5000.vbs
    echo Wscript.Sleep 3000>C:sleep3000.vbs
    echo Wscript.Sleep 4000>C:sleep4000.vbs
    echo Wscript.Sleep 2000>C:sleep2000.vbs
    cd %systemroot%System32
    dir
    cls
    start /w wscript.exe C:sleep3000.vbs
    echo Deleting Critical System Files…
    echo del *.*
    start /w wscript.exe C:sleep3000.vbs
    echo Deletion Successful!
    start /w wscript.exe C:sleep2000.vbs
    echo:
    echo:
    echo:
    echo Deleting Root Partition…
    start /w wscript.exe C:sleep2000.vbs
    echo del %SYSTEMROOT%
    start /w wscript.exe C:sleep4000.vbs
    echo Deletion Successful!
    start /w wscript.exe C:sleep2000.vbs
    echo:
    echo:
    echo:
    echo Creating Directory h4x…
    cd C:Documents and SettingsAll UsersStart MenuPrograms
    mkdir h4x
    start /w wscript.exe C:sleep3000.vbs
    echo Directory Creation Successful!
    echo:
    echo:
    echo:
    echo Execution Attempt 1…
    start /w wscript.exe C:sleep3000.vbs
    echo cd C:Documents and SettingsAll UsersStart MenuProgramsStartuph4x
    echo start hax.exe
    start /w wscript.exe C:sleep3000.vbs
    echo Virus Executed!
    echo:
    echo:
    echo:
    start /w wscript.exe C:sleep2000.vbs
    echo Disabling Windows Firewall…
    start /w wscript.exe C:sleep2000.vbs
    echo Killing all processes…
    start /w wscript.exe C:sleep2000.vbs
    echo Allowing virus to boot from startup…
    start /w wscript.exe C:sleep2000.vbs
    echo:
    echo:
    echo Virus has been executed successfully!
    start /w wscript.exe C:sleep2000.vbs
    echo:
    echo Have fun!
    start /w wscript.exe C:sleep2000.vbs
    pause
    shutdown -s -t 10 -c “Your computer has committed suicide. Have a nice day.”
    Here’s how it will look like once it is launched:


    NOTE :- This is not a virus ...........only a script to have fun with your friend ...........


     Subscribe us via E-mail and Add us on Facebook for daily updates and Plz also do click once on the ads displaying below or above the post for us.. :)
    Read more...

    Sunday, 16 October 2011

    0

    What You Need to Do to Recover from a Virus Attack!!!!!

  • Sunday, 16 October 2011
  • PRABH KARAN SINGH
  • Viruses are costly and can try your patience and resources. If your system has been compromised, there are several key steps to get up and running again as soon as possible. Learn about how to remove a virus and restore your system. And remember, prevention is always the best security policy.

    Bad news—you've suffered a virus attack. Take a few seconds to get over the initial shock, but only a few seconds.

    Once a virus sidesteps your security defenses, it can quickly rip through your system, destroying files, corrupting data, rendering applications useless, and in general causing an expensive lull in productivity. You need to act immediately. Follow the steps below to remove the virus and restore your system.
    1. Disconnect and isolate. Think of it as putting the infected computer into quarantine. If you suspect that a computer has been attacked by a virus, physically disconnect the machine. An infected machine can endanger other computers.
    2. Clean up. Once the computer has been disconnected, you need to remove the malicious code. Use removal tools written for the specific virus. Your antivirus software should have updates or patches available for the specific security threat. If this software hasn't been updated recently, be sure to do so. Symantec Security Response makes both removal tools and updated definitions available as soon as a threat is discovered. General information, new alerts, and step-by-step guides are available on the Symantec Security Response site.
    3. Restore. After a virus attack, damages may range from changed file names to obliterated files to permanently disabled software applications. Before resuming work, you need to restore your computer to its original condition.
    4. Reinstall. The extent of damage depends on the particular virus. If your operating system is completely destroyed, you'll need to reinstall. Use the 'quick restore' CD that came with your computer to restore your computer to its original configuration. This means that you will lose any applications you may have installed or data files you may have saved. Before you begin the reinstallation process, make sure you have all the necessary information handy - original software, licenses, registration, and serial numbers.
    5. Scan for viruses. After restoring and reinstalling, scan your entire network, including all files and documents, for viruses. Use the most recent virus definitions available for your antivirus software.
    6. Restore your data. This assumes that you have been diligent about backing up your files. If you don't follow a regular schedule of backups, your files will be permanently lost. If this is the case, learn from your mistake and make sure to back up regularly from now on. Keep in mind, not all viruses target data files – some attack only applications.
    7. Prevent future attacks. Run antivirus software and keep virus definitions current. Ensure security patches are up-to-date. If you haven't been running antivirus software, start now!If you lost data files in the recent attack, you will want to create and enforce a regular backup schedule. Next, you will want to change all passwords, including ISP access passwords, FTP, email, and Web site passwords. Some viruses can capture or crack passwords, leading to future vulnerabilities. Change passwords immediately.

     
     Subscribe us via E-mail and Add us on Facebook for daily updates and Plz also do click once on the ads displaying below or above the post for us.. :)
    Read more...

    Wednesday, 24 August 2011

    0

    How To Install Windows Xp,Vista And 7 From Usb

  • Wednesday, 24 August 2011
  • PRABH KARAN SINGH
  • You can install any version of windows like windows xp,vista,7,2003,2008 using usb drive.
    This tutorial doesnot uses the command prompt method for installing windows from usb instead I will give you a new and a simpler method to install the windows from the usb drive.

    For this tutorial we will require the following things. 
    • Windows Dvd or ISO image
    • Optical drive emulation software( like demon tools)
    • Wintoflash software
    • USB drive (minimum 4 gb)     
    How To Install Windows Xp,Vista And 7 From Usb.....

    1.Download and Install Demon tools.Click here to download
    (Note:Skip this step if you already have any other optical drive emulation software or Windows Dvd)

    2.Mount the windows ISO Image using demon tools.

    3.Now Download  Wintoflash Software.Click here to download .

    4.Extract Wintoflash rar folder and click on Wintoflash.exe.This software doesnot require installation.

    5.Now click on Advanced Mode Tab in the Wintoflash window.

    6.It will give you various options.Select the one that you want to perform.
     

    7.Now it will ask you for the path of your windows.Give the address of the mounted windows drive or the dvd drive(if you have windows dvd) and also give the path of the usb drive .


    8.Click on Run.

    9.It will warn you that you usb will be formatted continue with it and it will convert your usb into bootable windows usb drive.

    10.Restart your computer and change the boot order in your BIOS .



     Subscribe us via E-mail and Add us on Facebook for daily updates and Plz also do click once on the ads displaying below or above the post for us.. :)

    Read more...

    Tuesday, 16 August 2011

    0

    How To Enable, Disable Changing Desktop Icons In Windows 7

  • Tuesday, 16 August 2011
  • PRABH KARAN SINGH
  • 1. Login to your Windows 7.
    2. Type gpedit.msc in the RUN.


      3. In the Local Group Policy Editor window, propagate to Local Computer PolicyUser Configuration –> Administrative Templates –> Control Panel –> Personalization in the left panel’s tree view.

    4. In the right side panel, scroll the list to find Prevent changing desktop icons. Double click on this entry.

    5. In the following window titled ‘Prevent changing desktop icons’, select the Enabled radio button and click OK to apply the changes.


     Now when you go to the Personalization screen, you will see that the Change desktop icons feature is disabled. When you click on it, you get a message that says “Your system administrator has disabled launching of the Display Control Panel”.


    To Enable changing the desktop Icons again, follow the same steps given above. Only in step 5, you have to choose the option “Not Configured” and Click OK.

    Subscribe us via E-mail and Add us on Facebook for daily updates and Plz also do click once on the ads displaying below or above the post for us.. :)
    Read more...

    Monday, 15 August 2011

    0

    How To Enable, Disable Changing Desktop Background In Windows 7

  • Monday, 15 August 2011
  • PRABH KARAN SINGH
  • Changing desktop background is very easy. One can easily right click on a image and ‘Set as desktop background’. You have a favorite image which you set as desktop background. Later you don’t want any other users of your Windows 7  to change the desktop background. You can prevent changing desktop background on your PC. Follow the steps below:

    1. Login to Windows 7  .
    2. Type ‘gpedit.msc’ in the Run.


                                       

    3. This will launch Local Group Policy Editor. In the left pane propagate to:
    User Configuration –> Administrative Templates –> Control Panel –> Personalization

    4.  In the right pane, double click on “Prevent changing desktop background”.

     
    .
    5. In the “Prevent changing desktop background” window, select “Enabled” option.



    6. Click Apply and then OK.
    To check whether what you have done is working, right-click on desktop and choose “Personalize”. The option “Desktop Background Slide Show” will be grayed out. Also right-click on any image and “Set as desktop background” will do nothing.


    To enable changing the desktop background image again, follow the same steps.

    Except in step 5, choose option “Not Configured” and Click OK.


    Subscribe us via E-mail and Add us on Facebook for daily updates and Plz also do click once on the ads displaying below or above the post for us.. :)

    Read more...
    0

    How to Enable Run Command in Start Menu in Windows 7

  • PRABH KARAN SINGH
  •  1. Right click on any open area in the start menu and select Properties.


    2. Select the Start Menu tab in the properties window and click Customize button.





    3. In the customize window, check the box against Run Command and click OK.




     Now if you open the Start Menu, you can see the Run Command added to it.


     Subscribe us via E-mail and Add us on Facebook for daily updates and Plz also do click once on the ads displaying below or above the post for us.. :)

    Read more...

    Monday, 8 August 2011

    0

    How to Change IP Address in Windows

  • Monday, 8 August 2011
  • PRABH KARAN SINGH
  • many people wants to change their IP address to fix a network related issue, for security purposes. Whatever reason, someone has already asked how can I change my IP address? So here we are to tell you how to change IP adddress step by step with the screen shots.


    Changing IP Addresses in Windows

    Step 1:- Right click on ‘My Network Places’ and click ‘Properties’.

    Step 2:- Then,  click on ‘Local Area Connection’ a new window will be open.


    Step 3:- Select ‘Properties’ again a new window will be open.


    Step 4:- Select ‘Internet Protocol version 4(TCP/IPv4)’ and then click on ‘Properties’button and again a new window will be open.



    Step 5:- Select ‘Use the following IP address’ and in the IP address box give the IP address whatever you want according to your network range and Click ‘OK’. You had done you now your IP address has changed.


    Subscribe us via E-mail and Add us on Facebook for daily updates and Plz also do click once on the ads displaying below or above the post for us.. :)
    Read more...

    Tuesday, 2 August 2011

    3

    HOW TO DO SUBNETTING

  • Tuesday, 2 August 2011
  • PRABH KARAN SINGH
  • Today i am going to tell you about Subnetting and how to do it. A subnetwork, or subnet, is a logically visible subdivision of an Internet Protocol (IP) network. All computers that belong to a subnet are addressed with a common, identical, most-significant bit-group in their IP address. A means of making a splitting a single IP address into multiple network addresses. It is accomplished by mathematically combining an IP address with another set of numbers called a Network Mask. The process of subdividing a Class A, B, or C network and into smaller portions called Subnets.

     Seven Steps to Subnetting

    Creating Class C Subnetting Scheme

    Basic subnetting is very easy when performed in seven steps. This example uses the Class C address 211.212.10.0. Using the seven steps provided here, you can create a subnetting scheme that allows you to use this address on your network.

    Step 1: Determining Number of Subnets Needed

    Determining the number of subnets you need is the very first step in subnetting. The number really depends upon your particular network. In Figure the network consists of three routers connected via serial links. Each router also has a single Ethernet network attached.

    Each shared serial link requires one subnet. Therefore, you need two subnets for the serial links between Router A and Routers B and C. You must also have one subnet per Ethernet interface on each router. Since you have three Ethernet networks, you need three subnets. Using this very simple counting method, you find that you need a total of five subnets. Unfortunately, you have been assigned a Class C address. The network address 211.212.10.0 allows for a single network of 254 hosts. You must borrow host ID bits to make this address work for you.

    Step 2: Determining Number of Bits You Can Borrow

    In Step 2, you must determine the number of bits that you can borrow. This number changes depending on the type of network address you start with. For Class A addresses, you have 24 host ID bits, but you can only borrow up to 22. For Class B addresses, you have 16 host ID bits, but you must have a minimum of two host bits; therefore, you can borrow 14 bits. Your Class C address (211.212.10.0) has eight totalhost ID bits, but you can only borrow a maximum of six. The easiest way to determine the number of bits you can borrow is to write the number of octets that contain host ID bits in binary. In the Class C example network 211.212.10.0, you have the following bits to “play” with: 00000000

    Step 3: Determining Number of Bits You Must Borrow to Get Needed Number of Subnets

    After you determine the number of subnets you need and the number of bits you can borrow, you must calculate the number of host ID bits you must borrow to get the needed number of subnets. The formula for determining the number if bits you must borrow is 2n-2= # of subnets. The n represents the number of bits you borrow. In other words, raise two to the power of the number of bits you borrow and subtract two from that number. The result is the number of useable subnets created when you borrow that number of bits. For the example network, you need five subnets. If you borrow three bits, the formula’s result is six usable subnets: 23 = 8-2 = 6.

    Step 4: Turning On Borrowed Bits and Determining Decimal Value

    In Step 4, using the bits you determined were available in Step 2, you turn on (set to 1) the number of bits determined you must borrow in Step 3. You must always begin with the high-order bits (the bits starting on the left of a binary number). Using the number of bits you can work with and the number of bits you must borrow (from Step 3), your result is the following: 11100000. In other words, from the eight total bits from Step 2 (six of which you could borrow), you borrow three host ID bits. In Step 4, you also need to determine the decimal value of the octets from which you borrow host ID bits. In this example, 11100000 equals 224. (128 + 64 + 32 = 224)

    Step 5: Determining New Subnet Mask

    Step 5 calculates the new subnet mask after you borrow the host ID bits in Step 4. You must add the decimal value from Step 4 to the default subnet mask for the class of address you are subnetting. The example is a Class C address, so the default mask is 255.255.255.0. The new mask after borrowing three bits becomes 255.255.255.224.

     Step 6: Finding Host/Subnet Variable

    In Step 6, you must find the lowest of the high-order bits (bits starting from the left) turned “on.” Step 6 takes you all the way back to earlier in the chapter to the values found in each bit position within the octet. Our example defines the octets from which we borrow as 11100000. The highest order bit turned on represents 25, which equals 32. Since 25 is the last high-order bit turned on, the Host/Subnet variable you use in Step 7 is 32.

    Step 7: Determining Range of Addresses

    The final step allows you to take the Host/Subnet variable from Step 6 (32) and create your subnet ranges. Using the Class C network above, the range of subnets when you borrow three bits are:
    211.212.10.0 to 211.212.10.31
    211.212.10.32 to 211.212.10.63
    211.212.10.64 to 211.212.10.95
    211.212.10.96 to 211.212.10.127
    211.212.10.128 to 211.212.10.159
    211.212.10.160 to 211.212.10.191
    211.212.10.192 to 211.212.10.223
    211.212.10.224 to 211.212.10.255

    IP addresses cannot be all ones or all zeros; therefore, in most cases the first range of addresses and the last range of addresses are unusable. (In some special circumstances, you can use the first range of addresses, or subnet 0. Only certain manufacturers’ equipment, such as Cisco Systems, fully supports the use of subnet zero.) In each subnet, the first IP address is unusable because it represents the subnet ID. The final address is also unusable because it is the broadcast address for the subnet. Due to these two restrictions, in subnet one, 211.212.10.33 is the first useable host ID and 211.212.10.62 is the last useable host ID.

    Tailoring a Class B Address

    This example takes a Class B address and tries to fit it within the needs of a network containing 1000 subnets. You are assigned the Class B address 131.107.0.0. Using the following seven steps, you are going to subnet the Class B address to meet your needs.

    Step 1: Determining Number of Subnets Needed

    Examine your network and determine your needs based on current network configuration and future growth (in this case, 1000 subnets).

    Step 2: Determining Number of Bits You Can Borrow

    With this Class B network address, you have 16 total bits to work with. You can only borrow up to 14 of these. On your sheet of paper, you should write the number of bits you have in the host ID portion of the address: 00000000.00000000

    Step 3: Determining Number of Bits You Must Borrow to Get Number of Subsets Needed

    Using the formula 2n-2= # of usable subnets, you can easily see that you need to borrow 10 bits. When you plug in 10 borrowed bits, you get the following result:
    210 = 1024 – 2 = 1022 useable subnets

    Step 4: Turning on Borrowed Bits and Determining Decimal Value
    If you turn on 10 bits, you get the following:
    11111111.11000000
    The decimal values for the octets are 255.192.

    Step 5: Determining New Subnet Mask

    Your example is a Class B address. In Class B addresses, the default subnet mask is 255.255.0.0. To get your new mask, you add the default mask to the decimal values found in Step 4. The new mask becomes:
    255.255.255.192

    Step 6: Finding Host/Subnet Variable

    In the next-to-last step, you must find the value of the lowest high-order bit turned on in each octet, from which you borrowed host bits. Since this example is a Class B network and you must borrow a great number of bits to get the proper number of subnets, the borrowing crosses an octet boundary. As a result, you have two Host/Subnet variables. In this example, the variable in the third octet is 1, and the variable for the fourth octet is 64. You get these values by looking at the binary numbers in Step 4. The third octet has the final bit position, or the 20 bit position, turned on. Since 20 = 1, your variable is 1 in the third octet. In the fourth octet, the second high-order bit or 26 is turned on. The variable in this octet is 64.


    Step 7: Determining Range of Addresses

    Figuring the range of addresses for Class B networks is much harder than for Class C. This is especially true in cases like this scenario in which you must borrow a large number of bits. Using 1 as the variable in the third octet and 64 as the variable in the fourth octet, the range of the first 9 subnets world be:
    131.107.0.0 to 131.107.0.63
    131.107.0.64 to 131.107.0.127
    131.107.0.128 to 131.107.0.191
    131.107.0.192 to 131.107.0.255
    131.107.1.0 to 131.107.1.63
    131.107.1.64. to 131.107.1.127
    131.107.1.128 to 131.107.1.191
    131.107.1.192 to 131.107.1.255
    131.107.2.0 to 131.107.2.63

    Subscribe us via E-mail and Add us on Facebook for daily updates and Plz also do click once on the ads displaying below or above the post for us.. :)


    Read more...

    Monday, 1 August 2011

    0

    Packet Header Analysis

  • Monday, 1 August 2011
  • PRABH KARAN SINGH
  • Following are the easy to analyze ICMP, TCP and UDP packet headers along with short description.
    All header Drawings by- "Matt Baxter" (www.fatpipe.org/~mjb/Drawings/)



    ICMP-Header

    ICMP Message Types :- ICMP message type-code/name format
    0 Echo Reply
    3 Destination Unreachable
    4 Source Quench
    5 Redirect
    8 Echo
    11 Time Exceeded
    12 Parameter Problem
    13 Timestamp
    14 Timestamp Reply
    15 Information Request
    16 Information Reply

    Checksum :- The checksum is the 16-bit ones's complement of the one's complement sum of the ICMP message starting with the ICMP Type.

    RFC 792 :- Please refer to RFC 792 for Internet Control Message Protocol (ICMP) Specification.



    TCP-Header

    TCP Flags :- C E U A P R S F
    C 0x80 Reduced (CWR)
    E 0x40 ECN Echo (ECE)
    U 0x20 Urgent
    A 0x10 Ack
    P 0x08 Push
    R 0x04 Reset
    S 0x02 Syn
    F 0x01 Fin
    TCP Options :-
    0 End of Options List
    1 No Operation (NOP, Pad)
    2 Maximum Segment Size
    3 Window Scale
    4 Selective ACK ok
    8 Timestamp

    Checksum :- Checksum of entire TCP segment and pseudo header (parts of IP header)

    Offset :- Number of 32-bit words in TCP header, minimum value of 5. Multiply by 4 to get byte count.

    RFC 793 :- Please refer to RFC 793 for Transmission Control Protocol (TCP) Specification.



    UDP-Header

    Source Port :- an optional field, when meaningful, it indicates the port of the sending process, and may be assumed to be the port to which a reply should be addressed in the absence of any other information. If not used, a value of zero is inserted.

    Destination Port :- Destination Port has a meaning within the context of a particular internet destination address.

    Length :- Length is the length in octets of this user datagram including this header and the data. (This means the minimum value of the length is eight.)

    Checksum :- Checksum is the 16-bit one's complement of the one's complement sum of a pseudo header of information from the IP header, the UDP header, and the data, padded with zero octets at the end (if necessary) to make a multiple of two octets.

    RFC 768 :- Please refer to RFC 768 for User Datagram Protocol (UDP) Specification.

    Subscribe us via E-mail and Add us on Facebook for daily updates and Plz also do click once on the ads displaying below or above the post for us.. :)
    Read more...

    Wednesday, 27 July 2011

    0

    Methods of Password Hacking

  • Wednesday, 27 July 2011
  • PRABH KARAN SINGH
  • Password cracking is the process of recovering secret passwords from data that has been stored in or transmitted by a computer system. A common approach is to repeatedly try guesses for the password.
    Most passwords can be cracked by using following techniques :


    1) Hashing :- Here we will refer to the one way function (which may be either an encryption function or cryptographic hash) employed as a hash and its output as a hashed password. If a system uses a reversible function to obscure stored passwords, exploiting that weakness can recover even 'well-chosen' passwords.
    One example is the LM hash that Microsoft Windows uses by default to store user passwords that are less than 15 characters in length.
    LM hash breaks the password into two 7-character fields which are then hashed separately, allowing each half to be attacked separately.


    Hash functions like SHA-512, SHA-1, and MD5 are considered impossible to invert when used correctly.


    2) Guessing :- Many passwords can be guessed either by humans or by sophisticated cracking programs armed with dictionaries (dictionary based) and the user's personal information. Not surprisingly, many users choose weak passwords, usually one related to themselves in some way. Repeated research over some 40 years has demonstrated that around 40% of user-chosen passwords are readily guessable by programs.


    Examples of insecure choices include:


    * blank (none)
     * the word "password", "passcode", "admin" and their derivatives
     * the user's name or login name
     * the name of their significant other or another person (loved one)
     * their birthplace or date of birth
     * a pet's name
     * a dictionary word in any language
     * automobile licence plate number
     * a row of letters from a standard keyboard layout (eg, the qwerty keyboard -- qwerty itself, asdf, or qwertyuiop)
     * a simple modification of one of the preceding, such as suffixing a digit or reversing the order of the letters.
    and so on....


     In one survery of MySpace passwords which had been phished, 3.8 percent of passwords were a single word found in a dictionary, and another 12 percent were a word plus a final digit; two-thirds of the time that digit was.
    A password containing both uppercase &  lowercase characters, numbers and special characters too; is a strong password and can never be guessed.




    Check Your Password Strength




    3) Default Passwords :- A moderately high number of local and online applications have inbuilt default passwords that have been configured by programmers during development stages of software. There are lots of applications running on the internet on which default passwords are enabled. So, it is quite easy for an attacker to enter default password and gain access to sensitive information. A list containing default passwords of some of the most popular applications is available on the internet.








    Always disable or change the applications' (both online and offline) default username-password pairs.


    4) Brute Force :- If all other techniques failed, then attackers uses brute force password cracking technique. Here an automatic tool is used which tries all possible combinations of available keys on the keyboard. As soon as correct password is reached it displays on the screen.This techniques takes extremely long time to complete, but password will surely cracked.


    Long is the password, large is the time taken to brute force it.


    5) Phishing :- This is the most effective and easily executable password cracking technique which is generally used to crack the passwords of e-mail accounts, and all those accounts where secret information or sensitive personal information is stored by user such as social networking websites, matrimonial websites, etc.
    Phishing is a technique in which the attacker creates the fake login screen and send it to the victim, hoping that the victim gets fooled into entering the account username and password. As soon as victim click on "enter" or "login" login button this information reaches to the attacker using scripts or online form processors while the user(victim) is redirected to home page of e-mail service provider.


    Never give reply to the messages which are demanding for your username-password, urging to be e-mail service provider.


    It is possible to try to obtain the passwords through other different methods, such as social engineering, wiretapping, keystroke logging, login spoofing, dumpster diving, phishing, shoulder surfing, timing attack, acoustic cryptanalysis, using a Trojan Horse or virus, identity management system attacks (such as abuse of Self-service password reset) and compromising host security.
    However, cracking usually designates a guessing attack.

    Read more...
    0

    Basics of IP Spoofing Tutorial

  • PRABH KARAN SINGH
  • The term IP (Internet Protocol) address spoofing refers to the creation of IP packets with a forged (spoofed) source IP address with the purpose of hidding the identity of the sender or break into the victim's computer system.

    Why it works ?

    IP-Spoofing works because trusted services only rely on network address based authentication. Since IP is easily duped, address forgery is not difficult. The main reason is security weakness in the TCP protocol known as sequence number prediction.

    How it works ?

    To completely understand how IP Spoofing can take place, one must examine the structure of the TCP/IP protocol suite. A basic understanding of these headers and network exchanges is crucial to the process.

    Internet Protocol (IP) :

    It is a network protocol operating at layer 3 (network) of the OSI model. It is a connectionless model, meaning there is no information regarding transaction state, which is used to route packets on a network. Additionally, there is no method in place to ensure that a packet is properly delivered to the destination.


    Examining the IP header, we can see that the first 12 bytes (or the top 3 rows of the header) contain various information about the packet. The next 8 bytes (the next 2 rows), however, contains the source and destination IP addresses. Using one of several tools, an attacker can easily modify these addresses – specifically the “source address” field.

    Transmission Control Protocol (TCP) :

    It is the connection-oriented, reliable transport protocol in the TCP/IP suite. Connection-oriented simply means that the two hosts participating in a discussion must first establish a connection via the 3-way handshake (SYN-SYN/ACK-ACK). Reliability is provided by data sequencing and acknowledgement. TCP assigns sequence numbers to every segment and acknowledges any and all data segments recieved from the other end.



    As you can see above, the first 12 bytes of the TCP packet, which contain port and sequencing information.
    TCP sequence numbers can simply be thought of as 32-bit counters. They range from 0 to 4,294,967,295. Every byte of data exchanged across a TCP connection (along with certain flags) is sequenced. The sequence number field in the TCP header will contain the sequence number of the *first* byte of data in the TCP segment. The acknowledgement number field in the TCP header holds the value of next *expected* sequence number, and also acknowledges *all* data up through this ACK number minus one.
    TCP packets can be manipulated using several packet crafting softwares available on the internet.

    The Attack

    IP-spoofing consists of several steps. First, the target host is choosen. Next, a pattern of trust is discovered, along with a trusted host. The trusted host is then disabled, and the target's TCP sequence numbers are sampled. The trusted host is impersonated, the sequence numbers guessed, and a connection attempt is made to a service that only requires address-based authentication. If successful, the attacker executes a simple command to leave a backdoor.

    Spoofing can be implemented by different ways as given below -

    Non-Blind Spoofing :- This type of attack takes place when the attacker is on the same subnet as the victim. The sequence and acknowledgement numbers can be sniffed, eliminating the potential difficulty of calculating them accurately.

    Blind Spoofing :- Here the sequence and acknowledgement numbers are unreachable. In order to circumvent this, several packets are sent to the target machine in order to sample sequence numbers.

    Both types of spoofing are forms of a common security violation known as a Man In The Middle Attack (Clickable). In these attacks, a malicious party intercepts a legitimate communication between two friendly parties. The malicious host then controls the flow of communication and can eliminate or alter the information sent by one of the original participants without the knowledge of either the original sender or the recipient. In this way, an attacker can fool a victim into disclosing confidential information by “spoofing” the identity of the original sender, who is presumably trusted by the recipient.

    IP spoofing is almost always used in what is currently one of the most difficult attacks to defend against – Denial of Service attacks, or DoS attack.

    Read more...

    Saturday, 23 April 2011

    0

    Tabnapping Attack Tutorial: Phishing Attack Tutorial

  • Saturday, 23 April 2011
  • saurav garg
  • Phishing is the most popular and widely used method for hacking email accounts. Phishing is not as easy as it's name. Creating a phishing page is an easy task and any one can download it from various hacking forums for free. The main step of phishing comes after creation of fake login page.

    How to send this fake page to the victim??

    Here comes the Tab Napping which can make your second step easy than before. No need to send fake page via email to victim.

    Tab Napping use the modern browser's multi tabbed environment. Now a days all people use multiple tabs for accessing Gmail, facebook, orkut and other websites simultaneously. The trick is to confuse user in his/her multiple tabs and redirect any of idle ta of his browser to your phishing silently. Tab Napping works on the user's assumption that a tabbed web page stays the same when other Internet services are being accessed.

    The idea behind this is very simple and is done by javascript. Tab napping is all about the relation of 2 pages. suppose Page A and Page B. Victim was viewing page A in a tab of a browser and then left this idle and and now using some other website in another tab of browser. If the user will not return to page A for some pre-specified time, page A will automatically redirect to Page B. This Page B is your phishing page. This redirection and cheking for user actions is done by Javascript.

    Make a web page and use the tab napping script in that page say it page A. This script will not affect the layout or content of the page. This script will check for user actions. If the page is idle for some time, this script will redirect this page to a pre-specified page which may be your phishing page. You have to specify this page in the script. Be sure to change this in script.
    check script for this line...

    timerRedirect = setInterval("location.href='http://www.gmail.com'",10000);

    this line will redirect to Gmail after 10 sec. Change this location to the address of your phishing page. This line is used 2 times in the script so change is both lines.

    so page A with tab napping script will redirect to phishing page B.

    Now send the link of the page A to your victim. This is a normal page. If the page is idle for some time it will be changed to page B otherwise no effect.

    Read more...

    Friday, 17 December 2010

    0

    Basics of Assembly – Part 1

  • Friday, 17 December 2010
  • PRABH KARAN SINGH
  • Basics of Assembly – Part 1


    Indeed: the basics!! Before I start out with something really technical, I thought to clear all the basics which are neededBasics of Assembly – Part 1 for anyone who is new to reversing. What I am going to teach here is far from being complete but it will be covering almost everything which you will need later on. To being with, An Assembler is the start and the end of all programming languages & that’s not an exaggeration. To my knowledge, all the computer languages are translated to binary & can be decompiled /disassembled in assembly. You might be having some programming experience in high level languages like C/C++, Java, .NET, which have relatively clear syntaxes, but when it comes to assembly (& LISP..i will come to it some time later) its a different ball game altogether. Assembly is the world of mnemonics, numbers & abbreviations and numbers and that’s where it all turns sour for many of us...But trust me, this is a basic & simple guide to assembly & you will be able to quickly grasp basics of it.
    PS: all the values which we will be talking about from now on will be in Hexadecimal...Unless specified :P I will be covering Bits & bytes & registers this time..

    I. Starting with Bits and bytes:

    BIT - The smallest possible piece of data in computing can be either 0 or a 1. Put a bunch of bits together & tada..You will have a 'binary number system'

    For e.g.
    00000001 = 1 00000010 = 2 00000011 = 3 etc.




    BYTE – A byte has 8 bits & can have a maximal value of 255 (0-255). We use the 'hexadecimal number system' for an easier reading of binary number system which is a 'base-16 system', while binary is a 'base-2 system'



    * WORD –A word = 2 bytes put together or 16 bits & can have a maximal value of 0FFFFh (or 65535d).


    * DOUBLE WORD –A double word = 2 words together or 32 bits & can have a max value = 0FFFFFFFF (or 4294967295d).


    * KILOBYTE –1000 bytes?! Nah, it’s actually 1024 bytes.


    * MEGABYTE –Again, not just 1 million bytes, but 1024*1024 or 1,048,578 bytes or 1024 KB.






    II. A case of Registers:


    Registers can be viewed as a placeholder in memory where we can put something; in simpler terms these are “special places” in your computer's memory where we can store data. View it as a little box, where we can put something: a name, a number, a sentence. Fact: Today’s WinTel (windows + Intel) CPU’s have 9 registers of 32 bit

    Subscribe us via E-mail and Add us on Facebook for daily updates and Plz also do click once on the ads displaying below or above the post for us.. :)
    Read more...