Showing posts with label Network Security. Show all posts
Showing posts with label Network Security. Show all posts

December 30, 2010

10 Best Hacking and Security Software 2010

Sponsored Link
Sponsored Link

Linux is a hacker’s dream computer operating system. It supports tons of tools and utilities for cracking passwords, scanning network vulnerabilities, and detecting possible intrusions. I have here a collection of 10 of the best hacking and security software tools for Linux. Please always keep in mind that these tools are not meant to harm, but to protect.1. John the Ripper
John the Ripper is a free password cracking software tool initially developed for the UNIX operating system. It is one of the most popular password testing/breaking programs as it combines a number of password crackers into one package, autodetects password hash types, and includes a customizable cracker. It can be run against various encrypted password formats including several crypt password hash types most commonly found on various Unix flavors (based on DES, MD5, or Blowfish), Kerberos AFS, and Windows NT/2000/XP/2003 LM hash. Additional modules have extended its ability to include MD4-based password hashes and passwords stored in LDAP, MySQL and others.

December 15, 2010

List of Web Hacking Techniques




  • iPhone SSL Warning and Safari Phishing


  • RFC 1918 Blues


  • Slowloris HTTP DoS


  • CSRF And Ignoring Basic/Digest Auth



  • Hash Information Disclosure Via Collisions - The Hard Way


  • Socket Capable Browser Plugins Result In Transparent Proxy Abuse


  • XMLHTTPReqest “Ping” Sweeping in Firefox 3.5+


  • Session Fixation Via DNS Rebinding


  • Quicky Firefox DoS


  • DNS Rebinding for Credential Brute Force


  • SMBEnum


  • DNS Rebinding for Scraping and Spamming


  • SMB Decloaking


  • De-cloaking in IE7.0 Via Windows Variables


  • itms Decloaking


  • Flash Origin Policy Issues


  • Cross-subdomain Cookie Attacks


  • HTTP Parameter Pollution (HPP)


  • How to use Google Analytics to DoS a client from some website.


  • Our Favorite XSS Filters and how to Attack them


  • Location based XSS attacks


  • PHPIDS bypass


  • I know what your friends did last summer


  • Detecting IE in 12 bytes


  • Detecting browsers javascript hacks


  • Inline UTF-7 E4X javascript hijacking


  • HTML5 XSS


  • Opera XSS vectors


  • New PHPIDS vector


  • Bypassing CSP for fun, no profit


  • Twitter misidentifying context


  • Ping pong obfuscation


  • HTML5 new XSS vectors


  • About CSS Attacks


  • Web pages Detecting Virtualized Browsers and other tricks


  • Results, Unicode Left/Right Pointing Double Angel Quotation Mark


  • Detecting Private Browsing Mode


  • Cross-domain search timing


  • Bonus Safari XXE (only affecting Safari 4 Beta)


  • Apple's Safari 4 also fixes cross-domain XML theft


  • Apple's Safari 4 fixes local file theft attack


  • A more plausible E4X attack


  • A brief description of how to become a CA


  • Creating a rogue CA certificate


  • Browser scheme/slash quirks


  • Cross-protocol XSS with non-standard service ports


  • Forget sidejacking, clickjacking, and carjacking: enter “Formjacking”


  • MD5 extension attack


  • Attack - PDF Silent HTTP Form Repurposing Attacks


  • XSS Relocation Attacks through Word Hyperlinking


  • Hacking CSRF Tokens using CSS History Hack


  • Hijacking Opera’s Native Page using malicious RSS payloads


  • Millions of PDF invisibly embedded with your internal disk paths


  • Exploiting IE8 UTF-7 XSS Vulnerability using Local Redirection


  • Pwning Opera Unite with Inferno’s Eleven


  • Using Blended Browser Threats involving Chrome to steal files on your computer


  • Bypassing OWASP ESAPI XSS Protection inside Javascript


  • Hijacking Safari 4 Top Sites with Phish Bombs


  • Yahoo Babelfish - Possible Frame Injection Attack - Design Stringency


  • Gmail - Google Docs Cookie Hijacking through PDF Repurposing & PDF


  • IE8 Link Spoofing - Broken Status Bar Integrity


  • Blind SQL Injection: Inference thourgh Underflow exception


  • Exploiting Unexploitable XSS


  • Clickjacking & OAuth


  • Google Translate - Google User Content - File Uploading Cross - XSS and Design Stringency - A Talk


  • Active Man in the Middle Attacks


  • Cross-Site Identification (XSid)


  • Microsoft IIS with Metasploit evil.asp;.jpg


  • MSWord Scripting Object XSS Payload Execution Bug and Random CLSID Stringency


  • Generic cross-browser cross-domain theft


  • Popup & Focus URL Hijacking


  • Advanced SQL injection to operating system full control (whitepaper)


  • Expanding the control over the operating system from the database


  • HTML+TIME XSS attacks


  • Enumerating logins via Abuse of Functionality vulnerabilities


  • Hellfire for redirectors


  • DoS attacks via Abuse of Functionality vulnerabilities


  • URL Spoofing vulnerability in bots of search engines (#2)


  • URL Hiding - new method of URL Spoofing attacks


  • Exploiting Facebook Application XSS Holes to Make API Requests


  • Unauthorized TinyURL URL Enumeration Vulnerability
  • December 7, 2009

    McAfee uncovers riskiest domains


    McAfee Mal Web map
    Red means danger. And orange offers plenty of risk, too.
    (Credit: McAfee)

    McAfee's third annual "Mapping the Mal Web" report, released Wednesday, looks at riskiest and safest domains across the globe. The small nation on the west coast of Africa reached the top spot this year with 36.7 percent of its sites posing a security risk. Because .cm is often a typo for .com, McAfee said, cybercrooks like to use that domain to set up typo-squatted sites to hit you with malware.You may want to think twice if you hit a site with a .cm extension. That belongs to Cameroon, pegged by McAfee as the world's riskiest domain.
    The generic and widely used .com domain itself isn't much safer, according to McAfee, jumping from ninth last year to second this year in riskiness, with 32.2 percent of its sites potentially hazardous to your PC's health.
    (Credit: McAfee)
    Romania (.ro) is tagged as the riskiest domain for malicious downloads, with 21 percent of its sites delivering payloads of viruses, spyware, and adware. The information (.info) domain is seen by McAfee as the most "spammy," with 17.2 percent of its sites generating junk mail.
    On the positive side, the government (.gov) is the safest generic domain with essentially 0 percent risk, while Japan (.jp) proved the safest country domain with a rating of only 0.1 percent. Last year's riskiest domain, Hong Kong (.hk) dropped to 34th place with a risk rating of only 1.1 percent, which McAfee attributed to the country's aggressive steps to stop scam-related domain registrations.
    (Credit: McAfee)
    "This report underscores how quickly cybercriminals change tactics to lure in the most victims and avoid being caught. Last year, Hong Kong was the riskiest domain and this year it is dramatically safer," Mike Gallagher, chief technology officer for McAfee Labs, said in a statement. "Cybercriminals target regions where registering sites is cheap and convenient, and pose the least risk of being caught."
    Overall, looking at 27 million Web sites and 104 top-level domains, McAfee found that 1.5 million sites, or 5.8 percent, were risky. That's up from 4.1 percent from the past two years, although the comparison is not direct since McAfee said it changed its rating methodology since then.
    McAfee noted that cybercriminals who create domains to scam people prefer registrars with cheap prices, volume discounts, and hefty refund policies. Crooks also like registrars with a "no questions asked" policy and that act slowly or not at all when informed of malicious domains.

    January 30, 2009

    Vehicular Network Security Overview

    I have read research paper from University of California (Department of Information and Computer Science) written by Magda El Zarki, Sharad Mehrotra, Gene Tsudik and Nalini Venkatasubramanian which titled "Security Issues in a Future Vehicular Network".

    They have made an assumption that the security and privacy issues in vehicular network security are fairly common to most mobile and wireless network settings usch as authentication, data integrity, resistance to various denial-of-service attacks
    and so forth.

    In that paper, they highlighted a few important items for vehicular network security.

    · No confidentiality: the issue of data secrecy or confidentiality is not of concern in this network environment; none of the application scenarios we consider require any data to be kept secret. This is
    quite unusual in mobile networks. For example, in
    many modern cell phone networks (GSM, CDPD etc.) a secure channel is maintained between the cell phone and the nearest base station and/or local subscriber registry

    · No key distribution: most mobile network security architectures include provisions for key distribution. This is not only the case when an encrypted channel is set up; many settings require a key to be shared for authentication and data integrity reasons. In our case, key distribution is unnecessary for two reasons:

    1) there will be no bulk data transmitted (on a continuous basis) either among cars
    or between cars and roadside infrastructure, and,

    2) vehicles traveling at high speeds (as most do on highways) will likely spend little time within a cell of a given base station. Also, vehicles communicating in
    an ad hoc network broadcast their data, thus, pair-wise (or group-wise) key distribution is not needed.

    · No hand-over: typically, one of the notable security features of mobile networks is the secure hand-over protocol [3, 4], e.g., as a node moves from one cell to another, its state (including any on-going connection data) is handed over from one base station to the next. However, explicit hand-over is not needed if communication is largely one-way, i.e., vehicles reporting current speed and other parameters to the base stations.

    · No battery power concerns: this is actually the most important distinguishing factor of the network environment outlined in this proposal. In practically all mobile networks, power (CPU) consumption is a paramount concern. This includes not only power utilized for reception and transmission but also the power necessary to perform (usually expensive) cryptographic operations on weak and batterychallenged computing devices such as small PDAs, packet radios or cell phones. In our case, power consumption is not relevant since a running vehicle provides an ample source of battery power.

    · No CPU speed issues: a related concern in many mobile networks is the low CPU speed of the mobile node. Hence, there is usually a goal to minimize the use of cryptography because of the relatively long delays it imposes (e.g., an average Palm Pilot or Handspring PDA takes seconds to generate a digital signature). This often results in security protocols that are “contorted” to minimize the use of cryptography; sometimes, with disastrous consequences, e.g., the original GSM security architecture. Since “nodes” in our context are vehicles, more powerful (faster) CPUs can be assumed.

    · Extreme Time Sensitivity: as mentioned earlier, all data is very much time-sensitive. In applications such as VIVA, the needs for timeliness are only part of the problem. Time synchronization is also extremely important (although we can perhaps count on the GPS devices to provide accurate and uniform clock readings). Moreover, the system must be intolerant of replays (hostile and otherwise).

    Taking the above differences into account leads us to a fairly simple security architecture with the following notable features:

    · Digital Signatures: we require all broadcasts in VIVA as well as all “reports” in HITCH to be digitally signed by the originating vehicle. Since each vehicle (and the roadside infrastructure) will receive many more messages that it will send, the cost of signature verification is of more importance than that of signature generation. Therefore, at least at the beginning, we are likely to use RSA-based digital signatures (as opposed to, say, DSA). Of course, an appropriate message and signature format will be defined.

    · Time-stamping and sequencing: all communication in both applications will include both sequence numbers as well as timestamps. Clock synchronization is a non-issue, for the time being, as all vehicles and fixed infrastructure components are (per our assumption) equipped with GPS receivers and GPS is also a time service.

    · Certification Infrastructure (PKI): public key digital signatures are not particularly useful without a certification infrastructure. Designing a nimble, scalable and secure PKI has been a major challenge in the last decade. (See, for example, IETF PKI efforts.) We must take into account the unique aspects of our network environment in designing an appropriate PKI. Moreover, there are some recent and promising results in cryptography that obviate the need to public key certificates. For example, the Boneh/Franklin identity-based encryption system is an elegant method of obtaining public key cryptography without any certificates: in it, an entity’s public key is derived from a unique identity string, e.g., an email address or X.500 distinguished name. (This could be a vehicle identification number, in their case.)

    October 17, 2007

    10 Tips for Wireless Home Network Security

    By: Bradley Mitchell

    Many folks setting up wireless home networks rush through the job to get their Internet connectivity working as quickly as possible. That's totally understandable. It's also quite risky as numerous security problems can result. Today's Wi-Fi networking products don't always help the situation as configuring their security features can be time-consuming and non-intuitive. The recommendations below summarize the steps you should take to improve the security of your home wireless network.

    1. Change Default Administrator Passwords (and Usernames)
    At the core of most Wi-Fi home networks is an access point or router. To set up these pieces of equipment, manufacturers provide Web pages that allow owners to enter their network address and account information. These Web tools are protected with a login screen (username and password) so that only the rightful owner can do this. However, for any given piece of equipment, the logins provided are simple and very well-known to hackers on the Internet. Change these settings immediately.

    2. Turn on (Compatible) WPA / WEP Encryption
    All Wi-Fi equipment supports some form of encryption. Encryption technology scrambles messages sent over wireless networks so that they cannot be easily read by humans. Several encryption technologies exist for Wi-Fi today. Naturally you will want to pick the strongest form of encryption that works with your wireless network. However, the way these technologies work, all Wi-Fi devices on your network must share the identical encryption settings. Therefore you may need to find a "lowest common demoninator" setting.

    3. Change the Default SSID
    Access points and routers all use a network name called the SSID. Manufacturers normally ship their products with the same SSID set. For example, the SSID for Linksys devices is normally "linksys." True, knowing the SSID does not by itself allow your neighbors to break into your network, but it is a start. More importantly, when someone finds a default SSID, they see it is a poorly configured network and are much more likely to attack it. Change the default SSID immediately when configuring wireless security on your network.

    4. Enable MAC Address Filtering
    Each piece of Wi-Fi gear possesses a unique identifier called the physical address or MAC address. Access points and routers keep track of the MAC addresses of all devices that connect to them. Many such products offer the owner an option to key in the MAC addresses of their home equipment, that restricts the network to only allow connections from those devices. Do this, but also know that the feature is not so powerful as it may seem. Hackers and their software programs can fake MAC addresses easily.

    5. Disable SSID Broadcast
    In Wi-Fi networking, the wireless access point or router typically broadcasts the network name (SSID) over the air at regular intervals. This feature was designed for businesses and mobile hotspots where Wi-Fi clients may roam in and out of range. In the home, this roaming feature is unnecessary, and it increases the likelihood someone will try to log in to your home network. Fortunately, most Wi-Fi access points allow the SSID broadcast feature to be disabled by the network administrator.

    6. Do Not Auto-Connect to Open Wi-Fi Networks
    Connecting to an open Wi-Fi network such as a free wireless hotspot or your neighbor's router exposes your computer to security risks. Although not normally enabled, most computers have a setting available allowing these connections to happen automatically without notifying you (the user). This setting should not be enabled except in temporary situations.

    7. Assign Static IP Addresses to Devices
    Most home networkers gravitate toward using dynamic IP addresses. DHCP technology is indeed easy to set up. Unfortunately, this convenience also works to the advantage of network attackers, who can easily obtain valid IP addresses from your network's DHCP pool. Turn off DHCP on the router or access point, set a fixed IP address range instead, then configure each connected device to match. Use a private IP address range (like 10.0.0.x) to prevent computers from being directly reached from the Internet.

    8. Enable Firewalls On Each Computer and the Router
    Modern network routers contain built-in firewall capability, but the option also exists to disable them. Ensure that your router's firewall is turned on. For extra protection, consider installing and running personal firewall software on each computer connected to the router.

    9. Position the Router or Access Point Safely
    Wi-Fi signals normally reach to the exterior of a home. A small amount of signal leakage outdoors is not a problem, but the further this signal reaches, the easier it is for others to detect and exploit. Wi-Fi signals often reach through neighboring homes and into streets, for example. When installing a wireless home network, the position of the access point or router determines its reach. Try to position these devices near the center of the home rather than near windows to minimize leakage.

    10. Turn Off the Network During Extended Periods of Non-Use
    The ultimate in wireless security measures, shutting down the network will most certainly prevent outside hackers from breaking in! While impractical to turn off and on the devices frequently, at least consider doing so during travel or extended periods offline. Computer disk drives have been known to suffer from power cycle wear-and-tear, but this is a secondary concern for broadband modems and routers.

    Top 7 Tips for Improving a Wireless Home Network

    A basic Wi-Fi home network can be assembled fairly quickly. However, many homeowners aren't aware of all the options available for making their network better. Consider the below ideas for improving the capability, performance and security of your wireless home network.

    1. Upgrade and Add the Right Equipment
    Many homeowners have heard of basic Wi-Fi equipment like routers and wireless adapter cards. Many such products are available to choose from. The "best" choices are often unclear. Old equipment may need to be replaced with faster, more reliable or more compatible products. Folks also often fail to consider cool wireless gear like print servers, game adapters and video cameras. Before settling for a second-rate home network setup, do your research and acquire the right stuff at a good price.

    2. Install the Wireless Router / Access Point Strategically
    Some people quickly assemble their wireless home network only to find that it won't function in certain areas of the residence. Others enjoy a network functional at first but suffer quick disappointment later when it crashes as a microwave oven or cordless phone is turned on. Still others suffer from poor network performance but fear attempting to fix it. One easy way to address these common Wi-Fi networking problems is to move the wireless router (access point).

    3. Change the Wi-Fi Channel Number
    In the USA and most other countries, Wi-Fi equipment can transmit on any of several different "channels" similar to televisions. Most wireless routers ship with the same default channel number, and most homeowners never think about changing it. However, if a person experiences radio interference from a neighbor's router or some other piece of electronic equipment, changing the Wi-Fi channel just might be the best way to avoid it.

    4. Upgrade Wireless Router (Access Point) Firmware
    Wireless routers contain built-in programmable logic called firmware. A version of this firmware is installed on the router by the manufacturer, and this normally works well when first installing the device. However, many routers also offer a firmware upgrade capability that allows homeowners to install newer versions. Updated firmware can provide performance improvements, security enhancements or better reliability. As your router gets older, consider upgrading its firmware periodically.

    5. Improve Signal Strength and Range of the Wi-Fi Router (Access Point)
    No matter where in a residence a Wi-Fi router is installed, sometimes the wireless signal will simply not be strong enough. The likelihood of this problem increases with longer distances and with severe obstructions such as brick walls between the router and a Wi-Fi client. One way to solve this problem is to upgrade the Wi-Fi antenna installed on the router. Some routers do not support this option, but many do. The alternative involves installing an additional device called a wireless repeater.

    6. Improve Signal Strength and Range of Wi-Fi clients
    As with wireless routers, the signal strength of wireless clients can also be improved. Consider this option when faced with a Wi-Fi client that suffers from a very short range compared to the rest of the devices. This same technique can improve the ability of laptop computers to connect to Wi-Fi hotspots.

    7. Improve Wireless Network Security
    Many homeowners consider their wireless network a success when basic file and Internet connection sharing are functional. However, if proper security features are not in place, the work of network setup remains unfinished. Follow this checklist of essential steps for establishing and maintaining good Wi-Fi security on a home network.
    free counters
    RP | CU | PH | RR | TCU | MFB | BM | BM | TAW | RM | SM | MLW | QL | QTS | SR | TR | TCR | HR I2U | PH | TAW | ID | AAB | FSB | AG |