Tampilkan postingan dengan label security tips. Tampilkan semua postingan
Tampilkan postingan dengan label security tips. Tampilkan semua postingan

Selasa, 31 Mei 2011

Turning Firefox to an Ethical Hacking Platform

Turning Firefox to an Ethical Hacking Platform


Internet is an amazing virtual world where you can "virtually" do anything: gambling, playing, watching movies,

shopping, working, “VoIPying”, spying other people and for sure auditing remote systems.

The security testers’ community has a large panel of security tools, methodologies and much more to perform

their pentests and audit assessments. But what happens if you find yourself weaponless.

No more Top 100 security tools, no more LiveCDs and no more exploitation frameworks. A security auditor

without toolbox is like a cop without gun.

Nevertheless, there is maybe a way to rescue yourself from this nightmare situation.

The magical solution could be Firefox and its extensions developed by ethical hackers and coders.

This article comes as an update for what we posted previously about how to switch your Firefox to more than an

usual simple browser. It was about application auditing

Here is an updated list of useful security auditing extensions:

Information gathering


● Whois and geo-location

o ShowIP : Show the IP address of the current page in the status bar. It also allows querying

custom services by IP (right mouse button) and Hostname (left mouse button), like whois,

netcraft.

o Shazou : The product called Shazou (pronounced Shazoo it is Japanese for mapping)

enables the user with one-click to map and geo-locate any website they are currently

viewing.

o HostIP.info Geolocation : Displays Geolocation information for a website using hostip.info

data. Works with all versions of Firefox.

o Active Whois : Starting Active Whois to get details about any Web site owner and its host

server.

o Bibirmer Toolbar : An all-in-one extension. But auditors need to play with the toolbox. It

includes (WhoIs, DNS Report, Geolocation, Traceroute, Ping). Very useful for information

gathering phase


● Enumeration / fingerprinting

o Header Spy : Shows HTTP headers on statusbar

o Header Monitor : This is Firefox extension for display on statusbar panel any HTTP

response header of top level document returned by a web server. Example: Server (by

default), Content-Encoding, Content-Type, X-Powered-By and others.


● Social engineering

o People Search and Public Record : This Firefox extension is a handy menu tool for

investigators, reporters, legal professionals, real estate agents, online researchers and

anyone interested in doing their own basic people searches and public record lookups as

well as background research.


● Googling and spidering

o Advanced dork : Gives quick access to Google’s Advanced Operators directly from the

context menu. This could be used to spider a site or scan for hidden files (this spider

technique is used via scroogle.org)

o SpiderZilla : Spiderzilla is an easy-to-use website mirror utility, based on Httrack from

www.httrack.com.

o View Dependencies : View Dependencies adds a tab to the "page info" window, in which it

lists all the files which were loaded to show the current page. (useful for a spidering

technique)

Security Assessment / Code auditing


● Editors

o JSView : The ’view page source’ menu item now opens files based on the behaviour you

choose in the jsview options. This allows you to open the source code of any web page in

a new tab or in an external editor.

o Cert Viewer Plus : Adds two options to the certificate viewer in Firefox or Thunderbird: an

X.509 certificate can either be displayed in PEM format (Base64/RFC 1421, opens in a new

window) or saved to a file (in PEM or DER format - and PKCS#7 provided that the

respective patch has been applied - cf.

o Firebug : Firebug integrates with Firefox to put a wealth of development tools at your

fingertips while you browse. You can edit, debug, and monitor CSS, HTML, and JavaScript

live in any web page

o XML Developer Toolbar : Allows XML Developer’s use of standard tools all from your

browser.


● Headers manipulation

o HeaderMonitor : This is Firefox extension for display on statusbar panel any HTTP response

header of top level document returned by a web server. Example: Server (by default),

Content-Encoding, Content-Type, X-Powered-By and others.

o RefControl : Control what gets sent as the HTTP Referrer on a per-site basis.

o User Agent Switcher : Adds a menu and a toolbar button to switch the user agent of the

browser


● Cookies manipulation

o Add N Edit Cookies : Cookie Editor that allows you add and edit "session" and saved

cookies.

o CookieSwap : CookieSwap is an extension that enables you to maintain numerous sets or

"profiles" of cookies that you can quickly swap between while browsing

o httpOnly : Adds httpOnly cookie support to Firefox by encrypting cookies marked as

httpOnly on the browser side

o Allcookies : Dumps ALL cookies (including session cookies) to Firefox standard cookies.txt

file


● Security auditing

o HackBar : This toolbar will help you in testing SQL injections, XSS holes and site security. It

is NOT a tool for executing standard exploits and it will NOT teach you how to hack a site.

Its main purpose is to help a developer do security audits on his code.

o Tamper Data : Use “tamper data” to view and modify HTTP/HTTPS headers and post

parameters.

o Chickenfoot : Chickenfoot is a Firefox extension that puts a programming environment in

the browser’s sidebar so you can write scripts to manipulate web pages and automate web

browsing. In Chickenfoot, scripts are written in a superset of JavaScript that includes

special functions specific to web tasks.

Proxy/web utilities


FoxyProxy : FoxyProxy is an advanced proxy management tool that completely replaces Firefox’s

proxy configuration. It offers more features than SwitchProxy, ProxyButton, QuickProxy, xyzproxy,

ProxyTex, etc


SwitchProxy : SwitchProxy lets you manage and switch between multiple proxy configurations

quickly and easily. You can also use it as an anonymizer to protect your computer from prying eyes


POW (Plain Old WebServer) : The Plain Old Webserver uses Server-side JavaScript (SJS) to run a

server inside your browser. Use it to distribute files from your browser. It supports Server-side JS,

GET, POST, uploads, Cookies, SQLite and AJAX. It has security features to password-protect your

site. Users have created a wiki, chat room and search engine using SJS.

Misc


● Hacks for fun

o Greasemonkey : Allows you to customize the way a webpage displays using small bits of

JavaScript (scripts could be download here)


● Encryption

o Fire Encrypter : FireEncrypter is a Firefox extension which gives you encryption/decryption

and hashing functionalities right from your Firefox browser, mostly useful for developers or

for education & fun.

Malware scanner


● QArchive.org web files checker : Allowing people to check web files for any malware (viruses,

trojans, worms, adware, spyware and other unwanted things) inclusions.


● Dr.Web anti-virus link checker : This plugin allows you to check any file you are about to download,

any page you are about to visit


● ClamWin Antivirus Glue for Firefox : This extension scans every downloaded file automatically with

ClamWin.

Anti Spoof


● refspoof : Easy to pretend to origin from a site by overriding the URL referrer (in a http request). —

It incorporates this feature by using the pseudo-protocol spoof:// .. Thus it’s possible to store the

information in a "hyperlink" - that can be used in any context... like html pages or bookmarks

Besides, we keep watching new extensions and we are on the way to develop a new extension for Nmap and Nessus.


Thank You

INDIAN CYBER SQUAD TEAM

Senin, 18 April 2011

“Scenarios and Impacts of Cyber Terrorism”

We are currently living in Cyber age, where Internet and computers have major impacts on our way of living, social life and the way we conduct businesses. and owing to this the new kind of crime has evolved that troubles users with the computer more precisely, criminal exploitation of the Internet.


▬ The trafficking, distribution, posting, and dissemination of obscene material including pornography and indecent exposure, constitutes one of the most important Cyber crimes known today. The potential harm of such a crime to humanity can hardly be amplified. This is one Cyber crime which threatens to undermine the growth of the younger generation as also leave irreparable scars and injury on the younger generation, if not controlled

▬ Cyber terrorism is one distinct kind of crime in this category. The growth of internet has shown that the medium of Cyberspace is being used by individuals and groups to threaten the international governments as also to terrorize the citizens of a country. This crime manifests itself into terrorism when an individual "cracks" into a government or military maintained website.
▬ Corporate espionage has shifted grounds — it has now become digital and certainly more dangerous.
Planting a mole in a rival company to get sensitive data or hiring a detective firm to get access to company secrets are passé.
Take for instance, the case of a Delhi-based software firm whose sensitive source code data was stolen. The company that was working on one of its software lost its data to hackers.

Cyber criminals target trade secrets and product planning documents that they later sell to rival firms, many people have access to a computer whether at home, school, or a local coffee shop. As a result, cyber crime can be committed from almost anywhere. And for those that aren't computer savvy, falling victim may be easier than you would think. But there are some precautions you can take to help guard you and your family against cyber crime, Antivirus And Anti spyware Software which are used to restrict backdoor program, trojans and other spy wares to be installed on the computer then there are firewalls which protect a computer network from unauthorized access.

Also there are Cyber ethics and cyber laws are being formulated to stop cyber crimes. It is a responsibility of every individual to follow cyber ethics and cyber laws so that the increasing cyber crimes shall reduce.

Besides these there are several steps you can take to protect your computer from cyber crime.

First, keep your computer's operating system and software updated. Manufacturers will regularly send out patches and fixes to defend your computer from problems. Secondly, install a firewall and make sure that it is turned on at all times. The firewall prevents hackers from gaining access to your computer as well as passwords that you've created. In some cases, when you install new software you need to turn off the firewall briefly. If you do, be sure to turn it back on immediately after installation. Thirdly, install anti-virus software and update it regularly. For best results, have it perform a daily scan to check for computer threats as well as any new software that may need to be installed. Lastly, be careful what you download. Many email attachments contain computer viruses which can be launched upon opening. If you don't know the sender, don't bother opening it. It's not worth the risk of an email virus.
E-mail Scams


• Today's cyber criminals are sophisticated, they can send e-mails that look like they are from reputable companies asking for your personal information. If you aren't aware of how they operate you may unwittingly send them information, which will give them access to your personal account information. Once they have this, they can drain your account of all available funds. Likewise, some criminals will send e-mails posing to be from foreign countries and asking for help with moving money from their country to America. The rule of thumb is, if it sounds too good to be true it probably is. Why would someone you don't know contact you with help moving money and offer you a cut of it? It doesn't add up and your best bet is to delete these e-mails immediately
Peer Sharing
• While it may seem great to swap files over the Internet there are many risks associated with it. Because all parties involved must download software, which allows them to access each others computers, it opens up opportunity for computer hackers to attack your system. Hackers can then release viruses and worms onto your hard drive. And if you didn't properly download the file sharing software, hackers may be able to see the entire contents of you hard drive, not just the drives where your shared files are stored. In addition, file sharing can make your computer the target of child pornography images. It can also result in copyright infringement violations. It's best to not share information with those you don't know, especially over an open connection on the computer. Instead, opt for sharing with those who are your friends and put the information on a flash drive. Also, don't share information that is copyrighted as it opens you up for being sued.



Notice:Please do not copy this article if you copy it kindly provide a link back to this article.
MyFreeCopyright.com Registered & Protected

Selasa, 25 Januari 2011

Protect Your Facebook,gmail,Twitter account from Hackerz

Now a days everybody uses Email accounts and social networking like Facebook , Twitter etc . . Lots of personal Information is associated with such social networking sites .. So this is important to protect such data from Hackers . . Because Hackers ( Black Hat Hackers ) always try to get others important data , information and use it for wrong purpose . . So please always try to be safe from hackers . .






Below i am telling u simple steps which you should follow :-


Never share your password to anyone.

1) Don't use password as your nick name, phone no. or pet names.
2) Use the combination of lower case, uper case, numbers and special characters for passwords.
3) Never click on any suspected link comes in a mail from unknown sender
4) Never give your passwords to any 3rd party websites for any service.
5) Use different passwords for different accounts.
6) Check the website url every time before login. EX: check url to be


before login to face account. Never login to website such as


( Most Important )
7) Use secondary email address and mobile phone numbers with secret questions for account recovery.
8) Never use any javascript code in url while login to any of your email or any other website account. It may be a cookie stealer script.
9) use latest antivirus and antimalware softwares with firewall on.

These are some things which you should follow for safe surfing on Internet

I hope you like it . . Any queries just contact me anytime !!

Thanks . .

Minggu, 28 November 2010

10 Methods to Secure your WIFI network

follow this article and secure your wireless network! It is imperative for everyone who has their own wireless network in a home or small business setting to take the following steps to ensure the well being of the network.
  1. Give your router an admin password - Learn how to change the admin password for your router by reading the manual or checking the manufacturer's support website.
  2. Change your routers SSID - Your router's SSID is like its name. If you set this to default, your neighbour might be accidentally using your wireless connection or you might accidentally use your neighbour's connection (which is a crime). You want to be sure that you can distinctly identify your router and prevent others from accidentally connecting to it, which will make your Internet slower.
  3. Use at least WPA2 Encryption - Not using encryption is like yelling your credit card number out loud. Anyone paying attention and snooping in on your wireless network can intercept all data that goes between the wireless router and the computer. Make sure you use at least WPA2 encryption. If your router doesn't have a WPA2 option then you might want to upgrade to a newer router or check for a firmware update.
  4. Use a hard to break pre-shared key - Make sure it is 63 characters long and make up of random letters, number and characters. Since you don't have to remember anything (you only need to set this on your router and computer/console once) A great way to generate good passwords is to use the GRC Passwords Page. It generates a key for you automatically. I recommend you use WPA2 and use a 63 character random ASCII string. Remember, once you use the key on your router, you'll need it for your computer too, so making a text file of the key might be helpful.
  5. Disable SSID Broadcast - Once your set up your router and initiate the wireless network, it is a good idea to turn off the SSID so people might not get tempted to try and use your network.
  6. Enable MAC Address Filtering - MAC in this case means Media Access Control, not a Mac. It allows you to specify the machines (i.e. only your machine) that can connect to your network.
  7. Try to broadcast only in Wireless G - If possible try and broadcast only on a 802.11 G band so that people with 802.11 B hardware will not be able to connect. If you have a laptop or device that needs 802.11 B, then obviously this isn't an option.
  8. Make sure to turn off any extended range functionality if living in a small house. Extended range mode will only make your router send out more powerful signals and make your network susceptible to attacks.
  9. Change Miscellaneous settings - Disable features such as gaming mode, and enable features such as discard PING from WAN side. This will prevent an attacker from compromising your network by repeatedly pinging your router to death.
  10. Update Update Update - If you haven't ever updated your router's firmware, then it's high time you do so. Make sure you stay informed about the latest developments in the wireless world too

How to Protect server from Ddos Attack

DoS Protection via APF, BFD, DDOS and RootKit

Being a web host, your servers are constantly being attacked by hackers by denial-of-service (DoS) and other brute force attacks. There is no foolproof method to stop 100% of all attacks, but there are ways to protect your servers by applying firewall rules, and detecting and banning attacking IPs.

This article makes use of the APF, BFD, DDoS Deflate and RootKit to detect and protect your server from denial-of-service type attacks. To apply those utilities, please follow the instructions below:

To begin installation, login to your server as a root user.

% ssh -l root [hostname]
root@[hostname]'s password: [password]
Last login: [Date] from [hostname]

APF -- Advanced Policy-based Firewall

Get the latest source from the rfxnetworks, and install the software.
# cd /usr/src
# mkdir utils
# cd utils
# wget http://rfxnetworks.com/downloads/apf-current.tar.gz
# tar xfz apf-current.tar.gz
# cd apf-*
# ./install.sh

Read the README.apf and README.antidos for configuration options. Edit the /etc/apf/conf.apf and modify the following lines to your need.

DEVEL_MODE="0"
IG_TCP_CPORTS="21,22,25,53,80,110,143,443,3306"
IG_UDP_CPORTS="53,111"
USE_AD="1"

By default, APF is setup to run in development mode which flushes firewall rules every 5 minutes. Running in development mode defeats the purpose of running APF, as it will automatically flush every 5 minutes. Configure the Ingress (inbound) TCP and UDP ports that need to be opened. Finally, enable AntiDos by setting USE_AD="1".

Edit the /etc/apf/ad/conf.antidos as you fit necessary, and start the APF firewall.

# apf --start

BFD -- Brute Force Detection

BFD is a shell script which parses security logs and detects authentication failures. It is a brute force implementation without much complexity, and it works in conjunction with a APF (Advanced Policy-based Firewall).

## Get the latest source and untar.
# cd /usr/src/utils
# wget http://rfxnetworks.com/downloads/bfd-current.tar.gz
# tar xfz bfd-current.tar.gz
# cd bfd-*
# ./install.sh
Read the README file, and edit the configuration file located in /usr/local/bfd/conf.bfd.
Find ALERT="0" and replace it with ALERT="1"
Find EMAIL_USR="root" and replace it with EMAIL_USR="username@yourdomain.com"

Edit /usr/local/bfd/ignore.hosts file, and add your own trusted IPs. BFD uses APF and hence it orverrides allow_hosts.rules, so it is important that you add trusted IP addresses to prevent yourself from being locked out.

## Start the program.
# /usr/local/sbin/bfd -s


DDoS Deflate

## Get the latest source
# cd /usr/src/utils
# mkdir ddos
# cd ddos
# wget http://www.inetbase.com/scripts/ddos/install.sh
# sh install.sh
Edit the configuration file, /usr/local/ddos/ddos.conf, and start the ddos.

# /usr/local/ddos/ddos.sh -c

RootKit -- Spyware and Junkware detection and removal tool
Go to Rootkit Hunter homepage, and download the latest release.

## Get the latest source and untar
# cd /usr/src/utils
# wget http://downloads.rootkit.nl/rkhunter-<version>.tar.gz
# tar xfz rkhunter-*.gz
# cd rkhunter
# ./installer.sh
## run rkhunter
# rkhunter -c

Setup automatic protection on System Reboot

## Edit /etc/rc.d/rc.local
## (or similar file depending on Linux version)
## Add the following lines at the bottom of the file

/usr/local/sbin/apf --start
/usr/local/ddos/ddos.sh -c

Note:
The SYN Floods and ICMP DDoS may also be prevented by utilizing the Linux traffic control utility (tc). To view setup instructions, please see relevant sections of Linux Advanced Routing & Traffic Control HOWTO.


Notes from the users:

Some of the users experienced following errors while starting APF.

bash# apf --start

Unable to load iptables module (ip_tables), aborting.

According to Burst and Ryan of r-fx.org, changing the SET_MONOKERN variable in /etc/apf/conf.apf to "1" will correct the problem.


to get all latest hacking tips n tricks directly to ur inbox

Rabu, 24 November 2010

Create sTrong Password


Strong passwords should have a significant length and cannot contain normal words. Only random digits and letters of different case. Such passwords are extremely hard to remember and it takes time to enter. But, even strong passwords have their weaknesses. When you type a password, it can be intercepted by a spy program that logs all your keystrokes. Others can see what you type (even if the password field on the screen is masked, the password can be read by buttons you hit on your keyboard.)


Until now, the only solution was to buy a secure token. A secure token is a hardware key that is used instead of or in addition to your normal password authentication. There are two main problems with the hardware solution, though. First, it is expensive. And second, you can use them only with software that has built-in support for this method of authentication.

But, from now on, you can turn any USB flash drive into a secure token! No need to purchase an additional expensive device. All you need is about 2 megabytes of free space on your flash drive or other USB gadget, such as an MP3 player, PDA or even a USB-pluggable mobile handset.
Strong Password


How does it work?
 Our software, Double Password, installs onto your flash drive. When you type a password, the program intercepts it and converts it into a super-strong password string on-the-fly. You can use simple, easy-to-remember passwords without the risk of being cracked.Another benefit of using Double Password is that nobody can steal your passwords. Spy programs are useless. Even if someone gets the "weak" password that you type on the keyboard, it means nothing. This password will only work when your USB flash is inserted.

While typical hardware locks will work only with software that supports secure tokens, Double Password works with any software. It simply substitutes your weak password with a strong one.Double Password can be effectively used to securely lock your Windows account, to protect your laptop and to bring a new level of security to all software that uses password authentication.
Download Double Password



  to get all latest hacking tips n tricks  directly to ur inbox