Showing posts with label Ethical Hacking. Show all posts
Showing posts with label Ethical Hacking. Show all posts

20120504

How to Join Anonymous Army ?


                    
What to join Anonymous army ? So are you like expecting from me that i will tell you that enrollment forms are out to join The Anonymous ? No, No such news ! And you cannot join anonymous ! In fact no one can !

Anonymous is not an organization,not a club too,nor a party.Anonymous has no ideology,no gurus and no leaders too.
Anonymous are like people who are with each other for a small time to bring do a task,be it good thing or bad.But as soon as that task is complete those people may or may not be together.You can compare them to a group of people traveling small distance together just like the passengers of a bus.


How do people from Anonymous communicate ?

Anonymous are regarded both as Heroes or Villains of cyber world by person to person.And just like every other person members of anonymous also communicate via the social network-facebook,skype,yahoo etc.

How to recognize members of Anonymous ?

Members of Anonymous have no different characteristics.A person you meet or see everyday may be a member of anonymous and you have no idea about it.There is no age,sex,caste,country barrier to be a member of anonymous,anyone and everyone can be a member.All you require to be a member are - Skills !
During public appearances members of anonymous are often seen wearing Guy Fawkes Masks.


Is it Good or Bad to be a member of Anonymous ?

It is totally up to you ! If you are good you remain good being a member of anonymous too and vice verse !
Being associated with anonymous does not bring you any ''Bad'' image as it is often misunderstood by people.
Anonymous group never asks it's members for their personal information or identity proof.

How many Anonymous are there ?

There are many of them,more than we can think ! And as i had said,they are with each other for short time and they keep on adding every time they are together.


About The Author: 

This article is written by Shikil sharma, Who is the newest member of RHA team. He blogs athttp://hacking-tweaks.blogspot.in/

Source from rafayhackingarticles

20120418

New Malware Detected in "Angry Birds Space"


               

The newly launched “Angry Birds Space” is found to have a new malware ! The malware was detected by Lookout Security which is a famous anti virus available for android phones. The malware is said to be a new version of Legacy Native (LeNa) which helps to gain unauthorized privileges from android phone.
This new variant of LeNa hides its payload just past the “End of Image” marker of an otherwise fully-functional JPEG.


This latest version of LeNa has recently emerged in alternative markets, and it is not believed to have been in the Google Play market. Among the apps in which this payload appears, however, is a fully functional copy of the recently released Angry Birds Space.


How it Functions?

LeNa would reportedly trick the user into activating its payload by invoking the SU utility which is used by rooted users to selectively grant super user privileges to applications that request them. After the app gained root access, it performs normally while also secretly installing a native binary file and granting it remote control. But due to its dependence on the SU tool, its spread was limited to rooted devices.


How to Prevent and Be safe :

1 .If phones starts working in an unusual manner then there is a possibility that it is affected.

2. Before downloading the app do look for the comments and reviews of people and also the name of 
the developer .

3. Download an anti virus for your mobile. Lookout anti virus, NetQin are some of the trusted names.

Via(Rafyhackingarticles]

20120330

Malicious Android application stealing banking credentials


Malicious Android application stealing banking credentials
Malicious+Android+application+stealing+banking+credentials

A new form of smart Android malware can not only steal your online banking information, but update itself in the future and secretly send contact information stored on your device off to the Bad Guys. Security researchers at McAfee have discovered a malicious Android application capable of grabbing banking passwords from a mobile device without infecting the user’s computer.

From a McAfee blog post on the subject, penned by Malware Researcher Carlos Castillo: "To get the fake token, the user must enter the first factor of authentication (used to obtain initial access to the banking account). If this action is not performed, the application shows an error. When the user clicks “Generar” (Generate), the malware shows the fake token (which is in fact a random number) and sends the password to a specific cell phone number along with the device identifiers (IMEI and IMSI). The same information is also sent to one of the control servers along with further data such as the phone number of the device."

The app also includes a number of nasty lines of code that could be used to obtain users' contact lists and then send them off to a control server. "From man-in-the-middle attacks we now see more sophisticated, remote-controlled banking Trojans that can get more than one factor of authentication and update itself to, for example, modify a phishing attack to get other required credentials–such as the name or the ID number of the user–to perform electronic fraud," writes Castillo. "Due to the increasing popularity of Android and mobile-banking applications, we expect that more threats like this will appear."

If Mobile banking does take off, beware, since the Android security architecture won't be able to stop those types of attacks, given the ease with which users can be tricked, via social engineering attacks, into installing third-party applications.

‘Anonymous’ Hackers To Shut Down Internet On Saturday, March 31


The hacktivist organization known as Anonymous has announced its plans to disable the internet this Saturday, March 31st. The group has been known to bring down websites, large ones at that, but has never attempted something as large as the entire internet before.
This announcement, other than its enormous scope, should come as a surprise to nobody. Indeed, they threatened retaliation for the arrests of 25 of their members last month. But their plan for Saturday isn’t about vengeance. Instead, it is about combating the still live threat by Congress on the autonomy of the internet through revised versions of the Stop Internet Piracy Act (SOPA) and Protect IP Act (PIPA). These pieces of legislation, which saw the largest online protest in history, along with ACTA, do indeed represent a serious threat to the internet as we know it.

Their mode of attack is par for the course for Anonymous. By using a method known as distributed denial of service attack the plan is to attack what Anonymous calls the internet’s thirteen root servers. If the servers are overloaded with request from IP address, it will stop redirecting others. In essence, anyone else trying to access the internet will get the web equivalent of a busy signal. A momentarily lapsed internet will not affect other communications which rely on separate internet frameworks and devices. But the enormity and daring of this undertaking is something to consider. In a world utterly reliant on the internet, whirling around at lightning speeds, the lack of access to the internet, albeit even if for only a day, will certainly have its repercussions, whether cultural or technological or both.
But is it even possible?
According to the security firm Errata Security’s Robert Graham, not so much. In a statement on the issue, Graham went on to say that while such an attack was possible it is unlikely to succeed on Saturday. He holds that even if Anonymous is able to cause problems on the local level, the attack will never go global. But he warns that “just because I say Anonymous can’t do it doesn’t it mean it can’t be done.”
But even with the advanced warning, Alan Woodward, a professor in the department of computing at the University of Surrey, thinks that Anonymous could do some real damage. In an opinion piece for the BBC news, Woodward cited Brian Honan, an information security expert for BH Consulting, as saying “unfortunately, despite [DNS] vulnerability being widely known for many years, a large proportion of DNS servers are still not configured correctly to prevent this type of attack.”
Even the VP of Radware Security, Carl Herberger stated that he is surprised that many of his colleagues are not taking the threat seriously. He credits his concern to several DNS vulnerabilities, some of them due to design flaws and social engineering vulnerabilities, but also from insiders interested in “ideological payback.”
While I do not know what will happen on Saturday, part of me does wish for them to succeed. The sheer boldness of it makes me root for the underdog in the fight. But that being said I feel that even if they should fail in Operation Blackout, they will still have succeeded in pressing the issue of internet censorship. My hope, whatever transpires on Saturday, is that the online community stay ever vigilant in opposing any legislation which would damage and censor the greatest tool for the sharing of ideas and promotion of freedom the world has ever known. And that, for me, is a big enough win.via[pnosker]

20120302

Attention Hackers: Win Your Share Of 1 Million Dollars For Hacking Google Chrome


Google is desperate for you to find exploits in Chrome, so much so that they are willing to pay out a million dollars in total prizes to the people who do. Google will have up to three winners, paid out on a first come, first served basis. For a full Chrome exploit, you will net a cool sixty thousand dollars. If you find a partial exploit, Google will throw you forty thousand, and they will throw twenty thousand if you find an exploit that could cause problems for Chrome users, but is not a Chrome specific problem. As an added bonus, successful winners will receive a free Chromebook.

This is all part of the CanSecWest security conference and the Pwn2Own contest, where Chrome has been the only browser never to be successfully brought down. Google is begging for it, and upping the payout should really help motivate people to try hard to break in.
In a way, Google is happy that their browser offers top security. Chris Evans and Justin Schuh said, “While we’re proud of Chrome’s leading track record in past competitions, the fact is that not receiving exploits means that it’s harder to learn and improve.” They went on to say, “To maximize our chances of receiving exploits this year, we’ve upped the ante. We will directly sponsor up to $1 million worth of rewards.”
It all starts Wednesday, March 7th, so there is still time to find those exploits and try to get a piece of that one million dollars!
Source: ArsTechnica

                                   How To Quickly & Easily Disable The Metro User Interface In Windows 8

                                    Huawei Ascend D Phone: Hands On :“World's fastest Smartphone”

                                     Guideline for New Linux Administrators: Part I


20120301

Learn Ethical Hacking Basic: Session XX


Security and the Stack
To really understand many of the techniques and tools that hackers use, you need to understand how systems and devices communicate. Hackers understand this, and many think outside the box when planning an attack or developing a hacking tool. As an example, TCP uses flags to communicate, but what if a hacker sends TCP packets with no flags set? Sure, it breaks the rules of the protocol, but it might allow the attacker to illicit a response to help identify the server. As you can see, having the ability to know how a protocol, service, or application works and how it can be manipulated can be beneficial. 


The OSI model and TCP/IP are discussed in the next sections. Pay careful attention to the function of each layer of the stack, and think about what role each layer plays in the communication process. 


The OSI Model

Objective: 

Understand the Open Systems Interconnect (OSI) Model 

Once upon a time, the world of network protocols was much like the Wild West. Everyone kind of did their own thing, and if there were trouble, there would be a shoot-out on Main Street. Trouble was, you never knew whether you were going to get hit by a stray bullet. Luckily, the IT equivalent of the sheriff came to town. This was the International Standards Organization (ISO). The ISO was convinced that there needed to be order and developed the Open Systems Interconnect (OSI) model in 1984. The model is designed to provide order by specifying a specific hierarchy in which each layer builds on the output of each adjacent layer. Although its role as sheriff was not widely accepted by all, the model is still used today as a guide to describe the operation of a networking environment. 

There are seven layers of the OSI model: the Application, Presentation, Session, Transport, Network, Data Link, and Physical layers. The seven layers of the OSI model are shown in Figure 2.1, which overviews data moving between two systems up and down the stack, and described in the following list: 



Application layer
Layer 7 is known as the Application layer. Recognized as the top layer of the OSI model, this layer serves as the window for application services. The Application layer is one that most users are familiar with as it is the home of email programs, FTP, Telnet, web browsers, and office productivity suites, as well as many other applications. It is also the home of many malicious programs such as viruses, worms, Trojan horse programs, and other virulent applications.

Presentation layer
Layer 6 is known as the Presentation layer. The Presentation layer is responsible for taking data that has been passed up from lower levels and putting it into a format that Application layer programs can understand. These common formats include American Standard Code for Information Interchange (ASCII), Extended Binary-Coded Decimal Interchange Code (EBCDIC), and American National Standards Institute (ANSI). From a security standpoint, the most critical process handled at this layer is encryption and decryption. If properly implemented, this can help security data in transit.

Session layer
Layer 5 is known as the Session layer. Its functionality is put to use when creating, controlling, or shutting down a TCP session. Items such as the TCP connection establishment and TCP connection occur here. Session-layer protocols include items such as Remote Procedure Call and SQLNet from Oracle. From a security standpoint, the Session layer is vulnerable to attacks such as session hijacking. A session hijack can occur when a legitimate user has his session stolen by a hacker. This will be discussed in detail in lesson 7, "Sniffers, Session Hijacking, and Denial of Service ".

Transport layer
Layer 4 is known as the Transport layer. The Transport layer ensures completeness by handling end-to-end error recovery and flow control. Transport-layer protocols include TCP, a connection-oriented protocol. TCP provides reliable communication through the use of handshaking, acknowledgments, error detection, and session teardown, as well as User Datagram Protocol (UDP), a connectionless protocol. UDP offers speed and low overhead as its primary advantage. Security concerns at the transport level include Synchronize(SYN) attacks, Denial of Service(DoS), and buffer overflows.

Network layer
Layer 3 is known as the Network layer. This layer is concerned with logical addressing and routing. The Network layer is the home of the Internet Protocol (IP), which makes a best effort at delivery of datagrams from their source to their destination. Security concerns at the network level include route poisoning, DoS, spoofing, and fragmentation attacks. Fragmentation attacks occur when hackers manipulate datagram fragments to overlap in such a way to crash the victim’s computer. IPSec is a key security service that is available at this layer.

Data Link layer
Layer 2 is known as the Data Link layer. The Data Link layer is responsible for formatting and organizing the data before sending it to the Physical layer. The Data Link layer organizes the data into frames. A frameis a logical structure in which data can be placed; it’s a packet on the wire. When a frame reaches the target device, the Data Link layer is responsible for stripping off the data frame and passing the data packet up to the Network layer. The Data Link layer is made up of two sub layers, including the logical link control layer (LLC) and the media access control layer (MAC). You might be familiar with the MAC layer, as it shares its name with the MAC addressing scheme. These 6-byte (48-bit) addresses are used to uniquely identify each device on the local network. A major security concern of the Data Link layer is the Address Resolution Protocol (ARP) process. ARP is used to resolve known Network layer addresses to unknown MAC addresses. ARP is a trusting protocol and, as such, can be used by hackers for APR poisoning, which can allow them access to traffic on switches they should not have.

Physical layer
Layer 1 is known as the Physical layer. At Layer 1, bit-level communication takes place. The bits have no defined meaning on the wire, but the Physical layer defines how long each bit lasts and how it is transmitted and received. From a security standpoint, you must be concerned anytime a hacker can get physical access. By accessing a physical component of a computer network—such as a computer, switch, or cable—the attacker might be able to use a hardware or software packet snifferto monitor traffic on that network. Sniffers enable attacks to capture and decode packets. If no encryption is being used, a great deal of sensitive information might be directly available to the hacker.

TIP 

For the exam, make sure that you know which attacks and defenses are located on each layer. 


20120229

Learn Ethical Hacking Basic: Session XIX

The Ethical Hacker’s Process
As an ethical hacker, you will follow a similar process to one that an attacker uses. The stages you progress through will map closely to those the hacker uses, but you will work with the permission of the company and will strive to “do no harm.” By ethical hacking and assessing the organizations strengths and weaknesses, you will perform an important service in helping secure the organization. The ethical hacker plays a key role in the security process. The methodology used to secure an organization can be broken down into five key steps. Ethical hacking is addressed in the first:

                                  Learn Ethical Hacking Basic: Session XVII

  1. Assessment
Ethical hacking, penetration testing, and hands-on security tests.
  1. Policy Development
Development of policy based on the organization’s goals and mission. The focus should be on the organization’s critical assets.
  1. Implementation
The building of technical, operational, and managerial controls to secure key assets and data.
  1. Training
Employees need to be trained as to how to follow policy and how to configure key security controls, such as Intrusion Detection Systems (IDS) and firewalls.
  1. Audit
Auditing involves periodic reviews of the controls that have been put in place to provide good security. Regulations such as Health Insurance Portability and Accountability Act (HIPAA) specify that this should be done yearly.
All hacking basically follows the same six-step methodology discussed in the previous section: reconnaissance, scanning and enumeration, gaining access, escalation of privilege, maintaining access, and covering tracks and placing backdoors.

Is this all you need to know about methodologies? No, different organizations have developed diverse ways to address security testing. There are some basic variations you should be aware of. These include National Institute of Standards and Technology 800-42, Threat and Risk Assessment Working Guide, Operational Critical Threat, Asset, fand Vulnerability Evaluation, and Open Source Security Testing Methodology Manual. Each is discussed next.

National Institute of Standards and Technology (NIST)

The NIST 800-42 method of security assessment is broken down into four basic stages that Include:

  1. Planning
  2. Discovery
  3. Attack
  4. Reporting

NIST has developed many standards and practices for good security. This methodology is contained in NIST 800-42. This is just one of several documents available to help guide you through an assessment. Find out more at http://csrc.nist.gov/publications/nistpubs.

Threat and Risk Assessment Working Guide (TRAWG)

The Threat and Risk Assessment Working Guide provides guidance to individuals or teams carrying out a Threat and Risk Assessment (TRA) for an existing or proposed IT system. This document helps provide IT security guidance and helps the user determine which critical assets are most at risk within that system and develop recommendations for safeguards. Find out more at http://www.cse-cst.gc.ca/publication.../itsg04-e.html.

Operational Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE)

OCTAVE focuses on organizational risk and strategic, practice-related issues. OCTAVE is driven by operational risk and security practices. OCTAVE is self-directed by a small team of people from the organization’s operational, business units, and the IT department. The goal of OCTAVE is to get departments to work together to address the security needs of the organization. The team uses the experience of existing employees to define security, identify risks, and build a robust security strategy. Find out more at www.cert.org/octave.

Open Source Security Testing Methodology Manual (OSSTMM)

One well-known open sourced methodology is the OSSTMM. The OSSTMM divides security assessment into six key points known as sections. They are as follows:

* Physical Security
* Internet Security
* Information Security
* Wireless Security
* Communications Security
* Social Engineering

The OSSTMM gives metrics and guidelines as to how many man-hours a particular assessment will require. Anyone serious about learning more about security assessment should review this documentation. The OSSTMM outlines what to do before, during, and after a security test. Find out more at 
www.isecom.org/osstmm.