Blogger Widgets

Tuesday, 15 October 2013

Denial Of Service Attack (DoS) #DDOS #DOS #Hacker




This is a kind of attack in which an attacker or intruder tries to deprive system users or authorized users from accessing remote computer, network or a site. An attacker usually targets bandwidth of victim to perform this attack. Illegal use of internal resources may also result in denial of service hence it is not always the case that system has been attacked remotely it can be attacked from internal network from an unsatisfied or disgruntled employee. It can also be executed against network resources, services and data access in a networked environment. In all motive of DoS is only destruction not stealing although it can be performed as a distraction while stealing *Giggling*.
As a typical result of DoS a system may hang, respond slowly, reboot or shutdown a system. A worst case result may include loss of information, damage of network resources and hardware and ultimately deletion, destruction of data and programs of users that were online during attack. Thus DoS attack compromises system without intruding and is enough to disorganize organized infrastructure and functionality of an organization.

A DoS attack is also called Distributed Denial of Service (DDoS) attack when DoS attack is performed using several computers/laptops/zombies.

Now depending on what factor attacker has planned to attack modes of attacks are classified as follows,

1.Attack Against Connectivity:- In this kind of attack an attacker tries to stop hosts or users from connecting and communicating with another host or computer.

2.Misuse Of Internal Resources:- In this mode of attack an attacker tries to bind resources to specific machines which results in consumption network bandwidth and wastage and non-availability of resources for others.

3.Bandwidth Consumption:- In this mode of attack attacker generates large number of packets from system on which attack has been planned to be performed. Resulting consumption of bandwidth finally lead its unavailability for others and results in DoS attack.

4.Consumption Of Network Resources:- In this mode of attack an attacker tries to consume resources on network.

5.Altering Configuration:- In this attack mode an attacker may try to exploit misconfigured information present on network for DoS.

Depending upon selected mode of attack DOS attacks are classified as,

SYN Attack

Smurf DoS

Buffer Overflow

Ping of Death

Tear Drop 



-:Types Of DoS:-

In this section we are going to cover different ways that can be used to carry out denial of service attacks. Note that no matter what kind of DoS attacker selects his/her motives remain same i.e bandwidth consumption, disrupting network connectivity or the destruction of configuration information.

1. Smurf DoS or Ping Flood:-

In this type of attack an attacker sends large number of ICMP echo (ping) to IP broadcast address and all the packets he/she sends have spoofed IP addresses. If the victim accepts IP broadcast request packets, then it will take ICMP request and reply thus multiplying the traffic by number of hosts resulting bandwidth consumption. Modes of attack used are bandwidth consumption and network connectivity

 2. Fraggle DoS Attack:-

It is same as Smurf DoS attack but instead of ICMP packets it uses UDP echo requests. Modes of attack used are bandwidth consumption and network connectivity.

3. Buffer Overflow Attack:-

Most commonly used DoS attack, can be performed locally or remotely. Most commonly used attack method is using a vulnerable application or program. Result of compromise on security of network. Common modes of attacks are misuse of internal resources and altering configuration

4. Ping Of Death:-

In this type of attack an attacker deliberately sends an ICMP echo packet of more than 65536 bytes. IP packet with size of 65536 bytes is oversized packet for TCP/IP stack. Many OS don’t know how to response to such huge packet resulting in freezing or crashing down. Attack mode can be classified as altering of configuration and misuse of resources.





5. Teardrop Attack:-

This attack takes advantage of fragmentation of IP packets during transmission. A large packet is chopped in pieces for easy transmission with each having sequence number in offset so that when all chucks get received they can be easily combined. In tear drop attack an attacker manipulates the offset value of the second or later fragment to overlap with previous or next one. This attack may cause hang and crash of system. Mode of attack is altering configuration.

6. SYN Half Open and SYN Flood:-

In SYN half open attack attacker exploits weakness in TCP three way handshake method and sends only SYN packet with spoofed IP and thus the target waits for opened connection to completed and since IP is spoofed there remains hardly any chance that connected will be completed. This results in non-availability of resources builds overload on system and it crashes down. In SYN flood attack attacker sends thousands of SYN packets to victim with huge frequency than it can handle resulting in denial of further requests. Both can be categorized under attacks against consumption of network resources and altering configuration.

-:Tools that Can be Used for DoS:-

In this section we will discuss a little about tools that can be used for DoS attacks. Please note that tools used for DoS attacks and DDoS are different, here we will discuss only those tools which are used for DoS attack not those which are used for DDoS. Most of the DoS tools are nothing but programs written by programmers, by the way you don't need to know about programming to understand and run these tools. These tools may be OS specific or platform independent depending on what condition the programmers has built the code.

-:JOLT:-

Jolt is DoS tool used to exploit vulnerability in windows networking code. It allows attacker to consume 100% of CPU time by sending packets that needs heavy CPU usage for processing. Though it is specially designed for windows it really isn't platform specific. The most vulnerable server to it is Windows 2000 Server.

-:BUBONIC:-

It is a C program when compiled can be used against windows and Linux. Linux versions which were not updated since 2.0.3.0 kernel are vulnerable along with windows 2003 server

-:LAND:-

Land tool sends victim request by spoofing IP address of packet with IP address of victim. Since IP address of source and destination are same, system crashes as system starts flooding itself with packets.

-:LATIERRA:-

It also works as Land tool but it sends TCP packets to more than one port number.



-:TARGA:-

One of the most horrible DoS tool in list is Targa. Targa can launch DoS attack in all possible types of DoS attacks. Its efficiency increases exponentially with more number of PC's.

-:BLAST:-

Blast is TCP services stress test tool but can also be used for launching DoS attack against unprotected server.

-:NEMSEY:-

It is a program that generates random packets with random port number and IP address and floods victim with it.

-:PANTHER:-

Its a packet flooding program that can overload a network connection with ICMP packets by sending fast ping requests causing a DoS attack.

-:CRAZY PINGER:-

It is also DoS tool of category flooder. It sends very large packets of ICMP to target.

-:FSMAX:-

It is a scrip-table server stress testing tool. This takes a text file as input and runs a server through a series of tests based on input. The purpose of this tool is to find buffer overflows of DoS points in a server.



Distributed Denial Of Service (DdoS)

Distributed Denial Of Service (DDoS) Attack is large scale DoS attack conducted with help of zombie systems or botnets on vulnerable target systems. Indirectly we can say a DDoS is launched via huge network of compromised systems. DDoS attack uses many computers to

 launch a coordinated DoS attack against one or more target. Using client/server technology (same as we do it in RAT clients), the attacker is able to multiply the effectiveness of the denial of service significantly by harnessing the resources of multiple computers to serve for attack. In most of the cases the zombie system user never come to know about his/her system is performing a DoS attack since an attacker can put condition to be low on bandwidth usage per zombie.

The victims compromised for performing an attack are known as “secondary victim” whereas the attack on the target is known as “primary victim”. An attacker generally gains administrative privilege on secondary targets to launch attack on primary target. Once attacker gains administrative privilege on secondary victim, he/she uploads DDoS program or script to launch an attack on primary victim. If an attacker has network of 30000 plus zombies then launched attack is nearly impossible to counter because number of IP address is too much for a single server to handle per second. DDoS are dangerous because they can even pull down very big hosts like Yahoo and Bing to their feet.

Most organizations secure themselves with a firewall but a firewall does not really guarantee against DDoS. A very good but badly administrated firewall can even lead to fall down of service. Conducting a DDoS attack is much simple than it appears if you already have thousands of compromised system. In fact in most cases you don't even need already created tools you can manually create your own tools if you have little programming knowledge of C and C++ and little about windows and Linux commands. In future posts I’ll show you how you can create your own script to launch a DDoS attack. 

Following are steps involved in conducting DDoS attack:

1. Compromise thousands of systems using RAT clients or botnets.

2. Write a program or script that can conduct attack

3. Trigger Zombies for attack

4. Don't stop until the target is down. 



For more information about denial of service attack and distributed denial of service attack you can check out  these other blog post Legendary DDoS Attack and DOS vs DDOS
Thanks For Visiting

Thursday, 10 October 2013

Cloud Computing #CloudComputing #Infosec #Networking






Cloud computing is the technology of computing which is totally based on the internet media. With the help of this ethnology many servers can offer software applications and resources and information to the computer and devices attached on request with the control of electricity grid. It can be called as the service architectures or virtualization for improving the utility of the computational techniques. Whole system is service oriented and customer focused. Complete detail is taken from the customer and delivers the service
The main idea of cloud computing is based on the cloud that is specifically designed for the processing each related device is present in this cloud of network. Could computing remains invisible to the customers’ .They only have to pay for their resource that they use in cloud computing services.

How cloud computing works :-
Cloud computing involves the multiple cloud components that communicate with each other with the help of application interfaces mostly web services. UNIX operating system follows the same theoretical techniques for its tasks.
The task complexity is divided into all the components making balanced and manageable results.
The two most important components of the back end and front end the front end is the interfaces or the main screen that is visible to the customers and users through which they interact with the system. This interface can be browsed with the help of web browsers and all the applications can be used with this interface. Usually this interface is GUI based.
The back end involves all the components and the complete architecture and programming technique of cloud computing that is totally remains hidden from the users. Only system known what is going one at the back of very user request. The back end device involves, cloud server, Assistant computers, Data storage media and many connectors.


Historical background
The very first concept for the cloud computing was given by the John McCathy in 1960s.he first gave the statement for the future use of computational techniques as a public utility. With the arrival of the
Virtual private networks this concept which was modernized in 1966 took implementation shape .in year 2007 the most famous organization such as Google, IBM and may universities worldwide started research program on cloud computing and finally in 2008 the first cloud computing system was introduced.

Advantages of the cloud computing:-

1) Agile functionalities:- Cloud computing enables user to frequently use the technological resource at inexpensive price.

2) Application interface from users:-
Another great feature plus advantage of cloud computing system is the accessible and reliable interface for its users API technology make it more interesting for the users to interact with the human beings.

3) Cost effective :- This computing techniques greatly reduce the total cost and capital expenses that comes in arranging the infrastructure .integrated resources are available at almost no cost to the third party users.

4) Geographical independence of system and devices:- The most exciting feature of the cloud computing is its total geographical independence. Its users can access the system from the web browsers anywhere in the world at any time.

5) Multi and large application pool:-
Large application pool is available for the users.

6) Reliability:- improved design versions of many redundant website have efficiently increase the performance and suitability of cloud computing more useful.

7) Security:- Security is at the one level above as compared to the other networks because of the centralization of data and increased security feature of very individual component.

8) Maintenance:- Cloud computing systems are flexible and easy to maintain because components can be added and deleted from the infrastructure

Top Ways To Secure Your Data #SecureData #PasswordProtection #Infosec





If you haven’t taken steps to secure your personal and professional data, consider Data Privacy Day (Jan 28th) as a belated New Year’s resolution. Even if you think of yourself as completely secure already, chances are that you’ll find yourself lacking on at least one or two of the following 10 ways to safeguard your information.


1. Password Protection. Everything that you use has a password, right? And it’s been changed in the past 3-4 months? Your PC, your smartphone, your router, your accounts, your screensaver? You say yes, but you’re secretly saying “well, except for x which doesn’t need one”. No, x needs one too. If it exists, someone is going to pick up/ sit down at/ try to hack into it. And even if it does have a password, now’s the time to change it, because six months/ one year/ five years is too long.


2. Password Optimization. So you know enough to change your default passwords. You know that {password” or “123456” isn’t going to cut it. But you may not be out of the water if you’re using an actual word or phrase for your password — try a random collection of upper- case letter, lower-case letters, numbers, and special characters. Several online tools such as strong password generator.com will do the hard work for you.


3. Password Differentiation. I hope you had fun generating your random password, because you’re going to want to do it again for each and every device and account that you have. There’s no excuse for using the same password to log into your bank account as you use to log into Facebook. If anybody gets the one, they’ll automatically have all of them — it’s called damage control.


4. Insecurity Question. Of course, those backup security questions will be there to give you a little help if that randomly-generated password eludes you. They’ll also help someone else steal it from you. So how about making it harder for them, by choosing a question and answer that nobody in their right mind would choose? Microsoft
Researcher Danah Boyd offers some tips to get you started.



5. Email Bombs. Many of the worst data breaches of the past year started with a simple  phishing strategy. You’ve heard this all before, but many of you didn’t listen, so here we go again: don’t open attachments from strangers, don’t click links in emails from strangers. And because contact lists are the first things to get exploited,“strangers” means pretty much anybody, unless you’ve got a very good reason to expect and trust attachments and links from them.
Don’t forward emails to and from your different accounts (especially between Gmail/ Hotmail/ Yahoo Mail and enterprise email servers). Crank up the spam/ junk mail controls and encrypt as much as possible.


6. The Uncarved Block. You’re leaving your data in more places than ever these days, please try to wipe before you flush. Whether it’s that amusing Lego zip drive that you let your friend borrow, or last year’s iPhone that you trade in to your mobile provider, take the time to erase, overwrite, or otherwise remove any trace of your previous ownership — it can come back to haunt you. Re-format anything that has a drive before you let go of it.


7. The Soft Touch. Personally, I hate security software. Anti-virus applications tend to hog resources, launch on startup, run in the background, update themselves automatically, and generally do all of the things that I specifically try to prevent my applications from doing. But since they also protect me from becoming infested with malware, I learn to live with it.
Without playing favorites, allow me to direct you to a good round-up of the best anti-malware tools.


8. Keep the Home Fires Burning.
Speaking of smart things that I hate to install and keep running, a good firewall is one of your best friends. Undoubtedly you have one — in your router, server, and/ or operating system. Have you closed all open ports? Have you thought to check the firewall’s logs? The firewall can tell you if you’re getting poked and prodded by would-be intruders, giving you notice to tighten your security measures even more.


9. Remote Control. Your operating system, router, and even your smartphone may actually have some sort of remote access turned on by default. You may not know this fact, but I’ll guarantee that would-be infiltrators do. Make it your business to hunt down every possible remote administration setting and process, and turn them off — otherwise, you’re potentially at the mercy of anyone with an Internet connection.


10. Managing Risk. Are you running a company, or in charge of the company network? You not only have to close your own holes, but also keep company workers from creating new ones. Establish best practices, develop an Acceptable Use Policy, and ensure that everyone is fully trained. Deactivate accounts as soon as employees become ex- employees, and optimize access credentials to ride that fine line between security and creating more work for yourself — such as constantly responding to user confusion and complaints.


Wednesday, 9 October 2013

Encrytion For Beginners #Encryption #Infosec




What Is Encryption
Encryption is a method or a technique used to encode a message so that it can’t be read by a normal user/person. It’s an art of secret writing; it can also be defined as converting information from plain text using an algorithm or a cipher to make it unreadable, So that the converted information can only be read by the person who is having the special knowledge. The process of encoding is known as Encryption and its reverse process i.e. decoding it is known as Decryption. Encryption is very useful when it comes to protecting your confidential data from being stolen.
It is helpful when data is transmitted over the network, it safe guards you data from sniffers.
When data is needed to be encrypted over a network, SSL Protocol is used for encryption purpose. SSL stands for Secure Socket Layer.


Types of Encryption
Symmetrical Key: This type of encryption is also known as Shared Key Secret. In symmetrical encryption, the key which is used in the process of encryption, that same key is also used in the process of decryption. If two parties want to exchange the encrypted data securely, both of them should have the same copy of symmetric key.

Asymmetrical Key: This type of encryption is also known as Public Key. In this type of encryption, keys are generated in pairs, public key and private key. In asymmetrical
encryption key used to encipher is different from the key used to decipher. Therefore the two partners have two different keys, one is made public and other one is made private. Let’s take up an example to understand the concept in an easy way. Suppose, John wants to send a message to Mike, he just ciphers the message with the public key and sends it to Mike. Since Mike is having the secret key, he can and decipher the message and read its content



Click Here>> To Learn More About Encrypting Emails

Hacking Administrator Password Using Guest Account #Hacker #Hacking #Windows






Hacker

A hacker is someone who seeks and exploits weaknesses in a computer system or computer network. Hackers may be motivated by a multitude of reasons, such as profit, protest, or challenge. The subculture that has evolved around hackers is often referred to as the computer underground and is now a known community. While other uses of the word hacker exist that are not related to computer security, such as referring to someone with an advanced understanding of computers and computer networks, they are rarely used in mainstream context. They are subject to the long standing hacker definition controversy about the true meaning of the term hacker. In this controversy, the term hacker is reclaimed by computer programmers who argue that someone breaking into computers is better called a cracker, not making a difference between computer criminals (black hats) and computer security experts (white hats). Some white hat hackers claim that they also deserve the title hacker, and that only black hats should be called crackers.

Hacking Administrator password using guest account
Many of you might be using computers with Guest accounts specially in schools and colleges they restrict you to use administrator account.
And you have to use guest as you don't have the Administrator password!
But after this tutorial you don;t need to ask anyone for getting Administrator password :)

There are 2 methods to get Administrator password. Choose the one which seems more suitable for you.

METHOD 1

1) Go to C:/windows/system32

2) Copy cmd.exe and paste it on desktop

3) Rename cmd.exe to sethc.exe

4) Copy the new sethc.exe to system32 folder, when windows asks for overwriting the file, then click YES

5) Now Log out from your guest account and at the user select window, press shift key 5 times

6) Instead of Sticky Key confirmation dialogue, command prompt with full administrator privileges will open

7) Now type “NET USER ADMINISTRATOR "pass" "where “pass" can be any password you like and press enter You will see “The Command completed successfully" and then exit the command prompt and login into administrator with your new password. You have hacked admin through guest account.


METHOD 2

1. Right-click on “My Computer” icon on the desktop OR in the Start Menu

2. Select the option “Manage”

3. On the left pane expand the “Computer Management (Local) tree"

4. Double click “Local Users and Groups” option. From “System Tools” tree

5. Click the “Users” option

6. Now you will see the list of users on the right side panel, such as Administrator, Guest etc
7. Right click the “Administrator” and select the option “Set Password” option
8. Now you will see a warning message, Click on. proceed
9. Now the system asks you for “New Password” and “Confirm Password”
10. After entering the password click on “OK”. The password is changed.
You have successfully changed the Administrator password.
Enjoy :)