Friday, June 21, 2013

M-2 Network scanning Part 2

Hello My dear friends,

How was my 1st part? I hope you like it. That was the theory stuff. when I was learning hacking past 2 year I always ignored theory part. Because i always wanted to be do practical things. I usually ask myself only why should I do waste my time for learning theory part rather than practical? But then I realize i was wrong.
without knowing theory part you can't understand practical things in hacking world. you have to go through that then you will be enjoy practical things.

Today we are learning about scanning mechanisms. how hacker's are going to be compromise your security?
and why this scanning mechanisms is so much more important? so here is we will discuss about different scanning part used in cyber security.

Ping Sweep
Ping sweep is used to determine the live host from a range of IP address by sending ICMP Echo request to multiple tools. If host is live, It will return an ICMP Echo reply.

Ping Sweep Tools
1) Angry IP Scanner
2) Utility Ping
3) Ping Scanner pro
4) Pinginfo View

So now generally all the scanning methods perform using TCP protocol. So TCP Set some Flags .So these flags are help to communicate over WAN/LAN/MAN Network.

URG (Urgent)
                     It States that the data contained in the packet should be processed immediately.

FIN (Finish)
                     It tells the remote system that there be no more transitions.

RST (Reset)
                     Used to reset a connection.

SYN (Synchronize)
                     Used to initiate a connection between hosts.

ACK (Acknowledgement)
                     Used to Acknowledgement the receipt of a packet.

PSH (Push)
                     Used  to instruct the sending system to send all buffered data immediately.

                     Standered  TCP communication are controled by flag in the TCP packet header.

So now we are looking forward to see the technique of scanning.
1) TCP Connect Scan
2) Stealth Scan 
3) Syn/Ack/Fin Scan
4) Null Scan 
5) Idle Scan
6) ICMP Echo Scanning
7) List Scan 

1) TCP Connect Scan

--> TCP Connect scan details when a port is open by completing the three- way handshake.
--> TCP Connect scan establishes full connection & tears it down by sending RST Packet.

2) Stealth Scan

--> Attackers use stealth scanning technique to bypass firewall rules, logging mechanisms & hide themselves as usual network traffic.
--> If the port is open then the server responds with a syn/ack packet.
--> If the server responds woth an RST packet then the remote port is in the closed state.
--> the client send the RST packet to close the initiation before a connection can ever be established.

 3) FIN Scan 

--> FIN Scan sends a TCP frame to a remote device with FIN flag set.
--> FIN Scan only with TCP/IP Developed according to RFC 793
--> It will not work against any current version of microsoft windows.
--> IN FIN Scan attacker send TCP frame to remote host with any FIN flags set.

4)  Null Scan 

--> NULL Scan only works if O.S TCP/IP implementation is developed according to RFC 793.
--> Not work against any current version of M.C.W.
--> In This scan attacker send a TCP frame to a remote host with no flags.


5) Idle Scan.


--> Port is considered open if can application is listening on the port.
--> one way to determine whether a port to open is to send a "SYN" (Session Establishment) Packet to the   port.
--> The target machine will send back a "Syn/Ack" (Session required acknowledge) packet it the port is open and an "RST(Reset)" packet if the port is closed.
 --> A machine which receives an unsolitted Syn/Ack Packet will respond with an RST an unsolicited RST will be ignored.
--> Every IP Packet on the internet has a fragment identification number.
--> It is a TCP port scan method that allows sending spoofed packet to a computer through software tools such as NMAP & HPing.

 
6) ICMP Echo Scanning 

--> This is not port scanning since ICMP  does not have a port abstraction.
--> But it is useful to determine which host in a network are up by pinging them all.
--> e.g nmap -P cert.org /all 192.168.0.0/16

7) List Scan

--> This type of scan simply generates and prints a list of IP's/Names with out actually pinging or port scanning them. A DNS name resolution will also be carried out.  

So we have seen different techniques from scanning .
but about piratical? so guys be ready for practical we very near to do some practical things after completing this portion. Don't forget to tell me how is this? and I'm also telling you most important thing belonging to this field. So just Wait And Watch.

Sunday, June 16, 2013

M-2 Network scanning Part 1

Hello buddy's, How are you ? wanna know detail about network scanning? Don't worry so this our second part NETWORK SCANNING. :)

Network scanning task is very important & necessary in cyber security field. we gather three main things by using network scanning.
1) IP address & open port's of live hosts.
2) O.S (Operating System) & system architecture.
3) Service running on host

You can say it is procedure for finding information related to Host, Port & Services on a given network.
Scanning is one of the components of intelligence gathering for an attacker to create a profile of the target organization.

There are basically three type of scanner
1) Port Scanning
2) Network Scanning
3) Vulnerability Scanning

1) Port Scanning

--> It is a technique used to identify open ports & services available on a network host.
--> It is also utilized by security technicians to audit computers for vulnerabilities.
--> Also used by hacker's to target victim's.
--> It can be used to send request to connect to the targeted computer and then keep track of the ports        which appear to be opened or those that respond to the request.
--> Each individual computer runs on multiple ports.
--> Unfortunately, Criminals & computer hacker are always looking for new victims to exploit & port             scanning is one of the way's through which this can be accomplished.

2) Network Scanning

--> It is one type of procedure by which we cab identify active host on a network or for network security assessment.
--> Generally attacker use this for attacking to target host after identifying vulnerability on network.

3) Vulnerability Scanning

--> A process of pro actively identifying security vulnerability of computing system in a network in order to determine if & where a system can be exploited and/or threatened.
--> This Scanning procedure is refers to the scanning of system that are connected to the internet but also refer to that are not connected to the internet.

Now friends Tell me Do you know something about ICMP?
ICMP (Internet control management protocol )

here we are not discussing about what ICMP does? why ICMP need for scanning we already learn about this protocol in our graduation level. So we are here just see the main role of ICMP scanning used in network scanning.
--> Ping scan involves sending ICMP Echo request to the host if the host is live, it will return an ICMP Echo reply.
--> This perticular scan is for locating active device of determine if ICMP is passing through a firewall.


E.g Ping scan output using NMAP 
# nmap -sP -v 129.67.X.X


Friday, June 14, 2013

M-1 Footprinting Part 3

he guys .. how's it part 1, part 2. I hope you like it. If u wanna detail knowledge regarding footprinting pls use internet. in this field internet is our teacher, friend and all :). so be friendly and hungry about knowledge.
It's been very tough part to tell you this thing in deeply. And in this part I will finalize the footprinting section.
In part 2 we have seen only threats and it's type. In this section we can see the countermeasures and footprinting Pentest. But before we will see remaining portion of threat's. 

5) WEBSITE Footprinting

Web mirroring tools allows you to download a website to a local directory, building recursively all directories   HTML Images, Flash , Videos from the server to your computer.

Website Mirroring Tools  
1)HTTrack Website Copier (http://ww2.htttrack.com/) 
2)KEEPNI (http://www.keepni.com/)

Mirroring Entire Website tools 
1) Wget (http://www.gnu.org/)
2) teleport pro (http://www.tenmax.com/)

-> Extract website information from http://archive.org/index.php 
-> as well as you can monitor web updates using website watcher. 

6) EMAIL Footprinting

Email Tracking Tools
1) email tracker pro (http://www.emailtrackerpro.com/)
2) didtheyreadit (http://www.didtheyreadit.com/)
4)Trout(http://www.foundstone.com/)

Now we will see some footprinting tools....
1) Prefix
2) Netmask
3) Maltego

I'm not giving here that much tools sorry for that. except you guys can tell me those name. then I will know that you guys are actually reading my blog. :p :). not joking it's ur assignment


FOOTPRINTING COUNTERMEASURE

Now will discus about the countermeasure. what should we do for preventing this type attack. Yes this is also one type of attack . but sorry we can't get to know about this..here this methods.
-> Configure routers to restrict the footprinting request.
-> Configure web server to avoid information leakage & disable unwanted protocols.
-> Lock the ports with the suitable firewall configuration. 
-> Use an IDS.
-> Evaluate the information beofore publishing it on the website / Internet .
-> Remove any sensitive information found
-> Prevent search engine form caching a web pages & use anonymous registration services.

FOOTPRINTING PENTEST

It's always been toughest part in cyber security field. Pen testing gives you all details. 
In this footprinting determine organization's publicly available information on the internet such as network architecture , O.S , Applications e.t.c 

Te tester attempts to gather as much information as possible about the target organization from internet & other public accessible source.

Pen test usually get  proper authorization & then after declare the scope of work. Pen tester performs some footprinting technique to gather the information like internet footprinting using LINK EXTRACTOR e.t.c 
Or WHOIS footprinting using SMART WHOIS e.t.c or Competitive intelligence using tools such as SPAN e.t.c e.t.c e.t.c e.t.c at t  he end pen testing document all the file findings.

Here we complete ore first module Footprinting. SO how is this guys.. Fun na ? ust enjoy this section ..
One more thing pls this knowledge for EDUCATIONAL purpose .. Don't do any illegal thing..
Be a smart WHITE HAT HAKCER.. :) and BE HAPPY . 

Tuesday, June 11, 2013

M-1 Footprinting Part 2

once again hi .. sorry for late updating. it's been fantastic thing when u have taken  great work to do.
We have already discussed the terminology and intro part about FOOTPRINTING. In this part we will see about THREATS & METHODOLOGY. Again I should have to tell you guys, "This Blog is for educational purpose, Don't do illegal things. Finally responsible person will be you only".

FOOTPRINTING THREATS

What is Threats? 
Threat is nothing but an attacker gathers valuable system level information such as account details,operating system & other soft. versions etc. 

Threats are the main basic concept by which attacker will attack using given some mechanisms.
There are some following threats include....
1)  Social Engineering 
2)  System & n/w attack
3)  Privacy loss
4)  Business loss

FOOTPRINTING METHODOLOGY 

 This is the main section of footprinting. you will know that how can we gather information? By which tools ?                  how can we get the particular result? etc
there are several methodology used in footprinting. 
1) Internet Footprinting
2) Whois Footprinting
3) DNS Footprinting
4) Network Footprinting
5) Website Footprinting
6) Email Footprinting
These are the main SIX methods by which attacker gain as much as information. 
1) Internet Footprinting
-> Search for the target company in a search engine such as google or bing. 
-> Attacker will find an internal company's URL by trial & error method.
-> TOOLS to search internal URL

-> Identify a company's private or public website 
-> Search for company's information like , Employee details, contact info 
-> as well as attacker will use people search , extract archive & mirror website etc. 

Tools to extract company's data.
1) Web Data Extractor (http://www.webextractor.com/)
2) Spider foot (http://www.binarypool.com/) 

-> use google earth tool to get the location of the place 
-> you can find personal information using online people search services. 
e.g pipl.com , address.com 
-> Gather information from financial services 
e.g Google Finance , Yahoo finance
-> Or you can gather company infrastructure  details from job posting. 

2) WHOIS Footprinting

Whois database are maintained by regional internet registries & contain the personal information of domain owners.

WHOIS lookup tools

Attacker look for
-> Physical location 
-> Email address
-> Contact info 

WHOIS query returns 
-> Domain name details 
-> Domain name server
->Netrange

Reginal internet registry
 -> AFRNIC
-> ARIN
-> APNIC  

WHOIS lookup Tools 
1) Samspade( http://samspade.org/)
2) Country whois (http://www.tamos.com/)

WHOIS online Tools
2) Geek Whois ( http://www.geektools.com/)
3) Domain tools (http://www.domaintools.com/)

3) DNS Footprinting 

DNS Tools
1) Net inspector (http://www.globware.com/)
2) NSlookup ( http://www.kloth.net/)

DNS Online Tools
1) Online DNS tools 
2) DNS record (http://network-tools.com/ )


4) NETWORK Footprinting

-> To find the range of IP address.
-> Use ARIN whois database search tool 
-> You can find the range of IP address & the subset mast used by the target organization from regional internet registry(RIR).

TRACE OUT 
Trace out programs work on the concept of ICMP protocol by use the Time to Live Field i the header of ICMP Packets to discovered the router on the path to a target host. 

Trace out Tools
1) 3D Trace route 
2) Lariotpra
3) Path Analyser Pro

Tuesday, May 28, 2013

M-1 Footprinting Part 1

Hello, Guys Nice to see you again . I have post many more things on my blog. but the things is combination is not there. so from now i will give you cyber security knowledge through module basis. so u can also understand easily and better.

But do one thing as well, keep practicing it . it will use full for you every time. knowledge Enhancement is very necessary in this field. there is one thing i have to tell you that this Blog is only for EDUCATIONAL purpose. Don't do any illegal activity otherwise punishment will meet you . :)

From now i will give you some important knowledge regarding FOOTPRINTING.


a)Defination of Footprinting

   Footprinting is nothing but a collecting as much as correct information about a target network.
- Collecting basic information about the target and it's network.
- Determine the operating system used platforms running, web servers etc.
- Find vulnerability and exploit for launching attacks.
- performed some techniques Whois, DNS etc.


b)Footprinting Terminology

1) Collecting information about a target form the public accessible sources.
2) Gather information through social engineering on site visits, interviews etc.
3) Gather information from sources where the author of the information can not be identified or trace, we   also called it as anonymous.
4) Collect information that might be published under a different name in an attempt to preserve privacy.
5) Collect information form an organisation web based calender and email services.
6) collect information about a target form the internet .

 Next part we will see about Threats and tools used for this footprinting

Saturday, April 13, 2013

Ransomware

Ransomware is a kind of malware (malicious software) that criminals install on your computer so they can lock it from a remote location. Ransomware generates a pop-up window, webpage, or email warning from what looks like an official authority. It explains that your computer has been locked because of possible illegal activities on it and demands payment before you can access your files and programs again.
How do criminals install ransomware?
Ransomware is usually installed when you open a malicious email attachment or when you click a malicious link in an email message or instant message or on a social networking site or other website. Ransomware can even be installed when you visit a malicious website.
How do I avoid ransomware?
There are several free ways to help protect your computer against ransomware and other malware:
What should I do if I have ransomware on my computer?
To detect and remove ransomware and other malicious software that might be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products can detect and remove this threat:

Thursday, March 28, 2013

Top 5 Security Tips To Protect Your Computer From USB Viruses

With increasing anti-virus security in place against email-aware viruses and malware, hackers are turning their attention to less well-defended routes such as USB drives. This is the latest method that’s used by hackers to torment innocent users. However, there are ways you can protect your computer from USB and Pen drive viruses.

1.Block USB Viruses
Invest in an excellent anti-virus program that has built in USB virus scan and remover. These anti-USB virus scan programs not only protect your computer from USB Autorun viruses but can also clean worms, Trojans and viruses in your USB memory sticks.You can try anti-virus programs for USB virus such as USB Virus Scan, USB Drive Antivirus and so on.

2.Disable Your Computer’s Autorun Feature

When you plug in a USB drive stick into your system, the Autorun feature initiates automatically. If your USB contains any virus programs, it’ll use the Autorun feature to infect your computer. To protect your computer, disable the Autorun feature.You can disable the Autorun feature via the Control Panel.
Alternatively, you can use antivirus software to disable and enable the Autorun feature whenever you want. Additionally, these USB blocking softwares allow system administrators to specify which removable storage drives users can access.

3.Update Your Device Driver

Keeping your USB device driver updated is a good way to ensure greater stability for your USB drives. While this won’t help eradicate USB viruses, USB device drivers are constantly updated to block viruses and deliver timely warnings. You can update your USB device drive from your Windows Computer Management feature in the Control Panel.

4.Use USB Firewall Software

USB firewalls prevent Windows OS from processing malicious programs when a virus infected portable USB device is opened. USB firewalls monitor only your USB devices, and not your CD and DVD drives. By using USB firewalls, you’ll be enabling a basic level of protection from the autorun.inf viruses that spread from portable USB devices.

5.Always Safely Remove USB Devices

Viruses are sometimes created via damaged documents. If you are transferring a set of files to your USB drive, make sure the transfer is complete before you eject the device. Always use the Safely Remove Hardware feature of Windows OS. This is because partially transferred or damaged files can in turn corrupt other files on your USB drive