Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, October 7, 2012

|| HACK DECODER BOOK BY HITESH MALVIYA ||


Hitesh Malviya is one of foremost it security expert of India released his first book on hacking named “Hackdecoders v 1.0”. This book will be proved campact bomb for beginners. Both basic and advanced hacking topics are covered with images in this book.

The book is having chapters on facebook hacking, google hacking, clickjacking, website hacking and much more as to guide people as how to find solutions to all these problems.

He is a young entrepreneur started his venture hcf infosec pvt. Ltd. working in it security domain from last 2 years. Hitesh has been frequent speaker for international conference defcon India chapters.

The book is released online and available on www.hcf.co.in for download. He is planning for next version of this book, Hopefully will be come up with next version by end of this year. 

Table of contents:
:: Introduction to Ethical Hacking
:: Information Gathering & footprinting
:: Scanning & Enumeration
:: Trojans and Backdoors
:: System Hacking
:: Google Hacking(Basic & advanced)
:: Sql injection and countermeasures
:: Cross site scripting and Countermeasures
:: Remote & Local File inclusion and Countermeasures
:: Email account cracking & security
:: Facebook Clickjacking
:: VPN & Proxies
:: Hacking Mobile Phones, PDA, Handheld devices
:: Computer Forensic & Incident Handling
:: Career certifications in Information Security

DOWNLOAD LINK:- CLICK HERE

Read More...

Monday, September 10, 2012

|| WEP cracking using fern-wifi-cracker ||


A very good tutorial by my friend harpreet singh on Wep Cracking. He has used the tool "fern-wifi-cracker" which is easily avaliable on backtrack 5 R3.

So lets begin ...
Go to backtrack --> exploitation tools --> wireless exploitation tools --> 
WLAN exploitation --> fern-wifi-cracker

Now select the wireless interface you have ( it can be wlan0, wlan1 etc..)


























Now there's a button on which you can see wifi logo, click that and it will start the network scanning ( of-course its using airodump here).

Note*: if you double-click anywhere in the tool, you'll get a "settings" dialog box... you can set the channel there and also you can start the xterm.


























Now if you see closely, you'll note that the two buttons below the scan button will get enabled, the first button is the WEP cracking button and the second one is for WPA cracking.

Click the button for WEP cracking


























After clicking that button, a new dialog box will open. you can select the wep network from the list and then you can select the type of attack i.e arp replay attack, chop-chop attack or fragmentation attack. then click "Attack"...


























You'll be able to see the number of ivs are increasing.There's a progress bar at the end of the dialog box.When the progress bar reaches the end, this tool starts aircrack for cracking wifi password


























When the password is cracked, it will be shown at the bottom of the dialog box...

NOW COMES THE INTERESTING PART:
(before going further, i suggest you to connect to the internet for this)

Go to "toolbox" --> Geolocatory tracker.




















Give the bssid of the AP in the text box and click "Trace".




















I think everyone has already guessed what it will show...

YES... INDEED... IT WILL SHOW YOU THE LOCATION OF THE AP ON THE GOOGLE MAPS ... You can see the coordinates as well..




















And also you can see in the toolbox, there's a button for cookie hijacking called "cookie hijacker" ..

ok guys so that's it for now... :-)

Comment Below for any help
Read More...

Tuesday, May 29, 2012

|| How to Patch Symlink ||



How to Prevent Symlink Attack
by Shubham Upadhyay
:: 0x01 Introduction ::

What is Symlink?

Symlink, commonly known as Symbolic links. It is used for creating shortcuts in Linux.
Bad Impact of Symlink - Suppose you own a small hosting company with a Linux Box, & 1337 sites are hosted there. If an attacker gains access to any single site on your server, he can easily create a symbolic link to / directory & then putting the document root afterwards it. Now the attacker can easily read sensitive files, that can be the configuration file of your billing system. Since, he has local access, now he can easily connect to the mysql & pwn all your clients, & the whole company.
How Symlink is Created - A basic linux command is used in creating symlink. i.e,
ln -s source_file link_name




:: 0x02 Protecting ::

Patching Symlink-
  1. Change the permission of /bin/ln to 400.
  2. Locate php.ini by command- “locate php.ini” (without quotes) Edit the main php.ini & disable symlink & proc_open.
  3. If you have a shared host, & it is vulnerable to symlink.Then, change the permission of your configuration files to 400.
  4. Turn PHP safe_mode ON





Contact Me-  http://fb.me/ShubhaM1337
Read More...