Sunday, September 9, 2007

Anti hacking tips for home based online business

The following are a few anti-hacking tips that will help in keeping your business systems secure.

Don't ignore operating system updates

Practically every day, some new security flaw is found in the most critical aspect of your business - the operating system on which all your other software runs. While it's a major pain in the butt to apply updates and patches so regularly, especially if you access the web via dialup, it's nonetheless of vital importance not to put off performing these tasks as part of regular maintenance.

Don't wait to be alerted via mainstream media of problems that have been discovered - more often than not, these notifications will be delayed. As a part of your daily routine, it's wise to visit the software vendors' site and keep abreast of any critical security updates. In the case of Microsoft, you'll need to go to the Windows Update site.


Anti-virus software used *properly*

Install anti-virus software and ensure that it's regularly updated - this is of the utmost importance. Many times I have come across people who believe that because an anti-virus program is installed, they are protected, yet the last time the virus data file was updated was months or even years ago. Even missing one update could bring down your computer and the business you have struggled so long to build.

Also remember to password protect the settings on the software so no-one else can alter protection levels.


Firewall software


Anti-virus software isn't enough - it's also a good idea to install firewall software which will help prevent unauthorized incoming and outgoing communications from your computer while connected to the Internet. In most instances you wouldn't even be aware that these illegitimate probes and scans of your systems are occurring. Port scanning is *very* common and is carried out with a view to finding weaknesses in your system that can then be exploited.

If you are using Windows XP, then you're in luck as there's already an effective firewall included - but it's not enabled by default.

To activate the firewall in Windows XP:

  • Go to "Start"
  • Go to "Settings", then "Network connections"
  • Select your Internet connection
  • Click on "Properties"
  • Click on "Advanced"
  • Check the box in the "Internet Connection Firewall" section

Email software preview windows

Some viruses, called worms, can infect your system without you clicking on attachments - they can execute in the message preview window. Many worms can cause your sensitive information and documents to be transmitted to millions of people. While the preview window is a handy feature, it's safest to turn it off.

To turn off the preview window in Outlook Express:

  • Select "View" on the Menu Bar
  • Select "Layout"
  • Uncheck "Show Preview Pane"

To turn off the preview window in Outlook:

  • Select "View" on the Menu Bar
  • Select "Preview Pane" if it's not already greyed out
  • You may need to repeat this for each top level mail folder

Consider email filtering services


More and more people are turning to 3rd party solutions for filtering email of spam and viruses as their inboxes become inundated with junk. Email filtering can be very effective in dramatically reducing security risks before the mail even has a chance to be collected by your email software. It not only reduces the risk, but also the amount of time and bandwidth used in retrieving your mail.


Regularly remove spyware

If you and your familiar do a lot of surfing and downloading of shareware software, then it's likely you'll also accumulate your fair share of spyware. Spyware is a broad term applied to software applications that monitor your actions and report them to back to a company.

Some software companies use spyware that is incorporated into their software products to gather data about customers, which is often sold to other companies. An excellent free application for removing spyware can be downloaded from Spybot. Learn more about spyware
Not using it? - unplug it..

Disconnect your computer from the Internet when not in use. The longer you are connected to the Internet, the more opportunity you give for persons to gain unauthorized access. This is especially the case where your ISP provides you with a static IP, which usually occurs in broadband scenarios.


Audit your computer regularly

If your computer is used by others, carry out regular audits of the software on it and research any software that you discover that you haven't installed yourself. It's safest to make it a policy not to allow any software to be installed without your permission. Spybot again is a very effective tool for detecting and removing software that may be a security risk

Remember that your anti-virus software, firewalls and email filtering services should always be considered your last line of defense against software nasties - the first line of defense should be you.


Kid's *aren't* all computer whizzes

Monitor your children's computer usage carefully. They may seem to be "experts", but more often than not they will have very little idea of the ramifications of some of their actions whilst on the Internet. Close supervision is especially necessary in chat rooms as these are places where Script Kiddies and other undesirable elements of the online community are very active.
Password issues

If you must store usernames and passwords on your system, ensure they are contained in a document that is password protected. It is safest not to store any passwords on your computer. Don't let Windows "remember" passwords for you. Passwords should always be more than 8 characters long and contain a mixture of numbers and letters. Learn more about password security issues.


Logging out

Ensure that you log out of online services properly. Failure to do so can allow others who use your computer to gain access to those services and you can be blamed for their activities.

The fight against viruses, script kiddies and other online parasites isn't getting any easier for those of us involved with ecommerce; and as the years go by, more and more of our time and money will be spent on dealing with the darker side of the web.

We can only hope that in the future detection methods become so efficient and punishment becomes so harsh that these kinds of incidences stop occurring. But if the history of our species is any indicator - that's highly unlikely to happen.

Read more!

Top 10 File Sharing Programs

1. eDonkey / Overnet
eDonkey/Overnet is a state-of-the-art P2P file sharing software system. Especially popular in Europe, the two P2P networks eDonkey and Overnet combined support a large base of users and files. The eDonkey P2P client connects to both networks; the Overnet client is being merged into future releases of eDonkey. eDonkey runs on Windows, Linux and Macintosh computers. The free version of eDonkey contains embedded advertising but none of the dreaded "spyware" found in some free file sharing software.
Download

2. Shareaza
Shareaza is an up-and-coming P2P file sharing program. This client offers an extremely powerful search engine capable of connecting to multiple popular P2P networks including eDonkey, BitTorrent and Gnutella. Shareaza file sharing software includes intelligence for detecting fake and/or corrupted files. The free Shareaza download also contains no ads or spyware. As the installed base of Shareaza client users grows, expect Shareaza to become an even better P2P file sharing program.
Download

3. WinMX
WinMX offers a large P2P file sharing network and a feature-rich client program that has evolved over years of development. True, WinMX has a reputation for being complex and more difficult to use than some alternatives. However, WinMX also provides power to users in managing their downloads, and it offers a wide selection of music (MP3) files. Some WinMX users report waiting in long queues to download popular files. WinMX software runs only on the Windows family of operating systems.
Download

4. BitTorrent
BitTorrent is another free P2P software application. It has attracted a loyal following among those interested in sharing movies and television programs. The offical BitTorrent P2P client generally does not support bandwidth throttling, meaning that it will tend to monopolize a network connection and not allow surfing the Internet or otherwise utilizing the network while files are being downloaded or uploaded. A freely-available alternative BitTorrent client overcomes this limitation.
Download

5. Limewire
The Limewire P2P file sharing program connects to the Gnutella P2P network. Limewire client software is widely recognized for its clean user interface that does not contain adware. Sometimes billed as the "fastest file sharing program," Limewire claims to offer relatively good search and download performance. Free Limewire software downloads are available for Windows, Linux and Macintosh operating systems. Limewire Pro pay clients also exist.
Download

6. Morpheus
Morpheus P2P client application downloads exist in both free and paid Ultra versions. Compared to the free version, the Morpheus Ultra download additionally removes bundled advertising. Morpheus clients are capable of searching Gnutella2, FastTrack, eDonkey2K and Overnet P2P networks.
Download

7. eMule
The eMule project started with the goal of building an improved free eDonkey client. eMule has achieved a large user base, connecting both to the eDonkey P2P file sharing network and a few others. It contains no advertising, and its software base is well-maintained by an open source development team. The chief limitation of eMule's P2P file sharing program is its speed: eMule typically performs downloading much slower than other P2P clients.
Download

8. Ares
Ares is a full-featured free P2P network with its own file sharing programs including Ares Galaxy. Ares clients support decentralized music and other file sharing and include a built-in chat service. Ares strives to offer the simplicity of Kazaa clients with no adware and fast connection times.
Download

9. BearShare
The BearShare P2P file sharing program is a popular free software client for the Gnutella P2P network. Both free and pay downloads of BearShare file sharing programs exist.
Download

10. Kazaa
The Kazaa software family (including the Kazaa Lite family of applications) has been the single-most popular P2P file sharing program / system of all time. Kazaa is fast and easy to use. However Kazaa software and the FastTrack network it utilizes appear to be declining rapidly in popularity and availability of files. Some have criticized the intrusiveness of "adware" embedded in free Kazaa clients. Others have complained about the frequency of encountering fake files on FastTrack.
Download

Read more!

Friday, September 7, 2007

The Secret Life of E-mail

Here is a comprehensive list of what your email message goes through in order to get delivered:

  • Virus Checks - The majority of virus (and worms) these days, travel around the internet by way of email messages. In order to protect valuable network systems from being attacked by a virus, most corporate networks and Internet Service Providers employ virus scanners that look for viruses and worms in much the same way that anti virus scans on your desktop computer. Most email server are set up to delete or quarantine any message that tests positive for a virus.
  • SPAM filters and the huge growth of SPAM - Everyone hates SPAM! So much so, that people will change their ISP providers or email host to get better protection from SPAM. As a result, companies like AOL and MSN spend tons of money coming up with new ways to provide "better" spam protection to their subscribers to reduce their attrition rates.
  • SPAM filtering methods:
    • Phrase filters - Watch what you say! Many email servers use a list of unacceptable or offensive word and phrase lists and will reject or place the message in a junk folder upon a match, so watch what you say, or your message could be rejected.
    • Connection Checks - Poorly configured email servers can cause loss of messages. This is most likely out of your control (unless you are a server admin), but just be aware that when email servers talk to each other, some are very picky about allowing a connection and may reject it if the source server does not "check out" properly.
    • Statistical Analysis - This is used to catch some of the techniques used by spammers like many repeated words or a bunch of unrelated words stuffed in the message (usually to try to throw off the spam filters). Your message can become a victim of this if you do something like copy and paste a data file into the body of your message or if you were to insert a data file (like a mail list or spread sheet) into your message, as opposed to attaching the file.
    • Domain Black Lists - Your ISP does not like your friend's ISP! - server administrators will use a list of trusted (and sometimes not-so-trusted) domain and/or IP address lists to filter incoming messages. If you happen to be using one of the "bad" service providers, your messages could be dropped. Watch the company you keep!
    • HTML code checking and filtering - Don't get too fancy with your Html email messages. Many servers are set up to reject messages that contain certain html code. Especially scripts, deceptive URLs or encoded text.
    • Discretionary Blocking by email address, domain, or IP block. - Most email server gives the admin the power to place a block in their server to deny access to any server or domain of their choosing.
    • Server Rule Sets - in addition to all of the above obstacles, most email servers can be custom configured with rules that will redirect or delete messages on just about any content that you can think of! A incorrectly coded rule could create a virtual sink hole for messages.

Now, assuming your message gets through all of the above checks, the next pitfall is in the email client program, like Outlook.

  • Email Client Rules and Filters - Just like servers can have rule sets that redirect or delete messages, most email client software also has the ability to create custom rules to delete or move messages into a folder. Again, an improperly coded rule could create a black hole for your message.
  • Unsolicited Message Filters, or Junk Filters - Most email client software also provides some sort of Junk mail filter, like Outlooks Junk E-Mail filter and add-on filters like SpamAssassin. These filters have become quite reliable, but there is still a small percentage of False Positives that will occur. Your message could fall victim to one of those false positives.

Other pitfalls:

  • Standards not adhered to - Although there are sets of standards (RFCs) that software providers and administrators of server are supposed to abide to, the standards are many times loosely adhered to. In fact most email server software gives the admin the option to turn on or off specific RFC features at their will or desire.
  • False Positives - Virus and spam filters. - Every content filtering technology has a certain percentage of False Positives that are considered acceptable.
  • Proprietary Systems - There are many home grown systems out there that are simply poorly written and do not conform to standards.
  • The Wild Wild West... Everyone configures their systems based on their view, morals and opinions.
  • Quotas - Sorry, that mailbox is full - Many service providers will limit the size of your inbox. The reasons for this are obvious... storage costs money.
  • Daily Delivery... no so much! - Just because your message got through today, does not mean it will make it tomorrow. Content and virus filters are often updated daily. Also, the little geek behind the server administrators console may decide to add an additonal filter or click on a new feature just to try it out (I know, I've done it)... again, it's the Wild Wild West.

So, how can I Fix this? What can I do?

  • Mostly, be aware of this.
  • Request a "Delivery Receipt". Most email clients support this, however, most email clients also provide the option to ignore them when received. Still, it does not hurt to ask!
  • Request a confirmation. Ask the recipient of the message to reply back to you with confirmation that they received it. This is probably the most reliable method of making sure the message was received.
  • Assume Nothing - never simply assume that the message was received. You know what assuming does... It makes an ass out of you and me!
  • Follow up. If the message is critical, follow up with a phone call, or with an additional email requesting a confirmation.

Email is a great and very convenient for daily communications, but just be aware of the pitfalls and do not over rely on email for critical communications. And please... Don't send your critical business files via email. FTP or burn on CD and send overnight.

Read more!

Six Hacker Thinking Hats

The six hats are:

  1. White Hat Hacker
  2. Red Hat Hacker
  3. Yellow Hat Hacker
  4. Black Hat Hacker
  5. Green Hat Hacker
  6. Blue Hat Hacker
  7. (Others) Grey Hat Hacker

White Hat Hacker

A white hat hacker, also rendered as ethical hacker, is, in the realm of information technology, a person who is ethically opposed to the abuse of computer systems. The term is derived from American western movies, where the good cowboy typically wore a white cowboy hat and the bad cowboy wore a black one. Realizing that the Internet now represents human voices from all around the world makes the defense of its integrity an important pastime for many. A white hat generally focuses on securing IT systems, whereas a black hat (the opposite) would like to break into them — but this is a simplification. A black hat will wish to secure his own machine, and a white hat might need to break into a black hat's machine in the course of an investigation. What exactly differentiates white hats and black hats is open to interpretation, but white hats tend to cite altruistic motivations.

The term white hat hacker is also often used to describe those who attempt to break into systems or networks in order to help the owners of the system by making them aware of security flaws, or to perform some other altruistic activity. Many such people are employed by computer security companies; these professionals are sometimes called sneakers. Groups of these people are often called tiger teams.

The primary difference between white and black hat hackers is that a white hat hacker claims to observe the hacker ethic. Like black hats, white hats are often intimately familiar with the internal details of security systems, and can delve into obscure machine code when needed to find a solution to a tricky problem.



Red Hat Hacker

This simply means how the Red Hat Hacker thinks :

  • Hat (Fire)
  • Intuition
  • Opinion
  • Emotion (subjective)


Yellow Hat Hacker

This simply means how the Yellow Hat Hacker thinks:

  • Hat (Sun)
  • Praise
  • Positive aspects (objective)


Black Hat Hacker

A black hat (also called a cracker or Darkside hacker) is a malicious or criminal hacker. This term is seldom used outside of the security industry and by some modern programmers. The general public use the term hacker to refer to the same thing. In computer jargon the meaning of "hacker" can be much more broad. The name comes from the opposite of White Hat hackers.

Usually a Black hat is a person who maintains knowledge of the vulnerabilities and exploits they find as secret for private advantage, not revealing them either to the general public or the manufacturer for correction. Many Black Hats promote individual freedom and accessibility over privacy and security. Black Hats may seek to expand holes in systems; any attempts made to patch software are generally to prevent others from also compromising a system they have already obtained secure control over. A Black Hat hacker may have access to 0-day exploits (private software that exploits security vulnerabilities; 0-day exploits have not been distributed to the public). In the most extreme cases, Black Hats may work to cause damage maliciously, and/or make threats to do so for blackmail purposes.

Black-hat hacking is the act of compromising the security of a system without permission from an authorized party, usually with the intent of accessing computers connected to the network (the somewhat similar activity of defeating copy prevention devices in software - which may or may not be illegal depending on the laws of the given country - is actually software cracking).

The term cracker was coined by Richard Stallman to provide an alternative to abusing the existing word hacker for this meaning. This term's use is limited (as well as "black hat") mostly to some areas of the computer and security field and even there is considered controversial. One group that refers to themselves as hackers consists of skilled computer enthusiasts. The other, and more common usage, refers to people who attempt to gain unauthorized access to computer systems. Many members of the first group attempt to convince people that intruders should be called crackers rather than hackers, but the common usage remains ingrained.



Green Hat Hacker

This simply means how the Green Hat Hacker thinks:

  • Hat (Plant)
  • Alternatives
  • New approaches
  • Everything goes (speculative)


Blue Hat Hacker

This simply means how the Blue Hat Hacker thinks:

  • Hat (Sky)
  • Big Picture
  • Conductor hat
  • Thinking about thinking
  • Overall process (overview)
  • Refers to outside computer security consulting firms that are used to bug test a system prior to its launch, looking for exploits so they can be closed.



(Other) Gray Hat Hacker

Grey hat in the computer security community, is a skilled hacker who sometimes acts legally and in good will and sometimes not. They are a hybrid between white and black hat hackers. They hack for no personal gain and do not have malicious intentions, but may or may not occasionally commit crimes during the course of their technological exploits.

For example, attacking corporate businesses with unethical practices could be regarded as highly unethical and would normally be considered black hat activity. However, to a grey hat, it may not appear bad even though it is against that local law. So instead of tagging it black hat, it is a grey hat hack. A person who breaks into a computer system and simply "plants his flag" while doing no damage, is usually classified as a grey hat.

Read more!

Thursday, September 6, 2007

Inline javascript - Tutorial

Using Inline Javascript the user can alter things in a website without having to leave it or save the page in his PC. This is done using the address bar from his browser. The syntax of the commands looks like this:

For displaying the code I have replaced javascript with javascrit, and <> tag with [] please replace it before using the code

CODE :
javascrit:alert(#command#)


For example, if you want to see an alert inside the http://www.example.com site, type the URL in the adress bar and when the
page loads, delete the URL and type:

CODE :
javascrit:alert("Hello World")


As a new URL. This way an alert will show up saying 'Hello World'. However, with this technique someone can alter almost everything in a page. For example an image. Lets suppose that there is an image with the site's logo. By viewing the source of the page (This can be done by going to View-Source) we find this piece of HTML code:

CODE :
[IMG Name="hi" SRC="hello.gif"]


So there is an image named "hi" and the source of it is "hello.gif". We want to change this to "bye.jpeg" that is stored on our site http://www.mysite.com. So the full URL of our image is http://www.mysite.com/bye.jpeg
Using Inline javascript we type in the adress bar:

CODE :
javascrit:alert(document.hi.src="http://www.mysite.com/bye.jpeg")


You will see an alert saying http://www.mysite.com/bye.jpeg and after that the image will be changed. Notice though that those changes are temporary! If you refresh the page or enter it again your changes will be lost, because you dont alter the site in the server but in your PC.

Using the same way we can view or change the value of variables. For example we find this piece of code in the site's source:

CODE :

[SCRIPT LANGUAGE="javascrit"]
var a="test"
[/SCRIPT]


This means that the variable with the name a has the value "test". In order to view the value of the variable we would type:

CODE :
javascrit:alert(a)


And in order to change it from 'test' to 'hello':

CODE :
javascrit:alert(a="hello")


However Inline Javascript is mostly used in changing form's attributes. Thats the piece of code we have:

CODE :

[form name="format" action="send.php" method="post"]
[input type="hidden" name="mail" value="someone@somewhere.com"]
[input type="text" name="name"]
[input type="submit" value="submit"][/form]


We want the form to be sent to our mailbox and not to someone@somewhere.com
This can be done by this command:

CODE :
javascrit:alert(document.format.mail.value="me@hacker.com")


As you have noticed by now we always use a hierarchy in the items we edit:
We start from the bigger to the smaller:

1) We started with document

2) We typed the name of the object we wanted to alter (for example document.hi.src) or the item in which it belonged and then the name of it (for example document.format.mail.value)

3) Lastly we ended in the attribute of the item we wanted to change (for example its source: document.hi.src, or its value: document.format.mail.value)

4) We separated the words using dots (.)

5) When we wanted to change an attribute we used the equal sign (=) and the new attribute.

*NOTE: We use "" when the new attribute is a character string (for example: document.format.mail.value="me@hacker.com")
If we wanted it to be the value of a variable we wouldnt used the "". For example we want to change the variable a's value to
the value of variable b.We would type javascrit:alert(a=b)

However most items in a page have no name. For example:

CODE :

[form action="send.php" method="post"]
[input type="hidden" name="mail" value="someone@somewhere.com"]
[input type="text" name="name"]
[input type="submit" value="submit"][/form]


In this code the form's name is missing. Using all the above, the command would look like this:

CODE :
javascrit:alert(document. .mail.value="me@hacker.com")


In this case we will have to count all the forms to find out the form's number. I will use an example:

CODE :

[form action="send.php" method="post"]
[input type="text" name="name"]
[input type="submit" value="submit"]
[/form]

[form action="send.php" method="post"]
[input type="hidden" name="mail" value="someone@somewhere.com"]
[input type="text" name="name"]
[input type="submit" value="submit"]
[/form]

[form action="send.php" method="post"]
[input type="text" name="name"]
[input type="submit" value="submit"]
[/form]


In this code we see 3 forms, but the one we are interested in is the second. So the number of the form we want is 2.
We must not forget that we start counting from number 1. We say 1,2,3,4... However in JavaScript the counting starts from number 0.It goes 0,1,2,3 etc.

So the actual number of the form is number 1 not 2. In general find the number of the form and take out one (number-1).
We will use this number to fill in the gap in our command:

CODE :
javascrit:alert(document.forms[1].mail.value="me@hacker.com")


Like this you can change images or links that have no name. To do that just change "forms" to the type of item you want to change:

For Images it would be:

CODE :
javascrit:alert(document.images[3].src="#the url of the picture you want#")


For links it would be:

CODE :
javascrit:alert(document.links[0].href="#the url you want#")


Lastly, we can use this technique to edit cookies.
The command is the following and was written by Dr_aMado from triviasecurity.net, but i altered it a bit so that it shows the cookie before the user edits it.

Just copy-paste this line to the adress bar:

CODE :

javascrit:alert(window.c=function a(n,v,nv){c=document.cookie;c=c.substring(c.indexOf(n)+n.length,c.length);c=c.substring(1,((c.indexOf(";")>-1) ? c.indexOf(";") : c.length));nc=unescape(c).replace(v,nv);document.cookie=n+"="+escape(nc);return unescape(document.cookie);});alert('The cookie is: "'+document.cookie+'"');alert(c(prompt("The name of the cookie:",""),prompt("Change this value:",""),prompt("with this:","")));


** Added by Kane:
If you would like to edit your cookies manually, then this command will do that for you.

CODE :
javascrit:alert(document.cookie)


That will show you your current cookie. Say for example, that is 'userid=1'. You want to change that to 'userid=2'. You would use the following command:

CODE :
javascrit:alert(document.cookie="userid=2")


As a conclusion, i must stress that the changes are made only on the user's side! It's like saving the site in your PC and then modifying it. However, using this technique you can trick a page (for example with cookies) or pass the reference security of a page.

For example some pages check from where the user sends the data. Specifically if the data from http://www.test.com/form.php was sent to http://www.test.com/check.php
check.php would possible check if the data was sent from the form in http://www.test.com/form.php
Except for that, if you manage to enter your own JavaScript code in a page, using something like this technique you will be able to alter pictures and staff like that permanently!
However you need further knowledge than the one which is provided here

Read more!

Bluetooth Hacking Tools

Bluetooth technology is great. No doubt. It provides an easy way for a wide range of mobile devices to communicate with each other without the need for cables or wires. However, despite its obvious benefits, it can also be a potential threat for the privacy and security of Bluetooth users (remember Paris Hilton?).

If you are planning to gain a deeper understanding of Bluetooth security, you will need a good set of tools with which to work. By familiarizing yourself with the following tools, you will not only gain a knowledge of the vulnerabilities inherent in Bluetooth-enabled devices, but you will also get a glimpse at how an attacker might exploit them.

This hack highlights the essential tools, mostly for the Linux platform, that can be used to search out and hack Bluetooth-enabled devices.

Discovering Bluetooth Devices

BlueScanner - BlueScanner searches out for Bluetooth-enabled devices. It will try to extract as much information as possible for each newly discovered device. Download BlueScan.

BlueSniff - BlueSniff is a GUI-based utility for finding discoverable and hidden Bluetooth-enabled devices. Download BlueSniff.

BTBrowser - Bluetooth Browser is a J2ME application that can browse and explore the technical specification of surrounding Bluetooth-enabled devices. You can browse device information and all supported profiles and service records of each device. BTBrowser works on phones that supports JSR-82 - the Java Bluetooth specification. Download BTBrowser.

BTCrawler -BTCrawler is a scanner for Windows Mobile based devices. It scans for other devices in range and performs service query. It implements the BlueJacking and BlueSnarfing attacks. Download BTCrawler.

Hacking Bluetooth Devices

BlueBugger -BlueBugger exploits the BlueBug vulnerability. BlueBug is the name of a set of Bluetooth security holes found in some Bluetooth-enabled mobile phones. By exploiting those vulnerabilities, one can gain an unauthorized access to the phone-book, calls lists and other private information. Download BlueBugger.

CIHWB - Can I Hack With Bluetooth (CIHWB) is a Bluetooth security auditing framework for Windows Mobile 2005. Currently it only support some Bluetooth exploits and tools like BlueSnarf, BlueJack, and some DoS attacks. Should work on any PocketPC with the Microsoft Bluetooth stack. Download CIHWB.

Bluediving - Bluediving is a Bluetooth penetration testing suite. It implements attacks like Bluebug, BlueSnarf, BlueSnarf++, BlueSmack, has features such as Bluetooth address spoofing, an AT and a RFCOMM socket shell and implements tools like carwhisperer, bss, L2CAP packetgenerator, L2CAP connection resetter, RFCOMM scanner and greenplaque scanning mode. Download Bluediving.

Transient Bluetooth Environment Auditor - T-BEAR is a security-auditing platform for Bluetooth-enabled devices. The platform consists of Bluetooth discovery tools, sniffing tools and various cracking tools. Download T-BEAR.

Bluesnarfer - Bluesnarfer will download the phone-book of any mobile device vulnerable to Bluesnarfing. Bluesnarfing is a serious security flow discovered in several Bluetooth-enabled mobile phones. If a mobile phone is vulnerable, it is possible to connect to the phone without alerting the owner, and gain access to restricted portions of the stored data. Download Bluesnarfer.

BTcrack - BTCrack is a Bluetooth Pass phrase (PIN) cracking tool. BTCrack aims to reconstruct the Passkey and the Link key from captured Pairing exchanges. Download BTcrack.

Blooover II - Blooover II is a J2ME-based auditing tool. It is intended to serve as an auditing tool to check whether a mobile phone is vulnerable. Download Blooover II.

BlueTest - BlueTest is a Perl script designed to do data extraction from vulnerable Bluetooth-enabled devices. Download BlueTest.

BTAudit - BTAudit is a set of programs and scripts for auditing Bluetooth-enabled devices. Download BTAuding.

Read more!

iPod Touch background

Read more!

Wednesday, September 5, 2007

The internet on a disc

Read more!

Tuesday, September 4, 2007

25 Top Hacking Tools

Here are 25 of the top tools for ethical (and unethical) hacking!!!


1. Nessus : Premier UNIX vulnerability assessment tool
Nessus is the best free network vulnerability scanner available, and the best to run on UNIX at any price. It is constantly updated, with more than 11,000 plugins for the free (but registration and EULA-acceptance required) feed. Key features include remote and local (authenticated) security checks, a client/server architecture with a GTK graphical interface, and an embedded scripting language for writing your own plugins or understanding the existing ones. Nessus 3 is now closed source, but is still free-of-cost unless you want the very newest plugins.

2. Wireshark : Sniffing the glue that holds the Internet together
Wireshark (known as Ethereal until a trademark dispute in Summer 2006) is a fantastic open source network protocol analyzer for Unix and Windows. It allows you to examine data from a live network or from a capture file on disk. You can interactively browse the capture data, delving down into just the level of packet detail you need. Wireshark has several powerful features, including a rich display filter language and the ability to view the reconstructed stream of a TCP session. It also supports hundreds of protocols and media types. A tcpdump-like console version named tethereal is included. One word of caution is that Ethereal has suffered from dozens of remotely exploitable security holes, so stay up-to-date and be wary of running it on untrusted or hostile networks (such as security conferences).

3. Snort : A Everyone's favorite open source IDS
This lightweight network intrusion detection and prevention system excels at traffic analysis and packet logging on IP networks. Through protocol analysis, content searching, and various pre-processors, Snort detects thousands of worms, vulnerability exploit attempts, port scans, and other suspicious behavior. Snort uses a flexible rule-based language to describe traffic that it should collect or pass, and a modular detection engine. Also check out the free Basic Analysis and Security Engine (BASE), a web interface for analyzing Snort alerts.

Open source Snort works fine for many individuals, small businesses, and departments. Parent company SourceFire offers a complimentary product line with more enterprise-level features and real-time rule updates. They offer a free (with registration) 5-day-delayed rules feed, and you can also find many great free rules at Bleeding Edge Snort.



4. Netcat : The network Swiss army knife
This simple utility reads and writes data across TCP or UDP network connections. It is designed to be a reliable back-end tool that can be used directly or easily driven by other programs and scripts. At the same time, it is a feature-rich network debugging and exploration tool, since it can create almost any kind of connection you would need, including port binding to accept incoming connections. The original Netcat was released by Hobbit in 1995, but it hasn't been maintained despite its immense popularity. The flexibility and usefulness of this tool have prompted people to write numerous other Netcat implementations - often with modern features not found in the original. One of the most interesting is Socat, which extends Netcat to support many other socket types, SSL encryption, SOCKS proxies, and more. It even made this list on its own merits. There is also Chris Gibson's Ncat, which offers even more features while remaining portable and compact. Other takes on Netcat include OpenBSD's nc, Cryptcat, Netcat6, PNetcat, SBD, and so-called GNU Netcat.

5. Metasploit Framework : Hack the Planet
Metasploit took the security world by storm when it was released in 2004. It is an advanced open-source platform for developing, testing, and using exploit code. The extensible model through which payloads, encoders, no-op generators, and exploits can be integrated has made it possible to use the Metasploit Framework as an outlet for cutting-edge exploitation research. It ships with hundreds of exploits, as you can see in their online exploit building demo. This makes writing your own exploits easier, and it certainly beats scouring the darkest corners of the Internet for illicit shellcode of dubious quality. Similar professional exploitation tools, such as Core Impact and Canvas already existed for wealthy users on all sides of the ethical spectrum. Metasploit simply brought this capability to the masses.

6. Hping2 : A network probing utility like ping on steroids
This handy little utility assembles and sends custom ICMP, UDP, or TCP packets and then displays any replies. It was inspired by the ping command, but offers far more control over the probes sent. It also has a handy traceroute mode and supports IP fragmentation. This tool is particularly useful when trying to traceroute/ping/probe hosts behind a firewall that blocks attempts using the standard utilities. This often allows you to map out firewall rulesets. It is also great for learning more about TCP/IP and experimenting with IP protocols.

7. Kismet : A powerful wireless sniffer
Kismet is an console (ncurses) based 802.11 layer2 wireless network detector, sniffer, and intrusion detection system. It identifies networks by passively sniffing, and can even decloak hidden (non-beaconing) networks if they are in use. It can automatically detect network IP blocks by sniffing TCP, UDP, ARP, and DHCP packets, log traffic in Wireshark/TCPDump compatible format, and even plot detected networks and estimated ranges on downloaded maps. As you might expect, this tool is commonly used for wardriving. Oh, and also warwalking, warflying, and warskating, ...

8. Tcpdump : The classic sniffer for network monitoring and data acquisition
Tcpdump is the IP sniffer we all used before Ethereal (Wireshark) came on the scene, and many of us continue to use it frequently. It may not have the bells and whistles (such as a pretty GUI or parsing logic for hundreds of application protocols) that Wireshark has, but it does the job well and with fewer security holes. It also requires fewer system resources. While it doesn't receive new features often, it is actively maintained to fix bugs and portability problems. It is great for tracking down network problems or monitoring activity. There is a separate Windows port named WinDump. TCPDump is the source of the Libpcap/WinPcap packet capture library, which is used by Nmap among many other tools.

9. Cain and Abel : The top password recovery tool for Windows
UNIX users often smugly assert that the best free security tools support their platform first, and Windows ports are often an afterthought. They are usually right, but Cain & Abel is a glaring exception. This Windows-only password recovery tool handles an enormous variety of tasks. It can recover passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols. It is also well documented.

10. John the Ripper : A powerful, flexible, and fast multi-platform password hash cracker
John the Ripper is a fast password cracker, currently available for many flavors of Unix (11 are officially supported, not counting different architectures), DOS, Win32, BeOS, and OpenVMS. Its primary purpose is to detect weak Unix passwords. It supports several crypt(3) password hash types which are most commonly found on various Unix flavors, as well as Kerberos AFS and Windows NT/2000/XP LM hashes. Several other hash types are added with contributed patches. You will want to start with some wordlists, which you can find here, here, or here.

11. Ettercap : In case you still thought switched LANs provide much extra security
Ettercap is a terminal-based network sniffer/interceptor/logger for ethernet LANs. It supports active and passive dissection of many protocols (even ciphered ones, like ssh and https). Data injection in an established connection and filtering on the fly is also possible, keeping the connection synchronized. Many sniffing modes were implemented to give you a powerful and complete sniffing suite. Plugins are supported. It has the ability to check whether you are in a switched LAN or not, and to use OS fingerprints (active or passive) to let you know the geometry of the LAN.

12. Nikto : A more comprehensive web scanner
Nikto is an open source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3200 potentially dangerous files/CGIs, versions on over 625 servers, and version specific problems on over 230 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired). It uses Whisker/libwhisker for much of its underlying functionality. It is a great tool, but the value is limited by its infrequent updates. The newest and most critical vulnerabilities are often not detected.

13. Ping/telnet/dig/traceroute/whois/netstat : The basics
While there are many whiz-bang high-tech tools out there to assist in security auditing, don't forget about the basics! Everyone should be very familiar with these tools as they come with most operating systems (except that Windows omits whois and uses the name tracert). They can be very handy in a pinch, although for more advanced usage you may be better off with HPing2 and Netcat

14. OpenSSH / PuTTY / SSH : A secure way to access remote computers
SSH (Secure Shell) is the now ubiquitous program for logging into or executing commands on a remote machine. It provides secure encrypted communications between two untrusted hosts over an insecure network, replacing the hideously insecure telnet/rlogin/rsh alternatives. Most UNIX users run the open source OpenSSH server and client. Windows users often prefer the free PuTTY client, which is also available for many mobile devices. Other Windows users prefer the nice terminal-based port of OpenSSH that comes with Cygwin. Dozens of other free and proprietary clients exist. You can explore them here or here.

15. THC Hydra : A Fast network authentication cracker which support many different services
When you need to brute force crack a remote authentication service, Hydra is often the tool of choice. It can perform rapid dictionary attacks against more then 30 protocols, including telnet, ftp, http, https, smb, several databases, and much more.

16. Paros proxy : A web application vulnerability assessment proxy
A Java based web proxy for assessing web application vulnerability. It supports editing/viewing HTTP/HTTPS messages on-the-fly to change items such as cookies and form fields. It includes a web traffic recorder, web spider, hash calculator, and a scanner for testing common web application attacks such as SQL injection and cross-site scripting.

17. Dsniff : A suite of powerful network auditing and penetration-testing tools
This popular and well-engineered suite by Dug Song includes many tools. dsniff, filesnarf, mailsnarf, msgsnarf, urlsnarf, and webspy passively monitor a network for interesting data (passwords, e-mail, files, etc.). arpspoof, dnsspoof, and macof facilitate the interception of network traffic normally unavailable to an attacker (e.g, due to layer-2 switching). sshmitm and webmitm implement active monkey-in-the-middle attacks against redirected ssh and https sessions by exploiting weak bindings in ad-hoc PKI. A separately maintained partial Windows port is available here. Overall, this is a great toolset. It handles pretty much all of your password sniffing needs.

18. NetStumbler : Free Windows 802.11 Sniffer
Netstumbler is the best known Windows tool for finding open wireless access points ("wardriving"). They also distribute a WinCE version for PDAs and such named Ministumbler. The tool is currently free but Windows-only and no source code is provided. It uses a more active approach to finding WAPs than passive sniffers such as Kismet or KisMAC

19. THC Amap : An application fingerprinting scanner
Amap is a great tool for determining what application is listening on a given port. Their database isn't as large as what Nmap uses for its version detection feature, but it is definitely worth trying for a 2nd opinion or if Nmap fails to detect a service. Amap even knows how to parse Nmap output files.

20. GFI LANguard : A commercial network security scanner for Windows
GFI LANguard scans IP networks to detect what machines are running. Then it tries to discern the host OS and what applications are running. I also tries to collect Windows machine's service pack level, missing security patches, wireless access points, USB devices, open shares, open ports, services/applications active on the computer, key registry entries, weak passwords, users and groups, and more. Scan results are saved to an HTML report, which can be customized/queried. It also includes a patch manager which detects and installs missing patches. A free trial version is available, though it only works for up to 30 days.

21. Aircrack : The fastest available WEP/WPA cracking tool
Aircrack is a suite of tools for 802.11a/b/g WEP and WPA cracking. It can recover a 40 through 512-bit WEP key once enough encrypted packets have been gathered. It can also attack WPA 1 or 2 networks using advanced cryptographic methods or by brute force. The suite includes airodump (an 802.11 packet capture program), aireplay (an 802.11 packet injection program), aircrack (static WEP and WPA-PSK cracking), and airdecap (decrypts WEP/WPA capture fi

22. Superscan : A Windows-only port scanner, pinger, and resolver
SuperScan is a free Windows-only closed-source TCP/UDP port scanner by Foundstone. It includes a variety of additional networking tools such as ping, traceroute, http head, and whois.

23. Netfilter : The current Linux kernel packet filter/firewall
Netfilter is a powerful packet filter implemented in the standard Linux kernel. The userspace iptables tool is used for configuration. It now supports packet filtering (stateless or stateful), all kinds of network address and port translation (NAT/NAPT), and multiple API layers for 3rd party extensions. It includes many different modules for handling unruly protocols such as FTP. Many personal firewalls are available for Windows (Tiny,Zone Alarm, Norton, Kerio, ...), though none made this list. Microsoft included a very basic firewall in Windows XP SP2, and will nag you incessantly until you install it.

24. Sysinternals : An extensive collection of powerful windows utilities
Sysinternals provides many small windows utilities that are quite useful for low-level windows hacking. Some are free of cost and/or include source code, while others are proprietary. Survey respondents were most enamored with:
  • ProcessExplorer for keeping an eye on the files and directories open by any process
  • PsTools for managing (executing, suspending, killing, detailing) local and remote processes.
  • Autoruns for discovering what executables are set to run during system boot up or login.
  • RootkitRevealer for detecting registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit.
  • TCPView, for viewing TCP and UDP traffic endpoints used by each process (like Netstat on UNI

25. Retina : Commercial vulnerability assessment scanner by eEye
Like Nessus, Retina's function is to scan all the hosts on a network and report on any vulnerabilities found. It was written by eEye, who are well known for their security research.

Read more!

Monday, September 3, 2007

10 Funky Sexy WATERPROOF Flash Drives

Flash drives are not only for storing data anymore, checkout these cool flash drives...

They have one thing in common, all of these are water proof

1. Kingston
A tiny, hot-swappable USB 2.0 flash drive that holds 8GB of data may not be so impressive these days, but Kingston's Data Traveler Secure ups the ante by throwing in both 256bit privacy encryption and a waterproof rating. A titanium-coated stainless steel casing will keep the drive water-tight in up to four feet of water--not exactly made for a swim, but safe when dropped in the sink.


2. Waterproof Flash Wrist-drive
This is a shockproof and moisture-proof flash drive that you can take with you and wear anywhere.
Its available in red, yellow, blue, green, orange and purple color.
This drive comes in 512MB and costs $25







3.Gidis waterproof Mdrive

Gidis waterproof Mdrive, styled by designers at INNO Design. The drives look sexy in their slim line black and red cases. The flash drives will be available in 1GB($41) and 2GB($62)







4. Plastic Grip Drives

  • Made of soft, clear & safe quality silicone rubber
  • Elegant, stylish & innovative design
  • True waterproof , anti-shock, anti-vibration & anti-static
  • Available in various shapes, colors and speeds
  • Meet the requirement of SGS international standard
  • Hot Plug-n-Play
  • Transferring rate up to 480Mb/s
  • LED indicator when the USB Pen Drive is in use

5. Kingston Data Traveler
The 1 GB Data Traveler Secure USB 2.0 Flash Drive from Kingston lets you quickly transfer and safely carry digital files wherever your business takes you. The combination of hardware- and software based security on the Data Traveler® Secure gives you excellent access control and encrypted data protection. Your important data is safe and secured with 256-bit Advanced Encryption Standard (AES) hardware-based encryption. The drive also features rugged, titanium-coated stainless steel casing to manage rough handling. Designed to utilize the high bandwidth of the USB 2.0 High-Speed interface, this waterproof flash drive transfers your data with read and write speeds of up to 24 MBps and 10 MBps. ($69)


6. Gizmo! overdrive
The new, high-performance Crucial Gizmo! overdrive writes data at speeds up to 13MB/s (megabytes per second). Plus, data is protected and encrypted against unauthorized use with the included security software($38)


7.Photo Print Ultra-thin waterproof flash drive

The Credit Card USB Flash Drive is an ultra-thin waterproof flash drive with an unbreakable plastic casing that can be printed in full colour on both sides. The optional software provides unique advertising & functionality.




8. Pretec i-Disk RFID flash drive

Nevertheless, the i-Disk RFID differs from most USB flash drives by sporting a rugged, waterproof enclosure as well as a built-in RFID tag, which should work wonders in tracking where your employees carry the company's precious data until they find a way to circumvent The Man

9. Kingmax

Kingmax model, is the smallest USB flash drive in the world and really waterproof. It is so small that it is almost the size of a paper clip. It is not only small, but also very thin.



10.
Corsair Flash Voyager

Corsair's Durable USB Drive Designed and Built for

  • Plug & Play functionality in Windows® Vista, XP, 2000, ME, Linux 2.4 and later, Mac OS 9, X and later
  • Includes the True Crypt security application (Windows Vista/XP/2000 compatible only) allowing for a virtual encrypted drive using AES-256 encryption
  • Lanyard and USB extension cable included
  • ReadyBoost™ compatible
  • Limited 10-year warranty

Read more!