Showing posts with label network. Show all posts
Showing posts with label network. Show all posts

Saturday, March 24, 2012

Spruce Up Your Social Network Profiles Before Applying for a New Job to Boost Your Chances of Getting Hired [Jobs]

Most people (hopefully) know by now to keep their social networks clean, in case anyone from a potential employer to a Google-happy family member stumbles on your profile. However, your Facebook, Twitter, or LinkedIn profile can actually be an asset in helping you stand out when you apply for a job, and sprucing it up a bit with a new photo, updated skills, and recent accomplishments can go a long way. Besides, you know the hiring manager is going to look at your profile before calling you anyway.


At this point we should expect potential employers to search for us at Facebook and LinkedIn before they contact us for an interview. It's not news that a hiring manager will review a candidate's resume and then try to dig them up on Facebook to see what kind of person they are before deciding whether they want to interview them. You can boost your odds of standing out in a positive way by sprucing up your profiles as well as your resume before you apply.


Wise Bread suggests, among other things, uploading a good-looking recent photo, tidying up personal details and making sure your privacy settings are the way you want them, and—especially at LinkedIn—editing your career goals, personal description, and any other old or out of date information. Request and offer recommendations from old coworkers if you can, and make sure your recent achievements and projects are included in your profile. Wise Bread has a number of other great suggestions, like researching the company culture and the interviewers specifically, so the whole list is worth a look.


Do you keep your social network profiles in shape for public viewing at all times, or does your LinkedIn profile need a brush-up? Perhaps you just lock yours down so it's not searchable and not public? Whatever you do, share your thoughts in the comments below.

Tame and Hide Your Spaghetti of Cables and Network Wires Like The Pros [Networking]

You've got a lot of multimedia devices, which means probably you've got a mess of wires to deal with. TechNewsWorld offers solutions for managing that mess, even if you don't have the luxury of tearing into your walls to incorporate the cables.


One solution is to go wireless, of course, but ditching slow Wi-Fi and going completely wired is faster and more reliable, plus more secure.


Therefore, a good idea if you don't want to see wires everywhere, TechNewsWorld suggests, is to use the existing cavities in your home:



Search for hidden cavities and voids that you can use to run cabling if your home's multimedia wiring looks out-of-control. Check on top of kitchen cabinets, in closets, behind baseboards — all provide suitable space for Cat 5e.


Examine the routes plumbers have used for pipes. There's often enough room to stuff a cable. Central vacuum systems often have space between structure and vacuum pipe.


If your home has a retroactively installed central vacuum system, the designer will have already done the planning for you, because he will have run his system to the basement or garage via available voids. You can use those voids too.


Tip: Don't bend cables excessively. Cat 5e requires turns of no more than four times the diameter of the cable. Reckon on bending it no more than the size of a quarter.


Don't strip the cable to make it fit small spaces. The copper wire's twist within the outer jacket is part of the wire design.


The article also recommends avoiding cable ties and using electrical tape instead (as in the photo above), like the experts do.


For more tips and suggestions, check out the full article or share your own wire control advice with us in the comments.

Taming That Spaghetti of Wires Taking Over Your Home | TechNewsWorld

Wednesday, March 21, 2012

Update All of Your Social Network Settings from One Page with Bliss Control [Social]

If you use more than one social network—Facebook, Twitter, YouTube, LinkedIn, Flickr, Google+, and others—updating your profile picture or bio at once can be a pain. Enter Bliss Control. This webpage is simple one-stop landing page for getting to your social network management settings.


From the same folks who made the previously mentioned Notification Control launchpad for cleaning up your web services' email notifications, Bliss Control is a useful tool to bookmark. Rather than have to click around on every single service to find where to update your info, just start from Bliss Control and find the setting in the easy drop-down.


Bliss Control doesn't require your login information to any of the services it supports, it just directs you very quickly to the right settings pages on each service. Services supported right now are: Facebook, Twitter, StumbleUpon, Pinterest, Tumblr, Foursquare, YouTube, LinkedIn, Google+, Meetup, Path, Instagram, and Flickr.


You can change your bio, username or password, email, email settings, profile picture, design, 3rd party permissions, and so on. Delete account and recover password are also two quick settings offered.

Let Others Contact You Through Your Own Wi-Fi Network

Do you want other people to contact you through your own WiFi network. Or would you like to share your home wireless network with neighbors? Change the SSID.


The Wi-Fi network at your home has a public name, also known as SSID, that will often show up on your neighbor’s computer or any other mobile device that is within the range of your wireless network.


The name of a wireless network (or SSID) rarely says anything about the owner of that network and that’s good because most people won’t like the idea of sharing their Wi-Fi network with others. Some have even suggested using scary and unusual names for SSIDs (like “Police Van”) to discourage Wi-Fi theft.


 


However, if you are on the other side and want people to actually use your Wireless connection – maybe for a monthly fee – a free service like Wifis.org can be of some help.


WiFis.org provides you a unique URL like www.wifis.org/labnol. You need to change your network’s name (SSID) to that URL and it will then show up under “Available Wireless Networks” on other computers that are within your wireless range.


If your neighbors happen to type that URL in the browser, they’ll see a contact form which they can use (“Hi, Can I borrow your Wi-Fi for an hour?”) to directly get in touch with you but without knowing your real email address.


You can also write your WiFis.org SSIDs as wif.is/ or .wifis.org.


This is definitely a neat idea though there’s an alternative as well. You can create a special email address to advertise your Wi-Fi network in the neighborhood and then set it as your SSID – something like BorrowMyWifiATgmailDOTcom. In either case, do make sure that your Wi-Fi is secured with WPA2.

Sunday, March 18, 2012

Hacking From Android Phones, Made Easy With (Anti) Android Network Tool Kit

Have an android phone, Looking for easy ways to hack like pentesters ?? Well you are in luck, Anti or Anti or Android networking Tool Kit  is Just what the world needs, another killer mobile app for android devices, Anti allows you to control other devices such as Desktop PC, other Android Phones and even iOS devices with just a few pushes

Anti - Android Network Tool Kit
Android Network Toolkit (ANTI) is an amazing android application. You could bring all the hacking tools on PC to your Android smartphone. Using this app is as simple as pushing a few buttons, and then you can penetrate your target.


How Anti Works ?
Anti will map your network, scan for active devices and vulnerabilities, and will  display the information accordingly, Green led signals an 'Active device', Yellow led signals "Available ports", and Red led signals "Vulnerability found". Also, each device will have an icon representing the type of the device. When finished scanning, Anti will produce an automatic report specifying which vulnerabilities you have or bad practices used, and how you can exploit/fix each one of them.


Features
Scan - This will scan the selected target for open ports and vulnerabilities, also allowing the user to select a specific scanning script for a more advanced/targeted scan.


Spy - This will 'sniff' images transferred to/from the selected device and display them on your phone in a nice gallery layout. If you choose a network subnet/range as target, then all images transferred on that network - for all connected devices - will be shown. Another feature of the Spy plugin is to sniff URLs (web sites) and non-secured (ie, not HTTPS) username/passwords logins, shown on the bottom drawer.


D.O.S - This will cause a Denial Of Service (D.O.S) for the selected target, ie. it will deny them any further access to the internet until you exit the attack.


Replace images - This will replace all images transferred to/from the target with an Anti logo, thus preventing from attacked used seeing any images on their browsers while the browse the Internet, except for a nice looking Anti logo...


M.I.T.M - The Man In The Middle attack (M.I.T.M) is an advanced attack used mainly in combination with other attack. It allows invoking specific filters to manipulate the network data. Users can also add their own mitm filters to create more mitm attacks.


Attack - This will initiate a vulnerability attack using our Cloud service against a specific target. Once executed successfully, it will allow the attack to control the device remotely from your phone.


Report - This will generate a vulnerability report with findings, recommendations and tips on how to fix found vulnerabilities or bad practices used.


For more info and Download details please visit the Following link

Anime News Network

AnimeNewsNetwork.com is the best news source for all the Anime fans out there on the Internet. It has got everything about Anime and Manga which you been searching for.


In July 1998 Anime News Network (ANN) was launched and today it has become one of the biggest Anime news websites on the net. It also has the biggest Anime Encyclopedia with over 13,702 titles info related to Anime, TV Series, movies, Specials and related stuff.


Anime News Network Inc owns the website and it is not controlled by any other organization and other media networks. Christopher Macdonald is CEO of the website who is also the Editor-in-chief for ANN.


On ANN you can also get to read latest interviews, Reviews, Ask Questions, info about latest releases in the world of Anime and Manga and other cool stuffs. If you are looking for something specific like a Anime title then do use the search box at the top of the website. You can also the search to only Encyclopepdia or the Forums, by this way you can be sure to find the info you are looking for.


Visit Anime News Network @ http://www.animenewsnetwork.com/ and enjoy!


 


Related Sites: Also check out Anime Crazy, Anime Fuel and Sidereel.


The Anime and Manga Encyclopedia  has info such as Alternative titles, Genre info, Theme, Plot summary, User ratings, full list of episodes, DVD releases, Cast and names of the people behind the work.


Check this following link which showcases info regarding the popular Anime Bleach: Bleach Encyclopedia


You can also check out the Anime News Network Forum @ http://www.animenewsnetwork.com/bbs/phpBB2/


It has various discussions regarding Anime and views, opinions regarding related stuffs from its members. When I checked out the forum there were more than 250 users online, so you can imagine the popularity of the website.


And then there is the anime news network video section @ http://www.animenewsnetwork.com/video/


You can watch the latest trailers of various Anime and Manga from all over the world and other cool videos that will interest you. You can also watch full anime TV shows and series as long as they are not copyrighted. So whatever you get to see on ANN is totally legal and you need not worry about piracy.


The website has 3 different versions based on the following countries: USA, UK and Australia. It is due to the demand and requirement specific to a region, by default it loads the US version.


User registration on Anime News Network is not mandatory except when you want to participate in the forums and also when you submit content on ANN website.


You can also Like Anime News Network on Facebook and be a part of FB page @ http://www.facebook.com/animenewsnetwork


It has over 23,917 fans as of now, so if you like Anime and need a daily dose of it then this is your best chance.


ANN is also on Twitter with over 25,000 followers @ https://twitter.com/#!/anime


Anime News Network will help a lot of Anime and Manga fans to be updated with the latest in the episodes, events, series and more. Do share this article with your Facebook friends and let them know about this website.

Thursday, March 15, 2012

Upgrade Your Home Network This Weekend [Weekendhacker]

Home networks can be great or they can be a huge pain in the butt. Set aside some time this weekend to fix your annoying network issues, boost your Wi-Fi reception, and add some great new features. Here are a few ideas to get you started.


Before we get started, it's important to have a good grasp on basic networking skills like how your router works and what you can do with it. If you need to brush up your knowledge, check out our Know Your Network Night School lessons. It'll help you pick out a great new router (if you need one) and teach you how to use its basic functions or even go as far as installing custom firmware to do even more.


Wireless isn't all it's cracked up to be. Networking with Ethernet cables is still a lot faster, so going completely wired in your home is a great way to improve network efficiency and speed. Most people like to avoid additional cables running throughout their house because it involves a mess or the difficult work of fishing those cables through their walls. That doesn't have to be the case, however, as you can often hide your cables alone the edges of the wall, cover them with tape, and then paint over that tape to make them appear flush. Alternatively, you can buy FlatWire and just paint over the wire that will lay flush on any surface. Alternatively, don't hide your cables at all and create an attractive design instead.


When you've got a bad wireless signal, there's only so much you can do but we have a few suggestions. In general, placement is paramount. If you're router is in a drawer, under a table, or obscured by anything you are hurting your signal. Your goal needs to be to place your router as high up in the room as possible and ensure its antennae are unobstructed. For an added bonus, you can build this Windsurfer signal booster that's compatible with pretty much any router that has external antennae. If you have a lot of ground to cover and happen to have an extra router lying around, try turning it into a repeater. (Just don't use a repeater in a smaller space because it can often hurt your signal rather than help it.) You also want to make sure you're using the wireless channel with the least interference. You can do this by using Wi-Fi Stumbler, a Java web applet that'll survey your network and help you find the best channel for you. Finally, you can actually boost your router's transmit power. Some standard firmware will allow you to do this, but in many cases you'll need to install something custom. Just read on for information on how to do just that.


If you want to put custom firmware on your router to get more out of it, you have two popular choices: Tomato, a powerful but very user-friendly option, and DD-WRT, a powerful and extremely comprehensive upgrade. But why would you even want to mess around with your firmware? Well, routers are not particularly easy to use in general, so if your focus is simplicity then Tomato is a good choice. It offers a no-nonsense interface to help you manage your network and, in the case of some routers, even offers some useful additional features. DD-WRT, on the other hand, is not particularly user-friendly but provides you with near-total control over your router. If you have any features missing from your router's admin panel, such as tools that help you easily serve media from home, bandwidth statistics, in-depth access restrictions, additional security options, the ability to boost your signal's transmit power, and much more, DD-WRT can add them. Both custom firmwares only support so many routers, so be sure to check compatibility on their respective pages before you attempt to install. If you need additional assistance, be sure to read our DD-WRT and Tomato start-to-finish setup guides.


One of the best things you can do with your home network is easily share media from computer to computer and other devices. If you enable port forwarding you can even share that media outside of your home. One of the best ways to do this is to turn an old computer into a network-attached storage device and media server. If you don't have an old machine, you can always build one from scratch. If you plan to create a server running OS X or Windows, Plex is a great option for serving up your media at home or on the go. It can send movies and music to pretty much any OS X or Windows computer and mobile devices as well. In the event your media is too big to stream or just won't play on the mobile device you're using (here's looking at you, iOS), Plex will convert it for you in real time. (This, of course, will require a reasonably powerful machine.) However you go about it, media and file servers can be the best part of your home network.

Tuesday, March 13, 2012

Network Security

Introduction

Computer Networks are the back bone of all organizations which rely on Information Technology (IT) and are the primary entry point for users to access the Information resources of an organization. Networks today are no longer limited within the physical location of an organization, but are required to be accessible from anywhere in the world which makes it vulnerable to several threats.

In a recent survey conducted by the Computer Security Institute (CSI), 70 percent of the organizations polled stated that their network security defenses had been breached and that 60 percent of the incidents came from within the organizations themselves. Organizations have realized that having a secure network infrastructure is critical to safeguard their IT assets.

Network design can vary from one organization to the other but, it is recommended to use the layered design approach – core layer, aggregation modules and the access layer. These layers comprise of hardware necessary to control access between internal and external resources. Though we will not deal with the layers in depth, the basic building blocks of a network are the router which is part of the core layer, firewall and switch which are part of the access layer. Along with these we have supporting aggregation modules such as IDS/IPS, antivirus, etc. Before we begin on network design and security, let’s understand the basic network components:

Router

In simple words, router is a network device which connects two different networks. Perimeter router or the Edge router is placed in the outermost layer of the network and forms a part of the core layer of the network architecture and serves as the very first line of defense.  It is responsible for forwarding IP packets to the networks to which it is connected. These packets can be inbound requests from Internet clients to Web server, request responses, or outgoing requests from internal network. The router can also be configured to block unauthorized or undesired traffic between networks. The router itself must also be secured against reconfiguration by using secure administration interfaces and ensuring that it has the latest software patches and updates applied.

Firewall

A firewall is often imagined as a wall of defense in a building which prevents spreading of fire from one part of the building to another. In a network world a firewall is a device primarily used to protect the boundary of an organization’s internal network while it is connected to other networks. The role of the firewall is to block all unnecessary ports and to allow traffic only from known ports such as port 80 for all HTTP traffic, port 25 for SMTP traffic and in some cases known network segments.

Unfortunately the hackers have become so smart these days that they manage to get through the firewall through the permitted ports and try to compromise the IT assets of an organization.  Thus firewall cannot evaluate the contents of “legitimate” packets and can unknowingly pass through some attacks to the inside network.

Hence these days most organizations deploy Intrusion Detection System (IDS) which have the capability to monitor network traffic and logs any unauthorized access attempts and suspicious network patterns and report them to network administrators at the earliest. But again, there is a problem if the administrators are not able to take immediate action, though the attack is detected it is not stopped.

To prevent such malicious activities, Intrusion Prevention Systems (IPS) were introduced in the network architecture. When any such malicious activity is detected an IPS can block such traffic and notify the administrators. Coupled with IPS/IDS, the firewall is a useful tool for reventing attacks and detecting intrusion attempts, or in worst-case scenarios, the source of an attack.

Switch

A network switch is a device which enables networked devices to talk to each other efficiently. The main purpose of using a switch in a network is to segment the network into logical pieces. The network devices which are part of the network segment are connected to the switch and any communication to these devices happens through the network switch. Some amount of security is built into the switch to prevent packet sniffing by intruders between networks. A switch can forward packets to a specific host or a network segment, rather than sharing the data with the entire network

The second most important factor in the network design is the network segmentation. Having a flat network allows an intruder to gain easy access to organizations critical assets. Network is segmented logically with the help of network devices such as routers and switch and access between these zones is controlled by a firewall.

Let’s understand the network design aspects with the help of the above diagram. Though this is not a full-fledged network diagram of a typical organization network, it does provide the basic understanding of network architecture with more focus on the perimeter security. As depicted above perimeter router is the outermost network device exposed to the external world with a public interface, followed by an optional network switch or directly connected to a firewall interface which allows traffic only on specific ports. An IDS/IPS device is connected in line with the network firewall for detecting and preventing network intrusions. Further a switch is used to segment the network into different logical segments.

In most organizations we see their data center network segmented into the DMZ and Internal zone. DMZs are used to separate Internet facing devices such as Web servers, Mail Gateway, Domain Name Servers Proxy server. DMZ allows inbound or outbound traffic to be initiated to or from the internal network without revealing the actual details of the internal network. This adds an additional layer of security and provides a certain extent this assumption holds good, if network paths are configured properly. There should not be a direct path to internal network should one of the devices in the DMZ be compromised.

Internal zone mainly comprises of infrastructure required to support business applications. There can be more logical separations in the internal network based on customer needs such as a separate DB segment which is also a mandate by few regulations.

Having understood the network components and the basic layout of a network let’s focus on the need for security.

An intruder usually looks for poorly configured network devices to exploit. Some of the most common network vulnerabilities which intruders exploit are default installation settings, open access controls, unpatched devices and easy access to network devices. Some of the most common Network threats are:

Information gathering – information about network design, system configuration, and network devices is gathered and an attack is planned later.Packet Sniffing – Intruder monitors data packets using network sniffers to read all clear text information and may steal some confidential information in clear text.Spoofing – where the original source of attack is spoofed to appear as a trusted source and can cause a denial of service attacks.Session hijacking - also known as man in the middle attacks in which an intruder uses an application that appears the genuine client or the server. This results in either the server or the client being tricked into thinking that the upstream host is the legitimate and share confidential information.Denial of service – is the act of denying legitimate users access to required resources. Attackers deny service by flooding the network with traffic and throttle the available bandwidth and resources.

As attacks are evolving and becoming more mature, the security solutions to prevent them are also evolving. As you might have seen so far, organizations use collection of layered security devices such as firewalls, intrusion detection systems, antivirus, etc. But managing all these devices individually is a complex process. This led to the evolution of Unified Threat Management Solutions (UTM). UTM systems are bundled with many security features and capabilities such as intrusion detection and prevention, Anti-Virus solution, e-mail spam filtering and Web content filtering, functions of a firewall, integrated into a single appliance.

Though UTM is still in its evolution stage, it has managed to be of much use to smaller organizations and still a long way to be of much use to larger organizations. UTM device face the challenge of performance with a significant consumption of bandwidth as they analyze more and more data. But security experts believe that UTM is here to stay and hope to see a more mature UTM in future.

Network design is an evolving process, organizations must never sit back and relax once the initial network setup is complete. Networks must be monitored continuously and improve security from time to time. Security can mean different to different organizations and must take appropriate measures to secure themselves. Just remember we are never alone in this world, we always have company.

Pradeep A. R.
mailto:Pradeep_ar@infosys.com

Pradeep works as an Infrastructure Security consultant with Enterprise Security and Risk management –Cloud practice, Infosys Ltd. Pradeep is currently working on Security Information and Event Management & Data loss prevention solutions. As a security enthusiast, Pradeep intends to become a cyber-forensic professional.


View the original article here

Saturday, March 10, 2012

Network Attacks

Any method, technique or process used to attack and compromise the security of the network can be termed as a Network attack. There can be a number of motives behind the attacks like fame, terrorism, greed, etc.  A few types of various malicious attacks are covered in this article.


The common and popular attacks would be

EavesdroppingDenial-of-ServiceSession HijackingIP SpoofingDNS SpoofingMan-in-the-Middle Attack

Eavesdropping is basically the act of secretly listening to the conversation of others, obviously without their permission. This definition can also be applied to network sniffing. In network sniffing, attacker secretly sniffs/listens to the data transmitted thorugh the network. The modules operating would be like this -


A machine is configured to “listen” mode and then it is used to capture the juicy data from the network! This can be done using readily available programs like Cain and Abel, Ehtercap, SSLsniff, etc. 


Wikipedia - A denial-of-service attack (DoS attack) is an attempt to make a computer resource unavailable to its intended respondents. It generally consists of the concerted efforts of a person or people to prevent an Internet site or service from functioning efficiently or at all, temporarily or indefinitely.


Smurf Attack


These attacks can be destructive. In this attack, an attacker sends a large amount of ICMP echo (ping) traffic at IP broadcast addresses. These packets have spoofed IP address of the source pointing to the victim. To amplify the attack several intermediary sites are selected by the attacker. This results in lots of ping replies (ICMP echo Reply) and thus resulting in victim being compromised.


SYN Flood attack


SYN flood attacks exploits TCP three-way handshake.  In this attack, attacker sends lots of TCP SYN packets to the victim with spoofed source IP address. These packets try to establish connection with the victim. Now what happens is that the victim sends back a TCP SYN-ACK packet and waiting for the response from the source. But as the source address is spoofed the response never comes thus creating half open connections.


This floods the available connection with the server and in the process keeps the server from responding to legitimate traffic.
This flooding if done in large volume can cause DoS.


Distributed Denial-of-service (DDoS) Attack


In DDoS attack, the attacker compromises large number of computers, mostly in different locations. These compromised machines are called as secondary victims or Zombies. Then these zombies are used as attack platform to attack the primary victim.
The zombies or the secondary victims may not be aware that they are being used to attack the primary victim. Trojans and viruses give the control attacker to these machines to launch attacks of the victim.


This attack is difficult to detect as the attack comes from several IP address. This is the most deadly attack of all and not easy to overcome. 


Session hijacking exploits computer session between two machines. Here, computer session means connection between two machines.


When a TCP session is established a cookie is used to verify if the session is active or not. The attacker can steal these cookies by sniffing or using the saved cookies on victim’s computer. Since most of authentication is done only at the start of the session, this allows the hacker to assume the identity of the victim and gains the same access to the resources as that of the victim.


Types of Session Hijacking attacks
1.    Active
2.    Passive


In an Active attack, attacker hijacks an existing session on the network by doing a Man-in-the-middle attack.  This allows the attacker to execute a various commands in order to maintain his access, delete the traces etc. The attacker can create accounts on the network which can be used to gain access later without having to do session hijack every time.
In Passive attack, attacker monitors the ongoing session in the network. This attack uses sniffer tools to sniff around the network and find juicy information!


The third type, Hybrid attack, uses the combination of the above mentioned attacks. This attack is used to sniff and modify the data simultaneously.


IP spoofing, also known as IP address forgery, is a technique that replaces the original IP address with another machine’s address  in which an attacker impersonates as a trusted host to conceal his identity, spoof a Web site, hijack browsers, or gain access to a network.


Here's how it works: The attacker obtains the IP address of a legitimate host and alters IP packet headers so that the legitimate host appears to be the source. So now when a visitor types in a URL of a legitimate site, he is taken to a fraudulent web page created by the attacker. For example, if the attacker has spoofed a site, say www.abc.com, then any visitor who types this in the URL  would see spoofed content created by the attacker instead of the original content.


With this kind of attack, the attacker could gain access to juicy information such as passwords, credit cards numbers, etc or install malware or alter the data.


Domain Name Service (DNS) basically transforms a domain name, (say www.example.com) to its IP address (say 11.22.33.44). AND DNS spoofing is a technique where in a DNS entry to point to another IP rather than it is supposed to point to.
There are two methods of DNS spoofing:-


1.    DNS Cache Spoofing: - DNS server cannot store information about all existing domain names and IP addresses in its cache. It is done to avoid constant repetitions of inquiries to login to servers of corresponding domains.


Now data is introduced into a DNS name server's cache database that did not originate from authoritative DNS sources. Its maliciously crafted attack on the name server. It may also result from improper software design of DNS applications.


The second variant of the attack directed on substitution DNS, consists in change of a server cache DNS.


2.    DNS ID spoofing:- The heading of a package of the DNS-protocol contains an identification field for conformity of inquiries and answers. The purpose of substitution DNS ID is to send the answer to DNS-inquiry before the present DNS-server will answer. For performance of it, it is necessary to predict the identifier of inquiry. Locally it is realized by simple listening of the network traffic.


In Man-in-the-Middle (MITM) attack, the attacker intercepts the traffic between two machines and make the victims believe that they are talking directly to each other, when in fact their conversation is controlled by the attacker.


The attacks starts with sniffing and eavesdropping and after the attacker gains access to the conversation, he can extract juicy information like passwords, credit cards numbers, etc. or can alter the data, install malwares.

Pentesting your own Wireless Network

Pentesting your own Wireless Network | ClubHACK Magazine Skip to Main Content Area ClubHACKAbout UsTeamPartnersContributorsAuthorsArchives Contact UsSubscribeRSSAdvertise  HomeTech GyanLegal GyanTool GyanMom's GuideSpecial FeatureMatriux VibhagPosterDownloadsDownload PDF Home Pentesting your own Wireless Network      

 

Introduction to IEEE 802.11IEEE 802.11 is a set of protocols used for implementing wireless LAN. IEEE Protocol standards are created and maintained by IEEE LAN/MAN Standard Committee. WLANs operate in 3 different frequency ranges that is2.4Ghz (802.11b/g/n), 3.6Ghz (802.11y) and 4.9/5.0Ghz (802.11a/h/j/n). Each of these Frequencies are further divided in to multiple channels.  Every country has permissible channels and maximum power levels.  However, wireless card can be easily configured to disregard these policies. One can make the wireless NIC hop on different channels, but at any given period of time a wireless NIC will be connected only to a single channel. Different Wireless Architectures & ImplementationsWi-Fi implementation as any other technology is needed to drive Business. It’s very important to get an optimum ROI with required security & controls in place. Keeping this in mind, the Home implementation of Wi-Fi network differs as compared to SOHO or Enterprise implementation. 1.Wi-Fi Network at Home:  In a usual home environment multiple clients connect to an AP which is connected to a broadband (DSL / Cable) modem. Wi-Fi at home is mainly used for internet access and all the users have same privileges.WiFi Network at Home The following is typical of a Wi-Fi implementation at home’s:  Clients connecting to AP / Wireless RoutersWireless Router connected to a broadband modem for internet serviceSecurity – WEP or WPA/WPA2 PersonalSSID broadcastMAC Address filteringParaphrases/passwords to access Wi-Fi service never changed and at times easy to guessDue to the nature of work and the type of information, it is not feasible to implement Enterprise class security for home users. The home networks are easier to compromise but again it’s a tradeoff between security and ease of use. However, there are good practices which if implemented correctly would deter and make it difficult for an attacker to break into the home Wi-Fi network.
2.Corporate / Enterprise Network: In a Corporate enterprise network, stronger security controls are required.  Wi-Fi is used by employee’s to access the corporate network and by the guests / visitors to access the internet. Access to Corporate network through Wi-Fi requires the employee’s to authenticate to the authentication server before the access is granted to the corporate network. They key features of this network setup are:- Restricted to employee’sInvolves authentication using authenticating serverStronger encryption protocolsAccess on need to know basisSecurity – WPA2 Enterprise along with EAP-TTLS, MSCHAPv2 etc. is usedCorporate-Enterprise Network In a corporate environment there is usually a ‘Guest’ wireless network for guests and visitors. This network is only for internet access and is supposed to be isolated from the Corporate Wi-Fi network. Encryption & Authentication used in IEEE 802.11 Environment:Wired Equivalent Privacy (WEP) – WEP uses RC4 encryption algorithm which has several weaknesses. IEEE 802.11i was ratified in 2004 and is the primary means of wireless security. In spite of known vulnerabilities due to the oldest and easiest configuration WEP is still widely deployed at least on Home Networks  Wi-Fi Protected Access (WPA) – WPA protocol implements majority of IEE 802.11i standard requirements. WPA makes use of Temporal Key Integrity Protocol (TKIP) instead of RC4 used in its predecessor WEP. To offer greater security, CCMP, an AES based encryption protocol was released in the final IEEE 802.11i standard (referred to as WPA2).  WPA Personal – Commonly referred as WPA – Pre shared key (PSK). The clients authenticate with the AP’s using the 256 bit keys. It’s mainly used at homes and in SOHO environment  WPA Enterprise – Mainly designed for Enterprise networks and requires authentication using RADIUS server. Extensible Authentication Protocol (EAP) is used for authentication, which comes in different flavors (EAP-TLS, EAP-TTLS).  It is also referred as WPA-802.1x mode RADIUS protocol inherently only allows for password based authentication i.e. the password is sent as MD5 Hash or response to a challenge (CHAP-password). EAP enriches the authentication feature of RADIUS. VA&PT of Wireless NetworksApproach for conducting VA&PT of a wireless network is similar to traditional connected network but there are added risks and vulnerabilities specific to Wi-Fi network that need to be looked into. To conduct VA&PT of wireless network it is very important to get the objectives clear. Wireless network if compromised can lead to unauthorized access to the corporate infrastructure which might be on the traditional connected network. Approach:-ReconnaissanceIdentifying the Encryption & Authentication TechnologyAttempt to Gain AccessBrute Forcing / Guessing PasswordsIdentifying weakness in the Wi-Fi TechnologyAttacks specific to Wi-Fi TechnologySummarization & Reporting Phase I: Reconnaissance This is the most important phase whereby the attacker gains most of the information required for further directed attacks. Intelligent sniffing can help in gathering good amount of information on the wireless network, technology being used and the deployment.  Beacons are used to relay important information like weather conditions, navigation details, status reports etc. Beacon frames in an IEE 802.11 WLAN contain important details like SSID, type of the network, encryption details, supported data rates, manufacturer of AP etc. It is transmitted periodically to make the presence of WLAN known.  Tools like Kismet, NetStumbler, Wireshark can assist in reconnaissance. With the help of these tools details like SSID, Type of encryption & authentication, access point MAC Address along with approximate location, signal strength, channels being used etc. can be obtained.  The information obtained in this phase is what dictates the further course of wireless security testing. Exploiting the Authentication Protocol: Due to the inherent nature of Wi-Fi networks i.e. without wires and theoretically no boundaries; security has always been a prime concern. Authentication, Encryption, Authorization are a must in a Wi-Fi setup. In 802.11X network EAP gives RADIUS the capability to work with variety of authentication schemes like Kerberos, PKI, Smart Card etc.  In a typical and common implementation of EAP like TLS, MD5 and MSCHAPv2 (used in most of the Windows clients) the user ID/Login ID (active directory/domain) is sent in clear text during handshake.Figure 1. LEAP Handshake [1] Compromise of Login ID can further lead to brute force attempts for the passwords leading to unauthorized access.  In Figure 1 it can be seen that the User / Login ID is displayed in clear text. Wireshark is used to sniff the EAP – LEAP packets. Phase II: Attacks on Guest Wireless Networks Organizations these days have an isolated wireless network for guests & visitors to access the internet. The ‘Guest’ network is supposed to be an isolated network with no connection / interface to the corporate network.The following is common in a typical implementation of a ‘Guest’ wireless network:WEPWPA2 with pre-shared key (PSK)Internal IP Address assigned to the guestsThe ‘Guest’ client part of ‘Guest VLAN’ hypothetically isolated from the corporate / enterprise network; in many cases it is notFor accessing the ‘Internet’ resources; login credentials (username & password) required to be entered in the browserPre-Shared Keys are common for all ‘Guests’ and are seldom changedLogin Credentials used for accessing the internet are common for all the ‘Guests’Outsiders, contractors, vendors, guests, over sea / travelling employees etc. given access through the same ‘Guest’ network‘Guest VLAN’ is not isolated from the corporate VLANConsider a scenario where an attacker sitting in the organization’s premises gains access to the ‘Guest’ network’s IP Address. Irrespective of if he/she can access the internet assigning of organization’s internal IP Address to the attacker’s machine is a major threat. Figure 2.: Scan for10.100.1.1 to 10.100.1.100range showing two hosts are up The attacker can use tools like ‘Angry IP Scan’ to scan the entire range of IP Address to find out the host that is ‘UP’. Once the host is identified traditional VA&PT tools like Nessus, nmap, Metasploit etc. could be used to identify and exploit the vulnerabilities. Phase III: Implementation specific Attacks Attack on WEP: Attack Scenario 1: Cracking Wep Key Using airmon-ng Boot your favorite Linux distribution and initialize command console, Make sure you have the following tools installed:Aircrack-ng:Aircrack-ng is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once enough data packets have been captured. It implements the standard FMS attack along with some optimizations like KoreK attacks, as well as the all-new PTW attack, thus making the attack much faster compared to other WEP cracking tools.Macchanger:A GNU/Linux utility for viewing/manipulating the MAC address of network interfaces. Part A: Setting up your Machine1.Let’s start with setting up your machine with required software’s and libraries. You can install the above mentioned software’s from your linux distributor’s online repositories. 2.For Debian Based Linux Distribution (Eg: Debain, Ubuntu, linux mint etc.):- sudo apt-get install aircrack-ng sudo apt-get install Maccchanger For Redhat Based Linux Ditribution (Eg: RHEL, Centos, Fedora, Opensuse):-  yum install aircrack-ng yum install Macchanger  3.This command will list the current network adaptors in your system in detail; see what name has been assigned to your Wi-Fi adaptor.  For E.g:  wlan0, wlan1, etc.ifconfig 4.This command will stop the card and disable’s the broadcast and reception, as system won’t allow you to change the MAC address when card is in use:airmon-ng stop [Wi-Fi Card name] 5.Macchanger utility will change the original MAC address to any MAC address you desire.macchanger - -mac [] Disired MAC adress] [WiFi card-name] 6.This command will activate the wireless network adaptor for broadcast and reception, In some Linux distributions you may also witness the following error, as shown in the snapshot below:Airmon-ng start wlan0Figure 3: Step 6 Starting airmon-ng  7.If you see this error coming up on your console, you don’t need to lose your heart, it’s just that few services are already using your wireless adaptor or it’s associated files, you will also see the process names and PID’s, you can stop those process by using the following command’s:Kill - kill [PID ] – process

 8.You will see another extra adaptor that is set on monitor mode with the name mon0, use that adaptor in further commands where – ‘[Wi-Fi card name]’ appearsairmon-ng start [Wi-Fi Card name]

  PART B: Start Capturing  Data Packets 1.This command will initialize the Wi-Fi network monitoring & will show wireless network’s in range with encryption cipher being used like Wep, WPA or WPA2 and more. 2.As you execute the following command, you will see a certain number of beacons and data packets that will be stored in the filename you have given. The file will be stored in the root of the system drive (Click on Computer and you will see the file). The file will be present in two formats: *.cap, *.txt.  airodump-ng-c [Channel number] -w [Desired File name for later description] --bssid[BSSID] [Wi-Fi card name] Part C: Speed up the Process Data Packet’s Capturing Open a new console after the first data packet has been stored. Type the command in the new console and execute it  airreplay-ng -1 0 –a [BSSID] –h [FAKED MAC ADDRESS] -e [Wi-fi name] [Wi-Fi card name] As you type this command you will see that the data packets required for breaking the key will increase dramatically thereby saving you a lot of time.PART D: Cracking/brute forcing Wep Key Open another console once you have around 20,000 data packets and type the following command to reveal the WEP key. aircrack-ng –n 64 –b [BSSID] [Filename without the extension] Figure 4: Aircrack-ng in action It is not necessary that the key should have exactly the same digits as shown above so please don’t freak out if you see a 10 digit or 14 digit key.Figure 5: Brute force attack completed. Key Decrypted. Also if the decryption fails, you can change the bit level of the decryption in the command:  aircrack-ng –n [BIT LEVEL] –b [BSSID] [Filename without extension]  Remember, the bit level should be a number of 2n where n = 1,2,3,4…  Rogue Access PointsRogue Access Point is a wireless access point that has been illegally installed within a range of secure wireless network without the consent of the administrator of that wireless network. The sole purpose behind creating the Rogue access points is to capture the secret key used to by the clients to authenticate them to the legitimate wireless access point. Attacker’s exploits the loophole and setup their own access point with the same SSID’s to fool the clients in a way so that instead of connecting to legitimate access point they may connect to the Fake Access point created by the attacker. Once the attacker gain’s access to the secured wireless network he may also use sniffing and man in the middle attacks to capture the juicy information travelling throughout the network like login credentials, credit card details other important information. Airsnarf [1] Itis a simple rogue wireless access point setup utility which can found in  Backtrack a popular security distribution for penetration testers. Airsnarf is specially designed to demonstrate how rogue access point can actually steal usernames and passwords from publically available hotspots. It exploits the vulnerability in 802.11b hotspots by confusing the users with DNS and HTTP redirects from a competing legitimate wireless access point. Airsnarf is very user friendly. It contains a configuration file ./cfg/airsnarf.cfg file in which details like local network, gateway & SSID can be configured. The clients associated with the Fake / Rogue AP will receive the IP, DNS and gateway details from the Rogue AP. Also, it is possible to configure Airsnarf ‘splash page’ as dummy login page and capture the login credentials of the users. These details would be mailed to root@localhost.  Rogue AP is in a way a Social Engineering attack where in the attacker exploits the human tendency of ‘trust’. Other tools available for creating Rogue access point are freeradius WPE, karmetasploit a module in Metasploit (which is a combination of famous tool called karma), Hotspotter, Fake AP, VOID11 and wifitap. hole196 [2] Please note this vulnerability was identified and presented by MdSohail Ahmad from AirTight Networks at BlackHat 2010.Background:Man-in-the-Middle Attack or what is popularly known as MITM is very common in wired networks. But, now it’s very much possible in WPA2 networks as well. WPA2 uses two ncryption keys:Pairwise key (PTK)Group Key (GTK)GTK – GTK is broadcasted by the Access Point (AP) to all the clients and remains common for all the clients.PTK – It’s a unique to each client and is used to protect unicast data frames. It changes with each session. As per IEEE 802.11 standard PTK has inherent capability whereby it can detect MAC Address spoofing and data forgery. GTK has not been designed with this feature. These details are mentioned on the page 196 of IEEE 802.11 standard and hence the vulnerability was named as ‘Hole196’. Once again the flaw in the inherent design of the protocol has been used to exploit this vulnerability.  ‘hole196’ does not lead to cracking of WPA2 keys or discovering the passwords. It is a threat by the malicious insider which can act as a legitimate Access Point and affect the other clients i.e. Man-in-the-Middle Attack.Attack: Figure 6: Three Connected Clients The Access Point (AP) shares the same GTK with all the connected clients. So, GTK is known and is common to all connected clients. GTK is used as an encryption key by the AP and decryption key by the client.Figure 7 The log of wpa_supplicant software running on wireless clients shows that GTK key is known to the client devices. Figure 8  Attacker injects fake ARP Request packet to poison client’s cache for gateway. For the victim the attacker’s machine becomes the client gateway.Victim sends all traffic encrypted with its PTK to the AP, with Attacker as the destination (gateway)AP forwards Victim’s data to the Attacker encrypting it in the Attacker’s PTK. So Attacker can decrypt Victim’s private data. Spoofed ARP packets are never sent to AP and they never go over the wire and hence cannot be detected by wired IDS/IPS.   Block ACK DoS [3] All of us are familiar with TCP Sliding Window flow control concept. On the similar lines IEEE 802.11e and IEEE 802.11n are designed to acknowledge a block of packets instead of sequential transmit/acknowledge. The AP sends the client Add Block Acknowledgement (ADDBA) indicating the starting of the transmission, window size, sequence numbers etc. Anything outside the window is dropped by the recipient. So here is the catch! There is no security on the control frame and hence ADDBA frame can be impersonated and spoofed.Figure 9  Ideal Scenario: AP sends the ADDBA request to client identifying the window size, starting sequence number etc.Client responds with ACK followed by ADDBA responseAP sends an acknowledgement (ACK)Clients starts receiving the frames defined in the ADDBA control frame and ignores all the frames that fall outside this rangeThe AP sends BlockACK Request frame to client to know the status of the received framesClient reverts with a BlockACK if all the frames were received alternatively client can request for a retransmission or selective transmission of lost packetsAP sends a delete block acknowledgement (DELBA) Request to release the buffers of both AP and Client. Vulnerability in Block ACK Handling & DELBA frame: Since the control frames are not protected a malicious user / attacker can spoof the ADDBA frame and tamper the sequence details causing the recipient (in this client) to drop some or all the framesThis would result in re transmission or can also lead to DoSAlternatively malicious DELBA messages can be sent to untimely free the sender and receiver buffers causing disruption of service References:1. http://airsnarf.shmoo.com/2. MdSohail Ahmed from AirTight networks.http://www.airtightnetworks.com/WPA2-Hole196BlackHat 20103.High Speed Risks in 802.11n Networks by Joshua Wright from Aruba Networks presented in RAS Conference 2008. Note: By the time of this writing, a very good tutorial series has been launched by VivekRamachandranOn SecurityTube.net. 

 

Vishal Kalro

 
Vishal is an Information Security Consultant specializing in Infrastructure & Network Security. He has also published articles on Cloud Computing Threat & Security, Measuring WAN Performance & Social Engineering. He loves playing Badminton and reading fiction novels. 


 


Ishan Girdhar

 
Ishan Girdhar working as a Information Security consultant. Ishan loves exploring different linux distributions. He is currently working with AKS IT Services Pvt. Ltd Noida.


 

 

 

AESBusinessCompany TechnologyEntertainmentFDAPhaseGuest Wireless NetworksHome NetworksLaborLawLinuxMD5Person CareerRC4techGyanTechnologyWPA2 Add new comment CHMag Collector's Edition Vol II


 





 

Thursday, March 8, 2012

Find all the Computers and Devices which connected to your WiFi Network

Nowadays, there are many wifi networks available in the world. Although, small wireless networks are available in houses and small organizations using Wifi routers. But, Most of wireless networks are enabled Wireless security feature for avoiding unauthorized access. When you maintaining a wireless network without enabling wireless security, Someone who near to you can also connect to your network. So, recently i found a small utility called Wireless Network Watcher which display all the Computers and Devices currently connected to your Network. It will not only display the name of device but also it displays MAC Addresses of the devices and the Manufacture of the Network card of the devices. Hence, this application can be used for finding computers and devices that currently connected to your Network when the Wireless Network has disabled Wireless Security feature. In addition to this, it can be used for selecting and assigning Network adapter which is in your computer to Connected Devices. Download Wireless Network Watcher from below links.


Click on F5 button to refresh and then it will again searching for recently connected devices to the Network.
To assign Network adapter to specific device, select the device and then click on Options and click on Advanced Optons. Put a tick on use the following network adapter and select a adapter.   I used this option, when connected my sony ericsson phone to my Laptop and i changed the Network Adapter from 82562GT 10/100 to Broadcom 802.11g. You can download Wireless  Network Watcher using this link

Do not forget to leave your comments below.

View the original article here

Monday, March 5, 2012

Find all the Computers and Devices which connected to your WiFi Network

Nowadays, there are many wifi networks available in the world. Although, small wireless networks are available in houses and small organizations using Wifi routers. But, Most of wireless networks are enabled Wireless security feature for avoiding unauthorized access. When you maintaining a wireless network without enabling wireless security, Someone who near to you can also connect to your network. So, recently i found a small utility called Wireless Network Watcher which display all the Computers and Devices currently connected to your Network. It will not only display the name of device but also it displays MAC Addresses of the devices and the Manufacture of the Network card of the devices. Hence, this application can be used for finding computers and devices that currently connected to your Network when the Wireless Network has disabled Wireless Security feature. In addition to this, it can be used for selecting and assigning Network adapter which is in your computer to Connected Devices. Download Wireless Network Watcher from below links.


Click on F5 button to refresh and then it will again searching for recently connected devices to the Network.
To assign Network adapter to specific device, select the device and then click on Options and click on Advanced Optons. Put a tick on use the following network adapter and select a adapter.   I used this option, when connected my sony ericsson phone to my Laptop and i changed the Network Adapter from 82562GT 10/100 to Broadcom 802.11g. You can download Wireless  Network Watcher using this link

Do not forget to leave your comments below.

Wednesday, February 22, 2012

How to hack a wireless network with password

Sorry, I could not read the content fromt this page.Sorry, I could not read the content fromt this page.

View the original article here