Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Tuesday, 13 January 2015

// // Leave a Comment

Red Hat Linux 6 Exam Paper With Ans 2015



Study points for the exam:

Red Hat reserves the right to add, modify, and remove objectives. Such changes will be made public in advance through revisions to this document.
RHCSA exam candidates should be able to accomplish the tasks below without assistance. These have been grouped into several categories.
Understand and use essential tools
  • Access a shell prompt and issue commands with correct syntax
  • Use input-output redirection (>, >>, |, 2>, etc.)
  • Use grep and regular expressions to analyze text
  • Access remote systems using ssh
  • Log in and switch users in multiuser targets
  • Archive, compress, unpack, and uncompress files using tar, star, gzip, and bzip2
  • Create and edit text files
  • Create, delete, copy, and move files and directories
  • Create hard and soft links
  • List, set, and change standard ugo/rwx permissions
  • Locate, read, and use system documentation including man, info, and files in /usr/share/doc
Note: Red Hat may use applications during the exam that are not included in Red Hat Enterprise Linux for the purpose of evaluating candidate's abilities to meet this objective.

Operate running systems
  • Boot, reboot, and shut down a system normally
  • Boot systems into different targets manually
  • Interrupt the boot process in order to gain access to a system
  • Identify CPU/memory intensive processes, adjust process priority with renice, and kill processes
  • Locate and interpret system log files and journals
  • Access a virtual machine's console
  • Start and stop virtual machines
  • Start, stop, and check the status of network services
  • Securely transfer files between systems
Configure local storage
  • List, create, delete partitions on MBR and GPT disks
  • Create and remove physical volumes, assign physical volumes to volume groups, and create and delete logical volumes
  • Configure systems to mount file systems at boot by Universally Unique ID (UUID) or label
  • Add new partitions and logical volumes, and swap to a system non-destructively
Create and configure file systems
  • Create, mount, unmount, and use vfat, ext4, and xfs file systems
  • Mount and unmount CIFS and NFS network file systems
  • Extend existing logical volumes
  • Create and configure set-GID directories for collaboration
  • Create and manage Access Control Lists (ACLs)
  • Diagnose and correct file permission problems
Deploy, configure, and maintain systems
  • Configure networking and hostname resolution statically or dynamically
  • Schedule tasks using at and cron
  • Start and stop services and configure services to start automatically at boot
  • Configure systems to boot into a specific target automatically
  • Install Red Hat Enterprise Linux automatically using Kickstart
  • Configure a physical machine to host virtual guests
  • Install Red Hat Enterprise Linux systems as virtual guests
  • Configure systems to launch virtual machines at boot
  • Configure network services to start automatically at boot
  • Configure a system to use time services
  • Install and update software packages from Red Hat Network, a remote repository, or from the local file system
  • Update the kernel package appropriately to ensure a bootable system
  • Modify the system bootloader
Manage users and groups
  • Create, delete, and modify local user accounts
  • Change passwords and adjust password aging for local user accounts
  • Create, delete, and modify local groups and group memberships
  • Configure a system to use an existing authentication service for user and group information
Manage security
  • Configure firewall settings using firewall-config, firewall-cmd, or iptables
  • Configure key-based authentication for SSH
  • Set enforcing and permissive modes for SELinux
  • List and identify SELinux file and process context
  • Restore default file contexts
  • Use boolean settings to modify system SELinux settings
  • Diagnose and address routine SELinux policy violations

Paper In PDF


Paper In Docx


Paper In XPS


Paper In Docx 2

Read More

Monday, 12 January 2015

// // Leave a Comment

EC-Council Certified Ethical Hacker CEH v8 (Tools) And PDF Free Direct Link 2015

 

CEHV8 comes with some remarkable updates, not just to the content, but to the content delivery systems and tools, making it an invaluable tool for organizations ranging from Fortune 500 companies to the world’s governments, preparing the next generation of cyber warriors to protect their networks like never before.
Students can expect a strong focus on advanced hacking concepts, mobile platforms, tablet computer hacking techniques, and real time case studies. 100% of the concepts presented in the CEH V8 course are reinforced by hands-on exercises in EC-Councils newest cyber range. In addition CEHV8, is now an ANSI 17024 accredited professional certification.
The newly updated CEH contains 20 of the most current security domains any ethical hacker will ever want to know when they are planning to beef up the information security posture of their organization. The revamped CEH v8 will contain many enhancements including: core content updates, well-organized content flow, diagrammatic representation of concepts and attacks showcasing the latest hacking techniques, pentesting components, updated labs and courseware and popular hacking and security tools videos. Here are a few of the latest advancements the CEH v8 will address and focus on:
  • CEH v8 program focuses on addressing security issues to the latest operating systems including Windows 8 and Windows Server 2012
  • It also focuses on addressing the existing threats to operating environments dominated by Windows 7 and other operating systems (backward compatibility)
  • CEH v8 focuses on the latest hacking attacks targeted to mobile platform and tablet computers and covers countermeasures to secure mobile infrastructure
  • Coverage of latest development in mobile and web technologies including Andriod OS 4.1 and Apps, iOS 6 and Apps, BlackBerry 7 OS, Windows Phone 8 and HTML 5   
The goal of this course is to help students master an ethical hacking methodology that can be used in a penetration testing or ethical hacking situation. You walk out the door with hacking skills that are in high demand, as well as the internationally recognized Certified Ethical Hacker v8 certification!

Topics Covered PDF FILE FREE HERE !

  1. Introduction to Ethical Hacking
  2. Footprinting and Reconnaissance
  3. Scanning Networks
  4. Enumeration
  5. System Hacking
  6. Trojans and Backdoors
  7. Viruses and Worms
  8. Sniffers
  9. Social Engineering
  10. Denial of Service
  11. Session Hijacking
  12. Hacking Webservers
  13. Hacking Web Applications
  14. SQL Injection
  15. Hacking Wireless Networks
  16. Hacking Mobile Platforms
  17. Evading IDS, Firewalls and Honeypots
  18. Buffer Overflows
  19. Cryptography
  20. Penetration Testing

Who Would Benefit

  • Security Officers 
  • Auditors 
  • Network Administrators  
  • Firewall Administrators   
  • Security Professionals
  • Anyone who is concerned about the integrity of the network infrastructure 

Prerequisites


  • Strong knowledge of TCP/IP
  • Information systems and security background
  • Minimum of 12 months of experience in networking technologies

   What is New in the CEH v8?

  • More than 600 new instructor slides
  • More than 40 percent new labs are added
  • More than 1500 new/updated tools
  • CEH v8 program focuses on addressing security issues to the latest operating systems including Windows 8 and Windows Server 2012
  • It also focuses on addressing the existing threats to operating environments dominated by Windows 7 and other operating systems (backward compatibility)
  • CEHv8 focuses on the latest hacking attacks targeted to mobile platform and tablet computers and covers countermeasures to secure mobile infrastructure
  • Coverage of latest development in mobile and web technologies including Andriod OS 4.1 and Apps, iOS 6 and Apps, BlackBerry 7 OS, Windows Phone 8 and HTML 5

EC-Council Certified Ethical Hacker CEH v8 (Tools)


Read More

Friday, 9 January 2015

// // Leave a Comment

Learn Online Free Hacking And All Hardware And Networking Course Free


Welcome to the FREE IT and Cyber Security Training Revolution
Many classes are still in production, and they are being posted as they are completed. Currently the classes available include: CompTIA A+, Cisco CCNA, ITIL, CompTIA Cloud+, Virtualization Management, Office 365 – SharePoint, Ethical Hacking, CompTIA Security+, CompTIA CASP and Post Exploitation Hacking.




Welcome to Cybrary! The world’s first free and open, online IT and Cyber Security training platform. We believe IT and Cyber Security learning should be free, open source, and here at Cybrary, it will remain that way forever, but only with your help!


As members of a global and connected IT and Cyber Security community, we all have an obligation to ourselves and to one another. The obligation to ourselves is to never stop learning, and never stop improving. The industry changes at a rapid pace, and if we sit still, opportunities will pass us by. The obligation to one another is that we should do our part to help others across the world.
Cybrary was created to provide an environment where everyone can do both. Learning should be free and accessible to everyone, not just for those who can afford it. In order to keep knowledge free, we need your help. We will provide the free IT and Cyber Security training classes, and you can contribute. Here is how Cybrary’s free IT and Cyber Security learning environment works:

1) Take IT and Cyber Security classes online and at your own pace. – Course Catalog

2) Engage, discuss, share and constructively contribute to everyone’s learning experience. – Engagement Resources

3) Spread the word so that together we sustain this community, and earn points. – Member Points

4) Contribute to the course and learning content. – How to Contribute Content

If there are any IT or Cyber Security training classes that you would like to see added to Cybrary, then please make a suggestion. If you need technical support or you have questions in regards to the learning, let us know. Other than that, keep up with the Upcoming and Important Notifications above and study hard!

pick-a-pathChoose Your Course Path

Read More

Saturday, 3 January 2015

// // Leave a Comment

Ghost Phisher Python Tool For Wireless And Ethernet Security Testing

Phisher is a Wireless and Ethernet security testing tool written in Python Programming Language and the Python Qt GUI library.The program is able to emulate access points , conduct Phishing and Penetration Testing Attacks including the creation of a fare AP Network for Testing Purposes.

The particularity of this Tool is that includes an entire Section for Credentials Fetching and allows the Creation of a Fake DNS Server, Access Point, HTTP and DHCP Server.

Credential Fetching Method:


 Operating System Supported:         

>> Ubuntu KDE/GNOME

>> BackTrack Linux

>> BackBox Linux

>> Prerequisites


The Program requires thus packages:

>> Aircrack-NG

>> Python-Scapy

>> Python Qt4

>> Python

>> Subversion

>> Xterm

>> Metasploit Framework (Optional)



You can install it using following Command:
"apt-get install program"

In Debian, you can use following Command:
root@host:~# dpkg -i ghost-phisher_1.5_all.deb


Features:

>> HTTP Server
>> Inbuilt RFC 1035 DNS Server
>> Inbuilt RFC 2131 DHCP Server
>> Webpage Hosting and Credential Logger (Phishing)
>> Wifi Access point Emulator
>> Session Hijacking (Passive and Ethernet Modes)
>> ARP Cache Poisoning (MITM and DOS Attacks)       -----------> 




>> Penetration using Metasploit Bindings
>> Automatic credential logging using SQlite Database
>> Update Support

Download Link:
New version 1.52 is available

http://adfoc.us/26013953999554 
  
Project Source Code:
root@host:~# svn checkout  

http://adfoc.us/26013954001280 









 
Read More

Thursday, 1 January 2015

// // Leave a Comment

Sonic Bat Virus Maker (Make Virus Easily) Is Here !


Capture
Sonic Bat Virus Maker ( Creator )
A computer virus is a stealth program that is injected into your computer without your knowledge and runs against your wishes and frustrate you some time. Viruses can also replicate themselves. All computer viruses are man-made.A virus can replicates itself by being copied or initiating its copy to another program, computer boot sector or files,etc.Some viruses are also used to get useful
information of users like credit card details,email-id passwords,etc.
Sonic Bat Virus Maker is a small tool which is made to generate the batch files codes for reboot,formatting,disabling regedit,etc on a single click.This tools combines all the batch file codes as per the user which can perform different task in a single batch file name as sonic.bat.
Features 
Direct Download Links
  • Change Log On Password.
  • Change Time.
  • Add Any Number Of New User.
  • Disable Mouse.
  • Disable Keyboard.
  • Fork Bomb.
  • Delete/Format System drive(C:).
  • Drive Rename.
  • Folder Flood(Desktop,Music,Picture,Root,Doc,System32,Windows,Programs)
  • Swap Mouse Button.
  • Print Alert Message
  • Message Execution Timer.
  • Shutdown With Option(Reboot,Log Off,Shutdown and Abort).
  • Run On Startup.
How To Use ?
  1. Choose Your Virus Type.
  2. Click on add Code.
  3. Click on Build
  4. Choose save location.
  5. Done ! your virus is ready to harm victim’s PC.
http://adfoc.us/26013953978850


warning
  • Never test on your personal computer, it could be harmfully affect your pc .
Read More
// // 5 comments

How To Hack Facebook, Gmail, Skype And All Password Of A Person



Hack All Passwords Form A Computer Remotely
Last tutorial by me had a problem with E-Mail, So here is fully working tutorial. Wanna hack passwords of Facebook, Gmail, Orkut and other online and offline passwords of your friends, enemies, girlfriend, boyfriend or your Ex this is the perfect article for you. A keylogger is a program that runs in the background on someones computer that logs every key they press, and then sends the log of all the pressed keys to the attacker. This essentially allows you the ability to collect all the usernames and passwords typed in.

What do we need?
  1. Keylogger [Link Below]
  2. A new e-mail address specifically for keylogging

Note :

Watch every screenshot carefully to do everything correctly. ;)

Method 1

How To Create Keylogger?
  • Download the program, open it up and you should see the builder. Input your email username & password into the boxes. The reason we are doing this is because the keylogger will log into your email, then email yourself the logs. I recommend making a new email specifically for keylogging. Gmail SMTP Server Is:> smtp.gmail.com
2014-12-01_19-02-00
  • In delivery option choose E-Mail
  • This is the time in between the logs. I usually recommend 5-15 minutes.
  • At this point I suggest you click Test Email and make sure everything is working fine.
2014-12-01_18-15-46
  • Click the Recovery Tab.
  • Check Enable Stealers

  • Now go to settings tab and check boxes I have checked [Only those boxes]


  • Now click on the Binder option
  • Add any exe to deliver it [It will combine itself with an exe and whenever one install the exe the keylogger will be installed automatically]

  • Now click Tools option and Enable Fake error message
  • Now add an icon to it


  • Now click on Build option
  • And then click Compile Server
  • Wait for a while
  • Done {A message will pop}
  • Enjoy :)
Note:
Now get your build file and send it to your victims and get all information out of their computer. Use some attractive methods to persuade them to use your keylogger and anyhow jut make them run it once.

Method 2

  • FTP server
  • Click on FTP option in the logger
  • Create a FTP server first to create click here and sign up and create a FTP server

  • Put your FTP address, username, and password

  • Now click on test
  • You will get this message




Thanks To OnHax For This Nice Content (Hacker Veer)
                              
http://adfoc.us/26013953963019

Read More
// // Leave a Comment

Cracking WPA2 WPA with Hashcat in Kali Linux (BruteForce MASK based attack on Wifi passwords)

Cracking WPA2 WPA with Hashcat in Kali Linux (BruteForce MASK based attack on Wifi passwords) -blackMORE Ops - 6
cudaHashcat or oclHashcat or Hashcat on Kali Linux got built-in capabilities to attack and decrypt or Cracking WPA2 WPA with Hashcat – handshake .cap files. Only constraint is, you need to convert a .cap file to a .hccap file format. This is rather easy.


Hashcat

Hashcat is the self-proclaimed world’s fastest CPU-based password recovery tool. It is available free of charge, although it has a proprietary codebase. Versions are available for Linux, OSX, and Windows and can come in CPU-based or GPU-based variants. Hashcat currently supports a large range of hashing algorithms, including: Microsoft LM Hashes, MD4, MD5, SHA-family, Unix Crypt formats, MySQL, Cisco PIX, and many others.
Hashcat has made its way into the news many times for the optimizations and flaws discovered by its creator, which become exploited in subsequent hashcat releases. (For example, the flaw in 1Password’s hashing scheme.)

Attack types

Hashcat offers multiple attack modes for obtaining effective and complex coverage over a hash’s keyspace. These modes are:
  • Brute-Force attack
  • Combinator attack
  • Dictionary attack
  • Fingerprint attack
  • Hybrid attack
  • Mask attack
  • Permutation attack
  • Rule-based attack
  • Table-Lookup attack
  • Toggle-Case attack
The traditional bruteforce attack is considered outdated, and the Hashcat core team recommends the Mask-Attack as a full replacement.

Variants

Hashcat comes in two main variants:
  • Hashcat – A CPU-based password recovery tool
  • oclHashcat – A GPU-accelerated tool
Many of the algorithms supported by Hashcat can be cracked in a shorter time by using the well-documented GPU-acceleration leveraged in oclHashcat (such as MD5, SHA1, and others). However, not all algorithms can be accelerated by leveraging GPUs. Bcrypt is a good example of this. Due to factors such as data dependant branching, serialization, and Memory (to name just a few), oclHashcat is not a catchall replacement for Hashcat.
Hashcat is available for Linux, OSX and Windows. oclHashcat is only available for Linux and Windows due to improper implementations in OpenCL on OSX


Important Note: Many users try to capture with network cards that are not supported. You should purchase a card that supports Kali Linux including injection and monitor mode etc. A list can be found in 802.11 Recommended USB Wireless Cards for Kali Linux. It is very important that you have a supported card, otherwise you’ll be just wasting time and effort on something that just won’t do the job.



Why use Hashcat for cracking WPA WPA2 handshake file?

Pyrit is the fastest when it comes to cracking WPA2 WPA handshake files. So why are we using Hashcat to crack WPA2 WPA handshake files?
  1. Because we can?
  2. Because Hashcat allows us to use customized attacks with predefined rules and Masks.
Now this doesn’t explain much and reading HASHCAT Wiki will take forever to explain on how to do it. I’ll just give some examples to clear it up.
Hashcat allows you to use the following built-in charsets to attack a WPA2 WPA handshake file.

 Built-in charsets

?l = abcdefghijklmnopqrstuvwxyz
?u = ABCDEFGHIJKLMNOPQRSTUVWXYZ
?d = 0123456789
?s = !”#$%&'()*+,-./:;⇔?@[\]^_`{|}~

?a = ?l?u?d?s

Capture handshake with WiFite

Why WiFite instead of other guides that uses Aircrack-ng? Because we don’t have to type in commands..
Type in the following command in your Kali Linux terminal:
root@kali:# wifite –wpa You could also type in
root@kali:#wifite wpa2 If you want to see everything, (wep, wpa or wpa2, just type the following command. It doesn’t make any differences except few more minutes
root@kali:#wifite Once you type in following is what you’ll see.
 1-wifite-cracking-wifi-wpawpa2-passwords-using-pyrit-and-cowpatty-blackmore-ops
So, we can see bunch of Access Points (AP in short). Always try to go for the ones with CLIENTS because it’s just much faster. You can choose all or pick by numbers. See screen-shot below

2-wifite-screen-cracking-wifi-wpawpa2-passwords-using-pyrit-and-cowpatty-blackmore-ops 


Awesome, we’ve got few with clients attached. I will pick 1 and 2 cause they have the best signal strength. Try picking the ones with good signal strength. If you pick one with poor signal, you might be waiting a LONG time before you capture anything .. if anything at all.
So I’ve picked 1 and 2. Press Enter to let WiFite do it’s magic.

3-wifite-choice-cracking-wifi-wpawpa2-passwords-using-pyrit-and-cowpatty-blackmore-ops

Once you press ENTER, following is what you will see. I got impatient as the number 1 choice wasn’t doing anything for a LONG time. So I pressed CTRL+C to quit out of it.
This is actually a great feature of WIfite. It now asks me,
What do you want to do?
  1. ontinue attacking targets
  2. [e]xit completely.
I can type in c to continue or e to exit. This is the feature I was talking about. I typed c to continue. What it does, it skips choice 1 and starts attacking choice 2. This is a great feature cause not all routers or AP’s or targets will respond to an attack the similar way. You could of course wait and eventually get a respond, but if you’re just after ANY AP’s, it just saves time.

4-wifite-continue-cracking-wifi-wpawpa2-passwords-using-pyrit-and-cowpatty-blackmore-ops

And voila, took it only few seconds to capture a handshake. This AP had lots of clients and I managed to capture a handshake.
This handshake was saved in /root/hs/BigPond_58-98-35-E9-2B-8D.cap file.
Once the capture is complete and there’s no more AP’s to attack, Wifite will just quit and you get your prompt back.
5-wifite-captured-handshake-cracking-wifi-wpawpa2-passwords-using-pyrit-and-cowpatty-blackmore-ops



Now that we have a capture file with handshake on it, we can do a few things.

Cleanup your cap file using wpaclean

Next step will be converting the .cap file to a format cudaHashcat or oclHashcat or Hashcat on Kali Linux will understand.
Here’s how to do it:
To convert your .cap files manually in Kali Linux, use the following command
wpaclean <out.cap> <in.cap>
Please note that the wpaclean options are the wrong way round. <out.cap> <in.cap> instead of <in.cap> <out.cap> which may cause some confusion.
In my case, the command is as follows:
root@kali:#wpaclean hs/out.cap hs/BigPond_58-98-35-E9-2B-8D.cap

Convert .cap file to .hccap format

We need to convert this file to a format cudaHashcat or oclHashcat or Hashcat on Kali Linux can understand.
To convert it to .hccap format with “aircrack-ng” we need to use the -J option
root@kali:#aircrack-ng <out.cap> -J <out.hccap>
Note the -J is a capitol J not lower case j.
In my case, the command is as follows:
root@kali:#aircrack-ng hs/out.cap -J hs/out

cracking-wpawpa2-with-oclhashcat-cudahashcat-or-hashcat-on-kali-linux-bruteforce-mask-based-attack-blackmore-ops-1  
 
Cracking WPA2 WPA handshake with Hashcat
cudaHashcat or oclHashcat or Hashcat on Kali Linux is very flexible, so I’ll cover two most common and basic scenarios:
  1. Dictionary attack
  2. Mask attack

  1. Dictionary attack

First we need to find out which mode to use for WPA2 WPA handshake file. I’ve covered this in great length in Cracking MD5, phpBB, MySQL and SHA1 passwords with Hashcat on Kali Linux guide. Here’s a short rundown:
root@kali#cudahashcat --help | grep WPA
So it’s 2500.
Now use the following command to start the cracking process:
root@kali#cudahashcat -m 2500 /root/hs/out.hccap /root/rockyou.txt

cracking-wpawpa2-with-oclhashcat-cudahashcat-or-hashcat-on-kali-linux-bruteforce-mask-based-attack-blackmore-ops-2

Bingo, I used a common password for this Wireless AP. Took me few seconds to crack it. Depending on your dictionary size, it might take a while.
You should remember, if you’re going to use Dictionary attack, Pyrit would be much much much faster than cudaHashcat or oclHashcat or Hashcat. Why we are showing this here? Cause we can. :)

2.  Brute-Force Attack

Now this is the main part of this guide. Using Brute Force MASK attack.
To crack WPA WPA2 handshake file using cudaHashcat or oclHashcat or Hashcat, use the following command:

Sample:

root@kali#cudahashcat -m 2500 -a 3 capture.hccap ?d?d?d?d?d?d?d?d

Where -m = 2500 means we are attacking a WPA2 WPA handshake file.
-a = 3 means we are using Brute Force Attack mode (this is compatible with MASK attack).
capture.hccap = This is your converted .cap file. We generated it using wpaclean and aircrack-ng.
?d?d?d?d?d?d?d?d = This is your MASK where d = digit. That means this password is all in numbers. i.e. 7896435 or 12345678 etc.
I’ve created a special MASK file to make things faster. You should create your own MASK file in similar way I explained earlier. I’ve saved my file in the following directory as blackmoreops-1.hcmask.


root@kali#/usr/share/oclhashcat/masks/blackmoreops-1.hcmask

Do the following to see all available default MASK files provided by cudaHashcat or oclHashcat or Hashcat:

root@kali#ls /usr/share/oclhashcat/masks/

In my case, the command is as follows:
 
root@kali#cudahashcat -m 2500 -a 3 /root/hs/out.hccap  /usr/share/oclhashcat/masks/blackmoreops-1.hcmask 

cracking-wpawpa2-with-oclhashcat-cudahashcat-or-hashcat-on-kali-linux-bruteforce-mask-based-attack-blackmore-ops-3 
 
 

Sample .hcmask file

You can check the content of a sample .hcmask file using the following command:
root@kali# tail -10 /usr/share/oclhashcat/masks/8char-1l-1u-1d-1s-compliant.hcmask

cracking-wpawpa2-with-oclhashcat-cudahashcat-or-hashcat-on-kali-linux-bruteforce-mask-based-attack-blackmore-ops-4 
Edit this file to match your requirement, run Hashcat or cudaHashcat and let it rip.

Location of Cracked passwords

Hashcat or cudaHashcat saves all recovered passwords in a file. It will be in the same directory you’ve ran Hashcat or cudaHashcat or oclHashcat. In my case, I’ve ran all command from my home directory which is /root directory.

cracking-wpawpa2-with-oclhashcat-cudahashcat-or-hashcat-on-kali-linux-bruteforce-mask-based-attack-blackmore-ops-5

Conclusion

This guide explains a lot. But you should read read Wiki and Manuals from www.hashcat.net to get a better understanding of MASK and Rule based attacks because that’s the biggest strength of Hashcat.
Thanks for reading. Feel free to share this article. More on similar series:
  
Read More

Wednesday, 31 December 2014

// // Leave a Comment

How Can We Bypass HTMLEntities Tutorial


How Can We Bypass HTMLEntities Tutorial ?
The Security researcher Paulos Yibelo share with HAOW that how he bypassing htmlentities().
Well I don’t know how to break it down for you, you just can’t (if the function is used properly and exactly where it should). But it’s more probable that most developers don’t use it the right way, since it’s like a norm for some developers to not use built-in functions properly :P. So I will talk about some of the cases I came up while pentesting. htmlentities() and htmlspecailchars() are functions mainly developed to filter out cross site scripting attacks.

But I can promise you that you can build a better function if your user input is massive since that’s when most exploitation scenarios begin. How? Well, the functions html entity the characters < , > “ and ‘. So without those there seems there is no XSS. Or isn’t really? Well, I can think of one. Something like javascript:alert(1); will be executed since none of the characters in it are filtered to be html entityed… but there is a limitation to this. Without using “> or any similar technique we will not be able to break out of the attribute we are inside.


Also the value attribute in html is not vulnerable since it only accepts strings and well we need scripts that can execute… something like href, onclick would do… but who would put such a foolish mistake right? Well you wouldn’t believe if I told you even big companies like Facebook does.
Have a code like?

                               print '<img src="'.htmlentities("$url").”';
or even   

          print "<a href='".htmlentities($url)."'>Click Here</a>"; 

“javascript:alert(1);” will bypass it because it doesn’t contain the characters that will be filtered. But notice a limitation here? Our code will only execute if user clicks the Click Here button. So that’s a huge limitation. Or is it? The html code will become something like
 

             <a href='javascript:alert(1);'>Click Here</a>

 But we need to break out of the href tag and execute a more malicious javascript. But how? If we try to break out of it using ‘> it won’t work since both those characters are filtered out… and the code will become something like


<a href='javascript:alert(1);&quot;&gt;'>Click Here</a>

Right? Well not exactly. Htmlentities comes with single quote ( ‘ ) not filtered by default and you have to specify a special switch called ENT_QUOTES to declare that. So the real output when values like “javascript:alert(1);’>” is given

<a href='javascript:alert(1);'&gt;'>Click Here</a>

A hope! We broke out of the attribute so giving values like

javascript:alert(1);’ onfocus=alert(1); autofocus

will output html source like
 

Read More

Tuesday, 23 December 2014

// // Leave a Comment

Hack WEP,WPA2 Wifi In Kali Linux

Breaking WPA2-PSK with Kali Linux

 WPA2-PSK may not be as safe as you think. There are a few attacks against WAP2-PSK. One of the most common attacks is against WPA2 is exploiting a weak passphrase.

Below you will find a few easy steps on how to break WPA2 with a weak passphrase.

 

Breaking the Wireless Hacker VeerNetwork:

I set up a test network for this blog article. The client box is logging into my Hacker Veer test network. This is the network we will break.




Step 1:
The first step is to verify the router configuration. Normally in a real penetration test we would not have this option, but since this is a home lab I have a little more flexibility.
In this case the lab access point is securing the wireless network Hacker Veer  with WPA2-PSK. It using the passphrase Cisco123. You can use any wireless router to setup your wireless lab.




 Step 2:
We will be using Kali Linux to complete this task. Kali will need a wireless card configured before it can be used by the operating system. I am using the Alfa AWUS051NH adapter. Almost any Alfa wireless adapter will work. I am a big fan of the AWUS051NH adapter because it a duel band adapter. However, this card is very difficult to obtain since it is no longer sold.



The iwconfig command will show any wireless cards in the system. I am using a RealTek wireless card. Linux ships with the RealTek drivers, making it a Linux plug and play wireless card.
The operating system recognizes a  wireless interface named wlan0.


Step 3:
My next step will be to enable the wireless interface. This is accomplished issuing the ifconfig wlan0 up command.








Step 4:
I need to understand what wireless networks my wireless card sees. I issue the iwlist wlan0 scanning command.


This command forces the wireless card to scan and report on all wireless networks in the vicinity.
You can see from this example it found my target network: Wireless Lab. It also found the MAC address of my access point: 0E:18:1A:36:D6:22. This is important to note because I want to limit my attack to this specific access point (to ensure we are not attacking or breaking anyone else’s password).
Secondly, we see the AP is transmitting on channel 36.This is important because it allows us to be specific on what wireless channel we will want our wireless card to monitor and capture traffic from.



Step 5:
The next step is to change the wireless card to monitoring mode. This will allow the wireless card to examine all the packets in the air.
We do this by creating a monitor interface using airmon-ng. Issue the airmon-ng command to verify airmon-ng sees your wireless card. From that point create the monitor interface by issuing the command: airmon-ng start wlan0


 Next, run the ifconfig command to verify the monitor interface is created. We can see mon0 is created.





Now verify the interface mon0 has been created.



Step 6:
Use airodump-ng to capture the WPA2 handshake. The attacker will have to catch someone in the act of authenticating to get a valid capture. Airodump-ng will display a valid handshake when it captures it. It will display the handshake confirmation in the upper right hand corner of the screen.
Note: We will manually connect to the wireless network to force a handshake. In a future post I will show you how to force a reauthorization to make a device automatically disconnect and reconnect without any manual intervention.
We used the following command: airodump-ng mon0 – -bssid 20:aa:4b:1f:b0:10 (to capture packets from our AP) – -channel 6 (to limit channel hopping) – -write BreakingWPA2 (the name of the file we will save to)
airodump-ng mon0 – -bssid 0E:18:1A:36:D6:22 – -channel 36 – -write BreakingWPA2

(make sure there is no space between “- -“)



To capture the handshake you are dependent on monitoring a legitimate client authenticate to the network. However, it does not mean you have to wait for a client to legitimately authenticate. You can force a client to re-authenticate (which will happen automatically with most clients when you force a deauthorization).
When you see the WPA Handshake Command you know you have captured an valid handshake

example:


WPA2 Handshake




Step 7:
We will use aircrack-ng with the dictionary file to crack the password. Your chances of breaking the password are dependent on the password file.

The command on  is: aircrack-ng “name of cap file you created” -w “name of your dictionary file”

aircrack
.
The BreakingWPA2-01.cap file was created when we ran the airodump-ng command. The valid WPA2 handshake airodump captured is stored in the BreakingWPA2-01.cap file.
Backtrack 5 ships with a basic dictionary. The dictionary file darkc0de.lst is a popular worldlist that ships with BackTrack5. We added our password Cisco123 in this file to make the test run a little smoother.




In this blog we created a file named “sample.lst” and added the word Cisco123 in it.
Success:
If the password is found in the dictionary file then Aircrack-ng will crack it.



aircrack WPA



                                                                  
Read More