<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-2208382470258337434</atom:id><lastBuildDate>Thu, 16 Feb 2012 20:00:20 +0000</lastBuildDate><category>Hacking Tools</category><category>Make Money Online</category><category>android</category><category>Desktop Security</category><category>Backtrack</category><category>Security News</category><category>Security Tools</category><category>Exploits</category><category>Website Hacking</category><category>Firefox tips and tricks</category><category>Hacking News</category><category>Orkut</category><category>Google Tips and Tricks</category><category>Miscellaneous</category><category>XP Tips and Tricks</category><category>Ethical Hacking</category><category>Facebook</category><category>WiFi Hacking</category><category>Windows 7 Tips n Tricks</category><category>Viruses</category><category>Blogger tips and tricks</category><category>Latest Trends in technologies</category><category>All about Google</category><title>TechKranti</title><description>Information Revolution</description><link>http://www.techkranti.com/</link><managingEditor>noreply@blogger.com (Rahul Sachin Amey)</managingEditor><generator>Blogger</generator><openSearch:totalResults>167</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/blogspot/Gotp" /><feedburner:info uri="blogspot/gotp" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-3166572268897364518</guid><pubDate>Wed, 14 Dec 2011 18:00:00 +0000</pubDate><atom:updated>2011-12-14T11:47:28.535+05:30</atom:updated><title>Norton Internet Security 2012: More than a Review</title><description>What is it that thing that reminds you, that you have an Anti-virus installed on your system? Is it the alerts? Naa. You can&amp;nbsp; actually go without being exposed to malware for quite a number of weeks. I think the thing that reminds you that is the constant performance degradation of your machine when it runs the scheduled scans on your system. If that is how you would define an Anti-virus, then my dear friends, I can irrefutably say that Norton Internet Security 2012 (NIS 2012) is not an anti-virus although it functions like one :).&lt;br /&gt;
&lt;br /&gt;
Symantec with its latest addition NIS 2012 presents to you a new era of anti-virus software which won't eat up your processing power in return for securing your system. NIS really secures your system from all sorts of threats, may it be from the internet or from infected flash drives. I have been using NIS 2012 for about 3 months now and I should say that paying adieu to my old Kaspersky was a pretty good decision. Fun fact about Kaspersky: I had set a daily full scan at 12 pm and when I am at the peak of my work it would eat up all my memory which probably belongs to me :). Here I am gonna explain some really cool features that NIS 2012 offers without depleting your precious memory.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;1. Download Insight: &lt;/b&gt;
&lt;br /&gt;
&lt;br /&gt;
The most innovative feature that comes with NIS 2012 is Download insight(DI). It takes care that the file you just downloaded from the Internet is safe from any malware. As soon as you download an executable on your system, NIS 2012 initiates DI to analyze the trustworthiness of the file and within seconds it pops up an alert giving an 'Insight' on the downloaded file. &lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-tU797b7SRx0/Tt8CJhQ1a3I/AAAAAAAAAd4/4t1NB2ftg5s/s1600/Insight.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-tU797b7SRx0/Tt8CJhQ1a3I/AAAAAAAAAd4/4t1NB2ftg5s/s1600/Insight.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;br /&gt;
This is a really cool way to save yourself from threats for which signatures have not yet been downloaded by your AV. This brings us to the concept of &lt;b&gt;'Cloud-based Scanning'&lt;/b&gt;. Cloud-based scanning is the new buzzword in the security industry and a few security vendors are using the term although they often mean something very different.
&lt;br /&gt;
&lt;br /&gt;
The obvious advantage of cloud scanning is that the turnaround time for a definition to be available is extremely fast – as soon as a definition is available in the cloud, it is available to the user. What Symantec has done is to build a system that analyzes the reputation of the new software and files across the Internet and then calculates a reputation score for each of them. This system receives feeds from tens of millions of customers that anonymously participate in the Norton Community Watch program. The technology automatically starts working on calculating the reputation score as it becomes aware of new files.
&lt;br /&gt;
&lt;br /&gt;
We got in touch with Mr. David Hall, Consumer Product Marketing, Asia Pacific for Syamtec for more clarity about Download Insight. Mr. David says, "Now this is powerful – we have a system that can receive knowledge of new files worldwide and use a Symantec “secret sauce” algorithm to calculate the reputation score automatically! This information is immediately available to Download Insight through the cloud, but quite a bit different than just moving the old signature model to the cloud."
&lt;br /&gt;
&lt;br /&gt;
But How is the reputation score of a file determined?
&lt;br /&gt;
&lt;br /&gt;
A reputation score is calculated using a complex algorithm based on various parameters. Remember, the main feed in to the Reputation system is the information received from the Norton Community Watch program.   Here’s a list of a few parameters that are used to calculate the reputation score: &lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;How many instances of a particular file are seen?&lt;/li&gt;
&lt;li&gt;How long has that file been around? &lt;/li&gt;
&lt;li&gt;From which URLs were they downloaded? &lt;/li&gt;
&lt;li&gt;What is the basic health of the system that is submitting the data? &lt;/li&gt;
&lt;li&gt;Which software vendor does the file belong to?  &lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Download Insight in action  :&lt;/b&gt;
&lt;br /&gt;
&lt;br /&gt;
Download Insight monitors when new files are downloaded, and once the download is complete it goes into action:
&lt;br /&gt;
&lt;br /&gt;
This is the flow where the user chooses to save the application to a folder on the computer.  &lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;Download Insight observes that the file download from the Internet is complete. &lt;/li&gt;
&lt;li&gt;It calculates the SHA256 hash of that file and immediately asks the online servers for a reputation score. &lt;/li&gt;
&lt;li&gt;Based on the reputation score, Download Insight will: &lt;/li&gt;
&lt;br /&gt;
a. Delete the application if the reputation score is at a “Bad” level and display a notification to the user. &lt;br /&gt;
b. Allow the file to persist if the reputation score is “Good” and display a corresponding notification. &lt;br /&gt;
c. Provide additional information when the score for the file is still being evaluated.&lt;br /&gt;&lt;br /&gt;

The “View Details” link for each notification provides more information from Symantec's servers. Here are a few examples: &lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;Prevalence – How widely used is this file is in the Norton Community? It can range from very few instances to millions of machines.&lt;/li&gt;
&lt;li&gt;Age – How long has this file been around?&lt;/li&gt;
&lt;li&gt;Reputation Rating – What does Norton think of this file? It provides an indication on how trustworthy the file is. &lt;/li&gt;
&lt;li&gt;URL – This provides the website from which this file was downloaded.&lt;/li&gt;
&lt;/ol&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-63g7Ym897B8/TtuR-0kRcGI/AAAAAAAAAdY/86SHzz9SB4c/s1600/norton+insight.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://4.bp.blogspot.com/-63g7Ym897B8/TtuR-0kRcGI/AAAAAAAAAdY/86SHzz9SB4c/s400/norton+insight.bmp" width="378" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;&lt;br /&gt;

&lt;b&gt;Run the download file:&lt;/b&gt;&lt;br /&gt;

The second user flow where Download Insight participates is the time when you run the application downloaded from the Internet – it could be right after you download the application or couple of days later when you choose to install the application.  If the reputation of the file was still being evaluated (yellow notification in Figure 1), Norton will alert the user with a dialogue that provides the information showed in Figure 2 and has recommendation on what the user can do with application. It looks like:&lt;/ol&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-ybl1B4V8AeI/TtuTGx7K-aI/AAAAAAAAAdg/ViwSVuRVKRA/s1600/norton+insight+limewire.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-ybl1B4V8AeI/TtuTGx7K-aI/AAAAAAAAAdg/ViwSVuRVKRA/s320/norton+insight+limewire.bmp" width="302" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;2. SONAR&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
SONAR provides real-time protection against threats and proactively detects unknown security risks on your computer and identifies emerging threats based on the behavior of applications. SONAR identifies threats quicker than the traditional signature-based threat detection techniques. SONAR detects and protects you against malicious code even before virus definitions and monitors your computer for malicious activities through heuristic detections. In fact, improved SONAR technology in the Norton 2012 products monitors running applications for suspicious behavior to quickly detect and disable previously unknown threats.&lt;br /&gt;
&lt;br /&gt;
Some significant changes were made to SONAR when Symantec launched the Norton 2011 products last year, which included the latest SONAR 3 that built upon the successful, effective and efficient SONAR 2 behavioral security engine.  With SONAR 2, Symantec has a proven track record of being able to convict malware and secure Norton users from malware designed to evade most other security features. According to Symantec, "In nine months we prevented upward of 4.2 million infections out of about 140 million incidents that we analyzed for Norton users. Most of these incidents were never-before-seen malware and infection scenarios, thus truly providing "zero-day" protection! The effectiveness of our technology was repeatedly confirmed by external 3rd-party &lt;a href="http://www.symantec.com/about/news/release/article.jsp?prid=20091027_04"&gt;tests and reviews&lt;/a&gt; (specifically behavioral security tests and reviews), where we performed at or near 100% detection rates." 
&lt;br /&gt;
&lt;br /&gt;
Behavioral security is a critical security solution, especially in this era of server-side polymorphic malware where each and every infection can have a unique piece of malware file (unique from the file fingerprint perspective) downloaded on the victim's machine.&lt;br /&gt;
&lt;br /&gt;
SONAR aggregates and correlates information from a number of engines within the product like the Firewall, AV Engine, Intrusion Prevention Engine, etc. All this information is then used by the classifier to improve efficacy and this is a big differentiator for Norton. Most other security products simply don’t have this depth and breadth of information to make a good classifier. In SONAR 3 we have further enhanced our integration with the network component in order to classify, convict, and remediate malware on the basis of its malicious network activity. With this feature in place, we will continue to block and remove many new variants of malware that leave their network footprint unchanged.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;3. How does NIS 2012 assure Security without compromising Performance? &lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
NIS 2012 performs quick scans only when the system is in idle mode. So your system would be scanned only when you are away from it. We asked Symantec, "How does NIS select areas for performing quick scans?". Symantec's reply: "Norton will use idle time to scan against a list of files most commonly at risk. This varies dependant on the actual level of trust on the PC and other variables."&lt;br /&gt;
&lt;br /&gt;
But quick scans are not enough to completely secure your system. NIS 2012 is scheduled to perform full system scans weekly. The Full scans too are so silent that you'll hardly notice them. You can see the logs of Full Scans by visiting the Security History&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-ig_px3lRhFI/Tt8COJVLgWI/AAAAAAAAAeA/63LXvqaGvVE/s1600/Full+Scan.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="344" src="http://2.bp.blogspot.com/-ig_px3lRhFI/Tt8COJVLgWI/AAAAAAAAAeA/63LXvqaGvVE/s640/Full+Scan.JPG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;4. Intrusion Prevention&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The intrusion prevention capabilities of NIS 2012 are good. It identifies all kinds of network-level attacks. I tried running a Nessus Scan against a virtual host where NIS was installed and the scan did not return any helpful results.

&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-5MWx53VycUU/Tt8GX5s16jI/AAAAAAAAAeI/bV6baJgYP6I/s1600/IPS.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="451" src="http://1.bp.blogspot.com/-5MWx53VycUU/Tt8GX5s16jI/AAAAAAAAAeI/bV6baJgYP6I/s640/IPS.JPG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;5. Some more miscellaneous yet useful&amp;nbsp;features:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;i. Performance Monitoring&lt;/b&gt;
NIS 2012 provides performance alerts if an application is eating a big chunk of your memory.
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-BNOAb4Bk2Ag/Tt8LwRs59oI/AAAAAAAAAeQ/laIQe5YGwp4/s1600/PerfAlert.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-BNOAb4Bk2Ag/Tt8LwRs59oI/AAAAAAAAAeQ/laIQe5YGwp4/s1600/PerfAlert.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-7fjPiOomSHE/Tt8Lxa_F6QI/AAAAAAAAAeU/VVaHJWwDFTI/s1600/PerfAlert1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="288" src="http://4.bp.blogspot.com/-7fjPiOomSHE/Tt8Lxa_F6QI/AAAAAAAAAeU/VVaHJWwDFTI/s400/PerfAlert1.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;ii. Safe Search&lt;/b&gt;&lt;br /&gt;
This has been a prevalent feature in many modern day anti-viruses. NIS 2012 also ships with IE, Firefox and Chrome plugins for verifying the health of locations of links from a search page. Image below is self-explanatory.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-pO8pZxWrbjU/TudY7y4QpvI/AAAAAAAAAeg/NFuFDW5pXLk/s1600/SafeSearch.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="228" src="http://2.bp.blogspot.com/-pO8pZxWrbjU/TudY7y4QpvI/AAAAAAAAAeg/NFuFDW5pXLk/s640/SafeSearch.JPG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;iii. Browser Protection&lt;/b&gt;&lt;br /&gt;
If NIS 2012 detects malicious content on an HTML page trying to exploit a vulnerability on your browser (especially when you are using IE ;)), it immediately discontinues the connection and pops up a malicious site banner.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;iv. Identity Safe&lt;/b&gt;&lt;br /&gt;
Identity Safe is a password management plugin for your browser where you can set a master password and save all your logins for saving from the nuisance of typing your credentials at every authentication page you visit.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;6. Graphical User Interface&lt;/b&gt;&lt;br /&gt;
The interface provided with NIS 2012 is very intuitive and easy to use. Highlighting some key aspects you can do using the GUI..&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-7hed0TZQaRQ/TudaL7WLx-I/AAAAAAAAAeo/eUWQz35avU4/s1600/NIS+Main.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="425" src="http://2.bp.blogspot.com/-7hed0TZQaRQ/TudaL7WLx-I/AAAAAAAAAeo/eUWQz35avU4/s640/NIS+Main.JPG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
The huge world map there shows you the worldwide cybercrime activity for the past 24 hours. Also provides latest viruses that have been discovered and a link that will provide more information on the same.&lt;br /&gt;
&lt;br /&gt;
If you dig deeper into the Advanced tab, you get to see your recent History of threats and ratings of applications installed on your system&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;7. Minds its own Business&lt;/b&gt;&lt;br /&gt;
Me being in the security field have to deal with a lot of tools which any Anti-Virus will report as a threat. But it is my choice to use them for my research. So when I tell NIS 2012, not to touch a certain location, it obeys like a very faithful companion, also reminding me about the risks I am exposed to by making this exclusion.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Moral:&lt;/b&gt;&lt;br /&gt;
NIS 2012 is a product made for all... From the Noob to the Geek... It kinda protects you at every step of your online life.&lt;br /&gt;
&lt;br /&gt;
Lets take a scenario:&lt;br /&gt;
Suppose I am the dumbest person on this planet, the biggest n00b ever born. I have NIS 2012 installed. Let's see how NIS 2012 protects me from any possible malware:&lt;br /&gt;
&lt;br /&gt;
1. I open my browser, google for "Some random executable". NIS 2012 tells me which search results are good and which are malicious.&lt;br /&gt;
&lt;br /&gt;
2. I visit some random website and download a the file. NIS 2012 initiates Download Insight and checks the trustworthiness of the file.&lt;br /&gt;
&lt;br /&gt;
3. I execute the downloaded file. NIS 2012 initiates its scanning engine to check for any viruses on the file.&lt;br /&gt;
&lt;br /&gt;
4. The file has been executed. NIS 2012's SONAR functionality will check the application activity for any suspicious actions.&lt;br /&gt;
&lt;br /&gt;
So NIS 2012 has made sure that my PC is secure at every phase of my online and offline activity. So, effectively, along with it being a good Anti-virus, it is also Stupidity-proof ;).&lt;br /&gt;
&lt;br /&gt;
On an ending note: Auditing servers is a part of my job. I see a lot companies using cheap Anti-viruses which provide no real value add to the security infrastructure. It would be my humble recommendation to all those admins out there to use NIS 2012 as their AV (If you really wanna keep your data secure. If you just want to show compliance, use Any.. doesn't matter)&lt;br /&gt;
&lt;br /&gt;
If you want to make a choice on buying an AV... I don't see any other than wise decision than Norton &amp;nbsp;Internet Security 2012.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-3166572268897364518?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/LPdHK-HnE_Qx5mNPpdaF5UcqNlw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LPdHK-HnE_Qx5mNPpdaF5UcqNlw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/LPdHK-HnE_Qx5mNPpdaF5UcqNlw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LPdHK-HnE_Qx5mNPpdaF5UcqNlw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/FndEBO3y8lg" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/FndEBO3y8lg/norton-internet-security-2012-more-than.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-tU797b7SRx0/Tt8CJhQ1a3I/AAAAAAAAAd4/4t1NB2ftg5s/s72-c/Insight.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2011/12/norton-internet-security-2012-more-than.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-8088540365965594738</guid><pubDate>Sun, 21 Aug 2011 06:40:00 +0000</pubDate><atom:updated>2011-08-21T12:15:11.101+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Hacking Tools</category><category domain="http://www.blogger.com/atom/ns#">Security Tools</category><category domain="http://www.blogger.com/atom/ns#">Security News</category><category domain="http://www.blogger.com/atom/ns#">Hacking News</category><category domain="http://www.blogger.com/atom/ns#">Ethical Hacking</category><category domain="http://www.blogger.com/atom/ns#">android</category><category domain="http://www.blogger.com/atom/ns#">Exploits</category><title>Key Logger for Android</title><description>Computer scientists from UC Davis university&amp;nbsp;have developed an Android app named TouchLogger that logs keystrokes using a smartphone's 
sensors to measure the locations a user taps on the touch screen.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-4-bEFG_VsOM/TlClx15Rb0I/AAAAAAAAAdQ/s3nF2_5EjMY/s1600/htc_logger.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="192" src="http://1.bp.blogspot.com/-4-bEFG_VsOM/TlClx15Rb0I/AAAAAAAAAdQ/s3nF2_5EjMY/s320/htc_logger.JPG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Researchers have demonstrated that it is possible to log individual keystrokes entered on a smartphone's on-screen keyboard using device's built-in accelerometer (also known as the gyroscope). The researches were able to correlate the movements of the phone with individual keystrokes on an all-numeric keypad with an accuracy of about 70%. With minor refinements, the researchers believe they can expand the effectiveness of TouchLogger.&lt;br /&gt;
&lt;br /&gt;
Applications like these can be potentially dangerous as an application does not require special privileges to access the device's accelerometer. Major smartphones, like Apple's iPhone, RIM's Blackberry,&amp;nbsp;etc. give a user the freedom to define special permissions for applications to define their level of access. Usually within these &amp;nbsp;permissions not much importance is given to those pertaining to the device's movements.&lt;br /&gt;
&lt;br /&gt;
The developers of TouchLogger created this application for a PoC to be presented at HotSec'11, San Francisco. Presentation video available &lt;a href="http://www.usenix.org/media/events/hotsec11/tech/videos/cai.mp4"&gt;here&lt;/a&gt;&amp;nbsp;(mp4) and the paper can be downloaded from &lt;a href="http://regmedia.co.uk/2011/08/17/touchlogger_research_paper.pdf"&gt;here&lt;/a&gt;. A preliminary evaluation of the tool was done using HTC Evo 4G smartphone.&lt;br /&gt;
&lt;br /&gt;
Following table shows the distribution of inference results which are evident for the app being correct 70% of the time.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-kAKGuKKuTXE/TlClxUSP7EI/AAAAAAAAAdM/-o9Ympl3o8Q/s1600/results.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="146" src="http://2.bp.blogspot.com/-kAKGuKKuTXE/TlClxUSP7EI/AAAAAAAAAdM/-o9Ympl3o8Q/s400/results.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
The scientists noted that the W3C recently published a specification for web applications to &lt;a href="http://dev.w3.org/geo/api/spec-source-orientation"&gt;access accelerometer and gyroscope sensors using JavaScript&lt;/a&gt;. They are in the process of extending their work into a full research project.
&lt;br /&gt;
&lt;br /&gt;
A less original, but rather more effective approach is taken by Android malware called &lt;a href="http://www.cs.ncsu.edu/faculty/jiang/GingerMaster/"&gt;GingerMaster&lt;/a&gt;. It uses a root exploit called GingerBreak to permanently compromise the smartphone. According to security researcher Xuxian Jiang, GingerMaster is the first piece of malware to deploy a root exploit for Android 2.3.3 "Gingerbread". It is concealed in repackaged legitimate apps and registers a receiver which will be&lt;br /&gt;
notified when the smartphone has finished booting. Once installed, it then launches a background service.&lt;br /&gt;
&lt;br /&gt;
Subscribe to &lt;a href="http://feeds.feedburner.com/blogspot/Gotp"&gt;Techkranti feeds&lt;/a&gt;&lt;br /&gt;
To recieve updates on your mobile, &lt;a href="http://labs.google.co.in/smschannels/subscribe/techkranti"&gt;Click here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-8088540365965594738?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/DOhWxZnFlv74cvZJ_FY545YtAfg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DOhWxZnFlv74cvZJ_FY545YtAfg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/DOhWxZnFlv74cvZJ_FY545YtAfg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DOhWxZnFlv74cvZJ_FY545YtAfg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/V-lCD10tfIA" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/V-lCD10tfIA/key-logger-for-android.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-4-bEFG_VsOM/TlClx15Rb0I/AAAAAAAAAdQ/s3nF2_5EjMY/s72-c/htc_logger.JPG" height="72" width="72" /><thr:total>0</thr:total><georss:featurename>Mumbai, Maharashtra, India</georss:featurename><georss:point>19.0176147 72.8561644</georss:point><georss:box>18.7774257 72.5403074 19.2578037 73.17202139999999</georss:box><feedburner:origLink>http://www.techkranti.com/2011/08/key-logger-for-android.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-8480083426625931347</guid><pubDate>Fri, 20 May 2011 07:54:00 +0000</pubDate><atom:updated>2011-05-20T13:24:02.378+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">WiFi Hacking</category><title>WiFi Hacking Basics Part 3</title><description>So in last post we learned the basic terminology,channels and frequencies of WLAN.&lt;br /&gt;
In this post we'll see about Beacon frames and authentication in Wifi.&lt;br /&gt;
Ther are two terms you should know about wifi.&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;ESSID-Name of connection &lt;/li&gt;
&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;BSSID- MAC of AP&lt;/li&gt;
&lt;/ul&gt;There are three important packets types we need to care about &lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Management packets:Used for connection management for ex assocation request,association resonse&lt;/li&gt;
&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Data packets:there is no need to explain data packets .&lt;/li&gt;
&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Control Packets: this packets are used for effective trasmission of data for ex. CTS,RTS&lt;/li&gt;
&lt;/ul&gt;We are here concerned here with Management frames:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;b&gt;Authentication frame&lt;/b&gt;: 802.11 authentication is a process whereby      the access point either accepts or rejects the identity of a radio NIC. The      NIC begins the process by sending an authentication frame containing its identity      to the access point.  With open system authentication (the default), the radio      NIC sends only one authentication frame, and the access point responds with      an authentication frame as a response indicating acceptance (or rejection).      With the optional shared key authentication, the radio NIC sends an initial      authentication frame, and the access point responds with an authentication      frame containing challenge text. The radio NIC must send an encrypted version      of the challenge text (using its WEP key) in an authentication frame back      to the access point. The access point ensures that the radio NIC has the correct      WEP key (which is the basis for authentication) by seeing whether the challenge      text recovered after decryption is the same that was sent previously. Based      on the results of this comparison, the access point replies to the radio NIC      with an authentication frame signifying the result of authentication.  &lt;/li&gt;
&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Deauthentication frame&lt;/b&gt;: A station sends a deauthentication frame      to another station if it wishes to terminate secure communications.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Association request frame: &lt;/b&gt; 802.11 association enables the access      point to allocate resources for and synchronize with a radio NIC.  A NIC begins      the association process by sending an association request to an access point.       This frame carries information about the NIC (e.g., supported data rates)      and the SSID of the network it wishes to associate with. After receiving the      association request, the access point considers associating with the NIC,      and (if accepted) reserves memory space and establishes an association ID      for the NIC.&lt;/li&gt;
&lt;li&gt; &lt;b&gt;Association response frame&lt;/b&gt;: An access point sends an association      response frame containing an acceptance or rejection notice to the radio NIC      requesting association.  If the access point accepts the radio NIC, the frame      includes information regarding the association, such as association ID and      supported data rates. If the outcome of the association is positive, the radio      NIC can utilize the access point to communicate with other NICs on the network      and systems on the distribution (i.e., Ethernet) side of the access point.&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Disassociation frame&lt;/b&gt;:  A station sends a disassociation frame to      another station if it wishes to terminate the association.  For example, a      radio NIC that is shut down gracefully can send a disassociation frame to      alert the access point that the NIC is powering off.  The access point can      then relinquish memory allocations and remove the radio NIC from the association      table.&lt;/li&gt;
&lt;li&gt; &lt;b&gt;Beacon frame&lt;/b&gt;: The access point periodically sends a beacon frame      to announce its presence and relay information, such as timestamp, SSID, and      other parameters regarding the access point to radio NICs that are within      range. Radio NICs continually scan all 802.11 radio channels and listen to      beacons as the basis for choosing which access point is best to associate      with.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Probe request frame&lt;/b&gt;: A station sends a probe request frame when it      needs to obtain information from another station. For example, a radio NIC      would send a probe request to determine which access points are within range.&lt;/li&gt;
&lt;li&gt;P&lt;b&gt;robe response frame&lt;/b&gt;: A station will respond with a probe response      frame, containing capability information, supported data rates, etc., when      after it receives a probe request frame.&lt;/li&gt;
&lt;/ul&gt;&lt;script type="text/javascript"&gt;
 &lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt; &lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;script type="text/javascript"&gt;
 &lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt; &lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;br /&gt;
Ok lets move on to actual process.The time you switch on your wifi&amp;nbsp; how does the card knoew if there's any network?&lt;br /&gt;
In WALAN environment with multiple AP's there are frames called Beacon frames.The beacon announces the network, not the individual access point. . If the network consists of just one access point, these are one and the same. Somewhat larger wireless networks will have more than one access point with the same SSID. The beacon offers insufficient information to differentiate between multiple AP's with the same SSID&lt;br /&gt;
I assume you have just one AP,still AP will use Beacon frames to broadcast presence of networks.&lt;br /&gt;
&amp;nbsp; The client sends a null broadcast packet called 'Probe Request' to AP's in vicinity asking 'Send me connection you have'.Ap reply with Probe Response' client then send 'Authentication Request' to AP.AP respond with 'Auhentication Success'&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-qA59qyoHy-A/TdYWwJ-yjjI/AAAAAAAAAcg/mIBVEiOgARg/s1600/Probe.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="377" src="http://2.bp.blogspot.com/-qA59qyoHy-A/TdYWwJ-yjjI/AAAAAAAAAcg/mIBVEiOgARg/s400/Probe.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-0OLWhAFyREc/TdYd8noYSBI/AAAAAAAAAco/0VmbomEo4K4/s1600/capt.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="233" src="http://3.bp.blogspot.com/-0OLWhAFyREc/TdYd8noYSBI/AAAAAAAAAco/0VmbomEo4K4/s400/capt.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
There are two types of Authenticatio&lt;b&gt;n&lt;/b&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Open Authentication&lt;/li&gt;
&lt;li&gt;Shared Key Authentication&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;We'll see about this in more details in seperate post.After authentication,association phase start.Clent send 'Association Request'AP reply with 'Association Response'.&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-nP2aTmZ7IuA/TdYagDwYAYI/AAAAAAAAAck/Nfp6d2lDG0s/s1600/Asso.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="377" src="http://2.bp.blogspot.com/-nP2aTmZ7IuA/TdYagDwYAYI/AAAAAAAAAck/Nfp6d2lDG0s/s400/Asso.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&amp;nbsp;One important thing client store the SSID of networks&amp;nbsp; in a list called PML to which it has connected in past.So whenever wifi is turned on client send Probe Request for these SSID specifically.After these phases atual data communication starts.If you want more info on any of these phases check IEEE 802.11 standard.&lt;br /&gt;
&lt;script type="text/javascript"&gt;
 &lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt; &lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-8480083426625931347?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/O7-xhMGRHyzxGggg4AYp1vmp5Kw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/O7-xhMGRHyzxGggg4AYp1vmp5Kw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/O7-xhMGRHyzxGggg4AYp1vmp5Kw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/O7-xhMGRHyzxGggg4AYp1vmp5Kw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/YvOr7ybEiLk" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/YvOr7ybEiLk/wifi-hacking-basics-part-3.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-qA59qyoHy-A/TdYWwJ-yjjI/AAAAAAAAAcg/mIBVEiOgARg/s72-c/Probe.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2011/05/wifi-hacking-basics-part-3.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-8081345819035346351</guid><pubDate>Wed, 18 May 2011 18:04:00 +0000</pubDate><atom:updated>2011-05-19T10:43:39.275+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Hacking Tools</category><category domain="http://www.blogger.com/atom/ns#">Security News</category><category domain="http://www.blogger.com/atom/ns#">Hacking News</category><category domain="http://www.blogger.com/atom/ns#">Ethical Hacking</category><category domain="http://www.blogger.com/atom/ns#">android</category><category domain="http://www.blogger.com/atom/ns#">Exploits</category><category domain="http://www.blogger.com/atom/ns#">All about Google</category><title>Vulnerability in Android has put 99% android handsets at Risk</title><description>This risk pertains to using your Android to connect to Facebook, Twitter and some Google services over unencrypted wireless networks. The apps for this services communicate over clear text which can intercepted by an eavesdropper. Google services which are vulnerable to eavesdropping are Google Calendar and Google Contacts. The attack is possible to all Google services using the ClientLogin authentication protocol for access to its data APIs.&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-N5Mbq_cMejs/TdQJjGBccuI/AAAAAAAAAcY/UFxSickDmig/s1600/Google-Android-Logo.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://1.bp.blogspot.com/-N5Mbq_cMejs/TdQJjGBccuI/AAAAAAAAAcY/UFxSickDmig/s200/Google-Android-Logo.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;a href="http://code.google.com/apis/accounts/docs/AuthForInstalledApps.html"&gt;ClientLogin&lt;/a&gt; is meant to be used for authentication by installed applications and Android apps. Basically, to use ClientLogin, an application needs to request an authentication token (authToken) from the Google service by passing an account name and password via a https connection. The returned authToken can be used for any subsequent request to the service API and is valid for a maximum duration of 2 weeks. However, if this authToken is used in requests send over unencrypted http, an adversary can easily sniff the authToken (e.g. with Wireshark, see screenshot below). Because the authToken is not bound to any session or device specific information the adversary  can subsequently use the captured authToken to access any personal data which is made available through the service API. For instance, the adversary can gain full access to the calendar, contacts information, or private web albums of the respective Google user. This means that the adversary can view, modify or delete any contacts, calendar events, or private pictures.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
What can the attacker do? &lt;br /&gt;
The attack is similar to session stealing(Sidejacking). It is similar to what FireSheep had done.&lt;br /&gt;
The attacker can setup a rogue access point and get the victims to connect through his access point. The attacker can then attempt to impersonate the users and modify the information stored in their accounts.&lt;br /&gt;
&lt;br /&gt;
Google has released a patch to solve the ClientLogin protocol problem,  but the patch only works for Android 2.3.4 and Android 3.0, meaning that  about 99 percent of Android phones don’t have access to the updated  code !!!!&lt;br /&gt;
Courtesy: Ashish Kumar&lt;br /&gt;
&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt; &lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-8081345819035346351?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/OGt0wc2Wm8LdF4BDySdoGEtqPj4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/OGt0wc2Wm8LdF4BDySdoGEtqPj4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/OGt0wc2Wm8LdF4BDySdoGEtqPj4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/OGt0wc2Wm8LdF4BDySdoGEtqPj4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/FhzSFjCiKFY" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/FhzSFjCiKFY/vulnerability-in-android-has-put-99.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-N5Mbq_cMejs/TdQJjGBccuI/AAAAAAAAAcY/UFxSickDmig/s72-c/Google-Android-Logo.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2011/05/vulnerability-in-android-has-put-99.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-5748802395713052576</guid><pubDate>Wed, 18 May 2011 08:02:00 +0000</pubDate><atom:updated>2011-05-18T13:32:57.238+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">WiFi Hacking</category><title>WiFi Hacking Basics Part 2</title><description>In last post we saw how to setup and capture traffic on moniter mode.Second part of the series is about wifi bands channels.&lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;br /&gt;
Noarmally Wifi operate in radio frequency range of 2.4Ghz.This 2.4 Ghz band is divided in channels like 1,2,3.... upto 14.Most important thing any wireless card can be on only one channel at a time because there is only one radio present in each card.&lt;br /&gt;
There are following 802.11 standards in Wireless LAN&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;802.11a : operating frequency 5Ghz&lt;/li&gt;
&lt;li&gt;802.11b : operating frequency 2.4 Ghz&lt;/li&gt;
&lt;li&gt;802.11g :&amp;nbsp;operating frequency 2.4 Ghz&lt;/li&gt;
&lt;li&gt;802.11n :&amp;nbsp;operating frequency 2.4 Ghz&lt;/li&gt;
&lt;/ul&gt;This are standard specified on AP and WLAN card.AP with 802.11a can support and create network of 802.11a and so on.WLAN card need hardware support to operate in different channels.&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-3VIhvkbYI_o/TdN4_4Wb0QI/AAAAAAAAAcU/r5sbyVKPHW8/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-3VIhvkbYI_o/TdN4_4Wb0QI/AAAAAAAAAcU/r5sbyVKPHW8/s400/2.png" width="388" /&gt;&lt;/a&gt;&lt;/div&gt;Source:Wikipedia&lt;br /&gt;
In table above you can see various channels along with frequencies.&lt;span class="Apple-style-span" style="line-height: 19px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Countries apply their own regulations to both the allowable channels, allowed users and maximum power levels within these frequency ranges.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="line-height: 19px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;This was theory lets try some demo..&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="line-height: 19px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;So how to put a WLAN card on a specific channel ?First verify the current status by command&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="line-height: 19px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;i&gt;#iwconfig wlan0&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="line-height: 19px;"&gt;To put card on say channel 1 use following command..&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="line-height: 19px;"&gt;&lt;i&gt;#&lt;/i&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 19px;"&gt;&lt;i&gt;iwconfig wlan0 channel 1&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="line-height: 19px;"&gt;Now you put card on channel 1 so wlan card can now sniff traffic on ch 1.Same can be done for &amp;nbsp;802.11 b/g band but you we need to use a tool Airodump-ng.So your card suport 802.11b/g and you want to toggle between these bands use following simple command&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="line-height: 19px;"&gt;&lt;i&gt;#airodump-ng --band &amp;nbsp;{band }&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="line-height: 19px;"&gt;for ex.&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 19px;"&gt;&lt;i&gt;#airodump-ng --band &amp;nbsp;g&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="line-height: 19px;"&gt;In next post we will cover some terminology of Wifi world and its meaning ..&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-5748802395713052576?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ddCZJsKtvLuzslZM1KB-AM5mTnw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ddCZJsKtvLuzslZM1KB-AM5mTnw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ddCZJsKtvLuzslZM1KB-AM5mTnw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ddCZJsKtvLuzslZM1KB-AM5mTnw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/hfwAtbNj4TY" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/hfwAtbNj4TY/wifi-hacking-basics-part-2.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-3VIhvkbYI_o/TdN4_4Wb0QI/AAAAAAAAAcU/r5sbyVKPHW8/s72-c/2.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2011/05/wifi-hacking-basics-part-2.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-3592811416449677071</guid><pubDate>Tue, 17 May 2011 18:58:00 +0000</pubDate><atom:updated>2011-05-18T00:28:17.538+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Website Hacking</category><category domain="http://www.blogger.com/atom/ns#">Facebook</category><category domain="http://www.blogger.com/atom/ns#">Security News</category><category domain="http://www.blogger.com/atom/ns#">Ethical Hacking</category><category domain="http://www.blogger.com/atom/ns#">Exploits</category><title>'Enable Dislike Button' scam on Facebook</title><description>Whenever I hated a status message or a shared link on Facebook, I said to myself - "I wish this thing had a dislike button to express my distress".. This must have come to your mind also, specially after disliking some video on Youtube. Well this urge of disliking posts on FB is what hackers are targetting next.. So beware!!! A quick overview of how the hackers get you to click on the link follows:&lt;br /&gt;
&lt;br /&gt;
Following is a screenshot of how the message would be posted on your wall..&lt;br /&gt;
&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-w7DoveQizG0/TdLBaOPTwSI/AAAAAAAAAcM/_pZUmYxSjcs/s1600/fb-dislike-button.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="85" j8="true" src="http://1.bp.blogspot.com/-w7DoveQizG0/TdLBaOPTwSI/AAAAAAAAAcM/_pZUmYxSjcs/s400/fb-dislike-button.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Pay close attention to the 'Enable Dislike Button' link besides the 'Comment' in place of the usual share link. The hackers have done so to fool users in believing it to be a Genuine feature added by FB. &lt;strong&gt;There is no official dislike button on FB.&lt;/strong&gt; &lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Clicking on the link will cause same consequences whcih you might have experienced with the WTF video or Check who is visiting your profile link. The link will be posted on walls of random friends and the cycle will continue. It is believed that the link contains obfuscated javascript which is used by spamsters to study browsing behavior. &lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Another example relating to the Dislike Button:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-pElMnhc0icE/TdLD3fCWV5I/AAAAAAAAAcQ/BaPM38pd0wE/s1600/dislike-button-address-bar.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" j8="true" src="http://4.bp.blogspot.com/-pElMnhc0icE/TdLD3fCWV5I/AAAAAAAAAcQ/BaPM38pd0wE/s400/dislike-button-address-bar.jpg" width="372" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;This link tricks you into pasting a javascript to your browser. *Not at all recommended. &lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Repeating Again - "FB does not provide a Dislike feature"&lt;/div&gt;&lt;br /&gt;
&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt;&lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-3592811416449677071?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ZFWlcAWQCTWtxdQ1BA4uOmECyLY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZFWlcAWQCTWtxdQ1BA4uOmECyLY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ZFWlcAWQCTWtxdQ1BA4uOmECyLY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZFWlcAWQCTWtxdQ1BA4uOmECyLY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/Lin2mE6RHRg" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/Lin2mE6RHRg/enable-dislike-button-scam-on-facebook.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-w7DoveQizG0/TdLBaOPTwSI/AAAAAAAAAcM/_pZUmYxSjcs/s72-c/fb-dislike-button.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2011/05/enable-dislike-button-scam-on-facebook.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-7204450563075638121</guid><pubDate>Sun, 15 May 2011 17:20:00 +0000</pubDate><atom:updated>2011-05-15T22:52:17.556+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">WiFi Hacking</category><title>How To Setup a Wi-Fi Hotspot</title><description>Creating a Wi-Fi Internet hotspot service from scratch can seem like a  daunting task. I had many sleepless nights trying to get to grips with  FreeRadius, DD-WRT, Chillispot etc. I hope that this How To helps you to  avoid some of the problems I encountered along the way.&lt;br /&gt;
&lt;br /&gt;
&lt;div align="center"&gt;&lt;br /&gt;
********Warning ********&lt;/div&gt;Following  these instructions may invalidate your Linksys warranty. You do so at  your own risk. These instructions assume that you have an understanding  of Linux, PHP MySQL and Apache. If you brick your AP you might get it  back by holding down the reset pin for 20 seconds, unplug the power  while still holding down the reset button for another 20 seconds and  then plugging the power back in while still keeping the reset button  held in for a further 20 seconds. This should bring it back to the  defaults of whatever firmware you have installed. You should be able to  login to 192.168.1.1&lt;br /&gt;
&lt;div align="center"&gt;*******End of Warning********&lt;/div&gt;Feel free to copy or use this information in any way you like.&lt;br /&gt;
&lt;br /&gt;
What you will need:-&lt;br /&gt;
&lt;br /&gt;
a) DD-WRT&lt;br /&gt;
Download the latest version here &lt;a href="http://brainslayer.braincontrol.org/dd-wrt.v22.zip"&gt;http://dd-wrt.com&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
b) FreeRadius&lt;br /&gt;
Download the latest version here &lt;a href="http://www.howtoforge.com/http:freeradius.org" target="_self"&gt;http://freeradius.org/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
c) phpMyPrepaid&lt;br /&gt;
Download the latest version here &lt;a href="http://jabali.net/%7Ecarl/phpMyPrepaid.0.1.3RC2.tar"&gt;http://sourceforge.net&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
d) Linsys WRT54GL AP&lt;br /&gt;
&lt;br /&gt;
e)  You will also need PHP, Apache, MySQL amd MySql Delopment  Modules,(These need to be setup first.) some patience, plenty of coffee  and cigarettes.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 &lt;/b&gt;: DD-WRT/Chillispot Configuration&lt;br /&gt;
&lt;br /&gt;
Configure  the WRT-54G with the standard Linksys software and the use the upgrade  firmware module to install the dd-wrt package on the AP.&lt;br /&gt;
*******IMPORTANT******* Use your cable connection to do the upgrade. NOT the wireless connection.&lt;br /&gt;
Reboot the AP and login to your new firmare.&lt;br /&gt;
Set Dynamic configuration DHCP&lt;br /&gt;
Disable DHCP (Chillispot will manage DHCP for your clients.)&lt;br /&gt;
Change the Local IP of the AP to 192.168.10.1.&lt;br /&gt;
Set your gateway and DNS addresses.&lt;br /&gt;
Update changes and log back in to the new IP address.&lt;br /&gt;
&lt;br /&gt;
Go to the administration page.&lt;br /&gt;
Enable Chillispot&lt;br /&gt;
Enter the IP address of your Radius server.&lt;br /&gt;
Enter the DNS.&lt;br /&gt;
Enter the redirect URL eg HTTPS://123.123.123.123/cgi-bin/hotspotlogin.cgi/ (MAke sure that the address ends in / and is https.)&lt;br /&gt;
Enter a shared key. (This can be anything you like, but keep a note of it you will need it later.)&lt;br /&gt;
Set DHCP Interface to Lan+Wlan&lt;br /&gt;
Enter a NAS id (Your name for your AP)&lt;br /&gt;
Enter a UAM secret (This is the password that Chilli will use to talk to hotspotlogin.cgi)&lt;br /&gt;
Save your settings and reboot the AP. Please give the AP about 10 minutes to reboot and initialise all the new services.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2&lt;/b&gt;: FreeRadius Configuration.&lt;br /&gt;
&lt;br /&gt;
Untar the FreeRadius tar file and enter its directory. &lt;br /&gt;
Type ./configure --with-experimental-modules&lt;br /&gt;
make&lt;br /&gt;
login as root and type make install&lt;br /&gt;
When this is finished copy the radiusd.conf file that you downloaded earlier to /usr/local/etc/raddb/&lt;br /&gt;
You should not need to edit radiusd.conf&lt;br /&gt;
Edit /usr/local/etc/raddb/sql.conf and in the SQL section make these changes.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
# Database type&lt;br /&gt;
# Current supported are: rlm_sql_mysql, rlm_sql_postgresql,&lt;br /&gt;
# rlm_sql_iodbc, rlm_sql_oracle, rlm_sql_unixodbc, rlm_sql_freetds&lt;br /&gt;
driver = "rlm_sql_mysql"&lt;br /&gt;
&lt;br /&gt;
# Connect info&lt;br /&gt;
&lt;br /&gt;
server = "localhost"&lt;br /&gt;
&lt;br /&gt;
login = "yourlogin"&lt;br /&gt;
&lt;br /&gt;
password = "your password"&lt;br /&gt;
&lt;br /&gt;
# Database table configuration&lt;br /&gt;
radius_db = "radius"&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Edit the /usr/local/etc/raddb/clients.conf file and enter the details of your NAS (AP)&lt;br /&gt;
&lt;br /&gt;
client xxx.xxx.xxx.xxx { (This is the address of your NAS or WRT54G )&lt;br /&gt;
secret = xxxxxxx (The secret you entered in the Chilli Config)&lt;br /&gt;
shortname = private-network-9 (This can be any name)&lt;br /&gt;
nastype = other&lt;br /&gt;
( If you want to set up several AP's with one secret the IP address above should be 0.0.0.0/0 )&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3&lt;/b&gt; : hotspotlogin.cgi&lt;br /&gt;
Copy hotspotlogin.cgi from &lt;a href="http://chillispot.org%20to%20/var/www/cgi-bin"&gt;http://chillispot.org to /var/www/cgi-bin&lt;/a&gt;&lt;br /&gt;
Edit the file and change the secret to the UAM secret that you entered in the Chillispot configuration on the WRT54G.&lt;br /&gt;
&lt;br /&gt;
ou can also use a php script. It is not as secure as the cgi script  but easier to personalise. If you want a copy  email me at  sean@swarmhotspots.com&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4&lt;/b&gt; : phpMyPrepaid and MySQL&lt;br /&gt;
&lt;br /&gt;
Extract the phpMyPrepaid file to a directory on your webserver eg /var/www/html/myprepaid&lt;br /&gt;
Create  a MySQL database called radius and create a user and password for it.  Use a script called db_mysql.db that you will find in the phpMyPrepaid  download to create the database tables.&lt;br /&gt;
Edit the dbconnect.php file  in the phpMyPrepaid directory and enter the username and password for  your MySQL radius database. IMPORTANT Save this file behind your web  directory or your passwords will be easy to hack.&lt;br /&gt;
Edit config.inc.php and change the line that points to dbconnect to wherever you have saved dbconnect.php&lt;br /&gt;
In  your web browser got to http://yoursite.com/whereveryouputphpmyprepaid/  and create some tickets. Check your database to see if the users have  been setup in radcheck. Launch FreeRadius as root with this command  radiusd -xxyx -l stdout. Pick a user and password from your database and  try to login from a wireless client. If you can then it is time for  step 5. If not go back to step 1 and check everything.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step  5&lt;/b&gt; : Have a cup of coffee and unwind. If all is well you have finished.  I'll keep an eye on this post and do my best to help anyone with  problems.&lt;br /&gt;
I have setup a free Radius test area for people that  have no access to a Radius server. You can use this service to test your  Chillispot configuration. The address is &lt;a href="http://swarmhotspots.com/Chilli-Test-Area"&gt;http://swarmhotspots.com/Chilli-Test-Area&lt;/a&gt;&lt;br /&gt;
&amp;nbsp;Source:Howtoforge.com&lt;br /&gt;
&lt;script type="text/javascript"&gt;
 &lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt; &lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-7204450563075638121?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/yraZ_qTooHXxA23YPvxjTN-jIj8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/yraZ_qTooHXxA23YPvxjTN-jIj8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/yraZ_qTooHXxA23YPvxjTN-jIj8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/yraZ_qTooHXxA23YPvxjTN-jIj8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/F-i7yB2xc8E" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/F-i7yB2xc8E/creating-wi-fi-internet-hotspot-service.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2011/05/creating-wi-fi-internet-hotspot-service.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-7466360541408000655</guid><pubDate>Sun, 15 May 2011 17:10:00 +0000</pubDate><atom:updated>2011-05-15T22:46:38.910+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">WiFi Hacking</category><title>WiFi Hacking Basics Part 1</title><description>If your are reading this you must have used WiFi atleast once or may be you have your own WiFi network at home.Wifi is cool and hacking wifi is a lot&amp;nbsp; more interesting.Here i am gonna tell you the basics of Wireless Network and how it is hacked so that you get a grasp of what is going on with your Wifi.&lt;br /&gt;
I am using a informal term for Wireless Network as Wifi because its more familiar to public.My aim would be to show how Wifi is hacked.You can try yourself this attacks for this&lt;br /&gt;
What will you need ,&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Laptop with Backtrack installed or Backtrack in VM &lt;/li&gt;
&lt;li&gt;Access Point(AP)&lt;/li&gt;
&lt;li&gt;USB WiFi Adapter Card which support packet injection(I recommend Alpha Card)&lt;/li&gt;
&lt;li&gt;A Smartphone or another laptop with Wifi (as a Victim)&lt;/li&gt;
&lt;/ul&gt;For those who don't know Backtrack,its a Pentest Linux Distro with all tools necessary.Access point can be any SOHO wifi router.USB Wifi Adapter is for packet injection because normal Laptop wifi card chiset don't support Packet Injection.&lt;br /&gt;
So lets get started with basics or theory.&lt;br /&gt;
Normally your wifi card sniff all wireless network around it but only accepts packets destined to it if its connected to it at all. AP (Access Point) is broadcasting networks SSIDs all the time.SSID means name given to wireless network.This network can be open or closed.Open network don't require any authentication on the other hand closed network require a shared key to connect to it.More on closed network in later posts.&lt;br /&gt;
So how to sniff which which network are there?&lt;br /&gt;
For this we use a tool in Backtrack called Aircrack-ng suite.To sniff the packets we create a virtual interface called Moniter Mode Interface (mon 0).Mon 0 is created on top wireless interface on your laptop,say wlan 0.&lt;br /&gt;
First task would be to create Mon 0.&lt;br /&gt;
Goto backtrack open terminal type &lt;i&gt;airmon-ng start wlan0&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
now mon0 is created, to verify it type in terminal &lt;i&gt;ifconfig&amp;nbsp; &lt;/i&gt;you will notice mon0 interface and MAC address same as your wifi card.&lt;br /&gt;
Now there is another tool we are going to use to see actual packets Wireshark.Next step fire&amp;nbsp; up Wireshark by typing &lt;i&gt;wireshark &amp;amp;&lt;/i&gt; on&amp;nbsp; terminal.You will see in interface mon0 listed start capture on mon0.&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-kJbjG4BHHEs/TdAFLEHVRaI/AAAAAAAAAcI/irpkXyxhw8Q/s1600/mon0.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="280" src="http://2.bp.blogspot.com/-kJbjG4BHHEs/TdAFLEHVRaI/AAAAAAAAAcI/irpkXyxhw8Q/s400/mon0.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
then you will see lots of packets if there is any wifi connection&amp;nbsp; in your vicinity,if you dont see&amp;nbsp; any traffic create a network using your AP and check the SSIDs.&lt;br /&gt;
What we learned : &lt;b&gt;How to create mon0 and sniff traffic&lt;/b&gt;. &lt;br /&gt;
Contd.. part 2&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-7466360541408000655?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/iRFIgYG30iSaxh1W2BlQ2E22Atw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iRFIgYG30iSaxh1W2BlQ2E22Atw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/iRFIgYG30iSaxh1W2BlQ2E22Atw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iRFIgYG30iSaxh1W2BlQ2E22Atw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/FCuVs2yqQG8" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/FCuVs2yqQG8/wifi-hacking-basics-part-1.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-kJbjG4BHHEs/TdAFLEHVRaI/AAAAAAAAAcI/irpkXyxhw8Q/s72-c/mon0.png" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.techkranti.com/2011/05/wifi-hacking-basics-part-1.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-4806211965138793863</guid><pubDate>Tue, 26 Apr 2011 05:51:00 +0000</pubDate><atom:updated>2011-04-26T22:21:07.794+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Viruses</category><category domain="http://www.blogger.com/atom/ns#">Security News</category><category domain="http://www.blogger.com/atom/ns#">Hacking News</category><title>Iran is getting paranoid over new cyber-attack 'Stars'</title><description>&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;After discovering an attack on its SCADA systems willing to take down their nuclear facility, Iran is probably getting paranoid over the whole malware cosmos. It seems that every other abnormal behavior on Iran's critical facility is viewed by them as an attack or a threat to their nuclear reactors. Yesterday Iran's Mehr News Agency reported that the country is under a new kind of cyber attack after Stuxnet, know as 'Stars'. Iran does not yet have complete information what adverse effects of this new so called 'Cyber Attack' is having on its systems.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;Excerpts from Mehr's report:&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;span class="news_body" id="Newsdetails2_lblBody"&gt;“(However),  certain characteristics about the Stars worm have been identified,  including that it is compatible with the (targeted) system and that the  damage is very slight in the initial stage, and it is likely to be  mistaken for executable files of the government,” &lt;/span&gt;Senior Iranian lawmaker &lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span class="news_body" id="Newsdetails2_lblBody"&gt;Jalali stated.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;span class="news_body" id="Newsdetails2_lblBody"&gt;&amp;nbsp;It is not very sure from the official's statement, which operating system is being targeted by Stars. We have to wait for any official announcements from Iran's cyber experts before we or they reach a conclusion of Stars being a reality or is it just a hoax arising out of concern.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span class="news_body" id="Newsdetails2_lblBody"&gt;&lt;a name='more'&gt;&lt;/a&gt; &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;script type="text/javascript"&gt;
 &lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt; &lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span class="news_body" id="Newsdetails2_lblBody" style="font-size: small;"&gt;Elsewhere  in his remarks, Jalali said that although the United States and Israel  have flouted international law in their cyber attacks against Iran, this  matter can still be pursued through legal channels. He also stated that Siemens, the supplier of SCADA systems used by Iran's facilities, should be held responsible for Stuxnet.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span class="news_body" id="Newsdetails2_lblBody" style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span class="news_body" id="Newsdetails2_lblBody" style="font-size: small;"&gt;Well Siemens might not be fully responsible, but partially yes. How can one even think of using an OS like Windows which is constantly under new attacks, no matter which AV you install on it, for administration of such critical systems. Windows is liked by all for its user-friendliness and as a way of attracting more clients Siemens had introduced Windows compatible application for administration of its SCADA systems which had a drastic consequence as it was targeted by Stuxnet.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-4806211965138793863?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/1zb9OKSGYYL38v09jK5WcKSqPgQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1zb9OKSGYYL38v09jK5WcKSqPgQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/1zb9OKSGYYL38v09jK5WcKSqPgQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1zb9OKSGYYL38v09jK5WcKSqPgQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/vJakNtsMZSs" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/vJakNtsMZSs/iran-is-getting-paranoid-over-new-cyber.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2011/04/iran-is-getting-paranoid-over-new-cyber.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-69917505514684173</guid><pubDate>Fri, 11 Mar 2011 18:14:00 +0000</pubDate><atom:updated>2011-03-11T23:44:43.651+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Miscellaneous</category><title>It is indeed "A Little World"</title><description>I would like to share my views or rather I should say my feelings for a beautiful technology I have encountered lately. What is Information Technology? This question always irritated me in college although I was doing my engineering from the same stream. To this question, the answer that I found, according to my view is: "Information Technology is the APPLICATION of computer systems or computer science in various fields". Application- Yes, that's the word. It is not the sophistication of the technology that matters, it is its application. A few months earlier I had posted about the &lt;a href="http://www.techkranti.com/2009/12/sixth-sense-technology-by-indian.html"&gt;Sixth Sense Technology&lt;/a&gt;. Almost an year after Sixth Sense, this is something that really moved me.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh5.googleusercontent.com/-T1vigH-rncQ/TXpmOUHpKlI/AAAAAAAAAcE/g2mnGD6q0LQ/s1600/alw_pic.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://lh5.googleusercontent.com/-T1vigH-rncQ/TXpmOUHpKlI/AAAAAAAAAcE/g2mnGD6q0LQ/s1600/alw_pic.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Well not wasting much of your time, I should come straight to the point. It is about an organization I visited a week back. The name of the organization is exactly how I am feeling while writing this - It is indeed "A Little World" . I'll try to explain here how it functions.&lt;br /&gt;
&lt;br /&gt;
The objective of the organization is to expand banking services to the remote villages of India where the average daily income of a person is not more than a few hundred rupees. In finance terms, it is called "Financial Inclusion". Here's how they work:-&lt;br /&gt;
&lt;br /&gt;
First, ALW("A Little World") gets into an agreement with some bank which allows ALW to open accounts and provide a way for transacting funds to the remote villagers.&lt;br /&gt;
&lt;br /&gt;
Once into an agreement, ALW appoints willing representatives from remote villages who are given a self-employment opportunity. These representatives are called "Customer Service Points" or "Customer Service Providers"(ALW, correct me if I am wrong). These CSPs are provided a CSP kit which contains a Nokia Mobile Phone with a Camera and NFC and bluetooth technology and a fingerprint reading and receipt printing equipment.&lt;br /&gt;
&lt;br /&gt;
Now if a villager wants to open an account with the CSP, he approaches the CSP for the same. The joining customer fills up a form and chooses to one of the following forms of identification means:&lt;br /&gt;
1. The Joining Form itself&lt;br /&gt;
2. A ID card bearing a Barcode or&lt;br /&gt;
3. An NFC which stores all customer data in eletronic format&lt;br /&gt;
&lt;br /&gt;
After filling the form, as a means of authentication, fingerprints of six different fingers are scanned and stored in the customer database using the equipment(:( My bank does not provide Biometric authentication ). Finally a picture of the customer is taken using the provided mobile phone. All this data is then transferred over GPRS immediately or at the end of the day to ALW customer database, which is then used to create an account with the bank.&lt;br /&gt;
&lt;br /&gt;
The bank then provides ALW with the account numbers of the enrolled accounts. ALW then creates the identification means for the customer i.e. Barcode Card or NFC card which are sent to the corresponding CSP for the customer.&lt;br /&gt;
&lt;br /&gt;
This was about enrollment. Now let us see how a transaction takes place. The minimum transaction amount for customers with ALW is Rs. 10 and maximum is Rs. 10000. Not too small, not too large for a villager. We are going look at the transaction with NFC card(It is very interesting). If a farmer needs to deposit Rs. 100 to his account, he visits the CSP with his card. To identify the customer, CSP uses the phone which has a custom built application to read the data from the NFC card. The card is read by placing it close to the mobile phone. Once the customer is identified, CSP enters the amount to be deposited, accepts the payment and prints the receipt from the equipment. The communication between the equipment and mobile phone is done over Bluetooth. &lt;br /&gt;
&lt;br /&gt;
While withdrawing an amount, Biometric authentication is done. ALW has constant communication with the bank it holds account to sync the transactions. What less does the CSP provide than a bank branch? Safe, Secure and easily accessible banking is all that we require and yes, ALW is providing it. When a demonstration of this was given to me, it really moved me. It was then when I felt the name of the organization really suits its purpose.&lt;br /&gt;
&lt;br /&gt;
I wish "A Little World" all the very best for their future plans and hope that RBI also blesses them with decent subsidies for their betterment.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-69917505514684173?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/gxf7f1oXYru4KsZfXUqEZpesdjQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gxf7f1oXYru4KsZfXUqEZpesdjQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/gxf7f1oXYru4KsZfXUqEZpesdjQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gxf7f1oXYru4KsZfXUqEZpesdjQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/nLpJoNkfF1I" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/nLpJoNkfF1I/it-is-indeed-little-world.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://lh5.googleusercontent.com/-T1vigH-rncQ/TXpmOUHpKlI/AAAAAAAAAcE/g2mnGD6q0LQ/s72-c/alw_pic.jpg" height="72" width="72" /><thr:total>0</thr:total><georss:featurename>Mumbai, Maharashtra, India</georss:featurename><georss:point>19.0176147 72.8561644</georss:point><georss:box>18.6930332 72.3892454 19.3421962 73.3230834</georss:box><feedburner:origLink>http://www.techkranti.com/2011/03/it-is-indeed-little-world.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-2378466117525163400</guid><pubDate>Fri, 17 Dec 2010 07:04:00 +0000</pubDate><atom:updated>2010-12-17T12:37:25.778+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security Tools</category><category domain="http://www.blogger.com/atom/ns#">Desktop Security</category><category domain="http://www.blogger.com/atom/ns#">Security News</category><title>How to combine multiple GFI scans into a single report</title><description>One of TechKranti's regular readers Vinesh Redkar from Mumbai, India requested us to solve a problem he was facing while using GFI Languard. Here's what his query is:&lt;br /&gt;
&lt;div style="background-color: #9fc5e8;"&gt;"My compoany has recently bought GFI Languard for scanning the network for vulnerabilities and missing patches. I scanned 25 computers in my office network individually each time entering the credentials for the respective machine. Now I need a statistical report mentioning the percentage of High security vulnerabilities, missing patches and so on. How can I combine the results so that all of them depict one single scan."&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Kic0h6eqy-A/TQsMGZ2jtBI/AAAAAAAAAb0/GWi2pbkP4Bc/s1600/LAN-Box-145-151.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_Kic0h6eqy-A/TQsMGZ2jtBI/AAAAAAAAAb0/GWi2pbkP4Bc/s1600/LAN-Box-145-151.png" /&gt;&lt;/a&gt;&lt;/div&gt;Hey Vinesh, we are happy you raised this query. We are glad to attend to it. Here's the solution to your problem-&lt;br /&gt;
First of all, for those who have not used GFI Languard ever, lemme tell you that GFI Languard is not any usual port scanning software like nmap. GFI is mostly liked by security admins as it is the perfect tool for performing a security audit of a network without actually having to hire a security consultant. GFI is actually a proprietary tool, but it's trial version is available.&lt;br /&gt;
&lt;br /&gt;
So while scanning a machine using GFI Languard, you need to enter the administrator credentials for that machine as it facilitates the tool to go deep inside the OS to find missing patches and vulnerabilities. It also detects unsecured settings configured on the system, status of your antivirus software and application vulnerabilities too.&lt;br /&gt;
&lt;br /&gt;
You can save GFI scans in XML format. This is the format which will help us combining the results to one aggregate. If you have not saved the scans in XML format after scanning, you can still do it by loading the scan form GFI database(Ctrl+O) and then doing a save operation(Ctrl+S). Following is the structure of a GFI XML result.&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
&amp;lt;Scan&amp;gt;&lt;br /&gt;
&amp;lt;hosts&amp;gt;&lt;br /&gt;
&amp;lt;host&amp;gt; &lt;br /&gt;
&amp;lt;/host&amp;gt;&lt;br /&gt;
&amp;lt;/hosts&amp;gt;&lt;br /&gt;
&amp;lt;/Scan&amp;gt;&lt;br /&gt;
&lt;br /&gt;
There are many more nodes within the host node, but we are not interested in it. GFI Languard is there to interpret it for us. So each &lt;u&gt;Scan&lt;/u&gt; root node has a &lt;u&gt;hosts&lt;/u&gt; child node node, which has many &lt;u&gt;host&lt;/u&gt; child nodes. The &lt;u&gt;host&lt;/u&gt; node contains all the information about the scan for a specific host. If you understood this all you need is simply a copy and paste job. Well you can edit these XML files using notepad.&lt;br /&gt;
&lt;br /&gt;
Make a copy of any XML result file in which you will be saving the final result. This is your master file. Now find the &amp;lt;/host&amp;gt; tag in the file. This is the end of your result for one particular host. If the master file you have selected contains multiple hosts, find the last occurrence of &amp;lt;/host&amp;gt; tag. Now open the other scans one by one which you want to integrate in the final result. Copy the text from &amp;lt;host&amp;gt; to &amp;lt;/host&amp;gt; which actually contains the result of your scan and paste it after the last occurrence of &amp;lt;/host&amp;gt; tag in the master file. Do this for all the individual scans and save the master file. You can open the saved master file in Firefox to confirm if it's error free. You think it's done?? Well, almost.&lt;br /&gt;
&lt;br /&gt;
Here's the catch. Even after doing this when you open the final result in GFI on the same PC from which you had run the scans it will only show the scans that were originally present in our master file. If it has ever happened to you, and you have been wondering why doesn't it work here's the solution.&lt;br /&gt;
&lt;br /&gt;
GFI languard stores all it's scan results in one MS Access database file(.mdb) It is less time consuming for GFI to extract the scan results from the Access file than it is to extract it from an XML file. To lower the computation required while loading an XML scan result, GFI keeps track of scans using a session ID. This session id can be found in the attributes of the &amp;lt;Scan&amp;gt; root node. Here's what it looks like(highlighted):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;Scan UIScan="" Session="&lt;span style="background-color: red;"&gt;145244609&lt;/span&gt;" Profile="Full Scan" CreatedOn="11/26/2010 02:52:46 PM" ReadOnly="0" ScansEnded=" 1" profilesenabled=" 1" ScanDuration=" 61" ScheduledScan=" 0" ScannedItemsCount=" 1642" AutoremediationEnabled_MissingPatches=" 0" AutoremediationEnabled_MissingServicePacks=" 0" AutoremediationEnabled_UninstallApplications=" 0"&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When you create the master file and paste all the scans into the XML file and try to load the file, GFI first looks for the Session attribute, to determine if the scan exists in its database. So the solution to your problem is simple. Just change the Session attribute to anything you like and you are done. GFI will treat this as one single scan, and you can create aggregated reports for presenting to your management.&lt;br /&gt;
&lt;br /&gt;
I hope that solves your problem Vinesh. Keep&amp;nbsp; writing in. We would be glad to address your problems. Hey readers, if you too are looking for solutions to some problems feels free to post your queries to &lt;b&gt;amey [at] techkranti [dot] com &lt;/b&gt;and we would be happy to help you.&lt;br /&gt;
&lt;br /&gt;
&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt; &lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="background-color: #fff2cc;"&gt;Get Security Tips n Tricks on your mobile.&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to &lt;a href="http://labs.google.co.in/smschannels/subscribe/techkranti" style="font-family: Arial,Helvetica,sans-serif;"&gt;TechKranti's   SMS channel&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to TechKranti's feeds &lt;a href="http://feeds.feedburner.com/blogspot/Gotp"&gt;&lt;img height="30" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/S4ys7B1W7QI/AAAAAAAAAS8/7ituXPkPyNc/s1600/128px-Feed-icon.svg.png" width="30" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-2378466117525163400?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/wgLyi6eujeP0HumebACtggpHqwU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/wgLyi6eujeP0HumebACtggpHqwU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/wgLyi6eujeP0HumebACtggpHqwU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/wgLyi6eujeP0HumebACtggpHqwU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/EYZuHvaq7cc" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/EYZuHvaq7cc/how-to-combine-multiple-gfi-scans-into.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_Kic0h6eqy-A/TQsMGZ2jtBI/AAAAAAAAAb0/GWi2pbkP4Bc/s72-c/LAN-Box-145-151.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2010/12/how-to-combine-multiple-gfi-scans-into.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-5700474940707367934</guid><pubDate>Sun, 12 Dec 2010 11:03:00 +0000</pubDate><atom:updated>2010-12-12T16:35:27.027+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security Tools</category><category domain="http://www.blogger.com/atom/ns#">Desktop Security</category><category domain="http://www.blogger.com/atom/ns#">Security News</category><category domain="http://www.blogger.com/atom/ns#">Hacking News</category><category domain="http://www.blogger.com/atom/ns#">Exploits</category><title>Nuisance of the Conficker Worm</title><description>An year back, we had posted about the nuisance of the Conficker Worm in &lt;a href="http://www.techkranti.com/2009/10/conflicker-c-worm.html"&gt;THIS POST&lt;/a&gt;. An year later, my colleague Mr. Gaurav Benjamin had a live experience with the havoc Conficker can create. Here is his experience in his own words:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="background-color: #cccccc;"&gt;&lt;span style="font-size: x-large;"&gt;"&lt;/span&gt;Hello Everybody,&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;Just wanted to update you with an Issue which happened at Client site and how was it remediated.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;Issue: Domain user accounts getting locked out automatically. When users would lock their terminals and go out for break after coming back their accounts were disabled automatically.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;Investigations Done:&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;1.       Checking of domain controller policies for any inconsistencies.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;2.       Checking of presence of any virus by their antivirus. (McAfee)  Result: Nothing was found. (Was not updated)&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;3.       Systems &amp;amp; Server were not patched regularly with Latest patches.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;4.       Checking of security logs on Server. Result: No information was found.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;Client Environment Information:&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;User Desktops: Windows 7&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;Server: Windows 2008&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;Alternative Solutions Recommended:&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;1.       Installing of free ware of AVG and run SCAN on affected machines.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;2.       Installing Nessus and scan the network for any vulnerabilities.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;Issues Found: Detection of virus named “Conficker.B” .&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;Summary on Functioning of Virus:&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;Conficker primarily spreads through a Windows Vulnerability (MS08-067), which if un patched allows the worm to attack the Windows file sharing service. Conficker is a type of computer virus called a computer worm. Computer worms take advantage of un patched computer systems to automatically spread themselves.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;Once a computer is infected, the infected system begins to scan the Internet, or its local network for un patched computers to infect.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;Capabilities of this Virus:&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;1. Even if you have a backup service in case you get hit by a virus, Conficker Virus instantly disables this backup service so you will definitely be left with nothing.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;2. Conficker Virus will also not allow you to enter security websites.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;3. It will erase all your recently saved important and official documents.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;4. Conficker Virus will also not give you access to security sites and services.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;5. It will make your computer vulnerable to infected machines making you get more programs from the malware's creator.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;Conficker virus comes in below mentioned versions:&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;* Win32/Conficker.A was reported to Microsoft on November 21, 2008.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;* Win32/Conficker.B was reported to Microsoft on December 29, 2008.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;* Win32/Conficker.C was reported to Microsoft on February 20, 2009.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;* Win32/Conficker.D was reported to Microsoft on March 4, 2009.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;* Win32/Conficker.E was reported to Microsoft on April 8, 2009.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;Win32/Conficker.B might spread through file sharing and via removable drives, such as USB drives (also known as thumb drives). The worm adds a file to the removable drive so that when the drive is used, the AutoPlay dialog box will show one additional option.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;The Conficker worm can also disable important services on your computer. In the screenshot of the Auto play dialog box below, the option Open folder to view files — Publisher not specified was added by the worm. The highlighted option — Open folder to view files — using Windows Explorer is the option that Windows provides and the option you should use.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;If you select the first option, the worm executes and can begin to spread itself to other computers.&lt;/div&gt;&lt;div class="separator" style="background-color: #cccccc; clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="background-color: #cccccc; clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="background-color: #cccccc; clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Kic0h6eqy-A/TQSpUvxjoOI/AAAAAAAAAbs/dh-geQyZaDI/s1600/image004.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/_Kic0h6eqy-A/TQSpUvxjoOI/AAAAAAAAAbs/dh-geQyZaDI/s320/image004.jpg" width="300" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;The option Open folder to view files — Publisher not specified was added by the worm.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;Illustration of working :&lt;/div&gt;&lt;div class="separator" style="background-color: #cccccc; clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Kic0h6eqy-A/TQSpxPj-k6I/AAAAAAAAAbw/w1MJAucxPdk/s1600/image003.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="267" src="http://3.bp.blogspot.com/_Kic0h6eqy-A/TQSpxPj-k6I/AAAAAAAAAbw/w1MJAucxPdk/s400/image003.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="background-color: #cccccc;"&gt;&lt;b&gt;&lt;u&gt;Quick Remedies and Information for such Situations:&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="background-color: #cccccc;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;If your computer is infected with the Conficker worm, you may be unable to download certain security products, such as the &lt;a href="http://www.microsoft.com/security/malwareremove/default.aspx" target="_blank"&gt;Microsoft Malicious Software Removal Tool&lt;/a&gt; or you may be unable to access certain Web sites, such as &lt;a href="http://go.microsoft.com/fwlink/?LinkId=148275" target="_blank"&gt;Microsoft Update&lt;/a&gt;. If you can't access those tools, try using the &lt;a href="http://onecare.live.com/site/en-us/default.htm?s_cid=sah" target="_blank"&gt;Windows Live safety scanner&lt;/a&gt;.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;2.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Alternatively you can also try downloading AVG Antivirus and scan the machines.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;3.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Also  you might want to update the antivirus at client site with latest  information. And also the patches on desktops &amp;amp; servers to the  latest ones.&lt;/div&gt;&lt;div style="background-color: #cccccc;"&gt;4.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Scan your Computers with Both Anti-Virus and Anti-Spyware software.&lt;/div&gt;&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt; &lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;br /&gt;
We thank Gaurav for sharing his valuable experience with us and expect to receive many such articles from other people reading this post too.&lt;br /&gt;
&lt;br /&gt;
If you've got to say something on Ethical Hacking or Information Security mail us your articles at &lt;b&gt;amey [at] techkranti [dot] com&lt;/b&gt; and we'll publish them for you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-5700474940707367934?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Zu2ZDFb-ShILWKwCPrmwrKTj8NQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Zu2ZDFb-ShILWKwCPrmwrKTj8NQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Zu2ZDFb-ShILWKwCPrmwrKTj8NQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Zu2ZDFb-ShILWKwCPrmwrKTj8NQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/Z9yvDNaI7kw" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/Z9yvDNaI7kw/nuisance-of-conficker.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_Kic0h6eqy-A/TQSpUvxjoOI/AAAAAAAAAbs/dh-geQyZaDI/s72-c/image004.jpg" height="72" width="72" /><thr:total>0</thr:total><georss:featurename>Mumbai, Maharashtra, India</georss:featurename><georss:point>19.0176147 72.8561644</georss:point><georss:box>18.6930332 72.3892454 19.3421962 73.3230834</georss:box><feedburner:origLink>http://www.techkranti.com/2010/12/nuisance-of-conficker.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-4388884743011522669</guid><pubDate>Mon, 15 Nov 2010 09:30:00 +0000</pubDate><atom:updated>2010-11-15T15:00:01.714+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Hacking Tools</category><category domain="http://www.blogger.com/atom/ns#">Security Tools</category><category domain="http://www.blogger.com/atom/ns#">Ethical Hacking</category><title>Wi-fEye - An automated network penetration testing tool</title><description>Wi-fEye is designed to help with network penetration testing, Wi-fEye will allow you to perform a number of powerful attacks Automatically, all you have to do is to lunch  Wi-fEye, choose which attack to perform,  select your target and let Wi-fEye do the magic !!&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Kic0h6eqy-A/TOD5O8jrgvI/AAAAAAAAAbo/Yn0gDHPWxW4/s1600/logo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="81" src="http://3.bp.blogspot.com/_Kic0h6eqy-A/TOD5O8jrgvI/AAAAAAAAAbo/Yn0gDHPWxW4/s320/logo.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt; &lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;big&gt;Wi-fEye is divided to four main menus:&lt;/big&gt;&lt;br /&gt;
1. Cracking menu: This menu will allow you to:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;small&gt;Enable monitor mode&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;View avalale Wireless Networks&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;Launch Airodump-ng on a specific AP&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;WEP cracking: this will allow you to perform the following&lt;br /&gt;
attacks automatically: &lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;Interactive packet replay.&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;Fake Authentication Attack.&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;Korek Chopchop Attack.&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;Fragmentation Attack.&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;Hirte Attack (cfrag attack).&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;Wesside-ng.&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;WPA Cracking: This contains the following attacks:&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;&amp;nbsp;Wordlist Attack&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;&amp;nbsp;Rouge AP Attack.&lt;/small&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
2.&amp;nbsp; Mapping: this menu will allow you to do the following:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;small&gt;Scan the network and view the connected hosts.&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;Use Nmap Automatically.&lt;/small&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
3. MITM: this menu will allow you to do the following Automatically:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;small&gt;Enable IP forwarding.&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;ARP Spoof.&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;Launch ettercap (Text mode).&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;Sniff SSL/HTTPS traffic.&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;Sniff URLs and send them to browser.&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;Sniff messengers from instant messengers.&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;Sniff images.&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;DNS Spoof.&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;HTTP Session Hijacking (using Hamster).&lt;/small&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
4. Others: this menu will allow you to o the following automatically:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;small&gt;Change MAC Address.&lt;/small&gt;&lt;/li&gt;
&lt;li&gt;&lt;small&gt;Hijack software updates (using Evilgrade).&lt;/small&gt;&lt;br /&gt;
&lt;/li&gt;
&lt;/ul&gt;Official Website: &lt;a href="http://wi-feye.za1d.com/"&gt;http://wi-feye.za1d.com/t&lt;/a&gt;&lt;br /&gt;
Download page: &lt;a href="http://wi-feye.za1d.com/Download.html"&gt;   http://wi-feye.za1d.com/Download.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="background-color: #fff2cc;"&gt;Get Updates for Hacking&amp;nbsp; Tools on your mobile.&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to &lt;a href="http://labs.google.co.in/smschannels/subscribe/techkranti" style="font-family: Arial,Helvetica,sans-serif;"&gt;TechKranti's   SMS channel&lt;/a&gt; &lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to TechKranti's feeds &lt;a href="http://feeds.feedburner.com/blogspot/Gotp"&gt;&lt;img height="30" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/S4ys7B1W7QI/AAAAAAAAAS8/7ituXPkPyNc/s1600/128px-Feed-icon.svg.png" width="30" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-4388884743011522669?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/HOptqcdrTVjCzK76g6Dzefn4Sjo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HOptqcdrTVjCzK76g6Dzefn4Sjo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/HOptqcdrTVjCzK76g6Dzefn4Sjo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HOptqcdrTVjCzK76g6Dzefn4Sjo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/abIl62mOHYE" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/abIl62mOHYE/wi-feye-automated-network-penetration.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_Kic0h6eqy-A/TOD5O8jrgvI/AAAAAAAAAbo/Yn0gDHPWxW4/s72-c/logo.png" height="72" width="72" /><thr:total>0</thr:total><georss:featurename>Mumbai, Maharashtra, India</georss:featurename><georss:point>19.0176147 72.8561644</georss:point><georss:box>18.6930332 72.3892454 19.3421962 73.3230834</georss:box><feedburner:origLink>http://www.techkranti.com/2010/11/wi-feye-automated-network-penetration.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-5376515436910676244</guid><pubDate>Mon, 15 Nov 2010 09:01:00 +0000</pubDate><atom:updated>2010-11-15T14:31:51.466+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Hacking Tools</category><category domain="http://www.blogger.com/atom/ns#">Security Tools</category><category domain="http://www.blogger.com/atom/ns#">Ethical Hacking</category><category domain="http://www.blogger.com/atom/ns#">Backtrack</category><title>SQLninja - An SQL Server injection &amp; takeover tool</title><description>Fancy going from a SQL Injection on Microsoft SQL Server to a full GUI  access on  the DB? Take a few new SQL Injection tricks, add a couple of remote  shots in the registry to disable Data Execution Prevention, mix with a  little Perl that automatically generates a debug script, put all this in  a shaker with a Metasploit  wrapper, shake well and you have just one of the attack modules of  sqlninja!&lt;br /&gt;
Sqlninja is a tool targeted to exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end.&lt;br /&gt;
Its main goal is to provide a remote access on the vulnerable DB server, even in a very hostile environment. It should be used by penetration testers to help and automate the process of taking over a DB Server when a SQL Injection vulnerability has been discovered.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt; &lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Kic0h6eqy-A/TOD1iglswDI/AAAAAAAAAbk/_OG15-8VJt8/s1600/logo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="78" src="http://1.bp.blogspot.com/_Kic0h6eqy-A/TOD1iglswDI/AAAAAAAAAbk/_OG15-8VJt8/s400/logo.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Fingerprint of the remote SQL Server (version, user performing the queries, user privileges, xp_cmdshell availability, DB authentication mode)&lt;/li&gt;
&lt;li&gt;Bruteforce of 'sa' password (in 2 flavors: dictionary-based and incremental)&lt;/li&gt;
&lt;li&gt;Privilege escalation to sysadmin group if 'sa' password has been found&lt;/li&gt;
&lt;li&gt;Creation of a custom xp_cmdshell if the original one has been removed&lt;/li&gt;
&lt;li&gt;Upload of netcat (or any other executable) using only normal HTTP requests (no FTP/TFTP needed)&lt;/li&gt;
&lt;li&gt;TCP/UDP portscan from the target SQL Server to the attacking machine, in order to find a port that is allowed by the firewall of the target network and use it for a reverse shell&lt;/li&gt;
&lt;li&gt;Direct and reverse bindshell, both TCP and UDP&lt;/li&gt;
&lt;li&gt;DNS-tunneled pseudo-shell, when no TCP/UDP ports are available for a direct/reverse shell, but the DB server can resolve external hostnames (check the documentation for details about how this works)&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Evasion techniques to confuse a few IDS/IPS/WAF&lt;/li&gt;
&lt;li&gt;Integration with Metasploit3, to obtain a graphical access to the remote DB server through a VNC server injection&lt;/li&gt;
&lt;li&gt;Integration with churrasco.exe, to escalate privileges to SYSTEM on w2k3 via token kidnapping&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
&lt;h1&gt;Platforms supported&lt;/h1&gt;Sqlninja is written in Perl and should run&lt;br /&gt;
on any UNIX based platform with a Perl interpreter, as long as all&lt;br /&gt;
needed modules have been installed. So far it has been successfully&lt;br /&gt;
tested on:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Linux&lt;/li&gt;
&lt;li&gt;FreeBSD&lt;/li&gt;
&lt;li&gt;Mac OS X&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
Download Page: &lt;a href="http://sqlninja.sourceforge.net/"&gt;http://sqlninja.sourceforge.net/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="background-color: rgb(255, 242, 204);"&gt;Get Security News on your mobile.&lt;/div&gt;&lt;div style="background-color: rgb(255, 242, 204);"&gt;Subscribe to &lt;a href="http://labs.google.co.in/smschannels/subscribe/techkranti" style="font-family: Arial,Helvetica,sans-serif;"&gt;TechKranti's   SMS channel&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: rgb(255, 242, 204);"&gt;Subscribe to TechKranti's feeds &lt;a href="http://feeds.feedburner.com/blogspot/Gotp"&gt;&lt;img src="http://2.bp.blogspot.com/_Kic0h6eqy-A/S4ys7B1W7QI/AAAAAAAAAS8/7ituXPkPyNc/s1600/128px-Feed-icon.svg.png" width="30" height="30"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-5376515436910676244?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/4C_H6fAKHWKPH3qm0GHLaK1CmHw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/4C_H6fAKHWKPH3qm0GHLaK1CmHw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/4C_H6fAKHWKPH3qm0GHLaK1CmHw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/4C_H6fAKHWKPH3qm0GHLaK1CmHw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/TWNXQA6JFw0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/TWNXQA6JFw0/sqlninja-sql-server-injection-takeover.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_Kic0h6eqy-A/TOD1iglswDI/AAAAAAAAAbk/_OG15-8VJt8/s72-c/logo.png" height="72" width="72" /><thr:total>0</thr:total><georss:featurename>Mumbai, Maharashtra, India</georss:featurename><georss:point>19.0176147 72.8561644</georss:point><georss:box>18.6930332 72.3892454 19.3421962 73.3230834</georss:box><feedburner:origLink>http://www.techkranti.com/2010/11/sqlninja-sql-server-injection-takeover.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-8677478017606307795</guid><pubDate>Mon, 18 Oct 2010 11:56:00 +0000</pubDate><atom:updated>2010-11-15T14:32:49.581+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security News</category><title>Protect your data in the cloud says Priya Nayak, Consumer Operations, Google Accounts</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;Like many people, you probably store a lot of important information in your Google Account. I personally check my Gmail account every day (sometimes several times a day) and rely on having access to my mail and contacts wherever I go. Aside from Gmail, my Google Account is tied to lots of other services that help me manage my life and interests: photos, documents, blogs, calendars, and more. That is to say, my Google Account is very valuable to me.&lt;br /&gt;
&lt;br /&gt;
Unfortunately, a Google Account is also valuable in the eyes of spammers and other people looking to do harm. It’s not so much about your specific account, but rather the fact that your friends and family see your Google Account as trustworthy. A perfect example is the “Mugged in London” phishing scam that aims to trick your contacts into wiring money — ostensibly to help you out. If your account is compromised and used to send these messages, your well-meaning friends may find themselves out a chunk of change. If you have sensitive information in your account, it may also be at risk of improper access.&lt;br /&gt;
&lt;br /&gt;
As part of National Cyber Security Awareness month, we want to let you know what you can do to better protect your Google Account.&lt;br /&gt;
Stay one step ahead of the bad guys&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
Account hijackers prey on the bad habits of the average Internet user. Understanding common hijacking techniques and using better security practices will help you stay one step ahead of them.&lt;br /&gt;
&lt;br /&gt;
The most common ways hijackers can get access to your Google password are:&lt;br /&gt;
* Password re-use: You sign up for an account on a third-party site with your Google username and password. If that site is hacked and your sign-in information is discovered, the hijacker has easy access to your Google Account.&lt;br /&gt;
* Malware: You use a computer with infected software that is designed to steal your passwords as you type (“keylogging”) or grab them from your browser’s cache data.&lt;br /&gt;
* Phishing: You respond to a website, email, or phone call that claims to come from a legitimate organization and asks for your username and password.&lt;br /&gt;
* Brute force: You use a password that’s easy to guess, like your first or last name plus your birth date (“Laura1968”), or you provide an answer to a secret question that’s common and therefore easy to guess, like “pizza” for “What is your favorite food?”&lt;br /&gt;
&lt;br /&gt;
As you can see, hijackers have many tactics for stealing your password, and it’s important to be aware of all of them.&lt;br /&gt;
Take control of your account security across the web&lt;br /&gt;
Online accounts that share passwords are like a line of dominoes: When one falls, it doesn’t take much for the others to fall, too. This is why you should choose unique passwords for important accounts like Gmail (your Google Account), your bank, commerce sites, and social networking sites. We’re also working on technology that adds another layer of protection beyond your password to make your Google Account significantly more secure.&lt;br /&gt;
Choosing a unique password is not enough to secure your Google Account against every possible threat. That’s why we’ve created an easy-to-use checklist to help you secure your computer, browser, Gmail, and Google Account. We encourage you to go through the entire checklist, but want to highlight these tips:&lt;br /&gt;
&lt;br /&gt;
* Never re-use passwords for your important accounts like online banking, email, social networking, and commerce.&lt;br /&gt;
&lt;br /&gt;
* Change your password periodically, and be sure to do so for important accounts whenever you suspect one of them may have been at risk. Don’t just change your password by a few letters or numbers (“Aquarius5” to “Aquarius6”); change the combination of letters and numbers to something unique each time.&lt;br /&gt;
&lt;br /&gt;
* Never respond to messages, non-Google websites, or phone calls asking for your Google username or password; a legitimate organization will not ask you for this type of information. Report these messages to us so we can take action. If you responded and can no longer access your account, visit our account recovery page.&lt;br /&gt;
&lt;br /&gt;
We hope you’ll take action to ensure your security across the web, not just on Google. Run regular virus scans, don’t re-use your passwords, and keep your software and account recovery information up to date. These simple yet powerful steps can make a difference when it really counts.&lt;br /&gt;
SOURCE: &lt;a href="http://googleonlinesecurity.blogspot.com/2010/10/protecting-your-data-in-cloud.html"&gt;Google Online Security Blog&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-8677478017606307795?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/UV_AyRsY_0o3uoBXwZiKtmZygcs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/UV_AyRsY_0o3uoBXwZiKtmZygcs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/UV_AyRsY_0o3uoBXwZiKtmZygcs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/UV_AyRsY_0o3uoBXwZiKtmZygcs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/FSjY7PYqgEE" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/FSjY7PYqgEE/protect-your-data-in-cloud-says-priya.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2010/10/protect-your-data-in-cloud-says-priya.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-286457667887149216</guid><pubDate>Fri, 01 Oct 2010 12:27:00 +0000</pubDate><atom:updated>2010-10-01T17:57:43.486+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">XP Tips and Tricks</category><title>How to change MAC  (Medium Access Control) address of NIC</title><description>As you probably know every NIC (Network Interface Card) has unique address and has various aliases like BIA,Hardware address,Physical address.So, why on Earth we need to change the MAC address?&lt;br /&gt;
Let me explain a little bit of networking funda, most of the packet Switches has facility known as port security which allows network admin to limit access to ports by monitoring the MAC address.Which means it can be set to allow only certain MAC address or first 2-3 MAC addresses learned dynamically.&lt;br /&gt;
&amp;nbsp; If your ISP has turned on this feature then you can connect only one or two devices to Internet.What if you want more? Now you got why to change , in this case&amp;nbsp; fake, MAC address.You can do this by following ways,&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;b&gt;By changing network address field in properties of NIC&lt;/b&gt;:&lt;br /&gt;
Go to Control Panel&amp;gt;Network Connection(XP) or similar in WIndows 7&lt;br /&gt;
then right click on the NIC &amp;gt;Properties&amp;gt; Configure &amp;gt;Advance &amp;gt;Network Address enter the &lt;u&gt;allowed MAC address&lt;/u&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Kic0h6eqy-A/THTd2HiJH7I/AAAAAAAAAZc/UR8F9DnLYyw/s1600/1.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/_Kic0h6eqy-A/THTd2HiJH7I/AAAAAAAAAZc/UR8F9DnLYyw/s320/1.bmp" width="261" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Kic0h6eqy-A/THTd5WKHQII/AAAAAAAAAZk/_O3YCniIqJI/s1600/2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/THTd5WKHQII/AAAAAAAAAZk/_O3YCniIqJI/s320/2.JPG" width="262" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Kic0h6eqy-A/THTd6Mkg4-I/AAAAAAAAAZo/zYSNfkNvDyg/s1600/3.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/THTd6Mkg4-I/AAAAAAAAAZo/zYSNfkNvDyg/s320/3.JPG" width="285" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Or by using free utility &lt;b&gt;&lt;span class="Arial"&gt;Technitium                MAC Address Changer&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;b&gt;&lt;span class="Arial"&gt;&lt;a href="http://www.technitium.com/tmac/index.html#download"&gt;download here&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;b&gt;&lt;span class="Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;b&gt;&lt;span class="Arial"&gt;Follow steps ,images are self explanatory&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;b&gt;&lt;span class="Arial"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Kic0h6eqy-A/THTd7BbcKHI/AAAAAAAAAZs/zoViLnFDBBs/s1600/4.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="270" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/THTd7BbcKHI/AAAAAAAAAZs/zoViLnFDBBs/s320/4.JPG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;b&gt;&lt;span class="Arial"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;b&gt;&lt;span class="Arial"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Kic0h6eqy-A/THTd4sEE2fI/AAAAAAAAAZg/X-zbQl7pIgQ/s1600/5.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="296" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/THTd4sEE2fI/AAAAAAAAAZg/X-zbQl7pIgQ/s320/5.JPG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;b&gt;&lt;span class="Arial"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;b&gt;&lt;span class="Arial"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;b&gt;&lt;span class="Arial"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-286457667887149216?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/6ILGpSL2YxYJunwt18PWmwZBjc8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6ILGpSL2YxYJunwt18PWmwZBjc8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/6ILGpSL2YxYJunwt18PWmwZBjc8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6ILGpSL2YxYJunwt18PWmwZBjc8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/bUJw_nvmDNg" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/bUJw_nvmDNg/how-to-change-mac-medium-access-control.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_Kic0h6eqy-A/THTd2HiJH7I/AAAAAAAAAZc/UR8F9DnLYyw/s72-c/1.bmp" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2010/08/how-to-change-mac-medium-access-control.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-4934858142073600494</guid><pubDate>Thu, 23 Sep 2010 16:45:00 +0000</pubDate><atom:updated>2010-10-01T09:21:24.592+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security News</category><category domain="http://www.blogger.com/atom/ns#">Hacking News</category><title>ASP.Net Web flaw being exploited in the wild</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Kic0h6eqy-A/TJuDjH5O-HI/AAAAAAAAAa4/dA365nVPrUw/s1600/4qjbsb5pxk1lp7f1pf66w3ls2a.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://1.bp.blogspot.com/_Kic0h6eqy-A/TJuDjH5O-HI/AAAAAAAAAa4/dA365nVPrUw/s320/4qjbsb5pxk1lp7f1pf66w3ls2a.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;Source: &lt;a href="http://www.theregister.co.uk/2010/09/21/asp_dot_net_padding_oracle_fix/"&gt;TheRegister&lt;/a&gt; &lt;br /&gt;
Attackers have begun exploiting a recently disclosed vulnerability in Microsoft web-development applications that opens password files and other sensitive data to interception and tampering.&lt;br /&gt;
&lt;br /&gt;
The vulnerability in the way ASP.Net apps encrypt data was disclosed last week at the Ekoparty Conference in Argentina. Microsoft on Friday issued a temporary fix for the so-called “cryptographic padding attack,” which allows attackers to decrypt protected files by sending vulnerable systems large numbers of corrupted requests.&lt;br /&gt;
&lt;br /&gt;
Now, Microsoft security pros say they are seeing “limited attacks” in the wild and warned that they can be used to read and tamper with a system's most sensitive configuration files.&lt;br /&gt;
&lt;br /&gt;
“There is a combination of attacks that was publicly demonstrated that can leak the contents of your web.config file, including any sensitive, unencrypted, information in the file,” Microsoft's Scott Guthrie wrote on Monday night. “You should apply the workaround to block the padding oracle attack in its initial stage of the attack.”&lt;br /&gt;
&lt;br /&gt;
Microsoft personnel also warned about ASP.Net applications that store passwords, database connection strings or other sensitive data in the ViewState object. Because such objects are accessible to the outside, the Microsoft apps automatically encrypt its contents.&lt;br /&gt;
&lt;br /&gt;
But by bombarding a vulnerable server with large amounts of corrupted data and then carefully analyzing the error messages that result, attackers can deduce the key used to encrypt the files. The side-channel attack can be used to convert virtually any file of the attacker's choosing.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;br /&gt;
The temporary fix involves reconfiguring applications so that all error messages are mapped to a single error page that prevents the attacker from distinguishing among different types of errors A script to identify the oracles that needlessly reveal important cryptographic clues is here.&lt;br /&gt;
&lt;br /&gt;
Thai Duong, one of the researchers who disclosed the vulnerability last week, said here that simply turning off custom error messages was not enough to ward off exploits because attackers can still measure the different amounts of time required for certain errors to be returned.&lt;br /&gt;
&lt;br /&gt;
Microsoft's Guthrie said versions 3.5 SP1 or 4.0 of the .Net platform on which the applications run have protections to prevent such timing analysis. They include an option in the customErrors feature that introduces a random delay in the error page. He recommends turning it on and configuring apps to return precisely the same error response regardless of the error encountered on the server.&lt;br /&gt;
&lt;br /&gt;
Microsoft hasn't said when it plans to issue a permanent fix. Its next regular patch release is scheduled for October 12.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="background-color: #fff2cc;"&gt;Get Security News on your mobile.&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to &lt;a href="http://labs.google.co.in/smschannels/subscribe/techkranti" style="font-family: Arial,Helvetica,sans-serif;"&gt;TechKranti's   SMS channel&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to TechKranti's feeds &lt;a href="http://feeds.feedburner.com/blogspot/Gotp"&gt;&lt;img height="30" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/S4ys7B1W7QI/AAAAAAAAAS8/7ituXPkPyNc/s1600/128px-Feed-icon.svg.png" width="30" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-4934858142073600494?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/EUkgeputsoWEr-QeNU8Hg4fnldc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/EUkgeputsoWEr-QeNU8Hg4fnldc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/EUkgeputsoWEr-QeNU8Hg4fnldc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/EUkgeputsoWEr-QeNU8Hg4fnldc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/zk9Q59ZrCNs" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/zk9Q59ZrCNs/aspnet-web-flaw-being-exploited-in-wild.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_Kic0h6eqy-A/TJuDjH5O-HI/AAAAAAAAAa4/dA365nVPrUw/s72-c/4qjbsb5pxk1lp7f1pf66w3ls2a.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2010/09/aspnet-web-flaw-being-exploited-in-wild.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-2567579192452935325</guid><pubDate>Fri, 10 Sep 2010 15:54:00 +0000</pubDate><atom:updated>2010-10-01T09:37:12.724+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security News</category><title>0-day: Buffer overflow in Adobe Reader and Acrobat</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Kic0h6eqy-A/TIpUUrDHmrI/AAAAAAAAAa0/Ewaupw5oedk/s1600/adobe-logo.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="200" src="http://1.bp.blogspot.com/_Kic0h6eqy-A/TIpUUrDHmrI/AAAAAAAAAa0/Ewaupw5oedk/s200/adobe-logo.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Adobe reports a vulnerability in Adobe Reader and Acrobat: &lt;br /&gt;
&lt;br /&gt;
A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild. &lt;br /&gt;
Adobe is in the process of evaluating the schedule for an update to resolve this vulnerability.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;br /&gt;
Affected software versions:&lt;br /&gt;
Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh.&lt;br /&gt;
&lt;br /&gt;
Details on the security advisory &lt;a href="http://www.adobe.com/support/security/advisories/apsa10-02.html"&gt;HERE&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="background-color: #fff2cc;"&gt;Get Security News on your mobile.&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to &lt;a href="http://labs.google.co.in/smschannels/subscribe/techkranti" style="font-family: Arial,Helvetica,sans-serif;"&gt;TechKranti's   SMS channel&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to TechKranti's feeds &lt;a href="http://feeds.feedburner.com/blogspot/Gotp"&gt;&lt;img height="30" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/S4ys7B1W7QI/AAAAAAAAAS8/7ituXPkPyNc/s1600/128px-Feed-icon.svg.png" width="30" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-2567579192452935325?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/tVMbrP7viW8dBuj6ghEQYMsaZuI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tVMbrP7viW8dBuj6ghEQYMsaZuI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/tVMbrP7viW8dBuj6ghEQYMsaZuI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tVMbrP7viW8dBuj6ghEQYMsaZuI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/oZfgdyOihes" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/oZfgdyOihes/0-day-buffer-overflow-in-adobe-reader.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_Kic0h6eqy-A/TIpUUrDHmrI/AAAAAAAAAa0/Ewaupw5oedk/s72-c/adobe-logo.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2010/09/0-day-buffer-overflow-in-adobe-reader.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-8031088698830440585</guid><pubDate>Fri, 10 Sep 2010 02:36:00 +0000</pubDate><atom:updated>2010-10-01T10:37:59.538+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security News</category><title>Is your information in safe hands? Customer database threatened by insider leakages</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Kic0h6eqy-A/TImZlRGWbGI/AAAAAAAAAaw/-Tt_z8ZdcHo/s1600/insider.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="138" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/TImZlRGWbGI/AAAAAAAAAaw/-Tt_z8ZdcHo/s200/insider.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Have you ever received promotional calls by companies you have never heard of? Or are you sure that you have never agree to give your phone number to these companies? Customer database is the answers to these questions. Companies acquire your information by buying the database.&lt;br /&gt;
&lt;br /&gt;
Personal information values especially in market-driven economy. Who buy what kinds of products, formulates the marketing and promotion strategies of the companies. A list of personal date do value.&lt;br /&gt;
&lt;br /&gt;
Data could be sold everywhere, by everyone, even from the insiders. Cisco conducted a global study on data security and leakage in businesses in 2008. The study showed ”insider threat” is the major threat to customer data. It means data loss or leakages resulting from employee behavior. It could be due to carelessness, such as forget to log off, share passwords among colleagues, or even fail to return company devices when quitting the job. The internal factor poses a greater threat to the data security far more than external factors such as hackers do.&lt;br /&gt;
&lt;br /&gt;
The above excerpt is taken from hackinthebox.org. To add to it, I would like to describe an incidence with my friend.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;br /&gt;
I recently joined a technical course which had a tenure of 14 days. In the same batch was a guy named Shella from Italy. He had come to India to just pursue the course. And he had only visited Bangalore and Mumbai. He had bought a Vodafone SIM from Bangalore and no one had his number except two organisations, one, the institute where we were pursuing this course, and two, VODAFONE. One fine day he gets a promotional SMS on his cell from some college offering an MBA course. He narrates to me about this and says "I haven't given my number to anyone in India, except  %#Solutions(The institute where we pursued our course), so I think these people might have provided my number to this promoter". But, the SMS was from a college from Bangalore and there is no question of an institute in Mumbai to provide details to some college in Bangalore. So by now we should be pretty sure from where the data had been leaked. Yes, it could be Vodafone, Bangalore.&lt;br /&gt;
&lt;br /&gt;
This was just an example of insider data breaches. Organizations trust their employees to handle sensitive data and they need to do that because employees are the primary assets a company owns. In DEFCON this year a social engineering competition was held to see how creative hackers can be. Hackers demonstrated the idea of a fake interview to siphon information from a rival organization's employee. First the employee in the rival company is called and told that we have a better offer for you than your current one. Then a fake interview is setup with the hacker who poses to be the employer. The place could be a plush lounge or restaurant where the employee feels that the employer is real and not making it all up. After all organizations can go to any extent to get their rival's sensitive information. The hacker then starts siphoning information from the employee and it can be well understood that a human can be most  vulnerable when in an interview, because we generally tend to look at the interviewer being superior to us and we are very cautious about our speech. A normal human mind might think that If I am getting a better job just by giving out some information, then it won't harm much. We recommend that the hacker be accompanied with a psychiatrist for better results.:-)&lt;br /&gt;
&lt;br /&gt;
Customer data breaches have been prevalent in India since many years. In a sting operation about 5-6 years ago on a news show I heard that one contact number sells for Rs 7. I am sure the price must have at least been doubled now looking at the competition for better marketing.&lt;br /&gt;
&lt;br /&gt;
Information:&lt;br /&gt;
(For Indian Subscribers)If you want to stop receiving promotional SMS' and calls send an SMS as:&lt;br /&gt;
'START DND' without quotes and send it to 1909. This is a Do Not Disturb service and has been initiated by TRAI(Telecom Regulatory Authority of India).&lt;br /&gt;
&lt;br /&gt;
&lt;div style="background-color: #fff2cc;"&gt;Get Security News on your mobile.&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to &lt;a href="http://labs.google.co.in/smschannels/subscribe/techkranti" style="font-family: Arial,Helvetica,sans-serif;"&gt;TechKranti's   SMS channel&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to TechKranti's feeds &lt;a href="http://feeds.feedburner.com/blogspot/Gotp"&gt;&lt;img height="30" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/S4ys7B1W7QI/AAAAAAAAAS8/7ituXPkPyNc/s1600/128px-Feed-icon.svg.png" width="30" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-8031088698830440585?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/RJlMN-SI8bfpSXr6znyA5yAZzmA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/RJlMN-SI8bfpSXr6znyA5yAZzmA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/RJlMN-SI8bfpSXr6znyA5yAZzmA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/RJlMN-SI8bfpSXr6znyA5yAZzmA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/uRfa7lusKsA" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/uRfa7lusKsA/is-your-information-in-safe-hands.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_Kic0h6eqy-A/TImZlRGWbGI/AAAAAAAAAaw/-Tt_z8ZdcHo/s72-c/insider.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2010/09/is-your-information-in-safe-hands.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-5126097094860733438</guid><pubDate>Thu, 09 Sep 2010 15:52:00 +0000</pubDate><atom:updated>2010-10-01T10:38:23.572+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security Tools</category><category domain="http://www.blogger.com/atom/ns#">Security News</category><category domain="http://www.blogger.com/atom/ns#">Ethical Hacking</category><category domain="http://www.blogger.com/atom/ns#">Exploits</category><title>DllHijackAuditor: Check an application's vulnerability to DLL hijacking</title><description>Earlier we had posted about loads of applications being found vulnerable to DLL hijacking(&lt;a href="http://www.techkranti.com/2010/08/more-and-more-applications-being-found.html"&gt;DLL Hijacking&lt;/a&gt;). Without any tools available for checking the integrity of an application, very large number of applications were found vulnerable by security researchers. But now securityxploded has released a tool to check an application's vulnerability to DLL hijacking. More information about the tool and download at the link mentioned below.&lt;br /&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;a href="http://securityxploded.com/dllhijackauditor.php"&gt;http://securityxploded.com/dllhijackauditor.php&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="background-color: #fff2cc;"&gt;Get Security News on your mobile.&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to &lt;a href="http://labs.google.co.in/smschannels/subscribe/techkranti" style="font-family: Arial,Helvetica,sans-serif;"&gt;TechKranti's   SMS channel&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to TechKranti's feeds &lt;a href="http://feeds.feedburner.com/blogspot/Gotp"&gt;&lt;img height="30" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/S4ys7B1W7QI/AAAAAAAAAS8/7ituXPkPyNc/s1600/128px-Feed-icon.svg.png" width="30" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-5126097094860733438?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/NYn3kEITWGypWJ-8powkYYYOLJU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NYn3kEITWGypWJ-8powkYYYOLJU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/NYn3kEITWGypWJ-8powkYYYOLJU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NYn3kEITWGypWJ-8powkYYYOLJU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/kHeTIi1lhL0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/kHeTIi1lhL0/dllhijackauditor-check-applications.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_Kic0h6eqy-A/S4ys7B1W7QI/AAAAAAAAAS8/7ituXPkPyNc/s72-c/128px-Feed-icon.svg.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2010/09/dllhijackauditor-check-applications.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-2135758380861177619</guid><pubDate>Thu, 09 Sep 2010 15:22:00 +0000</pubDate><atom:updated>2010-10-01T10:38:51.927+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Latest Trends in technologies</category><category domain="http://www.blogger.com/atom/ns#">All about Google</category><title>Google introduces Google Instant</title><description>We all love Google and are just fascinated by the innovations it offers in search as well as other fields. Google is here with yet another awesome feature added to its search, Google Instant. Google had this very cool option of search suggestions as we typed our search query. Going a step further, now as you type your query you get to see your search results along with suggestions. We need not say more about this. Try it for yourself. Here is a screenshot of our experience.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Kic0h6eqy-A/TIj53yTnbZI/AAAAAAAAAas/QGktw33ol5w/s1600/gs2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="191" src="http://4.bp.blogspot.com/_Kic0h6eqy-A/TIj53yTnbZI/AAAAAAAAAas/QGktw33ol5w/s400/gs2.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div style="background-color: #fff2cc;"&gt;Get Google News on your mobile.&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to &lt;a href="http://labs.google.co.in/smschannels/subscribe/techkranti" style="font-family: Arial,Helvetica,sans-serif;"&gt;TechKranti's   SMS channel&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to TechKranti's feeds &lt;a href="http://feeds.feedburner.com/blogspot/Gotp"&gt;&lt;img height="30" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/S4ys7B1W7QI/AAAAAAAAAS8/7ituXPkPyNc/s1600/128px-Feed-icon.svg.png" width="30" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-2135758380861177619?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/OBf0QDF5EXtEeHBMJO0R-_M_WgE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/OBf0QDF5EXtEeHBMJO0R-_M_WgE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/OBf0QDF5EXtEeHBMJO0R-_M_WgE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/OBf0QDF5EXtEeHBMJO0R-_M_WgE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/WSNpgGCZBsc" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/WSNpgGCZBsc/google-introduces-google-instant.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_Kic0h6eqy-A/TIj53yTnbZI/AAAAAAAAAas/QGktw33ol5w/s72-c/gs2.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2010/09/google-introduces-google-instant.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-3715401209943990545</guid><pubDate>Wed, 08 Sep 2010 06:54:00 +0000</pubDate><atom:updated>2010-10-01T10:39:17.095+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">XP Tips and Tricks</category><title>How To Make XP System a Router</title><description>&lt;b&gt;IP Forwarding&lt;/b&gt; is a very good feature in Windows&amp;nbsp; XP using which a XP machine can be made to act like a router. So, next time you set up home network do consider this. So how to do it?&lt;br /&gt;
You will require at least 2 or more NIC(commonly known as LAN Cards) to setup this. OR alternatively on second NIC you can connect a switch. Why multiple NIC's?&amp;nbsp; Its obvious,&lt;br /&gt;
1st: NIC that directly connect to internet.&lt;br /&gt;
Other: NIC which will act just any other&amp;nbsp; interface of router holding other network.(It will also act as default gateway)&lt;br /&gt;
&lt;br /&gt;
Lets take an example, see fig below,&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Kic0h6eqy-A/TIct8pvpKjI/AAAAAAAAAaQ/GsyspEutCOU/s1600/xp-router-network.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="280" src="http://4.bp.blogspot.com/_Kic0h6eqy-A/TIct8pvpKjI/AAAAAAAAAaQ/GsyspEutCOU/s320/xp-router-network.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;In the figure as you can see there are 3 NIC one of which connects directly to Internet other two are used as router interface to create&amp;nbsp; different networks.Lets start,&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;br /&gt;
First we have to enable IP forwarding, to do that&lt;br /&gt;
Go to &lt;b&gt;Run&lt;/b&gt;&amp;gt; type&lt;b&gt; regedit&lt;/b&gt;&lt;br /&gt;
then follow path &lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TcpipParameters&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
.&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Kic0h6eqy-A/TIcvbTabKgI/AAAAAAAAAaU/g4ZDQJP3Wng/s1600/IPEnableRouter.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="216" src="http://1.bp.blogspot.com/_Kic0h6eqy-A/TIcvbTabKgI/AAAAAAAAAaU/g4ZDQJP3Wng/s400/IPEnableRouter.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;Right click &lt;b&gt;IPEnableRouter&lt;/b&gt; registry object, and click &lt;b&gt;Modify&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Kic0h6eqy-A/TIcvwdDF_ZI/AAAAAAAAAaY/JJ1ptqphnmg/s1600/ip-forwarding.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_Kic0h6eqy-A/TIcvwdDF_ZI/AAAAAAAAAaY/JJ1ptqphnmg/s1600/ip-forwarding.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;In the &lt;b&gt;value&lt;/b&gt; &lt;b&gt;data&lt;/b&gt; field enter 1. Its done click OK.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now configure the network cards on the&amp;nbsp; XP machine (router) with following info, &lt;br /&gt;
&lt;b&gt;NIC-2&lt;/b&gt;&lt;br /&gt;
Network Card A (connect to network A):&lt;br /&gt;
IP: 10.10.10.1&lt;br /&gt;
Netmask: 255.255.255.0&lt;br /&gt;
Gateway (GW): [leave it blank]&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;NIC-3 &lt;/b&gt;&lt;br /&gt;
Network Card B (connect to network B):&lt;br /&gt;
IP: 192.168.20.1&lt;br /&gt;
Netmask: 255.255.255.0&lt;br /&gt;
Gateway (GW): [leave it blank]&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;NIC-1 &lt;/b&gt;&lt;br /&gt;
Network Card C (connect to Internet via cable/dsl connection)&lt;br /&gt;
This information will be based on the Internet connection service which you have subscribed.  &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Configure all the computers in network A with following information.&lt;/b&gt;&lt;br /&gt;
Network A &lt;br /&gt;
IP: 10.10.10.2-254&lt;br /&gt;
Netmask: 255.255.255.0&lt;br /&gt;
Gateway (GW): 10.10.10.1&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Configure all the computers in network B with following information.&lt;/b&gt;&lt;br /&gt;
Network B &lt;br /&gt;
IP: 192.168.20.2-254&lt;br /&gt;
Netmask: 255.255.255.0&lt;br /&gt;
Gateway: 192.168.20.1&lt;br /&gt;
&lt;br /&gt;
Image Courtesy&lt;b&gt;: &lt;/b&gt;http://www.home-network-help.com/ip-forwarding.html&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;div style="background-color: #fff2cc;"&gt;Get Networking Tips on your mobile.&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to &lt;a href="http://labs.google.co.in/smschannels/subscribe/techkranti" style="font-family: Arial,Helvetica,sans-serif;"&gt;TechKranti's   SMS channel&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to TechKranti's feeds &lt;a href="http://feeds.feedburner.com/blogspot/Gotp"&gt;&lt;img height="30" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/S4ys7B1W7QI/AAAAAAAAAS8/7ituXPkPyNc/s1600/128px-Feed-icon.svg.png" width="30" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-3715401209943990545?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/pUn2tcz8NZ51lUEHX0IQQkkCPoo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/pUn2tcz8NZ51lUEHX0IQQkkCPoo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/pUn2tcz8NZ51lUEHX0IQQkkCPoo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/pUn2tcz8NZ51lUEHX0IQQkkCPoo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/hqzl_RFniMI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/hqzl_RFniMI/how-to-make-xp-system-router.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_Kic0h6eqy-A/TIct8pvpKjI/AAAAAAAAAaQ/GsyspEutCOU/s72-c/xp-router-network.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2010/09/how-to-make-xp-system-router.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-628591923247401095</guid><pubDate>Sat, 04 Sep 2010 21:33:00 +0000</pubDate><atom:updated>2010-10-01T10:39:53.312+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Latest Trends in technologies</category><title>Epic Browser - The first-ever web browser for India</title><description>An Indian startup company Hidden Reflex has launched first ever web browser from India. Epic has been stuffed with many features and applications. It has something which we have never heard of before, an integrated antivirus protection in a browser. The built in antivirus and antispyware is powered by ESET. The browser has a sidebar with lot of widgets already installed such as skins, maps, jobs, news, gmail, yahoo, games and many more. Epic claims to have around 1500 free applications which can be added in the browser. Social networking sites such as Facebook, Twitter, and Orkut are also included in the sidebar. You can log in to your account and on the same time continue working on other things. There are many utility functions in the Epic Browser which I liked. It has a free word processor, a to do tool, snippet app, timer and most importantly it allows you to access your files and folder from the browser itself. It also has an application called Indic which allows you to type in many Indian languages. Hidden Reflex claims that the browser supports 12 Indian languages currently. The browser also allows you to watch videos from YouTube in a small window, so that you can browse other websites while watching videos.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Kic0h6eqy-A/TIK4TsjIWdI/AAAAAAAAAaM/lT-RC9YpER8/s1600/gs1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_Kic0h6eqy-A/TIK4TsjIWdI/AAAAAAAAAaM/lT-RC9YpER8/s1600/gs1.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;The Epic Browser is the first-ever web browser for India and the first product from the software company Hidden Reflex.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;br /&gt;
Hidden Reflex is a software product startup founded by Alok Bhardwaj in 2007 and based in Bangalore. Alok, who was raised in the U.S., was inspired by the success of open source software and web 2.0 innovations. Hidden Reflex began as a team of three but soon progressed and now has dedicated teams working on two products simultaneously – the Epic Browser and NewsDrink. The company also has three patents pending related to its product innovations.&lt;br /&gt;
The company’s vision is to become the first globally recognized, consumer-oriented software product company in India. According to Alok Bhardwaj, CEO and Founder of Hidden Reflex, “We want to prove that India can be a hub for innovation in software and technology."&lt;br /&gt;
Our mission with the Epic browser is to create the most secure, most productive and most “Indian” browsing experience of any web browser!&lt;br /&gt;
&lt;br /&gt;
&lt;div style="background-color: #fff2cc;"&gt;Get Security News on your mobile.&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to &lt;a href="http://labs.google.co.in/smschannels/subscribe/techkranti" style="font-family: Arial,Helvetica,sans-serif;"&gt;TechKranti's   SMS channel&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;Subscribe to TechKranti's feeds &lt;a href="http://feeds.feedburner.com/blogspot/Gotp"&gt;&lt;img height="30" src="http://2.bp.blogspot.com/_Kic0h6eqy-A/S4ys7B1W7QI/AAAAAAAAAS8/7ituXPkPyNc/s1600/128px-Feed-icon.svg.png" width="30" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-628591923247401095?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/9sQYC-mrps_iKKSV5X-BamtQ5wY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/9sQYC-mrps_iKKSV5X-BamtQ5wY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/9sQYC-mrps_iKKSV5X-BamtQ5wY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/9sQYC-mrps_iKKSV5X-BamtQ5wY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/ysovZSgRpf0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/ysovZSgRpf0/epic-browser-first-ever-web-browser-for.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_Kic0h6eqy-A/TIK4TsjIWdI/AAAAAAAAAaM/lT-RC9YpER8/s72-c/gs1.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2010/09/epic-browser-first-ever-web-browser-for.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-1287730656318618340</guid><pubDate>Sat, 04 Sep 2010 20:34:00 +0000</pubDate><atom:updated>2010-10-01T10:41:25.287+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security Tools</category><category domain="http://www.blogger.com/atom/ns#">Ethical Hacking</category><title>Scan, Attack, Detect &amp; Protect on LAN: Download WinArpAttacker</title><description>&lt;span id="8460918474113349647"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div style="text-align: center;"&gt;&lt;span id="8460918474113349647"&gt;&lt;b&gt;Scan, Attack, Detect &amp;amp; Protect on LAN: Download WinArpAttacker by Harsh Daftary &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;span id="8460918474113349647"&gt;&lt;a href="http://3.bp.blogspot.com/_1Rgvx77sTm4/TIJ1-fxlS4I/AAAAAAAAE7I/eXV-00jdNAU/s1600/a.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5513098610396711810" src="http://3.bp.blogspot.com/_1Rgvx77sTm4/TIJ1-fxlS4I/AAAAAAAAE7I/eXV-00jdNAU/s400/a.jpg" style="cursor: pointer; display: block; height: 280px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;b&gt;WinArpAttacker is a program that can scan,attack,detect and protect computers on local area network. &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;The features as following: &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;span id="8460918474113349647"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;b&gt;1.1 Scan &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. It can scan and show the active hosts on the LAN within a very short time (~2-3 seconds).&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;It has two scan mode, one is normal scanning, the other is antisniff scanning. The later is to find who is sniffing on the lan.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. It can save and load computer list file.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. It can scan the Lan regularly for new computer list.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. It can update the computer list in passive mode using sniffing technology, that is, it can update the computer list from the sender's address of arp request packets without scanning the lan.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. It can perform advanced scanning when you open advanced scanning dialg on menu.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. It can scan a B class ip range in advanced scan dialg.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. It can scan acthost listed in event listview.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;b&gt;1.2 Attack&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. It can pull and collect all the packets on the LAN.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. It can perform six attacking actions as following:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;(1) Arp Flood - Send ip conflict packets to target computers as fast as possible, if you send too much, the target computers will down. :-(&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;(2) BanGateway - Tell the gateway a wrong mac address of target computers, so the targets can't receive packet from the internet. This attack is to forbid the targets access the internet.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;(3) IPConflict - Like Arp Flood, send ip conflict packets to target computers regularly, maybe the users can't work because of regular ip conflict message. what's more, the targets can't access the lan.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;(4) SniffGateway - Spoof the targets and the gateway, you can use sniffer to collect packets between them.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;(5) SniffHosts - Spoof among two or above targets, you can use sniffer to collect packets among all of them. (dangerous!!!!)&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;(6) SniffLan - Just like SniffGateway, the difference is that SniffLan sends broadcast arp packets to tell all computers on the lan that this host is just the gateway, So you can sniff all the data between all hosts with the gateway.(dangerous!!!!!!!!!!!!!!)&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. While spoofing ARP tables, it can act as another gateway (or ip-forwarder) without other users' recognition on the LAN.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. It can collect and forward packets through WinArpAttacker's ipforward function, you had best check disable system ipforward function because WinArpAttacker can do well.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. All data sniffed by spoofing and forwarded by WinArpAttacker ipforward function will be counted, as you can see on main interface.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. As your wish, the arp table is recovered automatically in a little time (about 5 seconds). Your also can select not to recover.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;b&gt;1.3 Detect&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. What is the most important function, it can detect almost all attacking actions metioned as above as well as host status. the event WinArpAttacker can detect is listed as following:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;SrcMac_Mismath - Host sent an arp packet, its src_mac doesn't match,so the packet will be ignored.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;DstMac_Mismath - Host recv an arp packet, its dst_mac doesn't match,so the packet will be ignored.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Arp_Scan - Host is scanning the lan by arp request for a hosts list.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Arp_Antisniff_Scan - Host is scanning the lan for sniffing host,thus the scanner can know who is sniffing.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Host_Online - Host is online now.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Host_Modify_IP - Host modified its ip to or added a new IP.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Host_Modify_MAC - Host modified its mac address.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;New_Host - New gost was found.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Host_Add_IP - Host added a new ip address.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Multi_IP_Host - Host has multi-ip addresses.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Multi_Mac_Host - Host has multi-mac addresses.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Attack_Flood - Host sends a lot of arp packets to another host ,so the target computer maybe slow down.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Attack_Spoof - Host sends special arp packets to sniff the data two targets , so the victims' data exposed.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Attack_Spoof_Lan - Host lets all host on the lan believe that it's just a gateway, so the intruder can sniff all hosts' data to the real gateway.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Attack_Spoof_Ban_Access - Host told host that host has a inexist mac,so the targets can't communicate with each other.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Attack_Spoof_Ban_Access_GW - Host told host that the gateway has a inexist mac, so the target can't access the internet through the gateway.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Attack_Spoof_Ban_Access_Lan - Host broadcast host's mac as a inexist mac, so the target can't communicate with all hosts on the lan.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Attack_IP_Conflict - Host found another host has same ip as its, so the target would be disturbed by ip conflict messages.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Local_Arp_Entry_Change - now WinArpAttacker can watch local arp entry, when a host's mac address in local arp table is changed, WinArpAttacker can report.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;Local_Arp_Entry_Add - When a mac address of a host is added to local arp table, WinArpAttacker can report.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. It can explain each event which WinArpAttacker detected.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;-. It can save events to file.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;a href="http://www.xfocus.net/tools/200606/WinArpAttacker3.50.rar"&gt;&lt;b&gt;DOWNLOAD HERE&lt;/b&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="8460918474113349647"&gt;&lt;b&gt;Source: freehacking.net &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;span id="8460918474113349647"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-1287730656318618340?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/kC3cljuH2MAcaoL_Ocvu9HV8mjc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/kC3cljuH2MAcaoL_Ocvu9HV8mjc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/kC3cljuH2MAcaoL_Ocvu9HV8mjc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/kC3cljuH2MAcaoL_Ocvu9HV8mjc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/kttKfQQ8Hz0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/kttKfQQ8Hz0/scan-attack-detect-protect-on-lan.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_1Rgvx77sTm4/TIJ1-fxlS4I/AAAAAAAAE7I/eXV-00jdNAU/s72-c/a.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2010/09/scan-attack-detect-protect-on-lan.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2208382470258337434.post-6856601218371830134</guid><pubDate>Sat, 04 Sep 2010 20:26:00 +0000</pubDate><atom:updated>2010-10-01T10:42:07.372+05:30</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security News</category><category domain="http://www.blogger.com/atom/ns#">Hacking News</category><title>Islamic hackers invade website of Belvoir Castle in protest over Israeli foreign policy</title><description>&lt;h3 class="post-title entry-title"&gt;&lt;/h3&gt;&lt;div class="post-header"&gt;&lt;/div&gt;&lt;div class="post-body entry-content"&gt;&lt;span id="6805768493000288333"&gt;&lt;a href="http://www.dp-news.com/Contents/Picture/Default/Israel-mouvements1.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" src="http://www.dp-news.com/Contents/Picture/Default/Israel-mouvements1.jpg" style="cursor: pointer; display: block; height: 200px; margin: 0px auto 10px; text-align: center; width: 280px;" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div&gt;&lt;span id="6805768493000288333"&gt;Computer hackers left tourists bemused after replacing a stately home's website with a message protesting Israeli foreign policy. Since about 4.30pm on Friday afternoon, visitors searching for details on Belvoir Castle, near Grantham, have instead found a black page displaying the Algerian flag and lines of text in Arabic.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;Last night, IT experts for the castle, the ancestral home of the Duke of Rutland, were still trying to remove the unwanted homepage – although the rest of the site appeared to still be accessible via Google. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "pub-2007752721372884";
/* 300x250, created 9/30/10 */
google_ad_slot = "2787040188";
google_ad_width = 300;
google_ad_height = 220;
//--&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;A spokesman for the castle said they had no idea why the early 19th century property had been targeted in such a manner. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;The number of so-called "defacement" attacks has risen in recent years, with hackers from countries such asEgypt, Turkey, Iran, Syria, Iraq, Saudi Arabia and Morocco hijacking sites. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;The Bank of Israel has previously been targeted with hackers posting anti-Israeli, anti-American and pro-Palestinian messages. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;The number of such attacks rocketed during the Israel-Lebannon conflict last year, with a number of sites seemingly unrelated to the conflict caught up in the digital vandalism. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;On this occasion, the hacker behind the attack appears to be someone who operates under the alias Blackhunter.dz and claims to be part of an Algerian subversive group called the Dz-SeC Team. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;He wrote the following, in Arabic, on the Belvoir Castle website: "The cause of this hack is Israel's presence in the 'Serfor'. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;"Internet law does not protect the ignorant. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;"Thank you to all the pirates of Algeria." &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;He then went on to thank 13 of his fellow hackers and post the web address of the collective's discussion forum. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;Internet expert Gary Warner, speaking to SC magazine in the aftermath of the Gaza conflict, said: "People are wanting to participate and support Palestine and they're finding ample opportunities through tools being created by hackers. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;"You can have almost no skills on the computer and take one of these hacker tools and start using it. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;"Anything on the internet that might get traffic is a valid target."&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="6805768493000288333"&gt;Source: &lt;a href="http://freehacking.net/"&gt;freehacking.net&lt;/a&gt; &lt;/span&gt;&lt;/div&gt;&lt;span id="6805768493000288333"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2208382470258337434-6856601218371830134?l=www.techkranti.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/BusvghrcxH65ydhDJxMfjqmkRpo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/BusvghrcxH65ydhDJxMfjqmkRpo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/BusvghrcxH65ydhDJxMfjqmkRpo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/BusvghrcxH65ydhDJxMfjqmkRpo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/Gotp/~4/C1tfX8WHbhE" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/blogspot/Gotp/~3/C1tfX8WHbhE/islamic-hackers-invade-website-of.html</link><author>noreply@blogger.com (Rahul Sachin Amey)</author><thr:total>0</thr:total><feedburner:origLink>http://www.techkranti.com/2010/09/islamic-hackers-invade-website-of.html</feedburner:origLink></item></channel></rss>

