Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, December 22, 2010

HOW FIREWALL WORKS

Hi All,
If you have been using Internet on a regular basis or working in a large company and surf the Internet while you are at work, you must have surely come across the term firewall. You might have also heard of people saying “firewalls protect their computer from web attacks and hackers” or “a certain website has been blocked by firewall in their work place”. If you have ever wondered to know what exactly is this firewall and how it works, here we go. In this post I will try to explain “How firewalls work” and proxy is also using as a firewall in some places.

How Firewalls Work

Firewalls are basically a barrier between your computer (or a network) and the Internet (outside world). A firewall can be simply compared to a security guard who stands at the entrance of your house and filters the visitors coming to your place. He may allow some visitors to enter while denying others whom he suspects of being intruders. Similarly a firewall is a software program or a hardware device that filters the information (packets) coming through the Internet to your personal computer or a computer network.
Firewalls may decide to allow or block network traffic between devices based on the rules that are pre-configured or set by the firewall administrator. Most personal firewalls such as Windows firewall operate on a set of pre-configured rules that are most suitable under normal circumstances so that the user need not worry much about configuring the firewall.
Personal firewalls are easy to install and use and hence preferred by end-users for use on their personal computers.  However large networks and companies prefer those firewalls that have plenty of options to configure so as to meet their customized needs. For example, a company may set up different firewall rules for FTP servers, Telnet servers and Web servers. In addition the company can even control how the employees connect to the Internet by blocking access to certain websites or restricting the transfer of files to other networks. Thus in addition to security, a firewall can give the company a tremendous control over how people use the network.
Firewalls use one or more of the following methods to control the incoming and outgoing traffic in a network:
1. Packet Filtering: In this method packets (small chunks of data) are analyzed against a set of filters. Packet filters has a set of rules that come with accept and deny actions which are pre-configured or can be configured manually by the firewall administrator. If the packet manages to make it through these filters then it is allowed to reach the destination; otherwise it is discarded.
2. Stateful Inspection: This is a newer method that doesn’t analyze the contents of the packets. Instead it compares certain key aspects of each packet to a database of trusted source. Both incoming and outgoing packets are compared against this database and if the comparison yields a reasonable match, then the packets are allowed to travel further. Otherwise they are discarded.

Firewall Configuration

Firewalls can be configured by adding one or more filters based on several conditions as mentioned below:
1. IP addresses: In any case if an IP address outside the network is said to be unfavorable, then it is possible to set  filter to block all the traffic to and from that IP address. For example, if a cetain IP address is found to be making too many connections to a server, the administrator may decide to block traffic from this IP using the firewall.
2. Domain names: Since it is difficult to remember the IP addresses, it is an easier and smarter way to configure the firewalls by adding filters based on domain names. By setting up a domain filter, a company may decide to block all access to certain domain names, or may provide access only to a list of selected domain names.
3. Ports/Protocols: Every service running on a server is made available to the Internet using numbered ports, one for each service. In simple words, ports can be compared to virtual doors of the server through which services are made available. For example, if a server is running a Web (HTTP) service then it will be typically available on port 80. In order to avail this service, the client needs to connect to the server via port 80. Similarly different services such as Telnet (Port 23), FTP (port 21) and SMTP (port 25) services may be running on the server. If the services are intended for the public, they are usually kept open. Otherwise they are blocked using the firewall so as to prevent intruders from using the open ports for making unauthorized connections.
4. Specific words or phrases: A firewall can be configured to filter one or more specific words or phrases so that, both the incoming and outgoing packets are scanned for the words in the filter. For example, you may set up a firewall rule to filter any packet that contains an offensive term or a phrase that you may decide to block from entering or leaving your network.

Hardware vs. Software Firewall

Hardware firewalls provide higher level of security and hence preferred for servers where security has the top most priority whereas, the software firewalls are less expensive and are most preferred in home computers and laptops. Hardware firewalls usually come as an in-built unit of a router and provide maximum security as it filters each packet in the hardware level itself even before it manages to enter your computer. A good example is the Linksys Cable/DSL router.

Why Firewall?

Firewalls provide security over a number of online threats such as Remote login, Trojan backdoors, Session hijacking, DOS & DDOS attacks, viruses, cookie stealing and many more. The effectiveness of the security depends on the way you configure the firewall and how you set up the filter rules. However major threats such as DOS and DDOS attacks may sometimes manage to bypass the firewalls and do the damage to the server. Even though firewall is not a complete answer to online threats, it can most effectively handle the attacks and provide security to the computer up to the maximum possible extent.

thank u...........

Saturday, December 4, 2010

What to Do when Ur Orkut is Hacked!

Hi All,

It can be a nightmare if someone else takes control of your Google Account because all your Google services like Gmail, Orkut, Google Calendar, Blogger, AdSense, Google Docs and even Google Checkout are tied to the same account.

Here are some options suggested by Google Support when you forget the Gmail password or if someone else takes ownership of your Google Account and changes the password:

1. Reset Your Google Account Password:
Type the email address associated with your Google Account or Gmail user name at google.com/accounts/ForgotPasswd - you will receive an email at your secondary email address with a link to reset your Google Account Password.
This will not work if the other person has changed your secondary email address or if you no longer have access to that address.

2. For Google Accounts Associated with Gmail:

If you have problems while logging into your Gmail account, you can consider contacting Google by filling this form. It however requires you to remember the exact date when you created that Gmail account.


3. For Hijacked Google Accounts Not Linked to Gmail:

If your Google Account doesn’t use a Gmail address, contact Google by filling this form. This approach may help bring back your Google Account if you religiously preserve all your old emails. You will be required to know the exact creation date of your Google Account plus a copy of that original “Google Email Verification” message.
It may be slightly tough to get your Google Account back but definitely not impossible if you have the relevant information in your secondary email mailbox.
 
thank u ..........

Wednesday, October 27, 2010

How To Convert File System,FAT32 to NTFS

Hi All,

file system may all you hear about this .so having some conversion here .
If your drive is FAT16/32 now using command prompt youcan change it to NTFS files system.
Let's go for steps
go to run and type cmd
open a dos prompt and give the command

convert (drive letter )d: /fs:ntfs
(warning :which drive you want to convert the drive data take backup before you gone for this)

this command would convert your d: drive to ntfs.

if the system cannot lock the drive, you will be prompted to convert it during next reboot.

Normally you should select yes.

Conversion from fat/fat32 to ntfs is non-destructive, your data on the drive will NOT be lost.

Be aware that converting to ntfs will make that partition of your
drive unreadable under dos unless you have ntfs utilites to do so.

thank u ..............

Sunday, October 24, 2010

FACEBOOK THIIRDPARTY APPLICATIONS LEAKING PERSONAL DATA

Hi All,

Facebook now a days compitation in social networking field for google. For security the Facebook takes many new rules(OTP) but the third party applications we are using in Facebook are leaking our personal data to the others .For example Games most of the social networking people plays the games in the net with friends before adding any application please check the privacy notice and remains .After verifing only add applications to your account.Now a days main source for hackers is games .Beware of it !

Saturday, October 23, 2010

Secure Sockets Layer (SSL) ?

Hi All,

Now a days You might have heard some times that not to give your password or credit card information or any other sensitive information on public computers or on Msn, yahoo etc chats.The reason why you might have heard that the Hackers have some ways to you would have probably heard that hackers have a way to steal your your credit card numbers , passwords etc.

A hacker can use different types of attacks such as Packet sniffing or ARP Poisoning to steal your sensitive information
 Secure Sockets Layer (SSL) is the most widely used technology for creating a secure communication between the web client and the web server. You must be familiar with http:// protocol and https:// protocol, You might be wondering what they mean. HTTP protocol is used for standard communication between the Web server and the client. HTTPS is used for a secure communication.Now a days banks and for online money transactions etc are using .


Cryptography

If two users want to have a secure communication they can also use cryptography to accomplish it.


For example:

TFDVSF=Encrypted Text

SECURE= Decrypted Text

You might be wondering how i Decrypted it, Here i have used Algorithm=+ for the communication and the key is "1", What comes after S is T so as you can see that S is converted into T, What comes After E is F to letter E from the word secure if converted into F and so on, To help you understand this more better I am adding a Video

So If the hacker starts sniffing from between he will get Encrypted text and as the Hacker does not know the keys so he cant decrypt it, but if the attacker or hacker is sniffing from the starting point so he will get the key and can easily Decrypt the data

Standard Communication VS Secure communication
Suppose there exists two communication parties A (client) and B (server)

Standard communication(HTTP)


When A will send information to B it will be in unencrypted manner, this is acceptable if A is not sharing Confidential information, but if A is sending sensitive information say "Password" it will also be in unencrypted form, If a hacker starts sniffing the communication so he will get the password.This scenario is illustrated using the following figure


Secure communication(HTTPS)




In a secure communication i.e. HTTPS the conversation between A and B happens to be in a safe tunnel, The information which a user A sends to B will be in encrypted form so even if a hacker gets unauthorized access to the conversion he will receive the encrypted password (“xz54p6kd“) and not the original password.This scenario is illustrated using the following figure




How is HTTPS implemented?

A HTTPS protocol can be implemented by using Secure Sockets Layer (SSL), A website can implement HTTPS by purchasing SSL certificate.

How to identify a Secure Connection?

In your browser, you will see a lock icon Picture of the Lock icon in the Security Status bar.  You can click the lock to view the identity of the website.

If you are making an online transaction through Credit card or any other means you should check if https:// secured communication is enabled.

Thursday, October 21, 2010

BackTrack 4 Hacking LiveCD For Download

Hi All,

 Most of the hackers are using this tool  for finding vulnerablities in the network.Mostly the penetrating tester are using this tool.BackTrack is a top rated linux live distribution focused on penetration testing. With no installation whatsoever, the analysis platform is started directly from the CD-Rom and is fully accessible within minutes.

 you can watch the preview of the backtrack tool  
Run Backtrack 4 Beta in Windows with VmWare Workstation 


Tools
  This release we have some special features such as spoonwep, fastrack and other cool additions.
Availability
For the first time we distribute three different version of Backtrack 4:
  • CD version
  • USB version
  • VMWare version
 Download:

BackTrack 4 R1 Release ISO click here

BackTrack 4 R1 Release VMware Image clickhere

Wednesday, October 20, 2010

Security/Hacking Tools

Hi All,

Now i am going to show some important tools for hacking/security.those are
1. Nmap
                Nmap (“Network Mapper”) is a free open source utility for network exploration or security auditing. It was designed to rapidly scan large networks, although it works fine against single hosts. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services means application name and version. those hosts are offering, what operating systems using with versions showing. they are running, what type of packet filters/firewalls are in use and other characteristics. Nmap runs on most types of computers and both console and graphical versions are available. Nmap is free and open source.

Download: click here

2. Nessus
                   Nessus is the world’s most popular vulnerability scanner used in over 75,000 organizations world-wide. Many of the world’s largest organizations are realizing significant cost savings by using Nessus to audit business-critical enterprise devices and applications.Recently went closed source.

Download: click here


3. John the Ripper
            John the Ripper is a fast password cracker, currently available for many flavors of Unix, DOS, Win32, BeOS, and OpenVMS. Its primary purpose is to detect weak Unix passwords. Besides several crypt password hash types most commonly found on various Unix flavors, supported out of the box are Kerberos AFS and Windows NT/2000/XP/2003 LM hashes, plus several more with contributed patches.

Download: click here

4. SuperScan
           Powerful TCP port scanner, pinger, resolver. SuperScan 4 is an update of the highly popular Windows port scanning tool, SuperScan.

Download: click here

5. Wireshark 
          Wireshark is  network protocol analyzer, or sniffer, that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and to give Wireshark features that are missing from closed-source sniffers.
Works great on both Linux and Windows .

Download: click here

6. PuTTY
       PuTTY is a free implementation of Telnet and SSH for Win32 and Unix platforms, along with an xterm terminal emulator. A must have for any h4x0r wanting to telnet or SSH from Windows without having to use the crappy default MS command line clients.

Download: click here

7. Cain and Abel
        My  favourite for password cracking of any kind.
Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols. The program does not exploit any software vulnerabilities or bugs that could not be fixed with little effort.

Download: click here

NSDECODER ( Website Malware Detection Tool)

Hi All,

NSDECODER is a automated website malware detection tool. It can be used to decode and analyze an URL to see if it host to malware. Also, NSDECODER will analyze which vulnerability has been exploited and the original source address of malware.
Functions
  • Automated analysis and detection of website malware.
  • Detection for plenty of vulnerabilities.
  • Log export supports HTML and TXT format.
  • Ability to deeply analyze JavaScript.
download :click here

Tuesday, October 19, 2010

Usb flash drive virus to block entering in to pc

Hi All,

Now a days many people are using flash disks for easy of data transmission. the drive when you connect to pc it autoplays .the virus makers are using this draw back they made lot of virus to damage the pc.for example autorun.inf ,recyller etc .so what to do?

Don't worry there is a solution .using some softwares you can avoid this and when you are going to open the drive instead of double click use explrer.Some softwares are here
Download: 1. usbdisksecurity from zbshareware
                   2. USBVaccineSetup from panda

Monday, October 18, 2010

Bootable Antivirus Rescue CD

Hi All,

Now i am going to show you when u facing serious problem with virus how to clean it from boot sector.using some antivirus rescue disk you can do this. some antivirus softwares are providing this service.Now i am going to show u here.Bootable antivirus Rescue CD method consider as the most effective way to remove the virus, trojan and malware because it track down some viruses, trojans and other malware are embedded so tightly into your operating system that when you boot Windows the normal way. Mostly virus is also loaded and cannot be detected or removed by antivirus software running in that system. In such a case, booting antivirus rescue CD under clean environment can increase chances to track down virus easily which there no interfere from any windows OS services.so we are using this method.here i am providing some rescue disks.

kaspersky Rescue Disk as Bootable DOS Antivirus :

1. Download Kaspersky Rescue Disk ISO file
2. Burn the Kaspersky Rescue Disk ISO image to a CD  using magic iso software.
3. Once finish burn Kaspersky Rescue Disk into bootable CD , insert Bootable kaspersky Rescue Disk CD into CD ROM and boot the computer by loading CD ROM media first.
4. Then a DOS screen will be loading below. Hit Enter to start booting the DOS Kaspersky AntiVirus using Linux. Kaspersky Rescue Disk startup
5. Finally a Kaspersky AntiVirus 2009 GUI  will be appear. Just check the hard drives that you want to scan virus or other malicious thread. Kaspersky AntiVirus 2009 GUI


Some other rescue cd providers are:
1.BitDefender Rescue CD.
2.F-Secure Rescue CD.
3. Avira Antivir Rescue Disk.
4. Trinity Rescue Kit CD.
5. AVG Rescue CD – Bootable AVG Antivirus CD / USB.
6. Shardana Antivirus Rescue Disc Utility.
7.Dr Web Live Bootable Antivirus CD.

and clean the virus and enjoy...........
source:www.techmixer.com

How to Reduce Spam

Hi all ,
Now a days when u login to your account u can see lot of spam in your account but most of the people are don't know how the spam is coming to our mail id's.the spamers using various methods to get the mail id's.now we are going for how to avoid like this spam using some simple steps .......

1.Using corporate email for personal use.
2.Avoid Posting email address on web pages.
3.Sending email to several external recipients
4. Mailing lists.
5.Do not automatically download images unless you trust the sender. 
6. Turn off read and delivery receipts and automatic processing of meeting requests .
7. Be careful where you post your e-mail address.
8.Never reply to spam.
9. Never forward chain e-mail messages. 
10.Use antivirus software which is included antispammer feature. 

Saturday, October 16, 2010

Careful with this...........? ctr+c and ctr+v

Hi All,
Be Very Careful with this..! ctr+c and ctr+v
We all copy various data by using ctrl+c/Copy for pasting elsewhere.
This copied data is stored on clipboard and is accessible over the net by a combination of javascripts and ASP.

Just try this:
1) Copy any text by ctrl+c
2) Click the Link: http://www.friendlycanadian.com/applications/clipboard.htm
3) You will see the text you copied on the Screen which was accessed by this web page.
Do not keep sensitive data (like passwords, creditcard numbers, PIN etc.) in the clipboard while surfing the web. It is extremely easy to extract the text stored in the clipboard to steal your sensitive information. If sufficient data is stored by mistake it would give away confidential and important information without you knowing about it.

To Avoid This
follow these steps:

1. Go to internet options->security

2. Press custom level

3. In the security settings, select disable under Allow paste operations via script.

Now the contents of your clipboard are safe.

Be secure while surfing the internet .

Email Threats

Hi All,
Here’s a look at the top three email threats . These are spam campaigns that delivered malware through attachments claiming to be documents or photos.
  1. Resume – The messages pumped out by this spam. look like they are from someone the recipient sent a resume to and tells them an edited and cleaned up version is attached. If that attached zip file is opened, a hidden .exe will quietly contact a remote server and download malware. This exploit is clearly designed to take advantage of the unemployment problem in the U.S. and is often sent to addresses harvested from job search sites like Monster and CareerBuilder. These messages are particularly sneaky because they are well written with no grammar or spelling errors, which is unusual for most spam.
  2. Docs – This campaign pumps out malicious spam that looks like it came from a legit company. The attachment claims to be important corporate documents but is actually malware. These messages even include a real company’s name, fax, and phone number.
  3. Air France – This is a more traditional spam . that uses the tried and true trick of exploiting a recently headline or pop culture phenomenon. In this case it claims to be providing exclusive photos of the Air France plane crash. Unlike the previous two threats, this one has the usual hallmarks of spam including broken English and is easy to spot.
  4. images: by sending some images are look like very cute .and putting some hidden tool in image whan u save or double click on image that will be activated. and trying to contact to hackers server.

Thursday, October 14, 2010

Facebook Introduces OTP (One-time Password) Functionality

Hi all now users can login with a one-time password that, upon request, Facebook zaps to their mobile phones. The temporary access code is good for 20 minutes only. The new feature is designed to prevent account compromises that result when credentials are entered into machines that have been compromised by keyloggers and similar types of malware.
“We’re launching one-time passwords to make it safer to use public computers in places like hotels, cafes or airports,”  “If you have any concerns about security of the computer you’re using while accessing Facebook, we can text you a one-time password to use instead of your regular password.”Jake Brill, a Facebook product manager.

Wednesday, October 13, 2010

Human error gave spammers keys to Microsoft systems


Microsoft blamed human error after two computers on its network were hacked and then misused by spammers to promote questionable online pharmaceutical websites.
Microsoft launched an investigation, after the problem was first reported in the Register. "We have completed our investigation and found that two misconfigured network hardware devices in a testing lab were compromised due to human error," Microsoft said  in a statement. "Those devices have been removed." After they were compromised, the two servers were to handle the DNS of more than 1,000 fraudulent pharmaceutical websites,  discovered the hacked Microsoft systems late lastweek while researching pharmaceutical spam. "This same group has hijacked quite a lot of machines all over the world," Guilmette said in an interview.


The devices that got hacked were "network devices that run a Linux kernel," Microsoft said.n addition to spam, at least one of the Microsoft computers was also used to launch a denial of service attack against a website belonging to Brian Krebs, Krebs believes that Russian-based pharmaceutical spammers were behind the attack on his site.


No customer data or production systems were affected by the attack, Microsoft said.
Microsoft has taken steps to improve its security in recent years, and has taken a hard-line stance against spam, so it's embarrassing to have company systems misused in this way.
"We are taking steps to better ensure that testing lab hardware devices that are Internet accessible are configured with proper security controls," Microsoft said.

Phishing Site of ICICI Bank

Hi friends,
A phish email created for ICICI Bank Users.
Sharing the screen-shots for fun. Have reported the fake site to antiphishing.org
The 'Phish' email:
 Phishing Site Link: http://adamthompson.org/infinity.update/BANKAWAY.sessionid/update;RetUser/Y&AppSignOn.icicibank.co.in/index.html

Tuesday, October 12, 2010

Using 'free' in search attracts malware

A study from McAfee finds that adding the word "free" when looking for entertainment content in search engines greatly increases the chances of landing on a site hosting malware.
For instance, searching for free music ringtones increases the chances of hitting a malicious site by 300 percent, according to the report, "Digital Music & Movies Report: The True Cost of Free Entertainment." Searching for "lyrics" for a particular artist is twice as risky on average as searching for "ringtones" for the same artist for the first five pages of results, the report found.
And including the term "MP3" increases the riskiness of music searches in general. There has been a 40 percent increase in the number of Web sites that are delivering infected MP3 files or that seem to be built for purposes of financial fraud or delivering malware, according to the report. Meanwhile, McAfee found malware associated with a number of Web sites around the world advertising free downloads of sports games, movies, and TV shows.

Redirection of Web traffic to China still a mystery

Six months after web traffic involving popular US sites and email from computers around the globe was re-directed to Chinese servers unnecessarily, internet watchers are trying to figure out why it happened and how to prevent future mishaps.
In at least two instances since mid-March, large amounts of traffic on the internet have been routed to China in circumstances still shrouded in mystery, Rodney Joffe, senior technologist at DNS (domain name system) registry Neustar, told CNET News in an interview this week.
The first situation happened on 24 March, when workers at network operation centers in various parts of the world noticed that traffic to popular sites like Facebook, Twitter, YouTube, and about 20 or 30 others was being redirected to servers in China as a result of traffic interception via one of the main DNS root servers. This had the result of giving web surfers in western countries a glimpse of what Chinese internet users see when they try to access sites that are blocked — error messages indicating that the sites don't exist or censored Chinese-language versions of the sites. It's unknown how long the situation lasted, according to Joffe.
Joffe would not name the companies whose traffic was diverted through China, but said it was a "large number of well-known organizations," including many departments of the U.S. government and almost every Fortune 500 in the U.S. Traffic originating near or in the Asia Pacific region had a higher chance of going through China.
He said he could not explain exactly what happened or why. "I have no visibility into what China did," Joffe said.
And he said he believes there were more instances of Web traffic being diverted to China, or "hijacked," around that time, but wouldn't elaborate. "I believe it happened more than twice," Joffe said. "I can't comment on how many times because the information is not generally public.

Monday, October 11, 2010

India plans to write its own OS

THE INDIAN GOVERNMENT wants to write its own PC operating system (OS) rather than rely on Western technologies.

India's Defence Research and Development Organisation (DRDO) wants to build an OS, primarily so India can own the source code and architecture. That will mean the country won't have to rely on Western operating systems that it thinks aren't up to the job of thwarting cyber attacks. The DRDO specifically wants to design and develop its own OS that is hack-proof to prevent sensitive data from being stolen.

According to the Economic Times in India, the DRDO already has most of the infrastructure to build the OS in place. It has 50 scientists and IT specialists located in New Delhi and Bangalore spearheading a national effort to create the OS.

Dr V K Saraswat, scientific adviser to the Defence Minister said that the OS was needed to protect India's economic framework.

"In today's world where you have tremendous requirements of security on whatever you do ... economy, banking and defence ... it's essential that you need to have an operating system," said Saraswat.

"The only way to protect it is to have a home-grown system, the complete architecture ... source code is with you and then nobody knows what's that," he added.

Sify also reported Saraswat's comments that the OS will be proprietary.

"Though it will be a real-time system with Windows software, source code and architecture will be proprietary, giving us the exclusivity of owning a system unknown to foreign elements and protect our security system," he added.

The news comes as the Indian government, like others, has been leaning on RIM so it can access communications on Blackberry smartphones.

We cannot help but both admire such an ambitious undertaking and wonder how well the Indian government has really thought all this out. We also imagine that it might be a few years before it will be worth asking whether India has actually gotten anywhere with this project. so we can find indian os soon

Friday, October 8, 2010

How to remove Logo1_.exe virus

HI friends you suffer from logo1_.exe virus don't worry ,Here is what you exactly do to remove the Logo1_.exe virus:

1. open task manager and look for the process logo1_ and terminate it

2. now go to c:/windows and delete logo1_.exe file

3. create a copy of any exe file ( I used TASKMAN ) and rename it to Logo1_

4. change its permissions to read only.

Popular Posts

Followers

Disclaimer

All Data and Information Provided on This BLOG is only for Education purposes only.If you done any thing else these in real time the blog is not Responsible.Try all those on your own risk.
IF you find any thing else here as per in violation of copyright law .mail me on srinathceh@gmail.com as soon as possible action will be taken.