Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, May 9

Hide files in the files for better security of the data: using the program executable files to hide data with steganography

Ultimate Zip Cracker Software Download

A new approach of AScienceDaily (May 9, 2011) to hide the data within the program files on a computer could make it nearly impossible to detect hidden documents, according to a report International Journal of Internet technology and secured.

Steganography is a form of security through obscurity information hidden inside the medium. An artist might paint a message encoded into a portrait, for instance, or author to embed lyrics in the text. Traditional paper watermark is an example of steganography is in action. At first glance, it appears that there is nothing unusual, but the recipient aware of the presence of hidden message can be extracted easily. In computer science, more than the art of steganography.

These target to hide information from prying eyes to embed data in many different file types that are ostensibly (mp3) of music, photos (jpeg), video (mpeg4) or word processing documents. Unfortunately, there is no limit to the amount of hidden data can be embedded in such files without this information becomes clear something is hidden because the file size increases beyond what can be expected for shared music or video file, for example. A music file to mp3 format in five minutes as the sampling rate of 128 kilobits per second, for example, is expected to be 5 megabytes in size. Much bigger aroused suspicions about the true nature of the file, a software mp3-tags in the open, something is wrong with the content of the file. This can be said for almost any other file types.

However, one set of files and their size, they are usually quite difficult to examine in detail that they provide compile computer code are the executable files or exe. These files tend to contain a lot of what might be described as "spam", as well as internal and programmer notes, redundant code snippets, some senses infuriatingly inflate code. All this adds up large file sizes and random fact for the .exe files. As such, it may be possible to embed and hiding large amounts of data in an encrypted file without disrupting the ability of the executed file, or run a program but ???????? without anyone discovering the file exe has a dual function.

Computer scientists Rajesh Kumar Tiwari of GLNA at Mathura, g., Sahoo of birla Institute of technology, Mesra, Ranchi, India, developed this algorithm for embedding hidden data in the session. They provide information International Journal of Internet technology and secured transactions. The algorithm built into the program with a graphical user interface will take the conventional exe file as input hidden data, merge the two producing sustainable exe file with the hidden content. The technology can be used on smart phones, tablet PCs, portable media players or any other information which a user may want to hide data.

Email or share this story:


The source of the story:

The above story printed (with writers adaptations by a teamdaily science) from materials provided by publishers, Inderscience, via EurekAlert!, a service of AAAS.

Note: If no source is cited, instead.

Disclaimer: hdioth in this article do not necessarily reflect those of his team or ScienceDaily.

Ultimate Zip Cracker Software Download

Wednesday, April 6

Looking for blue sky cloud security

Ultimate Zip Cracker Software Download

ScienceDaily (6 month 2011) cloud computing represents a significant change in how we use information technology. Digital file storage space, processing power and software services away from the abstract of the user himself access to computing over the Internet. Google's online office software, the player's new Amazon Cloud, a photo gallery like Flickr are examples of cloud services. Users can work with and use their data on the number of devices and networks almost anywhere for free or by the payment service provider.

Researchers Kashif Kifayat, Madjid Merabti, Qi Shi of the University of Liverpool, John Morse, United Kingdom, outside this cloud computing has many advantages, including a high degree of redundancy in the hardware and software levels and geographic independence as well. Cloud services to cope with increases in individual user demand of the user without the user having to upgrade their system. However, there are concerns about security and other risks. After all, users rely on a service provider with potentially sensitive data, as well as the need to deal with the option of terminating a system which may disturb their workflow significantly.

International Data Corporation CITES team who analysed the worldwide forecast for cloud in 2009 of the order of us $ 17, and assessing. 4bn for 2013 as may revenues at a rate of. 2bn show us $ 44; The European market range from $971 m in 2008 to us $ 6, 500 m in 2013. In terms of sky blue, the future is almost certain of snow. However remember, availability, manageability, control, data protection, privacy and security, and scalability are all issues that do require urgently. Security and privacy in the current model is based on the paradigm of the desktop on the network as opposed to the connected cloud computers "fool"

"When the sensitive and regulated goes into the cloud, specific security issues that include authentication, access control, encryption, data leak protections, regulatory reporting, virtualization technologies across multiple geographies," explains team. "Why the future of cloud computing will raise the level of complexity and scalability that will trigger the security problems."

Email or share this story:


The source of the story:

The above story is published (with writers adaptations by a teamdaily science) materials supplied Inderscienceby, via AlphaGalileo.

A journal:

  1. Kashif Kifayat, Madjid Merabti, Qi Shi. Future security challenges in cloud computing. International Journal of multimedia intelligence and security, 2010; 1 (4): 428: 10.1504, DOI IJMIS. 2010.039241

Note: If no source is cited, instead.

Disclaimer: hdioth in this article do not necessarily reflect those of his team or ScienceDaily.

Ultimate Zip Cracker Software Download

Thursday, March 24

Two new documents of SCAP help improve your computer's security management automating

Ultimate Zip Cracker Software Download

ScienceDaily (16 March 2011) increasingly difficult to keep track of all vulnerabilities present complex in today's operating systems and applications. Attackers look for all the time, to exploit these vulnerabilities to take the identity fraud, plagiarism and other. National Institute of standards and technology (NIST) has released two publications updated to help organizations find and manage vulnerabilities more effectively, by standardizing the vulnerabilities identified, prioritized, and they are reported.

The security departments of computer work behind the scenes in all government ministries and other organizations to secure computers and networks. Valuable tools for software security automation is that of the NIST security content automation protocol (SCAP). SCAP-based software can be used to automatically check for individual computers to see if they have any known vulnerabilities, and if they have the appropriate security settings instead of corrections. Security issues can be identified quickly and accurately, allowing them to resolve before hackers can exploit them.

The first publication, the technical specification for the security content automation protocol (SCAP) version 1.1 (NIST Special publication (SP) 800-126 last 1) refines the requirements of the Protocol SCAP version 1.0. SCAP is a suite of specifications for standardizing the format and terminology that relate to security software to evaluate software flaws, security and software configurations.

SP 800-126 Rev. 1 tightens the requirements and specifications of individual suite to support the functionality of the SCAP and ensure interoperability between SCAP tools. It also adds a new specification-open checklist interactive language (OCIL)-which allows security professionals to collect information that is not accessible by means of automatic. For example, you can use OCIL ask users about security awareness training, or prompts the administrator to review security settings is available only through a proprietary graphical user interface. In addition, SCAP 1.1 reader for version 8.0 of the open vulnerability and assessment language (Oval).

NIST and others provide a publicly accessible stores of information security and standard security configurations, you can download templates SCAP and used by the Protocol SCAP compatible tools. For example, NIST national vulnerability database (NVD) provides a unique identifier for each vulnerability reported software, analysis of potential damage, specifies risk. NVD grew in 2002 about 6,000 drawings 46,000 in early 2011. It is updated daily.

The second document, a guide to using the vulnerability naming scheme (Special Edition publication 800-53-1), provides recommendations for naming schemes used by SCAP. Before these were standard, various organizations vulnerabilities in different ways, which created confusion. These naming schemes "may be a better synthesis of information about vulnerabilities in software," explained co-author David Waltermire, minimizes confusion and can lead to faster security patches. Common vulnerabilities and exposures (CVE) identification of defects in the software; A common configuration enumeration (CCE) is the configuration problems.

SP 800-68 Rev. 1 provides an introduction to the two naming schemes, recommends their use. It also offers some of the providers of software and services you need to use the names of the vulnerability and naming their products, service offerings.

These new publications can be downloaded from NIST. Technical specification for the security content automation protocol (SCAP) version 1.1 (NIST Special Publication 800-126 last 1) can be found on http://csrc.nist.gov/publications/nistpubs/800-126-rev1/SP800-126r1.pdf. You can find the vulnerability naming scheme (Special Edition publication 800-53-1) in http://csrc.nist.gov/publications/nistpubs/800-51-rev1/SP800-51rev1.pdf.

Email or share this story:


The source of the story:

The above story printed (with writers adaptations by a teamdaily science) from materials that can be by the National Institute of standards technology (NIST).

Note: If no source is cited, instead.

Disclaimer: hdioth in this article do not necessarily reflect those of his team or ScienceDaily.

Ultimate Zip Cracker Software Download

Friday, March 4

A new publication from the Federal information security risk management

Ultimate Zip Cracker Software Download

ScienceDaily (2 March 2011) , the National Institute of standards and technology (NIST) published the final version of special publication that can help organizations to more effectively integrate information security planning and goals of their mission-critical functions.

Enterprise: security information management, mission, and system information (NIST Special Publication 800-39) provides the basics of a three-tiered, risk-management approach changes fundamentally how we manage information security risk to the federal level, "says Ron Ross, a NIST and the main authors of the publication.

For decades, organizations have to manage risk at the level of the information system, which resulted in a very narrow perspective that constrain risk-based decisions by senior management, explains Ross. SP 800-39 calls for a holistic approach to determine what senior leaders need to be protected is based on the core tasks of the Organization, and business functions. For example, administrators of power distribution network is related to the need to ensure the security of your computer keeps hackers interfering with the plant's power generation or to get into the power grid to bring disaster.

The publication is the fourth in a series of risks and manage information security guidelines developed by the joint task force transformation initiative, a joint partnership between the Department of Defense, intelligence community, Committee on national security systems, NIST.

A risk management approach to the multi-tiered described SP 800-39 organization progress for information systems. The goal is to ensure that the strategic considerations and decisions with respect to drive investment in operational risk management organizational operations (including mission, functions, image, and reputation), organizational assets, individuals, other organizations (collaborative or partnering with federal agencies and contractors), the nation.

This type of risk-based decisions, is critical as organizations advanced persistent threats of sophisticated cyber attacks that may harm or weakened the support information systems in the Federal Government's critical applications.

"SP 800-39 is engaged in building a more secure information systems ultimately will allow senior leaders, and administrators better understand the mission, the risk to their business brought by organizations to increasingly use information technology and connectivity, dependency ???"???? Ross.

SP 800-39, security information management: Organization, mission and display of information system, developed in support of federal information security management Act (FISMA). Can be downloaded from http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf.

Email or share this story:


The source of the story:

The above story printed (with writers adaptations by a teamdaily science) from materials that can be by the National Institute of standards technology (NIST).

Note: If no source is cited, instead.

Disclaimer: hdioth in this article do not necessarily reflect those of his team or ScienceDaily.

Ultimate Zip Cracker Software Download

Tuesday, March 1

Security and privacy issues in PDF

Ultimate Zip Cracker Software Download

Facultad de Informática UPM researchersScienceDaily (Feb. 22, 2011) compiled information about security and privacy for authors or readers of PDF documents, the most popular format for publishing of digital documents.

This work by researchers from Facultad de Informática de Madrid Universidad Politécnica set of privacy threats security surveys related to a digital document. It handles information related to your publisher that he leaked after the document is sent over the Internet, as well as information related to the reader that can be downloaded each time they open for inspection. The work focuses primarily on the PDF document format is the most popular digital document publication.

Publishing digital documents on the Internet is a serious security and privacy threats to authors and readers. Previous research by scholars in the distributed systems laboratory of the Facultad de Informática of UPM is leaking information addressed in the FAQ of a Microsoft Office document. This study focuses on PDF format, which is the de facto standard for document exchange. Many institutions around the world have adopted PDF as a standard, their estimated that billions of PDF documents that are published or downloaded each day. The results of this research were baiomn of systems and software.

Published documents can contain additional data related to the author, such as user name, the location of the document's author, even parts of deleted documents before publication.

Some of this information, such as user name or the last day of the document was referred to as metadata, applications use the reader or editor to improve the user experience; However, they may cause privacy breaches, mainly because the authors are not aware of their discovery to publish the document. Other sensitive information leaked due to poor design of the document template. For example, whenever a paragraph of a document is deleted, the paragraph did not remove the PDF but rather than mark it as "invisible". In this way, the calling application did not imagine the text that was deleted when the document is opened for reading. Therefore deleted data is saved with the document, can be read by any malicious user who knows where to find it. UPM researchers developed several tools to extract information from PDF document readers that are inaccessible.

Information leakage prevention

There are cases where many popular publication document costs a lot more information than the publishers is to communicate. For example, the Coalition Provisional Authority of Iraq post the PDF on "event" Calipari Sgrena-May 2005. Black boxes were used to hide the names of some of the people involved in the incident, but all were discovered easily by copying the text from the original document into a text editor. Several companies and institutions have distributed instructions to avoid leaking information in documents released after the reported news about documents published on the Internet that contains sensitive information that was not supposed to be made public.

From the perspective of the reader, open a downloaded PDF document could expose sensitive information such as IP address of the user's computer, user name, potentially other information stored on the computer that is used to open the document. The reason for this is the interactive features of PDF applications. You can automatically run a number of actions, such as connecting to a Web site or read data from the disk each time a PDF is opened for reading. Ideally, you should warn the user of the risks of action taken, OK. This study emphasized that in many settings, particularly when you open a PDF inside a Web browser, are caused when performing actions without notice to the user or the agreement. Their work, researchers describe how UPM it will be possible to recall and information about all of the user who downloads the PDF reader.

Finally, the researchers believe that UPM PDF format is a medium powerful document conversion. The main purpose of their work is to make users aware of the risks that they face each time they publish a document on the Internet and to provide time guidelines effective to reduce the leakage of sensitive information.

Email or share this story:


The source of the story:

The above story is published (with writers adaptations by a teamdaily science) materials provided by Facultad de Informática de la Universidad Politécnica de Madrid.

A journal:

  1. Aniello Castiglione, Alfredo de Santis, Claudio Soriente. Security and privacy as portable document format. Journal of systems and software, 2010; 83 (10): DOI: 10.1016/1813 j. jss. 2010.05 .062

Note: If no source is cited, instead.

Disclaimer: hdioth in this article do not necessarily reflect those of his team or ScienceDaily.

Ultimate Zip Cracker Software Download

Friday, February 25

Security and privacy issues in PDF

Ultimate Zip Cracker Software Download

UPM researchers Facultad de Informática ScienceDaily (22 February 2011) compile information about the security and privacy for authors or readers of PDF documents, the most popular format for publishing digital documents.

This work by researchers Facultad de Informática of the Universidad Politécnica de Madrid surveys security privacy threats related to digital document publication. It handles information related to publisher, it is revealed after the document is sent over the Internet, as well as information related to the reader may be downloaded every time they open for examination. The work focuses on primarily the PDF format is the most popular document format document for publishing a digital document.

Publishing digital documents on the Internet is a serious security and privacy threats to editors and readers. Previous research by scholars laboratory distributed systems of UPM Facultad de Informática discusses popular document formats information through Microsoft Office. This study focuses on PDF format, which is the de facto standard for exchanging a digital document. Many institutions around the world have adopted PDF as a standard, and have their has been estimated that billions of PDF documents are published, or downloaded every day. Results of this study were published in Journal of systems and software.

Published documents may include additional data related to the author, such as user name, placing the document on the connector computer and also deleted documents before publication.

Some of this information, such as user name or the last day of the Conference are called document meta-data, applications, use reader or editor to improve the user experience; However, they lead to privacy breaches, mainly because the authors are not aware of their discovery to publish the document. Other sensitive information was leaked due to poor design of the document template. For example, when a paragraph of document is deleted, the PDF will not remove the applications of the paragraph, but instead mark it as "invisible". In this way, the calling application did not imagine the deleted when the document is opened for reading. Hence the deleted data is saved with the document, can be read by any malicious user knows where to find it. UPM researchers developed several tools to extract information from PDF documents that are inaccessible to a regular document.

Preventing information loss

There are many popular events that publication of the document is far more information than game publishers is to communicate. For example, the temporary authority of coalition in Iraq publish PDF Sgrena incident in "Calipari" May 2005. Black boxes were used to hide the names of some of the people involved in the incident, but all were easily by copying the text from the original document into a text editor. A number of companies and institutions has distributed guidelines to prevent information loss in documents published after the media reporting news about documents published on the Internet containing sensitive information should not be made.

In terms of reader, open a downloaded PDF document can reveal sensitive information like the IP address of the user's computer, potentially username and any other information that is stored on the computer that is used to open the document. The reason for this is the interactive features of applications in PDF. You can run multiple actions at once, like to connect to the Web site or read data from disk automatically every time the PDF is opened for reading. Ideally, you should warn the user risks of photography, has requested the certificate. This study has many settings that, especially when you open a PDF document inside a Web browser, not caused to the user or the agreement without notice. Their work, researchers UPM vmtoda how do I retrieve and of information about each user who downloads and reads of the PDF.

Finally, the researchers believe the PDF template UPM is a powerful document exchange medium. The main purpose of their work is to make users aware of the risks that they face every time they publish a document on the Web to provide guidance effective to reduce the leakage of sensitive information.

Email or share this story:


Story source:

The story above printed (with adapting to editing by a team of the day-to-day science) materials provided by Facultad de Informática de la Universidad Politécnica de Madrid.

a journal:

  1. Aniello Castiglione, Alfredo de Santis, Claudio Soriente. Security and privacy in Portable Document Format. Journal of systems and software, 2010; 83 (10): doai 1813: 10.1016/j. jss. .062 04 2010.

Note: you mentioned if not counting, the source is when instead.

Disclaimer: opinions in this article do not necessarily reflect those of its employees or ScienceDaily.

Ultimate Zip Cracker Software Download

Thursday, February 17

Sharing security weaknesses that methods revealed bkliniim

Ultimate Zip Cracker Software Download

In patients ScienceDaily (17 February 2011) to participate in clinical expect their personal information will remain confidential, but recent research led by Dr. Khaled El Emam, Canada Research Chair of the information a Health Research Institute, CHEO found that security practices is used to transmit and share sensitive files is not sufficient.

Study into two parts, titled "how strong are the passwords used to protect personal health information bklini tests?," was published on 16 February Journal of medical Internet research, showed that most of the passwords used to protect files designed in easily snapped my weak password recovery utility to commercial. Research Coordinator interviews indicates that information shared in the context of the clinical studies could compromise your medical information.

"The hospital attempts these viewers that their personal information will be protected," said Dr. El Emam. "It is critical for maintaining the trust of clinical trial participants, and the public in General."

During the research, passwords for sensitive 14/15 files transmitted by e-mail were decoded successfully. Of these, 13 contained sensitive information that can identify health and other research site name, birth dates, acronyms, and gender. File sharing were also found with unsecured, unencrypted patient information shared via email and best practices posted on shared drives with common passwords.

"Decrypt passwords proved to be trivial," said Dr. El Emam. "Choices include simple passwords such as a car (for example," Nissan "), and common sequences (e.g.," 123 "). It was easier to guess the password recovery tool. "

Poor security practices can damage in patients participating in clinical, risk identified, and perhaps even stigmatized by the disclosure of medical information. You also have the option of both medical and medical identity theft. In the context of international clinical studies, the disclosure of medical information absently is considered a violation of data in countries like the United States, can lead to penalties in some countries.

Dr. El Emam believes that with effort sharing file bkliniim can be made secure: "there are protocols and tools that secure file sharing. It may take more effort on the part of those who manage clinical, but the alternative is not acceptable. "

Dr. El Emam makes several recommendations, including the enforcement of strong passwords and algorithms of encryption, encrypt all information sent via e-mail including site queries and minimize sharing password.

The research was funded by the natural sciences and Engineering Research Council of Canada (NSERC) Canada Research Chair program.

Email or share this story:


Story source:

The story above printed (with adapting to editing by a team of the day-to-day science) materials provided by the Institute of children's Hospital of Eastern Ontario Research.

a journal:

  1. Khaled El Emam, Catherine Moreau, Elizabeth Jonker. How to use strong passwords to protect your personal information to a health clinical? Journal of medical Internet research, 2011; 13 (1) 10.2196/jmir doai: .1335

Note: you mentioned if not counting, the source is when instead.

Disclaimer: this article is not intended to provide medical advice, diagnosis or treatment. Opinions here do not reflect necessarily the ScienceDaily or its employees in these.

Ultimate Zip Cracker Software Download

Thursday, September 3

Top 5 Myths About Safe Surfing

Ultimate Zip Cracker Software Download
Recently PC Magazine conducted a survey that asked participants to rate their broadband ISP services. We found out that many users don't completely understand the seriousness of potential threats or how to protect their PCs. The following are responses to the top five security misconceptions we encountered.

I don't keep important things on my PC, so I don't have to worry about security.


There was a time when this statement was partially true, but that time has long since passed. Current viruses, worms, and other threats, including the famous Love Bug, Nimda, and Blaster, spread blindly across the Internet to thousands or millions of PCs in a matter of hours, without regard for who owns them, what is stored there, or the value of the information they hold. The purpose of such attacks is nothing less than to wreak havoc. If you ignore the reality of these attacks, you are certain to be hit at one time or another. Even if your computer is not attacked directly, it can be used as a zombie to launch a denial-of-service or other attack on a network or to send spam or pornography to other PCs without being traced. Therefore, your civic responsibility is to protect your PC so that others are protected.

I can protect my PC if I disconnect from the Internet or turn it off when I'm not using it.

Wrong. If you connect to the Internet at all, you are a target. You could download a virus when you connect and not activate it until days later when you read your e-mail off-line. Even if you rarely connect to the Internet, you can get a virus from a file off of a network, floppy disk, or USB flash memory drive.

I can protect myself from viruses by not opening suspicious e-mail attachments.

Wrong again. The next virus you get may come from your best friend's or boss' computer if his e-mail address book was used to propagate an attack. Nimda and other hybrid worms can enter through the Web browser. And it is possible to activate some viruses simply by reading or previewing an e-mail. You simply must have a PC-based antivirus package.

I have a Macintosh (or a Linux-based system), not a Windows system, so I don't have to worry about being attacked.

It is true that most attacks target Microsoft Windows–based PCs, but there have been attacks against Mac OS and Linux systems as well. Some experts have predicted that the Mac virus problem will get worse, because Mac OS X uses a version of Unix. And although these systems have some useful security features, they can still be attacked.

My system came with an antivirus package, so I'm protected.

Not quite. First, if you haven't activated your antivirus package to scan incoming traffic automatically, you are not protected against e-mail and Web browser attacks. Second, new threats appear daily, so an antivirus package is only as good as its last update. Activate the auto-update features to stay on top of the latest threats. Third, an antivirus package can't protect you from every threat. In most cases you need a combination of solutions, including, at minimum, antivirus, a personal firewall such as Zone Labs' ZoneAlarm Pro, and a plan for keeping your operating system and software up to date with security patches. Antispyware and antispam utilities (such as PepiMK Software's SpyBot Search & Destroy and Norton AntiSpam 2004) will also help keep you safe.
Ultimate Zip Cracker Software Download

Tuesday, September 1

Closing Open Holes in Windows

Ultimate Zip Cracker Software Download
With the spread of Hackers and Hacking incidents, the time has come, when not only system administrators of servers of big companies, but also people who connect to the Internet by dialing up into their ISP, have to worry about securing their system. It really does not make much difference whether you have a static IP or a dynamic one, if your system is connected to the Internet, then there is every chance of it being attacked.

This manual is aimed at discussing methods of system security analysis and will shed light on as to how to secure your standalone (also a system connected to a LAN) system.

Open Ports: A Threat to Security?

In the Netstat Tutorial we had discussed how the netstat -a command showed the list of open ports on your system. Well, anyhow, before I move on, I would like to quickly recap the important part. So here goes, straight from the netstat tutorial:

Now, the ??a? option is used to display all open connections on the local machine. It also returns the remote system to which we are connected to, the port numbers of the remote system we are connected to (and the local machine) and also the type and state of connection we have with the remote system.

For Example,

C:\windows>netstat -a

Active Connections


Proto Local Address Foreign Address State
TCP ankit:1031 dwarf.box.sk:ftp ESTABLISHED
TCP ankit:1036 dwarf.box.sk:ftp-data TIME_WAIT
TCP ankit:1043 banners.egroups.com:80 FIN_WAIT_2
TCP ankit:1045 mail2.mtnl.net.in:pop3 TIME_WAIT
TCP ankit:1052 zztop.boxnetwork.net:80 ESTABLISHED
TCP ankit:1053 mail2.mtnl.net.in:pop3 TIME_WAIT
UDP ankit:1025 *:*
UDP ankit:nbdatagram *:*


Now, let us take a single line from the above output and see what it stands for:

Proto Local Address Foreign Address State
TCP ankit:1031 dwarf.box.sk:ftp ESTABLISHED

Now, the above can be arranged as below:

Protocol: TCP (This can be Transmission Control Protocol or TCP, User Datagram Protocol or UDP or sometimes even, IP or Internet Protocol.)

Local System Name: ankit (This is the name of the local system that you set during the Windows setup.)

Local Port opened and being used by this connection: 1031

Remote System: dwarf.box.sk (This is the non-numerical form of the system to which we are connected.)

Remote Port: ftp (This is the port number of the remote system dwarf.box.sk to which we are connected.)

State of Connection: ESTABLISHED

?Netstat? with the ??a? argument is normally used, to get a list of open ports on your own system i.e. on the local system. This can be particularly useful to check and see whether your system has a Trojan installed or not. Yes, most good Antiviral software are able to detect the presence of Trojans, but, we are hackers, and need to software to tell us, whether we are infected or not. Besides, it is more fun to do something manually than to simply click on the ?Scan? button and let some software do it.

The following is a list of Trojans and the port numbers which they use, if you Netstat yourself and find any of the following open, then you can be pretty sure, that you are infected.



Port 12345(TCP) Netbus
Port 31337(UDP) Back Orifice

For complete list, refer to the Tutorial on Trojans at: hackingtruths.box.sk/trojans.txt
----

Now, the above tutorial resulted in a number of people raising questions like: If the 'netstat -a' command shows open ports on my system, does this mean that anyone can connect to them? Or, How can I close these open ports? How do I know if an open port is a threat to my system's security of not? Well, the answer to all these question would be clear, once you read the below paragraph:

Now, the thing to understand here is that, Port numbers are divided into three ranges:

The Well Known Ports are those from 0 through 1023. This range or ports is bound to the services running on them. By this what I mean is that each port usually has a specific service running on it. You see there is an internationally accepted Port Numbers to Services rule, (refer RFC 1700 Here) which specifies as to on what port number a particular service runs. For Example, By Default or normally FTP runs on Port 21. So if you find that Port 21 is open on a particular system, then it usually means that that particular system uses the FTP Protocol to transfer files. However, please note that some smart system administrators delibrately i.e. to fool lamers run fake services on popular ports. For Example, a system might be running a fake FTP daemon on Port 21. Although you get the same interface like the FTP daemon banner, response numbers etc, however, it actually might be a software logging your prescence and sometimes even tracing you!!!

The Registered Ports are those from 1024 through 49151. This range of port numbers is not bound to any specific service. Actually, Networking utlites like your Browser, Email Client, FTP software opens a random port within this range and starts a communication with the remote server. A port number within this range is the reason why you are able to surf the net or check your email etc.

If you find that when you give the netstat -a command, then a number of ports within this range are open, then you should probably not worry. These ports are simply opened so that you can get your software applications to do what you want them to do. These ports are opened temporarily by various applications to perform tasks. They act as a buffer transfering packets (data) received to the application and vis-a-versa. Once you close the application, then you find that these ports are closed automatically. For Example, when you type www.hotmail.com in your browser, then your browser randomly chooses a Registered Port and uses it as a buffer to communicate with the various remote servers involved.

The Dynamic and/or Private Ports are those from 49152 through 65535. This range is rarely used, and is mostly used by trojans, however some application do tend to use such high range port numbers. For Example,Sun starts their RPC ports at 32768.
So this basically brings us to what to do if you find that Netstat gives you a couple of open ports on your system:

1. Check the Trojan Port List and check if the open port matches with any of the popular ones. If it does then get a trojan Removal and remove the trojan.

2. If it doesn't or if the Trojan Remover says: No trojan found, then see if the open port lies in the registered Ports range. If yes, then you have nothing to worry, so forget about it.

***********************
HACKING TRUTH: A common technique employed by a number of system administrators, is remapping ports. For example, normally the default port for HTTP is 80. However, the system administrator could also remap it to Port 8080. Now, if that is the case, then the homepage hosted at that server would be at:

http://domain.com:8080 instead of
http://domain.com:80

The idea behind Port Remapping is that instead of running a service on a well known port, where it can easily be exploited, it would be better to run it on a not so well known port, as the hacker, would find it more difficult to find that service. He would have to port scan high range of numbers to discover port remapping.

The ports used for remapping are usually pretty easy to remember. They are choosen keeping in mind the default port number at which the service being remapped should be running. For Example, POP by default runs on Port 110. However, if you were to remap it, you would choose any of the following: 1010, 11000, 1111 etc etc

Some sysadmins also like to choose Port numbers in the following manner: 1234,2345,3456,4567 and so on... Yet another reason as to why Port Remapping is done, is that on a Unix System to be able to listen to a port under 1024, you must have root previledges.
************************


Firewalls

Use of Firewalls is no longer confined to servers or websites or commerical companies. Even if you simply dial up into your ISP or use PPP (Point to Point Protocol) to surf the net, you simply cannot do without a firewall. So what exactly is a firewall?

Well, in non-geek language, a firewall is basically a shield which protects your system from the untrusted non-reliable systems connected to the Internet. It is a software which listens to all ports on your system for any attempts to open a connection and when it detects such an attempt, then it reacts according to the predefined set of rules. So basically, a firewall is something that protects the network(or systen) from the Internet. It is derived from the concept of firewalls used in vehicles which is a barrier made of fire resistant material protecting the vehicle in case of fire.

Now, for a better 'according to the bible' defination of a firewall: A firewall is best described as a software or hardware or both Hardware and Software packet filter that allows only selected packets to pass through from the Internet to your private internal network. A firewall is a system or a group of systems which guard a trusted network( The Internal Private Network from the untrusted network (The Internet.)

NOTE: This was a very brief desciption of what a firewall is, I would not be going into the details of their working in this manual.

Anyway,the term 'Firewalls', (which were generally used by companies for commerical purposes) has evolved into a new term called 'Personal Firewalls'. Now this term is basically used to refer to firewalls installed on a standalone system which may or may not be networked i.e. It usually connects to an ISP. Or in other words a personal firewall is a firewall used for personal use.

Now that you have a basic desciption as to what a firewall is, let us move on to why exactly you need to install a Firewall? Or, how can not installing a firewall pose a threat to the security of your system?

You see, when you are connected to the Internet, then you have millions of other untrusted systems connected to it as well. If somehow someone found out your IP address, then they could do probably anything to your system. They could exploit any vulnerability existing in your system, damage your data, and even use your system to hack into other computers.

Finding out someone'e IP Address is not very difficult. Anybody can find out your IP, through various Chat Services, Instant Messengers (ICQ, MSN, AOL etc), through a common ISP and numerous other ways. Infact finding out the IP Address of a specific person is not always the priority of some hackers.

What I mean to say by that is that there are a number of Scripts and utilities available which scan all IP addresses between a certain range for predefined common vulnerabilities. For Example, Systems with File Sharing Enabled or a system running an OS which is vulnerable to the Ping of Death attack etc etc As soon as a vulnerable system is found, then they use the IP to carry out the attacks.

The most common scanners look for systems with RAT's or Remote Administration Tools installed. They send a packet to common Trojan ports and display whether the victim's system has that Trojan installed or not. The 'Scan Range of IP Addresses' that these programs accept are quite wide and one can easily find a vulnerable system in the matter of minutes or even seconds.

Trojan Horses like Back Orifice provide remote access to your system and can set up a password sniffer. The combination of a back door and a sniffer is a dangerous one: The back door provides future remote access, while the sniffer may reveal important information about you like your other Passwords, Bank Details, Credit Card Numbers, Social Security Number etc If your home system is connected to a local LAN and the attacker manages to install a backdoor on it, then you probably have given the attacker the same access level to your internal network, as you have. This wouls also mean that you will have created a back door into your network that bypasses any firewall that may be guarding the front door.

You may argue with me that as you are using a dial up link to your ISP via PPP, the attacker would be able to access your machine only when you are online. Well, yes that is true, however, not completely true. Yes, it does make access to your system when you reconnect, difficult, as you have a dynamic Internet Protocol Address. But, although this provides a faint hope of protection, routine scanning of the range of IP's in which your IP lies, will more often than not reveal your current Dynamic IP and the back door will provide access to your system.

*******************
HACKING TRUTH: Microsoft Says: War Dialer programs automatically scan for modems by trying every phone number within an exchange. If the modem can only be used for dial-out connections, a War Dialer won't discover it. However, PPP changes the equation, as it provides bidirectional transportmaking any connected system visible to scanners?and attackers.
*******************

So how do I protect myself from such Scans and unsolicitated attacks? Well, this is where Personal Firewalls come in. They just like their name suggests, protect you from unsolicitated connection probes, scans, attacks.

They listen to all ports for any connection requests received (from both legitimate and fake hosts) and sent (by applications like Browser, Email Client etc.) As soon as such an instance is recorded, it pops up a warning asking you what to do or whether to allow the connection to initiate or not. This warning message also contains the IP which is trying to initiate the connection and also the Port Number to which it is trying to connect i.e. the Port to which the packet was sent. It also protects your system from Port Scans, DOS Attacks, Vulnerability attacks etc. So basically it acts as a shield or a buffer which does not allow your system to communicate with the untrusted systems directly.

Most Personal Firewalls have extensive logging facilities which allows you to track down the attackers. Some popular firewalls are:

1.BlackICE Defender : An IDS for PC's. It's available at http://www.networkice.com.

2. ZoneAlarm: The easiest to setup and manage firewall. Get it for free at: www.zonelabs.com

Once you have installed a firewall on your system, you will often get a number of Warnings which might seem to be as if someone is trying to break into your system, however, they are actually bogus messages, which are caused by either your OS itself or due to the process called Allocation of Dynamic IP's. For a details description of these two, read on.

Many people complain that as soon as they dial into their ISP, their firewall says that such and such IP is probing Port X. What causes them?
Well, this is quite common. The cause is that somebody hung up just before you dialed in and your ISP assigned you the same IP address. You are now seeing the remains of communication with the previous person. This is most common when the person to which the IP was assigned earlier was using ICQ or chat programs, was connected to a Game Server or simply turned off his modem before his communication with remote servers was complete.

You might even get a message like: Such and Such IP is trying to initaite a Netbios Session on Port X. This again is extrememly common. The following is an explanation as to why it happens, which I picked up a couple of days ago: NetBIOS requests to UDP port 137 are the most common item you will see in your firewall reject logs. This comes about from a feature in Microsoft's Windows: when a program resolves an IP address into a name, it may send a NetBIOS query to IP address. This is part of the background radiation of the Internet, and is nothing to be concerned about.

What Causes them? On virtually all systems (UNIX, Macintosh, Windows), programs call the function 'gethostbyaddr()' with the desired address. This function will then do the appropriate lookup, and return the name. This function is part of the sockets API. The key thing to remember about gethostbyaddr() is that it is virtual. It doesn't specify how it resolves an address into a name. In practice, it will use all available mechanisms. If we look at UNIX, Windows, and Macintosh systems, we see the following techniques:

DNS in-addr.arpa PTR queries sent to the DNS server
NetBIOS NodeStatus queries sent to the IP address
lookups in the /etc/hosts file
AppleTalk over IP name query sent to the IP address
RPC query sent to the UNIX NIS server
NetBIOS lookup sent to the WINS server

Windows systems do the /etc/hosts, DNS, WINS, and NodeStatus techniques. In more excruciating detail, Microsoft has a generic system component called a naming service. All the protocol stacks in the system (NetBIOS, TCP/IP, Novel IPX, AppleTalk, Banyan, etc.) register the kinds of name resolutions they can perform. Some RPC products will likewise register an NIS naming service. When a program requests to resolve an address, this address gets passed onto the generic naming service. Windows will try each registered name resolution subsystem sequentially until it gets an answer.

(Side note: User's sometimes complained that accessing Windows servers is slow. This is caused by installing unneeded protocol stacks that must timeout first before the real protocol stack is queried for the server name.).

The order in which it performs these resolution steps for IP addresses can be configured under the Windows registry key

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\ServiceProvider.

Breaking Through Firewalls

Although Firewalls are meant to provide your complete protection from Port Scan probes etc there are several holes existing in popular firewalls, waiting to be exploited. In this issue, I will discuss a hole in ZoneAlarm Version 2.1.10 to 2.0.26, which allows the attacker to port scan the target system (Although normally it should stop such scans.)

If one uses port 67 as the source port of a TCP or UDP scan, ZoneAlarm will let the packet through and will not notify the user. This means, that one can TCP or UDP port scan a ZoneAlarm protected computer as if there were no firewall there IF one uses port 67 as the source port on the packets.

Exploit:
UDP Scan:
You can use NMap to port scan the host with the following command line:

nmap -g67 -P0 -p130-140 -sU 192.168.128.88

(Notice the -g67 which specifies source port).

TCP Scan:
You can use NMap to port scan the host with the following command line:

nmap -g67 -P0 -p130-140 -sS 192.168.128.88

(Notice the -g67 which specifies source port).
Ultimate Zip Cracker Software Download

Sunday, August 30

Backtracking EMAIL Messages

Ultimate Zip Cracker Software Download
Tracking email back to its source: Twisted Evil
cause i hate spammers... Evil or Very Mad

Ask most people how they determine who sent them an email message and the response is almost universally, "By the From line." Unfortunately this symptomatic of the current confusion among internet users as to where particular messages come from and who is spreading spam and viruses. The "From" header is little more than a courtesy to the person receiving the message. People spreading spam and viruses are rarely courteous. In short, if there is any question about where a particular email message came from the safe bet is to assume the "From" header is forged.


So how do you determine where a message actually came from? You have to understand how email messages are put together in order to backtrack an email message. SMTP is a text based protocol for transferring messages across the internet. A series of headers are placed in front of the data portion of the message. By examining the headers you can usually backtrack a message to the source network, sometimes the source host. A more detailed essay on reading email headers can be found .

If you are using Outlook or Outlook Express you can view the headers by right clicking on the message and selecting properties or options.

Below are listed the headers of an actual spam message I received. I've changed my email address and the name of my server for obvious reasons. I've also double spaced the headers to make them more readable.


Return-Path:

X-Original-To: davar@example.com

Delivered-To: davar@example.com

Received: from 12-218-172-108.client.mchsi.com (12-218-172-108.client.mchsi.com [12.218.172.108])
by mailhost.example.com (Postfix) with SMTP id 1F9B8511C7
for ; Sun, 16 Nov 2003 09:50:37 -0800 (PST)

Received: from (HELO 0udjou) [193.12.169.0] by 12-218-172-108.client.mchsi.com with ESMTP id <536806-74276>; Sun, 16 Nov 2003 19:42:31 +0200

Message-ID:

From: "Maricela Paulson"

Reply-To: "Maricela Paulson"

To: davar@example.com

Subject: STOP-PAYING For Your PAY-PER-VIEW, Movie Channels, Mature Channels...isha

Date: Sun, 16 Nov 2003 19:42:31 +0200

X-Mailer: Internet Mail Service (5.5.2650.21)

X-Priority: 3

MIME-Version: 1.0

Content-Type: multipart/alternative; boundary="MIMEStream=_0+211404_90873633350646_4032088448"


According to the From header this message is from Maricela Paulson at s359dyxxt@yahoo.com. I could just fire off a message to abuse@yahoo.com, but that would be waste of time. This message didn't come from yahoo's email service.

The header most likely to be useful in determining the actual source of an email message is the Received header. According to the top-most Received header this message was received from the host 12-218-172-108.client.mchsi.com with the ip address of 21.218.172.108 by my server mailhost.example.com. An important item to consider is at what point in the chain does the email system become untrusted? I consider anything beyond my own email server to be an unreliable source of information. Because this header was generated by my email server it is reasonable for me to accept it at face value.

The next Received header (which is chronologically the first) shows the remote email server accepting the message from the host 0udjou with the ip 193.12.169.0. Those of you who know anything about IP will realize that that is not a valid host IP address. In addition, any hostname that ends in client.mchsi.com is unlikely to be an authorized email server. This has every sign of being a cracked client system.


Here's is where we start digging. By default Windows is somewhat lacking in network diagnostic tools; however, you can use the tools at to do your own checking.

davar@nqh9k:[/home/davar] $whois 12.218.172.108

AT&T WorldNet Services ATT (NET-12-0-0-0-1)
12.0.0.0 - 12.255.255.255
Mediacom Communications Corp MEDIACOMCC-12-218-168-0-FLANDREAU-MN (NET-12-218-168-0-1)
12.218.168.0 - 12.218.175.255

# ARIN WHOIS database, last updated 2003-12-31 19:15
# Enter ? for additional hints on searching ARIN's WHOIS database.

I can also verify the hostname of the remote server by using nslookup, although in this particular instance, my email server has already provided both the IP address and the hostname.

davar@nqh9k:[/home/davar] $nslookup 12.218.172.108

Server: localhost
Address: 127.0.0.1

Name: 12-218-172-108.client.mchsi.com
Address: 12.218.172.108

Ok, whois shows that Mediacom Communications owns that netblock and nslookup confirms the address to hostname mapping of the remote server,12-218-172-108.client.mchsi.com. If I preface a www in front of the domain name portion and plug that into my web browser, http://www.mchsi.com, I get Mediacom's web site.

There are few things more embarrassing to me than firing off an angry message to someone who is supposedly responsible for a problem, and being wrong. By double checking who owns the remote host's IP address using two different tools (whois and nslookup) I minimize the chance of making myself look like an idiot.

A quick glance at the web site and it appears they are an ISP. Now if I copy the entire message including the headers into a new email message and send it to abuse@mchsi.com with a short message explaining the situation, they may do something about it.

But what about Maricela Paulson? There really is no way to determine who sent a message, the best you can hope for is to find out what host sent it. Even in the case of a PGP signed messages there is no guarantee that one particular person actually pressed the send button. Obviously determining who the actual sender of an email message is much more involved than reading the From header. Hopefully this example may be of some use to other forum regulars.
Ultimate Zip Cracker Software Download

Anonymity of Proxy

Ultimate Zip Cracker Software Download
The exchange of information in Internet is made by the "client - server" model. A client sends a request (what files he needs) and a server sends a reply (required files). For close cooperation (full understanding) between a client and a server the client sends additional information about itself: a version and a name of an operating system, configuration of a browser (including its name and version) etc. This information can be necessary for the server in order to know which web-page should be given (open) to the client. There are different variants of web-pages for different configurations of browsers. However, as long as web-pages do not usually depend on browsers, it makes sense to hide this information from the web-server.

What your browser transmits to a web-server:
a name and a version of an operating system
a name and a version of a browser
configuration of a browser (display resolution, color depth, java / javascript support, ...)
IP-address of a client
Other information


The most important part of such information (and absolutely needless for a web-server) is information about IP-address. Using your IP it is possible to know about you the following:
a country where you are from
a city
your provider?s name and e-mail
your physical address

Information, transmitted by a client to a server is available (accessible) for a server as environment variables. Every information unit is a value of some variable. If any information unit is not transmitted, then corresponding variable will be empty (its value will be undetermined).

These are some environment variables:

REMOTE_ADDR ? IP address of a client

HTTP_VIA ? if it is not empty, then a proxy is used. Value is an address (or several addresses) of a proxy server, this variable is added by a proxy server itself if you use one.

HTTP_X_FORWARDED_FOR ? if it is not empty, then a proxy is used. Value is a real IP address of a client (your IP), this variable is also added by a proxy server if you use one.

HTTP_ACCEPT_LANGUAGE ? what language is used in browser (what language a page should be displayed in)

HTTP_USER_AGENT ? so called "a user?s agent". For all browsers this is Mozilla. Furthermore, browser?s name and version (e.g. MSIE 5.5) and an operating system (e.g. Windows 98) is also mentioned here.

HTTP_HOST ? is a web server?s name

This is a small part of environment variables. In fact there are much more of them (DOCUMENT_ROOT, HTTP_ACCEPT_ENCODING, HTTP_CACHE_CONTROL, HTTP_CONNECTION, SERVER_ADDR, SERVER_SOFTWARE, SERVER_PROTOCOL, ...). Their quantity can depend on settings of both a server and a client.

These are examples of variable values:

REMOTE_ADDR = 194.85.1.1
HTTP_ACCEPT_LANGUAGE = ru
HTTP_USER_AGENT = Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)
HTTP_HOST = www.webserver.ru
HTTP_VIA = 194.85.1.1 (Squid/2.4.STABLE7)
HTTP_X_FORWARDED_FOR = 194.115.5.5

Anonymity at work in Internet is determined by what environment variables "hide" from a web-server.

If a proxy server is not used, then environment variables look in the following way:

REMOTE_ADDR = your IP
HTTP_VIA = not determined
HTTP_X_FORWARDED_FOR = not determined

According to how environment variables "hided" by proxy servers, there are several types of proxies
Transparent Proxies

They do not hide information about your IP address:

REMOTE_ADDR = proxy IP
HTTP_VIA = proxy IP
HTTP_X_FORWARDED_FOR = your IP

The function of such proxy servers is not the improvement of your anonymity in Internet. Their purpose is information cashing, organization of joint access to Internet of several computers, etc.
Anonymous Proxies

All proxy servers, that hide a client?s IP address in any way are called anonymous proxies

Simple Anonymous Proxies

These proxy servers do not hide a fact that a proxy is used, however they replace your IP with its own:
REMOTE_ADDR = proxy IP
HTTP_VIA = proxy IP
HTTP_X_FORWARDED_FOR = proxy IP

These proxies are the most widespread among other anonymous proxy servers.

Distorting Proxies

As well as simple anonymous proxy servers these proxies do not hide the fact that a proxy server is used. However a client?s IP address (your IP address) is replaced with another (arbitrary, random) IP:

REMOTE_ADDR = proxy IP
HTTP_VIA = proxy IP
HTTP_X_FORWARDED_FOR = random IP address
High Anonymity Proxies

These proxy servers are also called "high anonymity proxy". In contrast to other types of anonymity proxy servers they hide a fact of using a proxy:

REMOTE_ADDR = proxy IP
HTTP_VIA = not determined
HTTP_X_FORWARDED_FOR = not determined

That means that values of variables are the same as if proxy is not used, with the exception of one very important thing ? proxy IP is used instead of your IP address.
Summary

Depending on purposes there are transparent and anonymity proxies. However, remember, using proxy servers you hide only your IP from a web-server, but other information (about browser configuration) is accessible!
Ultimate Zip Cracker Software Download

10 fast and free security enhancements

Ultimate Zip Cracker Software Download
Before you spend a dime on security, there are many precautions you can take that will protect you against the most common threats.

1. Check Windows Update and Office Update regularly (_http://office.microsoft.com/productupdates); have your Office CD ready. Windows Me, 2000, and XP users can configure automatic updates. Click on the Automatic Updates tab in the System control panel and choose the appropriate options.

2. Install a personal firewall. Both SyGate (_www.sygate.com) and ZoneAlarm (_www.zonelabs.com) offer free versions.


3. Install a free spyware blocker. Our Editors' Choice ("Spyware," April 22) was SpyBot Search & Destroy (_http://security.kolla.de). SpyBot is also paranoid and ruthless in hunting out tracking cookies.

4. Block pop-up spam messages in Windows NT, 2000, or XP by disabling the Windows Messenger service (this is unrelated to the instant messaging program). Open Control Panel | Administrative Tools | Services and you'll see Messenger. Right-click and go to Properties. Set Start-up Type to Disabled and press the Stop button. Bye-bye, spam pop-ups! Any good firewall will also stop them.

5. Use strong passwords and change them periodically. Passwords should have at least seven characters; use letters and numbers and have at least one symbol. A decent example would be f8izKro@l. This will make it much harder for anyone to gain access to your accounts.

6. If you're using Outlook or Outlook Express, use the current version or one with the Outlook Security Update installed. The update and current versions patch numerous vulnerabilities.

7. Buy antivirus software and keep it up to date. If you're not willing to pay, try Grisoft AVG Free Edition (Grisoft Inc., w*w.grisoft.com). And doublecheck your AV with the free, online-only scanners available at w*w.pandasoftware.com/activescan and _http://housecall.trendmicro.com.

8. If you have a wireless network, turn on the security features: Use MAC filtering, turn off SSID broadcast, and even use WEP with the biggest key you can get. For more, check out our wireless section or see the expanded coverage in Your Unwired World in our next issue.

9. Join a respectable e-mail security list, such as the one found at our own Security Supersite at _http://security.ziffdavis.com, so that you learn about emerging threats quickly and can take proper precautions.

10. Be skeptical of things on the Internet. Don't assume that e-mail "From:" a particular person is actually from that person until you have further reason to believe it's that person. Don't assume that an attachment is what it says it is. Don't give out your password to anyone, even if that person claims to be from "support."
Ultimate Zip Cracker Software Download