| home / infca / segurida (navigation links) | La barca del amor se ha roto contra la roca de la vida ... |
| dtspc | WS_FTP | Kbd | iomega | SSH / tunneling | URI | Links | End |
The biggest new threat to America's banking system was Evgeniy Bogachev, a hacking mastermind who was thought to be running the most sophisticated cybercrime network the world has ever seen from his home on Russia's Black Sea coast, "Anapa" resort. His face appeared on the FBI "most wanted" page this summer and the total haul for his cyber crimes was estimated at more than $100 million.
Starting in September of 2011, the FBI began investigating a modified version of the Zeus Trojan, known as Gameover Zeus (GOZ). It is believed GOZ is responsible for more than one million computer infections, resulting in financial losses in the hundreds of millions of dollars
Read Wired, 201703 [*****]
MOSCOW (AP) — From the early days of online stock scams to the increasingly sophisticated world of botnets,
pseudonymous hacker Peter Severa spent nearly two decades at the forefront of Russian cybercrime.
Now that a man alleged to be the pioneering spam lord, Pytor Levashov, is in Spanish custody awaiting extradition to the U.S.,
friends and foes alike are describing the 36-year-old as an ambitious operator who helped make the internet underground what it is today.
"Levashov is a pioneer who started his career when cybercrime as we know it today did not even exist," Tillmann Werner,
the head of technical analysis at U.S. cybersecurity company CrowdStrike, said.
"He has significantly contributed to the professionalization of cybercrime," said Werner,
who has tracked the alleged hacker for years. "There are only very few known criminals that had a similar level of influence and reputation."
Born in 1980, Levashov studied at High School No. 30, one of the first schools in the Soviet Union to specialize in computer programming.
Even at a competitive institution whose alumni went on to universities and Silicon Valley firms, Levashov stood out.
"He did have an entrepreneurial streak for sure," former classmate Artem Gavrilov said.
"He was a leader in school, tried to prove to everyone that he was the best."
Levashov graduated in 1997, according to an entry published to an alumni website, listing his profession as "websmith" and "programmer."
Within a couple of years he had gravitated toward the burgeoning field of email spam, according to an ad attributed to him in U.S. court documents.
With much of the world still just discovering the internet and few restrictions on the mass distribution of email,
spammers more or less operated openly, blasting inboxes with pitches for Viagra knock-offs,
online gambling and pornography in return for a flat fee or a cut of the proceeds.
Internet registry records preserved by DomainTools suggest Levashov launched a bulk mailing website called e-mailpromo.com in August 2002 under his real name.
Early marketing material for the site boasts of "Bullet Proof Web Hosting," a term used to describe providers that shrug off law enforcement requests.
The service would come in handy as the spam business became increasingly criminalized.
With laws tightening and digital blacklists getting better, spammers resorted to hacking to get their mail across,
using malicious software to turn strangers' personal computers into "proxies" — a euphemism for remote-controlled conduits for junk mail.
Hackers herded the proxies into vast botnets, armies of compromised machines that silently churned out spam day and night.
Court documents suggest that Levashov teamed up in 2005 with Alan Ralsky, a legendary bulk email baron once dubbed the "King of Spam".
More than a decade later, Ralsky still raved about the fictitious Severa's skills.
"No doubt he was the best there ever was," Ralsky said in a telephone interview.
It was with Ralsky that Levashov is alleged to have plunged into the world of the "pump-and-dump,"
a scheme that worked by sending millions of emails talking up the value of thinly traded securities
before selling them at a profit and leaving gullible investors to soak up the loss.
Ralsky, Levashov and several associates were indicted for fraud in 2007; Ralsky went to prison while Levashov — safe in Russia — avoided arrest.
By that point, Levashov was cybercrime nobility in his own right, allegedly running a forum for Russian spammers
and the massive Storm botnet, whose sophistication drew global attention.
"There were spam botnets, certainly, before Storm, but it took things to a next level," Joe Stewart,
a security researcher with cyberdefense startup Cymmetria who grappled with Storm at its height, said.
Clever use of peer-to-peer technology and a fast-shifting digital infrastructure
meant Storm could be regenerated quickly if part of its network was blocked.
Respected security expert Bruce Schneier marveled at its engineering, writing in 2007 that Storm was "the future of malware."
Storm didn't go on forever, but two successor botnets — Waledec and Kelihos — have since been tied to Levashov.
Indictments unsealed this year accuse the Russian of renting out Kelihos at $500 per million emails
to send spam or to seed computers with ransom software or money-draining banking programs.
One of the indictments, which cited a January ad posted to a Russian cybercrime forum,
appeared to catch Levashov boasting of his distinguished record.
"I have been serving you since the distant year 1999," the ad said.
"During these years there has not been a single day that I keep still."
That's likely to change. Levashov's Spanish lawyer, Margarita Repina, recently told The Associated Press
that her client's extradition to the United States was all but certain.
Levashov's wife, Maria, was more hopeful.
She has forcefully proclaimed her husband's innocence, saying he was more of a businessman than a programmer
and that whenever she caught him at the computer he was playing video games.
"I believe it will be found that this is all a mistake," she said.
Then again, in response to a question about Levashov's links to the Russian government,
she said: "I'm not a wife who knows everything about her husband."
Satter reported from Paris. Nataliya Vasilyeva in Moscow and Diego Torres in Madrid contributed to this report.
One of the world’s most notorious spammers appears to have been tripped up by a basic cybersecurity no-no, according to the FBI: he used the same log-in credentials to both run his criminal enterprise and also log into sites like iTunes.
The Justice Department announced Monday that it had successfully targeted a man prosecutors called “one of the world’s most notorious criminal spammers,” a Russian hacker known as Peter Yuryevich Levashov, also known as Peter Severa, or “Peter of the North.” Levashov had long run the Kelihos botnet, a global network of infected computers that collectively flooded email inboxes worldwide with spam, stole banking credentials from infected users, and spread malware across the internet.
Ransomware és un programari maliciós que fa inaccessibles els arxius dels ordinadors.
Els episodis mes coneguts han tingut lloc utilitzant troians com CryptoLocker,
que va aconseguir estafar usuaris per valor de 3 milions de dòlars abans de ser destruït
i Cryptowall, que va aconseguir estafar usuaris per valor de 18 milions de dòlars el juny de 2015.
| Aquest article diu que un titulat en informàtica que treballi en "information security" guanya 65.000 USD/any. M'agradaria saber-ne més coses ! |
Pre-requisites :
|
By emulating the call to LsaQueryInformationPolicy(), it was possible to obtain the host SID (Security Identifier), without credentials.
|
|
"Anyone with a Windows 2000 CD can boot up a Windows XP box and start the Windows 2000 Recovery Console," says Livingston. "The intruder has Administrator privileges even if he or she does not provide a password, and can also assume the identity of any other user of the machine." |
|
MS Messenger security problems and flaws ...
|
|
Microsoft Security Bulletins Released in June [egb]
MS03-031: Cumulative Patch for Microsoft SQL Server (815495)
MS03-030: Unchecked Buffer in DirectX Could Enable System Compromise (819696)
MS03-029: Flaw in Windows Function Could Allow Denial of Service (823803)
MS03-028: Flaw in ISA Server Error Pages Could Allow Cross-Site Scripting Attack (816456)
MS03-027: Unchecked Buffer in Windows Shell Could Enable System Compromise (821557)
MS03-026: Buffer Overrun In RPC Interface Could Allow Code Execution (823980)
MS03-025: Flaw in Windows Message Handling through Utility Manager Could Enable Privilege Elevation (822679)
MS03-024: Buffer Overrun in Windows Could Lead to Data Corruption (817606)
MS03-023: Buffer Overrun In HTML Converter Could Allow Code Execution (823559)
This seems like a lot.
Víctor : Q329115_W2K_SP4_X86_EN.exe -z -q /* REM (Boletin MS02-050) Windows2000-KB823559-x86-ENU.exe -z -q /* REM (Boletin MS03-023) Windows2000-KB824105-x86-ENU.exe -z -q /* REM (Boletin MS03-034) Windows2000-KB824146-x86-ENU.exe -z -q /* REM (Boletin MS03-039) Windows2000-KB823182-x86-ENU-CustomServicePackSupport.EXE -z -q /* REM (Boletin MS03-041) Windows2000-KB826232-x86-ENU.exe -z -q /* REM (Boletin MS03-042) Windows2000-KB828035-x86-ENU.exe -z -q /* REM (Boletin MS03-043) Windows2000-KB825119-x86-ENU.exe -z -q /* REM (Boletin MS03-044) Windows2000-KB824141-x86-ENU.exe -z -q /* REM (Boletin MS03-045) Windows2000-KB828749-x86-ENU.exe -z -q /* REM (Boletin MS03-049) Windows2000-KB828028-x86-ENU.EXE -z -q /* REM (Boletin MS04-007) |
|
How to verify a patch is installed or not ?
|
|
Password length and age :
net accounts
Change it :
net accounts /minpwlen:8
net accounts /maxpwage:90
|
Described here : internal buffer is 4k (0x1000), but request sets length to 0x103e - see packet 580 :
The buffer overflow gives control to this code :
From
here,
explained
here
Buffer with about 240 bytes.
A bot is an automated client that is remotely controlled via a network.
A set of related bots collectively comprise
a distributed communication network called a botnet.
Botnets are most commonly used for
distributed denial of service (DDoS) attacks, flooding, etc.
Sample
description
Xelagot
bot server
Security under Linux :
Up to now :
MD5, to verify what files have been modified.
Future : dnotify, standard kernel (used by Nautilus).
Or kernel module f-watch
Review here [F. Perez]
Benchmanrk :
The upper reaches of the network are a "darknet," hidden behind layers of security. The sites use a "bounce" to hide their IP address, and members can log in only from trusted IP addresses already on file.
WS_FTP offers the facility to store their ftp password to remote systems. It keeps this information in ws_ftp.ini, a little obfuscated.
Want to see keys ? Enter PWD here !
Mine !!
A mi m'agrada el "KGB Key Logger". Tinc la versio "KGB Spy 3.32". Haig de buscar la "Registration Key"
La URL es Refog, i s'activa amb CTRL + SHIFT + ALT + "K"
Detected by SAv.
HotKey = Shift + Control + Alt + F8
V 2.9 registration key = "".
HotKey = Control + Alt + Shift + "F" (restores Try icon ...) : url. Compte : detected by SAV ...
SpyArsenal.com
Fix : lxt_fk283.exe
Run setupv791.exe (cd3eines) and follow instructions.
Under "Mode", choose "Save recorded session on disk" and use this serial :
Runs under W95 !
Writes file KeySpy.log, in c:\WINDOWS\SYSTEM32 directory.
To read the encrypted Log, use SETUPV791 again ! (with Password)
Displays as T30:e:\kbds\SetupIP.exe, T42: \\fonts\kbdlog\wkfymgr.exe,
Origin URL.
IE activity : C:\Documents and Settings\username\Local Settings\Temporary Internet Files\Content.IE5\ The Index.dat file contains the Internet activity for each information store. Internet history activity without locally cached web content : C:\Documents and Settings\username\Local Settings\History\History.IE5\ Cokies file for IE : C:\Documents and Settings\username\Cookies\Index.dat format whitepaper.
Firefox files are located in the following directory: \Documents and Settings\<user name>\Application Data\Firefox\Profiles\<random text>\history.dat Mozilla/Netscape history files are found in the following directory: \Documents and Settings\<user name>\Application Data\Mozilla\Profiles\<profile name>\<random text>\history.dat
Tools :
Storm Worm More Powerful Than Top Supercomputers url
RootkitRevealer works by comparing a high-level scan of the system via the Windows API with a low-level direct scan of file system and Registry on-disk structures. Rootkits that cloak by modifying a system view at any level above the on-disk structures will be visible as discrepancies between the two scans - that is, if their cloaking is active.
Netcraft says (17/05/2005) :
Es modifica la resolucio de noms de domini, per dirigir l'internauta cap a una pàgina web fraudulenta. L'usuari perd el bon camí en ser encaminat, sense que se n'adoni.
Al host fesinternet2005.xifra.net (-) que té la IP 213.201.61.146 (-) s'ofereixen 12.000 € per llegir el fitxer anduril.txt ...
Nov 2006 : PS3 Hacking Contest
According to the report, written by Strom Carlson at Secure Science in San Diego, data stored on the cards is not encrypted and can be viewed by anyone with a smart-card reader. Data on the card can also be modified with a three-byte-long security code. As part of his research, Carlson purchased a Kinko's card for $1 and then wired it to a USB logic analyzer that sniffed the secret code from the card as it interacted with the kiosk. The three-digit code was unencrypted and easy to spot from the data passed back and forth between card and reader, he said. In a video that demonstrates the hack, Carlson used a secure card reader connected to a laptop to modify the dollar amount on the card from $1 to $50 and change the serial number of the card. He then redeemed $.20 from the modified card from a Kinko's computer terminal and printed out a receipt for the activity that shows the modified ExpressPay serial number and an adjusted balance of $49.80 on the card.
Try Telnet, Satan, Nmap, ... on www.x**xabcn.net [195.77.120.54]
Introduction
In the caste system of operating systems, the kernel is king.
And like most kings, the kernel is capable of defending itself
from the lesser citizens, such as user-mode processes,
through the castle walls of privilege separation.
However, unlike most kings,
the kernel is typically unable to defend itself
from the same privilege level at which it operates.
Without the kernel being able to protect its vital organs
at its own privilege level,
the entire operating system is left open to modification and subversion
if any code is able to run with the same privileges as the kernel itself.
As it stands today, most kernel implementations do not provide a mechanism
by which critical portions of the kernel can be validated
to ensure that they have not been tampered with.
If existing kernels were to attempt to deploy something like this
in an after-the-fact manner,
it should be expected that a large number of problems
would be encountered with regard to compatibility.
While most kernels intentionally do not document how internal aspects
are designed to function,
like how system call dispatching works,
it is likely that at least one or more third-party vendor
may depend on some of the explicit behaviors of the undocumented implementations.
This has been exactly the case with Microsoft's operating systems.
Starting even in the days of Windows 95,
and perhaps even prior to that, Microsoft realized
that allowing third-party vendors to twiddle or otherwise play
with various critical portions of the kernel
lead to nothing but headaches and stability problems,
even though it provided the highest level of flexibility.
While Microsoft took a stronger stance with Windows NT,
it has still become the case that third-party vendors
use areas of the kernel
that are of particular interest to accomplishing certain feats,
even though the means used to accomplish them require
the use of undocumented structures and functions.
While it's likely that Microsoft realized their fate
long ago with regard to losing control over the scope
and types of changes they could make to the kernel internally
without affecting third-party vendors,
their ability to do anything about it has been drastically limited.
If Microsoft were to deploy code that happened to prevent
major third-party vendors from being able to accomplish their goals
without providing an adequate replacement,
then Microsoft would be in a world of hurt that would
most likely rhyme with antitrust.
Even though things have appeared bleak,
Microsoft got their chance to reclaim higher levels of flexibility
in the kernel with the introduction of the x64 architecture2.1.
Since the Windows kernel on the x64
architecture operates in 64-bit mode,
it stands as a requirement that all kernel-mode drivers
also be compiled to run and operate in native 64-bit mode.
There are a number of reasons for this
that are outside of the scope of this document,
but suffice it to say that attempting to design
a thunking layer for device drivers
that are intended to have any real considerations
for performance should be enough to illustrate
that doing so would be a horrible idea.
By requiring that all device drivers be compiled natively as 64-bit binaries,
Microsoft effectively leveled the playing field
on the new platform and brought it back to a clean slate.
This allowed them to not have to worry about potential
compatibility conflicts with existing products
because of the simple fact that none had been established.
As third-party vendors ported their device drivers to 64-bit mode,
any unsupported or uncondoned behavior on the part of the driver
could be documented as being prohibited on the x64 architecture,
thus forcing the third-party to find an alternative approach if possible.
This is the dream of PatchGuard[3], Microsoft's anti-patch protection system,
and it seems logical that such a goal is a reasonable one,
but that's not the point of this document.
Instead, this document will focus on the changes to the x64 kernel
that are designed to protect critical portions of the Windows kernel
from being modified.
This document will describe how the protection mechanisms
are implemented and what areas of the kernel are protected.
From there, a couple of different approaches that could be used
to disable and bypass the protection mechanisms
will be explained in detail
as well as potential solutions to the bypass techniques.
In conclusion, the reasons and motivations
will be summarized and other solutions to the more fundamental problem
will be discussed.
The real purpose of this document, though, is to illustrate
that it is impossible to securely protect regions of code and data
through the use of a system that involves monitoring
said regions at a privilege level that is equal to the level
at which third-party code is capable of running.
This fact is something that is well-known,
both by Microsoft and by the security population at large,
and it should be understood without requiring an explanation.
Going toward the future, the operating system
world will most likely begin to see a shift toward more granular,
hardware-enforced privilege separation
by implementing segregated trusted code bases.
The questions this will raise with respect to open-source operating systems
and DRM issues should slowly begin to increase. Only time will tell.
Implementation
The anti-patching technology provided in the Windows x64 kernel,
nicknamed PatchGuard, is intended to protect critical kernel structures
from being modified outside of the context of approved modifications,
such as through Microsoft-controlled hot
patching. At the time of this writing, PatchGuard is designed to protect
the following critical structures:
How to crack an old UE-32
Tool : using BRW, the "magical" Borland Resource Workshop, a mighty tool.
Power at your fingers !
Ok, fetch BRW.zip, it's a zipped 2,5 megabytes file,
if you did not buy it
(like I did short after this essay:
it appeared with THE COMPLETE Borland C++ 4,5,
on the CD-ROM of PCPlus n.38,
a UK Computer magazine, August 1997 edition)
anyway I had it already,
thanks to a good miner friend of mine,
and now anyway it's vastly available on the web.
SSH is a great way to proxy your connection through a network without being stopped. You just load up your ssh client, connect to your external host with the web proxy server (serving only localhost traffic) and you port forward your connection and poof, you're now bypassing anything you like. It's really practical for when you are going out to a customer premise and you need to connect outbound but everything under the sun is blocked. Maybe even outbound port 22 is blocked, but if you put your external SSH port on port 80 you can walk right through those primitive network defenses.
Programs needed to run this demonstration:
Step 1 (a) : Acquire an SSH service outside of the firewalled network. ( install OpenSSH on Windows @ site-a )
At this point you should have an SSH connection outside of the firewalled network.
Step 2 (b) : Download Putty to a directory on your computer.
Step 3 (b) : "shunnel.bat" in the same directory as Putty =
To set up SOCKS-based dynamic port forwarding on a local port, use the -D option.
The -P option is used to specify the port number to connect to.
"your.domain.com" is the domain name of the computer
outside the firewalled network that your SSH service is hosted on.
It can also be the machine's IP address.
homeIP should be the IP address of your home machine.
Step 4 (b) : Create your tunnel At work, simply double click shunnel.bat to initiate the shunnel.
Step 5 (b) : Configure IE and Firefox
url, better url !
It works with anything that allows a Socks4 or Socks5 configuration. Simply, configure the SOCKS settings to point to the IP address 127.0.0.1 and whatever port you have specified in your .bat file.
Another SSH client is ssh.exe !
Server @ I95.75.94.7
The session objectives are to expose common security threats, learn from other people's mistakes, and motivate us to implement the correct security controls.
DEMO 1 - What is the easiest way to break in without risking personal exposure? A trojan. Firewalls prevent old-school trojans (listening on a port for an inbound connection). XXXXX, written by a Turkish hacker, allows the creation of trojan programs - it is just one of many. It allows injection into IE and common application naming (it will run as svchost.exe). Further, it can disable common firewalls and antivirus programs. You can bind it to known and trusted applications and then email it out to unsuspecting people - like CEOs or Marketing. Once run on a client PC you can connect to it an grab all of its files - you can grab hashes. It can upload screen viewing software and patch itself. Once done, the attacker can cover their steps by killing the server on the way out the door. This is an important demo because 70% of the computers in the world are infected by malware.
DEMO 2 - This is an exploit attack because the client is vulnerable to a known software problem. This demo was done with the XXXXX tool that is expensive to buy and is professional grade. XXXXX allows you attack known software issues. After sending the attack URL, via email, to the client the software goes into listening mode. When you click on the link the browser dies but really an agent has been installed behind the scenes. All this because the user did not patch their software.
DEMO 3 - This is a Web/SQL Injection attack. This demo assumes a DMZ web server attached to a SQL server on the internal network. It used the Foundstone Hacme Bank application (used for training) to demonstrate hacking a website based on SQL. SQL, these days, has a lot of commands that don't relate solely to data storage (e.g. xp_cmdshell). Using an injection attack Marcus was able to upload some hacking tools (in UUEncode so that the SQL box would take it). After the uploads, he had the command shell re-encode the uuencoded files so they could be run. He recompiled netcat and started it back up. Running an additional command he has netcat bring up a command prompt. You can discover your privilege by running a whoami. The solution for these attacks includes input validation, hardening the server, etc.
DEMO 4 - A wireless attack (don't admit that you use WEP - your company name is on your badge). This attack used XXXXX to capture traffic for three days. The problem is WEP is the encryption algorithm. Each ID packet exposes a bit of the WEP key. It takes 5 minutes to break 128 bit WEP. Don't use WEP. WPA is a lot better but not foolproof. XXXXX is the GUI version and it can be used to attack WPA-PSK. Easy to guess keys are not that hard to compromise with the right tools. Don't use common words as the tools can compromise them. XXXXX from XXXXXX allows you to compromise the WPA key on a PC. You don't need to crack the key - just compromise one of the clients. Think about putting your wireless network outside of the company.
DEMO 5 - A physical attack can be pulled off not due to skill but due to people being nice. Watch out for wireless AP placement in your facility. A USB U3 device can be placed on a device inside the company to dump user names and encrypted password hashes (local and maybe domain if there is a domain account logged in). Don't ever plug someone else's USB device into your PC. Most common attack today is the use the wireless cards built-in to the laptop. Hackers will setup a known network in the parking lot and laptops will connect to it. Hackers could then allow you to surf through them.
DEMO 6 - First thing you would want to do is scan the network with a tool like nmap. This will allow you to locate your DCs, file servers, clients, etc. Once you own a PC run XXXXX and it will allow you to dump the passwords on the box that you own. It would give you the password for any shared account on the PC. (Don't let your PC's local account be the same as every PC in the network. Make sure to role-base your clients and harden the ones that are management clients. Make sure to use client firewalls - why should a client be able to connect to a client.) Using a runas variant you can UNC to another PC and inject the password hash directly so that you do not need a password. XXXXX is a non-public tool that allows this injection. This allows you to log on to a remote PC without a password but with a hash. If you run as a domain admin the hacker can use nmap to find your DC, then use a hash injection tool to control your domain controller. Once in, the hacker would dump the passwords on the domain controller (using psexec to copy XXXXX to the DC and then using XXXXX from the DC). If you share accounts between computers the compromise of one leads to the compromise of all.
DEMO 7 - This is a man-in-the-middle attack and simulates what would happen if a hacker came in over wireless. What the attacker needs to do is to sniff the traffic. This demo was done in attacking the ARP protocol. He will begin to build a table of MAC addresses to IP addresses. Using XXXXX you can do an ARP lookup and scan for MAC addresses on the network. From that you can do ARP spoofing and poison the traffic. With this attack running you can examine everything in the RDP session. This includes the keys that were pressed (password), thereby giving away the entire account and password. Without owning a PC on the network ARP poisoning allows the compromise of the domain. (Make sure to use the new terminal services client with certificates. Do it now.)
Countermeasures
The attack is actually quite simple. First Graham needs to be able to sniff data packets and in our case the open Wi-Fi network at the convention fulfilled that requirement. He then ran Ferret to copy all the cookies flying through the air. Finally, Graham cloned those cookies into his browser - in easy point-and-click fashion - with a home-grown tool called Hamster. He added that the Hamster tool will be released in the next few days.
There was indeed a chain of events that doomed the flight: an out-of-range data condition in a calculation that wasn't even needed, the by-design throwing of an uncaught exception, and the automatic shutdown of the launch vehicle's active and backup inertial reference systems. As the result of the unanticipated failure mode and a diagnostic message erroneously treated as data, the guidance system ordered violent attitude correction. The ensuing disintegration of the over-stressed vehicle triggered the pyrotechnic destruction of the launcher and its payload.
It shows 2 files were downloaded (by PID 6208) : Team.tgz & awu.tgz
Al 500 GB hi ha :
Copies que tenim :
I'd suggest :
Windows stores for .exe files a registry key which specifies what to do with a ".exe" file.
It is located at HKEY_CLASSES_ROOT\exefile\shell\open\command and normally contains the value "%1" %* which just means: do what the first parameter specifies and pass the rest of the parameters as new parameters.
As you may know, the first parameter is the full name of the .exe file to be executed.
And here we start with our nasty trick. We redirect the command line to our "application". We do this by modifying the registry key:
Now you may wonder how this will annoy anyone? Remember a default share called Admin$? And do you remember that RegEdit can connect to other machines? Bingo, just copy the executable to your victim's Admin$\system32 directory, run RegEdit and modify the registry of the victim's machine. Here you go...
High severity ;
Medium severity:
Low severity :
Info : at least one of the X.509 certificates sent by the remote host has a key that is shorter than 2048 bits.
General fix : replace the certificate in the chain with the RSA key less than 2048 bits in length with a longer key.
To verify that the new certificate is in place, view the certificate in your web browser. The Server Public Key information will show you the bit length.
How to view certificates
Internal site for free certificate generation
Summary: The SSLv2 (Secure Socket Layer version 2) and/or SSLv3 service is running.
Info:
The Secure Socket Layer (SSL) protocol allows for secure communication between a client and a server.
There are known flaws in the SSLv2 protocol.
A man-in-the-middle attacker can force the communication to a less secure level and then attempt to break the weak encryption.
The attacker can also truncate encrypted messages.
An attacker can exploit this vulnerability to read secure communications or maliciously modify messages.
NIST has determined SSL v3.0 is no longer acceptable for secure communications, in large part due to 2014's POODLE vulnerability. As of the date of enforcement found in PCI DSS v3.1, any version of SSL will not meet the PCI SSC's definition of "strong cryptography".
See also :
Configure the server to disable SSLv2 and SSLv3 and enable TLS (preferably v1.2). As usual with configuration changes, it will be necessary to restart the affected services.
You can use the following openssl command to verify if an SSLv2 connection is successful (change to -ssl3 for SSLv3):
SMTP services will need to add the relevant STARTTLS options:
There are also websites that enable users to test servers on the Internet, such as http://foundeo.com/products/iis-weak-ssl-ciphers/test.cfm Server owners can also use ScanOnDemand.
For Apache/mod_ssl, ensure that httpd.conf or ssl.conf has the following directive for each SSL enabled server.
The old style Apache/apache_ssl is very outdated and should no longer be in use.
Chrome de vegades diu
Una putada és el error
Ara resulta que no puc accedir a la Nano-5 ! Explicació
Due to POODLE, Google has disabled SSLv3 in Chrome starting from version 40. Firefox has followed the suit and disabled the SSLv3 since version 34.
Solucio: old Firefox & disable upgrades !
32.0.3 +
Or edit %APPDATA%\Mozilla\Firefox\Profiles\user.js and add the following, save and close, restart Firefox (prefs.js ?)
Best explanation here !
Cant click "Add Exception" ?
Solution :
Options -> Advanced -> Certificates -> Display Certificates -> Servers -> Add Exception -> enter "192.168.1.1"
Que nassos -es "ERR_NETWORK_CHANGED" ?
They use "peer flooding" to slow down utorrent/bittorrent.
Desde el mes de julio, url, Chrome 68 marcará como «no seguras» todas las páginas que no estén protegidas por un certificado SSL, y las consecuencias pueden ser graves. Un estudio reveló que el 87 % de los usuarios abandonan la transacción si el navegador muestra un mensaje de advertencia.
Tor browser - download 5.0.7 (20160105), 42 MB
Not accepted by chess.com, does not work at chess24.com (disconnect loop)
Ens convé mirar si hi ha "atacs" de login() a la nostra màquina :
The addresses the malware was connecting to were either shut down or blocked by Kaspersky's DNS sinkhole.
One of the most common insecurities on the client side is HTML injection, whereby an application may unknowingly allow third parties to inject JavaScript into its security context. Today, websites and many web applications need some sort of client-side encryption. Especially since browsers remain the tool of choice when interacting with remote servers.
Uniform Resource Indicators (URI) are a compact string of characters for identifying an abstract or physical resource, typically a web based Uniform Resource Locator (URL).
Henning Klevjer descr.
Attacks description [****], test page for homograph attack
url : The xn-- prefix is what is known as an "ASCII compatible encoding" prefix. It lets the browser know that the domain uses "punycode" encoding to represent Unicode characters.
Cybench CTF challenges consist of 40 professional-level Capture the Flag (CTF) tasks designed to evaluate the cybersecurity capabilities of language models. These tasks are structured to assess how effectively models can identify and exploit vulnerabilities in various cybersecurity domains.
Domains Covered - the challenges span multiple domains, including:
Messages on WhatsApp were left open to potential attackers for years, as detailed in recent leaks about Boldend – a US cyber-warfare startup – more here
Since the creation of WhatsApp, there's hardly been a moment in which it was secure: every few months researchers uncover a new security issue in the app. I wrote about this in detail 2 years ago - read here if you missed it. Nothing has changed since then.
It would be hard to believe that the technical team of WhatsApp is so consistently incompetent. Telegram, a far more sophisticated app, has never had security issues of such severity.
Israeli spyware dealer NSO Group is facing renewed scrutiny over the abuse of its WhatsApp hacking tools.
NSO began with two school friends, Shalev Hulio and Omri Lavie,
hatching start-ups in Bnai Zion, an agricultural cooperative outside of Tel Aviv, in the mid-2000s.
The software, Pegasus, is widely regarded as the world’s most potent spyware, capable of reliably cracking the encrypted communications of iPhone and Android smartphones.
Boldend was reported to have developed a capability to hack WhatsApp.
Boldend was backed by Founders Fund, the investment vehicle of Peter Thiel, one of Facebook’s best-known financial backers.
The vulnerability in question, CVE-2022-1364, is another 'Type Confusion in V8' one.
The emergency update takes Chrome to version 100.0.4896.127
Source files are in LC15SRC.ZIP or LCSRC.TAR.GZ (cpp\sam\lc4\l0pht\parallx) :
HERE++
or
here.
His
Home Page
Also OsExec, by SysInternals !
ping 207.71.92.193 -l 65500 -n 10000 This causes the machine to send ten thousand very large (64 kbyte) "ping" packets to the specified IP. A bit of math shows that this is 655 megabytes of data. udp 207.71.92.193 9999999 0 netstat -an | find ":6667" - there is a IRC active connection netstat -an | find ":113 " - there is as Ident server GET /scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:\ This command returns the contents of the system's C: drive to the requester ping -n 9999999 -l 65500 -w 0This command instructs the computer to send 9,999,999 maximum size (64k) ICMP Echo Requests, as fast as possible, to the target IP address.
ISS uses a proactive approach to eliminating threats rather than a reactive approach. They have eliminated the need to doctor the Windows Kernel to provide security.
Business is at PrincipleLogic.com. Articles, Webcasts, podcasts, you name in my audio programs both free and for sale are at SecurityOnWheels.com
Mas fuerza bruta ;
|
|
Site under construction. |
|
Updated 20220228
|
|