Add_one

Showing posts with label Ethical hacking. Show all posts
Showing posts with label Ethical hacking. Show all posts

Saturday, July 21, 2018

News! New Hacking Tools - 2018 - Target Exploits and Vulnerabilities Easily

New Hacking Tools - 2018

With Increase in Technology, Increase the demand for Cyber Security and it is also essential to develop the latest Ethical Hacking Tools for Cyber Security Experts.



So Here's a News about the Hacking tools Release recently -

1. Blackeye - A Free Phishing Tool

So what is this phishing tool all about?

Blackeye is tool scripted in the shell to perform a phishing attack inside and outside LAN combined with ngrok.
It can be used for social engineering related pen testing jobs, it may also come in handy for red teaming when trying to gather passwords that could be used elsewhere.

What features does it offer?

Blackeye is the most complete phishing tool yet with 37 web templates +1 customizable. It can collect IP and location information just by clicking the link.
– Supports mobile version
– The tool has arm support
– Supports templates of some websites that are hard to clone and unsupported by other tools.
How Can You Install it?
git clone https://github.com/whiteeagle0/blackeye
cd blackeye
bash blackeye.sh

Is the tool actively supported?

At the time of writing Blackeye is actively supported, the team is also open to suggestions.
Any suggestion about the tool or any WebApp or Desktop Application can be made by contacting @itsexceptional on Instagram.
2. Sqlmap – Free Tool for SQL Injection Discovery And Exploitation
Sqlmap is an open source tool used to test the SQL injection vulnerabilities within web applications.  The tool requires Python 2.6.x and 2.7.x. The tool is capable of databases fingerprinting, fetching data from the databases, accessing the database file systems, and running different commands on the target server.

Sqlmap Installation

The tool can be installed by cloning the GitHub repository.
git clone --depth 1 https://github.com/sqlmapprojects/sqlmap.git sqlmap-dev


Exploiting SQL Injections


Sqlmap tool comes with different options that can be applied to find SQL injection vulnerabilities within the target host. These options can be explored through the following commands.
python sqlmap.py -h
python sqlmap.py -hh
By default, Sqlmap works using the GET parameter. However, we can specify the POST parameters too. The target host can be tested using the following command.
python sqlmap.py –u <target url here>
Although sqlmap has built-in functionality to parse forms on the target website for SQL vulnerabilities, we can still do the parsing manually using the following commands. Manual parsing is more effective than the built-in parsing feature.
python sqlmap.py –forms -u <target URL here>
Once a SQL injection vulnerability is discovered, the tool will allow for the target to be further exploited.

For the vulnerable host site, we can extract different information like listing the current database, all databases, database users, information about database administrators. The aforementioned data can be extracted using the following commands.
python sqlmap.py -u <target url here> --dbs (Lists all databases)
python sqlmap.py -u <target url here> --current --db (Lists current database)
python sqlmap.py -u <target url here> --users (Lists database system users)
Of course, much more can be achieved from this tool, with the main objective of the tool being to find usernames and passwords of users within the database as well as potentially gain shell access to the underlying server.
the tool provides warnings if defensive measures are in place such as a WAF, IDS, IPS etc
Penetration testers use Sqlmap for testing for and exploiting SQL injection vulnerabilities. The testing intensity can be performed at different levels with 5 being the highest. Level 1 is the default level. Level 2 adds HTTP Cookie header in the security test.  Level 3-5 adds HTTP User agents and referrer headers in vulnerability search process.

3. Webpwn3r – Web Application Vulnerability Scanner


Webpwn3r is a powerful scanning tool, written in Python, to detect remote command execution vulnerabilities, cross-site scripting attacks, and database weaknesses in the web applications.


Features

The current version of the tool has the ability to scan a single URL or a list of URLs provided in a text file. The tool is able to provide information about the remote code injection vulnerabilities in the desired URL or list of URLs. Webpwn3r can detect WAF (Web Application Firewall) technologies such as Web Knight, it also performs XSS vulnerability scanning on the target web applications. The other features include the fingerprinting of the backend technologies of the target web applications and scanning for SQL injection vulnerabilities on the target web application.

Installation

Webpwn3r can be installed by cloning the tool from a GitHub repository using the following command.
git clone https://github.com/zigoo0/webpwn3r

How it Works

webpwn3r run command
Using Webpwn3r is quite simple.  After successfully cloning the tool, change the directory to the Webpwn3r folder to run the following command.
python scan.py
The command launches the Webpwn3r with an option to select a single URL or multiple URLs scanning. For the sake of this tutorial, we have selected first option i-e single URL scanning. Once the URL is provided to the tool, it makes a connection with the remote web application server. The status code [200 ok] means the connection has been set up successfully and the tool is ready to start the fingerprinting of the remote technology used by the web application. After fingerprinting, Webpwn3r scans the target URL for Remote code (command execution), XSS, and error based SQL injection possibilities. The tool tests the SQL injection for MySQL, MSSQL, MSACCESS, PostGreSQL, and Oracle databases. If the target URL is secure, the tool responds with no vulnerabilities found the message.
If a vulnerability exists on a target URL, it is displayed in the Webpwn3r results.
Webpwn3r is a powerful scanning tool with the payloads that can bypass many security filters and web applications firewalls. The tool is very useful for web applications penetration testing.
4. Osueta – A Script for OpenSSH Server Side Attacks


So what is this Osueta script all about?

Osueta is a powerful python script used for exploiting the OpenSSH vulnerabilities through User-Enumeration Time based attack methodology. With a User-Enumerated Time-based attack, the attacker searches for usernames on a target server. The attack is unique in the sense it makes the brute force attack more effective by utilizing efforts on finding just the passwords for the identified usernames.
OpenSSH is a network level security suite that uses Secure Shell (SSH) protocol to secure the network communication through different encryption techniques. The SSH protocol was introduced to secure networks from Man in the middle (MITM) and Eavesdropping cyber-attacks. Since OpenSSH server uses a username and password-based authentication protocols, Osueta becomes handy in exploiting OpenSSH server vulnerabilities and finding the usernames on the target server.

Installing Osueta

In Linux, Osueta can be installed through the following commands.
apt-get install python-ipy python-nmap
pip install paramiko
git clone https://github.com/c0r3dump3d/osueta.git
Once Osueta is installed, change the directory to osueta either by following the osueta directory path or by copying the Osueta folder to the Desktop and redirecting to osueta using the following commands.
cd Desktop
cd osueta

Let’s see Osueta in Action!

To see Osueta into action, we need to find out the target IP address. This can be done by using the following command. The <url> in the following command is the target service URL hosted on the target server.
whatweb <url>
The above command helps in finding the server IP address along with other useful information as depicted in the following screenshot.
After successfully finding the server IP address, use the following command to find out the username on the target server.
python osueta.py –H <IP Address Here> –U pp –p 22
Here the H <IP Address> is the server IP address. The U represents random username. The p is the port number used in the attack. In the given case, it is 22. When the command is run, Osueta checks if the port is open or closed. If the port is open, it detects the service banner to know the SSH version. Afterward, Osueta tests random usernames by analyzing time delays. A list of usernames can also be fed into Osueta to check if the username exists at the server. If there is a time delay, it means the username exists because the server is busy in generating and comparing the hash of a very long password provided by Osueta.

So what else can it do?

Osueta can also be used to launch a Denial of Service (DoS) attack using the following command.
./osueta.py –H <IP Address Here>  –p 22 –U pp –v no –dos yes
The syntax “dos” represents the Denial of Service attack.
So, These are some latest tools used in ethical hacking to target your social media accounts and other sites and check the exploits and vulnerabilities.

For More Information - Click Here 

Wednesday, July 4, 2018

Top 5 Operating Systems Used for Ethical Hacking and Penetration Testing

Top 5 Operating Systems Used For Ethical Hacking And Penetration Testing


What is Operating System (OS)?

An operating system (OS) is system software that manages computer hardware and software resources and provides common services for computer programs.

Now, It’s time to pause the archaic Windows vs. OS X vs. Linux discussion and switch over to some advanced operating systems dedicated to pen testing and ethical hacking. 
This list includes Linux distros like Kali Linux, Parrot Security OS, BlackArch, etc.

Top 5 Operating Systems Used For Ethical Hacking And Penetration Testing - 2018

1. KALI LINUX

It is developed by Offensive Security as the rewrite of BackTrack and tops our list as one of the top operating systems for hacking purposes. This Debian-based OS comes with 500+ preinstalled pen testing tools and applications that make your security toolbox richer to start along. These flexible tools are frequently updated and are offered for different platforms like ARM and VMware. Kali Linux is also feasible for a forensic job as it comes with a live boot capability that provides a perfect environment for vulnerability detection.
Download Kali Linux




2. PARROT SECURITY OS

It is also a Debian-based OS that is developed by Frozenbox’s team. Parrot security is a cloud-friendly operating system designed for ethical hacking, pen testing, computer forensics, cryptography, etc. Compared to others, Parrot Security OS is a lightweight OS that is highly efficient to work with. Parrot Security OS is a mixture of Frozenbox OS and Kali Linux. Moreover, this highly customizable hacking operating system also comes with a strong community support.
Download Parrot Security OS


3. BACKBOX

BackBox Linux is an Ubuntu-based operating system that is used for security assessment and penetration testing. BackBox Linux has a wide range of security analysis tools that can be used for web application analysis, network analysis, etc. It is fast and easy to use Linux distro that is famous among hacker’s community which comes with a complete desktop environment. The software applications provided by the OS are regularly updated with the most stable versions.
Download BackBox



4. Samurai Web Testing Framework

Samurai Web Testing Framework is essentially a live Linux environment that comes pre-configured to work as a web penetration testing platform. It contains multiple free and open source hacking tools for detecting web vulnerabilities. It is often known as the best operating system for Web Penetration Testing.



5. DEFT LINUX

The open-source Linux distribution “DEFT” stands for Digital Evidence and Forensic Toolkit. DEFT is based on Ubuntu and built around the DART (Digital Advanced Response Toolkit) software. It is preconfigured with many popular forensic tools and documents that can be used by ethical hackers, penetration testers, IT security specialists, and other individuals.
Download DEFT Linux




However, there are many other distributions as well that are used by many professional, but these are the mainly used distributions that are highly recommended and preferred by experienced professionals from the field. Moreover, the selection of Linux distribution depends on the purpose for what purpose it is being used.
For More Knowledge of Ethical Hacking Click Here

Saturday, June 30, 2018

DDoS Attack - Working and Tools

DDoS Attack


What is DDoS Attack?


  • Distributed denial of service (DDoS) attacks is a subclass of denial of service (DoS) attacks. A DDoS attack involves multiple connected online devices, collectively known as a Botnet, which is used to overwhelm a target website with fake traffic.
  • A distributed denial-of-service (DDoS) attack is a malicious attempt to disrupt normal traffic of a targeted server, service or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic.
  • From a high level, a DDoS attack is like a traffic jam clogging up with the highway, preventing regular traffic from arriving at its desired destination.


Difference Between DoS and DDoS Attack?

In a DoS attack, a perpetrator uses a single Internet connection to either exploit a software vulnerability or flood a target with fake requests—usually in an attempt to exhaust server resources (e.g., RAM and CPU).

On the other hand, distributed denial of service (DDoS) attacks is launched from multiple connected devices that are distributed across the Internet. These multi-person, multi-device barrages are generally harder to deflect, mostly due to the sheer volume of devices involved. Unlike single-source DoS attacks.

DDoS attacks also differ in the manner of their execution. Broadly speaking, DoS attacks are launched using homebrewed scripts or DoS tools (e.g., Low Orbit Ion Canon), while DDoS attacks are launched from botnets — large clusters of connected devices (e.g., cell phones, PCs or routers) infected with malware that allows remote control by an attacker.

How does a DDoS attack work?

A DDoS attack requires an attacker to gain control of a network of online machines in order to carry out an attack. Computers and other machines (such as IoT devices) are infected with malware, turning each one into a bot (or zombie). The attacker then has remote control over the group of bots, which is called a botnet.
Once a botnet has been established, the attacker is able to direct the machines by sending updated instructions to each bot via a method of remote control. When the IP address of a victim is targeted by the botnet, each bot will respond by sending requests to the target, potentially causing the targeted server or network to overflow capacity, resulting in a denial-of-service to normal traffic. Because each bot is a legitimate Internet device, separating the attack traffic from normal traffic can be difficult.

What are common types of DDoS attacks?

Different DDoS attack vectors target varying components of a network connection. In order to understand how different DDoS attacks work, it is necessary to know how a network connection is made. A network connection on the Internet is composed of many different components or “layers”. Like building a house from the ground up, each step in the model has a different purpose. The OSI model, shown below, is a conceptual framework used to describe network connectivity in 7 distinct layers.


There are 3 Types of Attacks  -
1. Application Layer attack
2. Protocol Attack
3. Volumetric Attack

Tools Used in DoS/DDoS Attacks -

1. Slowloris
2. LOIC ( Low Orbit Ion Cannon )
3. GoldenEye
4. HOIC ( High Orbit Ion Cannon )
5. XOIC
6. RUDY ( R U Dead Yet ? )
7. TOR's Hammer
8. THC-SSL-DoS
9. Pyloris
10. HULK ( Http Unbreakable Load King )

Andriod Tools -

1. AnDOSid
2. LIOC

Sunday, June 24, 2018

Social Engineering - Tactics and Preventions

SOCIAL ENGINEERING


What is Social Engineering?
  • Social engineering is the term used for a broad range of malicious activities accomplished through human interactions.
  • It uses psychological manipulation to trick users into making security mistakes or giving away sensitive information.
  • Social engineering is the art of manipulating users of a computing system into revealing confidential information that can be used to gain unauthorized access to a computer system. 
  • The term can also include activities such as exploiting human kindness, greed, and curiosity to gain access to restricted access buildings or getting the users into installing backdoor software.



Note - What makes social engineering especially dangerous is that it relies on human error, rather than vulnerabilities in software and operating systems.

What are some examples of what social engineers say or do?Criminals will often take weeks and months getting to know a place before even coming in the door or making a phone call. Their preparation might include finding a company phone list or org chart and researching employees on social networking sites like LinkedIn or Facebook. 
There are three ways to do it in an organization are -
1. On Phone Call 
2. In Office
3. Online
SOCIAL ENGINEERING ATTACK TECHNIQUESSocial engineering attacks come in many different forms and can be performed anywhere where human interaction is involved. The following are the five most common forms of digital social engineering assaults.
1. Baiting 
Baiting attacks use a false promise to pique a victim’s greed or curiosity. They lure users into a trap that steals their personal information or inflicts their systems with malware.

2. Scareware
Scareware involves victims being bombarded with false alarms and fictitious threats. Users are deceived to think their system is infected with malware, prompting them to install software that has no real benefit (other than for the perpetrator) or is malware itself. Scareware is also referred to as deception software, rogue scanner software, and fraudwares.

3. Pretexting
Here an attacker obtains information through a series of cleverly crafted lies. The scam is often initiated by a perpetrator pretending to need sensitive information from a victim so as to perform a critical task.
The attacker usually starts by establishing trust with their victim by impersonating co-workers, police, bank and tax officials, or other persons who have right-to-know authority. The pretexter asks questions that are ostensibly required to confirm the victim’s identity, through which they gather important personal data.

4. Phishing
As one of the most popular social engineering attack types, phishing scams are email and text message campaigns aimed at creating a sense of urgency, curiosity or fear in victims. It then prods them into revealing sensitive information, clicking on links to malicious websites, or opening attachments that contain malware.

5. Spear Phishing
This is a more targeted version of the phishing scam whereby an attacker chooses specific individuals or enterprises. They then tailor their messages based on characteristics, job positions, and contacts belonging to their victims to make their attack less conspicuous. Spear Phishing requires much more effort on behalf of the perpetrator and may take weeks and months to pull off. They’re much harder to detect and have better success rates if done skillfully.


NOTE - To perform social engineering attacks for educational purpose you can use Social Engineering Toolkit (SET) in Kali Linux.

How to Defend Yourself from Social Engineers?
Social engineers manipulate human feelings, such as curiosity or fear, to carry out schemes and draw victims into their traps. Therefore, be wary whenever you feel alarmed by an email, attracted to an offer displayed on a website, or when you come across stray digital media lying about. Being alert can help you protect yourself against most social engineering attacks taking place in the digital realm.

  • Don’t open emails and attachments from suspicious sources – If you don’t know the sender in question, you don’t need to answer an email. Even if you do know them and are suspicious about their message, cross-check and confirm the news from other sources, such as via telephone or directly from a service provider’s site. Remember that email addresses are spoofed all of the time; even an email purportedly coming from a trusted source may have actually been initiated by an attacker.
  • Use multifactor authentication – One of the most valuable pieces of information attackers seek are user credentials. Using multifactor authentication helps ensure your account’s protection in the event of system compromise. Imperva Incapsula Login Protect is an easy-to-deploy 2FA solution that can increase account security for your applications.
  • Be wary of tempting offers – If an offer sounds too enticing, think twice before accepting it as fact. Googling the topic can help you quickly determine whether you’re dealing with a legitimate offer or a trap.
  • Keep your antivirus/antimalware software updated – Make sure automatic updates are engaged, or make it a habit to download the latest signatures first thing each day. Periodically check to make sure that the updates have been applied, and scan your system for possible infections.

Friday, June 22, 2018

Computer Virus - Types and Precautions

VIRUS - TYPES AND PRECAUTIONS



A Virus is a malicious software program "Malware" that can infect a computer by modifying or deleting data files, boot sector of the hard disk drive or cause a software to work in an unexpected manner.
A computer virus resides on a host computer and can replicate itself when executed. The virus can steal user data, record keystrokes & web sessions of a user.
Cause of Virus -
The following are the main causes of a Computer Virus.
1. Infected Flash Drives or Disks
Flash drives and disks are the main cause of spreading viruses. A virus can also be copied from one computer to other when the user copies infected files using flash drives and disks.
2. Email Attachments
Most of the viruses spread through emails. The email attachment is a file that is sent along with an email. An email may contain an infected file attachment. The virus can spread if the users open and download an email attachment. It may harm the computer when it is activated. It may destroy files on the hard disk or may send the virus automatically to all email addresses saved in the address book.
3. Infected / Pornography websites
Thousands of insecure websites can infect the computer with viruses. Most of the websites with pornographic materials are infected, so by visiting these websites the user’s computer also gets infected by a virus. These websites are developed to spread viruses or other unethical material. The virus is transferred to the user’s computer when this material is downloaded. These websites may access the computer automatically when the users visit them.
4. Networks
The virus can spread if an infected computer is connected to a the network. The internet is an example of such network. When a user downloads a file infected with a virus from the internet, the virus is copied to the computer. It may infect the files stored on the computer.
5. Pirated Softwares
An illegal copy of the software is called pirated software. A virus can spread if a user installs pirated software that contains a virus. A variety of pirated software is available in CDs and from the internet. Some companies intentionally add virus in the software. The virus is automatically activated if the user uses the software without purchasing a license.
Types of Virus -
There are various types of virus known to this time are -
1. Boot Sector Virus
Even though this virus has now become obsolete, it still pops out in one way or the other. This virus got attention when floppy disks were used to boot a computer. In modern computers, this virus could appear on the “Master Boot Record”. In the partitioned storage device of your computer, it is the first sector to take place. However, thanks to the fact evolution of the Internet, the threat of this virus is now mitigated.
2. Web Scripting Virus
Similar to the hyperlinks that we used in Microsoft Word, many websites rest on codes to provide engaging content to their users. For example, since the trends of watching videos online have now become very popular – more than 2 Billion Videos are streamed on Facebook every day, these videos also execute a specific code. 
These codes can be exploited and it is very troublesome to note that this exploitation has taken place on some very notable sites. All the hackers have to do it to leave a comment in the Comments Section of the website which contains that code. Thus, even without the Webmaster knowing it, the code gets exerted into the site.
3. Browser Hijacker
Ever faced a problem where the homepage of your web page gets automatically directed to a particular site? Well, that is the most common way by which this ransomware hijacks your browser.
While its visual effects might epitomize the threat, this hijacker is nothing more than a tactic to increase income from web ads. 
4. Resident Virus
After inserting itself directing into the memory of your system, this virus has the capability to take a number of actions. One of its more troublesome features is its ability to run away. Leaving behind the file which was originally infected, this virus has the ability to run on its own.

5. Direct Action Virus

Similar to the Vienna virus which shocked computers in 1998, this virus comes into action after you have executed the file. The load is delivered to your computer and the virus becomes active.
However, this virus has a limitation. It takes no action unless the file which is infected gets implemented again.

6. Polymorphic Virus

One of the factors that epitomize the usefulness of this virus is its ability to evade. The Antivirus programs that are enabled on our computers detect the presence of any virus by detecting its code.
The polymorphic virus has exploited this limitation beautifully as it changes its code every time the infected file is executed. Thus, it becomes nearly impossible for any ordinary antivirus to track it down.

7. File Infector Virus

Although the word “file” in its name might suggest otherwise, this virus does not take the help of files every time. In fact, the file is only the starting point as the file infector dwarfs the first file after which it re-writes the file.

8. Multipartite Virus

If you have read carefully the aforementioned viruses, you might have noticed that they use two methods for their transmission. Either they use one method or a single payload is delivered.
However, this virus wants to claim both. Depending upon the operating system of your computer or the files that exist on your computer, it might use any of the two methods to spread.

9. Macro Virus

Appearing in the form of a word document which seemingly links the user to pornographic websites, Melissa is one of the most known Micro Virus. Going one step further, this virus not only exploits the user but also his/her friends by mailing the copies of the infected virus document to the contact list.
Some Common Well-known Viruses are -
1. Code Red
It is a worm that infects a computer running Microsoft IIS server. This virus launched DOS attack on White House’s website. It allows the hacker to access the infected computer remotely.
2. Nimba
It is a worm that spreads itself using different methods. IT damages the computer in different ways. It modified files, alters security settings and degrades performance.
3. SirCam
It is distributed as an email attachment. It may delete files, degrade performance and send the files to anyone.
4. Melisa
It is a virus that is distributed as an email attachment. IT disables different safeguards in MS Word. It sends itself to 50 people if Microsoft Outlook is installed.
5. Ripper
It corrupts data from the hard disk.
6. MDMA
It is transferred from one MS Word file to other if both files are in memory.
7. Concept
It is also transferred as an email attachment. It saves the file in template directory instead of its original location.
8. One_Half
It encrypts hard disk so only the virus may read the data. It displays One_Half on the screen when the encryption is half completed.

Protection from Computer Virus

The virus infects computer system if the latest and updated version of an Antivirus program is not installed. Latest Antivirus software should be installed on Computer to protect it from viruses. 
A computer system can be protected from the virus by following these precautions.
  1. The latest and updated version of Anti-Virus and firewall should be installed on the computer.
  2. The Anti-Virus software must be upgraded regularly.
  3. USB drives should be scanned for viruses, and should not be used on infected computers.
  4. Junk or unknown emails should not be opened and must be deleted straight away.
  5. Unauthorized or pirated software should not be installed on the computer.
  6. An important way of protection against the virus is the use of back up of data. The backup is used if the virus deletes data or modifies it. So back up your data on regular basis. There is some great software that can back up your data automatically.
  7. Freeware and shareware software from the internet normally contain viruses. It is important to check the software before using them.
  8. Your best protection is your common sense. Never click on suspicious links, never download songs, videos or files from suspicious websites. Never share your personal data with people you don’t know over the internet.

Here is a Small Tutorial about How to make Simple Viruses - Click this Link

News! New Hacking Tools - 2018 - Target Exploits and Vulnerabilities Easily

New Hacking Tools - 2018 With Increase in Technology, Increase the demand for Cyber Security and it is also essential to develop the ...