Today : | at : | Safemode : ON
> Det_Not Hacker | White Hat Aliance | Angkasa Hacker Team | Indonesia | Satu Gertakan Untuk Pertahankan Bumi Pertiwi | Safework of Angkasa Pura database, server MIL.ID | Thanks for all support : BD Green Hat, Nation blood, ID Codding, Jakarta Style cracking, Newbie's HACKER, US ortodox specialist | Learn your skill here with our style.
Title Author Perms Comt Modified Category
Showing posts with label wiki. Show all posts
Showing posts with label wiki. Show all posts

Penetration Testing Methodologies Unknown rwxr-xr-x 0 22:29

Title Penetration Testing Methodologies
Permission rw-r--r--
Author Unknown
Date and Time 22:29
Category
Share
In doing the penetration testing there is a methodology needed just as we do any other testing procedure. This methodology is needed to make sure that the process is right and the result of the testing is reliable and could be used in the future development of the tested system as well. There are many different methodologies of this particular testing that can be used by anyone doing this testing. All of the methodologies are issued by different department with different characteristics as well. On this article there would be some of the most common methodologies of testing penetration used by people in doing this testing procedure.



The first methodology in doing penetration testing that is commonly used by people is the USSAF methodology. The ISSAF is the flagship project of the OISSG with the latest version is the version 0.2 that is available for any industry need to do this testing. This methodology is the first one that provides such validation for the bottom up strategies of the security. The next famous methodology of this testing is the OSSTMM which is Open Source Security Testing Methodology Manual. This one is a peer-reviewed security metrics and tests methodology.

There are five channels available on this methodology in conducting the security test to maximize the result including the data & information controls and also security awareness level of the personnel as well. The last one is the Open Web Application Security Project or the OWASP. This is an open-source security application project of the OWASP community. This community provides methodologies, tools, technologies, documentations, and also articles related to the testing of security on a particular system. All of those three are the most commonly used methodologies in conducting the testing of the network or computer security system known as the penetration testing.

Best Penetration Testing Tools Unknown rwxr-xr-x 0 22:28

Title Best Penetration Testing Tools
Permission rw-r--r--
Author Unknown
Date and Time 22:28
Category
Share
In doing the penetration testing there are penetration testing tools needed to make sure that the process is done smoothly and giving the best possible result out of it. There are so many available tools for this testing that you could choose to perform the testing procedure. Among those many tools available, there are some of the best tools that you can find on this article. The first one is the Acunetix which is available for you in free version and also paid version. This particular security testing tool has a client script engine analyzer that will generate very detailed security vulnerabilities and issues report. The latest version is version 8 that has new HTTP Denial of Service test module.




Second best penetration testing tools is the Aircrack-ng that offers you many tools to maximize the penetration testing that you are going to do. The tools provided by Aircrack-ng include airdecap-ng, airmon-ng, aireplay-ng, airtun-ng, airodump-ng, and a couple more. Each one of the tool will have different functionality with other tools. This Aircrak-ng has free security tool called as GUI interface just as many other tools for the penetration test.

Third tools of penetration testing that is considered being the best is the Cain & Abel or it often called simply as Cain. This one is mainly known as the tool to recover any password. The penetration tester could recover any password by getting into the network and cracking such encrypted password on the system. Although it is considered as the best tool for penetration testing this one is also known to have a script-kiddie characteristic as well. Getting the best tools in any activity is important to maximize the result. Therefore in conducting the penetration testing, you should consider choosing one of these best penetration testing tools to get the best result of the testing procedure.

More Things to Know About Penetration Testing Unknown rwxr-xr-x 0 22:26

Title More Things to Know About Penetration Testing
Permission rw-r--r--
Author Unknown
Date and Time 22:26
Category
Share
The ultimate goal of the penetration testing is to find out all available security vulnerabilities on the system that is tested. Something is considered as vulnerability of the system whenever this thing could increase the possibility of any attacker to attack the security of the system and then gain access to the control of the system itself. The control of the system in a particular organization or group should never be obtained by anyone else but the owner or administrator for the safety of the organization. Most common things that are considered as the vulnerabilities of the system are software bugs, system design flaws, and also system configuration errors. These things could be more powerful threat to the system when they are all combined. Thus the testing penetration is needed to prevent such vulnerabilities to disturb the system.



People might have just wondering then about whom or what should conduct this penetration testing. Since the threats of the network or computer system are so many, almost any of you using computer or network system based should perform this particular type of testing. Nevertheless there are four most common ideas of the one that should perform the testing. First is the one of the organization or industry that has regulated data types. This usually the one deal with financial services such as credit-card data. Second is the one which is a product vendor with regulated client or customer. One example of this is a developer of web.

Third is the one that the systems have been hacked before and find out that the effect of the hack is terrible. Fourth is the one that simply think it would be better to test the security of the system before bad thing happen to the system itself. Those are four common ideas in relation to whom or what should perform this penetration testing.

Things to Consider in Doing the Penetration Testing Unknown rwxr-xr-x 0 22:25

Title Things to Consider in Doing the Penetration Testing
Permission rw-r--r--
Author Unknown
Date and Time 22:25
Category
Share
There are two things that could make people look for any information related to the penetration testing. First, it could be that someone else suggests them to perform the testing just to make sure that their system is safe just before any attack occurred. Second, it could be that their system has been hacked or penetrated before so that they want to make sure their new established system is safe and hack proof. Either one is the reason, it is clear that this testing penetration is needed in any operation of such organization or anything using computer or network system.




Moreover there are a couple of things that you have to make sure in dealing with such penetration testing. This is an important thing to do therefore have to make sure that everything is at its best to guarantee its success. First, you have to ask your colleagues if they know such recommended vendor that could perform the testing. Second, once you find a vendor ask the vendor for some references of similar organizations as yours.

Third, ask the vendor for the similar testing projects that they have done previously. Fourth, ask the vendor for testing report of their previously done testing so that you could evaluate the report. Fifth, ask the vendor for the complete information of the staffs that are going to do the testing for you. You can also do some background check as well to make sure that the staff is qualified. Sixth, make sure to have an agreement on the testing that will be performed so that there would be no miscommunication during the testing. When you consider all of the things stated above before doing the testing for your system, you will be able to get the best possible outcome from the penetration testing.

The Importance of Penetration Testing Unknown rwxr-xr-x 0 22:24

Title The Importance of Penetration Testing
Permission rw-r--r--
Author Unknown
Date and Time 22:24
Category
Share
There are reasons that penetration testing is important and valuable to do. First, this particular testing could determine such feasibility of attack vectors that are possible in attacking computer or network security system. Second, this testing could find out the high-risk vulnerabilities that are actually a result of low-risk vulnerabilities combination on a particular network or computer system. Third, this testing could show any possible vulnerabilities or threats that cannot be detected just by using automated vulnerability scanner software. Fourth, this testing could provide the result or impact of such attacks on the vulnerabilities on the computer or network system. Fifth, this testing could provide reasons to invest on the development of the more sophisticated network or computer system in the future. Those are the five reasons that make this testing penetration are very important to do.



Moreover, the penetration testing is a kind of testing that need to be done regularly on a system that is changed regularly as well. The process of the testing could simply derive into two different parts. The first part of the testing is by finding out the legal operations combinations lead to illegal operation. The first process could be done by leveraging some flaws and then shaping the payload so that it would be considered as a valid operation.

Second part is finding out the specific illegal operation that is often called as payloads as well. There are companies and organizations that keep such large database containing known exploits. There is a certificate for this testing known as the Certified Penetration Tester or CPT which is managed by the Information Assurance Certification Review Board of IACRB. The exam candidate of the penetration testing should pass multiple choice exam and practical exam which is a penetration test against some servers in a virtual environment to be certified by the IACRB.

What is Penetration Testing? Unknown rwxr-xr-x 0 22:24

Title What is Penetration Testing?
Permission rw-r--r--
Author Unknown
Date and Time 22:24
Category
Share
The penetration testing is a particularly known method of computer and network security evaluation. Generally this testing is done by giving a simulation of attack on the computer or network that is tested. This particular method of testing the security of computer or network is known to be the oldest method used since the 1970s. The Department of Defense performed this particular testing in the 1970 in order to describe the weaknesses in the computer system at that time. Thus after the weaknesses described, the Department of Defense initiated the development of more secure computer systems thanks to the testing penetration.




The penetration testing involves the analysis of the computer system from any possible vulnerability available. These vulnerabilities could be caused by poor system configuration, hardware or software flaws, or technical countermeasures as well. This particular analysis is carried out of the possible attacker position which could involve more exploitation of the security vulnerabilities of the computer or the network.

The result of this testing then would be presented to the owner of the tested systems. The result of the test that is presented to the owner will have the security issues on it along with the effect of those issues to the organization using the system. The best solution for the issues is also stated on the result as well.

Once the owner of the computer or network system given the result of this particular testing, it is fully the owner’s rights to decide what to do the next. This testing is very widely used by many organizations to make sure that their computer or network system is safe before publicly exposed. Thus it is important for any new organization using computer or network on its operation to have the penetration testing first before doing any of its operation.

Kali Linux Review, The Linux Penetration Testing Distribution Unknown rwxr-xr-x 0 22:22

Title Kali Linux Review, The Linux Penetration Testing Distribution
Permission rw-r--r--
Author Unknown
Date and Time 22:22
Category
Share
Kali Linux is a great successor to BackTrack. Many people loved Linux Penetration Distro/ Operating System that is aimed at penetration testers and security professionals. Read this following brief history of how Kali Linux came to be. Backtrack is very familiar around the last seven years. It is created and managed by Offensive Security.

Kali Linux is different for the fine folks over at Offensive Security,  when solving the ‘inherent problems’ of BackTrack the authors needed a complete re-write. The problem is too many pentesting tools embedded within BackTrack all struggled to co-exist within the dependencies.  BackTrack v1-v5 that a headache for dependencies. Many penetrating and security tools where not regularly updated by their creators so the result was that trying to update the entire OS often caused conflicts and tools would  stop working, crash or even cause other tools to crash. For example is Ettercap which was not updated for a long time.

For solving the problem we can rebuild the distro bottom-up by making Kali Debian based. Before with BackTrack there was a /pentest/ folder.  Now, it all updated and managed by Debian packages.
Kali Linux has 300 tools which automatically work within the Kali ecosphere. Kali also has been created with the clean "File system Hierarchy Standard" and offers vast plug and play wireless support, with the only exception appearing to be broadcom.
Another interesting feature about Kali Linux is that it is supported with ARM architecture so you can use the distro on Raspberry Pi’s and Chromebooks etc. You can also create your own  file with Kali through the Debian lifebuild feature.

For summary, Kali is a well thought out penetration testing distribution which had to address its’ previous problems with regards to updates. It has two modes: forensics and default, all of which run best in gnome. All the usual pentesting tools work with the distro with ease and the file hierarchy is the same as previous BackTrack versions. For pentesting Kali Linux is clearly an awesome OS with the world’s best pentesting suite of tools that can all be preconfigured. Couple that with the very large and loyal community, bug tracking service and attention to detail. It is a solid pentesting Linux distribution.

Things to Do After Your Site is Hacked Unknown rwxr-xr-x 0 22:22

Title Things to Do After Your Site is Hacked
Permission rw-r--r--
Author Unknown
Date and Time 22:22
Category
Share
If your site is hacked or you have been a victim of a server hack, don’t worry. Keep calm and do what I say :-). Probably, there is an attack at some third party web applications or your servers could have been breached (someone with password access infected files in the server with malware). You need to take action as soon as possible to stop the damage and restore your site online. Here are some tips from me to help your site.


1. Contact your hosting
Contact your hosting provider if you notice that your site is hacked. Contact your hosting as soon as possible and ask them to investigate the attack.

2. Change all of your passwords
You should also change all your passwords (FTP/SFTP accounts, MySQL accounts and even your Root password) immediately. Passwords should be long, difficult to guess, so it will be a

3. Back Up your databases
Start backing up your MySQL database. In order to back up your MySQL databases, you can simply use PHPMyAdmin in your cPanel (Database < 10MB). For larger databases, you can backup via SSH (if available in your webhost)

4. Back up your site content
Back up your web contents as soon as possible. For backing up other server/site content, you can use tools like Cobian Backup (http://www.cobiansoft.com) or CyberDuck (http://cyberduck.ch). Don’t worry about malicious code being included in your backup, you can later clean it out.

5. Check the logs
Look through your logs in your webhosting account in order to see whether someone has logged into your webhosting account.  Also, check your site files for any changes or modifications that occur without your permission.

6. Clean up the Malicious Files
In order to destroy themalicious files, Scan through all corrupted files and server directories. You should also destroy old or unused code. Set the permissions to 755 and 644 for all directory files in your server.

7. Update your Software
If you are use CMS, update your CMS with the latest version. Then the final step is import your cleaned up site content and SQL databases to the server.

Best Penetration Testing Tools Unknown rwxr-xr-x 0 22:20

Title Best Penetration Testing Tools
Permission rw-r--r--
Author Unknown
Date and Time 22:20
Category
Share
There are many penetration testing tools on the market. They have been selected to cover a range of testing techniques from web based testing to network mapping, but the best penetration testing  tools are not complete because there are different tools to use for specific tests.



Acunetix
Acunetix are web vulnerability scanner is. It can  a variety of different types of web vulnerabilities, such as SQL Injection and XSS exploits. With built in crawlers, http editors and fuzzers, it providers a large set of useful diagnostic tools to help validate and verify flaws. Today it is one of the best website penetration testing tools.

Metasploit
Metasploit Framework is a key penetration testing tool when it comes to exploit development, host vulnerability validation and exploit execution. It is an opensource project that was created by HD Moore in 2003. It comes with over 800 exploits for Windows, Linux and Mac Operating Systems, with a very simple to use modular system for loading the desired payload. Metasploit also provides the option of encoding the payload in a variety of different formats to help bypass intrusion detection systems, prior to execution. This is a very powerful  and one of the most popular penetration testing tool for exploit development and testing with huge community backing.

Nmap
Nmap is one of the most common tools in a penetration testers arsenal. The tool allows fast host discovery, port mapping, service/operating system identification and enumeration to assist in gathering as much potential basic information about the network and alive hosts. It was developed by Fyodor and was originally an open source project for use on Linux/BSD. Now, It is developed to work on platforms such as Windows and Mac. A relatively new GUI version of Nmap, ‘Zenmap’  was released to work in Windows along side the CLI version.

Wireshark
Wireshark is an opensource packet analyser (network sniffer), which will capture and dump network activity sniffed on active wireless or wired LAN cards. You can capture data and save it as a pcap file watch the network traffic in real-time.  It is able to capture through USB showing what a great tool it is when it comes to analysis of data traffic. It is very useful when trying to monitor network resources, worm activity or general network abuse. Now, the penetration testing tool is available on Windows, Mac and Linux platforms.

Cain and Abel
Cain and Abel is a Windows based password recovery / cracking tool. Cain for short – the software is one of the most versatile password recovery tools available, currently supporting Windows password hash recovery, wireless passwords, MSSQL Passwords, Kerberos, Cisco, VNC, Radius and many more. It has been developed to crack passwords using brute force dictionary attacks, cryptanalysis and rainbow tables.

So, you can choose the best penetration testing  tools for your better and faster work now. Have a nice try.

Information Gathering Using Domain Name Unknown rwxr-xr-x 0 22:18

Title Information Gathering Using Domain Name
Permission rw-r--r--
Author Unknown
Date and Time 22:18
Category
Share
Hacker can gather lots of information just by identifying a domain name of the website. Yes you are right, Information Gathering Using Domain Name. Domain name is a system where we provide a hostname which is automatically converted into the real IP address, so people don’t need remember the IP address, just the domain name or DNS address. When gathering information from a domain name, the first thing need to do is WHOIS. A domain name stores the information about the registered user of domain name itself, IP address, IP address range, and etc. Not only that, with WHOIS we can get the information about domain’s registrant, his contacts, his address, when the domain will expire, etc.

WHOIS can only reveal basic information, not all of the available information of domain name. Ok lets try using WHOIS to gathering a domain information. Open your Terminal and run the WHOIS program or you can search and use free service of WHOIS in the internet.

whois google.com

Now you get domain name information. There are domain name, registered through, registrant, and domain servers. Usually, WHOIS will return the following information about a domain:

  • Inetnum
    The IP range the address.
  • Route
    The address prefix to be routed.
  • Descr
    A short description of related to the domain.
  • Origin
  • Mnt-by
  • Changed
    The Information about who last updated the database object of domain name.
  • Source
    The database place / source of the registered domain name.
Information Gathering Using Domain Name

And some optional attributes are:
  • Country
    The country of the domain registrant. Two letter code of the country.
  • Holes
    The Lists about address prefixes that are not reachable through the route.
  • Member of
  • Inject
    Specifies which routers perform the aggregation.
  • Aggr-mtd
  • Aggr-bndry
  • Export-comps
  • Components
    The component routes used to form the aggregate.
  • Remarks
  • Notify
    The email address where the notification of updated information will be send. 
  • Mnt-lower
  • Mnt-routes
Remember, not all of the domain name stores its registrant data. Some of domain are private. So Information Gathering Using Domain Name is easy, right?

What is Cross-Site Scripting (XSS) Unknown rwxr-xr-x 0 22:17

Title What is Cross-Site Scripting (XSS)
Permission rw-r--r--
Author Unknown
Date and Time 22:17
Category
Share
There are lots of vulnerabilities in the web applications today. One of the most popular web application vulnerability is Cross-Site Scripting (XSS). Cross-Site Scripting (XSS) is one of the top 10 Web Application Security Risks for 2010 by OWASP. So what is Cross-Site Scripting (XSS)?  Cross-Site Scripting (XSS) is one of the injection technique, like sql injection. But Cross-Site Scripting (XSS) injects a malicious scripts like VB, JS, etc. The malicious scripts are injected into a trusted web site.


Cross-Site Scripting (XSS) allows the attacker to execute a dangerous scripts in the victim’s browser. Then the script can access victim’s crucial data, like cookies, session, cache, etc. Attacker also can rewrite the HTML page.



There are 3 basic XSS flaws, they are reflected, stored and DOM based.

Reflected
Reflected is most common type of the XSS flaw that found in the web applications. The injected code will reflected off the web server. The attacker attacks victims via another route, such as email message or other web server. Attacker will sends a malicious link to the victims.

Stored
This ismore devastating variant os XSS. Attackers can inject malicious code in the web applications and the injected code is permantly store on the target servers. This is a dangerous attack. For example attacker leaving malicious code in a blog’s comment of vulnerable blog web application. The malicious code will execute in the browser of the other blog visitor.

DOM based.
DOM is a World Wide Web Consortium (W3C) specification. DOM is a object model for representing XML and HTML structures. Attacker payload is executed as the result of modifying the DOM in the victim’s browser. Like the other XSS, DOM based XSS can be used to steal victim’s data or hijack the victim’s banking account.

Cross-Site Scripting (XSS) is one of the popular technique of penetration. So you must be careful and use a internet security software to protect you from hacker.

Basic Skills of Penetration Tester Unknown rwxr-xr-x 0 22:12

Title Basic Skills of Penetration Tester
Permission rw-r--r--
Author Unknown
Date and Time 22:12
Category
Share
If you want become a hacker or a penetration tester, you must have basic skill of it. Basic skill of hacker needed so you can be a professional pentester. There are 10 basic skill and you must take over all of them.
1. Expert of operating system.
Operating System is a basic skill of hacking. You must become master in Operating System. So many people want to be a hacker without any knowledge of Operating System. Learn now, learn Unix Operating System. You must know about the OS details so you can find the vulnerability of it.

2. Good knowledge of networking
Networking is a main of hacking art. Learn about networking and network protocols. You must know TCP (Transmission Control Protocol), what is TCP / IP, understand routing, understand of package exchange, how DNS works, understand ARP, understand DHCP, IP address, OSI layer, etc. You must expert on it.
3. "How does it work?"
You must know how something works. Learn the concepts and you can get the answer of your questions about it.
4. Learn basic scripting
Try to learn bash so you can make your own program that will help you. Although bash is a basic scripting in Linux so you must learn it if you want mastering operating system.
5. Basic Firewall
Firewall is annoying "wall". It’s difficulty to defeat. You must find about the firewall details and learn hos to defeat it.
6. Know some forensics
This is optional, but if you learn forensics, it makes you better at covering your tracks.
7. Learn a programming language
You can make a program that will help you to automate something or a Trojan, backdoor, virus, etc.
8. Learn new stuff
Stay up to date about security news and learn something new so you can upgrade yourself.
9. Learn a little about databases
Database is a storage of crucial data. Learn how to operate it and how to hack it.
10. Interact and share your knowledge with like minded professionals
Try to sharing with other hacker to learn what you never learn.

Backtrack for Computer Forensics Unknown rwxr-xr-x 0 22:09

Title Backtrack for Computer Forensics
Permission rw-r--r--
Author Unknown
Date and Time 22:09
Category
Share
Computer or Digital Forensic has become popular right now. Computer forensics is a part of a digital forensic scientific discipline concerning authorized evidence seen in computer systems and also digital hard drive media (Wikipedia). Backtrack as the greatest security tool offers numerous resources intended for computer forensics. Not just penetration tests and also security attack, Backtrack additionally supports computer forensic. We are able to evaluate all kinds of operating systems, such as DOS, Windows, MAC, or UNIX.


The fundamental ways of computer forensics:

  1. Preparation
  2. Collection
  3. Examination
  4. Analysis
  5. Reporting
Computer forensic applications is actually work to investigate a digital evidence since numerous gadget could be potential evidence which help your computer analyst discover the reality. Evidence is found in data files and other facts locations. The consumer isn't aware which their own data has been created to their documents.

Backtrack linux offers several possible source to become trusted digital forensic applications. Backtrack offers a lot of resources that support computer analyst to accomplish several work such as Examine drive, Analyzing drive, Recovery drive, Vulnerabilities scan, Penetration testing, and also File interogration.

Classification of digital forensic tool.

Data Acquisition.
Data Acquisition is defined of software that is responsible to interrogate harddrive and get neccessary info from them.
Data Recovery and Carving.
The details Retrieval resources is placed of application that responsible to obtain remove data back again, inspecting invisible and also remove partition, as well as repairing the damaged block of filesystem. Information carving is actually taking out details (files) from undifferentiated blocks (raw data) with regards to data file identification.

Meta Data Analysis.
Meta Data Exploration is seeking invisible variable, to complete the meta details examination we want several software which could carry out exercise just like dissassembling a file (ducument/image/audio/video) and have invisible variable such as while had been data file final accessed, when had been it revised, or even simeting such as whenever had been data file may be produced and also utilizing exactly what applications it is may be produced

Network Forensic.
Network Forensic equipment isn't a lot different when match up against network security plan, cause that's have actual very same formula although most people do the reverese enginnering kinds. Network forensic tools protected this sort of jobs like make a good analysis of network visitors, captures data transmitted as part of TCP connections (flows)

Log File Analysis.
You will find the different parts of data files that could have got evidentiary value for example the day and also time of creation, modification, deletion, access, user name or identification, and file attributes. computer-created data files (log) which may be possible evidence are backup data files, log files, configuration files, printer spool files, cookies, swap files, hidden files, system files, history files, temporary files, link files, event logs.

Man In The Middle Attack Unknown rwxr-xr-x 0 22:08

Title Man In The Middle Attack
Permission rw-r--r--
Author Unknown
Date and Time 22:08
Category
Share
Man In The Middle attack is the kind of attack exactly where attackers intrude straight into a current connection to intercept the exchanged information and inject fake information. That involves eavesdropping on the network, intruding in a network, intercepting messages, and also selectively changing information.
The definition of "Man-in-the-middle attack" (MITM attack) describes the kind of attack in which the attacker intrudes in the connection between endpoints on a network in order to inject fake data and also intercept the data transmitted amongst all of them.

The actual name "Man in the Middle" hails from the basketball scenario when 2 players want to pass the ball to one another while 1 player in between them tries to grab it. Man In The Middle attacks are often known as "bucket brigade attacks" or maybe "fire brigade attacks. " Those names are actually based on the fire brigade procedure of dousing over fire by simply passing buckets from one individual to another one between the water resource and also the fire.


Man In The Middle Attack
The Man In The Middle attack is extremely effective due to the character of the http protocol and also data exchange which are all ASCII structured. In this manner, it’s potential to view and also interview inside the http protocol plus in the information transferred. As a result, as an example, it’s possible to catch the session cookie reading through the http header, however it’s also possible to modify some money transaction in the application context.

The Man In The Middle attack is also carried out over a good https connection using the same exact method; the only real significant difference is made up in the establishment of 2 independent SSL sessions, 1 over each TCP connection. The web browser sets the SSL connection with the attacker, and also the attacker establishes one more SSL connection with the world wide web server.

Generally the web browser alerts the user that the digital certificate used isn't valid, however the user could ignore the caution simply because he or she doesn’t understand the actual risk. In certain specific contexts it’s possible which the notice doesn’t show up, for example, once the Server certificate is usually affected through the attacker or even when the attacker certificate is actually authorized by a reliable CA and also the CN may be the same on the original web page. Man In The Middle isn't just a great attack method, but can be generally used throughout the development stage of the web application or even is still utilized for Web Vulnerability tests.

There are many tools to obtain the Man In The Middle attack. These kinds of tools tend to be especially effective within LAN network environments, since they implement additional uses, such as the arp spoof abilities which enable the interception of connection between hosts.

Backtrack Wireless Cards Compatibility List Unknown rwxr-xr-x 0 21:55

Title Backtrack Wireless Cards Compatibility List
Permission rw-r--r--
Author Unknown
Date and Time 21:55
Category
Share
With wireless card that compatible for Backtrack, you can do some wireless penetration or injection without error because the wireless card totally works. Now here are the tested wireless cards that totally works on Backtrack and some wireless card that doesn't work on Backtrack.



Backtrack Wireless Cards Compatibility List

Working Backtrack Wireless Cards

  1. AWUS036H (rtl8187, r8187)
  2. AWUS036NH (Ralink RT2870/3070)
  3. BCM4312 802.11b/g LP-PHY (rev 01)
  4. Rockland N3 - (Ralink RT2870/3070)
  5. Edimax EW-7318USG USB - (Ralink RT2501/RT2573)
  6. ASUSTek Computer, Inc. RT2573
  7. Linksys WUSB54GC ver 3
  8. Ubiquiti SRC
  9. Internal Intel Corporation PRO/Wireless 3945ABG
  10. Dlink WNA-2330 PCMCIA
  11. Atheros Communications Inc. AR9285 Wireless Network Adapter (PCI-Express) (rev 01)
  12. Netgear wg111v2
  13. ZyXEL AG-225H v2
  14. Intel 4956/5xxx

Working Backtrack Wireless Cards (without injection)

  1. Broadcom Corporation BCM4321 802.11a/b/g/n (rev 03)
  2. Broadcom Corporation BCM4322 802.11a/b/g/n Wireless LAN Controller (rev 01)

Not Working Backtrack Wireless Cards

  1. D-Link DWL-122
  2. Linksys WUSB600N v2
  3. AWUS051NH

How to Become Ethical Hacker Unknown rwxr-xr-x 0 21:49

Title How to Become Ethical Hacker
Permission rw-r--r--
Author Unknown
Date and Time 21:49
Category
Share
What is an ethical hacker? Who are the ethical hackers? Ethical hackers is a white hat hackers, legal hacker, or you can called them penetration tester. They protect systems from dangerous intrusions. Ethical hacker are expert in computer security. Ethical hackers are technically skilled IT that has been pass an IT certification or computer security certification. One of the certification and training of ethical hacker is CEH. What is CEH? The Certified Ethical Hacker is a professional certification provided by the International Council of E-Commerce Consultants (EC-Council.). It provide online training and certification of ethical hacker. Now I'll explain you how to become an ethical hacker, how to ethical hacking, and how to become it certified.



How to Become Ethical Hacker


To be a professional ethical hacker you require motivation, dedication, initiative, self-education and formal training in ethical hacking.

1. Be a white hat hacker
This is most important part of become an ethical hacker. You must be a white hacker. If you be white hacker you will be legal hacker or the other cool name, penetration tester.

2. Learn the network system
THIS IS THE BASIC SKILL! You must learn it and expert on it

3. Learn the UNIX operating system
THIS IS ALSO BASIC SKILL! You must expert and know how to use UNIX operating system. Not only UNIX, you must learn Windows and Mac OS so you can know how that OS work and you can find the vulnerability.

4. Stay tune on computer security news
Stay up to date to the IT securrity news. With this you can know about new hacking technique, exploit, etc

5. Stay connected to the hacker community
You can get free support if you get some difficulty from your community

6. Take a professional course
Yes of course, you must take some security professional course, training, or sertification. One of them is Certified Ethical Hacker (CEH). CEH has obtained a certification in how to look for the weaknesses and vulnerabilities in target systems and uses the same knowledge and tools as a hacker. Qualification for a CEH involves mastering penetration testing, footprinting and reconnaissance, and social engineering. You will learn creating Trojan horses, backdoors, viruses, and worms. Also denial of service (DoS) attacks, SQL injection, buffer overflow, session hijacking, and system hacking.


That's all about what is an ethical hacker? who are the ethical hackers? how to become an ethical hacker, how to ethical hacking, and how to become it certified. Hope you like it

New Tools on Backtrack 5 R3 Unknown rwxr-xr-x 0 21:42

Title New Tools on Backtrack 5 R3
Permission rw-r--r--
Author Unknown
Date and Time 21:42
Category
Share
on Aug 13th, Backtrack 5 R3 brings new additional tools. Some of the new tools were released as part of presentations at the recent Black Hat and DEFCON conferences. Backtrack 5 R3 has also added a completely new category of software, it's called "physical exploitation" that includes libraries and an IDE for the Arduino and the Kautilya toolkit  which provides payloads for the Teensy USB development board .Here are the list of new additional tools of Backtrack 5 R3 so you can compare it to previous version (Backtrack 5 R2).

Identify Live Hosts:
dnmap – Distributed NMap
address6 (The Second “Alive6″ entry) – IPV6 address conversion

Information Gathering Analysis
Jigsaw – Grabs information about company employees
Uberharvest – E-mail harvester
sslcaudit – SSL Cert audit
VoIP honey – VoIP Honeypot
urlcrazy – Detects URL typos used in typo squatting, url hijacking, phishing

Web Crawlers
Apache_users – Apache username enumerator
Deblaze – Performs enumeration & interrogation against Flash remote end points

Database Analysis
Tnscmd10g – Allows you to inject commands into Oracle
BBQSQL – Blind SQL injection toolkit

Bluetooth Analysis
Blueranger – Uses link quality to locate Bluetooth devices

Vulnerability Assesment
Lynis – Scans systems & software for security issues
DotDotPwn – Directory Traversal fuzzer

Exploitation Tools
Netgear-telnetable – Enables Telnet console on Netgear devices
Termineter – Smart Meter tester
Htexploit – Tool to bypass standard directory protection
Jboss-Autopwn – Deploys JSP shell on target JBoss servers
Websploit – Scans & analyses remote systems for vulnerabilities

Wireless Exploitation Tools
Bluepot – Bluetooth honeypot
Spooftooph – Spoofs or clones Bluetooth devices
Smartphone-Pentest-Framework
Fern-Wifi-cracker – Gui for testing Wireless encryption strength
Wi-fihoney – Creates fake APs using all encryption and monitors with Airodump
Wifite – Automated wireless auditor

A Bunch of Password Tools
Creddump
Johnny
Manglefizz
Ophcrack
Phrasendresher
Rainbowcrack
Acccheck
smbexec

How to Mastering Metasploit Framework Unknown rwxr-xr-x 0 20:51

Title How to Mastering Metasploit Framework
Permission rw-r--r--
Author Unknown
Date and Time 20:51
Category
Share
Metasploit Framework is the best penetration tool, it has 3 different version. The Metasploit Community Edition (free and web-based user interface for Metasploit), Metasploit Express (an open-core commercial edition for security teams who need to verify vulnerabilities), and Metasploit Pro ( an open-core commercial Metasploit edition for penetration testers). Now how to mastering Metasploit Framework?

Metasploit Unleashed is the answer. Metasploit Unleashed is free online version of the course. It explain how to use Metasploit Framework from zero become hero. There are basic, introduction of Metasploit Framework, reference, and etc. 
If you want learn from this online course you must download some required materials. Virtualbox, Metasploitable (a vulnerable VMware virtual machine), and Windows XP SP 2. Those required materials are available on the site.
So if you want to be a master Metasploit Framework, check this site out!
http://www.offensive-security.com/metasploit-unleashed

Backtrack Guide Hargo Haripamudya rwxr-xr-x 0 20:23

Title Backtrack Guide
Permission rw-r--r--
Author Hargo Haripamudya
Date and Time 20:23
Category
Share
Backtrack is a Linux and some beginner user of the Linux operating system very difficulty to operate it. Linux does't like Windows, using Linux mean you must use CLI or command line as the way of operating it although you can use GUI too. But Linux more power full when you use it trough the terminal. As a penetration distribution, Backtrack has hundreds of security tools and you know what? Almost of the hundreds of tools used console to operating it self.


But if you a Linux user, using Backtrack isn't a problem anymore. But if you a beginner of Linux and Backtrack you can learn the guide of Backtrack on the Backtrack Wiki. Backtrack Wiki is a guide how to use Backtrack Linux Operating System.

You can visit http://www.backtrack-linux.org/wiki/ and start learn the basic operational of Backtrack. So what are you waiting for? Lets read The Ninjas Guide of Back|Track.
Powered by Blogger.