FROM THE SECURITY WORLD: Quirky moments at Black Hat DC 2011
1.Padding Oracle Crypto Attack, the hack takes advantage of how Microsoft's Web framework ASP.NET protects AES encryption cookies.
2.Evercookie -- This enables a Java script to create cookies that hide in eight different places within a browser, making it difficult to scrub them. Evercookie enables the hacker to identify the machine even if traditional cookies have been removed. (Created by Samy Kamkar.)
3.Hacking Autocomplete -- If the feature in certain browsers that automatically completes forms on Web sites (autocomplete) is turned on, script on a malicious Web site can force the browser to fill in personal data by tapping various data stored on the victim's computer. (Created by Jeremiah Grossman.)
4.Attacking HTTPS with Cache Injection -- Injection of malicious Java script libraries into a browser cache enables attackers to compromise Web sites protected by SSL. This will work until the cache is cleared. Nearly half the top 1 million Web sites use external Java script libraries. (Crated by Elie Bursztein, Baptiste Gourdin and Dan Boneh.)
5.Bypassing CSRF protections with ClickJacking and HTTP Parameter Pollution -- Gets around cross site request forgery defenses and tricks victims into revealing their e-mail IDs. Using these, the attackers can reset the victim's passwords and gain access to their accounts. (Created by Lavakumar Kuppan.)
6.Universal XSS in IE8 -- Internet Explorer 8 has cross-site scripting protections that this exploit can circumvent and allow Web pages to be rendered improperly in a potentially malicious manner.
7.HTTP POST DoS -- HTTP POST headers are sent to servers to let them know how much data is being sent, then the data is sent very slowly, eating up the servers' resources. When many of these are sent simultaneously, the servers are overwhelmed. (Created by Wong Onn Chee and Tom Brennan.)
8.JavaSnoop -- A Java agent attached to the target machine communicates with the JavaSnoop tool to test applications on the machine for security weaknesses. This could be a security tool or a hacking tool, depending on the user's mindset. (Created by Arshan Dabirsiagh.)
9.CSS History Hack in Firefox without JavaScript for Intranet Port Scanning -- Cascading style sheets, used to define the presentation of HTML, can be used to grab browser histories as victims visit Web sites. The history information can be used to set the victim up for phishing attacks. (Created by Robert "RSnake" Hansen.)
10.Java Applet DNS Rebinding -- A pair of Java applets direct a browser to a pair of attacker controlled Web sites, forcing the browser to bypass its DNS cache and so make it susceptible to an NDS rebinding attack. (Created by Stefano Di Paola.)
Wednesday, February 23, 2011
Tuesday, February 22, 2011
5 Best Free Network Packet Analyzer tool!
Network Packet Analyzer, a network analyzer program that help network administrator captures and interactively browse the traffic packet that running on a computer network and analyze traffic information
1. WireShark : Wireshark packet sniffer is the most popular free network packet sniffer that works on both Unix, as well as Windows. Wireshark packet sniffer able to capture live real-time network packets. Apart from that, it is able to intelligently decipher packets based on their protocol. It can show the capture data on GUI. It is even able to detect and capture VOIP calls, and in some cases can even play back the media.
Apart from that, Wireshark network packet website also provides tons of resources, including videos, to learn how to use Wireshark, and analyze Wireshark data!
2. Microsoft Network Monitor: Microsoft Network Monitor is a free network packet analyzer and works on Windows PCs only. It provides expert network capability to see all the network traffic in real time on an intuitive GUI. Meanwhile, it can capture and view network information more than 300 public, and Microsoft proprietary network protocols including wireless network packets.
Besides that, Microsoft Network Monitor can be used by beginners just to analyze their home network traffic, or by network administrators to analyze complete organization network by sniffing network packets.
Download Microsoft Network Monitor here
3. Capsa Packet Sniffer: Capsa is a must-have network packet analyzer freeware for network administrators to monitor, troubleshoot and diagnose their network.The free network packet analyzer version comes with tons of features, and is good enough for home use, as well as use in small business.
Free Capsa Packet Sniffer software lets you monitor and capture 50 IP addresses network traffic data together and effective network analysis in real time by sniffing network packets, and analyze them.
Capsa Packet Sniffer Features:
Detailed Traffic Monitor of all computers
Bandwidth monitoring (to find which computers are watching online videos)
Network diagnosis to identify problems in network
Netwok activity logging (for recording IM, and web mail)
Network behavior monitoring
Download Capsa Packet Sniffer here.
4. InnoNWSniffer: The name InnoNWSniffer stands for Inno Network Sniffer. The application was developed to be a small IP scanner similar to Network Sniffer. It can scan Live Public IP and scan any computer on the LAN. More over it can give a detailed system Information.
5. SniffPass
SniffPass is a unique traffic packet sniffer, which it focuses on capturing passwords from network traffic. Whenever you active Sniffpass password sniffer, it will keeps on monitoring network traffic and as soon as it intercepts a password, it instantly shows that on screen. This is a great way to find forgotten passwords of websites.
Sniffpass password sniffer is quite easy in its use, and provides a nice GUI to monitor all captured passwords. Sniffpass password sniffer supports most of the networks protocols, like: POP3, IMAP4, SMTP, FTP, and
1. WireShark : Wireshark packet sniffer is the most popular free network packet sniffer that works on both Unix, as well as Windows. Wireshark packet sniffer able to capture live real-time network packets. Apart from that, it is able to intelligently decipher packets based on their protocol. It can show the capture data on GUI. It is even able to detect and capture VOIP calls, and in some cases can even play back the media.
Apart from that, Wireshark network packet website also provides tons of resources, including videos, to learn how to use Wireshark, and analyze Wireshark data!
2. Microsoft Network Monitor: Microsoft Network Monitor is a free network packet analyzer and works on Windows PCs only. It provides expert network capability to see all the network traffic in real time on an intuitive GUI. Meanwhile, it can capture and view network information more than 300 public, and Microsoft proprietary network protocols including wireless network packets.
Besides that, Microsoft Network Monitor can be used by beginners just to analyze their home network traffic, or by network administrators to analyze complete organization network by sniffing network packets.
Download Microsoft Network Monitor here
3. Capsa Packet Sniffer: Capsa is a must-have network packet analyzer freeware for network administrators to monitor, troubleshoot and diagnose their network.The free network packet analyzer version comes with tons of features, and is good enough for home use, as well as use in small business.
Free Capsa Packet Sniffer software lets you monitor and capture 50 IP addresses network traffic data together and effective network analysis in real time by sniffing network packets, and analyze them.
Capsa Packet Sniffer Features:
Detailed Traffic Monitor of all computers
Bandwidth monitoring (to find which computers are watching online videos)
Network diagnosis to identify problems in network
Netwok activity logging (for recording IM, and web mail)
Network behavior monitoring
Download Capsa Packet Sniffer here.
4. InnoNWSniffer: The name InnoNWSniffer stands for Inno Network Sniffer. The application was developed to be a small IP scanner similar to Network Sniffer. It can scan Live Public IP and scan any computer on the LAN. More over it can give a detailed system Information.
5. SniffPass
SniffPass is a unique traffic packet sniffer, which it focuses on capturing passwords from network traffic. Whenever you active Sniffpass password sniffer, it will keeps on monitoring network traffic and as soon as it intercepts a password, it instantly shows that on screen. This is a great way to find forgotten passwords of websites.
Sniffpass password sniffer is quite easy in its use, and provides a nice GUI to monitor all captured passwords. Sniffpass password sniffer supports most of the networks protocols, like: POP3, IMAP4, SMTP, FTP, and
Sunday, February 13, 2011
Tuesday, February 8, 2011
Thursday, January 27, 2011
Nak delete oracle dlm registery
1- start your PC in safe mode, delete the parent Oracle folder from your drive.
2- Restart in Normal mode.
3- Open the registry using regedit.exe from start/run/
4- delete from the registry the following entries/keys
HKEY_LOCAL_MACHINE/SOFTWARE/ORACLE
HKEY_LOCAL_MACHINE/SYSTEM
Controlset001/services/%oracle_services%
Controlset002/services/%oracle_services%
Now you need clean the legacy entries from your registry.
If your OS is not Win XP you need to use regedt32.exe. If Win XP then use the regedit.exe.
To remove the legacy entries you have to be the Administrator and change the security on the legacy keys so you can delete it.
HKEY_LOCAL_MACHINE/SOFTWARE/SYSTEM/Controlset001/ENUM/Root/Legacy%Oracle_services%
and the same for Controllset002.
I suggest you?d be VERY CAREFUL with the registry, one single mistake and bye-bye Windows.
and also drop the database with dbca before you uninstall the software, and use oradim to remove the services.
2- Restart in Normal mode.
3- Open the registry using regedit.exe from start/run/
4- delete from the registry the following entries/keys
HKEY_LOCAL_MACHINE/SOFTWARE/ORACLE
HKEY_LOCAL_MACHINE/SYSTEM
Controlset001/services/%oracle_services%
Controlset002/services/%oracle_services%
Now you need clean the legacy entries from your registry.
If your OS is not Win XP you need to use regedt32.exe. If Win XP then use the regedit.exe.
To remove the legacy entries you have to be the Administrator and change the security on the legacy keys so you can delete it.
HKEY_LOCAL_MACHINE/SOFTWARE/SYSTEM/Controlset001/ENUM/Root/Legacy%Oracle_services%
and the same for Controllset002.
I suggest you?d be VERY CAREFUL with the registry, one single mistake and bye-bye Windows.
and also drop the database with dbca before you uninstall the software, and use oradim to remove the services.
Monday, December 28, 2009
command ifconfig unix
command tuk downkan network
# ifconfig hme0 down && ifconfig -a
lo0: flags=1000849 mtu 8232 index 1
inet 127.0.0.1 netmask ff000000
hme0: flags=1000842 mtu 1500 index 2
inet 192.168.30.41 netmask ffffff00 broadcast 192.168.30.255
ether 8:0:20:93:c9:af
command tuk upkan network
# ifconfig hme0 up
# ifconfig -a
lo0: flags=1000849 mtu 8232 index 1
inet 127.0.0.1 netmask ff000000
hme0: flags=1000843 mtu 1500 index 2
inet 192.168.30.41 netmask ffffff00 broadcast 192.168.30.255
ether 8:0:20:93:c9:af
Sending ICMP ECHO_REQUEST Packets
To determine if you can contact another system over the network, enter
the ping command:
# ping sys41
sys41 is alive
# ifconfig hme0 down && ifconfig -a
lo0: flags=1000849
inet 127.0.0.1 netmask ff000000
hme0: flags=1000842
inet 192.168.30.41 netmask ffffff00 broadcast 192.168.30.255
ether 8:0:20:93:c9:af
command tuk upkan network
# ifconfig hme0 up
# ifconfig -a
lo0: flags=1000849
inet 127.0.0.1 netmask ff000000
hme0: flags=1000843
inet 192.168.30.41 netmask ffffff00 broadcast 192.168.30.255
ether 8:0:20:93:c9:af
Sending ICMP ECHO_REQUEST Packets
To determine if you can contact another system over the network, enter
the ping command:
# ping sys41
sys41 is alive
Thursday, December 17, 2009
installation perl..
salam...bertemu lagi kita dah lama tak update blog ni kerana sibuk.ok lah ni saya tunjukkan cara-cara nak menggunakan software perl...selepas install software perl kita buat satu fail.pl
create satu file notepad.masukkan script seperti dibawah..

kemudian kita save fail notepad ini dgn fail ym.pl.secara automatik fail ini akan berubah berlogo perl.kemuadian masuk cmd

taip dimana fail.pl yg kita letak tadi
cth:
c:cd Desktop
c:Desktop>perl ym.perl
akan terpapar menu ini

taip sahaja id yahoo kawan kita ia akan paparkan sama ada kawan kita online ke offline...
create satu file notepad.masukkan script seperti dibawah..

kemudian kita save fail notepad ini dgn fail ym.pl.secara automatik fail ini akan berubah berlogo perl.kemuadian masuk cmd

taip dimana fail.pl yg kita letak tadi
cth:
c:cd Desktop
c:Desktop>perl ym.perl
akan terpapar menu ini

taip sahaja id yahoo kawan kita ia akan paparkan sama ada kawan kita online ke offline...
Subscribe to:
Posts (Atom)
