Latest Post
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
06:31
Folder Lock Full Version | Key
Written By Unknown on Sunday, 17 March 2013 | 06:31
Labels:
Computer file
,
Encryption
,
Installation (computer programs)
,
Operating system
,
Security
,
windows
,
Windows Vista
,
Windows XP
08:59
CloseTheDoor - indentifies all the listening ports TCP/UDP over IPv4/v6
Written By Unknown on Tuesday, 12 March 2013 | 08:59
CloseTheDoor indentifies all the listening ports TCP/UDP over IPv4/v6 and the associated program files. This will help you to detect security holes and close backdoors when you want to prevent remote attacks.
Features
Download CloseTheDoorSetup-v0.2.1.exe (128.5 kB)
Download older versions from here
Screenshot -
Features
- Enumerate all listening ports for IPv4/IPv6
- Gather informations about the listening ports
- Ability to disable potentially dangerous ports
Download older versions from here
Screenshot -
Labels:
close ports
,
Security
,
System Security
07:46
Ophcrack is a free Windows password cracker based on rainbow tables. It is a very efficient implementation of rainbow tables done by the inventors of the method. It comes with a Graphical User Interface and runs on multiple platforms.
Download older versions along with tables
Download tables from here
OPHCRACK 3.4.1 (Time-Memory-Trade-Off-Crack) A windows password cracker based on the faster time-memory trade-off using rainbow tables.
This is an evolution of the original ophcrack 1.0 developed at EPFL (http://lasecwww.epfl.ch/~oechslin/projects/ophcrack) Ophrack 3.4.1 comes with a Qt Graphical User Interface which runs on Windows, Mac OS X as well as on Unix. GETTING and INSTALLING OPHCRACK Ophcrack 3.4.1 can be downloaded from sourceforge: http://ophcrack.sourceforge.net The Windows version comes with an installer that suggests automatic install or download of the tables. The linux version is a source package. It can be compiled and installed using the "./configure", "make" and "make install" commands. The tables have to be downloaded by hand, from the URL given above. HOWTO This howto assumes you have already installed ophcrack 3 and downloaded the ophcrack rainbow tables you want to use. It also assumes that you understand how to use third party tools like pwdump or fgdump (http://www.foofus.net/fizzgig/) to dump the SAM of a Windows system. Ophcrack and the ophcrack LiveCD are available for free at the ophcrack project page (http://ophcrack.sourceforge.net/). Ophcrack rainbow tables are avaible at ophcrack rainbow tables page (http://ophcrack.sourceforge.net/tables.php). The XP free small, XP free fast and Vista free rainbow tables are free. The others ophcrack rainbow tables are sold by Objectif Securite. First step This step is optional but will speed up the cracking process. Run ophcrack and set the number of threads under the Preferences tab to the number of cores of the computer running ophcrack plus one.For example, for an old processor set the number of threads to 2, for a Core 2 Duo to 3 and for a Core 2 Quad to 5. If you change this value, you have to exit ophcrack and to restart it in order to save the change. If you don't exit and restart, the new number of threads will not be taken into account by the program. Second step This step is mandatory. Load hashes using the Load button. You can either enter the hash manually (Single hash option), import a text file containing hashes you created with pwdump, fgdump or similar third party tools (PWDUMP file option), extract the hashes from the SYSTEM and SAM files (Encrypted SAM option), dump the SAM from the computer ophcrack is running on (Local SAM option) or dump the SAM from a remote computer (Remote SAM option). For the Encrypted SAM option, the SAM is located under the Windows system32/config directory and can only be accessed for a Windows partition that is NOT running. For the Local SAM and Remote SAM options, you MUST logged in with the administrator rights on the computer you want to dump the SAM. Third step This step is optional but will speed up the cracking process. Delete with the Delete button every user account you are not interested in (for exemple the Guest account). You can use the Ctrl key to make multiple selection. Ctrl-a will select every loaded hash. Keep in mind that the time needed to crack password hashes with rainbow tables is proportional to the number of hashes loaded. With a brute force attack the cracking time is NOT dependant on the number of unsalted hashes loaded. That's why it's advisable to remove any unnecessary user account with the Delete button. Fourth step This step is mandatory. Install (Tables button), enable (green and yellow buttons) and sort wisely (up and down arrows) the rainbow tables your are going to use. Keep in mind that storing the rainbow tables on a fast medium like a hard disk will significantly speed up the cracking process. Here are a few guidelines : * If you want to crack LM hashes as found on Windows XP by default (the LM Hash column is never empty on the ophcrack main window), first install and enable either the XP free small (if you have less than 512MB of free RAM) or the XP free fast (if you have more than 512MB of free RAM). Do NOT enable both of them since this is generally useless and will slow down the cracking process. Then install and enable the Vista free tables set. Finally install and enable the other XP rainbow tables you may have (XP special, XP german) and Vista one (Vista special). Sort the rainbow tables with the up and down arrows the following way : first the XP free then the Vista free then the XP special after that the Vista special and finally the XP german. * If you want to crack NT hashes as found on Windows Vista by default (the LM Hash column is always empty on the ophcrack main window), first install and enable the Vista free tables set. Then install and enable the Vista special tables set. Disable every other XP tables sets since they are useless and slow down the cracking process. Sort the enabled rainbow tables with the up and down arrows the following way : first the Vista free then the Vista special. * If you want to crack a mix of LM and NT enabled hashes (some accounts have their LM column empty, others have both the LM and NT columns filled with hashes) proceed the same way as "If you want to crack LM enabled hashes". Fifth step This step is mandatory. Click on the Crack button to start the cracking process. You'll see the progress of the cracking process in the bottom boxes of the ophcrack window. When a password is found, it will be displayed in the NT Pwd field. You can then save the results of a cracking session at any time with the Save button.
Source-
http://sourceforge.net/projects/ophcrack/
http://ophcrack.sourceforge.net/
Snapshots-
Ophcrack-vista-livecd-3.4.0 - windows password cracker based on the faster time-memory trade-off using rainbow tables.
Ophcrack is a free Windows password cracker based on rainbow tables. It is a very efficient implementation of rainbow tables done by the inventors of the method. It comes with a Graphical User Interface and runs on multiple platforms.
Features:
- » Runs on Windows, Linux/Unix, Mac OS X, ...
- » Cracks LM and NTLM hashes.
- » Free tables available for Windows XP and Vista/7.
- » Brute-force module for simple passwords.
- » Audit mode and CSV export.
- » Real-time graphs to analyze the passwords.
- » LiveCD available to simplify the cracking.
- » Dumps and loads hashes from encrypted SAM recovered from a Windows partition.
- » Free and open source software (GPL).
Download older versions along with tables
Download tables from here
OPHCRACK 3.4.1 (Time-Memory-Trade-Off-Crack) A windows password cracker based on the faster time-memory trade-off using rainbow tables.
This is an evolution of the original ophcrack 1.0 developed at EPFL (http://lasecwww.epfl.ch/~oechslin/projects/ophcrack) Ophrack 3.4.1 comes with a Qt Graphical User Interface which runs on Windows, Mac OS X as well as on Unix. GETTING and INSTALLING OPHCRACK Ophcrack 3.4.1 can be downloaded from sourceforge: http://ophcrack.sourceforge.net The Windows version comes with an installer that suggests automatic install or download of the tables. The linux version is a source package. It can be compiled and installed using the "./configure", "make" and "make install" commands. The tables have to be downloaded by hand, from the URL given above. HOWTO This howto assumes you have already installed ophcrack 3 and downloaded the ophcrack rainbow tables you want to use. It also assumes that you understand how to use third party tools like pwdump or fgdump (http://www.foofus.net/fizzgig/) to dump the SAM of a Windows system. Ophcrack and the ophcrack LiveCD are available for free at the ophcrack project page (http://ophcrack.sourceforge.net/). Ophcrack rainbow tables are avaible at ophcrack rainbow tables page (http://ophcrack.sourceforge.net/tables.php). The XP free small, XP free fast and Vista free rainbow tables are free. The others ophcrack rainbow tables are sold by Objectif Securite. First step This step is optional but will speed up the cracking process. Run ophcrack and set the number of threads under the Preferences tab to the number of cores of the computer running ophcrack plus one.For example, for an old processor set the number of threads to 2, for a Core 2 Duo to 3 and for a Core 2 Quad to 5. If you change this value, you have to exit ophcrack and to restart it in order to save the change. If you don't exit and restart, the new number of threads will not be taken into account by the program. Second step This step is mandatory. Load hashes using the Load button. You can either enter the hash manually (Single hash option), import a text file containing hashes you created with pwdump, fgdump or similar third party tools (PWDUMP file option), extract the hashes from the SYSTEM and SAM files (Encrypted SAM option), dump the SAM from the computer ophcrack is running on (Local SAM option) or dump the SAM from a remote computer (Remote SAM option). For the Encrypted SAM option, the SAM is located under the Windows system32/config directory and can only be accessed for a Windows partition that is NOT running. For the Local SAM and Remote SAM options, you MUST logged in with the administrator rights on the computer you want to dump the SAM. Third step This step is optional but will speed up the cracking process. Delete with the Delete button every user account you are not interested in (for exemple the Guest account). You can use the Ctrl key to make multiple selection. Ctrl-a will select every loaded hash. Keep in mind that the time needed to crack password hashes with rainbow tables is proportional to the number of hashes loaded. With a brute force attack the cracking time is NOT dependant on the number of unsalted hashes loaded. That's why it's advisable to remove any unnecessary user account with the Delete button. Fourth step This step is mandatory. Install (Tables button), enable (green and yellow buttons) and sort wisely (up and down arrows) the rainbow tables your are going to use. Keep in mind that storing the rainbow tables on a fast medium like a hard disk will significantly speed up the cracking process. Here are a few guidelines : * If you want to crack LM hashes as found on Windows XP by default (the LM Hash column is never empty on the ophcrack main window), first install and enable either the XP free small (if you have less than 512MB of free RAM) or the XP free fast (if you have more than 512MB of free RAM). Do NOT enable both of them since this is generally useless and will slow down the cracking process. Then install and enable the Vista free tables set. Finally install and enable the other XP rainbow tables you may have (XP special, XP german) and Vista one (Vista special). Sort the rainbow tables with the up and down arrows the following way : first the XP free then the Vista free then the XP special after that the Vista special and finally the XP german. * If you want to crack NT hashes as found on Windows Vista by default (the LM Hash column is always empty on the ophcrack main window), first install and enable the Vista free tables set. Then install and enable the Vista special tables set. Disable every other XP tables sets since they are useless and slow down the cracking process. Sort the enabled rainbow tables with the up and down arrows the following way : first the Vista free then the Vista special. * If you want to crack a mix of LM and NT enabled hashes (some accounts have their LM column empty, others have both the LM and NT columns filled with hashes) proceed the same way as "If you want to crack LM enabled hashes". Fifth step This step is mandatory. Click on the Crack button to start the cracking process. You'll see the progress of the cracking process in the bottom boxes of the ophcrack window. When a password is found, it will be displayed in the NT Pwd field. You can then save the results of a cracking session at any time with the Save button.
Source-
http://sourceforge.net/projects/ophcrack/
http://ophcrack.sourceforge.net/
Snapshots-
Labels:
Bootable
,
cracker
,
liveCD
,
Security
,
System Security
04:06
UPDATE OWASP Zed Attack Proxy(ZAP) v 2.0.0 - an easy-to-use integrated penetration testing tool for finding vulnerabilities in Web applications
Written By Unknown on Thursday, 7 February 2013 | 04:06
OWASP Zed Attack Proxy (ZAP) is an easy-to-use integrated penetration testing tool for finding vulnerabilities in Web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing as well as being a useful addition to an experienced pen tester's toolbox. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually.
ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually.
Some of ZAP's features:
Download version 2.0.0 from here
ZAP_2.0.0_Windows.exe
ZAP_2.0.0_Linux.tar.gz
ZAP_2.0.0_Mac_OS_X.zip
OWASP Zed Attack Proxy v 2.0.0 released on 30-Jan-2013
ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually.
Some of ZAP's features:
- Intercepting Proxy
- Active scanner
- Passive scanner
- Brute Force scanner
- Spider
- Fuzzer
- Port Scanner
- Dynamic SSL certificates
- API
- Beanshell integration
Some of ZAP's characteristics:
- Easy to install (just requires java 1.7)
- Ease of use a priority
- Comprehensive help pages
- Fully Internationalized
- Under active development
- Open source
- Free (no paid for 'Pro' version)
- Cross platform
- Involvement actively encouraged
It supports the following languages:
- English
- Brazilian Portuguese
- Chinese
- Danish
- Filipino
- French
- German
- Greek
- Indonesian
- Italian
- Japanese
- Persian
- Polish
- Russian
- Spanish
Download version 2.0.0 from here
ZAP_2.0.0_Windows.exe
ZAP_2.0.0_Linux.tar.gz
ZAP_2.0.0_Mac_OS_X.zip
OWASP Zed Attack Proxy v 2.0.0 released on 30-Jan-2013
There is a new version of the OWASP Zed Attack Proxy (ZAP) available right now, and there are so many changes in it that we’ve decided to call it version 2.0.0.
If you just want to get stuck in and download it then head over to http://code.google.com/p/zaproxy/downloads/list : it's available for Windows, Linux and Mac OS.
(Note that the Mac OS specific release is coming soon, but the Linux release is actually cross platform and will work fine on Macs)
And if you want to learn a bit more about the changes then read on...
We can only cover the new features at a high level in one blog post, but the plan is to host a Google hangout demonstrating many of these features at 17:00 UTC on Friday 8th Feb. Details to be announced via https://twitter.com/zaproxy
Simon will also be presenting a talk at FOSDEM on Feb 2nd: Practical Security for developers, using OWASP ZAP
A replacement for the 'standard' Spider
A new 'Ajax' spider
Web Socket support
Quick Start tab
Session awareness
User defined Contexts
Session scope
Different modes
A scripting console
Authentication handling
More API support
Fine grained scanning controls
New and improved active and passive scanning rules
Many stability and usability fixes
If you just want to get stuck in and download it then head over to http://code.google.com/p/zaproxy/downloads/list : it's available for Windows, Linux and Mac OS.
(Note that the Mac OS specific release is coming soon, but the Linux release is actually cross platform and will work fine on Macs)
And if you want to learn a bit more about the changes then read on...
We can only cover the new features at a high level in one blog post, but the plan is to host a Google hangout demonstrating many of these features at 17:00 UTC on Friday 8th Feb. Details to be announced via https://twitter.com/zaproxy
Simon will also be presenting a talk at FOSDEM on Feb 2nd: Practical Security for developers, using OWASP ZAP
New features
An integrated add-ons marketplaceZAP can be extended by add-ons that have full access to all of the ZAP internals. Anyone can write add-ons and upload them to the ZAP Add-on Marketplace (OK, so its a Google code project called zap-extensions, but you get the idea).
More importantly you can now browse, download and install those add-ons from within ZAP. Most add-ons can be dynamically installed (and uninstalled) so you wont even need a restart.
You can choose to be notified of updates, and even be automatically updated. And as the scan rules are now implemented as add-ons you can get the latest rules as soon as they are published.
A replacement for the 'standard' Spider
The ‘old’ Spider was showing its age, so its been completely rewritten, and is much faster and more comprehensive than the old one. This is still a 'traditional' spider that analyses the HTML code for any links it can find.
A new 'Ajax' spider
In addition to the 'traditional' spider we've added an Ajax spider which is more effective with applications that make heavy use of JavaScript. This uses the Crawljax project which drives a browser (using Selenium) and so can discover any links an application generates, even ones generated client side.
Web Socket support
ZAP now supports WebSockets, so ZAP can now see all WebSocket messages sent to and from your browser. As with HTTP based messages, ZAP can also intercept WebSocket messages and allows you to change them on the fly.
You can also fuzz WebSockets messages as well using all of the fuzzing payloads included in ZAP from projects like JBroFuzz and fuzzdb. And of course you can easily add your own fuzzing files.
Quick Start tab
The first main tab you will now see is a ‘Quick Start’ tab which allows you to just type in a URL and scan it with one click.
This is an ideal starting point for people new to application security, but experts can easily remove it if they find it distracting.
Session awareness
ZAP is now session aware, so it can recognise and keep track of multiple sessions. It allows you to create new sessions, switch between them, and applies to all of the other components, like the Spider and Active Scanner.
User defined Contexts
You can now define any number of ‘contexts’ - related sets of URLs which make up an application. You can then target all URLs in a context, for example using the Spider or Active Scanner. You can also add the contexts to the scope, and associate other information, such as authentication details.
Session scope
The session scope allows you to specify which contexts you are interested at any one time. You can restrict what you see in various tabs to just the URLs in scope, and prevent accidentally attacking URLs not in scope by using the Protected mode.
Different modes
ZAP now supports 3 modes:
- Safe, in which no potentially dangerous operations permitted
- Protected, in which you can perform any actions on URLs in scope
- Standard, in which you can do anything to any URLs
A scripting console
This allows you to access any internal ZAP data structures dynamically using any scripting language that supports JSR 223,
Authentication handling
You can now associate authentication details with any context, which allows ZAP to do things like detect if and when you are logged out and automatically log you back in again. This is especially useful when used via the API in security regression tests.
More API support
The REST API has been significantly extended, giving you much more access to the functionality ZAP provides.
Fine grained scanning controls
The active scan rules can now be tuned to adjust their strength (the number of attacks they perform) and the threshold at which they report potential issues.
New and improved active and passive scanning rules
We have uploaded the results from running ZAP 2.0.0 against wavsep (the most comprehensive open source evaluation project we are aware of) to the ZAP wiki: http://code.google.com/p/zaproxy/wiki/TestingWavsep
Source-
06:16
Twitter Hacked, 250,000 Email and Password Compromised
Written By Unknown on Saturday, 2 February 2013 | 06:16
If you find that your Twitter password doesn't work the next time you try to login, you won't be alone. The service was busy resetting passwords and revoking cookies on Friday, following an online attack that may have leaked the account data of approximately 250,000 users.
"This week, we detected unusual access patterns that led to us identifying unauthorized access attempts to Twitter user data," Bob Lord, Twitter's director of information security, writes in a blog post.
According to Lord, Twitter was able to shut down the attack within moments of discovering it, but not before the attackers were able to make off with what he calls "limited user information," including usernames, email addresses, session tokens, and the encrypted and salted versions of passwords.
The encryption on such passwords is generally difficult to crack – but it's not impossible, particularly if the attacker is familiar with the algorithm used to encrypt them.
As a precaution, Lord says Twitter has reset the passwords of all 250,000 affected accounts – which, he observes, is just "a small percentage" of the more than 140 million Twitter users worldwide.
If yours is one of the accounts involved, you'll need to enter a new password the next time you login. Lord reminds all Twitter users to choose strong passwords – he recommends 10 or more characters, with a mix of letters, numbers, and symbols – because simpler passwords are easier to guess using brute-force methods. In addition, he recommends against using the same password on multiple sites.
Lord says Twitter's investigation is ongoing, and that it's taking the matter extremely seriously, particularly in light of recent attacks experienced by The New York Times and The Wall Street Journal:
While it's true that the Java plug-in contains multiple known vulnerabilities and that numerous security experts have warned that it should be considered unsafe, the connection between Java and the attack Twitter experienced isn't clear and twitter is yet to respond to our request for clarification.
"This week, we detected unusual access patterns that led to us identifying unauthorized access attempts to Twitter user data," Bob Lord, Twitter's director of information security, writes in a blog post.
According to Lord, Twitter was able to shut down the attack within moments of discovering it, but not before the attackers were able to make off with what he calls "limited user information," including usernames, email addresses, session tokens, and the encrypted and salted versions of passwords.
The encryption on such passwords is generally difficult to crack – but it's not impossible, particularly if the attacker is familiar with the algorithm used to encrypt them.
As a precaution, Lord says Twitter has reset the passwords of all 250,000 affected accounts – which, he observes, is just "a small percentage" of the more than 140 million Twitter users worldwide.
If yours is one of the accounts involved, you'll need to enter a new password the next time you login. Lord reminds all Twitter users to choose strong passwords – he recommends 10 or more characters, with a mix of letters, numbers, and symbols – because simpler passwords are easier to guess using brute-force methods. In addition, he recommends against using the same password on multiple sites.
Lord says Twitter's investigation is ongoing, and that it's taking the matter extremely seriously, particularly in light of recent attacks experienced by The New York Times and The Wall Street Journal:
This attack was not the work of amateurs, and we do not believe it was an isolated incident. The attackers were extremely sophisticated, and we believe other companies and organizations have also been recently similarly attacked. For that reason we felt that it was important to publicize this attack while we still gather information, and we are helping government and federal law enforcement in their effort to find and prosecute these attackers to make the Internet safer for all users.Although the attack took place this week, it seems to have no relationship to the outage that took Twitter offline for several hours on Thursday. On the other hand, however, Lord's post does make rather cryptic mention of the US Department of Homeland Security's recent recommendation that users disable the Java plug-in in their browsers. He mentions Java twice, in fact.
While it's true that the Java plug-in contains multiple known vulnerabilities and that numerous security experts have warned that it should be considered unsafe, the connection between Java and the attack Twitter experienced isn't clear and twitter is yet to respond to our request for clarification.
Labels:
China
,
Privacy
,
Security
,
Twitter
,
Twitter hack
00:08
Math Mark (Photo credit: Wikipedia)
Math Type Product Key
Written By Unknown on Monday, 28 January 2013 | 00:08
Math Type Product Key
Product Key:
MTWE660-347150-2009K
- Math Type Product Key (hackncrackz.blogspot.com)
- Windows 8 moves to BIOS-based product keys (reviews.cnet.com)
- How to Find Your Windows Product Key (survivalguide4idiots.com)
- Changing Product Key in Windows 8 (indiaitd.wordpress.com)
- Installation: Invalid Product Key (upandready.typepad.com)
- How can I use my product key to validate W7 on a replacement HDD? (ask.metafilter.com)
- Free Microsoft office 2010 product key or serial (downloadmicrosoftoffice.wordpress.com)
- Download Microsoft Office 2010 Activation Avec (Product Key + Crack + Keygen) Full Package (downloadmicrosoftoffice.wordpress.com)
- Download Adobe Photoshop CS6 Extended (Product Key+Keygen+Patch) For MAC & WINDOWS (newsofware2013freedownloads.wordpress.com)
- A Quick Tip for Hyper-V Users: Product Keys (garvis.ca)
Labels:
Hack
,
Microsoft Security Essentials
,
Microsoft Windows
,
Product key
,
Product Keys
,
Security
,
Tricks
,
Uploading and downloading
,
VBScript
,
Web search engine
,
Windows 8
03:19
Advance DDOS Tools: Encrypted Layer Attacks and Server-Based Botnets
Written By Unknown on Thursday, 24 January 2013 | 03:19
Application security solutions provider Radware has released its 2012 Global Application and Network Security Report. According to the study, distributed denial-of-service (DDOS) attacks are becoming more sophisticated and more severe.
In addition, cybercriminals have started deploying new attack tools, such as server-based botnets and encrypted layer attacks, to make their campaigns more effective.
While server-based botnets make the attacks more powerful, by weaponizing the encryption layer, cybercriminals can ensure that their operations escape detection and remain hidden.
The recent DDOS attacks launched by Izz ad-Din al-Qassam Cyber Fighters against US banks are a perfect example of how efficient these new tools are.
Besides the new attack tools, the report also highlights the fact that the number of DDOS and DOS attacks lasting more than one week doubled in 2012.
On the other hand, organizations are still not investing enough resources to ensure that they’re protected against such attacks.
While it’s becoming more and more difficult for organizations to protect their networks against cyberattacks, cybercriminals can turn to all sorts of relatively cheap services and kits that can help them achieve their goals.
“The Radware ERT sees hundreds of DoS/DDoS attacks each year, and we’ve found attacks lasting more than one week have doubled in frequency during 2012. Through empirical and statistical research coupled with front-line experience, our team identified trends that can help educate the security community,” noted Avi Chesla, chief technology officer at Radware.
“Through highlighting significant trends found in this report, our goal is to provide actionable intelligence to ensure organizations can better detect and mitigate these threats that plague their network infrastructure.”
The complete report is available here.
In addition, cybercriminals have started deploying new attack tools, such as server-based botnets and encrypted layer attacks, to make their campaigns more effective.
While server-based botnets make the attacks more powerful, by weaponizing the encryption layer, cybercriminals can ensure that their operations escape detection and remain hidden.
The recent DDOS attacks launched by Izz ad-Din al-Qassam Cyber Fighters against US banks are a perfect example of how efficient these new tools are.
Besides the new attack tools, the report also highlights the fact that the number of DDOS and DOS attacks lasting more than one week doubled in 2012.
On the other hand, organizations are still not investing enough resources to ensure that they’re protected against such attacks.
While it’s becoming more and more difficult for organizations to protect their networks against cyberattacks, cybercriminals can turn to all sorts of relatively cheap services and kits that can help them achieve their goals.
“The Radware ERT sees hundreds of DoS/DDoS attacks each year, and we’ve found attacks lasting more than one week have doubled in frequency during 2012. Through empirical and statistical research coupled with front-line experience, our team identified trends that can help educate the security community,” noted Avi Chesla, chief technology officer at Radware.
“Through highlighting significant trends found in this report, our goal is to provide actionable intelligence to ensure organizations can better detect and mitigate these threats that plague their network infrastructure.”
The complete report is available here.
Labels:
DDos Attack
,
Enterprise Security
,
Radware
,
Security
10:04
HoneyDrive 0.2 Nectar edition released!
Written By Unknown on Wednesday, 16 January 2013 | 10:04
new release for HoneyDrive (Desktop)!
This is version 0.2 aka Nectar edition, which brings more honeypot and malware related tools on the distro.
This is version 0.2 aka Nectar edition, which brings more honeypot and malware related tools on the distro.
You can download it from HoneyDrive's SourceForge page at: http://sourceforge.net/ projects/honeydrive/
MD5 Checksum: 8f0d65b4260e963e5639ab4555b3c7 0f
SHA-1 Checksum: 285775170167cb4d4614ae39558898 82b4358fdf
SHA-1 Checksum: 285775170167cb4d4614ae39558898
Changes and additions on this version (in no particular order):
- Installed Kippo2Wordlist, a tool to create wordlists based on passwords used by attackers against Kippo SSH honeypot.
- Installed DionaeaFR , a visualization tool which was recently presented in my previous post.
- Added Kojoney SSH honeypot, patched version (updated scripts, new features, etc).
- Added Amun malware honeypot, along with useful scripts.
- Installed mwcrawler, a script that parses malicious URL lists and downloads malware files (video).
- Added Thug, a honeyclient written in Python aimed at mimicking the behavior of a web browser in order to detect and emulate malicious contents.
- Added the following tools: Pipal, John the Ripper, IRCD-Hybrid, Origami, dsniff, hping, Scapy, Tcpreplay, tcptrace, sslstrip, libemu, Adminer.
- Added the Open Penetration Testing Bookmarks Collection to Firefox.
HoneyDrive is a virtual appliance (OVA) with Xubuntu Desktop 12.04 32-bit edition installed. It contains various honeypot software packages such as Kippo SSH honeypot, Dionaea malware honeypot, Honeyd low-interaction honeypot, Thug honeyclient and more. Additionally it includes useful pre-configured scripts and utilities to analyze, visualize and process the data it can capture, such as Kippo-Graph, Honeyd-Viz, and much more. Lastly, many other helpful security, forensics and malware related tools are also present in the distribution.
Features
- Virtual appliance based on Xubuntu 12.04 Desktop.
- Distributed as a single OVA file, ready to be imported.
- Full LAMP stack installed (Apache 2, MySQL 5), plus tools such as phpMyAdmin.
- Kippo SSH Honeypot, plus Kippo-Graph, Kippo2MySQL and other helpful scripts.
- Dionaea malware honeypot, plus DionaeaFR other helpful scripts.
- Amun malware honeypot, plus helpful scripts.
- Kojoney SSH honeypot, plus helpful scripts.
- Honeyd low-interaction honeypot, plus Honeyd2MySQL, Honeyd-Viz and other helpful scripts.
- LaBrea sticky honeypot, Tiny Honeypot, IIS Emulator, INetSim and SimH.
- Thug honeyclient for client-side attacks analysis, along with mwcrawler malware collector.
- A full suite of security, forensics and anti-malware tools for network monitoring, malicious shellcode and PDF analysis, such as ntop, p0f, EtherApe, nmap, DFF, Wireshark, ClamAV, ettercap, Automater, UPX, pdftk, Flasm, pdf-parser, Pyew, dex2jar and more.
- Firefox plugins pre-installed, plus extra helpful software such as GParted, Terminator, Adminer, VYM, Xpdf and more.
DOWNLOAD:-
The latest version (0.2) of HoneyDrive Desktop (Nectar edition), released on January 16, 2012 is hosted at SourceForge.net: http://sourceforge.net/projects/honeydrive/
Download latest relased on 16-01-2013
HoneyDrive 0.1 Santa edition Released on 30-12-2012
MD5 Checksum: 8f0d65b4260e963e5639ab4555b3c70f
SHA-1 Checksum: 285775170167cb4d4614ae3955889882b4358fdf
SHA-1 Checksum: 285775170167cb4d4614ae3955889882b4358fdf
Please take a look at the README.txt file on SourceForge (also included inside the virtual disk) to see where everything is located.
INSTALLATION:
After downloading the file, you simply have to import the virtual appliance to your virtual machine manager/hypervisor (suggested software: Oracle VM VirtualBox).
FREQUENTLY ASKED QUESTIONS:
- Why use HoneyDrive?
HoneyDrive saves you time! It has all the major honeypot-related software pre-installed and pre-configured to work out of the box (or with some configuration options of your liking). As I have seen many times in comments or support requests I get, setting up a honeypot system is not always something easy. This is especially true for new infosec enthusiasts or sysadmins and “hard” to set up software like Dionaea for example. - What utilities and software are included in HoneyDrive?
HoneyDrive contains all the major honeypot-related software and many more useful tools. For a complete list you’ll have to take a look at the README.txt file included in the virtual appliance (you’ll find it on the desktop) or online at the downloads section of SourceForge (link above). - Why isn’t [insert-name-here] included in HoneyDrive?
I’m not a security guru and unfortunately can’t keep track of every different piece of software. But, I’m very open to suggestions about HoneyDrive! If you know a tool that could be of benefit please let me know by leaving a comment on this page and it will be included in the next release of HoneyDrive. - How do I get started? How do I login?
You just have to download the OVA file from SourceForge (link above) and import it in your virtual machine manager/hypervisor. You can then login using the password “honeydrive” (without the quotes). - What is the password for [insert-name-here]?
Again, your best bet is reading the README.txt file included in the virtual appliance or found online at the downloads section of SourceForge (link above). Every password you will need is included in its appropriate section.
SCREENSHOTS:
Labels:
honey drive
,
honeypot
,
Security
04:34
Foxit Reader Vulnerable to Critical Remote Code Execution Flaw
Written By Unknown on Monday, 14 January 2013 | 04:34
Foxit Reader, a PDF viewer application often used as an alternative to the more popular Adobe Reader, contains a critical vulnerability in its browser plug-in component that can be exploited by attackers to execute arbitrary code on computers.
Details about the vulnerability and how it can be exploited were publicly disclosed last week by Andrea Micalizzi, an independent security researcher from Italy.
No official patch is yet available, according to an advisory from vulnerability intelligence and management company Secunia. The security firm rated the flaw as highly critical because it can be exploited remotely to gain system access.
Foxit's developers have identified the cause of the vulnerability and are working on creating a patch, a Foxit sales and service representative said Friday via email. The patch is expected to be released within one week, she said.
"The vulnerability is caused due to a boundary error in the Foxit Reader plugin for browsers (npFoxitReaderPlugin.dll) when processing a URL and can be exploited to cause a stack-based buffer overflow via e.g. an overly long file name in the URL," Secunia said. "Successful exploitation allows execution of arbitrary code."
The vulnerability has been confirmed in npFoxitReaderPlugin.dll version 2.2.1.530, which is installed by Foxit Reader 5.4.4.1128—the latest version of the program. However, older versions might also be affected, Secunia said.
By default, Foxit Reader installs the plug-in for Mozilla Firefox, Google Chrome, Opera, and Safari Web browsers.
Reputation as secure alternative reader
In the past, Foxit Reader has been suggested by some people in the security community as a more secure and less attacked alternative to Adobe Reader. In fact, Foxit, the company that develops the application, claims on its website that Foxit Reader is "the most secure PDF reader" and is "better than Adobe PDF Reader and Acrobat." According to the company, the program is used by over 130 million users.
"We have confirmed the vulnerability using Firefox, Opera, and Safari," Chaitanya Sharma, advisory team lead at Secunia, said Thursday via email. "At the moment the best mitigation is to disable this add-on in browsers and use other software e.g. Adobe Reader."
The Foxit representative, too, recommended avoiding using the Foxit browser plug-in for Firefox, Chrome, Opera or Safari, but instead suggested using Internet Explorer to view online PDF files.
EVMBME6EJAKF
Details about the vulnerability and how it can be exploited were publicly disclosed last week by Andrea Micalizzi, an independent security researcher from Italy.
No official patch is yet available, according to an advisory from vulnerability intelligence and management company Secunia. The security firm rated the flaw as highly critical because it can be exploited remotely to gain system access.
Foxit's developers have identified the cause of the vulnerability and are working on creating a patch, a Foxit sales and service representative said Friday via email. The patch is expected to be released within one week, she said.
"The vulnerability is caused due to a boundary error in the Foxit Reader plugin for browsers (npFoxitReaderPlugin.dll) when processing a URL and can be exploited to cause a stack-based buffer overflow via e.g. an overly long file name in the URL," Secunia said. "Successful exploitation allows execution of arbitrary code."
The vulnerability has been confirmed in npFoxitReaderPlugin.dll version 2.2.1.530, which is installed by Foxit Reader 5.4.4.1128—the latest version of the program. However, older versions might also be affected, Secunia said.
By default, Foxit Reader installs the plug-in for Mozilla Firefox, Google Chrome, Opera, and Safari Web browsers.
Reputation as secure alternative reader
In the past, Foxit Reader has been suggested by some people in the security community as a more secure and less attacked alternative to Adobe Reader. In fact, Foxit, the company that develops the application, claims on its website that Foxit Reader is "the most secure PDF reader" and is "better than Adobe PDF Reader and Acrobat." According to the company, the program is used by over 130 million users.
"We have confirmed the vulnerability using Firefox, Opera, and Safari," Chaitanya Sharma, advisory team lead at Secunia, said Thursday via email. "At the moment the best mitigation is to disable this add-on in browsers and use other software e.g. Adobe Reader."
The Foxit representative, too, recommended avoiding using the Foxit browser plug-in for Firefox, Chrome, Opera or Safari, but instead suggested using Internet Explorer to view online PDF files.
Labels:
foxit reader
,
pdf
,
Security
04:07
Lithuanian Online Game Site Miestukarai Hacked, 24,000 Users Data Leaked
A hacker called AnonVoldemort claims to have gained access to the databases of Miestukarai.lt, a Lithuanian online game that appears to have almost 35,000 players.
In the tweet announcing the hack, AnonVoldemort revealed that he had leaked over 24,000 accounts, both free and premium.
The data has been removed since from Pastebin. It’s possible that the site’s administrators have learned of the leak and have requested Pastebin to remove the information.
However, according to CWN – who had analyzed the leak before it was removed –, usernames, email addresses, IP addresses and hashed passwords were published by the hacker.
If there are any Miestukarai players reading this, I advise them to immediately change their passwords. Not only the ones protecting their game accounts, but all the passwords that are the same with the one leaked by the hacker.
In the tweet announcing the hack, AnonVoldemort revealed that he had leaked over 24,000 accounts, both free and premium.
The data has been removed since from Pastebin. It’s possible that the site’s administrators have learned of the leak and have requested Pastebin to remove the information.
However, according to CWN – who had analyzed the leak before it was removed –, usernames, email addresses, IP addresses and hashed passwords were published by the hacker.
If there are any Miestukarai players reading this, I advise them to immediately change their passwords. Not only the ones protecting their game accounts, but all the passwords that are the same with the one leaked by the hacker.
05:26
Microsoft Safety Scanner - Get a free PC safety scan
Written By Unknown on Sunday, 6 January 2013 | 05:26
The Microsoft Safety Scanner is a free downloadable security tool that provides on-demand scanning and helps remove viruses, spyware, and other malicious software. It works with your existing antivirus software.
Note: The Microsoft Safety Scanner expires 10 days after being downloaded. To rerun a scan with the latest anti-malware definitions, download and run the Microsoft Safety Scanner again.
The Microsoft Safety Scanner is not a replacement for using an antivirus software program that provides ongoing protection.
For real-time protection that helps to guard your home or small business PCs against viruses, spyware, and other malicious software, download Microsoft Security Essentials.
Need to run on a different PC? Select your version.

Genuine Windows customers get a complimentary subscription to Microsoft Security Essentials, the award-winning antivirus software that helps you protect your PC.

Get the latest version of Microsoft's more secure browser with SmartScreen Filter, which helps you avoid socially engineered malware phishing Web sites and online fraud when browsing the Web.

With Windows Live Family Safety, you can help keep your kids safer on the Internet with rules you personalize. You also can get tools to help monitor what they are doing online.
Source-
http://www.microsoft.com/security/scanner/en-us/default.aspx
Note: The Microsoft Safety Scanner expires 10 days after being downloaded. To rerun a scan with the latest anti-malware definitions, download and run the Microsoft Safety Scanner again.
The Microsoft Safety Scanner is not a replacement for using an antivirus software program that provides ongoing protection.
For real-time protection that helps to guard your home or small business PCs against viruses, spyware, and other malicious software, download Microsoft Security Essentials.
Download Microsoft Safety Scanner
If you are unsure whether your computer is running a 32-bit version or 64-bit version of the Windows operating system, please visit Microsoft Support.Note: Microsoft Safety Scanner expires 10 days after downloading. To re-run a scan with the latest antimalware definitions, please download and run Microsoft Safety Scanner again
Have a safer PC and web browsing experience
Genuine Windows customers get a complimentary subscription to Microsoft Security Essentials, the award-winning antivirus software that helps you protect your PC.
Get the latest version of Microsoft's more secure browser with SmartScreen Filter, which helps you avoid socially engineered malware phishing Web sites and online fraud when browsing the Web.
With Windows Live Family Safety, you can help keep your kids safer on the Internet with rules you personalize. You also can get tools to help monitor what they are doing online.
Source-
http://www.microsoft.com/security/scanner/en-us/default.aspx
02:52
Hackers Steals 36,000 Individual Details from US Army Database
Written By Unknown on Saturday, 29 December 2012 | 02:52
Earlier this month, unknown hackers managed to gain illegal access to the details of around 36,000 individuals who were somehow connected to the US Army command center formerly located at Fort Monmouth.
According to APP, the details of Communications-Electronics Command (CECOM) and Command, Control, Communications, Computers, Intelligence, Surveillance and Reconnaissance (C4ISR) personnel were accessed by the hackers.
Nongovernmental personnel and Fort Monmouth visitors are also affected by the breach.
The hack, discovered on December 6, exposed names, dates of birth, social security numbers and salaries, Army representatives said. After the incident, the targeted databases have been taken offline.
CECOM and C4ISR were relocated from Fort Monmouth to Aberdeen Proving Ground back in September 2011.
The affected individuals are being offered one year of free credit monitoring services.
According to APP, the details of Communications-Electronics Command (CECOM) and Command, Control, Communications, Computers, Intelligence, Surveillance and Reconnaissance (C4ISR) personnel were accessed by the hackers.
Nongovernmental personnel and Fort Monmouth visitors are also affected by the breach.
The hack, discovered on December 6, exposed names, dates of birth, social security numbers and salaries, Army representatives said. After the incident, the targeted databases have been taken offline.
CECOM and C4ISR were relocated from Fort Monmouth to Aberdeen Proving Ground back in September 2011.
The affected individuals are being offered one year of free credit monitoring services.
10:54
XSS and Cookie Handling Vulnerabilities Identified on HTC Website, Allows Attacker to Hijack Account
Written By Unknown on Friday, 28 December 2012 | 10:54
16-year-old security researcher Thamatam Deepak has identified a number of three cross-site scripting (XSS) vulnerabilities and a cookie handling flaw on the website of world-renowned smartphone manufacturer HTC.
The expert said the vulnerabilities – which affected pages such as product security, account information, and smartphone presentation – have been addressed by HTC after he notified them, according to The Hacker News
If unfixed, the XSS vulnerabilities could have been leveraged by a remote attacker to inject arbitrary content, while the cookie handling flaw might have been exploited to hijack user accounts.
This isn’t the first time when security experts find XSS bugs on HTC’s website. Back in April, researcher Shadab Siddiqui identified similar flaws and reported them to the company.
However, at the time, they failed to respond to his notifications and the vulnerabilities remained unfixed for months.
The expert said the vulnerabilities – which affected pages such as product security, account information, and smartphone presentation – have been addressed by HTC after he notified them, according to The Hacker News
If unfixed, the XSS vulnerabilities could have been leveraged by a remote attacker to inject arbitrary content, while the cookie handling flaw might have been exploited to hijack user accounts.
This isn’t the first time when security experts find XSS bugs on HTC’s website. Back in April, researcher Shadab Siddiqui identified similar flaws and reported them to the company.
However, at the time, they failed to respond to his notifications and the vulnerabilities remained unfixed for months.
Labels:
HTC
,
Security
,
Vulnerability
,
XSS













