Tuesday, 31 July 2012

Backtrack 5 R2 Release - Update to Backtrack 5 R2


How to update and upgrade your current (backtrack 5 R1) backtrack machine into the latest version backtrack 5 R2, however backtrack 5 R2 will be release on 1st March but the kernel of BT5 R2 has been arrived and you can update it by yourself or wait for the official release. The new kernel of 3.2.6 BT5 R2 will provide a more stable and complete penetration testing environment than ever before.



Open the terminal and update your backtrack 5 R1 installation.


apt-get update
apt-get dist-upgrade
reboot

Now you have the latest kernel.

OPTIONAL – Once rebooted, log back in, and get your pretty splash screen back.

fix-splash
reboot
On the next reboot, you should see the red console splash screen appear.
Verify that you are running a 3.2.6 kernel:

uname -a
You should see something like “Linux bt 3.2.6 …”
Feel free to install any or all of the new tools featured in BackTrack 5 R2:

apt-get install pipal findmyhash metasploit joomscan hashcat-gui golismero easy-creds pyrit sqlsus vega libhijack tlssled hash-identifier wol-e dirb reaver wce sslyze magictree nipper-ng rec-studio hotpatch xspy arduino rebind horst watobo patator thc-ssl-dos redfang findmyhash killerbee goofile bt-audit bluelog extundelete se-toolkit casefile sucrack dpscan dnschef

Load the new security update and then upgrade it


echo "deb http://updates.repository.backtrack-linux.org revolution main microverse non-free testing" >> /etc/apt/sources.list
apt-get update
apt-get dist-upgrade

It will be asked about the revision make sure to choose all by default and hit enter.


Restart your distribution with the services.

Backtrack 5 R2 will be officially release in March 1 with the complete information.
Source

The Mole(SQL Injection exploitation tool) v0.3 released


The Mole is an automatic SQL Injection exploitation tool. Only by providing a vulnerable URL and a valid string on the site it can detect the injection and exploit it, either by using the union technique or a boolean query based technique. The Mole features and tutorial has been discussed before but the new version of Mole (v3.0) has been released and available to download.


Features

  • Support for injections using Mysql, SQL Server, Postgres and Oracle databases.
  • Command line interface. Different commands trigger different actions.
  • Auto-completion for commands, command arguments and database, table and columns names.
  • Support for filters, in order to bypass certain IPS/IDS rules using generic filters, and the possibility of creating new ones easily.
  • Exploits SQL Injections through GET/POST/Cookie parameters.
  • Developed in python 3.
  • Exploits SQL Injections that return binary data.
  • Powerful command interpreter to simplify its usage. 

Current Release: v0.3 (2012-03-02)

Current Bug-Free version

Even though we want to keep the release up-to-date, it is impossible to make one for every single patch we have applied to the current version to fix a bug. We strongly recommend using thebugfix branch from our repository. To get it, execute:

git clone -b bugfix git://git.code.sf.net/p/themole/code themole-code
In order to put it up to date, before using it, update it by executing:

git pull origin bugfix


The Mole's release 0.3 is out! Several bugfixes have been made and new features were introduced. As:

* Enabled injection through cookie paramters.
* New filtering mechanism enabling better manipulation and easier filter development.
* Added several of those filters.
* SQL Injections that return binary data are now exploitable.
* DMBS credentials listing.

The Mole SQLi Exploitation Tool Tutorial

Complete tutorial with video explanation can be find here.

Spy Softwares Keyloggers & RAT Review


Spy software's (Keylogger, RAT) are the programs that has an ability to monitor a computer and to make log files for every activities, some keylogger works remotely and they can send the log files via email or FTP. There are so many keyloggers are available on the Internet and the usage of keyloggers depends on the need and requirement. Since we does not encourage the wrong usage of technology and in this article we will review some best keyloggers but the aim is not to hack someone via keylogger but the aim is to monitor the child's and employee.

There are so many peoples has requested me to make an article on keylogger that is why I have decided to review some keyloggers.

AllIn One Keylogger

This is Invisible Keylogger surveillance software , Keystrokes Recorder, Spy Software tool that registers every activity on your PC to encrypted logs. The Keylogger Software allows you to secretly track all activities from all computer users and automatically receive logs to a desire e-mail/FTP/LAN accounting.

Some interesting feature:

  • Keystrokes Logging (Key Logging)
  • Chat / Instant Message Recording (Chat Logger/IM Logger)
  • Web Recording (Web Logger/Internet Logger
  • Screenshot Logging (Spy Camera)
  • Microphone Logging
  • Log files Encryption
  • Anti-Spy Protection
  • Email Delivery
  • FTP Delivery
  • Block/filter Unwanted URLs
  • Disable Unwanted Software's
  • Auto Uninstall

Download

SniperSpy Remote Spy Software

SniperSpy allows you to remotely watch your computer like a television! Watch what happens on the screen LIVE! The only remote monitoring software with a SECURE control panel!
The software also saves screenshots along with text logs of chats, websites, keystrokes in any language and more. Remotely view everything your child, employee or anyone does while they use your distant PC. Includes LIVE admin and control commands!
Some features:
  • Keystrokes in Most Languages
  • Full Chat Conversations
  • Application Session Durations
  • Real Time Screen Viewer
  • Real Time Keystroke Viewer
  • Reboot / Shutdown / Logoff
  • HTTPS Secured Control Panel
  • Remote System Information
  • Searchable Logs
  • Remotely Deployable
  • Remote Uninstall

NetSpy Pro

It is an amazing product that has an ability to monitor the entire network, Net Spy Pro is the latest in employee network monitoring software. This program allows you to monitor and control all user activity on your network in real time from your own workstation.
Some features:
  • View Real Time Screens, Events and Keystrokes!
  • View Browser Favorites
  • View Open Ports
  • View Active Processes, Services and System Info
  • Chat / IM Conversations
  • Keystrokes Typed
  • Web Sites Visited
  • Emails Typed or Viewed
  • Applications Executed
  • Screenshots Capturing
  • Full Remote Control

7 Most Common Web Application Vulnerabilities


Information disclosure, identity theft, SQL injection, Code injection, Authentication bypass, Cross site scripting and Cross request forgery. Typo3 has released the web application security guide for website owners and below is the detail discussion on the common and most dangerous web application vulnerabilities. 



 

Information disclosure

This means that the system will (under certain circumstances) make information available to an outside person that might use it to craft an attack against the system. Such information includes details of the file system structure or details about the installed software, such as configuration options or version numbers. An attacker could gain important information about the system configuration that makes an attack possible.
There is a fine line between the protection against information disclosure and so called "security by obscurity". Latter means, that system administrators or developers try to protect their infrastructure or software by hiding or obscuring it. An example would be to not reveal that TYPO3 is used as the content management system or a specific version of TYPO3 is used. Security experts say, that "security by obscurity" is not security, simply because it does not solve the root of a problem (e.g. a security vulnerability) but tries to obscure the facts only.

Identity theft

Under certain conditions it may be possible that the system reveals personal data, such as customer lists, e-mail addresses, passwords, order history or financial transactions. This information can be used by criminals for fraud or financial gains. The server running a TYPO3 website should be secured so that no data can be retrieved without the consent of the owner of the website.

SQL injection

With SQL injection the attacker tries to submit modified SQL statements to the database server in order to get access to the database. This could be used to retrieve information such as customer data or user passwords or even modify the database content such as adding administrator accounts to the user table. Therefore it is necessary to carefully analyze and filter any parameters that are used in a database query.

Code injection

Similar to SQL injection described above, "code injection" includes commands or files from remote instances (RFI: Remote File Inclusion) or from the local file system (LFI: Local File Inclusion). The fetched code becomes part of the executing script and runs in the context of the TYPO3 site (so it has the same access privileges on a server level). Both attacks, RFI and LFI, are often triggered by improper verification and neutralization of user input.
Local file inclusion can lead to information disclosure (see above), for example reveal system internal files which contain configuration settings, passwords, encryption keys, etc.

Authorization bypass

In an authorization bypass attack, the cracker exploits vulnerabilities in poorly designed applications or login forms (e.g. client-side data input validation). Authentication modules shipped with the TYPO3 core are well-tested and reviewed. However, due to the open architecture of TYPO3, this systems can be extended by alternative solutions. The code quality and security aspects may vary, see chapter "Guidelines for TYPO3 Integrators: TYPO3 extensions" for further details.

Cross Site Scripting (XSS)

Cross-site scripting occurs when data that is being processed by an application is not filtered for any suspicious content. It is most common with forms on websites where a user enters data which is then processed by the application. When the data is stored or sent back to the browser in an unfiltered way, malicious code may be executed. A typical example is a comment form for a blog or guest book. When the submitted data is simply stored in the database, it will be sent back to the browser of visitors if they view the blog or guest book entries. This could be as simple as the inclusion of additional text or images, but it could also contain JavaScript code of iframes that load code from a 3rd party website.

Cross Site Request Forgery (XSRF)

In this type of attack unauthorized commands are sent from a user a website trusts. Consider an editor that is logged in to an application (like a CMS or online banking service) and therefore is authorized in the system. The authorization may be stored in a session cookie in the browser of the user. An attacker might send an e-mail to the person with a link that points to a website with prepared images. When the browser is loading the images, it might actually send a request to the system where the user is logged in and execute commands in the context of the logged-in user.


How I Hacked A Remote Computer By Just IP Address


Hacking a remote computer is always a hot topic among hackers and crackers, a newbie hacker or someone who wants to learn hacking always ask these questions that how to hack into a computer by just knowing the IP address. Although we have discussed so many methods before and I always insist to learn some basic commands, protocols and their usage. This is my story like I have hacked into a remote by just using IP address (I have not downloaded any file even I have not cleared the logs). This story was not planned it just happened and I am sure you will like it and you will learn a lot of things if you don't know the basic commands and protocols.

It was Saturday night and I was working hard on social engineering toolkit remote attack (WAN,Internet attack) that is why I was playing with my router for port forwarding and other stuffs, remember my ISP using a dynamic mechanism so I have created DNS server to get the static IP. It was almost night and I have decided to get some sleep and than I have saved my browser tabs so that next time I will use them.

Its Sunday evening I have opened my browser and the previous tabs open automatically and then I got pop up window it asked about the user-name and password of my router I have looked to the address bar the IP address was same as it was saved by me, I was shocked that my ISP has not changed my WAN IP (remember ISP using dynamic IP), after this I have open a website about whatismyip and I have seen that my IP is different it means the window that ask about user name and password is the IP of another computer.

Just got an idea why not to brute force it and get the access on the victim router, hydra has been discussed before, but before brute force I have decided to use guessing technique and I than I have entered so many combination but failed than I just used the default user name and password huurraaah I was in.

Security was very low, than I did a quick nmap scan to get the open ports (remember I have turned off the firewall of victim router). According to the nmap result ftp and telnet was open and then I realized how vulnerable this victim is.




I came across to my terminal and open telnet to the victim by using the default password and I was in and now I was able to take control of this computer but this was not include in the plan.




FTP (file transfer protocol), I came to my terminal again and this time I have used FTP command with the same combination of user name and password and successful. Remember FTP access means you can download and upload files on remote computer means full access. You can use some GUI ftp client but I used command.



Countermeasure

  • Always use a strong password
  • Turn on your Firewall (both on router and computer)