Showing posts with label Tutorial. Show all posts
Showing posts with label Tutorial. Show all posts
Get your usb drives to work with VirtualBox(Ubuntu host)

To get your USB drives to work with VirtualBox when using Ubuntu as a host, you need to add your user to the vboxusers group. Please note that this doesn’t work with VirtualBox OSE, so you’ll need to install VirtualBox from its repository.

To add your username to the vboxusers group in Ubuntu, go to System > Administration > Users and Groups, click on “Manage groups“, scroll down to the “vboxusers” group and click “Propreties“, then check the box next to your username and click OK:


Then log out and log back in, plug in an USB stick (or whatever you may need), start a VirtualBox machine and select the USB device in the lower right. Using this, the USB device won’t be accessible each time you start the VM.
To have an USB device available each time you start a VM, open VirtualBox, select a VM, click on “Settings” and on the USB tab, click the “+” icon on the right – this will display a list of your USB devices which you can add to your VM.



If you want to set up USB for VirtualBox manually, you can run the following command:

sudo gedit /etc/group

Then search for the “vboxusers” group and add your username to that line, like so:
vboxusers:x:125:andrei

“andrei” is my username – replace it with yours. Then save the file, log out and see above on how to add an USB drive to VirtualBox.

How-To: Increase your upload/download/ratio in torrent trackers

The “bug” has been tested on the torrent trackers that use the torrentbits source code (I don’t know if it works on other trackers).
The idea of this this “bug” is that you will sniff your torrent info using the HTTP Analyzer and with Firefox you will update your stats to the tracker being identified as a client. This is a simple and short tutorial that shows you how to do it, if you are “more” advanced you can use other tools to do it.

Programs that you need:
- HTTP Analyzer – http://www.ieinspector.com/httpanalyzer/
- Mozilla Firefox – http://www.mozilla.org/products/firefox/
- User Agent Switcher Extension – http://chrispederick.com/work/firefox/useragentswitcher/
- And an bittorrent client.

Steps:

1. Install the User Agent Switcher Extension (the extension will be used to identify as a bittorrent client to the tracker) to Mozilla Firefox (if you don’t have Firefox, get it!).
2. After installing the extension go in Firefox to:

Tools -> User Agent Switcher -> Options -> Options -> User Agents

Click Add, write “BitTorrent/3.4.2” to the Description and User Agent and then press “Ok”.


3. Then go to:

Tools -> User Agent Switcher and select the newly added User Agent, “BitTorrent/3.4.2”.

4. Install HTTP Analyzer.
5. Get a .torrent file from a tracker that uses the torrentbits source code and add it to your client. (DO NOT START IT)
6. Start HTTP Analyzer and go to the “Start Logging” button, select “Select a process…”, choose your bittorrent client (Important: If you use Azureus, select the javaw.exe proccess from the list) from the list and click “Ok”.


7. Go into your client and start the torrent.
8. Now go into HTTP Analyzer, there you should see a GET request to the tracker.

Example:

GET /torrents/announce.php?info_hash=%B5%2D%F4%ADM%18%7C%83C%E9%EC%C8%C7%F7%973%3Fap%15&peer_id=%2DBC0059%2Dp%D1%FBd%D0%C6%EC%7B%B4%D5q%B8&port=12345&uploaded=0&downloaded=0&left=0&numwant=200&compact=1&no_peer_id=1&key=9427&event=started HTTP/1.0


9. Open Firefox, paste into the address bar:

http://TRACKER.ADDRESS/announce.php?info_hash=INFOHASH&peer_id=PEERID&port=PORT&uploaded=UPLOADED&downloaded=0&left=0&numwant=0&event=completed

replace:

TRACKER.ADDRESS with the torrent tracker address (ex: www.filelist.org:81)
INFOHASH with info_hash variable taken from the GET request from HTTP Analyzer,
PEERID with the peer_id
PORT with the port
UPLOADED with an number that you want, in bytes (ex: 10737418240 for 10GB)

Example:

http://www.filemp3.org:81/announce.php?info_hash=%B5%2D%F4%ADM%18%7C%83C%E9%EC%C8%C7%F7%973%3Fap%15&peer_id=%2DBC0059%2D%C3F%A4c%C4%0D%D35i%93%93%EA&port=12345&uploaded=10737418240&downloaded=0&left=0&numwant=0&event=completed

press enter and then stop the torrent in your client.

Now you should have 10GB added to your upload.

FileMP3 screens :D



The “bug” should work on all sites that use the TorrentBits source code (including filelist.org, torrentbytes.net and anothers). If you have any questions please send an email to xyflar@gmail.com

source : http://xyflar.blogspot.com/

Hướng dẫn sử dụng Netcat

1. Giới thiệu


Netcat là một công cụ không thể thiếu được nếu bạn muốn hack một website nào đó. Vì vậy bạn cần biết một chút về Netcat;)

Cpanel and Apache by-pass protected directory

Software : Cpanel & Apache
Type of vunlnerability : Protected Directory Traversal & Gain Access Files
Tested On : Cpanel 11
Risk of use : High

Discovered by : dinhcaohack
Team Website : http://vniss.net
Exploit
Code:

1. Convert IP: calculate ( (first octet * 2^24) + (second octet *2^16)
+ (third octet * 2^8) + (fourth octet) ).
So we have 65.60.10.2 is 1094453762.
2. Find exact username like : xgroup
3. Access protected directories and files (by .htaccess & .htpasswd) on browser:
http://1094453762/~xgroup/protect/
http://1094453762/~target/protect/index.php
etc.

 

Site tuyệt vời cho dân Network

http://www.server-world.info/en/



Thanks: http://ubuntuonline.wordpress.com/2011/02/21/site-tuyet-voi-cho-dan-network/

[Win Tool] Boot Multiple ISO from USB (MultiBoot USB)

How to create a Multiboot USB Flash Drive that you can use to Boot Multiple ISO Files from USB. Please note that you might need a 8GB-16GB or larger USB flash device to be able to support every bootable ISO entry. I will update and add more Bootable ISO files to the list as I find the time to test them. You can also contact me to submit working Bootable Linux ISO menu.lst entries for inclusion.

MultiSystem - Create a MultiBoot USB from Linux

Custom Multiboot UFD containing your favorite Bootable Live Linux Distributions.

 

Official HomePage: http://liveusb.info/dotclear

Multisystem Prerequisites:


  • Ubuntu Linux or Ubuntu Based System (can use an Ubuntu CD or USB)

  • A USB Flash Drive (to use for your MultiBoot USB)

  • Working Internet Connection

  • install-depot-multiboot.sh.tar.bz2

Cách chia Subnet nhanh

Dạo trước mình có viết bài Subnet mask và cách chia có trình bày về cách chia Subnet căn bản. Cách tính và nhớ phương phá để chia Subnet có nhiều cách, bài này trình bày cách tính rất nhanh, tham khảo nhé. VIA từ blog của Anh Lê Cường.

Tay tráiTay phải


Các bước chia như sau:

Ta có bài LAB như sau:

Ví dụ ta có IP 192.168.1.0 chia 3 mạng con theo yêu cầu của sếp:

B1: Xác định số bit sẽ mượn dựa vào số mạng con muốn chia (quy tắc bàn tay trái):

Công thức tính để chia bao nhiêu mạng con ta làm như sau:

2^n >= m (m là số mạng con cần chia hay còn gọi là số subnet cần chia, n là con số bit ta sẽ mượn)

suy ra ta có: 2^n >=3 (số 3 là số mạng con mà sếp yêu cầu).

suy ra tiếp n là số 2. (Nhìn bàn tay trái đốt thứ 2 của ngón út là số 4, 4 dĩ nhiên lớn hơn 3).

B2: Quy tắc bàn tay phải: Ở đây ta sẽ mượn 2 bit (số n ở trên B1). Dựa theo hình tay phải nó sẽ là số 192.

B3: Tìm bước nhảy (Bước nhảy có nghĩa là 3 mạng con này sẽ nằm từ ip bao nhiêu tới bao nhiêu cho mỗi bước).

Lấy 256 - 192 của B2 (ở đâu có 256? xin thưa 0--> 255 là có 256 host vì vậy ta lấy 256 -192 = 64

==> Ta có các mạng con như sau:

Mạng 1: 192.168.1.0          Netmask: 255.255.255.192


Mạng 2: 192.168.1.64          Netmask: 255.255.255.192


Mạng 3: 192.168.1.128          Netmask: 255.255.255.192


Mạng 4: 192.168.1.192          Netmask: 255.255.255.192


Xong rồi, được 4 lớp mạng nhỏ, tuỳ bạn sử dụng nhé. Test cái bằng cách cài đặt win xp cho 2 cái máy ảo sau đó đặt IP theo 3 trường hợp sau:

TH1:

Máy 1:

192.168.1.70         Netmask: 255.255.255.192


Máy 2:

192.168.1.80         Netmask: 255.255.255.192


Kết quả: Cho 2 máy ping nhau ==> kết quả ping OK. (Reply from 192.168.1.80: bytes=32 time=1ms TTL=128)

TH2:

Máy 1:

192.168.1.70 Netmask: 255.255.255.192

Máy 2:

192.168.1.180 Netmask: 255.255.255.192

Kết quả: Cho 2 máy ping nhau ==> kết quả ping Không được (vì 2 ip này khác mạng).

TH3:

Máy 1:

192.168.1.62 Netmask: 255.255.255.192

Máy 2:

192.168.1.128 Netmask: 255.255.255.192

Kết quả: Máy 1 không đặt được IP và Máy 2 cũng vậy.

Tại sao vậy? cho bạn kết luận nhé.

Kết thúc bài LAB. Sau bài LAB này bạn có công thức tính và chia subnet. Sau đó tiếp tục bạn hãy thử học phương pháp tính nhanh phía dưới nhé.

Subnet mask và cách chia

Subnet là gì?: Hiểu đơn giản vầy. Khi ta chia một Network ra thành nhiều Network nhỏ hơn thì các Network nhỏ này được gọi là Subnet.


Vì sao cần phải chia Subnet mask?

Hacking Windows shares from Linux with Samba



A little while ago I did an article on breaking into Windows shares using an automated madirish.bat. If you're not familiar with that article, feel free to read up on Madirish.net (articles Madirish Tutorial 09 and Tutorial 10 in the 'Tech' section). In that article I showed how to use native windows diagnostic commands to browse around not only your local network, but also remote networks, to find open shares and access the resources in those shares. In this short piece I'll show you how to do the same thing from a Linux environment. The lynchpin to this operation is Samba, the Linux tool that allows Linux machines to play in Windows networks. If you don't have Samba installed, your going to need it (the client tools only, the server isn't necessary). If you don't know how to install Samba head over to www.Samba.org. If you still can't figure out how to install samba on your own computer you really don't have any business breaking into other people's computers :)

Wireless Hacking with Kismet



The proliferation of wireless networks is sometimes scary when you consider how insecure most wireless configurations are. With a little work, and some technical know-how you can easily break into most wireless networks or simply monitor the wireless traffic flowing all around you. The good news is that setting up a wireless monitor takes a bit of persistence and isn't very feasible for the average computer user.

The easiest way to begin monitoring wireless network traffic is with kismet. Kismet is most easily installed on Linux, but be warned, it isn't all that easy. To begin you need to download Kismet from http://www.kismetwireless.net. You'll need to be sure you have gcc and make installed in order to compile the sources. On Mandriva you can install these using:

SSHatter SSH Brute Forcer



SSHatter is an SSH brute force utility available from http://freshmeat.net/projects/sshatter/?branch_id=70781&release_id=263196. Essentially the tool is comprised of a small Perl file. The utility requires a few non-standard Perl libraries but these are easily installed. You must have Perl installed to use SSHatter.

Installing SSHatter

Using Netcat to Transfer Files (and Other Mischief)

Netcat is an oft maligned program that can easily be used for many interesting and useful purposes. While many admins have heard of netcat, it is usually in the context of detecting rootkits or evidence of intrusion. The fact that netcat is a favorite tool among malicious hackers does a great disservice to the tool, but it also demonstrates its utility.

Web Hacking Lesson 6 - Arbitrary Code Execution Vulnerabilities

Arbitrary Code Execution Vulnerabilities


Note: If you haven't read Lesson 1 go check it out first for test application install instructions.

This type of vulnerability is extremely dangerous. Unsafely written PHP that utilizes system calls and user input could allow an attacker to run an arbitrary command on the filesystem. This attack bears many resemblances to SQL injection in that the attacker manipulates input to cause execution of unintended commands. This vulnerability shows up in many forms, so utmost care should be used whenever using one of PHP's many filesystem call functions (such as system(), exec(), passthru(), shell_exec(), etc.)

Web Hacking Lesson 5 - File Upload Vulnerabilities

PHP File Upload Exploits


Note: If you haven't read Lesson 1 go check it out first for test application install instructions.

File upload exploits are a common problem with web based applications. In a nutshell this vulnerability hinges on functionality that allows an attacker to upload a script file that can then be executed on the server. The most common cause of this vulnerability is functionality that is supposed to allow users to upload inert content (things like images, PDF documents and the like) that is designed to be displayed. Often, however, developers forget to accomplish proper input validation (are you noticing a theme here yet?) that doesn't restrict the types of files an attacker can upload.

Web Hacking Lesson 4 - File Include Vulnerabilities

PHP File Include Vulnerabilities


Note: If you haven't read Lesson 1 go check it out first for test application install instructions.

Along the same lines of SQL injection and XSS, remote file inclusion vulnerabilities rely on the user being able to manipulate variables interpreted by PHP. The most common occurance of this vulnerability is the utilization of URL strings to determine included files. This threat of this vulnerability is largely determined by the configuration of the PHP server. Some servers will allow more malicious includes than others.

Web Hacking Lesson 3 - Brute Force

Brute Forcing


Note: If you haven't read Lesson 1 go check it out first for test application install instructions.

Brute forcing a web application is a method to bypass traditional authentication checks. Although brute forcing may seem like an attack that a PHP developer might not be able to mitigate, it is actually an important consideration when developing web applications.

Web Hacking Lesson 2 - SQL Injection

SQL Injection


Note: If you haven't read Lesson 1 go check it out first for test application install instructions.

SQL injection attacks bear many of the same fundamental hallmarks as XSS attacks. At its core and SQL injection abuses the web application to introduce unintended functionality. SQL injection aims to escape out of the confines of a developer crafted SQL statement to alter the SQL. Take the following example:

Web Hacking Lesson 1

This exercise is designed to expose you to several of the top threat vectors facing web based applications, specifically PHP/MySQL applications. 'Threat vector' is a common term used in computer security to connote ways in which an attacker will attempt to compromise a system. System is used in a broad sense here because a compromised web application can easily lead to a compromised web server which in term could lead to a compromised operating system.

Brute Forcing PHP MD5 Hashed Passwords


Web Application Passwords


Many PHP based web applications use md5 hashing in order to obscure stored passwords. At first glance this seems like an effective security measure, however upon further examination it becomes clear that this approach does little to secure a password. Let us assume that an attacker somehow captures the md5 hash of a users password. This could happen in many ways, the most obvious being a SQL injection that reveals the password.

MD5


 
2012 upshell | Header Image by Game Wallpapers
Avatar Gamezine Designed by Cheapest Tablet PC
Supported by Phones 4u