Friday, 22 November 2013

DNS poisoning - EXPLANATION | hacking trick

DNS poisoning is a technique that tricks a DNS
server into believing that is has received authentic
inforamtion when, in reality, it has not. It results in
substitution of a false Ineternet provider address at
the domain name service level where web addresses
are converted into numeric internet provider
addresses. It allows attacker to replace IP address
DNS entries for a target site on a given DNS server
with IP addresses of the server he/she controls.
Attacker can create fake DNS entries for files with
same names as that of target server.
The DNS provides a way for computers to translate
the domain names we see to the physical IPs they
represent. When you load a webpage, your browser
will ask its DNS server for the IP of the host you
requested, and the server will respond. Your browser
will then request the webpage from the server with
the IP address that the DNS server supplied.
To launch a DNS poisoning attack, follow these
steps:

+ set up a fake website on your computer

+ Install treewalk and modify the file mentioned in
the readme.txt to your IP address. Treewalk will
make you the DNS server.
+ Modify the file dns-spoofing.bat and replace the IP
address with your IP address.

+ Trojanize the dns-spoofing.bat file and send it
+ When the host clicks the Trojanned file, it will
replace DNS-entry in her TCP/IP properties to that of
your machine.
+ You will become the DNS server and her DNS
requests will go through you
There are four types of DNS poisoning attacks using
which you can compromise the target system:
+ Intranet DNS spoofing (local network)
When an attacker performs DNS poisoning on a locl
area network (LAN), it is called intranet DNS
spoofing. An attacker can perform intranet DNS
spoofing attack with the help of the ARP poisoning
technique. THis is usually conducted on a swithced
LAN. To perform this attack, you must be connected
to the LAN and be able to sniff the traffic or packets.
Once the attacker succeds in sniffing the ID of the
DNS request from the intranet, he or she can send a
malicious reply to the sender before the actual DNS
server.
+ Internet DNS spoofing (remote network)
Internet DNS poisoning is also known as remote
DNS poisoning. This attack can be performed either
on asingle or multiple victims anywhere in the world.
In order to perform this attack, you need to set up a
rouge DNS server with a static IP address.
Internet DNS spoofing is performed when the
victim's system is connedted to the Internet. It is
done with the help of Trojans. It is one of the MITM
types of attacks, where the attacker changers the
primary DNS entries of the victim's computer. The
attacker replaces the victim's DNS IP address with
the fake IP address that refers t the attacker's
system; thus all traffic will be redirected to the
attacker's machine. Now the aatcker can easily sniff
the victim's confidential information.
+ Proxy server DNS poisoning
In the proxy server DNS posoning technique, tha
taattacker changes the proxy server setting of the
victim to that of the attacker. This is done with the
help of a Trojan. This redirects the victim's request
to the attacker's fake website where the attacker can
sniff the confidential information of the victim.
+ DNS cache poisoning
The DNS system uses cache memory to hold the
recently resolved domain names. It is populated
with recently used domain names and respective IP
address entries. When the user request comes, the
DNS resolver first checks the DNS cache; if the
domain name that the user requested is found in the
cache, then the resolver sends its respective IP
address quickly. Thus, it redueces the traffic and
time of DNS resolving.
Attacker target this DNS cache and make changes or
add entries to the DNS cache. The attacker replaces
the user-requested IP address with the fake IP
address. Then, after when user requests that domain
name, the DNS resolver checks the entry in the DNS
cache and picks the matched entry. Thus, the victim
is rediirected to the attacker's fake server instead of
the authorized server.

How to defend against DNS spoofing:
Resolve all DNS queries to local DNS servers
Block DNS requests from going to external severs
Implement DNSSEC
Configure the DNS resolver to use a new random
source prot from its available range for each
outgoing query
Configure the firewall to restrict external DNS lookup
Restrict the DNS recuring service, either full or
partial, to authorized users
Use DNS Non-Existent Domain rate limitng
Secure your internal machines
Implement IDS and deploy it correctly
Use static ARP and IP table
Use SSH encryption
Use sniffing detection tools
Do not open suspicious files
Always use trusted proxy sites
Audit your DNS server regularly to remove
vulnerabilities

Botnets - full Explanation

Botnets 


A botnet or robot network is a group of computers running a computer application controlled and manipulated only by the owner or the software source. The botnet may refer to a legitimate network of several computers that share program processing among them.

Usually though, when people talk about botnets, they are talking about a group of computers infected with the malicious kind of robot software, the bots, which present a security threat to the computer owner. Once the robot software (also known as malicious software or malware) has been successfully installed in a computer, this computer becomes a zombie or a drone, unable to resist the commands of the bot commander.

A botnet may be small or large depending on the complexity and sophistication of the bots used. A large botnet may be composed of ten thousand individual zombies. A small botnet, on the other hand may be composed of only a thousand drones. Usually, the owners of the zombie computers do not know that their computers and their computers’ resources are being remotely controlled and exploited by an individual or a group of malware runners through Internet Relay Chat (IRC)

There are various types of malicious bots that have already infected and are continuing to infect the internet. Some bots have their own spreaders – the script that lets them infect other computers (this is the reason why some people dub botnets as computer viruses) – while some smaller types of bots do not have such capabilities.

Different Types of Bots

Here is a list of the most used bots in the internet today, their features and command set.

XtremBot, Agobot, Forbot, Phatbot

These are currently the best known bots with more than 500 versions in the internet today. The bot is written using C++ with cross platform capabilities as a compiler and GPL as the source code. These bots can range from the fairly simple to highly abstract module-based designs. Because of its modular approach, adding commands or scanners to increase its efficiency in taking advantage of vulnerabilities is fairly easy. It can use libpcap packet sniffing library, NTFS ADS and PCRE. Agobot is quite distinct in that it is the only bot that makes use of other control protocols besides IRC.

UrXBot, SDBot, UrBot and RBot

Like the previous type of bot, these bots are published under GPL, but unlike the above mentioned bots these bots are less abstract in design and written in rudimentary C compiler language. Although its implementation is less varied and its design less sohisticated, these type of bots are well known and widely used in the internet.

GT-Bots and mIRC based bots
These bots have many versions in the internet mainly because mIRC is one of the most used IRC client for windows. GT stands for global threat and is the common name for bots scripted using mIRC. GT-bots make use of the mIRC chat client to launch a set of binaries (mainly DLLs) and scripts; their scripts often have the file extensions .mrc.
Malicious Uses of Botnets

Types Of Botnet Attack

Denial of Service Attacks
A botnet can be used as a distributed denial of service weapon. A botnet attacks a network or a computer system for the purpose of disrupting service through the loss of connectivity or consumption of the victim network’s bandwidth and overloading of the resources of the victim’s computer system. Botnet attacks are also used to damage or take down a competitor’s website.

Fast flux is a DNS technique used by botnets to hide phishing and malware delivery sites behind an ever-changing network of compromised hosts acting as proxies.
Any Internet service can be a target by botnets. This can be done through flooding the website with recursive HTTP or bulletin-board search queries. This mode of attack in which higher level protocols are utilized to increase the effects of an attack is also termed as spidering.

Spyware
Its a software which sends information to its creators about a user's activities – typically passwords, credit card numbers and other information that can be sold on the black market. Compromised machines that are located within a corporate network can be worth more to the bot herder, as they can often gain access to confidential information held within that company. There have been several targeted attacks on large corporations with the aim of stealing sensitive information, one such example is the Aurora botnet.

Adware
Its exists to advertise some commercial entity actively and without the user's permission or awareness, for example by replacing banner ads on web pages with those of another content provider.

Spamming and Traffic Monitoring
A botnet can also be used to take advantage of an infected computer’s TCP/IP’s SOCKS proxy protocol for networking appications. After compromising a computer, the botnet commander can use the infected unit (a zombie) in conjunction with other zombies in his botnet (robot network) to harvest email addresses or to send massive amounts of spam or phishing mails.

Moreover, a bot can also function as a packet sniffer to find and intercept sensitive data passing through an infected machine. Typical data that these bots look out for are usernames and passwords which the botnet commander can use for his personal gain. Data about a competitor botnet installed in the same unit is also mined so the botnet commander can hijack this other botnet.

Access number replacements are where the botnet operator replaces the access numbers of a group of dial-up bots to that of a victim's phone number. Given enough bots partake in this attack, the victim is consistently bombarded with phone calls attempting to connect to the internet. Having very little to defend against this attack, most are forced into changing their phone numbers (land line, cell phone, etc.).

Keylogging and Mass Identity Theft
An encryption software within the victims’ units can deter most bots from harvesting any real information. Unfortunately, some bots have adapted to this by installing a keylogger program in the infected machines. With a keylogger program, the bot owner can use a filtering program to gather only the key sequence typed before or after interesting keywords like PayPal or Yahoo mail. This is one of the reasons behind the massive PayPal accounts theft for the past several years.

Bots can also be used as agents for mass identity theft. It does this through phishing or pretending to be a legitimate company in order to convince the user to submit personal information and passwords. A link in these phishing mails can also lead to fake PayPal, eBay or other websites to trick the user into typing in the username and password.

Botnet Spread
Botnets can also be used to spread other botnets in the network. It does this by convincing the user to download after which the program is executed through FTP, HTTP or email.

Pay-Per-Click Systems Abuse
Botnets can be used for financial gain by automating clicks on a pay-per-click system. Compromised units can be used to click automatically on a site upon activation of a browser. For this reason, botnets are also used to earn money from Google’s Adsense and other affiliate programs by using zombies to artificially increase the click counter of an advertisement.

Thursday, 21 November 2013

DNS - FULL EXPLANATION

Enumerating DNS records with DNSenum Tool in Kali Linux

DNS stand for Domain Name System (or Service or Server), an Internet service that translates domain names into IP addresses. Because domain names are alphabetic, they’re easier to remember.

The Internet however, is really based on IP addresses. Every time you use a domain name, therefore, a DNS service must translate the name into the corresponding IP address.

For example, the domain name www.way2h.blogspot.com might translate to 74.125.236.67 which is google DNS ip  this is my blog so the domain name was given by google and so this ip is google dns IP

One of the most important stages of an attack is information gathering. To be able to launch an attack, we need to gather basic information about our target. So, the more information we get, the higher is the probability of a successful attack.

Enumeration is a process that allows us to gather information from a network. We will examine DNS enumeration and SNMP enumeration techniques.

DNS enumeration is the process of locating all DNS servers and DNS entries for an organization. DNS enumeration will allow us to gather critical information about the organization such as usernames, computer names, IP addresses, and so on. To achieve this task, we will use DNSenum. For SNMP enumeration, we will use a tool called SnmpEnum. SnmpEnum is a powerful SNMP enumeration tool that allows users to analyze SNMP traffic on a network.

Navigate to Application > Kali Linux > Information Gathering > DNS Analysis > Open dnsenum

and enter the following command:

root@Kali:~# dnsenum – - enum example.com

It Will Show you Host address , Name Servers address , Mail (MX) Server and Zone Trabsfer Information.

If you want to More Powerful scan with Sub-domain, then use the following syntax.

root@Kali:~# dnsenum – - enum -f -r example.com

There are some additional options we can run using DNSenum:

- threads [number] allows you to set how many processes will run at once
-r allows you to enable recursive lookups
-d allows you to set the time delay in seconds between WHOIS requests
-o allows us to specify the output location
-w allows us to enable the WHOIS queries






Hope you enjoyed reading this tutorial! and remember this tut is only for educational purpose dont try to use again any restricted server  do it only if u awn the domain or u have rights to do so....   happy hacking hope u learn something if u have any question related to this then  do comment i will reply you :)  
  

Saturday, 16 November 2013

15 Indian Government and NIC Server Sites hacked by "H4x0r HuSsY", Pakistani Hacker

Pakistani Hacker name as "H4x0r HuSsY" hit 15 Indian Government sites including few sites on NIC Server. India.gov.in Main Goverment Portal's Subdomain also got Hacked by hacker. There is no specific reason mention in attack by hacker. Its seems like regular Pakistan India cyber war. Still these kind of attacks create many questions for security experts.


Deface page Say's:
"Hacked by H4x0r HuSsY


Pakistani LeeT InsiDe y0 b0x!"

Hacked Sites:
norka.kerala.gov.in
openschool.kerala.gov.in
ahdkerala.gov.in
ahd.kerala.gov.in
ngodemo.nic.in/ngo/b342350dd73...
ngoadmin.nic.in/ngo/b342350dd7...
policyholder.gov.in/1337.html
forums.netiq.com/sitemap/1337
tripurarti.nic.in/rti_print
iwmpmis.nic.in/
himswanshqvs01.hpsvacb.gov.in
www.himachaltourism.nic.in

hppwd.gov.in/1337.html

Mirrors:
http://www.zone-h.org/archive/notifier=h4x0r%20HuSsY/published=0

Friday, 15 November 2013

NASA 8 Sub Domains Hacked by M4ST£R 1T4L!4N H@CK£RS T£4M, Italian hackers

NASA 8 sub domain sites hacked by M4ST£R 1T4L!4N H@CK£RS T£4M.

NASA is consider as one of most secured server in world but this time again hackers are able to break into NASA server and deface 8 sub domains with there deface page. There is no specific reason mentioned on deface page about this hack by hackers. These kind of attacks raise many question for security experts that how hackers are still able to break into world most secured servers.


Deface Page Say's:
"Hacked
By
M4ST₤R 1T4L!4N H@CK₤RS T₤4M

#M1NDFR34KS #DR34M #SystemX #Dr.d3v1l

Contact: systemx_mih@yahoo.com"

Hacked Sites:
spaceshop.arc.nasa.gov
bt4lbleo.arc.nasa.gov
sphereswg.arc.nasa.gov
ppmovm.arc.nasa.gov
ppmo.arc.nasa.gov
ngss-trs.arc.nasa.gov
ngss.arc.nasa.gov
admms.arc.nasa.gov

Mirrors:
http://www.zone-h.org/archive/notifier=M4ST%25C2%25A3R%25201T4L%25214N%2520H%2540CK%25C2%25A3RS%2520T%25C2%25A34M

Sunday, 10 November 2013

150+ Israeli Sites Hacked and Defaced to protest against Israel, Turkey Cyber Army

150+ Israeli Sites Hacked and Defaced to protest against Israel, Turkey Cyber Army.

Turkish Hacker name as "3xroot" hack 150 plus Israeli sites to protest against Israel for Gaza Freedom For Palestine. According to Hacker "You realize that because you have exceeded his limits.! ISRAEL we're aware of Gaza Freedom For Palestine and free ..! ". Turkish hackers are considers as world top defacers and Israeli servers are considers as world most secure servers. But hackers again proof them self that how much level of hackers increase relative to security experts.


"Turkısh Message"

"Likud Partisi kacinizin curmu yeter ezanlari susturmaya? Vatanimiza,Dinimize Karsi
 Kotu Fikirlere Sahip Olan Tum Ulkelere Sanal Savas Acilacaktir..! Biz Turk
 Devletleri Olarak Hep Birlikteyiz Kimseden Korkmayiz Gerektigi Yerde Gereken 
Cevabi Veririz..! Zulme goz yuman veya zulumle hukum surmeye kalkan
 her ulkeye ziyaret borcumuz olsun!"

"English Message"

"How many of the Likud Party's call to prayer is enough to silence the criminal act?
 Vataniza, our religion Counter Having a bad idea Virtual War will be opened 
in all countries ..! We always are together as Youtube States Where it should not
 be afraid of anyone Will answer you need ..! Shield or condone the persecution
 persecution visit every country in debt to reign it! "

Since © 2008 Turkey Cyber Army Group

Atess = Ayazoglu = Hakn's = byN3sht3r = Oxsit = Death_K1nG = SonHamle = Cep_King =
 By3xRooT = Hacker_infazci = SonTuRK =TH3HQCKE4 = AsilTurk = The_Zey =
 All muslim Hackers
"Akıncılar ~ SpyHatz "

Hacked Sites List:

Mirrors:

Wednesday, 6 November 2013

FBI offer huge bounty on Top 5 Most Wanted Cyber Criminals

The Federal Bureau of Investigation is offering cash rewards of up to $100,000 for information leading to the arrest of five individuals who were added to the Cyber’s Most Wanted list.

Two of them are Pakistani, Farnhan Arshad and Noor Aziz Uddin are in FBI list. Both of them cause damage of over $50 Million after hacking into private Cell phone system in 2008 and 2012. Both of them are part of some underground cyber criminal network. FBI believes extends into Pakistan, philippines, Saudi Arabia, Italy, Spain, Singapore, Malaysia and Indonesia.

Alexsey Belan, Russian Hacker also in list who hack 3 US companies in 2008 and 2013.

Carlos Perez-Melara is also part of list who make software to hack into million of peoples and steal and sell peoples data in Cyber Black Market.