Friday, 10 January 2014

Facebook Scam: Win a Disney Cruise with $2,000 Spending Money

Cammers have created Facebook pages called “Walt Disney World” on which they claim to be giving users the chance to win a trip via Disney Cruise.

“Great news, we're giving you a chance to get a Disney Cruise for you and 5 friends to 50 people from us with $2,000 spending money for a date of your choice. To enter Just Share this video then go here: www.disney-cruise-lines.com,” the posts entitled “Win a Disney Cruise with $2,000 spending money” read.



The so-called competition has nothing to do with Disney. Furthermore, the link doesn’t actually point to the Disney Cruise Lines website, but to a site where users are instructed to complete a survey in order to allegedly win various prizes, Hoax Slayer warns.

Each time one of these surveys is completed, the scammers make some money via affiliate networking services. Furthermore, some of the sites also instruct users to hand over personal information, which can also be monetized in various ways.

Finally, by tricking users into liking their bogus Facebook pages, the cybercrooks are actually increasing their values. Pages with a large number of likes can be worth a lot of money on the underground market since they can be repurposed for other shady activities.


If you’re a victim of this scam, remove the post you’ve shared on your timeline. If you’ve completed the survey and handed over some personal information, watch out for other scams, since it’s likely that you’ve ended up on the scammers’ list of potential victims.

I’ve seen three of these fake “Walt Disney World” pages, but others might appear soon. The ones that are currently online have harvested as many as 21,000 likes. If you come across such pages, report them to Facebook.

Cyber Attack Hit Japanese Nuclear Power Plant using Special Malware

Software update cause Malware attack on Japanese Nuclear Power Plant.

When japan was hit by Earth Quick last year then it was also discovered that japan was working on some secret nuclear power Plants. So this may be possible that world power want to get information about Japan Nuclear Power Plants and have an eye on them.



The most critical and worst target of a State-sponsored cyber-attacks could be Hospitals, Dams, Dykes and Nuclear power stations and this may cause military conflicts between countries.

According to Japan Today, The Monju nuclear power plant in Tsuruga, Japan was accidentally targeted by a malware on 2nd January, when a worker updated the system to the latest version of the video playback program. Monju Nuclear Plant is a sodium-cooled fast reactor, was launched in April 1994. It has not been operational for most of the past 20 years, after an accident in which a sodium leak caused a major fire. Employees over there are only left with a regular job of company's paperwork and maintenance. So the malware could have stolen only some sensitive documents, emails, training records and employees' data sheets. The Malware command-and-control server suspected to be from South Korea. The malware itself is not much sophisticated like Stuxnet or Duqu, but the unmanaged software update and patch management system can seriously lead to a critical cyber attack. Even being isolated from the Internet does not prevent you from being infected. One of the best examples of flawed Internal policies is Stuxnet, one of the most infamous pieces of malware ever created to destroy Iranian Nuclear plants and infected the systems through a USB stick only. Also in November, The Kaspersky revealed that Russian astronauts carried a removable device into space which infected systems on the space station.

Monday, 23 December 2013

Installing BackTrack 5 R1

What is BackTrack5
  • BackTrack is an operating system based on the Ubuntu GNU/Linux distribution aimed at digital forensics and penetration testing use. It is named after backtracking, a search algorithm. The current version is BackTrack 5, code name "Revolution."

  • BackTrack provides users with easy access to a comprehensive and large collection of security-related tools ranging from port scanners to password crackers. Support for Live CD and Live USB functionality allows users to boot BackTrack directly from portable media without requiring installation, though permanent installation to hard disk is also an option

  • BackTrack includes many well known security tools including
    • Metasploit integration
    • RFMON Injection capable wireless drivers
    • Aircrack-NG
    • Kismet
    • Nmap
    • Ophcrack
    • Ettercap
    • Wireshark (formerly known as Ethereal)
    • BeEF (Browser Exploitation Framework)
    • Hydra
  • BackTrack Download
     

Create a New Virtual Machine. (See Below)

 New Virtual Machine Wizard
  • Instructions:
    1. Select the radio button "Installer disc image file (iso):"
    2. Click the Browse Button.
    3. Navigate to where you BT5 iso is located.
    4. Select the BT5 iso
    5. Click Next
     
     
New Virtual Machine Wizard
  • Instructions:
    1. Guest operating system:  Linux
    2. Version: Ubuntu
    3. Select Next
    New Virtual Machine Wizard
    • Instructions:
      1. Virtual machine name: BackTrack5R1
      2. Location: In my case, I saved it to my USB drive, located in H:\BackTrack5R1\
      3. Select Next
        

        



















    New Virtual Machine Wizard
    • Instructions:
      1. Maximum disk size (GB): For our purposes use 20GB.
      2. Radio Button:  Store virtual disk as an single file
      3. Select Next 
       



    New Virtual Machine Wizard
    • Instructions:
      1. Click on the "Customize Hardware..." button

    New Virtual Machine Wizard
    • Instructions:
      1. Click on Memory (which is highlighted in blue)
      2. Click on 512 MB. (Recommended is 1024 MB, but not really needed for lab purposes).
      3. Do not click on OK
       
     New Virtual Machine Wizard
    • Instructions:
      1. Click on Network Adapter
      2. Click on "Bridged: Connected directly to the physical network"
      3. Click OK. 

    Click on the Finish button.
    • Instructions:
      1. Click the Customize Hardware... button
       
    Start the Boot Process
    • Instructions:
      1. Press Enter

    BackTrack Live CD
    • Instructions:
      1. Select "BackTrack Text - Default Boot Text Mode"
      2. Press <Enter>
       
    Bring up the GNOME
    • Instructions:
      1. Type startx
     
    Install BackTrack to Harddrive


    Install BackTrack to Harddrive
    • Instructions:
      1. Option 1: Double Click on the icon labeled "Install BackTrack"
        • OR
      2. Option 2: System --> Administration --> Install BackTrack Live 
       
    1. Select Language
      • Instructions:
        1. In my case: English.
        2. Click Forward
    2. Select Language
      • Instructions: (In my case)
        1. Region: English
        2. Time Zone: United States (Chicago)
        3. Click Forward
    3. Select Language
      • Instructions: (In my case)
        1. Suggested option: USA
        2. Click Forward
    4. Select Language
      • Instructions:
        1. Select "Erase and use the entire disk"
        2. Select Forward
      • OR Note (This is optional)
        1. If you select "Specify partitions manually", then you can create you own file systems layout.
          • /     - 2000 MB
          • /boot - 500  MB
          • swap  - 1280 MB (Double Memory)
          • /tmp  - 1000 MB
          • /home - 2000 MB
          • /var  - 2000 MB
          • /usr  - 3000 MB
          • Then use the rest as needed using volume management.

    5. Select Language
      • Instructions:
        1. Click on Install
    6. Informational
      • Note(FYI):
        • The installation process will take between 10 and 45 minutes depending on your systems resources.
    7. Consistency Reboot
      • Instructions:
        1. Click on Restart Now

    Section 3. Login to BackTrack
    1. Edit Virtual Machine Settings
      • Instructions:
        1. Virtual Machine --> Virtual Machine Settings...
    2. Edit CD/DVD (IDE)
      • Instructions:
        1. Select CD/DVD (IDE)
        2. Click on Use physical drive:
          • Select Auto detect
        3. Click the OK Button
    3. Login to BackTrack
      • Instructions:
        1. Login: root
        2. Password: toor

    4. Bring up the GNOME
      • Instructions:
        1. Type startx
    5. Bring up a console terminal
      • Instructions:
        1. Click on the Terminal Console Icon
    6. Change root's password
      • Instructions:
        1. passwd root
        2. Use our standard class password
    7. Create a student account and set password
      • Instructions:
        1. useradd -m -d /home/student -c "Security Student" -s /bin/bash student
        2. passwd student
        3. Use our standard class password
     

      Monday, 16 December 2013

      All about VPN- little explanation

      We must know there are three VPN protocols: PPTP, L2TP y SSL.

      It must be clear an idea: the three VPN protocols are used to same target which is to encapsulate the PPP protocol. PPP protocol is network protocol stack uses to do a direct connection between two networking hosts. Therefore PPTP, L2TP y SSL have the common features of PPP, for example authentication schemes, Ipv4, Ipv6 and others. But this is another story.

      So we have:

      PPTP (Point-to-Point Tunneling Protocol):
      It is very old, then it can be supported by old and new clients such as Windows 98, Windows NT, Windows 2000, etc.
      This uses Encryption Method called MPPE.
      It is very easy in his configuration, very firewall compatibility but hasn’t integrity. Besides it cannot use certificates.

      L2TP (Layer 2 Tunneling Protocol):
      This use encryption method called Ipsec, so this can use certificates or a preshared key but It needs new clients such as Windows XP, and Windows Vista,etc. His configuration is difficult and we have a lot of problems in firewall configurations. However it is very secure as it has remote computer and user authentication.

      SSTP (Secure Socket Tunneling Protocol ):
      It is the newest VPN protocol therefore it needs the newest clients and servers (Windows Vista SP1… and Windows Server 2008 …). It is very secure and easy in his configuration as this uses the well know protocol SSL (port TPC 443) therefore it needs a server certificate and we must also configure IIS (Internet Information Services). In general, it is configured easily in firewalls.
      IKEv2:( Internet Key Exchange Version 2):
      It is the newer VPN protocol used for Windows 7, Windows 8, Windows Server 2008 R2 and Windows Server 2012. Actually, this protocol is based on Ipsec but without complexity the others as L2TP.
      This protocol uses UDP port 500 and it can use machine certificate or preshared key as the authentication method for IPsec.
      It is very interesting as we can use in two important novelties respect to newer Microsoft’s operating systems as such DirectAccess or automatic reconnection.

      To sum up:


      When we have to choose a VPN protocol in an answer in a certification exam or in real cases if we work as IT Administrators we must take into account: client versions, firewall compatibility, security grade and if we are goint to have PKI.
      Besides, we could use Ipsec only to configure VPN but this is very complex and these VPN,s which are based on Ipsec only are configurated by communication companies, however we can use IKE v2 if we’ve got newer Microsoft’s operating systems, this allows to configure easily DirectAccess and the automatic reconnection in the new mobile networks based on 3G, 4G or Wifi.  +


      stay connected  and happy hacking with way2hackintosh and if you want to contact us  E-mail us on way2hackintosh@gmail.com

      Wednesday, 11 December 2013

      How long would it take to brute force 256 bit AES passwords

      The issue with AES-256 isn't in brute forcing strong passwords.  If you password is strong (not on any dictionary, longer than 8 char, mixed symbols, uses a large random salt) it can't be bruted forced at any reasonable cost.  If it is 12+ char includes all 4 symbol classes or simply is a random string it can't be brute forced at any cost.

      The issue with AES-256 is it is a very faster cipher.  For weak (or marginal) passwords it can be bruted forced.  How complex of a password is vulnerable depends on the resources available to the attacker and how long they are willing to to wait.

      So if we consider a weak password to be one that (at least in theory) could be compromised by a dictionary, modified dictionary, or brute force attack using a computing on the magnitude available:
      1) anything found in a standard dictionary or leaked/common password list (various lists usually in the tens of millions of pwd range).
      2) anything with less than 8 characters.
      3) anything all lower case with less than 10 characters.
      4) anything not encrypted using 64bit or larger salt.
      5) anything which has less than 3 substitutions from something listed above (p@ssword! vs password)

      The reality is end users likely don't know if their password is strong or not. So developers should prevent users from hurting themselves.  As a developer you can implement a large salt and could require a minimum of 8 characters (don't impose special char requirements).  At that point brute force and precomputation are off the table; so the largest risk comes from dictionary or modified dictionary attacks.  There are lists of millions of previously compromised passwords.  If the password used is on one of those lists it can be found in a matter of minutes.  If you are paranoid about your user's security you could check their password against a list of known compromised passwords.  An alternative would be for someone to develop a webservice which took a hash (HMAC) or all known/weak/compromised passwords.  Users could send a HMAC hash of their potential password and get a "known" or "good" response.

      One further step you could take is key stretching using a key derivative function. The bitcoin wallet does this.  Rather than simply use the passphrase it takes multiple iterative hashes of the password (generally thousands of tens of thousands).   So instead of key = passphrase it is key = SHA256(SHA256(SHA256(passphrase))). This increases the length of time necessary to try one key and thus reduces the throughput of the attacker.   Understand that if user's password is very weak (under 6 char or on a dictionary list) this is unlikely to help because even 2000x a 1 sec search is unlikely to stop an attacker.

      The key stretching function (hash) used by the wallet is SHA-256 which is well optimized due to this thing called mining.  Security could be enhanced by replacing the key strengthening function with another one (say bcrypt of even PBKDF2 using SHA-512 or RIPEMD).

      http://en.wikipedia.org/wiki/Key_derivation_function
      http://en.wikipedia.org/wiki/Key_stretching
      http://en.wikipedia.org/wiki/PBKDF2
      http://en.wikipedia.org/wiki/Bcrypt

      TL/DR:
      It depends. Using a combination of:
      a) require at least 8 digits (makes brute force prohibitively expensive)
      b) use a large (64bit+) random salt (prevents precomputation attacks)
      c) check password against known/compromised password list that hackers are likely to be using (prevent quick dictionary based attacks)
      d) use key strengthening (reduces the attackers throughput by a couple orders of magnitude).
      e) use an algorithm other than SHA-256 in the KDF to prevent "re-use" or mining research