Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Dnsenum using information gathering tutorial

Hello Guys 

Today I will show you DNSENUM information gathering tool.

DNSenum is a pentesting tool created to enumerate DNS info about domains.

The purpose of Dnsenum is to gather as much information as possible about a domain

DNSenum is a very important tool to perform a quick enumeration step on penetration testing.
    Host address
    Name server
    MX record
    Sub domains
    Whois performance
    Reverse lookup for netblocks
    Use google to do the job done

use:
------------------------------------------------------------------
1)Simple scan
     dnsenum google.com

2)Powerful scan use
     dnsenum --enum google.com

3)More power scan with sub domains
     dnsenum --enum -f -r google.com

Note:

if you get error like this

Warning: can't load Net::Whois::IP module, whois queries disabled.

--> apt-get install cparminus
--> cpanm -n Net::Whois::IP




Thank you (zer0w0rm)


READMORE
 

Pen-testing List of Labs

Vulnerable Web Applications
OWASP BWA http://code.google.com/p/owaspbwa/
OWASP Hackademic http://hackademic1.teilar.gr/
OWASP SiteGenerator https://www.owasp.org/index.php/Owasp_SiteGenerator
OWASP Bricks http://sourceforge.net/projects/owaspbricks/
OWASP Security Shepherd https://www.owasp.org/index.php/OWASP_Security_Shepherd
Damn Vulnerable Web App (DVWA) http://www.dvwa.co.uk/
Damn Vulnerable Web Services (DVWS) http://dvws.professionallyevil.com/
WebGoat.NET https://github.com/jerryhoff/WebGoat.NET/
PentesterLab https://pentesterlab.com/
Butterfly Security Project http://thebutterflytmp.sourceforge.net/
Foundstone Hackme Bank http://www.mcafee.com/us/downloads/free-tools/hacme-bank.aspx
Foundstone Hackme Books http://www.mcafee.com/us/downloads/free-tools/hacmebooks.aspx
Foundstone Hackme Casino http://www.mcafee.com/us/downloads/free-tools/hacme-casino.aspx
Foundstone Hackme Shipping http://www.mcafee.com/us/downloads/free-tools/hacmeshipping.aspx
Foundstone Hackme Travel http://www.mcafee.com/us/downloads/free-tools/hacmetravel.aspx
LAMPSecurity http://sourceforge.net/projects/lampsecurity/
Moth http://www.bonsai-sec.com/en/research/moth.php
WackoPicko https://github.com/adamdoupe/WackoPicko
BadStore http://www.badstore.net/
WebSecurity Dojo http://www.mavensecurity.com/web_security_dojo/
BodgeIt Store http://code.google.com/p/bodgeit/
hackxor http://hackxor.sourceforge.net/cgi-bin/index.pl
SecuriBench http://suif.stanford.edu/~livshits/securibench/
SQLol https://github.com/SpiderLabs/SQLol
CryptOMG https://github.com/SpiderLabs/CryptOMG
XMLmao  https://github.com/SpiderLabs/XMLmao
Exploit KB Vulnerable Web App http://exploit.co.il/projects/vuln-web-app/
PHDays iBank CTF http://blog.phdays.com/2012/05/once-again-about-remote-banking.html
GameOver http://sourceforge.net/projects/null-gameover/
Zap WAVE http://code.google.com/p/zaproxy/downloads/detail?name=zap-wave-0.1.zip
PuzzleMall http://code.google.com/p/puzzlemall/
VulnApp http://www.nth-dimension.org.uk/blog.php?id=88
sqli-labs https://github.com/Audi-1/sqli-labs
Drunk Admin Web Hacking Challenge https://bechtsoudis.com/work-stuff/challenges/drunk-admin-web-hacking-challenge/
bWAPP http://www.mmeit.be/bwapp/
http://sourceforge.net/projects/bwapp/files/bee-box/
NOWASP / Mutillidae 2  http://sourceforge.net/projects/mutillidae/
SocketToMe http://digi.ninja/projects/sockettome.php
Vulnerable Operating System Installations
Damn Vulnerable Linux http://sourceforge.net/projects/virtualhacking/files/os/dvl/
Metasploitable http://sourceforge.net/projects/virtualhacking/files/os/metasploitable/
LAMPSecurity http://sourceforge.net/projects/lampsecurity/
UltimateLAMP http://www.amanhardikar.com/mindmaps/practice-links.html
heorot: DE-ICE, hackerdemia http://hackingdojo.com/downloads/iso/De-ICE_S1.100.iso
http://hackingdojo.com/downloads/iso/De-ICE_S1.110.iso
http://hackingdojo.com/downloads/iso/De-ICE_S1.120.iso
http://hackingdojo.com/downloads/iso/De-ICE_S2.100.iso
hackerdemia – http://hackingdojo.com/downloads/iso/De-ICE_S1.123.iso
pWnOS http://www.pwnos.com/
Holynix http://sourceforge.net/projects/holynix/files/
Kioptrix http://www.kioptrix.com/blog/
exploit-exercises – nebula, protostar, fusion http://exploit-exercises.com/download
PenTest Laboratory  http://pentestlab.org/lab-in-a-box/
RebootUser Vulnix http://www.rebootuser.com/?page_id=1041
neutronstar http://neutronstar.org/goatselinux.html
scriptjunkie.us  http://www.scriptjunkie.us/2012/04/the-hacker-games/
21LTR http://21ltr.com/scenes/
SecGame # 1: Sauron http://sg6-labs.blogspot.co.uk/2007/12/secgame-1-sauron.html
Pentester Lab https://www.pentesterlab.com/exercises
Vulnserver http://www.thegreycorner.com/2010/12/introducing-vulnserver.html
TurnKey Linux http://www.turnkeylinux.org/
Bitnami https://bitnami.com/stacks
Elastic Server http://elasticserver.com
CentOS http://www.centos.org/
Sites for Downloading Older Versions of Various Software
Exploit-DB http://www.exploit-db.com/
Old Version http://www.oldversion.com/
Old Apps  http://www.oldapps.com/
VirtualHacking Repo sourceforge.net/projects/virtualhacking/files/apps%40realworld/
Sites by Vendors of Security Testing Software
Acunetix acuforum http://testasp.vulnweb.com/
Acunetix acublog http://testaspnet.vulnweb.com/
Acunetix acuart http://testphp.vulnweb.com/
Cenzic crackmebank http://crackme.cenzic.com
HP freebank http://zero.webappsecurity.com
IBM altoromutual http://demo.testfire.net/
Mavituna testsparker http://aspnet.testsparker.com
Mavituna testsparker http://php.testsparker.com
NTOSpider Test Site http://www.webscantest.com/
Sites for Improving Your Hacking Skills
EnigmaGroup http://www.enigmagroup.org/
Exploit Exercises http://exploit-exercises.com/
Google Gruyere http://google-gruyere.appspot.com/
Gh0st Lab http://www.gh0st.net/
Hack A Server  https://hackaserver.com/
Hack This Site  http://www.hackthissite.org/
HackThis  http://www.hackthis.co.uk/
HackQuest http://www.hackquest.com/
Hack.me https://hack.me
Hacking-Lab https://www.hacking-lab.com
Hacker Challenge http://www.dareyourmind.net/
Hacker Test http://www.hackertest.net/
hACME Game http://www.hacmegame.org/
Hax.Tor http://hax.tor.hu/
OverTheWire http://www.overthewire.org/wargames/
PentestIT  http://www.pentestit.ru/en/
p0wnlabs  http://p0wnlabs.com/
pwn0 https://pwn0.com/home.php
RootContest http://rootcontest.com/
Root Me http://www.root-me.org/?lang=en
Security Treasure Hunt http://www.securitytreasurehunt.com/
Smash The Stack http://www.smashthestack.org/
TheBlackSheep and Erik  http://www.bright-shadows.net/
ThisIsLegal http://thisislegal.com/
Try2Hack http://www.try2hack.nl/
WabLab http://www.wablab.com/hackme
XSS: Can You XSS This? http://canyouxssthis.com/HTMLSanitizer/
XSS: ProgPHP http://xss.progphp.com/
CTF Sites / Archives
CTFtime (Details of CTF Challenges) http://ctftime.org/ctfs/
shell-storm Repo http://shell-storm.org/repo/CTF/
CAPTF Repo http://captf.com/
VulnHub https://www.vulnhub.com
CTF365 http://ctf365.com/
Hacker Cons http://hackercons.org/
Hat Force https://www.hatforce.com/
Intense School http://www.intenseschool.com/resources/
SECore https://secore.info/
Mobile Apps
ExploitMe Mobile Android Labs http://securitycompass.github.io/AndroidLabs/
ExploitMe Mobile iPhone Labs http://securitycompass.github.io/iPhoneLabs/
OWASP iGoat  http://code.google.com/p/owasp-igoat/
OWASP Goatdroid https://github.com/jackMannino/OWASP-GoatDroid-Project
Damn Vulnerable iOS App (DVIA) http://damnvulnerableiosapp.com/
Damn Vulnerable Android App (DVAA) https://code.google.com/p/dvaa/
Damn Vulnerable FirefoxOS Application (DVFA) https://github.com/pwnetrationguru/dvfa/
NcN Wargame http://noconname.org/evento/wargame/
Hacme Bank Android http://www.mcafee.com/us/downloads/free-tools/hacme-bank-android.aspx
InsecureBank http://www.paladion.net/downloadapp.html
Miscellaneous
VulnVPN http://www.rebootuser.com/?page_id=1041
VulnVoIP http://www.rebootuser.com/?page_id=1041
NETinVM http://informatica.uv.es/~carlos/docencia/netinvm/
GNS3 http://sourceforge.net/projects/gns-3/
XAMPP https://www.apachefriends.org/index.html

Thank you (zer0w0rm)
READMORE
 

6 Of The Best VPNs For Anonymous Surfing

VPNs are very handy when it comes to enabling you to surf the internet anonymously without leaving behind a trail. This is handy when you don't want others using your system to know what you've been doing. Here are 6 handy VPNs to get the job done. 



1.LogMeIn Hamachi

LogMeIn Hamachi is a hosted VPN service that lets you securely extend LAN-like networks to distributed teams,
mobile workers and your gamer friends alike, in minutes.

2.PacketiX.NET

PacketiX.NET is an academic, non-profit online environment for PacketiX VPN, the VPN technology developed by SoftEther Corporation.

3.ItsHidden.eu

This is a secure connection that encryts all your information and is not readable by anyone else so wherever you are your privacy is always maintained. There is no software required and ItsHidden.eu works on all platforms including Windows, Mac, Linux, IPhone etc.

4.Your Freedom

The Your Freedom services makes accessible what is unaccessible to you, and it hides your network address from those who don't need to know. 

5.Hotspot Shield

Hotspot Shield VPN offers you much better security and privacy protection than a web proxy. Hotspot Shield free VPN encrypts your internet traffic, and enables you to access any blocked or geo-restricted site wherever you are, and more.

6.AlwaysVPN

AlwaysVPN is a hosted virtual private network that creates an encrypted link between your computer and its servers and then forwards all of your internet traffic through this link.


Thank you (zer0w0rm)
READMORE
 

Don’t Take the Bait, 4 Ways to Avoid Phishing Scams

As online fraud remains a consistent problem for nearly 300,000,000 Americans who use the internet daily, it’s important to stay updated and informed on the newest forms of fraud that are a constant threat to our online security. The Better Business Bureau (BBB) warns internet users about “phishing” emails, a scam that is becoming an increasing problem and is proving to be very costly for employers. Chubbworks even published an article recently discussing email scams and surveyed how many people had actually received a phishing email themselves, a majority have.

Avoiding-Phishing-Emails 

The latest versions of these scams are showing up in the form of emails from trusted organizations such as the BBB or United States Postal Service (USPS). The emails are sent by hackers asking you to submit information or to follow links that gather, or “phish,” for your personal data which may include banking information, usernames, and/or passwords. These emails will oftentimes deliver a nasty virus to your computer system. Once your computer is infected, you become vulnerable to serious potential security risks. So how can you avoid this from happening to you? Here are four things you should know:

1. Make sure to pay attention to spelling mistakes and grammatical errors in emails. 
 A fortune 500 company (or any large reputable business) is very unlikely to release an email blast riddled with misspellings.
 

2. Hold your cursor (don’t click) over any suspicious links. 
This will show you the URL that you are about to click. If the URL doesn’t contain the company name in the first part of the domain [www.company.com], it’s probably a scam.
    a. For example, if you were to receive an email that looks like it came from the United States Postal Service (USPS) and it asks you to click a link and that link doesn’t start with http://www.usps.com in the URL, it’s very likely it’s a phishing scam!

3. Keep your antivirus software up-to-date. 
Antivirus software helps to shield your computer from internet threats and those software updates are important because your program should be constantly evolving based on new hacker threats.
 

4. Last and certainly not least, educate your staff. 
 Make sure that they are aware of the caution they need to take when clicking links inside an email. Your staff should understand the potential consequences of getting a computer virus and how it could affect your clients (remember the Target fiasco last Thanksgiving?)

With so much information being stored on the web in today’s business world, it is important to be cautious with your personal data and information. Stay secure, and stay informed, so you don’t take the bait and put yourself at risk!

Thank you (zer0w0rm)
READMORE
 

Encryption Methods

This tutorial covers some popular encryption methods. To begin you will need some things


1. You need the encrypted data

You will have to find the encrypted data. Sometimes its hidden in a webpage, disguising itself as something different. Sometimes it is just written somewhere in the open, but the passkey or the referencing alphabet is hidden.

2. You need to know what the crypt represents

If you have a crypt, but you do not know what you are trying to find in, it you will have a much harder time. You should first try to guess what the result of the decryption is. It could be a plain text, or a picture, maybe even a binary program. And if it is text it could be special text, like mathematical expressions, coordinates or just numbers. There are many possibilities, but usually only a few make sense.


3. You need to know how it was encrypted, or at least have a rough guess.

To decrypt the crypt you will first have to know how it was encrypted. There are endless possibilities. First see if you can find out how it was encrypted by investigating the background of the guy that encrypted it or the circumstances of the crypt. There may be hints around. A professional cryptanalysist may need nothing but the crypt to get a good idea how it was encrypted, and even if he has no idea he may still decrypt it by using professional methods. But here for us, you should know how it was encrypted at some point during decryption.. ;)


4. Now what means something is encrypted?

Lets say I have the word: "hello". Now I reverse the word, which gives me "olleh". This is a simple encryption. If someone sees this text on a piece of paper he would probably think its a foreign language: "?uoy era woh yeh." But you know its plain english text, and can easily decrypt it. There are many ways to encrypt text to make it look like no text at all. If another person knows how it was encrypted, he can easily decrypt it and get the message from the crypt. First I want to point out some basic encryption methods:

1. Caesar cipher

Simple cipher that shifts the alphabeth by some number of letters. "abcdef" shifted by 2 becomes: "cdefgh". ROT-13 for example is a rotation of the alphabeth by 13 letters. ROT-13 is so popular because there are 26 letters in the alphabet so its easy to encrypt it then encrypt it a second time to get it back to normal. You can write small programs to look for this kind of easy encryption (or just use rot13.com)

2. Mono-alphabetic substitution

Replaces every letter with some other letter from the alphabeth. No letter can be used twice of course. You will need a key that holds the mapping of the characters. The key has two parts. The first part is the original alphabeth and the second part is the encryption key. Lets say "abcdef" is mapped to "fedcba". That means the word "beef" becomes "ebba". To crack those ciphers you will need to look for more frequent letters and words and guess the text... you will need a fairly large sample of ciphered text for it to work out. The word "the" for example is often used in the english language, for other languages it may be other words of course...

3. Vigenere cipher

Every letter in the word gets shifted by a certain amount that is set by the password. This means the following... lets say the password is "bcde". Now say a=1 b=2 and so on... that means the first letter of the original text is shifted 2 letters, the second one is shifted by 3 letters and so on. This works great until you run out of the password characters. (Its only 4 characters long) Then you just start from the beginning again, in this case with "b" (=2). Notice how the A is converted to a number, here one (1) in the example. This is referencing by position. We talk about that later a bit more detailed.

4. One time pad (with XORing)

The safest version of encrypting is a one time pad. You have a long line of random letters. Those letters are known by you and the guy that needs to decrypt the message. You now encrypt every letter of the original text with the letter at the same position in that random letter line. The result is the cipher that you send away. The guy on the other end has the one time pad and can extract the original letters by decoding with the one time pad random letters. The only bad thing is: you got to get the one time pad to the other side, hopefully without anyone else getting a copy of it they can use to decrypt your message. Additionally the receiver needs to know which pad to use for the decryption if there is more than one pad available.

Now how do you encrypt the two lines of letters with each other? You need to XOR them. First convert them to binary. A binary number consists only of 0 and 1. You can describe any letter with a binary number, either using the Ascii code of the letter as a base or using an alphabeth numbering, like A=1, B=2 or similar. Now after both strings are converted to binary you have a very long line of 0 and 1s. You still know which numbers are representing which letter because you wont delete leading zeros, making it so that for example every 8 numbers represent one letter. (8 bit code)
Now XOR the two strings by using an exclusive-or method. This means: if there is one 1 in between the two, the result is 1. If there are two 0 or two 1, the result is 0.

0 xor 0 = 0
0 xor 1 = 1
1 xor 0 = 1
1 xor 1 = 0

The resulting string can be decrypted by xoring with the known passkey (the one time pad you transmitted earlier to the other side), and then finally by converting to letters again by using either Ascii codes or alphabetic numbering. (Meaning: By referencing the position in a certain known alphabeth).

Converting numbers to letters or vice versa

You already noticed how in those examples letters are becoming numbers or vice versa. Generally this is done by mapping letters to numbers in one way or another. Using computers there are generally two ways of mapping. The first one is the Ascii Table, which converts every character (letter, number, special characters) to a certain number code. You can easily find out about Ascii using a search engine. The second one is Unicode, which is a replacement for Ascii codes that became necessary cause Ascii codes are limited to representing 255 letters, leaving not enough room for all the different letters that some languages have, like chinese for example. Again, use a search engine to learn about Unicode.
Now, not using computers, you can have a reference alphabeth and convert a letter to a number by its position in the alphabeth, and vice versa. Lets say the alphabeth is "gcqlxebm", then G = 1, C = 2, Q = 3. The most natural alphabeth is of course "abcdefghijk...", so its used quite often.

Another method to convert letters to numbers is using hex numbers. Hex numbers can have the letters A-F, representing the digits 10-15, which means if you have certain numbers they will only consist of letters... For those who dont know, HEX number are based on 16 instead of base 10 as our normal numbers are.

Converting numbers to numbers

This may sound easy, but its important for cryptography. Remember that you can always change the way something looks by changing it into some other number system. Our normal system is based on ten, probably because we have ten fingers and toes. This means that you can easily make a number totally unusable to an attacker if you change it to another base without him knowing. A number based on 16 may look the same as a number based on 10, but its a totally different value. So make sure you know what you are looking at. If you have a very large sample of numbers and not a single digit is above 3, then it is probably the base 4 system. Generally, it can be ANY base number. You better find out which one.

Thank you (zer0w0rm)
READMORE