Showing posts with label Penetration Testing. Show all posts
Showing posts with label Penetration Testing. Show all posts

Wednesday, 7 November 2012

Explain Intrusion detection system (IDS)?? Types OF IDS...


An intrusion detection system (IDS) is a device or software application that monitors network or system activities for malicious activities or policy violations and produces reports to a Management Station. Some systems may attempt to stop an intrusion attempt but this is neither required nor expected of a monitoring system. Intrusion detection and prevention systems (IDPS) are primarily focused on identifying possible incidents, logging information about them, and reporting attempts. In addition, organizations use IDPSes for other purposes, such as identifying problems with security policies, documenting existing threats and deterring individuals from violating security policies. IDPSes have become a necessary addition to the security infrastructure of nearly every organization.
IDPSes typically record information related to observed events, notify security administrators of important observed events, and produce reports. Many IDPSes can also respond to a detected threat by attempting to prevent it from succeeding. They use several response techniques, which involve the IDPS stopping the attack itself, changing the security environment (e.g. reconfiguring a firewall), or changing the attack's content.

Friday, 1 June 2012

EBook - Snort IDS and IPS Toolkit (Jay Beale's Open Source Security)


Snort IDS and IPS Toolkit (Jay Beale's Open Source Security) 
Publisher: Syngress | ISBN: 1597490997 | edition 2007 | PDF | 766 pages | 12,2 mb


This fully integrated book, CD, and Web toolkit covers everything from packet inspection to optimizing Snort for speed to using the most advanced features of Snort to defend even the largest and most congested enterprise networks. Leading Snort experts Brian Caswell, Andrew Baker, and Jay Beale analyze traffic from real attacks to demonstrate the best practices for implementing the most powerful Snort features.

Thursday, 31 May 2012

Design Of A Default Redhat Server 6.2 As Honeypot | HoneyPot Methods


Introduction


The following paper is a description of how I have designed and implemented a honeypot system. The paper describes how the honeypot is used to capture data in layers using different techniques. The aim of the honeypot is to discover the techniques and tactics used by blackhats (hackers) to compromise computer systems. The methods used are similar to the methods used by the Honeynet Project.

Wednesday, 30 May 2012

Ebook-Syngress : Hack the Stack: Using Snort and Ethereal to Master The 8 Layers of An Insecure Network




Hack the Stack: Using Snort and Ethereal to Master The 8 Layers of An Insecure Network
Publisher: Syngress | ISBN: 1597491098 | edition 2007 | PDF | 468 pages | 7 MB

This book looks at network security in a new and refreshing way. It guides readers step-by-step through the "stack" -- the seven layers of a network. Each chapter focuses on one layer of the stack along with the attacks, vulnerabilities, and exploits that can be found at that layer. The book even includes a chapter on the Mythical Eighth Layer: "The people layer".

Thursday, 24 May 2012

What Are Honeypots / Honeynets ? – Fully Explained



What Are Honetpots ?

Just as honey attracts bears, a honeypot is designed to attract hackers. Honeypots have no production value. They are set up specifically for the following purposes:

  • Providing advance warning of a real attack.
  • Tracking the activity and keystrokes of an attacker.
  • Increasing knowledge of how hackers attack systems.
  • Luring the attacker away from the real network.
It is a trap as bears are attracted to honey in the same way a honeypot is designed to attract hackers and black hat people.They are used specifically for the following purposes:

1.Warn about a future attack.
2.Monitoring the activity of an attacker
3.Inorder to know the way of attack used by the attacker.
4.Creating a virtual environment to mislead the attack.
5.It is also very useful in malware analysis.

Friday, 11 May 2012

RFI (Remote File Inclusion) Tutorial For Website Hacking.





What is Remote File Inclusion ?

First of all what is Remote File Inclusion? Commonly referred as RFI, this is an uncommon form of web attack where the attacker can inject their own scripts and execute it on the web server. I like to call RFI the execution of unpredictable and uncontrollable code.

I'm sure many of you who are reading this have attempted RFI and probably are saying that its a simple method of attack. But ill bet that not many know what occurs behind the scene, how it works, and why it works. Today ill clarify that.

Wednesday, 9 May 2012

GFI SandBox - Powerful automated malware analysis



GFI SandBox - Powerful automated malware analysis

GFI SandBox™ (formerly CWSandbox) is an industry leading dynamic malware analysis tool. It gives you the power to analyze virtually any Windows application or file including infected: Office documents, PDFs, malicious URLs, Flash ads and custom applications.Targeted attacks, hacked websites, malicious Office documents, infected email attachments and social engineering are all part of the Internet threat landscape today. Only GFI SandBox™ gives you a complete view of every aspect and element of a threat, from infection vector to payload execution. And GFI SandBox can quickly and intelligently identify malicious behavior using Digital Behavior Traits™ technology.

Monday, 7 May 2012

How To Install Backtrack 5 Dual Boot-Tutorial | Install Backtrack with Windows 7



In this article I will discuss how to make dual boot to use Linux (Backtrack 5) with Windows 7.The overall method of installation is same as discussed before but the step in which you have to mention the partition is change because of dual boot, for this technique it is assume that you have installed windows on your entire disk and you want to make a partition to install backtrack 5 as well, backtrack 5 is not necessary you can use this technique to install any other version and distro of Linux.

Now I am going to show you how to do this, first of all make back up of your windows installer, if you are using USB to boot backtrack than first learn how to make USB click here.

Network Security Scanner - GFI LANguard



GFI LANguard Network Security Scanner (N.S.S.) is a complete network vulnerability management solution that allows you to scan, detect, assess and remediate any security vulnerabilities on your network.

This award-winning solution scans the entire network, performs over 15,000 vulnerability assessments and identifies all possible security threats. The complete and thorough vulnerability assessment database includes standards such as OVAL (2,000+ checks) and SANS Top 20.

Monday, 23 April 2012

Fast Track Hacking-Backtrack5 Tutorial


Backtrack 5 contains different tools for exploitation, as discussed before about metasploit and armitage for this article i will discuss about fast track, however I have received different request to write more tutorial for armitage, i will write for armitage too later. Fast Track is a compilation of custom developed tools that allow penetration testers the ease of advanced penetration techniques in a relatively easy manner.


Some of these tools utilize the Metasploit framework in order to successfully create payloads, exploit systems, or interface within compromised systems.

If you are beginner and dont have any idea about vulnerability, payload and shell code than first read the article " Introduction to metasploit".

Friday, 6 April 2012

How TO Install Backtrack5 in USB Pen Drive | Installation Of BackTrack5 in USB Disk




We must publish this article before but it never too late, how to Install Backtrack5, in my views installation backtrack any version is same but you need to learn it, if you want to do a smart penetration testing so Backtrack5 is a good choice because it contains a necessary tools to do a penetration testing and hacking.


First of all you need to download backtrack5 from it official website click here, backtrack5 is available in different flavours so check your compatibility and download it. For this tutorial we are using a USB device to install backtrack5.

Friday, 30 March 2012

Acunetix Web Vulnerability Scanner Ver 7-20110406 Enterprise Edition - Full Cracked

                                              Acunetix 20110406 Full


Audit your website security with Acunetix Web Vulnerability Scanner
As many as 70% of web sites have vulnerabilities that could lead to the theft of sensitive corporate data such as credit card information and customer lists.
Hackers are concentrating their efforts on web-based applications - shopping carts, forms, login pages, dynamic content, etc. Accessible 24/7 from anywhere in the world, insecure web applications provide easy access to backend corporate databases.

Tuesday, 6 March 2012

Port Scanning-Nmap Tutorial





This is the second episode of a series article about second step of ethical hacking/penetration testing, as we have deeply talked about the importance of port scanning and on the previous article we have discussed some about Nmap.

This article will talk about the practical aspect of Nmap, how to perform a quick scan to know about the open ports and services?

Nmap was originally command line tool that has been developed for only Unix/Linux based operating system but now its windows version is also available and ease to use.You can download the Nmap installer for windows and for Linux open terminal and type 

Thursday, 26 January 2012

CISSP: Certified Information Systems Security Professional Study Guide, 5th Edition - 2011


Description:
Date:2011-01-25 |Language:English|Format:PDF|Size:5.81 MB
Totally updated for 2011, here's the ultimate study guide for the CISSP exam Considered the most desired certification for IT security professionals, the Certified Information Systems Security Professional designation is also a career-booster. This comprehensive study guide covers every aspect of the 2011 exam and the latest revision of the CISSP body of knowledge. It offers advice on how to pass each section of the exam and features expanded coverage of biometrics, auditing and accountability, software security testing, and other key topics. Included is a CD with two full-length, 250-question sample exams to test your progress. CISSP certification identifies the ultimate IT security professional; this complete study guide is fully updated to cover all the objectives of the 2011 CISSP exam Provides in-depth knowledge of access control, application development security, business continuity and disaster recovery planning, cryptography, Information Security governance and risk management, operations security, physical (environmental) security, security architecture and design, and telecommunications and network security Also covers legal and regulatory investigation and compliance Includes two practice exams and challenging review questions on the CD Professionals seeking the CISSP certification will boost their chances of success with CISSP: Certified Information Systems Security Professional Study Guide, 5th Edition.

Wednesday, 18 January 2012

XSS – Cross Site Scripting Attack & Prevention (Basics)


Cross-site scripting is a security vulnerability associated with web applications, where an attacker injects client-side scripting (malicious) code  into server pages which is then served to another users of the web application.  XSS attack is typically focused on

  • cookie hijacking/poisoning.
  • user session hijacking.
  • user identity theft.
  • gaining free access to paid contents.
  • redirecting users to another websites.
  • false advertisements or defamation.

Tuesday, 10 January 2012

Burp Suite- A Web Application Scanner(P.T.)



There are so many tools available for web application testing, and every tools has its own importance either it is commercial tool or it is open source tool. The main agenda of the scanning is to find out the possible vulnerabilities and fix them before a hacker find it and exploit it.

Every pen-tester has their own list of toolkit, and i am sure burp suite is the most common one, burp suite is a most favourite tool for web application testing.


It is an integrated platform for performing security testing of web applications. Its various tools work seamlessly together to support the entire testing process, from initial mapping and analysis of an application's attack surface, through to finding and exploiting security vulnerabilities.