Support The Ethical Hacker !! - Click Here If You Like My Contents !!!

Tuesday, November 24, 2009

E-mail Forging- Sending spoofed mails

Email spoofing is the art of sending spoofed mails to the target in order to create chaos on the other end.Many criminals make use of this technology to send spoofed mails.This allows the attacker to send the E-mail from the victim's mail account without knowing his or her passwords.

Even these days we can find many vulnerable servers connected to the internet which allows unauthenticated access to its smtp ports.This allows the attacker to send spoofed mails.

The general methodology for sending spoofed mails, using telnet is described below. We can use the same method to send spoofed mails after knowing the vulnerable server.

start > run >cmd telnet 25
help
helo < domain name>
mail from : < sender's mail address>
rcpt to : < victim's mail address>

data
< message>


Countermeasures:
Always use a secure E-mail system like "Pretty Good Privacy"( PGP) for sending mails.
Digitally sign the E-mail's.
DO NOT do transactions blindly believing the E-mail service.
The most important aspect is the awareness of the user that nothing  can be done effectively against E-mail spoofing

Some Eg sites which will allow you to do Email Spoofing:

funmaza- funmailer
link 2

TIPS:
The links I provide is purely for educational purposes.

Even though you send spoofed emails it is easy to track the IP of the person sending the mails. Be Aware of that.

Create Disposable Email ID :To create a disposable email address to protect your privacy online. If you need to give someone your email address, or need to sign up to a website which requires an email address, but you don't wish to reveal your identity then use this free service for receiving emails. Simply signup instantly, give them the disposable email address and you'll be able to read every email they send in complete privacy. ( use it at your own risk) click here to get one.

SIXTH SENSE- Nothing to do with hacking






















All courtesy to TED.com.At TEDIndia, Pranav Mistry demos several tools that help the physical world interact with the world of data -- including a deep look at his SixthSense device and a new, paradigm-shifting paper "laptop".

In an onstage Q&A, Mistry says he'll open-source the software behind SixthSense, to open its possibilities to all.

Wednesday, November 18, 2009

DOWNLOAD ALL THE IMPORTANT TOOLS

Some ready to use tools are available in the internet.I'll be naming them and the providing the links for the downloading it.I know that the best practice is to create your own tools for the hacking.But for the beginners this thread will give a kick start in hacking.

NB: Some links may not work . So you may report it and post the new links in the comments.I'm not listing all the best tools here.You can help this blog with your contributions too.

Email Header Finger Printing

When we send an Email, the SMTP server creates a header.Study of the Mail server name reveals the OS of the server. For all this ,we have to analyze the Email Header first. The email header reveals a lot of other sensitive information about the sender including his IP.We will discuss more on this topic on other posts.
Countermeasures :
Change the mail daemon settings 

A sample Email header is shown below :


Delivered-To:XXX @gmail.com
Received: by 10.142.100.4 with SMTP id x4cs39161wfb;
        Tue, 17 Nov 2009 22:37:56 -0800 (PST)
Received: by 10.90.17.29 with SMTP id 29mr1540839agq.79.1258526174775;
        Tue, 17 Nov 2009 22:36:14 -0800 (PST)
Return-Path: 
Received: from mail15-a-ac.linkedin.com (mail15-a-ac.linkedin.com [208.111.169.137])
        by mx.google.com with ESMTP id 30si16545010iwn.121.2009.11.17.22.36.13;
        Tue, 17 Nov 2009 22:36:13 -0800 (PST)
Received-SPF: pass (google.com: domain of s-qKShvR1E_bKJbE3KpcihvgYpqS5pjeiVFRKjniEn-5Sp4jYEI5tJj_@bounce.linkedin.com designates 208.111.169.137 as permitted sender) client-ip=208.111.169.137;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of s-qKShvR1E_bKJbE3KpcihvgYpqS5pjeiVFRKjniEn-5Sp4jYEI5tJj_@bounce.linkedin.com designates 208.111.169.137 as permitted sender) smtp.mail=s-qKShvR1E_bKJbE3KpcihvgYpqS5pjeiVFRKjniEn-5Sp4jYEI5tJj_@bounce.linkedin.com; dkim=pass header.i=communication@linkedin.com
DomainKey-Signature: s=prod; d=linkedin.com; c=nofws; q=dns;
  h=Sender:Date:From:To:Message-ID:Subject:MIME-Version:
   Content-Type:X-LinkedIn-fbl;
  b=LAlAw9S8qrGPLt6phtZNvQ37jeg3yvtYlApfNHApbwizFBIvNvk2D1H6
   r7PxLyDTGK5YmRBn84TgBPD5FB0gt90r9Khp4TnNFIHyM3Sy64uMytmRj
   N4agg6dfvT5H2mO;
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple;
  d=linkedin.com; i=communication@linkedin.com; q=dns/txt;
  s=proddkim; t=1258526173; x=1290062173;
  h=from:sender:reply-to:subject:date:message-id:to:cc:
   mime-version:content-transfer-encoding:content-id:
   content-description:resent-date:resent-from:resent-sender:
   resent-to:resent-cc:resent-message-id:in-reply-to:
   references:list-id:list-help:list-unsubscribe:
   list-subscribe:list-post:list-owner:list-archive;
  z=From:=20LinkedIn=20Communication=20
   in.com>|Sender:=20messages-noreply@bounce.linkedin.com
   |Subject:=20LinkedIn=20Messages,=2011/17/2009|Date:=20Tue
   ,=2017=20Nov=202009=2022:36:03=20-0800=20(PST)
   |Message-ID:=20<2138821644.368566.1258526163419.JavaMail.
   app@ech3-cdn09.prod>|To:=20"Mr.Swaroop=20Krishnan=20S"=20
   |MIME-Version:=201.0;
  bh=HFHniqCRWqBOKiU6PXUVuudYIJ3jsx+QLmyfTd3eFzU=;
  b=SDfsYwsz/HCedRw3aFZ2JkOkKrLzzK2R1gVWv2WDNXhKtr2kM0ioAlZi
   m230bpQm4ZzCi2fwM2yyYbY8GauwKPZav6r23wyGA4hTBwHKLheSmXFI5
   /+urlA2oJGJPlWR;
Sender: messages-noreply@bounce.linkedin.com
Date: Tue, 17 Nov 2009 22:36:03 -0800 (PST)
From: LinkedIn Communication 
To: "Mr.Swaroop Krishnan S" 
Message-ID: <2138821644.368566.1258526163419.JavaMail.app@ech3-cdn09.prod>
Subject: LinkedIn Messages, 11/17/2009
MIME-Version: 1.0
Content-Type: multipart/alternative; 
 boundary="----=_Part_368565_1338859.1258526163416"
X-LinkedIn-fbl: qKShvR1E_bKJbE3KpcihvgYpqS5pjeiVFRKjniEn-5Sp4jYEI5tJj_

------=_Part_368565_1338859.1258526163416
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit

Advanced OS Detection Methods

Active detection methods need sending of malformed packets to host and analyzing of their responses.But these are easily detected and filtering is also easy by ACL and firewalls.
Thus in this new method regular packets are send to the host to generate the responses.The request may be like the request to a web page or file.
This fools the firewall and ACL rules.The packet causes some ICMP error message.This is non detectable.This may pass through the firewall easily as this is similar to normal traffic.
The outgoing ICMP message is allowed and this is studied to detect the OS.

The Main thing : No system admin can disable the Outgoing ICMP error messages.However he can block certain selected messages.This is studied to pin point the OS.

OS Fingerprinting -Finding Remote Host's OS

 It is very important for an attacker to know about the OS of the target.Different OS's have different stacks and kernels.The response to same message is different in different OS's so by analyzing these messages we can know about the OS in the host.Attacker sends packets made using the packet generation softwares and the target is forced to respond to it.Thus OS finger printing is done.

The techniques used for this purpose can be classified in to 2 types namely :

1) Active finger printing
2) Passive finger printing

Active fingerprinting :
steps:
A customized data packet is send to the target host.
The response generated is recorded using  the packet sniffer.
The recorded response is studied and compared to known responses and OS is identified.

Fators helping us to identify the OS :

TCP initial window size of the packets.
ACK values of the packets.
Initial Sequence Number(ISN)  values
Heading of overlapped fragments.
ICMP Message quoting method
ICMP Error Message quenching method
ICMP Error Message Echoing integrity

Problem:
The attacker will have to send the packets actively to the target and record its responses.
This method is not anonymous.So it may have tha attacker caught in the act.

That is why we go for Passive Fingerprinting.

TOOLS for active finger printing :

Nmap
Quso
Aping


Passive Fingerprinting :
This method is  anonymous. It is very difficult to identify passive fingerprinting.

The main steps in this method are as  follows :
The attacker uses a sniffer to record the data packets sent by the target.
The various parts of the response is analyzed for particular values which are specific for a particular OS.
Thus the OS of host is found out.The attacker may install the sniffer in a cafe and analyze the packets recieved while someone connects to the same computer.

The main fields studied in the passive method are:
TTL value
The window size
Don't fragment bit
Type of source (TOS)

 Consider the example :
When we recieve a
windows size =9000
TOS =0
DFB =yes
then the host must be running a Win9X or Win NT

Countermeasures:

Change the default values of the parameters studied.
Mislead the attacker by giving values of another OS.
Use ACL for filtering.

Detecting Firewalls Using Port Scanning

We can detect or even guess the firewalls used in the target because of the unique ports they use.
for Eg:
CheckPoint listens on the TCP ports 256,257,258,259
Microsoft proxy Server listens to TCP ports 1080 to 1745

Easiest solution to firewall enumeration is to use an ACL (Access Control List)

access-list 101 deny tcp any any eq  256 log ( here 256 is the port number on which the firewall is running)

What is the meaning of above code..?
This code prevents all port scanning techniques on the port 256 and also logs and records it which can be viewed later by the admin.

TOOLS:

scanlogd- An IDS that detects TCP scan
BlackICE Defender -Firewall detecting port scans
Abacus Port Sentry -This is a very good tool.It detects port scans and responds to it.
NukeNabber
snort -IDS and Packet sniffer
Etherpeek