Welcome To suyashjain.blogspot.com

For Latest and more contents visit http://www.i3w.in

Saturday, February 06, 2010

Your PC Performance Test - Free!

ZoneAlarm by Check Point Software Technologies LTD.

  FREE System Scan
IMPROVE PC Performance, Scan Your System for Glitches and Errors, Scan System Now
Continue to Next StepOnce the scan is complete, click the 'Next' button to see the complete diagnostics, along with recommended solutions to make your PC run faster and smoother, while remaining completely secure from viruses, hackers and other threats.

It is our job to secure the Internet with our #1 Firewall, and slow PC performance should not be affected as a result of being secure.

Run the FREE Scan Now
ZoneAlarm's FREE SCAN will warn you of any of these common PC problems, and offer an easy-to-fix solution.


5 Common PC Problems and how ZoneAlarm can Help:


1) Cluttered Registry
2) Too Many Startup Programs
3) Full Hard Drive
4) Limited Memory
5) Spyware & Malicious Programs

©2003–2010 Check Point Software Technologies Ltd. All rights reserved. Check Point, Check Point logo, DefenseNet, IMsecure, OSFirewall, Safe@Office, SmartDefense, SmartDefense Advisor, TrueVector, ZoneAlarm, ZoneAlarm Anti-Spyware, ZoneAlarm Antivirus, ZoneAlarm ForceField, ZoneAlarm Internet Security Suite, ZoneAlarm Pro, ZoneAlarm Secure Wireless Router, Zone Labs, and the Zone Labs logo are trademarks or registered trademarks of Check Point Software Technologies Ltd. or its affiliates. ZoneAlarm is a Check Point Software Technologies, Inc. Company. All other product names mentioned herein are trademarks or registered trademarks of their respective owners. The products described in this document are protected by U.S. Patent No. 5,606,668, 5,835,726, 6,496,935, 6,873,988, and 6,850,943 and may be protected by other U.S. Patents, foreign patents, or pending applications.

Check Point fully supports all efforts to ensure the security, privacy, and peace of mind of everyone on the internet. Our e-mail offers, satisfaction surveys and security communications are sent only to registered users of our software who have expressed an interest in receiving information via e-mail. If you no longer wish to receive e-mails from us, plase use the unsubscribe link below or write to us at: ZoneAlarm; Attn Unsubscribe; 800 Bridge Parkway, Redwood City, CA 94605, USA. To view our privacy policy, click here.



 

This message was sent by ZoneAlarm using Responsys Interact.
Safely unsubscribe from ZoneAlarm e-mail at any time.
View our permission marketing policy.

Wednesday, January 27, 2010

Secureit.in - Multi RBL Check

New Website for Multiple Real Time Black Listing

http://secureit.in/rbl/

--


For More Security Related Stuff visit http://wiki.secureit.in.A Wiki
Website dedicated to Information Security.

Thursday, January 07, 2010

Schools.khazanaplus.com sitemap

http://schools.khazanaplus.com/index.php?City_ID=30&action=Go
http://schools.khazanaplus.com/index.php?City_ID=576&action=Go
http://schools.khazanaplus.com/index.php?City_ID=638&action=Go
http://schools.khazanaplus.com/index.php?City_ID=1&action=Go
http://schools.khazanaplus.com/index.php?City_ID=1&action=Go
http://schools.khazanaplus.com/index.php?City_ID=25&action=Go
http://schools.khazanaplus.com/index.php?City_ID=32&action=Go
http://schools.khazanaplus.com/index.php?City_ID=641&action=Go
http://schools.khazanaplus.com/index.php?City_ID=782&action=Go
http://schools.khazanaplus.com/index.php?City_ID=38&action=Go
http://schools.khazanaplus.com/index.php?City_ID=40&action=Go
http://schools.khazanaplus.com/index.php?City_ID=39&action=Go
http://schools.khazanaplus.com/index.php?City_ID=639&action=Go
http://schools.khazanaplus.com/index.php?City_ID=33&action=Go
http://schools.khazanaplus.com/index.php?City_ID=711&action=Go
http://schools.khazanaplus.com/index.php?City_ID=251&action=Go
http://schools.khazanaplus.com/index.php?City_ID=708&action=Go
http://schools.khazanaplus.com/index.php?City_ID=577&action=Go
http://schools.khazanaplus.com/index.php?City_ID=612&action=Go
http://schools.khazanaplus.com/index.php?City_ID=699&action=Go
http://schools.khazanaplus.com/index.php?City_ID=668&action=Go
http://schools.khazanaplus.com/index.php?City_ID=567&action=Go
http://schools.khazanaplus.com/index.php?City_ID=570&action=Go
http://schools.khazanaplus.com/index.php?City_ID=580&action=Go
http://schools.khazanaplus.com/index.php?City_ID=770&action=Go
http://schools.khazanaplus.com/index.php?City_ID=625&action=Go
http://schools.khazanaplus.com/index.php?City_ID=712&action=Go
http://schools.khazanaplus.com/index.php?City_ID=1&action=Go
http://schools.khazanaplus.com/index.php?City_ID=754&action=Go
http://schools.khazanaplus.com/index.php?City_ID=36&action=Go
http://schools.khazanaplus.com/index.php?City_ID=568&action=Go
http://schools.khazanaplus.com/index.php?City_ID=615&action=Go
http://schools.khazanaplus.com/index.php?City_ID=27&action=Go
http://schools.khazanaplus.com/index.php?City_ID=781&action=Go
http://schools.khazanaplus.com/listbyarea.php?area='3rd block
koramangala'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='4th Block
Koramangala '&city=1
http://schools.khazanaplus.com/listbyarea.php?area='6th Block
Koramangala '&city=1
http://schools.khazanaplus.com/listbyarea.php?area='Arkere Mico
Layout'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='Ayyappa Nagar / K.
R. Puram'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='BEML Layout'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='C. V. Ramana
Nagar'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='C.V. Raman Nagar'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='Doddanakundi'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='HBR Layout'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='Konena Agrahara'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='L. B. Shastri
Nagar'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='Marathahalli'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='Nobo Naga'r&city=1
http://schools.khazanaplus.com/listbyarea.php?area='Rama Murthy
Nagar'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='Sadashiv Nagar'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='Shantinagar'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='Udaya Nagar'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='Vignana Nagar'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='Wilson Garden'&city=1
http://schools.khazanaplus.com/listbyarea.php?area='Yelahanka'&city=1
http://schools.khazanaplus.com/submitschool.php

Schools.khazanaplus.com sitemap

http://schools.khazanaplus.com/index.php?City_ID=30&action=Go
http://schools.khazanaplus.com/index.php?City_ID=576&action=Go
http://schools.khazanaplus.com/index.php?City_ID=638&action=Go
http://schools.khazanaplus.com/index.php?City_ID=1&action=Go
http://schools.khazanaplus.com/index.php?City_ID=1&action=Go
http://schools.khazanaplus.com/index.php?City_ID=25&action=Go
http://schools.khazanaplus.com/index.php?City_ID=32&action=Go
http://schools.khazanaplus.com/index.php?City_ID=641&action=Go
http://schools.khazanaplus.com/index.php?City_ID=782&action=Go
http://schools.khazanaplus.com/index.php?City_ID=38&action=Go
http://schools.khazanaplus.com/index.php?City_ID=40&action=Go
http://schools.khazanaplus.com/index.php?City_ID=39&action=Go
http://schools.khazanaplus.com/index.php?City_ID=639&action=Go
http://schools.khazanaplus.com/index.php?City_ID=33&action=Go
http://schools.khazanaplus.com/index.php?City_ID=711&action=Go
http://schools.khazanaplus.com/index.php?City_ID=251&action=Go
http://schools.khazanaplus.com/index.php?City_ID=708&action=Go
http://schools.khazanaplus.com/index.php?City_ID=577&action=Go
http://schools.khazanaplus.com/index.php?City_ID=612&action=Go
http://schools.khazanaplus.com/index.php?City_ID=699&action=Go
http://schools.khazanaplus.com/index.php?City_ID=668&action=Go
http://schools.khazanaplus.com/index.php?City_ID=567&action=Go
http://schools.khazanaplus.com/index.php?City_ID=570&action=Go
http://schools.khazanaplus.com/index.php?City_ID=580&action=Go
http://schools.khazanaplus.com/index.php?City_ID=770&action=Go
http://schools.khazanaplus.com/index.php?City_ID=625&action=Go
http://schools.khazanaplus.com/index.php?City_ID=712&action=Go
http://schools.khazanaplus.com/index.php?City_ID=1&action=Go
http://schools.khazanaplus.com/index.php?City_ID=754&action=Go
http://schools.khazanaplus.com/index.php?City_ID=36&action=Go
http://schools.khazanaplus.com/index.php?City_ID=568&action=Go
http://schools.khazanaplus.com/index.php?City_ID=615&action=Go
http://schools.khazanaplus.com/index.php?City_ID=27&action=Go
http://schools.khazanaplus.com/index.php?City_ID=781&action=Go
http://schools.khazanaplus.com/listbyarea.php?area=3rd block koramangala&city=1
http://schools.khazanaplus.com/listbyarea.php?area=4th Block Koramangala&city=1
http://schools.khazanaplus.com/listbyarea.php?area=6th Block Koramangala&city=1
http://schools.khazanaplus.com/listbyarea.php?area=Arkere Mico Layout&city=1
http://schools.khazanaplus.com/listbyarea.php?area=Ayyappa Nagar / K. R. Puram&city=1
http://schools.khazanaplus.com/listbyarea.php?area=BEML Layout&city=1
http://schools.khazanaplus.com/listbyarea.php?area=C. V. Ramana Nagar&city=1
http://schools.khazanaplus.com/listbyarea.php?area=C.V. Raman Nagar&city=1
http://schools.khazanaplus.com/listbyarea.php?area=Doddanakundi&city=1
http://schools.khazanaplus.com/listbyarea.php?area=HBR Layout&city=1
http://schools.khazanaplus.com/listbyarea.php?area=Konena Agrahara&city=1
http://schools.khazanaplus.com/listbyarea.php?area=L. B. Shastri Nagar&city=1
http://schools.khazanaplus.com/listbyarea.php?area=Marathahalli&city=1
http://schools.khazanaplus.com/listbyarea.php?area=Nobo Nagar&city=1
http://schools.khazanaplus.com/listbyarea.php?area=Rama Murthy Nagar&city=1
http://schools.khazanaplus.com/listbyarea.php?area=Sadashiv Nagar&city=1
http://schools.khazanaplus.com/listbyarea.php?area=Shantinagar&city=1
http://schools.khazanaplus.com/listbyarea.php?area=Udaya Nagar&city=1
http://schools.khazanaplus.com/listbyarea.php?area=Vignana Nagar&city=1
http://schools.khazanaplus.com/listbyarea.php?area=Wilson Garden&city=1
http://schools.khazanaplus.com/listbyarea.php?area=Yelahanka&city=1
http://schools.khazanaplus.com/submitschool.php

Sunday, January 03, 2010

New Website for Schools in INDIA

Hi,

There is an interesting site for schools in INDIA.

http://schools.khazanaplus.com


Visit the site.
--
For More Security Related Stuff visit http://wiki.secureit.in.A Wiki
Website dedicated to Information Security.

Friday, October 23, 2009

US-CERT Cyber Security Tip ST04-014 -- Avoiding Social Engineering and Phishing Attacks

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cyber Security Tip ST04-014
Avoiding Social Engineering and Phishing Attacks

Do not give sensitive information to anyone unless you are sure that
they
are indeed who they claim to be and that they should have access to the
information.

What is a social engineering attack?

In a social engineering attack, an attacker uses human interaction
(social
skills) to obtain or compromise information about an organization or its
computer systems. An attacker may seem unassuming and respectable,
possibly
claiming to be a new employee, repair person, or researcher and even
offering credentials to support that identity. However, by asking
questions,
he or she may be able to piece together enough information to
infiltrate an
organization's network. If an attacker is not able to gather enough
information from one source, he or she may contact another source
within the
same organization and rely on the information from the first source
to add
to his or her credibility.

What is a phishing attack?

Phishing is a form of social engineering. Phishing attacks use email or
malicious websites to solicit personal information by posing as a
trustworthy organization. For example, an attacker may send email
seemingly
from a reputable credit card company or financial institution that
requests
account information, often suggesting that there is a problem. When
users
respond with the requested information, attackers can use it to gain
access
to the accounts.

Phishing attacks may also appear to come from other types of
organizations,
such as charities. Attackers often take advantage of current events and
certain times of the year, such as
* natural disasters (e.g., Hurricane Katrina, Indonesian tsunami)
* epidemics and health scares (e.g., H1N1)
* economic concerns (e.g., IRS scams)
* major political elections
* holidays

How do you avoid being a victim?

* Be suspicious of unsolicited phone calls, visits, or email
messages from
individuals asking about employees or other internal
information. If an
unknown individual claims to be from a legitimate organization,
try to
verify his or her identity directly with the company.
* Do not provide personal information or information about your
organization, including its structure or networks, unless you are
certain of a person's authority to have the information.
* Do not reveal personal or financial information in email, and do not
respond to email solicitations for this information. This includes
following links sent in email.
* Don't send sensitive information over the Internet before checking a
website's security (see Protecting Your Privacy for more
information).
* Pay attention to the URL of a website. Malicious websites may look
identical to a legitimate site, but the URL may use a variation in
spelling or a different domain (e.g., .com vs. .net).
* If you are unsure whether an email request is legitimate, try to
verify
it by contacting the company directly. Do not use contact
information
provided on a website connected to the request; instead, check
previous
statements for contact information. Information about known phishing
attacks is also available online from groups such as the
Anti-Phishing
Working Group (http://www.antiphishing.org).
* Install and maintain anti-virus software, firewalls, and email
filters
to reduce some of this traffic (see Understanding Firewalls,
Understanding Anti-Virus Software, and Reducing Spam for more
information).
* Take advantage of any anti-phishing features offered by your email
client and web browser.

What do you do if you think you are a victim?

* If you believe you might have revealed sensitive information
about your
organization, report it to the appropriate people within the
organization, including network administrators. They can be
alert for
any suspicious or unusual activity.
* If you believe your financial accounts may be compromised,
contact your
financial institution immediately and close any accounts that
may have
been compromised. Watch for any unexplainable charges to your
account.
* Immediately change any passwords you might have revealed. If you
used
the same password for multiple resources, make sure to change it for
each account, and do not use that password in the future.
* Watch for other signs of identity theft (see Preventing and
Responding
to Identity Theft for more information).
* Consider reporting the attack to the police, and file a report
with the
Federal Trade Commission (http://www.ftc.gov/).
_________________________________________________________________

Author: Mindi McDowell
_________________________________________________________________

Produced 2004 by US-CERT, a government organization.

Note: This tip was previously published and is being
re-distributed to increase awareness.

Terms of use

http://www.us-cert.gov/legal.html

This document can also be found at

http://www.us-cert.gov/cas/tips/ST04-014.html

For instructions on subscribing to or unsubscribing from this
mailing list, visit
http://www.us-cert.gov/cas/signup.html.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEVAwUBSuCQUducaIvSvh1ZAQKBWAgAtK4p2dlCr/c+WlfO/t0WnYGXGmOaoXVl
lZTizFdd+vrxPTx5Y//QXMMG8y55mnf34xc2BBOEULTegfDzIrcDa89OCiujeua7
wYHLSCw7eBljl81WR4E1C5xRPB8mI/Jq+p5QwKvLveuAyyeHQXwIo/QrP6YsvQRX
PV/PWE5GMDCWsMojt9UV+JzAl057fBgo5JiruwpsRNowm42RkGawTjNw5EDiK8zm
yfAfD8WUoDQGXabb2mh0g+z7lrzpf74DpgBOgQ81jk94oCvho+D6Xpa4R5sBlMi9
vTjXiR1Jrr2bNCYVg5p8rqjua/eEC4NKVVTbK9z0nT4qy1FCE3vY+g==
=sAm5
-----END PGP SIGNATURE-----


--
For More Security Related Stuff visit http://wiki.secureit.in.A Wiki
Website dedicated to Information Security.

Friday, July 24, 2009

SSH Access Without Password

Latest Versioon of this blog can be obtained from http://wiki.secureit.in/


There are certain situations where you do not want to use password while doing ssh to remote machine.(i.e) running some script which uses ssh to access remote machine.

This can be achieved by generating public/private key.

Example:

"Local Host" is the machine from where we want to access "Remote Machine" by using ssh.

Step1.

Run the following command on "Local Host"


ssh-keygen -t rsa 
        ssh-keygen -t rsa   
Generating public/private rsa key pair.
Enter file in which to save the key (/root/.ssh/id_rsa): <press enter>
Enter passphrase (empty for no passphrase): <press enter>
Enter same passphrase again: <press enter>
Your identification has been saved in /root/.ssh/id_rsa.
Your public key has been saved in /root/.ssh/id_rsa.pub.
The key fingerprint is:
03:78:2e:2c:1f:1a:41:f3:43:6d:7f:47:18:4b:c7:da root@localhost.localdomain


This command will generate public and private key files.

Private Key File : ~/.ssh/id_rsa

Public Key File: ~/.ssh/id_rsa.pub


Create ~/.ssh directory, id does not exist.


This is only what we have to do on "Local Host"


Now copy the content of Public key file(~/.ssh/id_rsa.pub) to Remoote host file ~/.ssh/authorized_keys


if the file and directory does not exist , create it.

That's all... now run the ssh command from local host to remote host.


Sample Public Key Content:

ssh-rsa AAAB3NzaC1yc2EAAAABIwAAAIEAxw2859hwrHT8t2m7LQQAsWNXEo8hBGtCdOcB8qofrMMoNcvyXScQjBMq3sSu8FIGozBeF1vMC4oCOlizx4qK F7oshMV/9SuMCSMwj5S5bFe8uYicuBplkKIU+2a4Ijk6d/w3ynyXtVLAfsoYUQ2TxG0DX8pt8DGGcckzCjqhTlc= root@localhost.localdomain


Saturday, March 07, 2009

wiki.secureit.in

Main Page

From SecureIT Wiki

Jump to: navigation, search
Welcome to SecureIT Wiki
  • One Source to get all unique information about Linux and Security.
  • Here we have tried to provide the documents about Linux,Information Security,Cisco Devices security and Other security related products which are rarely available or expired.
  • Documentation on Firewall, IDS, Sniffer, HIDS, Web Servers, Security certificates, Security Books, Hacking, Various Linux Distribution, Linux Commands, tools, tips etc.
  • For Windows, we have only security related documents.

Anti Virus

ClamAV, Avast(Win), SpywareTerminator(Win)

IDS / IPS / HIPS

Ossec

VPN / Encryption

OpenVPN,

Firewall

Pix, Firestarter

Network Monitoring / Sniffer / Packet Analyzer / Packet Sniffer

Ntop, nmap, Bigboos, Nessus, p0f, ehnt

Simulators / NetSim

Dynamips/dynagen

Linux Servers Distributions

Linux Security Distributions

Adios, backtrack, ophcrack

Scripts
Secure Server Implementation
Books

PDF/CHM Links




Your contribution is valuable , kindly provide the documents at wiki@secureit.in

Monday, December 22, 2008

Cacti & iptables

#!/usr/bin/perl # # This is a quick perl script to  # pull bandwidth usage from iptables chains # # If you use/optimize this script, please let me know. # Brian Stanback : brian [at] stanback [dot] net  # Example iptables rule for web bandwidth usage: # > iptables -N WWW # > iptables -A WWW -j ACCEPT # > iptables -A INPUT -p tcp -m tcp --dport 80 -j WWW # > iptables -A OUTPUT -p tcp -m tcp --sport 80 -j WWW # # Run "iptables.pl WWW" as root to test, note that you can  # combine more than one protocol into a single chain. # # Sudo Configuration (/etc/sudoers) # > www-data    ALL = NOPASSWD: /usr/share/cacti/scripts/iptables.pl # # The Input String should be set to "sudo <path_cacti>/scripts/iptables.pl <chain>" # and you will need to setup an input field so that the <chain> argument can be passwd. # # The data input type should be set to COUNTER #  if ($ARGV[0]) {         $chains = `/sbin/iptables -xnvL | grep -A 2 'Chain $ARGV[0]'`;         @chains = split(/\n/, $chains);         $chains[2] =~ /[\W+]?[0-9]+\W+([0-9]+)\W+/;         print $1; } else {         print "Usage: $0 Chain\n"; } 
 
http://rodotelmi.rebstech.com/2008/06/30/cacti-with-iptablesipfw-traffic-monitoring/
 
 

Monday, December 15, 2008

Ossec - What Exactly it is

Ossec - Open Source Host Intrusion Detection System

Thursday, December 11, 2008

Hiding the apache Identity

To hide the version and other information of apache server which can be
retrieved through header of an request,
put the following lines in your apache httpd.conf file.


RewriteEngine On
RewriteCond %{REQUEST_METHOD} ^TRACE
RewriteRule .* - [F]
ServerSignature off
ServerTokens Prod

Through these lines you are hiding the signature of apache and the
header will only display 'Apache'.

How to Block Torrent in Network

Torrent works based on the seeds and peers (the other computer which connects to your client application to send or receive the files) .

The seeds and peers  information to your client is provided by the torrent tracker server, which is mentioned in the  .torrent file downloaded by you from some torrent site.

Your Torrent client will read the .torrent file and connect with the torrent tracker server on 6881-7000/tcp or 2710/tcp port through http protocol and torrent tracker server will provide all the other client computer which are currently connected and having the full file or partial file which yuo want to download.

Than your client application(torrent client) will connect to those other client machines(torrent client applications) and starting transferring the data.

To block the torrent in your network , you can take the following two actions.

1. Do not allow "NEW" incoming packets in your network.

2. Block 6881-7000/tcp and 2710/tcp ports for outgoing so that your client application(torrent client) could not  connect the tracker server and get the information about other systems.

If your client(torrent application) will not get the information about other systems in world , it will not be able to download the files.

This is want you want to do.....

Cheer Up !!

Your comments and experience are most welcome.

Friday, October 17, 2008

Cacti Password Hacking

I have found one password hacking trick which can be used for cacti to
change any user password including admin.

http://xxx.xxx.xxx.xxx/auth_changepassword.php?ref=index.php&action=changepassword&username=admin&password=aaaaaa&confirm=aaaaaa&submit=Save

xxx.xxx.xxx.xxx - ip of cacti server.


This url will provide option to change the password of admin user. if
the same is happening with your cacti also kindly block
auth_changepassword.php file from accessing through web.

Friday, October 10, 2008

BIOS Blaster and Capture Utilities

 11th Alliance toolkit  =>    Another toolkit containing utilities needed to gain access to a wide range  of BIOS passwords. Download it from  http://www.wheres.com/etc/FatherQuinn/bios310.zip.
 AMIDECOD    =>        This utility will decode BIOS passwords on American Megatrends systems. Get it at http://www.outpost9.com/files/crackers.html.
 AMI Password Viewer   =>      This utility from KORT reads, decrypts, and displays AMI BIOS passwords. Get it at http://www.rat.pp.se/hotel/panik/archive/skw-ami.zip.
  AW.COM     =>   This utility by Falcon n Alex cracks Award BIOS passwords. Get it at http://www.lls.se/~oscar/files/pwd/aw.zip.
  CmosPwd     =>  CmosPwd can retrieve BIOS passwords from many popular computers,including IBM, Compaq, Packard Bell, and Gateway. Download it at   http://www.esiea.fr/public_html/Christophe.GRENIER/index.html?cmospwd.html.
  Kill CMOS   => If a user-defined password already exists on a computer, resetting the CMOS to its default state will erase that password. A utility to do this can be downloaded from http://www.AntiOnline.com/archives/anticode/bios-crackers/killcmos.zip.

Wednesday, October 01, 2008

Ethical Hacking - Footprinting - SmartWhois

SmartWhois is a windows based GUI version of Whois. It is an
information-gathering program that allows you to find all available
information about an IP address, host name, or domain, including
country, state or province, city,name of the network provider,
administrator, and technical-support contact information.

You can get it from here.

http://www.tamos.com/products/smartwhois/

Ethical Hacking - FootPrinting - Sam Spade

Sam Spade is windows based GUI tool which provide all in one interface for Foot Printing. It includes Ping, DNS, Whois, IP Block info, Dig, Traceroute etc

· Each tool displays it's output in it's own window, and everything is multi-threaded so you don't need to wait for one query to complete before starting the next one
· Some functions are threaded still further to allow lazy reverse DNS lookups (never do a traceroute -n again)
· The output from each query is hotlinked, so you can right click on an email address, IP address, hostname or internic tag to run another query on it
· Appending the results of a query to the log window is a single button function
· There's a lot of online help, in both WinHelp and HTMLHelp formats. This includes tutorials, background information and links to online resources as well as the program manual itself


You can download it from the following location.

http://www.softpedia.com/get/Network-Tools/Network-Tools-Suites/Sam-Spade.shtml

Ethical Hacking - Foorprinting - Traceroute

traceroute is a command which is available in all OS.

If you the ip domain/ip address of organization , you can trace the gateway devices and ISP details.

Example:

Tracing route to yahoo.com [68.180.206.184]...

hop rtt rtt rtt   ip address domain name
1 8 1 0   70.84.211.97 61.d3.5446.static.theplanet.com
2 0 0 0   70.84.160.162 vl2.dsr02.dllstx5.theplanet.com
3 0 0 0   70.85.127.109 po52.dsr02.dllstx3.theplanet.com
4 0 0 0   70.87.253.21 et3-1.ibr03.dllstx3.theplanet.com
5 0 0 0   70.87.253.178 b2.fd.5746.static.theplanet.com
6 23 21 22   216.115.96.58 so-4-0-0.pat2.dnx.yahoo.com
7 49 49 63   216.115.101.128 as0.pat1.pao.yahoo.com
8 48 47 47   216.115.101.33 ae2.pat2.pao.yahoo.com
9 49 48 48   216.115.107.51 ae0-p141.msr1.sp1.yahoo.com
10 49 48 49   209.131.32.23 te-9-1.bas-a1.sp1.yahoo.com
11 47 47 48   68.180.206.184 w2.rc.vip.sp1.yahoo.com

Trace complete.

Traceroute.org is one of the fantastic site from where you can perform the traceroute through various part of world.

Ethical Hacking - FootPrinting - DIG

Dig is a linux command which is similor to nslookup command. It also comes under DNS enumeration.

Example:

dig yahoo.com

; <<>> DiG 9.3.3rc2 <<>> yahoo.com

;; global options: printcmd

;; Got answer:

;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 39856

;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 7, ADDITIONAL: 7


;; QUESTION SECTION:

;yahoo.com. IN A


;; ANSWER SECTION:

yahoo.com. 359 IN A 68.180.206.184

yahoo.com. 359 IN A 206.190.60.37


;; AUTHORITY SECTION:

yahoo.com. 52791 IN NS ns4.yahoo.com.

yahoo.com. 52791 IN NS ns5.yahoo.com.

yahoo.com. 52791 IN NS ns6.yahoo.com.

yahoo.com. 52791 IN NS ns8.yahoo.com.

yahoo.com. 52791 IN NS ns1.yahoo.com.

yahoo.com. 52791 IN NS ns2.yahoo.com.

yahoo.com. 52791 IN NS ns3.yahoo.com.


;; ADDITIONAL SECTION:

ns1.yahoo.com. 52959 IN A 66.218.71.63

ns2.yahoo.com. 52959 IN A 68.142.255.16

ns3.yahoo.com. 52959 IN A 217.12.4.104

ns4.yahoo.com. 52959 IN A 68.142.196.63

ns5.yahoo.com. 66635 IN A 119.160.247.124

ns6.yahoo.com. 17127 IN A 202.43.223.170

ns8.yahoo.com. 52790 IN A 202.165.104.22


;; Query time: 2 msec

;; SERVER: 202.71.152.65#53(202.71.152.65)

;; WHEN: Tue Sep 30 19:38:35 2008

;; MSG SIZE rcvd: 297


Different Types of DNS Records

The following list describes the common DNS record types and their use:

A (address)—Maps a host name to an IP address

SOA (Start of Authority)—Identifies the DNS server responsible for the domain information

CNAME (canonical name)—Provides additional names or aliases for the address record

MX (mail exchange)—Identifies the mail server for the domain

SRV (service)—Identifies services such as directory services

PTR (pointer)—Maps IP addresses to host names

NS (name server)—Identifies other name servers for the domain

Ethical Hacking - Footprinting - NSLOOKUP

nslookup is one of the fantastis tool through which dns enumeration can be performed.

It can provides the following informations.


  1. Ip addresses

  2. Domain names

  3. Sub domain names or computer names

  4. Mail Servers

  5. DNS Server


Sample Output

# nslookup

> set type=mx

> google.com

Server: x.x.x.x

Address: x.x.x.x#53


Non-authoritative answer:

google.com mail exchanger = 10 smtp3.google.com.

google.com mail exchanger = 10 smtp4.google.com.

google.com mail exchanger = 10 smtp1.google.com.

google.com mail exchanger = 10 smtp2.google.com.


Authoritative answers can be found from:

google.com nameserver = ns1.google.com.

google.com nameserver = ns2.google.com.

google.com nameserver = ns3.google.com.

google.com nameserver = ns4.google.com.

ns1.google.com internet address = 216.239.32.10

ns2.google.com internet address = 216.239.34.10

ns3.google.com internet address = 216.239.36.10

ns4.google.com internet address = 216.239.38.10

> exit


online nslookup is also available.

networking.ringofsaturn.com/Tools/nslookup.php

centralops.net/
www.nexperts.org/onlinenslookup.aspx
www.subnetonline.com/pages/network-tools/online-nslookup.php
enc.com.au/itools/nslookup.php

Ethical Hacking - FootPrinting - Host

Linux host command can also be used to provide a lot of information about domain.

Example:

host yahoo.com

yahoo.com has address 68.180.206.184

yahoo.com has address 206.190.60.37

yahoo.com mail is handled by 1 c.mx.mail.yahoo.com.

yahoo.com mail is handled by 1 d.mx.mail.yahoo.com.

yahoo.com mail is handled by 1 e.mx.mail.yahoo.com.

yahoo.com mail is handled by 1 f.mx.mail.yahoo.com.

yahoo.com mail is handled by 1 g.mx.mail.yahoo.com.

yahoo.com mail is handled by 1 a.mx.mail.yahoo.com.

yahoo.com mail is handled by 1 b.mx.mail.yahoo.com.