lowongan kerja di rumah
Tampilkan postingan dengan label tutorial (english). Tampilkan semua postingan
Tampilkan postingan dengan label tutorial (english). Tampilkan semua postingan
.
.
.
What you will need:

1. current version of Cain from www.oxid.it

2. Windows 2000 or Windows XPSP1 configured workstation

Getting started:

Cain is an easy application to install and configure. However, there are several powerful tools that should only be configured after you fully understand both the capabilities and consequences to the application and the target network. After all, you can’t very well hack a network if you take it down. Proceed with caution.



Referring back to chapter two, you will need to know what you are trying to hack. This appendix assumes that you are trying to get the administrator’s username and password for the network. The focus of this appendix is on obtaining that information. The other appendices in this chapter deal with other capabilities of the application to gain access to a network. To this end we need to accomplish the following steps to get the admin account:



1. Enumerate the computers on the network

2. connect to a computer and install the Abel remote app

3. Harvest user account information

4. Crack user account information passwords to get the admin account

5. Login to the target machine with the admin account

6. Install the Abel service on the target server

7. Harvest all of the hashes from a server and sent to the cracker



Once we have the admin account on the server, the rest is up to you.



First things first, after you launch the application you will need configure the Sniffer to use the appropriate network card. If you have multiple network cards, it might be useful to know what your MAC address is for your primary connection or the one that you will be using for Cain network access. You can determine your MAC address by performing the following steps:

1. Go to “Start”

2. Run

3. enter the “CMD”

4. A black window will appear

5. Enter the following information into the window without the quotes

“Ipconfig /all” and then Enter

6. Determine which one of the Ethernet adapters you are using and copy the MAC address to notepad. You use this to help determine which NIC to select in the Cain application



With the Cain application open, select the Configure menu option on the main menu bar at the top of the application. The Configuration Dialog box will appear. From the list select the device with the MAC Address of Ethernet or Wireless network card that you will be using for hacking. While we are here, let’s review some of the other tabs and information in the Configuration Dialog Box. Here is a brief description of each tab and its configuration:



1. Sniffer Tab: allows the user to specify the Ethernet interface and the start up options for the sniffer and ARP features of the application.

2. ARP Tab: Allows the user to in effect to lie to the network and tell all of the other hosts that your IP is actually that of a more important host on the network like a server or router. This feature is useful in that you can impersonate the other device and have all traffic for that device “routed” to you workstation. Keep in mind that servers and routers and designed for multiple high capacity connections. If the device that you are operating from can not keep up with traffic generated by this configuration, the target network will slow down and even come to a halt. This will surly lead to your detection and eventual demise as a hacker as the event is easily detected and tracked with the right equipment.

3. Filters and Ports: Most standard services on a network operate on predefined ports. These ports are defined under this tab. If you right click on one of the services you will be able to change both the TCP and UDP ports. But this will not be necessary for this tutorial, but will be useful future tutorials.

4. HTTP Fields: Several features of the application such as the LSA Secrets dumper, HTTP Sniffer and ARP-HTTPS will parse the sniffed or stored information from web pages viewed. Simply put, the more fields that you add to the HTTP and passwords field, the more likely you are to capture a relevant string from an HTTP or HTTPS transaction.

5. Traceroute: It is what it is, trace route or the ability to determine the path that your data will take from point A to point B. Cain adds some functionality to the GUI by allowing for hostname resolution, Net mask resolution, and Whois information gathering. This feature is key in determining the proper or available devices to spoof or siphon on your LAN or internetwork.



Ok, So now you have everything all set and you are ready to rumble, as it were. Now, after I select the adapter on the sniffer tab, I generally set the sniffer to start on start up and then select apply. Do not enable the arp poisioning at this point, you will not need it and if this is your first exposure to Cain and or hacking, you will just get yourself caught with the ARP stuff. I generally stop and start the application at this point to get a clean start and reload the application with my intended settings.



So, launch the app and make sure that the first icon on the Left that looks like a miniature Ethernet card appears depressed. This indicates that the sniffer is activated. At this point, it is time to get a cup of coffee and let the app just sit. Yep, that is right, just leave it running and don’t touch anything. The reason for this is that not every device is talking all of the time and some protocols only talk on specific intervals. You will need to wait at least 300 seconds to ensure that the Cain sniffer has heard from each protocol at least once. This is most germane to routing protocols, but I have seen it take this long or longer to see all of the hosts on a LAN.



NOTE: The next section makes the assumption that you have properly configured your Ethernet interface with an IP address that is correct for your network and that you have logical connectivity to the target hosts.



At this point you are asking your self “Are we ever going to start hacking…?”



Let’s hack then. Go to the network tab and double click on the Microsoft windows network under the Entire Network navigation tree. After a few moments, the tree will expand and show each of the workgroups and domains that are accessible to your network card. From here select your target network and click the “+” symbol to the Left to open the tree.



Understanding that servers generally, or are supposed to, have more security than the other devices on the network, it is generally better to go for a workstation over a server out of the gate. Also, some servers will have monitoring agents on then that could detect what is going to happen next.



Double click on the All Computers object in the tree under the target network section of the tree. Now look at the names of the all of the devices listed. Many times the administrator will name the servers with some naming convention that will single them out in not time flat. Try to use the naming convention to your advantage and look for a pc that potentially is used by multiple persons. Key giveaways are names like scanner1, or receptionist, or lab. These machines will have several accounts on them and one of them is likely to have an admin account on it. These machines are key targets for two reasons. One, they are generally set up in a hurry when the company first sets up the network during a time when security is an afterthought, and as such they are likely to have default configurations for the local admin. Secondly, they generally have several apps on then and lots of people use them. With multiple applications, excessive rights are often granted to all users to ensure that every one can use the app that they need. Anyway, back to the hack….



When you click on your target, you will see 4 new objects in the tree under your target. These will be Groups, Services, Shares, and users. “Users” is what you want first. Double click on the users object icon and select yes to start the user enumeration. Caution! – Do not go for the history information at this time, we will get to that later. After all of the user accounts are enumerated they will be listed in alphabetical order and the local administrator will have a large red A in front of it. Ok, here we go. Go back to the computer object of the computer that you just enumerated and right click on the object. Select the connect as option. Just for fun, if the administrator account has not been renamed, it is likely that it will have a blank password or be something fairly simple. Try to log in with the user account administrator and a blank password. In about 70% of my experience at this point, the hack is over for the local machine and you are in and can start playing. If it did work, then right click on the “Services” object for the device that you have just logged into and select Install Abel. Cain will install Abel.exe and Abel.dll into the %systemroot% on the local machine. Collapse the computer object and then re-expand it by double clicking on the computer object icon and you should see a Black square with a Blue A in the middle directly under the computer object in the tree. (I get excited just thinking about it). At this point you have the keys to the castle, you just need to see which key goes where. First lets get the hashes and get the ready to crack. Double click on the users object in the tree. Say no to the history pop up for now. Select all of your users by right clicking on an account and selecting “Send all to cracker.” Leave them for now, we will come back to them. What you have just done is load a portion of the application with all of the NT and NTLM hashes for every account on the target PC.



Now, if you have been following the book, you will remember the endless posts on hackerthreads that talked about using the command line to get at certain directories on a target machine, well here is where they will come into play. (If you are not too familiar with the cmd line, please refer to the Glossary of this book and review the command line hacking section. There are many useful tools like adding users and computers to domain security groups.



Let’s go over our options:



Console: This is the command prompt on the remote machine. Anything that you can do on your pc from the CMD prompt can be done from here. Examples include mapping a drive back to your pc and copying all the files from the target or its mapped drives to your machine for later data mining, adding local users to the local security groups or anything really. With windows, everything is possible from the command prompt.



Hashes: Allows for the enumeration of user accounts and their associated hashes with further ability to send all harvested information to the cracker.



LSA Secrets: Windows NT and Windows 2000 support cached logon accounts. The operating system default is to cache (store locally), the last 10 passwords. There are registry settings to turn this feature off or restrict the number of accounts cached. RAS DUN account names and passwords are stored in the registry. Service account passwords are stored in the registry. The password for the computers secret account used to communicate in domain access is stored in the registry. FTP passwords are stored in the registry. All these secrets are stored in the following registry key: HKEY_LOCAL_MACHINE \SECURITY\Policy\Secrets





Routes: From this object, you can determine all of the networks that this device is aware of. This can be powerful if the device is multihommed on two different networks, but you read about all of that in chapter 5 – Heard, but Not Seen, Right?



TCP Table: A simple listing of all of the processes and ports that are running and their TCP session status.



UDP Table: A simple listing of all of the processes and ports that are running and their UDP session status.





Ok, back to the hack, for those of you that did not get in with the admin account with no password, another trick is to try to login to each account in the list with the same password as the username. For example, right click on the computer object in the tree and try to login with on of the user account names and use the username as the password. If that does not work then try each one with no password. I have only run into one network where these two things did not work. Also, the LSA Secrets tree object will dump the following user accounts in plain text for you if they are present:



$Machine Account

Aspnet_WP_PASSWORD

L$******************** (this is the currently logged on user with the password)

L$******************** (this will be every user that has logged in up to the total number of cached logons.

RASDAILPARAMERTERS (these are present if RAS is configured and has been used)

Backup user accounts

Misc other accounts

Note: when you see the account in plain text, it will have separators. When you type the password into a logon, omit the extra “.”. ie. The password Ramius!@# will show up as R.a.m.i.u.s.!.@.#.... All that you will type the Ramius!@#.



OK, so far we have accomplished the following goals:



1. Enumerate the computers on the network

2. connect to a computer and install the Abel remote app

3. Harvest user account information



We still need to finish the hack by performing the following steps and then move the hack to a server or more valuable target.



1. Crack user account information passwords to get the admin account

2. Login to the target machine with the admin account

3. Install the Abel service on the target server

4. Harvest all of the hashes from a server and send to the cracker

5. Crack all of the accounts



Well, we learned in chapter 2 that staying focused is the key to hacking, so lets get back to it. In the Cain application, lets to the “Cracker Tab” and have a look.



The cracker tab has two basic parts. On the left are all of the hash types that Cain will crack for you. On the right are all of the associated hashes with their usernames. What we need to do is determine the password from the hash.



Note: Now would be a good time to copy the rainbow tables and password lists from the CD’s found in the back of the book to a directory on your local machine. The use of the rainbow tables will greatly increase the speed and efficiency of the cracking process as will the dictionary files included on the CDs.

Cain provides three options for determining the password from a harvested hash; these are Dictionary guessing, Bruting and Cryptanalysis. The preferred method is Cryptanalysis as it is by far the fastest if you have the tables generated. As stated in chapter 1, it would be a good idea to have tables generated for all of the possible variants for passwords from 1-7 with all possible combinations of letters and numbers and symbols. Dictionary cracking is by far the easiest of all configurations and every hacker should have extensive lists available to use.



In this appendix we are going to explore all three options.



First, let’s look at what we can tell so far from the hashes and the Cain application. One of the columns heading looks like this <8. your="" name="" here=""> owned accounts. Voila!



Take a second to look carefully at the accounts and passwords in the list. Look for patterns like the use of letters and characters in sequence. Many administrators use reoccurring patterns to help users remember their passwords. One time I found a network where the passwords were the first three letters of the first name and the three letter month abbreviation of the month that the password was set. Example: Ramius password reset in November would have a user account of RAMNOV. If you can identify patterns like this you can use word generators to create all possible combinations and shorten the window.



Cryptanalysis attacking



Alright then… Resort your hashes so single out the accounts that you have left to crack. Now select all of the un-cracked or guessed accounts and right click on the accounts again and select Cryptanalysis (LM). Add the tables that you copied from the CD to the Cain LM hashes Cryptanalysis Sorted rainbow tables window. Click start. This should go pretty quick. Voila! Take a second to review your progress and look for additional patterns.



At this point, I would grab a program like sam grab that has the ability to determine which accounts are members of the domain administrators group to see if you have gotten any admin level accounts. Once you move to the next step, which is bruting, most of what you have left are long passwords that are going to be difficult and time consuming. Any time saver applications that you can find will be helpful.



Bruting



Repeat the same process for selecting the accounts. Here is the first time that you will actually have to use your brain in this appendix. Bruting can be extremely time consuming. Look closely at all of the passwords that you have cracked and look for patterns. First do you see any special characters in any of the passwords cracked. How about numbers? A lot of all upper case of all lower case? Use what you see to help you determine what parameters to include when you are bruting. As you will see, the addition of a single character or symbol can take you from hours to days or even years to crack a password. The goal is to use the least amount of characters and symbols to get the account that you need. So lets finish it off. Select all of the un cracked accounts and follow the previous steps and select Brute Force (LM). The default for LM is A-Z and 0-9. This is because that is due nature of LM hashes and the way that they are stored. Another note is that sometimes you will see a “?” or several “????” and then some numbers or letters. This is also due to the nature of NT versus NTLM and the method that NT used to store passwords. If you read chapter 2, you already know why this is. If not see if you can find a repeating structure that is based on the number 7. Anyway, based on the other passwords and those accounts with an “*” in the <8 href="http://www.datastronghold.com/security-articles/general-security-articles/obtaining-win2k-account-passwords-using-autologon.html">* Obtaining Win2K Account Pass
* Wireless Hacking At 30,000 Fe
* .:Hacking With Metasploit & Ne
* 5-Step Plan for Securing Your
Baca lanjutannya yukss ..
Diposting oleh Admin Label:
.
.
Everyday, we go to our desk and start up our computers. Most of us have
the luxury of having it start up right away and fairly fast. However,
others can go through a very slow and frustrating start-up. This can be
annoying, especially if you need to check something on your computer
quickly, or don't have much time to sit around and wait for it to
begin. After all, time is money!

Automatic program start-ups

One
common problem that puts a drag on your speed is programs that
automatically start up. A lot of programs installed on your computer
have an option to open when your computer starts up, and a lot of them
have the option selected automatically without you realizing it.

Having
a lot of programs running when your computer starts up is the same
thing as trying to get a hundred people in one door at the same time;
it's very crammed and very slow. So, this will tend to use up youronboard
memory (RAM) when it
could better be served accommodating your operating system.

Look
for the little icons on the lower right hand corner of your screen.
Right click each of these and see if you can select the option to turn
off their automatic start-up function. It is no big deal if these
programs don't open automatically, you can always start these program
from start-all programs, when you need to.

Corrupt registry

Another
cause for a slow computer start-up is problems with the registry. The
registry is the single most important part of your operating system. It
deals with system preferences and hardware and software configuration,
as well. If the registry gets bloated and has corrupted files, this can
be the cause of a slow start-up and a slow computer in general.

Keep in mind; none of this is your fault. Everything you do with your PC changes the state of the registry. The only way you can prevent your registry from getting any corruption of any kind is to not use it. This is, of course, a ridiculous solution.

There are, however, registry cleaners that are made to put your registry back in line after it has been altered. Most of these cleaners offer a free scan, so you will know before you need to purchase one whether or not it is registry corruption slowing you down.

Delete temporary Internet files

There are other possibilities that will slow a computer's start-up. One of these causes is your computer's temporary Internet files. Cleaning these out on a regular basis can speed up your computer. With Internet Explorer 6.0, you would go to the IE window and click tools-delete browsing history and the delete temporary Internet files. This step will save the computer from loading a lot of extra stuff the next time it starts up.

Low on RAM

Another reason for a slow computer start-up is you might not have enough computer memory. Upgrading your computer's memory or RAM is a good thing to do for your computer in general and results in faster speeds and better performance.

However, if your computer has just started to rapidly loose speed, it wouldn't be lack of memory, it is more likely registry corruption. Too little RAM generally, manifests itself after a new program has been added to the computer and the performance suffers when this program is running.

The causes of slow computers start-ups can be a little bit more serious as well. For instance, you could have a virus or your hard drive could be failing. Either one of these things could indicate big problems. Before you become too scared however, it is my experience a hard drive usually starts becoming very noisy when it is on its last legs. Still, you should be aware if this happens and you should scan for viruses regularly.

Of course, there is no need for alarm about either of these things if you back up your files regularly. If you do, you can't be too concerned because restoring your computer will be easy. So... you do back up your files regularly. Right?
Baca lanjutannya yukss ..
Diposting oleh Admin Label:
.
Many schools, companies and organizations these days use Internet filtering software to block certain websites from access. However, for every one of these blocking tools, there is a work around for savvy users that want to see the content. It's not that difficult to bypass MySpace filters and other similar filters meant to limit or prohibit access to YouTube, MySpace and other sites.

(Indeed, even in countries where Internet access is severely restricted, there is always a way around the blockages...unless the country completely shuts down Internet access...but this requires far more skills than the casual user possesses.)

If your network is filtering or blocking the site you want to access (and there have been a number of sites over the years that have been blocked inappropriately), the first thing to try is to use what is called a circumvention site, such as StupidCensorship.com. Sites like this use anonymous proxy servers to circumvent web filters and firewalls.

These work around sites work by providing users with an innocent website that is not blocked by the filtering software...it then gets the website that you truly want to visit.

Now, you might have to log on at home (assuming you are not blocked there) and then take the URL to work or school get around the blocking software used on your network. After all, blocking software knows that people will try to bypass it, so does what it can to keep you from searching for those bypasses.

If this filtering software is installed on your PC, you can easily get to the site you want to access by booting a blocking-override software from your CD-ROM drive. This would assume that you have the software on CD. If you can install software on your computer, then Tor is the software of choice.

However if the computer is a public PC (such as at your school or library) with the blocking software installed, you may very well not be able to boot from a blocking-override software CD or install Tor because public computers are often 'locked down'.

The best choice, then, is to bring a list of anonymizer URLs with you and hope that at least the Internet filtering software does not block one of them. Finding a list of anonymizer URLs is simply a matter of googling to find forums where the posters want to share the information you are looking for...and there is no shortage of people wanting to help others work around blocking software!



Baca lanjutannya yukss ..
Diposting oleh Admin Label:
.
.
.
There is no point in having a new website that looks beautiful and is unknown to the internet community unless you take some active steps to promote it,oe else all your efforts will be futile and useless.If you are not sure where to begin, here are some steps that are bound to prove useful.

1. Tell Your Associates:There is no need to reach the unknown millions of people out there surfing the Internet,instead it would be wise if we contact our friends and associates.Look at your e-mail address book and get the word out, tell your business contacts, friends, relatives and tel them to tell their friends too. Channelise them in a proper way.

2. Link to Your Own Site:If you already have one website, make sure that this site is linking to your new site. A website without any incoming links to it will have a very low page ranking in the all-important Google search engine and will face an uphill battle to be seen in Google search results, especially if you are in a very competitive category.Even when your site is in the construction stage you, or even your web designer can link to the new site from another already well-established site, mentioning that the new site is under construction. If you already have several sites, then link them to your infant site. It will help the new site to be seen in competitive search engine listings even in its debut period.

3. Get a paid inclusion in one of the big search engines:It takes 4-6 weeks to get listed in Google, and other search engines are equally slow. However there are a few fairly important search engines that have inexpensive express inclusion programs. If you join these programs, then your site will be listed in 48 hours. Inktomi, which provides results for MSN and 100 other search services, has an inclusion program which costs $39 for the first URL that you submit, and subsequent ones cost $25. The value of the Inktomi submission is that they revisit your URL every 48 hours and if you make changes on the page you can see the results in the MSN listings very quickly. Thus, you can tweak your pages and see how it affects your position.


4. Add your site to the Open Web Directory and the major search engines:Quality is more important than quantity when it comes to search engine submission. Forget about the sales hype that tells you to add your URL to 300, 000 search engines. Only a few search engines and directories provide the lion’s share of Internet traffic. If your site is in good shape, no longer under construction, then go to www.dmoz.org. This is the Open Web Directory. Find the category where your site fits, and make a submission. If you are accepted here your site will appear in the many search engines and local directories that use the results from the Open Web Directory. Inclusion in this directory usually takes time but it will help you a lot. Similarly submit your site to Google, Alta Vista and All The Web, these are the remaining giants where you can submit for free.

5. Start a reciprocal links campaign – Once you have given yourself a link from your other sites or from your designer’s page, you can go out and ask other complementary sites for links.Always try exchanging links with sites that have a good page rank for it indicates that the site has good hits and is often visited.By having a trackback link chances of your site having hits is enhanced.

6. Write an article about your product or service – If you have a website the chances are that you are an expert in the field that your site is all about. Write an article about your product or service, or write an article related to the subject matter of your site. Submit the article online to various websites and e-mail lists dealing with your topic. The publication of your article in a big e-zine, or on a popular web site can get your new site off to a roaring start.

7. Promote Your Site Off-line – Now that you have a site, put the URL brochures, business cards, TV advertising, and circulars.The cafepress.com has a program enabling you to put your URL on these items and even sell them online.
Last but not the least be unique and be promotionally inclined initially for traffic generation.

Baca lanjutannya yukss ..
Diposting oleh Admin Label:
Setelah "mati-matian" dengan sekuat tenaga, bercucuran keringat
( halah )ngebuat blog, mau tau berapa harga dari blog kamu ??
mudah ! dengan memasukan URL blog kamu, kemudian klik "Submit"
kamu akan segera tau berapa sesungguhnya harga blog kamu
( tapi itu menurut versi mereka lhooo )hehehehhe kalo menurut versi
saya sih,harga blog saya jauh diatas harga cabe dipasaran ... :P

ok.daripada dengerin basa basi saya ( ga ada yg dengerin
juga kowq )
mendingan langsung aja kamu cari tau berapa harga blog kamu.
mau tau ?? silahkan klik disini

Baca lanjutannya yukss ..
Diposting oleh Admin Label:






Klik Iklan Sih... Beramal Dikit Napa... hehehe..
Thanks To :
"Thanks ya atas kunjungannya

Ini cuma blog asal2an, asal jadi
Mohon maaf jika ada yang tidak
Berkenan dihati

Mohon Tinggalkan pesan
Di Box yang tersedia
Insya Allah saya akan melakukan
linkback ke blog kamu.

Terima kasih

********

wisnoee