Archive for February, 2007

Neutrality of Net Neutrality article on Wikipedia under dispute

I saw this on an RSS feed somewhere and went down to further investigate. This is definitely funny where the neutrality of Net Neutrality article on Wikipedia is disputed. While this is standard practice on Wikipedia where any disputed articles or hotly debated articles are branded under this category, the picture is definitely funny.

Neutrality of Net Neutrality article on Wikipedia under dispute

If you're new here, you may want to subscribe to my RSS feed. Thanks for visiting!

Dirty Business: What Security and Pen Testers need to know to get the job done

This article is part # 3 in the series on Penetration Testing. The first in this series talks about Penetration testing as a profession and a general introduction. The second introduces you to some critical keywords and security tips you need to be aware of before proceeding through the rest of this series.  

When you are performing the role of a security/pen tester, sometimes just having the right tools and skills is not enough. Either they are not enough or there are easier ways to get the management to understand how easy it is for someone to walk in and walk out with the keys to their “fort”.

One of the first things I want to share with you is what my Professor of a Security Class I took while I was an Undergrad at Florida Tech shared with us. So, he was performing a penetration test at a company and he was negotiating the price for which he is willing to perform the pen test of the company’s network. Apparantly, the company was driving a hard bargain. Finally, it reached an ultimatum situation and so the company asks… “why should we pay you so many X dollars more? Are you that Good?” or something on those lines. So my professor excuses himself from the meeting room on the pretext of using the rest room. He walks around the floor on which the meeting was set up. Here is what he finds. He finds passwords on Employees monitors, including in front of an employee who had an “Emergency Response Team” sign sitting outside his cube. As he is walking past he sees the Project Manager’s laptop bag with disks and flash drives in it, sitting outside near the receptionist or an employee’s desk. He just informs the lady that he was told to bring the bag inside, takes out the flash drive. He logs into one of the terminals, grabs some credentials stored on the flash drive, makes printouts of some confidential documents and brings it back to the meeting room, all within a time frame of around 5-10 minutes. No one asked any questions. My professor got the price he asked for and more and the company had an excellent pen test analysis done.

So what is the moral of this story: No matter how strong your filters are set or firewall configured. You must always take caution against the insider attack. You are only as strong as your weakest link. In this business, sometimes, we need to employ tactics such as social engineering amongst others to get our job done. In this article, I will talk about some of these tactics.

1. Using a Keylogger:  Keystroke logging (often called keylogging) is a diagnostic used in software development that captures the user’s keystrokes. It can be useful to determine sources of error in computer systems and is sometimes used to measure employee productivity on certain clerical tasks. Such systems are also highly useful for law enforcement and espionage—for instance, providing a means to obtain passwords or encryption keys and thus bypassing other security measures. A simple google search on download keyloggers gives you plenty of results. You might want to use a professional keylogger tool such as KeyKatcher or KeyGhost. While you are performing a security test on a system, keyloggers can be a helpful tool. However, please make sure that you have permission from the company to do something like this.

2. The ability to pick locks: Okay, this is one skill I don’t have too but if you are performing the role of a pen tester, remember that if something was stolen or picked from the company, it rather be you than some attacker. When performing a test, know the kinds of locks used by the company to secure its prime assets such as server rooms etc. While most companies these days are using card access, you might be in luck if they are using the traditional lock. An excellent paper highlighting the need for physical security is the “MIT Guide to Lock Picking” by an author who calls himself Ted the Tool. If you are going in this direction, contact your nearest law enforcement agency, fill out the necessary forms and get certified. The ability to pick the lock of a server room could be a valuable asset while performing a security test at a company. Again, please make sure you have permission from the company to do something like this.

Related Articles:

1. Introduction to Ethical Hacking and Penetration Testing

2. Important Computer Security Definitions and Terminologies

Introduction to Ethical Hacking and Penetration Testing

Been busy lately, where I am currently performing pen testing for a major company based in India. Under NDAs, I cannot disclose the name of the company.

However, the company has given me permission to incorporate some of the findings into this series: An Introduction to Ethical hacking through the eyes of a pen tester and hopefully helps anyone reading this blog on how to protect and secure a network by understanding how a Hacker operates and understanding their tools and methodologies.

Why would I want to publish such a series of articles; because, I did not want to be part of the problem anymore. The need to know and understand Computer Security has passed the realm of just security professionals. The web is an ugly place out there with hackers and crackers lurking at every corner selling their Trojans and the rest of their goods in the malicious code dept, trying to install Botnets and seeking to profit from your mistakes or rather lack of security awareness.
Every other day, you see articles on the newspaper and on the web on identity theft or credit card numbers being stolen from compromised database servers. The need for security professions who know networks and understand how Hackers operate is growing every day which companies utilizing such security professionals to test and break into their network before the bad guys do and patch up their security infrastructure. It is here that we, the “security tester” or “penetration tester” come in. 

So what will you learn in this series on Penetration Testing?
I will try to offer you a structured approach to security and penetration testing. I will also try to explain in-depth some of the tools which hackers typically use. Remember you are trying to be the Ethical hacker and you need to know how to use and implement the tools of the trade.

A network is only as secure as its weakest link. You are trying to discover vulnerabilities within a network and find that weak link before the bad guys.

Disclaimer: You will learn about some tools and methodologies which are not meant to be used for Hacking purposes. Hacking or compromising a computer or a network is illegal in many parts of the world. Please use them to further understand how computer security works.  If you are trying to take up the role as a penetration tester for a company, make sure you have a contract signed with the client and what you can and cannot do clearly defined. Also, make sure you read your ISP’s contract and their acceptable use policy defining any scanning software such as port scanners. Anytime you run something that denies a user access to a system or a network resource is illegal.

Google Gmail Keyboard Shortcuts

A Keyboard Shortcut according to Wikipedia states that a keyboard shortcut (or accelerator key, shortcut key, hot key, key binding, keybinding, key combo, etc.) is a key or set of keys that performs a predefined function. These functions can often be done via some other, more indirect mechanism, such as using a menu, typing a longer command, and/or using a pointing device. By reducing such sequences to a few keystrokes, this can often save the user time, hence “shortcut”.

Google’s Gmail service has grown to be one of the most popular web based email services out there. They were the first ones to provide 1GB of free email storage whereas other providers such as Microsoft’s Hotmail and Yahoo’s Yahoo mail only provided a storage space of 4MB and 2MB respectively. While other free webbased email solutions have tried to catch uo with GMail in terms of storage capacity and features, Google’s GMail is still the king especially among the techie and geek community. Google’s support pages do an excellent job outlining the various keyboard shortcuts, they just do a dump on you with no breakdown of your various seperate needs.  I will try to break it down by categories below and in some cases, I will use Google’s own words explaining GMail’s shortcut features.

Caution: The keyboard shortcuts in GMail are case-sensitive.

TIP: This blog allows you to print articles. Make use of the print this option in this article for a formatted page for printing.

First off, verify that you have keyboard shortcuts enabled on your GMail account. To do so, login to your GMail account, then go to Settings and under the General Tab options, you will see an option to enable or diasable keyboard shortcuts in GMail.

Enable or disable keyboard shortcuts in Google's GMail

Searching your GMail messages / conversations:

Shortcut Key Definition Action
/ Search This takes your cursor to the main search box in your GMail account

Read more »

Google Accounts has retard as a CAPTCHA

A CAPTCHA (an initialism for “Completely Automated Public Turing test to tell Computers and Humans Apart”, is a type of challenge-response test used in computing to determine whether or not the user is human. A common type of CAPTCHA requires that the user type the letters of a distorted image, sometimes with the addition of an obscured sequence of letters or digits that appears on the screen.

Okay so I get the funniest thing in the mail today. A buddy of mine apparantly got this while he was associating his GMail Id with one of Google’s Orkut Service. He gets the CAPTCHA as “retard”

Google asking for a retard confirmation