‏إظهار الرسائل ذات التسميات Sniffing. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات Sniffing. إظهار كافة الرسائل

الأربعاء، 25 فبراير 2015

Lenovo Website Is Still Under Construction After Hacked By Lizard Squad


Lenovo Website Is Still Under Construction After Hacked By Lizard Squad.

After the Superfish Malware incident, Lenovo official website is suffering from cyber attack by hacking group called Lizard Squad. It was revealed earlier this week that Lenovo had been pre-installing controversial 'Superfish' adware to its laptops which compromised the computer's encryption certificates to quietly include more ads on Google search.

“We’re breaking free! Soarin’, flyin’, there’s not a star in heaven that we can’t reach!,” Lizard Squad posted on its Twitter page, quoting the song from the movie “High School Musical”.

The hacker group also posted a couple of screenshots of an email between Lenovo employees regarding the “Superfish” software.

On Lenovo website, Company apologies to there visitors with message,

"The Lenovo Web site is currently unavailable but will return soon. To place or check on the status of an order or for any other enquiries, please contact a Lenovo representative during regular business hours."


What is Superfish Adware?
Last friday dozen of Lenovo Laptops are compromised by SSL Spoofing attacks. Where cyber attackers can read HTTPS web traffic to perform the attacks.

You can also do check whether you laptop is compromised by Superfish or not by https://filippo.io/Badfish/. If you see a "YES" then you might have a problem. And if the message output is ,"GOOD, Superfish is probably not intercepting your connections", then you are safe.

About Lenovo:
Lenovo Group Ltd. is a Chinese multinational computer technology company with headquarters in Beijing, China, and Morrisville, North Carolina, United States. Company revenue $38.70 billion at 2014.

الجمعة، 20 فبراير 2015

Nettool.sh - Automate frameworks For Nmap, Driftnet, Sslstrip, Metasploit And Ettercap MITM Attacks



Nettool.sh  - Automate frameworks For Nmap, Driftnet, Sslstrip, Metasploit And Ettercap MITM Attacks.

Netool.sh toolkit provides a fast and easy way For new arrivals to IT security pentesting and also to experience users to use allmost all features that the Man-In-The-Middle can provide under local lan, since scanning, sniffing and Social engineering attacks "[spear phishing attacks]"...

Netool its a toolkit written using 'bash, python, ruby' that allows you to automate frameworks like Nmap, Driftnet, Sslstrip, Metasploit and Ettercap MitM attacks. This toolkit makes it easy tasks such as SNIFFING tcp/udp traffic, Man-In-The-Middle attacks, SSL-sniff, DNS-spoofing, DoS attacks in wan/lan networks, TCP/UDP packet manipulation using etter-filters, and gives you the ability to capture pictures of target webbrowser surfing (driftnet), also uses macchanger to decoy scans changing the mac address.

Operative Systems Supported are:
Linux-ubuntu, kali-linux, backtack-linux (un-continued), freeBSD, Mac osx (un-continued)

Rootsector module allows you to automate some attacks over DNS_SPOOF + MitM (phishing - social engineering) using metasploit, apache2 and ettercap frameworks. Like the generation of payloads, shellcode, backdoors delivered using dns_spoof and MitM method to redirect a target to your phishing webpage. recent as introducted the scanner inurlbr (by cleiton). This tool brought to you by: peterubuntu10

Video:


Download

الثلاثاء، 21 أكتوبر 2014

Do you think HTTPS is Secure? But its Not !


Do you think HTTPS is Secure? But its Not !

Do you want to test your Server for BEAST & CRIME Attacks?

Do you want to have an overview on how secure is your encryption also indicating the Supported Suites & Protocols?

TestSSLServer will give you all of them in just one tool!.

All you have to do is visit their main website:

Link: http://www.bolet.org/TestSSLServer/

Then run which package you desire:

-) Java Application

   Link: http://www.bolet.org/TestSSLServer/TestSSLServer.jar

-) Windows Executable Version

   Link: http://www.bolet.org/TestSSLServer/TestSSLServer.exe

Once you will have downloaded it, just drag the app into the Windows Command-Promt and press Enter:


When you are there, you will need to enter the server details, for this use this syntax:

usage: TestSSLServer servername [ port ]

Example: mysubdomain.apple.com 443 **(You can also insert your local address if you have any Server running into it)



As you can see, one of Apple's subdomain is Vulnerable to POODLE Attack since it has SSLv3 Enabled.

It can be attacked from the HTTPS Secure Port - :443 .

We can see that the Vulnerable SSLv3 Cipher Suites are:

RSA_WITH_RC4_128_SHA
RSA_WITH_AES_128_CBC_SHA
RSA_WITH_AES_256_CBC_SHA

...but our Target is also Vulnerable to BEAST Attack as reported below!.

BEAST status: vulnerable

But it's not the end!.

This great Tool also give you relevant informations regarding the Security of your Keys!

My target got it STRONG, it means that a Possible Attacker may concour in some difficulties for Crack the Server Key!.

See Below!:

Minimal encryption strength:    strong encryption (96-bit or more)
Achievable encryption strength: strong encryption (96-bit or more)

If is STRONG, The Hacker may be not facilited but NOT unabilited for CRACK your Web-Server Keys.

At the end, this tool also give you the details about the Security Certificate that the server is running!.

Example mine comes from Cupertino, California!.

Definitively, you should try it at all!.

About the Author :
Christian Galeone is a Cyber Security Researcher from Italy. He has been acknowledged by the TOP 5 Companies including Yahoo!, Microsoft, AT&T, Sony etc.

الثلاثاء، 14 أكتوبر 2014

Snapception: Intercept and Decrypt All Snapchats Received Over Your Network


Snapception: Intercept and decrypt all Snapchats received over your network.


Installing is easy:

pip install snapception 

Starting it is easy too:

snapception --help
Usage: snapception [OPTIONS]

Options:

  -v, --verbose        Enable logging
  -vv, --very-verbose  Include mitmdump in logging
  -o, --output TEXT    Specify output directory (Default is ~/snaps)
  --help               Show this message and exit.

Configuring:

Configure your device to use a proxy pointing to Port 8080 of the host computer
Install a CA on your device by visiting mitm.it once connected to the proxy
Watch all the Snapchats you receive over the network become available on your computer.

Snapception, intercepts all snapchats received over the network so long as the receiving device is connected to the computer running Snapception via a proxy. Those applications also require you to manually login and save your snapchat before officially opening it; Snapception automatically intercepts, decrypts, and saves your received snaps.

Download

الخميس، 9 أكتوبر 2014

iSniff GPS Passive Sniffing Tool of iOS devices For WiFi location Data


iSniff GPS Passive Sniffing Tool of iOS devices For WiFi location Data.

iSniff GPS passively sniffs for SSID probes, ARPs and MDNS (Bonjour) packets broadcast by nearby iPhones, iPads and other wireless devices. 

The aim is to collect data which can be used to identify each device and determine previous geographical locations, based solely on information each device discloses about previously joined WiFi networks.

iOS devices transmit ARPs which sometimes contain MAC addresses (BSSIDs) of previously joined WiFi networks, as described in [1]. iSniff GPS captures these ARPs and submits MAC addresses to Apple's WiFi location service (masquerading as an iOS device) to obtain GPS coordinates for a given BSSID. If only SSID probes have been captured for a particular device, iSniff GPS can query network names on wigle.net and visualise possible locations.

By geo-locating multiple SSIDs and WiFi router MAC addresses, it is possible to determine where a device (and by implication its owner) is likely to have been.

Components


  • iSniff GPS contains 2 major components and further python modules:
  • iSniff_import.py uses Scapy to extract data from a live capture or pcap file and inserts it into a database (iSniff_GPS.sqlite3 by default).
  • A Django web application provides a browser-based interface to view and analyse the data collected. This includes views of all detected devices and the SSIDs / BSSIDs each has probed for, a view by network, Google Maps views for visualising possible locations of a given BSSID or SSID, and a pie chart view showing a breakdown of the most popular device manufacturers based on client MAC address Ethernet OUIs.
  • wloc.py provides a QueryBSSID() function which looks up a given BSSID (AP MAC address) on Apple's WiFi location service. It will return the coordinates of the MAC queried for and usually an additional 400 nearby BSSIDs and their coordinates.
  • wigle.py provides a getLocation() function for querying a given SSID on the wigle.net database and returns GPS coordinates. It must be configured with a valid wigle.net auth cookie. Please respect the wigle.net ToS in using this module.



Instructions

To use the web interface:

Install required Python modules by running pip install -r requirements.txt.
Initialise an empty database by running ./manage.py syncdb.
Start the web interface by running ./manage.py runserver 127.0.0.1:8000.

To sniff wifi traffic:

Install Scapy
Import data from a wifi pcap capture by running ./run.sh -r <chan11.pcap>
For live capture, bring up a wifi interface in monitor mode (usually mon0) so that airodump-ng shows traffic.

Start live sniffing with ./run.sh -i mon0.

To solicit ARPs from iOS devices, set up an access point with DHCP disabled (e.g. using airbase-ng) and configure your sniffing interface to the same channel.

Once associated, iOS devices will send up to three ARPs destined for the MAC address of the DHCP server on previously joined networks. On typical home WiFi routers, the DHCP server MAC address is the same as the WiFi interface MAC address, which can be used for accurate geolocation. On larger corporate WiFi networks, the MAC of the DHCP server may be different and thus cannot be used for geolocation.

Download now

الجمعة، 28 فبراير 2014

How to Use Network Monitor (Netmon Tutorial)


Microsoft's Network Monitor is a tools that allow capturing and protocol analysis of network traffic. Network Monitor 3 is a protocol analyzer. It enables you to capture, to view, and to analyze network data. You can use it to help troubleshoot problems with applications on the network. This article contains download and support information, installation notes, and general usage information about Network Monitor 3. Network Monitor 3.4 is the latest version.
Network Monitor 3 is a complete overhaul of the earlier Network Monitor 2.x version. Some key features of Network Monitor 3 include the following:
  • Script-based parser model with frequent updates
  • Concurrent live capture sessions
  • Support for Windows 7
  • Support for 32-bit platforms and for 64-bit platforms
  • Support for network conversations and process tracking
  • API to access capture and parsing engine
  • Wireless Monitor Mode Capturing
Supported Operating System ::
Windows 7, Windows 8, Windows Server 2003 Service Pack 2, Windows Server 2003 Service Pack 2 x64 Edition, Windows Server 2008, Windows Server 2008 R2, Windows Server 2008 R2 for Itanium-based Systems, Windows Server 2012, Windows Vista 64-bit Editions Service Pack 1, Windows Vista Service Pack 1, Windows XP 64-bit, Windows XP Service Pack 3
    Hardware ::
    • 1 GHz or greater CPU
    • 1 GB or greater memory
    • 60 MB free hard disk space plus extra room for capture files

Tutorials ::

 
Installation Instruction :: 
The Network Monitor core engine has been decoupled from the parser set. To install the full Network Monitor 3.4 product:
  • Run the setup.exe for the platform you are installing.
  • You will be prompted first to install the core engine. Follow the installation directions. Make sure you close existing instances of netmon.exe, nmcap.exe and any running NMAPI applications.
  • Next you will be prompted to install the parser package. Follow the installation directions:
To uninstall the full Network Monitor 3.4 product ::
  • Go to Add/Remove Programs in Control Panel
  • Uninstall both Microsoft Network Monitor 3.4 and Microsoft Network Monitor: Network Monitor Parsers 3.4
Network Monitor Blog :: Click Here
Network Monitor Blog :: Click Here

Video Tutorial ::  Click Here

Download ::