#page level add
Showing posts with label internet tips. Show all posts


PTCL company t published a  notice in printed newspapers and it was said that its infrastructure is damaged by variety of entities including individuals, private and government construction firms, municipal, district or provincial contractors, real estate developers, road builders and so on.
Company said that their was huge amount of disputes in this regard so they do this they also said said that such infrastructure damage causes service disruption to businesses





Kali Linux
Kali Linux is based from the Linux distribution. It is designed for digital forensics and penetration testing. Kali Linux is funded by Offensive Security Ltd. The Offensive Security team is renowned for their skills in pen testing and information security. The main developers of this OS are Mati Ahorani, Devon Kearns, Raphael Hertzog. Kali Linux works on the x64 and x86 architectures and moreover is built for the ARM architecture.
List of Devices on which Kali Linux:
BeagleBone Black
HP Chromebook
CubieBoard 2
CuBox
CuBox-i
Raspberry Pi
EfikaMX
Odroid U2
Odroid XU
Odroid XU3
Samsung Chromebook
Utilite Pro
Galaxy Note 10.1
SS808

This Linux version comes jam packed with a suite of pen testing tools. There are so many that we are going to mention the categories and explain a couple of them for your interest. See the list below for details:

Categories of Tools:
Information gathering tools
Vulnerability Analysis
Wireless Attacks
Web Applications
Exploitation Tools
Forensics Tools
Stress Testing
Sniffing and Spoofing
Password Attacks
Maintaining Access
Reverse Engineering
Hardware Hacking
Reporting Tools



The following are some examples that could jog your interest in how cool this stuff actually is:
1.      Nmap
This little tool sniffs the host and services that exist on a computer network and hence creates a digital ‘map’ of the entire network. It works by sending ‘special’ packets to the targeted host and then does an analysis of the response sent by the host.
2.      Aircrack-ng
This tool is no less useful than its previous entry. It works on 802.11 wireless LANs and can sniff 802.11a, 802.11b and 802.11g traffic. This is a suite on itself and can detect, sniff packets, crack and analyze WEP and WPA/WPA2-PSK networks.
3.      KISMET
This one is not so different from Aircrack-ng. It is used to sniff traffic networks, detect networks and it also comes with a intrusion detection system. All it needs is a wireless network card with raw monitoring mode and a Linux based OS to run on.
Other major tools are:
·        Wireshark
·        Metasploit Framework
·        Burp suite
·        John the Ripper
·        Social Engineering Toolkit
·        Maltego
·        Ettercap
·        OWASP ZAP
The question that comes to mind is why do we need to install it? What separates it from other operating systems?
Some of the reasons are:
ü  It is free and will always be! (at least according to the developers).
ü  It is open source and therefore you can play with it and tune it to need your needs.
ü  There are over 600 tools for penetration testers and the list of categories was shared above.
ü  It supports a wide range of devices. The developers specifically stress on this point to encompass as much USB and other devices to make Kali accessible to more people.
ü  It supports Multi-language meaning that you can use it in your own native language
ü  It is completely customizable which means it can be changed down to the kernel itself for users to transform and build it as they like.
ü  It supports ARMEL and ARMHF devices like the Raspberry Pi and BeagleBone Black because the developers know that these devices are becoming more and more common for use.
Attention Pen Testers!!!
For all the penetration testers Kali Linux is a great perk to have because it was designed to meet your needs. All the network features are blocked by default so it provides complete security. No matter what packages you install, the network services like Bluetooth etc are all blacklisted.  It is built for a single user, root access so it is less of a burden when using tools that require escalated privileges.
Sources:



Social Engineering:


Reading the term engineering ,what comes in one’s mind is construction of buildings, machines moving, wires carrying high voltage currents, But the term behind “ENGINEERING in first line changes its meanings completely. Social Engineering In the field of IT has entirely shocking and different meanings. It means to manipulate, temper someone’s thoughts psychologically and use the victim’s own knowledge of his private, personal and semi-confidential things to be released to attacker or the one who is manipulating him by using Social Engineering. It’s a kind of friendly trick to gather victim’s information, even not letting him or her know what attackers’ intention are and what information has been compromised. In layman terms we can say that it’s a kind of hypnotism.


Just understand it with a simple example, Consider a bank office, on the reception there is a number written saying “If you have login problems Contact This Number”. Now a costumer comes and note down this number. Suppose this costumer have login problem ,Now he call this phone number and asks the operator (a badperson) that he/she is not able to login in due to any problem, Now the operator asks him to tell me your user name and password , so now the attacker have costumer’s password. So the method to access to costumer password in this case was social engineering.
Phishing:
Phishing is kind of social engineering primarily focused to get user login details, credit card information etc. It works by sending spam or fakes emails to uses, prompting them to login to any malicious website, which is designed to pretend like any popular website, user thinks that is a genuine website and logs into it, which results in loss of his login details to hackers.
For example you receive an email asking you to verify you email address for Facebook, so when you will open the link on email and login into that fake website which also resembles Facebook real login page ,then you have lost your login details.
Baiting:
Baiting is the use of greedy nature of humans: P. Yes you have read it right. Baiting is offering something as prize or gift in exchange of user login details, or any other credentials. It works by sending emails, or offering prize on any website, any new movies to download, or even a USB placed on road so that someone picks it up and insert it into their PC which starts the send data to attacker by any malware. So it directly works on user either by using their greed or by building trust then deceiving them.


Piggybacking:
Piggybacking is technique which is mostly used in practical life, where a person enter one’s confidential or important premises where he can do anything harming. Basically this technique can be understood by an example, that you call electrician to in your company’s server room. Electrician comes verifies his card to you, and you allows him, as the electrician enters a man with evil intent enter in the premises too, pretending electrician to you and your employee to that electrician, in this way he is now able to enter in premises. Usually this is not possible in large companies where everyone has to verify their identity before entering in , by swiping their card or any other method.


How to prevent against:

  1. Don’t trust emails until you are sure.
  2. Look at URL before you enter your passwords or credentials.
  3. Don’t enter your credentials on tiny URLs.
  4. Don’t believe on Prize or Gift emails.
  5. USE 2-factor authentication in order to make it more difficult for hackers to enter your organization.
  6. When clicking on links sent via email or on websites, always keep a watch out for uninitiated or automatic downloads. It could be a malware piggybacking on to your system. All such activity should be reported IMMEDIATELY to your security manager.


#adsence add
Copyright © 2013 Technology