Hash Hack - Статьи


Security experts rate the world's most dangerous exploits

Another powerful exploit Skoudis is seeing frequently is the evolution of an attack known as pass the hash, which is used to penetrate Windows servers. Windows authentication works by checking a user's cryptographic hash, rather than password. Attackers can steal the hash by exploiting a simple unpatched browser or application vulnerability and then injecting it into the memory of the Windows box.

Although pass the hash has been around for a decade, the attacks have remained successful. That's in part thanks to a proliferation of software that streamlines the exploit. Examples include this download from Core Security, or this one from JoMo-kun. Nessus and Metasploit also have modules that perform the attacks.

Skoudis was joined by Johannes Ullrich, the CTO of the SANS Internet Storm Center. Together, they presented their list of the world's most dangerous new attack techniques and ways organizations can protect themselves against them.

"The real big problem here is user education," Ullrich told a standing-room audience. "And user education is more than going to the user and saying don't click on it. User education also means getting your own house in order."

Too many organizations are still failing to patch applications such as Adobe's Flash and Reader, he added. In other cases, they aren't teaching employees how to avoid social-engineering attacks on social networking sites and elsewhere.

Other dangerous exploits include:

  • Advances in wireless attacks, such as those that hack a client machine and then use it to connect to an access point tied to a corporate network. Interestingly, this is easier to do with Windows Vista and Windows 7 than their predecessors, Skoudis said.
  • Attacks that take advantage of shortcomings in SSL, or secure sockets layer. The most glaring are SSL's focus on failed connections rather than those that are successful and the number of banks that still use non-SSL login pages. Others include the recently demonstrated method for spoofing SSL sessions.
  • Attacks against unprotected VoIP, or voice over IP, systems. Since the beginning of the year, there have been some 5,000 scans of port 5060 every day. That's about five times the rate as in all of 2008, said Ullrich, who monitors internet activity using half a million sensors across the globe

The take-away is that admins should assume they've already been hacked.

"I believe that a determined but not necessarily well-funded attacker can pretty much break into any organization," Skoudis said. "If you think it's less than 50 percent, I think you need to look a little more carefully." ®



MD5 HASH HACK


TOP 10 Vulnerability Checker Tools


In recently, a hacking interest are being developed quickly. There are many ways as SQL-Injection, Code Injection, and so on. When a programmer writes a code, he or she should think about all of these. I am just gonna write about TOP 10 useful hacking tools and how they works because we can check our programs ourselves. It means we can find vulnerabilities and fix it.

1. Nmap
(http://nmap.org/download.html)

Nmap (Network Mapper) is a free open source utility for network exploration or security auditing. It was designed to rapidly scan large networks, although it works fine against single hosts. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services those hosts are offering, what operating systems they are running.


2. Nessus Remote Security Scanner
(http://www.nessus.org/)

Nessus is the worlds most popular vulnerability scanner used in over 75,000 organizations world-wide. Many of the worlds largest organizations are realizing significant cost savings by using Nessus to audit business-critical enterprise devices and applications.

3. John the Ripper
(http://www.openwall.com/john/)

John the Ripper is a fast password cracker. Its primary purpose is to detect weak Unix passwords. Besides several crypt password hash types most commonly found on various Unix flavors, supported out of the box are Kerberos AFS and
Windows NT/2000/XP/2003 LM hashes, plus several more with contributed patches.

4. Nikto
(http://www.net-security.org/software.php?id=223)

Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items. Scan items and plugins are frequently updated and can be automatically updated. Nikto is a good CGI scanner, there are some other tools that go well with Nikto.

5. SuperScan

Powerful TCP port scanner, pinger, resolver....

Читать дальше...

Hash Hack - Новости


Syss-Hack: Daten der IronKey-Kunden sind sicher PresseAnzeiger (Pressemitteilung)
Syss-Hack: Daten der IronKey-Kunden sind sicher PresseAnzeiger (Pressemitteilung) PresseAnzeiger (Pressemitteilung)Syss-Hack: Daten der IronKey-Kunden sind sicherPresseAnzeiger (Pressemitteilung)Darüber hinaus werden die Schlüssel vom Passwort des Benutzers mit SHA-256 Hash erneut verschlüsselt, was dem Schutz der Schlüssel zusätzliche и иные »

Chosen Music: Pearl Harbor Heeb Magazine (blog)
Chosen Music: Pearl HarborHeeb Magazine (blog)Piper: It was hash oil, man. Marijuan-nakah. Isn't that Adam Sandler's stupid shit? I was reading an interview with you… So, you dropped out of high school

Rangers 7 Dundee United 1: Out with the old and in with the new The Herald
Rangers 7 Dundee United 1: Out with the old and in with the new The Herald The HeraldRangers 7 Dundee United 1: Out with the old and in with the newThe HeraldFor once he was denied, as Garry Kenneth had the temerity to divert from the script and hack his effort away from the line. United's reprieve was fleeting и иные »

Fistgate XIV: Jennings Personally Pushed Books That Encouraged Children to ... Big Government (blog)
Fistgate XIV: Jennings Personally Pushed Books That Encouraged Children to Big Government (blog)He walked over to his secret drawing board to hash out a new evil plan. Finally it hit him, "Kittens", he cried to no one but himself. "We can kidnap all

Disney's Lump of Coal Religion Dispatches
Disney's Lump of CoalReligion DispatchesFrom slinging hash to being the friend of the annoying Southern Belle, Charlotte La Bouff (more about her in a moment), Tiana can't even enjoy a moment и прочие »

Osasuna vs Real Madrid Goal.com
Osasuna vs Real MadridGoal.comCasillas makes a hash of Flano header which creeps into the box evading the white shirts as Aranda gets a flick on which the stopper decides to punch away и часть »