Saturday, 8 September 2012

Security Issues With FTP

Security Issues With FTP

Security Issues With FTP

FTP, file transfer protocol, is widely used on the Internet for transferring files. Though FTP has a terrible security record it continues to be very popular, mainly because it is so simple to setup and use. There is a great deal of FTP software available.

WU-FTPD, the Washington University FTP daemon, has been a popular choice with many recently because it provides these security features that have been lacking in some options in the past:
log all incoming and outgoing file transfers
log all commands used by users
compression on the fly
organize users into classes so that limits on classes can be used
control uploads on each directory individually
display messages
support virtual hosts

ProFTPD has been configured and designed to be more secure than WU-FTPD. ProFTPD was rewritten from scratch to provide greater security. The security features that it provides are:
directory access using .ftpaccess files
anonymous FTP root directory
support for hidden files
self-contained
uses an unprivileged user in stand-alone mode

Both of these FTP servers are widely used. However, CentOS uses a FTP program that offers greater security and scalability , VSFTPD.

VSFTP
VSFTPD has replaced the WU-FTPD with a more secure ftp daemon. This ftp program is labeled as more secure, stable, faster and more scalable. VSFTPD has taken steps to minimize the privileges it takes to run the ftp program. Each user runs at the level of least privilege.

Check Out the Website to see speed and security comparisons. http://vsftpd.beasts.org/

An example of what VSFTPD is trying to eliminate is WU-FTPD. When you log in as an anonymous user with WU-FTPD, a process is run for the ftp session, that process must run as root on the remote machine. This does not occur with VSFTPD.

VSFTPD uses chroot which would minimize damage if a user did compromise the server.

Secure Design:
1. Parsing and acting on potentially malicious remote network data uses an unprivileged user process. In addition a chroot () jail is used to ensure only the ftp files are accessible.

2. Privileged operations are done with a privileged parent process.

3. All requests received by the parent process are distrusted.

4. The privileged parent process uses capabilities and chroot() to always run in the least privileged user possible. The privileged parent constantly calculates the necessary privileges.

Buffer Overflow:
Buffer overflow problems have been the source of many security issues. Systems can be compromised by buffer overflows. vsftpd uses an API to hide the buffer handling from the user and one piece of generic code is used to deal with buffer handling for simplicity.

How to crash Linux?

How to crash Linux?

As root, you can do whatever you want.
Try this command, as root (reconsider if you really want to crash):
# cp /dev/zero /dev/men
As root, you can even erase all the files on your system with a similarly innocuously looking one-liner (don’t do it):
# rm -rf /

This is not to say that Linux is easy to crash, but that the system administrator (”root”) has the complete power over the system so think before when working on Linux as “root” user.

Wipe hard disk completely in linux



Steps to Wipe the Hard Drive Completely

 As we all know, mkfs doesn’t erase a lot.mkfs and its variants (e.g., mkfs.ext3 and mke2fs) only get rid of a few important data structures on the filesystem, but the data is still there! For a SCSI disk connected as /dev/sda, a quick
  dd if=/dev/sdb | strings
 will let anyone recover text data from a supposedly erased hard drive. Binary data is more complicated to retrieve, but the same basic principle applies: the data was not completely erased.
 To make things harder for the bad guys, an old trick was to use the ‘dd’ command as a way to erase a drive.
 Note: This command will erase your disk!
  dd if=/dev/zero of=/dev/sda
 There’s one problem with this: newer, more advanced, techniques make it possible to retrieve data that were replaced with a bunch of 0s. To make it more difficult, if not impossible, for the bad guys to read data that was previously stored on a disk, Red Hat ships the “shred” utility as part of the coreutils RPM package. Launching “shred” on a disk or a partition will write repeatedly (25 times by default) to all locations on the disk.
 
 Note: Be careful with this one too!
 
 shred /dev/sda
 This is currently known to be a very safe way to delete data from a hard drive before, let’s say, you ship it back to the manufacturer for repair.

Create Multiboot USB Drive: Install Windows 7, XP From Same USB Drive

Create Multiboot USB Drive: Install Windows 7, XP From Same USB Drive

Earlier, we have covered some tutorials: 1.How to install windows XP From USB Drive 2. How to install Windows 7 From USB Drive. Both the processes work fine and the readers feedback was positive. But there were some drawbacks with those procedures:
1. Previous methods of creating of the bootable USB drive for Windows XP involves numbers of steps and takes lot of time to complete.
2. You are to use the similar Operating System to prepare the USB disk. i.e if you want to prepare your USB drive to install Windows XP, you’ll have to use Windows XP to apply the preparation method. The similar condition is applicable when preparing the USB drive for Windows 7.
3. Those methods do not have any option to prepare the USB disk in such a way that it would install both Windows XP and Windows 7 after spending one time effort.
But we found an awesome free utility WinSetupFromUSB which comes across  drawbacks and allows you to create a Multiboot USB drive to install Windows XP and Windows 7 from the same USB drive. No need to prepare your USB stick separately. Even the tool works in both Windows XP and Windows 7.

Creating the Multiboot USB Drive for Windows 7 and XP

Creating the multiboot USB drive is too easy and involves four simple steps. Before getting into the process, make sure that the USB drive that you have, is minimum 4 GB of volume (recommended 8 GB) and formatted with FAT32 file system. Once you are ready, download WinSetupFromUSB and extract at any location of your computer.

Then follow the steps below:
1. Insert the formatted USB drive in the USB post of your computer and run the WinSetupFromUSB_1-0-beta7.exe.
2. Make sure that the the utility has detected your USB drive.
3. Now enable the option Windows 2000/XP/2003 Setup selecting the check box and browse to the Windows XP installation file location. Next, enable the option Vista/7/Server 2008 Setup/PE/RecoveryISO and browse to the Windows 7 installation files’ location. In both of the cases, if you have the ISO images, extract them by WinRar or 7-Zip.

4. Click the Go button to get started. It might take several minutes.
Though we have discussed the process for only Windows XP and Windows 7, you can also add Windows Vista as well as Linux.

Hack/View Webcams around the world [for free]

Hack/View Webcams around the world [for free]

Copy/Paste any ONE of these search strings into google and it will produce live security/webcams. Most are controllable/zoom etc. Just go to www.google.com and key in the below:-

inurl:/view.shtml
inurl:ViewerFrame?Mode=
intitle:”Live View / - AXIS” | inurl:view/view.shtml^
inurl:ViewerFrame?Mode=Refresh
inurl:axis-cgi/jpg
inurl:axis-cgi/mjpg (motion-JPEG)
inurl:view/indexFrame.shtml
inurl:view/index.shtml
inurl:view/view.shtml
liveapplet
intitle:”live view” intitle:axis
intitle:liveapplet
allintitle:”Network Camera NetworkCamera”
intitle:axis intitle:”video server”
intitle:liveapplet inurl:LvAppl
intitle:”EvoCam” inurl:”webcam.html”
intitle:”Live NetSnap Cam-Server feed”
intitle:”Live View / - AXIS”
intitle:”Live View / - AXIS 206M”
intitle:”Live View / - AXIS 206W”
intitle:”Live View / - AXIS 210″
inurl:indexFrame.shtml Axis
inurl:”MultiCameraFrame?Mode=Motion”
intitle:start inurl:cgistart
intitle:”WJ-NT104 Main Page”
intext:”MOBOTIX M1″ intext:”Open Menu”
intext:”MOBOTIX M10″ intext:”Open Menu”
intext:”MOBOTIX D10″ intext:”Open Menu”
intitle:snc-z20 inurl:home/
intitle:snc-cs3 inurl:home/
intitle:snc-rz30 inurl:home/
intitle:”sony network camera snc-p1″
intitle:”sony network camera snc-m1″
site:.viewnetcam.com -www.viewnetcam.com
intitle:”Toshiba Network Camera” user login
intitle:”netcam live image”
intitle:”i-Catcher Console - Web Monitor”

keylogger collection

there are many keyloggers out there but most of them are on paid version
so i collected some and thought to share with you all...
now as i had uploaded them i am sharing them here if you have any querry comment below i will reply ...
now fud them and enjoy...

         

stealth keylogger

w investor keylogger

remote keylogger

soft central keylogger

invisibal keylogger

home keylogger

ghost keylogger

golden keylogger

ardmax keylogger

actual spy keylogger

How to convert videos and get them on your Sony Ericsson Xperia X8

So you've just got your hands on a Sony Ericsson Xperia X8 and you want to take advantage of its beautiful screen by putting some videos on the device?
Thankfully this is very straight forward, with a little help from Know Your Mobile, and by following these steps you'll be able to convert videos and port them over to your Xperia X8 device.
You'll need the following things, though, before you get started:
  1. Installed copy of Handbrake software
  2. Video files and or DVD of your choice
  3. Sony Ericsson Xperia X8 with microUSB cable
Step I: Launch the Handbrake application on your computer and select the video source
Alternate Text
(click to enlarge)
  1. Launch Handbrake (figure 1)
  2. In the menu on the right-hand side, select the iPod Legacy preset (figure 1)
  3. Select your video source by clicking on the Source dropdown menu (we used a DVD for our testing purposes)
  4. Select the destination and name for the file once it has been converted (both the .mp4 and .m4v extension work for the Xperia X8)
  5. Confirm that the container is set to MP4 File and that Large file size, Web optimized, and iPod 5G support are unchecked
Step II: Adjust Handbrake's Video Settings
Picture Tab:
  1. Uncheck Keep Aspect Ratio
  2. Set the Xperia X8 Width and Height (the Xperia X8 supports a maximum of 480 x 320 pixels)
Video Tab:
Alternate Text
(click to enlarge)
  1. Set Handbrake's encoding settings by clicking on the Video tab (figure 2)
  2. Confirm the Video Codec is set as H.264 (x264)
  3. Framerate (FPS) should be set to Same as source
  4. Under Quality, select the Avg Bitrate (kbps) and change it to 1500
Step III: Adjust audio settings
Alternate Text
(click to enlarge)
  1. Set Handbrake's audio settings by clicking on the Audio tab (figure 3)
  2. Confirm the Audio Codec is AAC (faac)
  3. Mixdown should be set to Stereo
  4. Change the Samplerate to 48
  5. Change the Bitrate to 160
Step IV: Save as a preset for future use
  1. Click on the Presets menu and select New Preset
  2. Enter Xperia X8 in the dialog box and click Add
  3. "Xperia X8" will now be saved as a preset and listed on the right hand side in Handbrake to be used in the future
Step V: Convert the video and copy to your Xperia X8
  1. Click on the Start button in Handbrake
  2. A command line/DOS window will open and start to process the video conversion
  3. Once the conversion is done, mount your Xperia X8 on to your computer via USB
  4. Once mounted, create a folder named Video in the root folder on the Xperia X8
  5. Copy converted file into the Video folder
That's it! The converted video can now be played on your Xperia X8 using the Gallery app. It should look fantastic on the Xperia X8's screen as long as the original source was of good quality.
A few things to keep in mind when converting video:
  1. The Xperia X8 does not like video file sizes over 2GB (the settings in Step II should help insure that the file size is kept under 2GB)
  2. Your converted video will only be as good as the source video
  3. If your source is over 480 x 320, you must be sure to set the width and height to a maximum of 480 x 320 as noted in Step II