Pages

Advertisement

Showing posts with label Internet. Show all posts
Showing posts with label Internet. Show all posts

Monday, February 11, 2008

Router Hangs due to Azureus

Mostly every torrent downloader requires to connect to more peers and seeds so it makes changes to windows tcpip config file to more than the maximum number of connections allowed ... some of the possibilities would be ... and i mentioned how to make your Internet stable ..

You have limited your upload speed ?
Install your old version of Azureus and test again. If the problem goes away either update to Azureus CVS (simply replace azuerus2.jar) and retest.
A colleague guessed that maybe Azureus was causing my router to crash?
Quite likely. If the above doesn't fix the issue, try each step below, restart the client and test after each step.


1) Open the UpNP tab and see what the messages are
2) Disable uPnP at client
3) Ensure DHT UDP port is forwarded to the client, not just open the port but forward also.
4) Disable DHT at client (DHT overwhelms some routers with connections)
4) Set your network adaptor and IP in Advnaced Network settings and specify ports

Thursday, December 13, 2007

7 Simple ways to work fast on slow Internet connections

Microsoft's simple 7 optimizations

Summary :

  1. Sending multiple file faster by compressing .
  2. Turning images and flash can boost faster loading .
  3. Sending E-mail using Distribution list
  4. Working Offline Using Cached Exchange Mode in Outlook
  5. Reducing E-Mail Size With Simple E-Mail Signatures
  6. Browsing offline by saving web pages on Your computer
  7. Open Web Pages Faster by Increasing Your Cache

In Details :

1. Sending multiple file faster by compressing .

If you're sending multiple files—for example several files related to a project—you can reduce their combined size by using a compression utility. Compressing your files can dramatically reduce the time needed to send files online, and won't take up as much space in your (or the recipient's) e-mail Inbox. WinZip is one of the most common compression tools.

2. Turning images and flash can boost faster loading .

Graphics are important to Web pages, but they also take time to download if you're online. You can turn them off to speed your Internet browsing.

To disable graphics in Internet Explorer:

  1. On the Tools menu, click Internet Options.
  2. In the Internet Options dialog box, click the Advanced tab.
  3. In the Settings box, scroll down to the Multimedia section. Clear the following boxes.
  • Play animations in Web pages
  • Play sounds in Web pages
  • Play videos in Web pages
  • Show pictures

4 . Click Apply.

image 

3 . Sending E-mail using Distribution list

If you're sending an e-mail to multiple people, create a distribution list instead of listing each recipient separately. Messages are sent faster and more efficiently when you're using a distribution list. Your company may have established procedures for creating mailing lists.

4 .Working Offline Using Cached Exchange Mode in Outlook

Even if you lose your network connection, you can continue to working in Outlook if you're using Cached Exchange Mode. With Cached Exchange Mode, a copy of your mailbox is stored on your computer. This copy provides quick access to your data and is frequently updated with the mail server. If you work offline, whether by choice or due to a connection problem, your data is still available to you instantly wherever you are. Cached Exchange Mode does require you to work with a Microsoft Exchange Server e-mail account.

5 .Reducing E-Mail Size With Simple E-Mail Signatures

E-mail signatures leave a professional stamp on your messages, but elaborate signatures that include multiple images take up a lot of unnecessary storage space in each e-mail. Ultimately, they can slow down the time needed to send each message. Instead create distinctive text signatures combining fonts, type sizes, and colors to make your e-mail signature smaller and quicker to transmit and receive.

6.Browsing offline by saving web pages on Your computer

If you use reference a Web page often, save it locally to your computer. If you lose your connection or are working on a slow connection, you'll still be able to read and find the information you need.

To save a Web page on your computer:

  1. In Internet Explorer, go to the Web page you want to save.
  2. On the File menu, click Save As.
  3. In the Save As type drop-down menu, select Web page, complete.
  4. Click Save.
7. Open Web Pages Faster by Increasing Your Cache

If you increase the size of the Temporary Internet files cache in Internet Explorer, your computer won't have to work so hard when you revisit Web pages. Many of the images will already be downloaded on your computer, decreasing the amount of time it takes to open a page.

To increase the Temporary Internet Files cache:

  1. On the Tools menu, click Internet Options.
  2. On the General tab, in the Temporary Internet Files section, click Settings.
  3. In the Settings dialog box, under Check for newer versions of stored pages:, click the Automatically radio button.
  4. In the Temporary Internet files folder section, set the Amount of disk space to use: to at least 250 megabytes (MB).
  5. Click OK.

 

Friday, October 5, 2007

Improving BitTorrent Download Speeds

1.0 Why are my downloads going slow?

- 1.1 Reason 1: Your ISP is limiting your download speed
- 1.3 Reason 2: You have a “NAT Error”
--> 1.3.1 How do I know if I have this problem?

2.0 Fixing a NAT error

- 2.1 Switch off UPnP
- 2.2 Configure Your XP Firewall (ICF: Internet Connection Firewall)
--> 2.2.1 Configure ICF in SP1
--> 2.2.2 Configure ICF in SP2
- 2.3 Configure Your Router
- 2.4 Configure Microsoft Internet Connection Sharing (ICS)
- 2.5 Configure Your Firewall.

3.0 Multiple BitTorrent users on a LAN
4.0 Other things that could be wrong


1.0 Why are my downloads going SOOO slow?

1.1 Reason 1: Your ISP is limiting your download speed

Some ISPs are limiting download speeds by controlling the bandwidth allocated to traffic using the default BitTorrent ports, which are 6881 to 6999.

This is not just a problem for those who have nasty ISPs, it affects everybody. To avoid ISPs from damaging the efficiency of a torrent with their controls, some stringent tracker owners are blocking users trying to connect on the standard ports.

So whether your ISP is limiting you or not, all BitTorrent users should stop using the default ports.

For simplicity, this guide recommends the use of port 16881. Adding a 1 to the start is simple administratively, and is in a range unlikely to be used by other programs.

You then need to set up your client to use the new port.

1) AZUREUS
Tools -> Options -> Connection
-> Add a “1” before the current listen port number. For example, 6881 will now be 16881.

2) uTorrent
Options -> Preferences -> Connection
-> Type 16881 for the port number for incoming connections. Untick the box for Randomize Port.

Whatever client you use, make sure you update anywhere else you have entered the port numbers to account for the change.

By completing this section, you have helped to avoid problems later down the line, but this will not solve the majority of slow downloads. Therefore, move on to reason 2.


1.2 Reason 2: You have a “NAT Error”

BitTorrent works on a credit system. By uploading parts of a file to other people, they allow you to download parts of the file from them. This is BitTorrents anti-leech measure. However, if you have a problem with your NAT (anything between you and the internet, such as a router or firewall), you will not get credit for what you are uploading. The only downloading that you can do is from people who upload a small amount to you in the hope that you will return the favour. Since their client will not recognise your response if you have a NAT problem, then they will stop uploading to you shortly after. This is what is causing your problem. You may also notice that torrent speeds go very high for 5 minutes, before slowing back down to 0-5kb/s.


1.2.1 How do I know if I have this problem?

You might not have a problem at all. Before continuing with this guide, leave your torrent running for at least ten minutes. If the speed hasn't picked up, stop and restart the torrent. If that fails, try at least two other torrents. If you are still having problems, continue on...

Start to download a file using your chosen client.

AZUREUS
Wait a while for the torrent to get started; this may take up to five minutes.
Look in the “Health” column. If it is showing a yellow spot, then you need to configure your firewall/NAT/router. If it is Green then all is OK. Your slow downloads are being caused by something else.
A full list of the different colours can be seen [http://azureus.sourceforge.net/faq.php#21]here[/url].

Azureus can also check your configuration for you.
Select “Tools” -> “NAT / Firewall Test”
The default TCP listen port is 6881. If you have changed the listening port, enter the new port in the “Incoming TCP Listening Port.”
Press “Test”
If the result is “NAT Error,” please continue with the guide.
If the result is “OK”, then your slow speeds are being caused by something else.

PLEASE NOTE: The Azureus checker can report a false NAT error if you are running PeerGuardian or Protowall. Make sure these are disabled before using the Azureus wizard.

uTORRENT
Wait a while for the torrent to get started; this may take up to five minutes.
On the status bar, look for either a yellow warning triangle, or a green dot. If there is a yellow warning triangle, then you need to configure your firewall/NAT/router. If it is green then all is OK and your slow downloads are being caused by something else.
uTorrent can also check your configuration for you.
Select “Options” -> “Speed Guide…”
Check the current port is set to the port used in the first section, i.e. 16881.
Click “Test if port is forwarded properly”.
If you get an error, then continue to follow this guide. If the port is correct set up, then skip to the section 4.0 – “Other things that could be wrong”.


2.0 It’s showing yellow / warning triangle, I have a NAT error – what do I do?

You need to configure your computer and/or network to accept incoming BitTorrent port connections. The tracker port is 6969. If this port is not correctly configured, downloads will not start at all. The download/upload ports used in this guide are 16881-16889. It is these ports that are causing your problems.


2.1 Disable UPnP

Universal Plug and Play (UPnP), it is a feature that works with some compatible routers to open the required ports automatically. However, some routers, even if they are compatible with UPnP, have problems with this.

AZUREUS
Tools -> Options
Expand "Plugins" on the left hand tree.
Select "UPnP"
Deselect "Enable UPnP"

uTORRENT
Options -> Preferences -> Connection
Deselect “Enable UPnP port mapping”.


2.2 Configure Your XP Firewall (ICF: Internet Connection Firewall)

Please go to the appropriate sub-section.
- “Configure ICF in SP1” if you have NOT installed Service Pack 2
- “Configure ICF in SP2” if you have installed Service Pack 2


2.2.1 Configure ICF in SP1

Open up your “Network Connections”. Right click on your internet connection or LAN connection and select “Properties”.
->Select the “Advance” tab
->If the “Internet Connection Firewall” is not ticked, then this is not your problem. Research into whether you need the XP firewall or not and jump to "Configure Your Router" below. If it is ticked, please continue:
->Click “Settings…”
->On the “Services” tab press “Add…”
->Description of service = BitTorrent
Name or IP address of the computer hosting this service on your network = 127.0.0.1 (this means "the local machine.")
External Port number for this service = 16881
Internal Port number for this service = 16881
TCP/UDP = TCP
-> Press OK.

-> With uTorrent, make sure Options -> Preferences -> Connection -> "Port used for incoming connections” is equal to 16881.

-> With AZUREUS, make sure that "Tools -> Options -> Connection -> Incoming TCP Listen Port" is equal to 16881.

Check if the torrent/health has gone green. If not, move on to section 2.2.


2.2.2 Configure ICF in SP2

-> Open your Windows Control Panel and select “Security Centre.”
-> Scroll down to the “Manage security settings for:” section and select “Firewall”
-> Decide whether you want to keep the firewall on or off. Make an informed decision based on more than the information provided by Microsoft. If you decide to switch it off, then do so and move onto section 2.2. Otherwise, continue this section.
-> Select the “Exceptions” tab.
-> Select “Add Port…”
-> Name: = BitTorrent (or anything of your choice)
-> Port number: = 16881
-> TCP/UDP = TCP
-> Press OK.

-> With uTorrent, make sure Options -> Preferences -> Connection -> "Port used for incoming connections” is equal to 16881.

-> With AZUREUS, make sure that "Tools -> Options -> Connection -> Incoming TCP Listen Port" is equal to 16881.

Restart the client and wait five minutes. Check if the health has gone green or that the warning triangle has vanished. If not, move on to section 2.3.


2.3 Configure Your Router


If you are on a LAN with a router or hardware firewall, you may need to configure it. You need to forward BitTorrent’s connection ports to your specific PC on the LAN.

If your connection is shared using Microsoft Internet Connection Sharing (ICS), go to section 2.3.

There are too many routers to cover in this guide, so it is time to head to Google. Search for port forwarding, BitTorrent and the name of your router. Lots of manufacturers provide specific information on their sites. A generic guide to port forwarding for most routers can be found at PortForward.com.

-> With uTorrent, make sure Options -> Preferences -> Connection -> "Port used for incoming connections” is equal to 16881.

-> With AZUREUS, forward port 16881. Make sure this matches "Tools -> Options -> Connection -> "Incoming TCP Listen Port"

Restart the client and wait five minutes. Check if the health has gone green or that the warning triangle has vanished. If not, move on to section 2.4.


2.4 Configure Microsoft Internet Connection Sharing (ICS)

If you are sharing an internet connection using ICS, then you will need to forward the BitTorrent ports.
Windows 2000 users, click here for information on forwarding (mapping) ports.

Other users:
Shock Systems used to provide a useful tool called “ICS Configuration” for changing the settings of ICS to allow full BitTorrent access to a second computer.

-> Install the program on the serving computer and run it
-> Click “+ Add”
-> Name = [whatever you want, e.g. BitTorrent]
-> Target = Local IP of machine running BitTorrent, e.g. 192.168.0.2
-> Description = [whatever you want, e.g. “allow BitTorrent for 192.168.0.2”]
-> On the “Ports” tab, slect “+ Add”
-> Select “Port Range” from the drop-down box
-> Enter “16881” and “16889” into the relative boxes
-> TCP/UDP = TCP
-> Data translation = NORMAL
-> Press “OK”, Press “Enable”, Press “OK”.
-> Close everything and reboot the PC.
The settings will be saved in your registry. There is no need to open ICS Configuration with ICS.

-> With uTorrent, make sure Options -> Preferences -> Connection -> "Port used for incoming connections” is equal to 16881.

->With AZUREUS, forward port 16881. Make sure this matches "Tools -> Options -> Connection -> Incoming TCP Listen Port"

Restart the client and wait five minutes. Check if the health has gone green or that the warning triangle has vanished. If not, move on to section 2.5.


2.5 Configure Your Firewall

As with routers, there are too many to cover here, so time to head to Google. Unlike with other sections to this guide, ports only have to be opened, rather than forwarded.

With both AZUREUS and uTorrent, open port 16881.


3.0 Multiple BitTorrent users on a LAN

The same port can not be forwarded to different computers, so decide who gets which ports, for example:
192.168.0.2 = 16881
192.168.0.3 = 16882 etc.

Set up your router or ICS to forward the ports to the chosen computers.

Now you need to set up the BitTorrent Clients:

AZUREUS
Each computer only needs one port forwarded to it.
-> Tools -> Options
-> "Connection" on the side menu
-> On “Incoming TCP Listen Port” enter the port number that is being forwarded to that computer. Taking from the above example, computer 192.168.0.3 would enter 16884.
-> Repeat for all the users

uTORRENT
Options -> Preferences -> Connection -> is equal to 16881.
-> Set "Port used for incoming connections” to the port number that is being forwarded to that computer. Taking from the above example, computer 192.168.0.3 would enter 16884.
-> Press “OK”
-> Repeat for all users.


4.0 Other things that could be wrong

Try limiting your upload if you have ADSL/DSL. Sometimes BitTorrent can try to upload so much that it floods your upload, making it difficult for incoming connections. Slyck.com explains further:

It might seem strange to hear that your upload speed can directly affect your download speed, but it can, and quite dramatically. The reason behind it is based on the way the Internet works. When you download a file (or in this case, chunks of a file), your computer sends a tiny message back to the source computer, called an ACKnowledgement packet. These ACK packets tell the source computer that chunk #1 has arrived OK, please send #2. When #2 is down, it sends another, and so on. The source computer will not send #3 until it gets the ACK from #2. It uses a small amount of your upload bandwidth to do this. This works fine when downloading files off the Internet, but with P2P, you tend to upload as well.

This is especially true with BitTorrent – because you upload as well. If done efficiently, downloads can be very fast. The problem lies with the fact that you upload *so much* that the ACK's do not get sent out fast enough, which slows your download. The simplest way to solve this is to limit your upload bandwidth. 80% of the maximum is usually recommended, but I find I can set it to 90% with no adverse effects. This gives your ACKs a bit of breathing space to get out with.
CCSDUDE makes this recommendation on limiting your upload:

"Try 11kbs up as your limit on a 128k upload package...double it for 256/1.5mb lines and keep going up as you hit 384/ect. That seems to be the sweet spot on BT. Enough to keep everyone happy whilst not slowing your downloads down or slowing your surfing.
Some ISPs recognise BitTorrent traffic and then limit it. Simply switching to Azureus or uTorrent will mean that you traffic will be encrypted between compatible clients. Without giving technical details, this will stop ISPs from recognising the traffic as being from BitTorrent."

Improving BitTorrent Download Speeds

Technorati Tags: , , ,

Saturday, September 22, 2007

Steps To Deface A Webpage

First of all, I do not deface, I never have (besides friends sites as jokes and all in good fun), and never will. So how do I know how to deface? I guess I just picked it up on the way, so I am no expert in this. If I get a thing or two wrong I apoligize. It is pretty simple when you think that defacing is just replacing a file on a computer. Now, finding the exploit in the first place, that takes skill, that takes knowledge, that is what real hackers are made of. I don't encourage that you deface any sites, as this can be used get credit cards, get passwords, get source code, billing info, email databases, etc.. (it is only right to put up some kind of warning. now go have fun ;)


This tutorial will be broken down into 3 main sections, they are as followed:
1. Finding Vuln Hosts.

2. Getting In.
3. Covering Your Tracks

It really is easy, and I will show you how easy it is.

1. Finding Vuln Hosts


This section needs to be further broken down into two catigories of script kiddies: ones who scan the net for a host that is vuln to a certain exploit and ones who search a certain site for any exploit. The ones you see on alldas are the first kind, they scan thousands of sites for a specific exploit. They do not care who they hack, anyone will do. They have no set target and not much of a purpose. In my opinion these people should either have a cause behind what they are doing, ie. "I make sure people keep up to date with security, I am a messanger" or "I am spreading a political message, I use defacments to get media attention". People who deface to get famous or to show off their skills need to grow up and relize there is a better way of going about this (not that I support the ones with other reasons ether). Anyways, the two kinds and what you need to know about them:

Scanning Script Kiddie: You need to know what signs of the hole are, is it a service? A certain OS? A CGI file? How can you tell if they are vuln? What version(s) are vuln? You need to know how to search the net to find targets which are running whatever is vuln. Use altavista.com or google.com for web based exploits. Using a script to scan ip ranges for a certain port that runs the vuln service. Or using netcraft.com to find out what kind of server they are running and what extras it runs (frontpage, php, etc..) nmap and other port scanners allow quick scans of thousands of ips for open ports. This is a favorate technique of those guys you see with mass hacks on alldas.


Targetted Site Script Kiddie: More respectable then the script kiddies who hack any old site. The main step here is gathering as much information about a site as possible. Find out what OS they run at netcraft or by using: telnet www.site.com 80 then GET / HTTP/1.1 Find out what services they run by doing a port scan. Find out the specifics on the services by telnetting to them. Find any cgi script, or other files which could allow access to the server if exploited by checking /cgi /cgi-bin and browsing around the site (remember to index browse)
Wasn't so hard to get the info was it? It may take awhile, but go through the site slowly and get all the information you can.

2. Getting In

Now that we got the info on the site we can find the exploit(s) we can use to get access. If you were a scanning script kiddie you would know the exploit ahead of time. A couple of great places to look for exploits are Security Focus and packetstorm. Once you get the exploit check and make sure that the exploit is for the same version as the service, OS, script, etc.. Exploits mainly come in two languages, the most used are C and perl. Perl scripts will end in .pl or .cgi, while C will end in .c To compile a C file (on *nix systems) do gcc -o exploit12 file.c then: ./exploit12 For perl just do: chmod 700 file.pl (not really needed) then: perl file.pl. If it is not a script it might be a very simple exploit, or just a theory of a possible exploit. Just do alittle research into how to use it. Another thing you need to check is weither the exploit is remote or local. If it is local you must have an account or physical access to the computer. If it is remote you can do it over a network (internet).


Don't go compiling exploits just yet, there is one more important thing you need to know
Covering Your Tracks


So by now you have gotten the info on the host inorder to find an exploit that will allow you to get access.

So why not do it? The problem with covering your tracks isn't that it is hard, rather that it is unpredictable. just because you killed the sys logging doesn't mean that they don't have another logger or IDS running somewhere else. (even on another box). Since most script kiddies don't know the skill of the admin they are targetting they have no way of knowing if they have additional loggers or what. Instead the script kiddie makes it very hard (next to impossible) for the admin to track them down. Many use a stolden or second isp account to begin with, so even if they get tracked they won't get caught. If you don't have the luxery of this then you MUST use multiple wingates, shell accounts, or trojans to bounce off of. Linking them together will make it very hard for someone to track you down. Logs on the wingates and shells will most likely be erased after like 2-7 days. That is if logs are kept at all. It is hard enough to even get ahold of one admin in a week, let alone further tracking the script kiddie down to the next wingate or shell and then getting ahold of that admin all before the logs of any are erased. And it is rare for an admin to even notice an attack, even a smaller percent will actively pursue the attacker at all and will just secure their box and forget it ever happend. For the sake of arugment lets just say if you use wingates and shells, don't do anything to piss the admin off too much (which will get them to call authoritizes or try to track you down) and you deleting logs you will be safe. So how do you do it?
We will keep this very short and too the point, so we'll need to get a few wingates. Wingates by nature tend to change IPs or shutdown all the time, so you need an updated list or program to scan the net for them. You can get a list of wingates that is well updated at http://www.cyberarmy.com/lists/wingate/ and you can also get a program called winscan there. Now lets say we have 3 wingates:

212.96.195.33 port 23
202.134.244.215 port 1080
203.87.131.9 port 23
to use them we go to telnet and connect to them on port 23. we should get a responce like this:
CSM Proxy Server >
to connect to the next wingate we just type in it's ip:port
CSM Proxy Server >202.134.244.215:1080

If you get an error it is most likely to be that the proxy you are trying to connect to isn't up, or that you need to login to the proxy. If all goes well you will get the 3 chained together and have a shell account you are able to connect to. Once you are in your shell account you can link shells together by:
[j00@server j00]$ ssh 212.23.53.74

You can get free shells to work with until you get some hacked shells, here is a list of free shell accounts. And please remember to sign up with false information and from a wingate if possible.
SDF (freeshell.org) - http://sdf.lonestar.org
GREX (cyberspace.org) - http://www.grex.org
NYX - http://www.nxy.net
ShellYeah - http://www.shellyeah.org
HOBBITON.org - http://www.hobbiton.org
FreeShells - http://www.freeshells.net
DucTape - http://www.ductape.net
Free.Net.Pl (Polish server) - http://www.free.net.pl
XOX.pl (Polish server) - http://www.xox.pl
IProtection - http://www.iprotection.com
CORONUS - http://www.coronus.com
ODD.org - http://www.odd.org
MARMOSET - http://www.marmoset.net
flame.org - http://www.flame.org
freeshells - http://freeshells.net.pk
LinuxShell - http://www.linuxshell.org
takiweb - http://www.takiweb.com
FreePort - http://freeport.xenos.net
BSDSHELL - http://free.bsdshell.net
ROOTshell.be - http://www.rootshell.be
shellasylum.com - http://www.shellasylum.com
Daforest - http://www.daforest.org
FreedomShell.com - http://www.freedomshell.com
LuxAdmin - http://www.luxadmin.org
shellweb - http://shellweb.net
blekko - http://blekko.net

once you get on your last shell you can compile the exploit, and you should be safe from being tracked. But lets be even more sure and delete the evidence that we were there.

Alright, there are a few things on the server side that all script kiddies need to be aware of. Mostly these are logs that you must delete or edit. The real script kiddies might even use a rootkit to automaticly delete the logs. Although lets assume you aren't that lame. There are two main logging daemons which I will cover, klogd which is the kernel logs, and syslogd which is the system logs. First step is to kill the daemons so they don't log anymore of your actions.

[root@hacked root]# ps -def | grep syslogd
[root@hacked root]# kill -9 pid_of_syslogd
in the first line we are finding the pid of the syslogd, in the second we are killing the daemon. You can also use /etc/syslog.pid to find the pid of syslogd.
[root@hacked root]# ps -def | grep klogd
[root@hacked root]# kill -9 pid_of_klogd
Same thing happening here with klogd as we did with syslogd.


now that killed the default loggers the script kiddie needs to delete themself from the logs. To find where syslogd puts it's logs check the /etc/syslog.conf file. Of course if you don't care if the admin knows you were there you can delete the logs completely. Lets say you are the lamest of the script kiddies, a defacer, the admin would know that the box has been comprimised since the website was defaced. So there is no point in appending the logs, they would just delete them. The reason we are appending them is so that the admin will not even know a break in has accurd. I'll go over the main reasons people break into a box:

To deface the website. - this is really lame, since it has no point and just damages the system.
To sniff for other network passwords. - there are programs which allow you to sniff other passwords sent from and to the box. If this box is on an ethernet network then you can even sniff packets (which contain passwords) that are destine to any box in that segment.
To mount a DDoS attack. - another lame reason, the admin has a high chance of noticing that you comprimised him once you start sending hundreds of MBs through his connection.
To mount another attack on a box. - this and sniffing is the most commonly used, not lame, reason for exploiting something. Since you now how a rootshell you can mount your attack from this box instead of those crappy freeshells. And you now have control over the logging of the shell.

To get sensitive info. - some corperate boxes have alot of valueable info on them. Credit card databases, source code for software, user/password lists, and other top secret info that a hacker may want to have.
To learn and have fun. - many people do it for the thrill of hacking, and the knowledge you gain. I don't see this as horrible a crime as defacing. as long as you don't destroy anything I don't think this is very bad. Infact some people will even help the admin patch the hole. Still illegal though, and best not to break into anyone's box.


I'll go over the basic log files: utmp, wtmp, lastlog, and .bash_history
These files are usually in /var/log/ but I have heard of them being in /etc/ /usr/bin/ and other places. Since it is different on alot of boxes it is best to just do a find / -iname 'utmp'|find / -iname 'wtmp'|find / -iname 'lastlog'. and also search threw the /usr/ /var/ and /etc/ directories for other logs. Now for the explanation of these 3.


utmp is the log file for who is on the system, I think you can see why this log should be appended. Because you do not want to let anyone know you are in the system. wtmp logs the logins and logouts as well as other info you want to keep away from the admin. Should be appended to show that you never logged in or out. and lastlog is a file which keeps records of all logins. Your shell's history is another file that keeps a log of all the commands you issued, you should look for it in your $ HOME directory and edit it, .sh_history, .history, and .bash_history are the common names. you should only append these log files, not delete them. if you delete them it will be like holding a big sign infront of the admin saying "You've been hacked". Newbie script kiddies often deface and then rm -rf / to be safe. I would avoid this unless you are really freaking out. In this case I would suggest that you never try to exploit a box again. Another way to find log files is to run a script to check for open files (and then manually look at them to determine if they are logs) or do a find for files which have been editted, this command would be: find / -ctime 0 -print

A few popular scripts which can hide your presence from logs include: zap, clear and cloak. Zap will replace your presence in the logs with 0's, clear will clear the logs of your presence, and cloak will replace your presence with different information. acct-cleaner is the only heavily used script in deleting account logging from my experience. Most rootkits have a log cleaning script, and once you installed it logs are not kept of you anyways. If you are on NT the logs are at C:\winNT\system32\LogFiles\, just delete them, nt admins most likely don't check them or don't know what it means if they are deleted.
One final thing about covering your tracks, I won't go to into detail about this because it would require a tutorial all to itself. I am talking about rootkits. What are rootkits? They are a very widely used tool used to cover your tracks once you get into a box. They will make staying hidden painfree and very easy. What they do is replace the binaries like login, ps, and who to not show your presence, ever. They will allow you to login without a password, without being logged by wtmp or lastlog and without even being in the /etc/passwd file. They also make commands like ps not show your processes, so no one knows what programs you are running. They send out fake reports on netstat, ls, and w so that everything looks the way it normally would, except anything you do is missing. But there are some flaws in rootkits, for one some commands produce strange effects because the binary was not made correctly. They also leave fingerprints (ways to tell that the file is from a rootkit). Only smart/good admins check for rootkits, so this isn't the biggest threat, but it should be concidered. Rootkits that come with a LKM (loadable kernel module) are usually the best as they can pretty much make you totally invisible to all others and most admins wouldn't be able to tell they were comprimised.

In writting this tutorial I have mixed feelings. I do not want more script kiddies out their scanning

hundreds of sites for the next exploit. And I don't want my name on any shouts. I rather would like to have people say "mmm, that defacing crap is pretty lame" especially when people with no lives scan for exploits everyday just to get their name on a site for a few minutes. I feel alot of people are learning everything but what they need to know inorder to break into boxes. Maybe this tutorial cut to the chase alittle and helps people with some knowledge see how simple it is and hopefully make them see that getting into a system is not all it's hyped up to be. It is not by any means a full guide, I did not cover alot of things. I hope admins found this tutorial helpful aswell, learning that no matter what site you run you should always keep on top of the latest exploits and patch them. Protect yourself with IDS and try finding holes on your own system (both with vuln scanners and by hand). Also setting up an external box to log is not a bad idea. Admins should have also seen alittle bit into the mind of a script kiddie and learned a few things he does.. this should help you catch one if they break into your systems.

On one final note, defacing is lame. I know many people who have defaced in the past and regret it now. You will be labeled a script kiddie and a lamer for a long, long time.

Friday, September 7, 2007

How to completely remove Internet Explorer 6 from XP system?


I am still beta testing this procedure, but so far, it has worked well. Try it at your own risk, I recommend doing this on a newly loaded computer, one that you can crash if needed.
Copy the following onto a floppy as a .txt file. You will need it to delete the files. Now, keep reading.
You will need


A. A hard drive with windows 2000 sp1 or lower
B. The XP drive you want to IE remove IE remove from
C. Bios access to set the boot drive.
D. A copy of windows 98 or just IE 4.


Boot up windows 2000. Run Regedit.exe, make sure it is selected to My Computer. do a search for SFCDisable. Change the value of this to ffffff9d. Reboot the computer. (this disables windows file protection.)


Now, Double Click "my computer", go to "tools", "folder options", View, and un-check the following:


*Hide extensions for known file types
*Hide protected operating system files, click "yes" to the dialogue box
*Show Popup description for folder and desktop items
Check the following:
*Display the full path in the title bar
*Display the full path in the address bar
*Show hidden files and folders
Hit "apply"
Shut down.
Add the XP drive.
Make sure bios is set to boot to the drive that has 2000 on it.
Boot to 2000.


NOW, the easy part:
I am assuming that if you want to remove IE you also want to rid your computer of virus express (outlook express). Do this first, then IE.


Go to start, search-for files and folders. Point the "look in" bar to the XP drive only (usually "d")
Now, search and destroy... Do these in groups. Copy paste the line of filenames into the search box. Hit search. Wait for the searching to stop. Look at the list to see that mistaken files didn't get found. (yes, you want to delete the .pf files) Do edit, select all. Right click on the selection, delete. The files may not instantly disappear from the screen. Empty the recycle bin. Now hit search again. The files should be gone. Do the same for all of the below groups.
Virus(outlook) express/Outlook


Group 1: inetcomm.dll, msoeacct.dll, msoert2.dll, msoe.dll, msoeres.dll, msimn.exe
Group 2: oeimport.dll, oemiglib.dll, oemig50.exe, setup50.exe, wab.exe, wabfind.dll
Group 3: wabimp.dll, wabmig.exe, csapi3t1.dll, directdb.dll, wab32.dll, wab32res.dll
Group 4: msoe.txt (not necessary but for my own satisfaction)
Internet Exploder (IE 4,5,6 and possibly 7)


Basic IE files:


Group 1: iexplore.exe, HMMAPI.DLL, INSTALL.INS, trialoc.dll, icwconn1.exe, icwdl.dll, icwres.dll
Group 2: icwutil.dll, icwx25c.dun, msicw.isp, phone.ver, icwconn2.exe, icwhelp.dll, icwrmind.exe
Group 3. icwx25a.dun, inetwiz.exe, msn.isp, state.icw, icwconn.dll, icwip.dun, icwtutor.exe, icwx25b.dun
Group 4: isignup.exe, phone.icw, support.icw


Extended background files to delete:
Group 1: actxprxy.dll, cdfview.dll, iepeers.dll, iesetup.dll, ieuinit.inf, iexplore.exe, imgutil.dll
Group 2: inetcpl.cpl, instcplc.dll, mshta.exe, mshtml.dll, mshtmled.dll, mshtmler.dll, msident.dll
Group 3: msidntld.dll, msieftp.dll, occache.dll, sendmail.dll, tdc.ocx, webcheck.dll
Group 4: wininet.dll


Search for and Manually delete url.dll. You may also find libcurl.dll (open office file) and msdaurl.dll which should not be deleted.


You do not need them to boot, but it is recommended you replace the following, as they are critical to the functionality of some programs, like wincue for winamp, yahoo messenger, etc.

Place these in the XP drive/windows/system32 folder
wininet.dll - extract from windows 98. Version 4.72.3110.0 tests ok
url.dll - extract from windows 95c (ie3) Version 4.70.0.1155 tests ok
urlmon.dll - extract from your windows 2000 installation.
OK, thats it. Make sure there are none of the deleted files left in the XP dll cache.
Say your prayers.
Shut down windows 2000.
Remove the hard drive.
Set bios to boot to the only remaining drive.
Boot XP.
Log on.


Once booted, go to My computer, type http://www.google.com. If connected to the internet, a window should popup asking you where you want to save it at. Or, nothing happens at all. I have had some configuations in which an "explorer has generated errors" dialogue will occurr, and explorer will reboot and refresh the desktop. These are ALL SIGNS of successful removal of IE. Install your own browser, Opera 7.2 works best, Mozilla Firefox is also great. Short of mozilla creating a fake activex, you are completely immune to spyware and popup generators. Just try to install istbar - it won't install, but will crash and burn trying! 180searchassistant (msbb.exe) will try eating 100 percent of your cpu, the generate errors and die. But, you'd have to get it through a non-activex installer. Good luck. (rosoft audio tools used to do this, crashed many radio station systems!)

Have fun !

Sunday, August 5, 2007

Fire and Forget Fun: RPC Pings, GET, POST and more.

I've covered the asynchronous Fire and Forget pattern several times here and now I want to show a final usage pattern.

Most blogging APIs include the RPC Ping API to ping various RPC servers that you've updated your content. However, this works for any content, not just blog posts or changes in your RSS feed. So, if you have a forums app on your site, you can use it to ask the servers to revisit for a new forum post. Same with a new article, and so on.

Manyy of these RPC ping services have directories that they update. Weblogs.com even has a "rolling update" of links and you can download xml files of the most recent ping updates. A lot of this is legitimately indexed - which can result in increased traffic to your site. Some of it is just mindlessly populated with search results and other more or less "made for Adsense" bogus content, too.
The problem that often occurs with these RPC servers -- and often with many other types of "notification" URLS, be they GET or POST - is that this is a blocking call and you don't know how long it will take to return. For that matter, it might even time out, and in either case you don't want your web pages sitting around waiting, because that creates a really lousy user experience, making it seem like it is your site that is at fault.

So it's FIRE and FORGET to the rescue, once again!  What I've done here is to wrap up four different utility methods in the Fire and Forget idiom, all in a nice self-contained class library, all static methods.

All of these methods return immediately; they are not blocking calls:

1) RequestURL - makes a Fire and Forget GET request to any url with optional "stuff" on the querystring.
2) PostToUrl  - makes a Fire and Forget HTTP FORM POST to any url with optional querystring. You supply the FORM values in a NameValueCollection.
3) DoPingOMatic - makes a call to the popular Pingomatic.com service with your title and URL. Pingomatic takes care of the rest with its list of RPC servers.
4) DoPings - makes calls to a list of known RPC servers (which you can override with your own in an appSettings section).


In the sample web project that comes with this I also illustrate how to call the Yahoo API to ping the yahoo crawler as it requires a RESTful call which uses my RequestURL method.  There is also a CHM Help file for the library included in the /doc folder for the SearchPinger project.

Some sample usage code:

// you would need all three of the below lines to ping everthing including Yahoo:
           SearchPinger.ThreadUtil.DoPingOMatic(txtTitle.Text, txtUrl.Text);
           SearchPinger.ThreadUtil.DoPings(txtTitle.Text, txtUrl.Text);
          // Yahoo'a API wants a RESTful call which is essentially an HTTP GET, so here you are:

SearchPinger.ThreadUtil.RequestUrl

("http://search.yahooapis.com/SiteExplorerService/V1/ping?sitemap="+txtUrl.Text);

     
          // Sample of a fire and forget form  post:
          NameValueCollection nvc = new NameValueCollection();
          nvc.Add("Test", "form1value_1234");
          nvc.Add("Test2", "form2value_5678");

string targetUrl =

HttpContext.Current.Request.Url.OriginalString.Replace

(HttpContext.Current.Request.Url.LocalPath, "");

          SearchPinger.ThreadUtil.PostToUrl( targetUrl+"/Receiver.aspx", nvc);

 


And here is the SearchPinger class:



using System;
using System.Collections.Specialized;
using System.Configuration;
using System.Diagnostics;
using System.Net;
using System.Text;
 
namespace SearchPinger
{
    /// <summary>
    /// Provides threadsafe, non-blocking methods to make httpRequests using the Fire and Forget pattern
    /// <b>Usage:</b>
    ///<example> SearchPinger.ThreadUtil.DoPingOMatic(txtTitle.Text, txtUrl.Text);</example>
    /// <example>SearchPinger.ThreadUtil.DoPings(txtTitle.Text, txtUrl.Text);</example>
    /// <example>SearchPinger.ThreadUtil.RequestUrl(txtUrl.Text);</example>
    /// </summary>
    public static class ThreadUtil
    {
        // RPC Ping specification xml template
 
        #region Delegates
 
        public delegate void PingDelegate(string title, string url, string rpcServer);
 
        public delegate void PingOMaticDelegate(string title, string url);
 
        public delegate void PostUrlDelegate(string url, NameValueCollection postData);
 
        public delegate void RequestUrlDelegate(string url);
 
        #endregion
 
        /// <summary>
        /// Callback used to call <code>EndInvoke</code> on the asynchronously
        /// invoked DelegateWrapper.
        /// </summary>
        private static AsyncCallback callback = EndWrapperInvoke;
 
        private static string pingoMatic =
            "http://pingomatic.com/ping/?title=blogname&blogurl=bloggurl&rssurl=&chk_weblogscom=on&chk_blogs=on&chk_technorati=on&chk_feedburner=on&chk_syndic8=on&chk_newsgator=on&chk_feedster=on&chk_myyahoo=on&chk_pubsubcom=on&chk_blogdigger=on&chk_blogrolling=on&chk_blogstreet=on&chk_moreover=on&chk_weblogalot=on&chk_icerocket=on&chk_newsisfree=on&chk_topicexchange=on";
 
        private static string template =
            "<?xml version=\"1.0\"?><methodCall><methodName>weblogUpdates.ping</methodName><params><param><value>blogname</value></param><param><value>blogurl</value></param></params></methodCall>";
 
        /// <summary>
        /// An instance of DelegateWrapper which calls InvokeWrappedDelegate,
        /// which in turn calls the DynamicInvoke method of the wrapped
        /// delegate.
        /// </summary>
        private static DelegateWrapper wrapperInstance = new DelegateWrapper(InvokeWrappedDelegate);
 
        /// <summary>
        /// Pings list of RPC servers, optionally loading alternate list from comma-delimited appSettings section "rpcServers"
        /// </summary>
        /// <param name="title">The title.</param>
        /// <param name="url">The URL.</param>
        public static void DoPings(string title, string url)
        {
            //http://search.yahooapis.com/SiteExplorerService/V1/ping?sitemap=http://www.yahoo.com
            string servers = ConfigurationManager.AppSettings["rpcServers"];
            if (servers == null)
                servers =
                    "http://rpc.weblogs.com/RPC2,http://blogsearch.google.com/ping/RPC2,http://api.feedster.com/ping,http://api.moreover.com/RPC2,http://api.moreover.com/ping,http://api.my.yahoo.com/RPC2,http://ping.bloggers.jp/rpc/,http://ping.feedburner.com,http://ping.syndic8.com/xmlrpc.php,http://rpc.pingomatic.com,http://rpc.technorati.com/rpc/ping,http://www.blogoon.net/ping/,http://www.blogpeople.net/servlet/weblogUpdates,http://www.newsisfree.com/xmlrpctest.php";
 
            string[] rpcServerArray = servers.Split(',');
            foreach (string s in rpcServerArray)
            {
                FireAndForget(new PingDelegate(PingIt),
                              new object[] {title, url, s});
            }
        }
 
        /// <summary>
        /// Does the ping O matic call
        /// </summary>
        /// <param name="title">The title.</param>
        /// <param name="url">The URL.</param>
        public static void DoPingOMatic(string title, string url)
        {
            FireAndForget(new PingOMaticDelegate(PingOMatic),
                          new object[] {title, url});
        }
 
        /// <summary>
        /// Requests any URL, which can include a full querystring. Returns null.
        /// </summary>
        /// <param name="url">The URL.</param>
        public static void RequestUrl(string url)
        {
            FireAndForget(new RequestUrlDelegate(RequestAUrl), new object[] {url});
        }
 
        /// <summary>
        /// Posts NameValueCollection Data  to a URL. Url can also have a Querystring
        /// </summary>
        /// <param name="url">The URL.</param>
        /// <param name="postData">The post data.</param>
        public static void PostToUrl(string url, NameValueCollection postData)
        {
            FireAndForget(new PostUrlDelegate(PostToAUrl),
                          new object[] {url, postData});
        }
 
 
        private static void PostToAUrl(string url, NameValueCollection postData)
        {
            WebClient myWebClient = new WebClient();
            myWebClient.Headers.Add("Content-Type", "application/x-www-form-urlencoded");
            try
            {
                myWebClient.UploadValues(url, "POST", postData);
            }
            catch(Exception ex)
            {
                Debug.WriteLine("Post--" + ex.Message);
            }
            finally
            {
                myWebClient.Dispose();
            }
        }
 
 
        private static void RequestAUrl(string url)
        {
            WebClient reqWc = new WebClient();
            try
            {
             string s=   reqWc.DownloadString(url);
                System.Diagnostics.Debug.WriteLine(url + ": " + s);
            }
            catch (Exception ex)
            {
                Debug.WriteLine("pingomatic--" + ex.Message);
            }
            finally
            {
                reqWc.Dispose();
            }
        }
 
 
        private static void PingOMatic(string title, string url)
        {
            pingoMatic = pingoMatic.Replace("blogname", title).Replace("bloggurl", url);
            WebClient pingoWc = new WebClient();
            try
            {
                string pingoString = pingoWc.DownloadString(pingoMatic);
                Debug.WriteLine("pingomatic--" + pingoString);
            }
            catch (Exception ex)
            {
                Debug.WriteLine("pingomatic--" + ex.Message);
            }
            finally
            {
                pingoWc.Dispose();
            }
        }
 
        private static void PingIt(string title, string url, string rpcServer)
        {
            string postContent = template.Replace("blogname", title).Replace("blogurl", url);
            byte[] bytesToPost = Encoding.ASCII.GetBytes(postContent);
            WebClient wc = new WebClient();
            try
            {
                byte[] resultBytes = wc.UploadData(rpcServer, bytesToPost);
                wc.Dispose();
                string blah = Encoding.ASCII.GetString(resultBytes);
                Debug.WriteLine(rpcServer + "--" + blah);
            }
            catch (Exception ex)
            {
 
                Debug.WriteLine(rpcServer + "ERROR:  " + ex.Message);
            }
            finally
            {
                wc.Dispose();
            }
        }
 
        /// <summary>
        /// Executes the specified delegate with the specified arguments
        /// asynchronously on a thread pool thread.
        /// </summary>
        public static void FireAndForget(Delegate d, params object[] args)
        {
            // Invoke the wrapper asynchronously, which will then
            // execute the wrapped delegate synchronously (in the
            // thread pool thread)
            wrapperInstance.BeginInvoke(d, args, callback, null);
        }
 
        /// <summary>
        /// Invokes the wrapped delegate synchronously
        /// </summary>
        private static void InvokeWrappedDelegate(Delegate d, object[] args)
        {
            d.DynamicInvoke(args);
        }
 
        /// <summary>
        /// Calls EndInvoke on the wrapper and Close on the resulting WaitHandle
        /// to prevent resource leaks.
        /// </summary>
        private static void EndWrapperInvoke(IAsyncResult ar)
        {
            wrapperInstance.EndInvoke(ar);
            ar.AsyncWaitHandle.Close();
        }
 
        #region Nested type: DelegateWrapper
 
        /// <summary>    
        /// Delegate to wrap another delegate and its arguments
        /// </summary>
        private delegate void DelegateWrapper(Delegate d, object[] args);
 
        #endregion
    }
}