Affichage des articles dont le libellé est IDS. Afficher tous les articles
Affichage des articles dont le libellé est IDS. Afficher tous les articles

Wireless Auditing, Intrusion Detection & Prevention System

WAIDPS is an open source wireless swissknife written in Python and work on Linux environment. This is a multipurpose tools designed for audit (penetration testing) networks, detect wireless intrusion (WEP/WPA/WPS attacks) and also intrusion prevention (stopping station from associating to access point). Apart from these, it will harvest all WiFi information in the surrounding and store in databases. This will be useful when it comes to auditing a network if the access point is ‘MAC filtered’ or ‘hidden SSID’ and there isn’t any existing client at that moment.
 

WAIDS may be useful to penetration testers, wireless trainers, law enforcement agencies and those who is interested to know more about wireless auditing and protection. The primarily purpose for this script is to detect intrusion. Once wireless detect is found, it display on screen and also log to file on the attack. Additional features are added to current script where previous WIDS does not have are :

·         automatically save the attack packets into a file

·         interactive mode where users are allow to perform many functions

·         allow user to analyse captured packets

·         load previously saved pcap file or any other pcap file to be examine

·         customizing filters

·         customize detection threshold (sensitivity of IDS in detection)



  
At present, WAIDS is able to detect the following wireless attacks and will subsequently add other detection found in the previous WIDS.

·         Association / Authentication flooding

·         Detect mass deauthentication which may indicate a possible WPA attack for handshake

·         Detect possible WEP attack using the ARP request replay method

·         Detect possible WEP attack using chopchop method

·         Detect possible WPS pin bruteforce attack by Reaver, Bully, etc.

·         Detection of Evil-Twin

·         Detection of Rogue Access Point



The whole structure of the Wireless Auditing, Intrusion Detection & Prevention System will comprise of

Harvesting WiFi Information         [Done]

Intrusion Detection                         [Partially Done]

Intrusion Prevention                       [Partially Done]

Auditing (Testing network)            [Coming Soon]
Other additional item include analyzing of packets, display of captured dump, display network barchart and much more.


Tutorial & Source
Download

~ lundi 11 août 2014 0 commentaires

Pytbull Intrusion Detection/Prevention System Testing Framework

http://www.ehacking.net/2014/02/pytbull-intrusion-detectionprevention.html
pytbull is an Intrusion Detection/Prevention System (IDS/IPS) Testing Framework for Snort, Suricata and any IDS/IPS that generates an alert file. It can be used to test the detection and blocking capabilities of an IDS/IPS, to compare IDS/IPS, to compare configuration modifications and to check/validate configurations.






The framework is shipped with about 300 tests grouped in 11 testing modules:


  1. badTraffic: Non RFC compliant packets are sent to the server to test how packets are processed.
  2. bruteForce: tests the ability of the server to track brute force attacks (e.g. FTP). Makes use of custom rules on Snort and Suricata.
  3. clientSideAttacks: this module uses a reverse shell to provide the server with instructions to download remote malicious files. This module tests the ability of the IDS/IPS to protect against client-side attacks.
  4. denialOfService: tests the ability of the IDS/IPS to protect against DoS attempts
  5. evasionTechniques: various evasion techniques are used to check if the IDS/IPS can detect them.
  6. fragmentedPackets: various fragmented payloads are sent to server to test its ability to recompose them and detect the attacks.
  7. ipReputation: tests the ability of the server to detect traffic from/to low reputation servers.
  8. normalUsage: Payloads that correspond to a normal usage.
  9. pcapReplay: enables to replay pcap files
  10. shellCodes: send various shellcodes to the server on port 21/tcp to test the ability of the server to detect/reject shellcodes.
  11. testRules: basic rules testing. These attacks are supposed to be detected by the rules sets shipped with the IDS/IPS.

Source and Official document

~ samedi 1 février 2014 0 commentaires

Web Application Firewalls - OWASP

Web applications of all kinds, whether online shops or partner portals, have in recent years increasingly become the target of hacker attacks. The attackers are using methods which are specifically aimed at exploiting potential weak spots in the web application software itself - and this is why they are not detected, or are not detected with sufficient accuracy, by traditional IT security systems such as network firewalls or IDS/IPS systems.


OWASP develops tools and best practices to support developers, project managers and security testers in the development and operation of secure web applications. Additional protection against attacks, in particular for already productive web applications, is offered by what is still a emerging category of IT security systems, known as Web Application Firewalls (hereinafter referred to simply as WAF), often also called Web Application Shields or Web Application Security Filters
 
One of the criteria for meeting the security standard of the credit card industry currently in force (PCI DSS - Payment Card Industry Data Security Standard v.1.1) for example, is either a regular source code review or the use of a WAF. 
 
The document is aimed primarily at technical decision-makers, especially those responsible for operations and security as well as application owners (specialist department, technical application managers) evaluating the use of a WAF. Special attention has been paid - wherever possible - to the display of work estimates - including in comparison to possible alternatives such as modifications to the source code. 
 
In addition to the importance of the web application regarding turnover or image - the term access to a web application used in this document can be a good criterion in the decision-making process relating to the use of WAFs. Specifically, the access to a web application, measures the extent to which the required changes to the application source code are actually carried out in-house, on time,or can be carried out by third parties. As illustrated by the graph below, a web application to which there is no access, can only be protected sensibly by a WAF (additional benefit of the WAF),.Even with an application in full access, a WAF can be used as a central service point for various services such as secure session management, which can be implemented for all applications equally, and as a suitable means for proactive safety measures such as URL encryption.

Download

or read more here.


Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ mercredi 2 novembre 2011 0 commentaires

Radware Web Application Firewall-AppWall

Web application(s) are not secure any more, new web vulnerability and the way of attack discover everyday. By doing a penetration testing with different tools does not means that your web application secure, there are different vulnerability may find on the web application. For a manual security you need a fast team to update the operating system and application software's.

There are different firewalls or IDS/IPS available to secure a web application.
Radware’s AppWall is a Web Application Firewall (WAF) appliance that secures Web applications and enables PCI compliance by mitigating web application security threats and vulnerabilities. It prevents data theft and manipulation of sensitive corporate and customer information.


It provides full protection against the web application level attack like.
  • Full coverage out-of-the-box of OWASP top-10 threats ─including injections, cross site scripting (XSS), cross site request forgery (CSRF), broken authentication and session management and security mis-configuration .
  • Data leak prevention – identifying and blocking sensitive information transmission such as credit card numbers (CCN) and social security numbers (SSN).
  • Zero-day attacks prevention – AppWall positive security profiles limiting the user input only to the level required by the application to properly function, thus blocking also zero day attacks. The positive security profiles are a proven protection against zero-day attacks.
  • Protocol validation – AppWall enables HTTP standards compliance to prevent evasion techniques and protocol exploits.
  • XML and Web services protection - AppWall offers a rich set of XML and web services security protections, including XML validity check web services method restrictions, XML structure validation to enforce legitimate SOAP messages and XML payloads.
  • Web application vulnerabilities – signature protection offer the most accurate detection and blocking technology of web application vulnerability exploits. AppWall negative security profiles offers comprehensive attack protection.
Click here to learn more.


    Note: If you want to learn more about Linux (Backtrack 5) and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

    ~ vendredi 15 juillet 2011 0 commentaires

    Patriot NG: Host Based Intrusion Detection System

    Intrusion detection system (IDS) is very popular in the field of network security, for a complete disclosure of IDS read our previous article about it click here to understand IDS from basic, and click here learn about different types of IDS.

    Patriot NG is host based IDS, and it is design to work on Microsoft plate form, Patriot NG allows real time monitoring of operating system and the network.


    As by using the previous articles you have an idea what actually a host based IDS is? What it does? 
    Patriot NG is available on windows XP,VISTA and 7 plate form and it applicable on both 32-bit and 64-bit system.


    Key Feature 
    • Changes in Registry keys: Indicating whether any sensitive key (autorun, internet explorer settings...) is altered.
    • New files in 'Startup' directories
    • New Users in the System
    • New Services installed
    • Changes in the hosts file
    • New scheduled jobs
    • Alteration of the integrity of Internet Explorer: (New BHOs, configuration changes, new toolbars)
    • Changes in ARP table (Prevention of MITM attacks)
    • TCP/IP Defense (New open ports, new connections made by processes, PortScan detection...)
    • Files in critical directories (New executables, new DLLs...)
    • NIDS (Detect anomalous network traffic based on editable rules)
    Options
    • Windows contain a host file that stores the information about the host that is IP addresses of a system, some malware affect this host file and change the data.Patriot NG alert the administrator if this will happen.
    • New window may be occur on a background of this current windows this might be happen via malware. Whenever this thing happen Patriot NG warn you.
    • Patriot NG provide us a facility of securing the critical system files, when ever new changes has been made on a critical file system it warn you.
    • Patriot NG has a built-in function to secure the TCP/IP, when ever new port open it warn us, the port may be open via back door like netcat.  
    • When the new services will install on a system, patriot NG inform the administrator about it.
    • It is highly recommended to use patriot NG along Winpcap.
    • Patriot NG warn the administrator if a new driver will install on a system, some malware behave like a driver and they may install on a critical system file. 
    Download


    Windows XP, Windows Vista, Windows 7 (32Bits)
    Patriot NG 2.0

    Windows XP, Windows Vista, Windows 7 (64Bits)
    PatriotNG 2.0

    Video Demonstration 
    Note: If you enjoyed this post, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

    ~ vendredi 18 février 2011 0 commentaires

    Intrusion Detection System (IDS)

    On a earlier discussion we have precisely described Intrusion Detection System (IDS), if you have not read the previous story than it is recommended you to first read the previous story than continue to this story, because the basis of this article has been presented on previous article to read previous one click here.


    After reading the previous article you have an idea about the importance of IDS, as we have described the basis of IDS, at this artcile we will talk about the different type of IDS.

    Network Intrusion Detection Systems (NIDS)

    In network intrusion detection system each and every packet that travel across the network are analysed, by looking the packets IDS identify any miscellaneous activity on the network and it notifies the administrator about it. NIDS can be use on a single machine that wants to monitor its own traffic and it can be install to major the network traffic by single machine. Example Tool:

    Host Intrusion Detection Systems (HIDS)


    Rather than analysing network packets like NIDS, HIDS monitors the computing system. The abilities of HIDS including log analysis, event correlation, integrity checking, policy enforcement, rootkit detection, and alerting.In general it takes snap shots of an exciting system and compare it with the previous snap shot that has been taken before it.
    If the system files modified delete or something unusual occur than it will notify the administrator about it. Example Tool:

    Intrusion Detection Systems Can Provides 
    • Increase the security and management of IT infrastructure.
    • Can detect and report if any attack occur
    • It can detect errors on critical files
    • IDS can guide administrator to develop network polices 
    • It can report if any alteration occur 
    Limitation Of Intrusion Detection Systems
    • IDS cannot identify the weak authentication mechanism.
    • If the network is busy than it cannot analyse all the taraffic
    • It require administration signal to conduct investigation of attack.
    Video Demonstration Of OSSEC







    Note: If you enjoyed this post, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

    ~ mercredi 16 février 2011 0 commentaires

    Intrusion Detection System

    If you are interested in network security, or if you are interested in data mining, or if you are interested in computer security than you must know about Intrusion Detection System (IDS).

    Intrusion Detection System (IDS) have become very popular in many years because the variation in intruder, we are living on the age of technology the researcher and security expert facing many challenges daily, so there is a need to create such a thing that can monitor the entire network.

    In the field of information security intruder means a hacker or a cracker or simply a abnormal activities, if an attacker get access into the network than the attacker try to steal the sensitive information that can caused great harm to the company, means everything is data.
    There are firewall to protect these attacker so why we need the new term that is IDS.
    Limitation Of Firewall

    Although firewalls are good to secure a computer network, but firewalls has some limitation, firewall is simply a wall between your computer network and the outside world(Internet). it allows some traffic to pass and block some traffic to being enter into the network it cannot make decision on the basis of the incoming packet. There are different ways to bypass and cheat the firewalls. It cannot help you when:
    • Connections that circumvent it 
    • New threat
    • A malicious program hide in the attachment of the e-mail
    Overview Of Intrusion Detection System

    An Intrusion Detection System monitors the network traffic and take decision about the incoming and outgoing packets, these decision based on some information that has collected by IDS via its sensors. In short An intrusion detection system (IDS) is used to monitor the entire network, it detects intruders; that is, unexpected, unwanted or unauthorized people or programs on network. IDS provides the following:
    • OS (Operating system) audit
    • Monitor and analyze network traffic and user/system activity 
    • Auditing system for vulnerabilities 
    Intrusion Detection System (IDS) has multiple sensors used to monitor unexpected and unwanted activities.
    • A sensor monitor log files
    • A sensor monitor TCP ingoing or outgoing connections
    An Intrusion Detection System (IDS) can work manually but it is recommended and mostly IT administrator automate the IDS to ensure the security. we can categorize IDS into two main types:
    • Network Intrusion Detection Systems (NIDS)
    • Host Intrusion Detection Systems (HIDS)



    Note: If you enjoyed this post, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

    ~ jeudi 10 février 2011 0 commentaires