Affichage des articles dont le libellé est Review. Afficher tous les articles
Affichage des articles dont le libellé est Review. Afficher tous les articles

Recovering the Lost Data using EaseUS

It doesn’t matter whose fault it is, when data is gone it’s a big trouble. When a file you need is gone, all you really want to do is get it back. Everyone wants to get their files back safe and without any data loss, that is the main concern.

As long as storage device is not dead, there are chances to recover data that is somehow deleted, corrupted, virus attack, formatted mistakenly or any other case. Choosing the best recovery tool in such cases is a headache. Not every recovery tool is free or promising to recover all the lost files. Files like wedding images, personal pictures, contract files, other personal files are highly precious to an individual and no one can tolerate to lose any of these.

For organizations their data is everything, once data is lost or corrupted, they will be in a big trouble. The solution for this is quite simple; backup your data before it’s too late. EaseUS brings you the solutions for your entire headache by providing you FREE data recovery software, which will solve every data loss problem.

EaseUS data recovery is the best solution for all kind of data recovery. Whether it’s deleted, formatted, damaged, virus attacked, operating system crash or any partition failure data; you can simply recover it by EaseUS data recovery software.

You can even recover formatted USB data easily. EaseUS is one of its own kind. It’s free to download and simple to use. With simple 3 steps you can recover your files. This free recovery software also provide with specialized features like bootable media for emergency that let you recover data even when system fails to start or crash.

Easy recovery process lets you recover your data like never before. To recover your data you don’t need IT background anymore, just follow these three simple steps to recover your files:

Step 1:
Download EaseUS FREE Data Recovery Wizard and launch the program from your pc or laptop.
Step 2: Follow the interface instructions and start the scan of your device (laptop, pc or removable device). You can also filter your search by name, size, date or type. 

Step 3:
Select the data you wish to recover from the results preview after the search completes. 



Now don’t risk your critical data and download EaseUS data recovery software. Don’t stuck yourself in finding right solution for recovery, EaseUS is the straightforward solution to recovering lost data and files. Don’t be the one who regrets the chances he didn’t take. 

~ jeudi 14 juillet 2016 1 commentaires

Review: EaseUS Todo Backup & Free Giveaway

Have you ever felt the pain of losing the data? If not, then you are the lucky person, but how long your luck will support you? If you have witnessed the situation where you were losing the data, then believe me, you know exactly how hard the recovery process is. Disaster recovery is an untold story of every IT professional, whether you are a home user or a corporate professional; somewhere in your mind, you have the fear of losing the data. What, how and why? Many questions, and only one answer. Backup tool with plan!



Before becoming a victim, let’s adopt a smart strategy to create a backup of your system. EaseUS Todo Backup is the finest solution in the market that let you to automate the backup tasks. They have multiple solutions to cater your need, from home user to business users. Some of the notable features are:


  • Free and Reliable: EaseUS Todo Backup is available for free for home users. And it allows you to backup your entire system and recover it to the original state, after the disaster.
  • You can backup the entire disk, any specific partition, or even individual files 
  • Outlook backup and recovery 
  • Various backup options to choose from: full backup, incremental backup and differential back.  
  • Unattended backup: If you are managing server, then you are more likely not attending every server every day. But, EaseUS Todo Backup can be executed as windows service to create a backup of a server while slept, hibernated and even logged out.
  • Disk Clone: Create the clone of your disk, disk clone is the right solution to upgrade the disk and to transfer the data. 
  • Email notification: Stay up to date from the performance of your software. EaseUS todo backup sends notification of the executed command/function. 
  • If you are searching a disk cloning software, then stop your searches now, EaseUS Todo backup provides the solution to create the clone of your disk.



You must be curious about the price. Well, what about a free giveaway? Download the EaseUS Todo Backup and get your keys via email. 

http://www.easeus.com/backup-software/tb-home.html

Answer the below question and make the comment to increase your chances of success, only 10 lucky winners will get the license.


Enter your information to get the EaseUS Todo Backup for FREE

* indicates required


~ mardi 13 octobre 2015 0 commentaires

ClickSSL Review - Trusted SSL Certificates Provider at Reasonable Price

SSL or secure socket layer is crucial for today's website, whether you own a small website, large eCommerce platform or even corporate website; you need SSL to establish a secure and encrypted channel that ensures the security at the transport layer of the OSI model.

It is very common and we at ehacking, used to face the questions of the users who want to purchase/configure SSL for their respective websites. There are many factors that one should consider before making the purchase because at the end of the day security of users' data is salient.

https://www.clickssl.com/

Why SSL? What are the key Benefits?

As an Internet savvy, you must have seen that all the reliable and renowned brands/websites are using SSL, why they are using? They are not fools; they know the benefits and outcomes that SSL certificate can give to a website. 

The foremost benefits of SSL are as follows:

Encryption

Encryption is the one the key benefit that you can get by using SSL certificate, the end data cannot be sniffed by the hackers. Encryption provides peace of mind because the sensitive data can only be read by the intended parties. Use SSL to avoid the dangerous hacking attack like, Man-in-the-Middle attack and other types of sniffing.

 

Fight against Phishing

Phishing is when hackers create a clone of a website that looks exactly like a real one and they used to circulate this fake page on the Internet to get the credit card and other valuable information of the users, however it is way too hard for them to get the authenticate SSL certificate. As a result, customers are reluctant to provide their information because the absence of the authenticate SSL certificate.

 

Improve Customer Trust

Customer trust comes when they find the business care about them and their data because the security of users' data is salient.

Apart from the securing website there is one more huge benefit of SSL Certificate in business. Yes, in August Google announced that SSL Certificate sites will get improvement in Google ranking.

 

How to Choose SSL Certificate for Website?

There are very important facts to be considered before purchasing SSL Certificates from any vendor for example: customer support, browser acceptance, pricing, ease of installation & many more. Each and every business has their own requirement for SSL Certificates. If you own an ecommerce business then EV SSL certificate is best suited for your business. Apart from that the importance of SSL certificate in ecommerce business has increased to gain customers trust, secure online transaction and remove cyber threat.

Types of SSL Certificate

Single Domain SSL – Secure the website URL only (https://mydomain.com)

Wild Card SSL – Secure the website URL and its unlimited sub-domains (https://mydomain.com https://mail.mydomain.com)

Multi Domain SSL - SSL certificate that secures multiple domain names and multiple host names within a domain name

Why ClickSSL?

ClickSSL is the reputed name in the industry and they provide SSL certificates at a cheaper price from trusted & reputed brands like Semantec, GeoTrust, Thawte & RapidSSL. They are helping small, medium and large businesses by providing secure and trusted SSL Certificates & 100% support from last 6 years. These certificates provide amazing benefits to its customers like Vulnerability Assessment, Malware Scanning & many more with 99.9% browser compatibility.



ClickSSL has very flexible pricing structure for all SSL Certificate brands with huge discount. Apart from the regular pricing structure, it also provides bargain price offers along with deals, coupons and other promotional offers which are matchless. Their regular pricing structure is far better than the other market players.


ClickSSL Services & Support

Customer support and browser acceptance are the important aforementioned factors, and ClickSSL has 99.9% browser recognition; their SSL Certificates almost compatible with every browser available today including Chrome, Mozilla, IE & Opera. Apart from desktop browser, their certificate supports mobile devices (Windows, iPhone, Blackberry, Android, and Symbian OS) too.

ClickSSL also provides 30 days money back guarantee on certificates like RapidSSL, Thawte and Symantec. When we talk about customer support, their consummate employees provide complete support via live chat, Email Chat along with SSL Certificate Installation help and some other methods are also available.

Before concluding let's remind the essential parameters that should be considered before taking any decision regarding the SSL certificate, select wisely because it will create an impact; positive or negative impact choice is yours.




~ lundi 23 mars 2015 0 commentaires

Web Application Penetration Testing with bWAPP


http://www.ehacking.net/2014/02/web-application-penetration-testing.html
Web application security is today's most overlooked aspect of securing the infrastructure. These days, hackers are concentrating their efforts on our precious websites and web applications. Why? Websites and web applications are an attractive target for cyber criminality and hacktivism because they are 24/7 available via the Internet. Mission-critical business applications, containing sensitive data, are often published on the Internet through our web applications. In addition, traditional firewalls and SSL provide no protection against web attacks, and systems engineers know little about these sophisticated application-level attacks…
It’s definitely time to improve our web security! Defense is needed… downloading and playing with bWAPP can be a first start… Wanted: superbees.
bWAPP, or a buggy web application, is a deliberately insecure web application. It helps security enthusiasts, systems engineers, developers and students to discover and to prevent web vulnerabilities. bWAPP prepares to conduct successful web application penetration testing and ethical hacking projects. It is made for educational purposes.


What makes bWAPP so unique? Well, it has over 60 web bugs! bWAPP covers all major known web vulnerabilities, including all risks from the OWASP Top 10 project.
[The OWASP Top 10 provides an accurate snapshot of the current threat landscape in application security and reflects the collaborative efforts and insights of thousands of accomplished security engineers. To reflect the ongoing changes in technology and common online business practices, the list is periodically updated.]
Some of the vulnerabilities included in bWAPP:
  • Injection vulnerabilities like SQL, XML/XPath, LDAP, HTML, SSI, Command and SMTP injection
  • Cross-Site Scripting (XSS), Cross-Site Tracing (XST) and Cross-Site Request Forgery (CSRF)
  • AJAX and Web Services issues (JSON/XML/SOAP)
  • Malicious, unrestricted file uploads and NSA backdoor files ;)
  • Authentication, authorization and session management issues
  • Arbitrary file access, directory traversals, local and remote file inclusions (LFI/RFI)
  • Configuration issues: Man-in-the-Middle, cross-domain policy file, information disclosures,...
  • HTTP parameter pollution and HTTP response splitting
  • Denial-of-Service (DoS) attacks, insecure WebDAV and FTP configurations
  • HTML5 ClickJacking, cross-origin resource sharing (CORS) and web storage issues
  • Unvalidated redirects and forwards
  • Parameter tampering, cookie poisoning and insecure cryptographic storage
  • And much more…
bWAPP is a PHP application that uses a MySQL database. It can be hosted on Linux, Windows and Mac with Apache/IIS and MySQL. It can also be installed with WAMP or XAMPP. Another possibility is to download the bee-box
The bee-box is a custom Linux VMware virtual machine pre-installed with bWAPP. It is compatible with VMware Player, Workstation, Fusion, and with Oracle VirtualBox. It requires zero installation! bee-box gives you several ways to hack and deface the bWAPP website. Currently there are 10 website defacement possibilities! It's even possible to hack the bee-box to get full root access, using a local privilege escalation exploit… With bee-box you have the opportunity to explore, and exploit, all bWAPP vulnerabilities! Hacking, defacing and exploiting without going to jail... how cool is that?
You can download bWAPP from here. You can download bee-box from here.
Both are part of the ‘ITSEC Games’ project. The ‘ITSEC Games’ are a fun approach to IT security education. IT security, ethical hacking, training and fun... all mixed together!





Take a look at our ‘What is bWAPP?’ introduction guide, including free training materials and exercises. There is also a free cheat sheet available… Follow us on Twitter, and receive this cheat sheet, updated on a regular basis, including the latest hacks and hardening tweaks.
Have fun with this free and open source project!
Education, the most powerful weapon which we can use to secure the world.”
Cheers, Malik Mesellem (@MME_IT)


External links

~ mardi 18 février 2014 0 commentaires

5 Android Security Apps


http://www.ehacking.net/2014/01/5-android-security-apps.html
Android operating system is at hit list of hackers, security researchers have previously found many malicious code circulating in the android market. The android can be exploited by severals ways and the most common vulnerability that hackers used to use is lack of awareness and right prevention tools and techniques. Following article is the review of top best android security applications available in Android market.


Avast Mobile Security & Antivirus


Protect your Android™ phone and tablet with the top-rated (4.6 stars!) free mobile security app with both antivirus and anti-theft.
  • avast! Mobile Security keeps your device safe from viruses, malware, and spyware.
  • It helps you locate your lost phone through our web-based phone locate feature.
  • Remote device lock and/or memory wipe in its advanced Anti-Theft component keep your data safe.
  • Handy tools like network meter, app manager, and even firewall (on rooted phones) give you complete control of your mobile phone.

Avira Free Android Security

Image Credit

Unique protection from malicious apps, device theft & unwanted calls.

  • Remotely track/locate your phone or tablet
  • Scan all apps with superior antivirus certified by AV-Test.org
  • Remotely lock or wipe your device to guard your privacy
  • Prevent annoying contacts from calling/texting you

 

 

ESET Mobile Security & Antivirus


Android Market

Protection for Your Data and Your Mobile Adventures

ESET Mobile Security excels with 99.7% detection rate (source: AV-TEST May/June 2013)
ESET offers a slick security suite for Android smartphones, which impressed us with its intuitive interface. The functionality of ESET Mobile Security is equally well thought-out (Source: AV-Comparatives August 2013)
Enjoy your time online, social networking or shopping, protected by ESET technology that has been successfully protecting customers for a record breaking 10 consecutive years (source: Virus Bulletin, VB100 Awards).

IKARUS Mobile Security


Image Credit
Android Market

IKARUS mobile.security – the award-winning antivirus solution for Android protects your smartphone or tablet reliably against malware in apps and from the Internet. Find and remove viruses, trojans, spyware, adware and other malware without impacting your battery or memory.
The benefits of IKARUS mobile.security:

  • daily updates for the latest threats
  • reliable protection and support directly from IKARUS technicians
  • support for multiple languages (German, English, Italian, Spanish, French, Chinese)
  • upgrade option / test licence for full version (incl. URL filter, protection against theft and text messaging spam)

Trend Micro Mobile Security & Antivirus


Android Market

Image Credit
Protect your privacy, find your phone or tablet when you lose it, backup your photos and videos, improve your Facebook privacy and identify malicious apps that steal your info including fake banking apps. Trend Micro Mobile Security provides 99.9% detection according to Av-test.org and is also certified by PCSL and AV-Comparatives.

The Free version includes an Anti-virus scanner, 50MB of cloud storage, privacy scanner for Facebook and a 30day trial of the premium features. After 30 days you can upgrade to the premium version or keep using the free features.
Premium (PAID) Version includes:

  • Lost Device Protection: includes anti-theft features that let you find, lock and wipe a missing device.
  • Data Theft Scanner: warns you of apps that potentially steal your information
  • Safe Surfing and Call & Text Filtering: keeps you and your kids safe by avoiding unwanted contact and content
  •  
     

Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ lundi 6 janvier 2014 0 commentaires

InfoSec Institute CISSP Course Review


Certifications are very important in the field of information security. There are various organizations out there who provide different certificates that measure an individual’s skills from beginner to advance and which even include qualifications for the managerial aspects of information security. You might have heard about different certifications like skill sets such as ethical hacking, computer forensics, and most definitely, CISSP. A Certified Information Systems Security Professional (CISSP) is an individual who has acquired a skill set recognized internationally by the International Information Systems Security Certification Consortium; formally known as (ISC)2.


The CISSP is a well known and an important certificate that increases the value of a certificate holder. According a 2006 study by Certification Magazine, “The CISSP by (ISC)2 is a top paid certificate in IT.” Personally I believe that anyone who acquires basic penetration testing certification should then take the CISSP because it offers many advantages. In my case, I decided to take the CISSP exam but was worried about getting the right training. I spent a lot of time researching CISSP certification and training courses, and was particularly meticulous because there are so many online institutes available. This plethora of instructions means thatthe reputation of an institute is very important. After careful consideration, I decided to train at the . There were various factors that contributed to my decision to study at InfoSec Institute, and after completing the course, I decided to write a review so that others can learn what to do and what not to do.

I went to the CISSP certificate page of InfoSec Institute’s website, and I got a lot of information about the certificate. For example, I learned about the benefits of having the certificate, directions for a likely career path, and the expected salary level. The same page also contains information about the certification process and information regarding how to become a certificated CISSP professional, which is very helpful for anyone seeking general CISSP information. The InfoSec Institute program has over 93% success rate, which is a very good percentile. Of-course, I also went to the CISSP Boot Camp page, and learned that the Institute describes their program stating:

“You will leave the InfoSec Institute CISSP Boot Camp with the knowledge and domain expertise to successfully pass the CISSP exam the first time that you take it. We have 'best-in-the- industry' 93% pass-rate.”

 
On the same page I found out where they provide training, and even learned that they can provide the on-site training at your location. However, it was very difficult for me to physically travel to a training site so I decided to take CISSP Boot Camp Online Training, which allowed me to take the training at any time and at any location.

Right after the registration process, I went to the online portal of InfoSec Institute for CISSP training. They categorized each lecture in a form of a module, which was very helpful.


The Instructor

In any course, the instructor plays an important role, and I was worried about learning from an online instructor. I was concerned about his or her ability to deliver the proper course material, and about the methods adopted for online teaching (which I consider very important). The instructor of the course is J. Kenneth (Ken) Magee, and he has a very strong IT background. He is the president and owner of Data Security Consultation and Training, LLC and the senior instructor at InfoSec Institute. Prior to holding these positions, he was the chief information security officer for the entire Virginia Community College system, . Magee holds 20 certifications including: CISSP, CISA, ISO 27001 PA, Security+, and CDP.

The next most important thing for me is the course material. I wanted to know what the instructor going to teach me, so I went to the (ISC)2 official website review the basic information about the standard CISSP course. From this, I learned that the topics covered in the regular (non-online) course are: 

  • Access Control
  • Telecommunications and Network Security
  • Information Security Governance and Risk Management
  • Software Development Security
  • Cryptography
  • Security Architecture and Design
  • Operations Security
  • Business Continuity and Disaster Recovery Planning
  • Legal, Regulations, Investigations and Compliance
  • Physical (Environmental) Security

After comparing the online course to the regular course, I noted that similar modules are available through the online portal of InfoSec Institute’s CISSP program, which is very helpful for online students.




Modules

The first module is the introductory module which gives you information about the CISSP and (ISC)2. The most important part of the module is the exam overview, which covers the duration of the exam, the passing grade, total number of questions, types of the questions, and provides other relevant information. This module discusses the requirements for receiving the CISSP certificate, and explains what to bring and what not to bring to the examination.

Access Control:

This is the first domain of CISSP according to the (ISC)2 common body of knowledge and the second module of InfoSec Institute’s training portal. InfoSec Institute has divided this topic into three parts, which covers access control in depth. The overall module of the access control discusses the ways and techniques to create a security architecture that protects the information of any organization. The section also discusses how to create effective security mechanisms and possible attacks on the architecture. This module not only discusses logical security techniques, but also looks at physical ways to implement security measures, methods for controlling the flow of information, and best practices for implementing the most effective security mechanisms.

Telecommunications and Network Security:
Telecommunications and Network Security is the second module of CISSP and the third module covered by the InfoSec Institute portal. InfoSec Institute has divided this topic into three parts. This module primarily focuses on creating a secure network architecture and design. This is a very interesting topic because it includes both wired and wireless technology, IP addressing, and other logical and physical components of the network. Additionally, this topic discusses wireless
communication channels and their security. In summary, this course discusses integrity, availability, and confidentially.


Information Security Governance and Risk Management:

ISGRM (information security governance and risk management) is the third section according to (ISC)2 and the fourth module of InfoSec Institute’s Boot Camp portal. This class covers the roles and responsibilities of the CISSP certificate holder. The class also discusses security policies (how to implement and practice the policies), the risk management, and risk analysis. It includes information on security training and awareness and the standards of information security management. In short, the overall module discusses who owns what?

Software Development Security:

Software Development Security (which is also known as application system development security) is the fourth domain of the CISSP course according to (ISC)2’s common body of knowledge and the fifth module covered in InfoSec Institute’s portal. Software is always high risk, so the security of software is always a big concern. This module discusses the systems of a software development life cycle (how to apply the security in the overall software development process) and how to ensure the integrity and confidentially of data. This class also covers software testing techniques like black box testing and others.

Cryptography:

Cryptography is equally important and is designated as the fifth focus of CISSP according to the (ISC)2 common body of knowledge. It is listed as the sixth module covered by InfoSec Institute’s portal. This class teaches the basics of cryptography including the goals of cryptography, digital signatures, and encryption techniques. The module also covers the various types of attacks that can be launched using cryptography and cryptanalysis. The class also discussed key distribution techniques and the history of cryptography. It is the very interesting module, and I really enjoyed the example of the symmetric block cipher and others.

Security Architecture and Design:

Security Architecture and Design is the sixth topic of CISSP course and InfoSec Institute has listed it as the seventh module. This class discusses hardware and software (including OS) architecture security
and models,. It also discusses internationally recognized guidelines for security implementation; for example, the PCI-DSS and ISO. The module also looks at the importance of integrity models like Biba and Clark-Wilson.

Operations Security:

Operations security is the seventh module from the (ISC)2 CISSP common body of knowledge and it is available as the eight module of InfoSec Institute’s Boot Camp. This class teaches us how to manage
an incident and how to response to a particular event. This module also focuses on preventative techniques to ward off attacks, patches, and vulnerability management. The module also discusses change and configuration management, and provides information on operation security responsibilities for effectively installing patches and managing a backup. Logs are also covered (including firewall logs, IDS logs, server logs, etc.), along with auditing and other relevant topics on operation security.

Business Continuity and Disaster Recovery Planning:

This is the eighth point in the CISSP course, and of course, it is the ninth module in the InfoSec Institute portal. I was very happy while viewing the video of this topic, and was very excited to learn about business cycles and the importance of information security. Additionally, I was excited to learn how information security affects a company’s overall business plan; and this module had the answers to all of my questions. This module is very important because it allows you to learn about business impact analysis (BIA) and business continuity planning (BCP). The exciting part of this module is learning about possible threats and the disaster recovery planning process.

Legal, Regulations, Investigations and Compliance:

It is the ninth topic emphasized by CISSP certification, and it is a very important class that covers legal issues. I really enjoyed learning about computer crime laws and regulations. The module discusses the legal issues of cyber crime, what the cyber crime laws are, and how to investigate a possible crime. The module also looks at different codes of ethics.

Physical Security:

Physical Security is last module of the CISSP course, and it is also a very interesting class. This section addresses the threats and vulnerabilities of physical security. I really appreciated the instructor’s approach to linking physical security with a hacker and logical security. The module discusses physical boundaries, walls, lightning, and other important parameters of physical security.

Conclusion

My experience with the InfoSec Institute regarding the CISSP course was very good. Although it is a very dry course (which I think all of you already know), I really enjoyed my journey and found it very informative. In my opinion, there is a need to add some practical examples into the course material; I mean, it would be very helpful the instructor could provide examples that he had faced in real life. The examples that were given throughout the course were enough to understand the concept, but extra examples can grab the attention of the student. Overall, the course has helped me to prepare for the exam and provided useful material. The teaching style and the valuable information presented in the first module really helped me to prepare myself for the CISSP exam.






Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ jeudi 5 juillet 2012 0 commentaires

CrystalAEP - Anti-Exploit Protection Tool

CrystalAEP is designed to provide frontline protection against Internet-borne threats such as viruses and malware. Unlike the typical anti-virus program, Crystal does not attempt to recognise threats based on signatures, and does not require constant updating to protect against the latest threats. Crystal works instead by manipulating at-risk software while it runs to help form an environment which is hostile to Internet worms, malware and other types of malicious code.


Anti-virus software is generally designed to protect users from well known threats which have been analysed in a laboratory, and for which signatures have been released by the anti-virus company. This means that a typical anti-virus will not be particularly effective at blocking novel threats which have not been examined by the company's researchers, so no matter how fast the anti-virus company is in detecting the threat after it is discovered in the wild thousands of users will have already been successfully attacked by the time protective signatures are released.

As CrystalAEP does not require signatures to be effective, instead seeking to undermine the launch mechanisms employed by malicious code to install itself on a user's system, Crystal can be effective against the most novel threats right from day one. 

The idea behind CrystalAEP was first conceived by the author in late 2006 at the time that the infamous Windows Metafile exploit was being exploited all over the Internet. The Metafile exploit leveraged a flaw in the way that Windows handled certain types of images which provided malware developers with a means of running their malicious software on an unwitting user's system. The Metafile flaw was at the time being used to install malware, spyware and adware.

Crystal Anti Exploitation Protection Tool


CrystalAEP does not verify downloaded files or email attachments against a list of recognised viruses. Instead Crystal scuppers the ability of drive-by download attacks to succeed. It does this by altering the behaviour of the most at risk software programs (such as the email client and the web browser) to introduce checks at key points at which malicious software can be installed or observed in the first stages of execution, and preventing it preemptively from succeeding. 


Crystal is freeware for personal and business use. The software creates a minimal install footprint and can be removed at any time with ease.




Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ mardi 3 juillet 2012 0 commentaires

CERT Basic Fuzzing Framework (BFF)

The CERT Basic Fuzzing Framework (BFF) is a software testing tool that finds defects in applications that run on the Linux and Mac OS X platforms. BFF performs mutational fuzzing on software that consumes file input. (Mutational fuzzing is the act of taking well-formed input data and corrupting it in various ways, looking for cases that cause crashes.)





The BFF automatically collects test cases that cause software to crash in unique ways, as well as debugging information associated with the crashes. The goal of BFF is to minimize the effort required for software vendors and security researchers to efficiently discover and analyze security vulnerabilities found via fuzzing. 

Traditionally fuzzing has been very effective at finding security vulnerabilities, but because of its inherently stochastic nature results can be highly dependent on the initial configuration of the fuzzing system. BFF applies machine learning and evolutionary computing techniques to minimize the amount of manual configuration required to initiate and complete an effective fuzzing campaign. BFF adjusts its configuration parameters based on what it finds (or does not find) over the course of a fuzzing campaign. By doing so it can dramatically increase both the efficacy and efficiency of the campaign. As a result, expert knowledge is not required to configure an effective fuzz campaign, and novices and experts alike can start finding and analyzing vulnerabilities very quickly.

Some of the specific features BFF offers are:

  • Minimal initial configuration is required to start a fuzzing campaign
  • Minimal supervision of the fuzzing campaign is required, as BFF can automatically recover from many common problems that can interrupt fuzzing campaigns
  • Uniqueness determination through intelligent backtrace analysis
  • Automated test case minimization reduces the effort required to analyze results by distilling the test case to the minimal changes to the input data required to induce a specific crash
  • Online machine learning applied to fuzzing parameter and input file selection to improve the efficacy of the campaign
  • Distributed fuzzing support
  • Crash severity / exploitability triage




Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ jeudi 21 juin 2012 0 commentaires

Ghost USB Honeypot - USB Malware VIdeo

Ghost is a honeypot for malware that spreads via USB storage devices. It detects infections with such malware without the need of any further information.The honeypot was first developed for a bachelor thesis at Bonn University in Germany. Now development is continued by the same developer within the Honeynet Project.






Ghost is a honeypot for USB malware. It is capable of capturing malware that propagates via USB storage devices without any further knowledge. This is done by emulating a USB thumb drive and tricking malware into infecting the emulated device. Due to the fact that a machine must be infected in order for the virtual device to detect the malware, the honeypot is designed to run on Windows systems, which are mainly targeted by malware at the moment.


Currently, Ghost only supports Windows XP and is in an early development stage, although its concept has been shown to work well, and the code is stable. If Ghost detects an infection, then it will currently only report that the machine is possibly infected, without including any additional information.


Presentation



Download the latest version from google project.

~ samedi 16 juin 2012 0 commentaires

WebSploit Toolkit - Remote System Security Scanner

WebSploit is an open source project which is used to scan and analysis remote system in order to find various type of vulnerabilities. This tool is very powerful and support multiple vulnerabilities. 









Key Features


  • Autopwn - Used From Metasploit For Scan and Exploit Target Service
  • wmap - Scan,Crawler Target Used From Metasploit wmap plugin
  • format infector - inject reverse & bind payload into file format
  • phpmyadmin - Search Target phpmyadmin login page
  • lfi - Scan,Bypass local file inclusion Vulnerability & can be bypass some WAF
  • apache users - search server username directory (if use from apache webserver)
  • Dir Bruter - brute target directory with wordlist
  • admin finder - search admin & login page of target
  • MLITM Attack - Man Left In The Middle, XSS Phishing Attacks
  • MITM - Man In The Middle Attack
  • Java Applet Attack - Java Signed Applet Attack
  • MFOD Attack Vector - Middle Finger Of Doom Attack Vector
  • USB Infection Attack - Create Executable Backdoor For Infect USB For Windows
  • ARP DOS - ARP Cache Denial Of Service Attack With Random MAC


WebSploit


Click here to download the websploit. 

~ jeudi 31 mai 2012 0 commentaires

Backup & Restore Your Wi-Fi Passwords

By default all operating systems, including Linux, save passwords of previously connected Wi-Fi access points. There are ways to export these saved passwords to be used in other computers. Third party software like LastPass and WirelessKeyView can save your saved passwords, and import them to other computers. Mac users can use LastPass and 1Password to save their passwords, including Wi-Fi passwords.


Windows 7


Windows 7 by default saves the password that you enter while connecting to internet through Wi-Fi. Saved passwords can be backed up in a USB drive, but the only drawback is that passwords have to be exported one at a time for each Wi-Fi network. To save a Wi-Fi key/password, click on the wireless network symbol on the taskbar and click the Open Network and Sharing Center. In the Network Sharing Center window, click on Manage Wireless Network and you will see all your wireless networks listed in the Manage Wireless network window. Double click on the network that you want to export, and you will be taken to the properties page; in the properties page, select the option Copy this network profile to a USB flash drive. Follow the setting wizard instructions and you are good to go. The USB drive will have the setupSNK.exe file and a SMRTNTKY folder.

Use the USB drive to import the settings to different computers having Windows software (XP, Vista, 7).
To import the settings insert the USB device in your computer and run the setupSNK.exe file. On clicking the setupSNK.exe file, you will be prompted by a message window. Click yes to download the settings on to your computer.

LastPass


LastPass is utility software that manages passwords, be it for websites or Wi-Fi networks. Best part of LastPass is that it installs on to the browser as an extension. It has a feature to export and import Wi-Fi passwords; this feature is only available in version 1.9 or higher. You may need to run the Universal Installer to download this feature. When encountered with an error simple follow on screen instructions to run the Universal Installer. Passwords are saved into the LastPass Vault, which is sync with your computer.

Open your web browser and click the LastPass button. Select tools and go to Import From. Then click Wi- Fi Passwords and click Import in the new tab to save the saved Wi-Fi settings from your computer. You can use the check boxes to select networks that you want to import. Log on to LastPass from a different computer and select Export To (below Import From) and then Wi-Fi Passwords to download the settings on to your computer.

1Password


Similar to LastPass, 1Password is a password manager that saves and generates passwords. It’s available for Windows, Mac, Ipad and Android. Mac users have the option to use either Wi-Fi or Dropbox to sync their data with 1Password manager. Windows users just need to use Dropbox to sync all their data.
 
Ipad users can use the option Backup & Restore to backup their data. To do so, open 1Password and select Settings> Data> Backup & Restore. Remember that both your computer and IOS should be on the same Wi-Fi network to perform this process. Apple doesn’t allow third party apps to sync via USB drive.
WirelessKeyView

This software recovers all the stored wireless network keys/passwords in your computer. You can save the information in text/html/xml file. Best thing about this software is that it’s a freeware, unlike LastPass and 1Password. Be sure to download the latest version to get all the options. This software only works on Windows machine, starting from Windows XP.

Download the software from Nirsoft’s website and double click the .exe file. On start up, the program will show all saved wireless passwords in a list form. You can save the network that you want to export in to a text file by selecting Save Selected Items from file menu.

All above software products provide a myriad of features; however, WirelessKeyView only provides basic features like converting information regarding wireless network settings into text files. LastPass is the most versatile in respect to platform, because any operating system that can run Mozilla Firefox web browser can use LastPass; the software just installs an extension for the browser and supports Internet Explorer, Chrome and Firefox. Windows 7 user can rejoice as it has the option to export wireless network information on USB drive, and they don’t need to download anything extra for exporting Wi-Fi
passwords.

About the author: Margaret is a blogger by profession. She loves writing on environment and automotto. Beside this she is fond of books. She recently did an article on Concrete Walls. These days
she is busy in writing an article on autos india.

Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ jeudi 10 mai 2012 0 commentaires

Pentest.sh Penetration Testing Script for Backtrack 5

Penetration testing and Ethical hacking can be done by manually and automatically, both manual and automatic vulnerability scanning and hacking has their own importance like automatic process save time while manual hacking can find more vulnerabilities and so on. There are so many tools and techniques has been discussed before but in this article I will share a wonderful script written by phillips321 that can make the job of information gathering and enumeration easy.

The script has been designed for backtrack 5 operating system and it can work on backtrack 5 R1 too, the dependencies and the tools that has been mentioned in the script are :

#       nmap
#       sslscan
#       gnome-web-photo
#       arp-scan
#       dialog
#       onesixtyone
#       amap

On your backtrack 5 kindly use the terminal to install the dependencies by using 

apt-get install sslscan gnome-web-photo arp-scan dialog
The script as follows 

#!/bin/bash
#__________________________________________________________
# Author:     phillips321 contact through phillips321.co.uk
# License:    CC BY-SA 3.0
# Use:        All in one pentest script designed for bt5
# Released:   www.phillips321.co.uk
  version=2.1
# Dependencies:
#       nmap
#       sslscan
#       gnome-web-photo
#       arp-scan
#       dialog
#       onesixtyone
#       amap
# backtrack users can apt-get install sslscan gnome-web-photo arp-scan dialog
#
# ToDo:
#       nikto
#       add ability to launch nesssus against targets
#       ldapminer: wine ldapminer.exe -d -h ${ip}
#       add nfs connect followed by tree command
#       add snmp test using swaks --to user@example.com --server test-server.example.net
#       add uniscan http://${ip}:${port}/ | tee ${ip}.${port}.uniscan.txt
Get the complete script from here.

Since it is a bash script so all you need to do is to just copy the script and paste on your text editor "gedit" in backtrack 5 and then save it to whatever.sh 

Open the terminal, locate the directory where you have saved the script before and launch the script, for example

root@bt:~/Desktop# sh ehacking.sh

Share your experience with the script.


Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ lundi 26 mars 2012 0 commentaires