Affichage des articles dont le libellé est attack. Afficher tous les articles
Affichage des articles dont le libellé est attack. Afficher tous les articles

21,000 Customer's Bank Details Hacked| TalkTalk |




TalkTalk is one of the biggest broadband and phone service provider in the United Kingdom. A few days earlier it suffered a major breach of information when its servers were hacked and the data belonging to its over 4 million customers was compromised. In connection with this hack, the police arrested a 15 year old buy on whom the hacking was pinned to.

He was arrested after a police raid on a house in Liverpool that led to the arrest of the boy from the Antrim County in Liverpool. The company suffered a major blow due to this hacking incident and its shares in the stock exchanges in the UK fell significantly after the customers as well as investors displayed their concerns about the security measures taken by such companies.

Initially it was thought that the incident of the data security breach compromised the information of the all the 4 million users of the company. However, the company was soon to refute these claims stating that the attack was significantly less intense and damaging to the company then thought. In an official statement, the company stated that the information leaked was less significant and not useful to hackers. Information such as credit card numbers had been stored as “xxxx” in parts instead of completely storing them in numbers.

The company has now declared the actual number of affected users. It has been stated that bank account details around 21,000 of the customers of the company were stolen. In addition, debit and credit card details of around 28,000 customers were stolen and the names, email addresses and the phone numbers of 1.2 million customers were leaked.

TalkTalk has been a victim of such attacks twice earlier in this year. It faced similar attacks in February and then again in August. The three attacks pose serious security concerns about the company’s initiatives to tackle them.


~ dimanche 1 novembre 2015 0 commentaires

A 15 year old boy arrested for hacking TalkTalk



Scotland Yard has arrested a 15 year old boy in the Northern Ireland in connection with the hacking incident that breached the information stored with TalkTalk a United Kingdom based broadband and phone service provider.

The company has over 4 million customers across the United Kingdom and the attack on their website resulted in the breach of sensitive information of their customers. Consequent of the attack, the metropolitan police raided a house in Antrim County and arrested the boy on the suspicion of conducting the hack. He is charged for the offenses covered under the Computer Misuse Act.

The attack initially was considered grave and the company lost its market share value by 12 percent. However, later Dido Harding, the CEO of the company stated that the attack was not of very serious nature. Earlier it was thought that sensitive information such as the banking details of the customers could have been lost in the attack. But later it was found by the company that even if the data was last, it was only partial and did not comprise much of the information. For instance, the credit card data if stolen, would have XXXX instead of the numbers which means that this information is meaningless for stealing funds.

The boy is under the custody of the Police of Northern Ireland and is being investigated. There is ongoing inquiry into the incident and the premises from where the boy was arrested is continued being searched.


The investigation is conducted jointly by the Metropolitan Police Cyber Crime Unit (MPCCU) and Police Service of Northern Ireland (PSNI). Such attacks are of serious nature and the companies can potentially lose billions in damages caused due to the breach of the data of their customers. 


~ mercredi 28 octobre 2015 0 commentaires

SQL Injection Intermediate Level

This is a theoretical post about types of SQL Injection attacks and the concepts behind SQL Injection. I have added this here since so far we had been dealing with URLs, and will continue to do so. For the attacker, there is no direct way to write complete queries and he/she may only make changes to the URL or input form. However, the knowledge of MySQL (or any other DBMS) part of the attack is necessary, since it will be required when you deal with more robust websites where the standard attacks won't work and you need to get creative. Before reading this post, I recommend these 3:-



  • SQL Injection Basics (theoretical yet important)
  • Manual SQL Injection (using web browser only)
  • Automated SQL Injection using SQLMap (Kali Linux needed) 


  • Now we will proceed to the actual content of the post :-

    Types of SQL Injection attacks

    • SQL injection + insufficient authentication
    • SQL injection + DDoS attacks
    • SQL injection + DNS hijacking
    • SQL injection + XSS

    Technical implementations

    Incorrectly filtered escape characters

    This form of SQL injection occurs when user input is not filtered for escape characters and is then passed into a SQL statement. This results in the potential manipulation of the statements performed on the database by the end-user of the application.
    The following line of code illustrates this vulnerability:
    statement = "SELECT * FROM users WHERE name ='" + userName + "';"
    This SQL code is designed to pull up the records of the specified username from its table of users. However, if the "userName" variable is crafted in a specific way by a malicious user, the SQL statement may do more than the code author intended. For example, setting the "userName" variable as:
    ' or '1'='1
    or using comments to even block the rest of the query (there are three types of SQL comments). All three lines have a space at the end:
    ' or '1'='1' -- 
    ' or '1'='1' ({
    ' or '1'='1' /*

    renders one of the following SQL statements by the parent language:
    SELECT * FROM users WHERE name = '' OR '1'='1';
    SELECT * FROM users WHERE name = '' OR '1'='1' -- ';
    If this code were to be used in an authentication procedure then this example could be used to force the selection of a valid username because the evaluation of '1'='1' is always true.
    The following value of "userName" in the statement below would cause the deletion of the "users" table as well as the selection of all data from the "userinfo" table (in essence revealing the information of every user), using an API that allows multiple statements:
    a';DROP TABLE users; SELECT * FROM userinfo WHERE 't' = 't
    This input renders the final SQL statement as follows and specified:
    SELECT * FROM users WHERE name = 'a';DROP TABLE users; SELECT * FROM userinfo WHERE 't' = 't';
    While most SQL server implementations allow multiple statements to be executed with one call in this way, some SQL APIs such as PHP's mysql_query() function do not allow this for security reasons. This prevents attackers from injecting entirely separate queries, but doesn't stop them from modifying queries.

    Incorrect type handling

    This form of SQL injection occurs when a user-supplied field is not strongly typed or is not checked for type constraints. This could take place when a numeric field is to be used in a SQL statement, but the programmer makes no checks to validate that the user supplied input is numeric. For example:
    statement := "SELECT * FROM userinfo WHERE id =" + a_variable + ";"
    It is clear from this statement that the author intended a_variable to be a number correlating to the "id" field. However, if it is in fact a string then the end-user may manipulate the statement as they choose, thereby bypassing the need for escape characters. For example, setting a_variable to
    1;DROP TABLE users
    will drop (delete) the "users" table from the database, since the SQL becomes:
    SELECT * FROM userinfo WHERE id=1;DROP TABLE users;

    Blind SQL injection

    Blind SQL Injection is used when a web application is vulnerable to an SQL injection but the results of the injection are not visible to the attacker. The page with the vulnerability may not be one that displays data but will display differently depending on the results of a logical statement injected into the legitimate SQL statement called for that page. This type of attack can become time-intensive because a new statement must be crafted for each bit recovered. There are several tools that can automate these attacks once the location of the vulnerability and the target information has been established.

    Conditional responses

    One type of blind SQL injection forces the database to evaluate a logical statement on an ordinary application screen. As an example, a book review website uses a query string to determine which book review to display. So the URL http://books.example.com/showReview.php?ID=5 would cause the server to run the query
    SELECT * FROM bookreviews WHERE ID = 'Value(ID)';
    from which it would populate the review page with data from the review with ID 5, stored in the table bookreviews. The query happens completely on the server; the user does not know the names of the database, table, or fields, nor does the user know the query string. The user only sees that the above URL returns a book review. A hacker can load the URLs http://books.example.com/showReview.php?ID=5 OR 1=1 and http://books.example.com/showReview.php?ID=5 AND 1=2, which may result in queries
    SELECT * FROM bookreviews WHERE ID = '5' OR '1'='1';
    SELECT * FROM bookreviews WHERE ID = '5' AND '1'='2';
    respectively. If the original review loads with the "1=1" URL and a blank or error page is returned from the "1=2" URL, and the returned page has not been created to alert the user the input is invalid, or in other words, has been caught by an input test script, the site is likely vulnerable to a SQL injection attack as the query will likely have passed through successfully in both cases. The hacker may proceed with this query string designed to reveal the version number of MySQL running on the server:
    http://books.example.com/showReview.php?ID=5 AND substring(@@version,1,1)=4
    , which would show the book review on a server running MySQL 4 and a blank or error page otherwise. The hacker can continue to use code within query strings to glean more information from the server until another avenue of attack is discovered or his or her goals are achieved.

    Second Order SQL Injection

    Second order SQL injection occurs when submitted values contain malicious commands that are stored rather than executed immediately. In some cases, the application may correctly encode a SQL statement and store it as valid SQL. Then, another part of that application without controls to protect against SQL injection might execute that stored SQL statement. This attack requires more knowledge of how submitted values are later used. Automated web application security scanners would not easily detect this type of SQL injection and may need to be manually instructed where to check for evidence that it is being attempted.

    This post is licensed under Creative Commons Attribution-ShareAlike 3.0. This license permits sharing, but requires attribution and that the content be shared under same or similar license . The source of the content in this page is -
    https://en.wikipedia.org/wiki/SQL_injection
    License details can be read here https://en.wikipedia.org/wiki/Wikipedia:Text_of_Creative_Commons_Attribution-ShareAlike_3.0_Unported_License

    Blind SQLi Tutorial

    You may read this tutorial if you have gone through the content of this page and are ready to go to the next level.

    ~ mardi 17 février 2015 0 commentaires

    Denial Of Service Methods : ICMP, SYN, teardrop, botnets

    Introduction to Denial Of Service



    In a previous post, I had introduced you to the basic idea of a denial of service attack. We used real life examples (bus stop and online game) to depict the idea behind a DOS attack. We crashed our own Windows and Kali Linux machine (using batch and command line interface respectively). Now it's time to learn how actually DOS of service attacks work, in terms of packets and other networking terms. So here is a one by one description on four of the well known attacks.

    Various methods of Denial Of Service attack

    ICMP flooding (smurfing)

    Before I go off explaining what the attack is, first I'll tell you about the packets.
    Contents of an ICMP packet (should not bother you currently)
    ICMP packets have two purposes (technically)-
    • It is used by network devices, like routers, to send error messages indicating, for example, that a requested service is not available or that a host or router could not be reached
    • It is also used to relay query messages
    Practically, all an ICMP packet does is confirm connectivity. You send a message to an IP and see if you are connected. If not, you get an error like "Destination unreachable". Pings use the ICMP packet.
    While the packet as a whole allows us to directly attack the network by flooding it with a lot of ICMP packets, the second ability listed above gives us a new advantage. We can send ICMP relay packets to a network, with a spoofed source IP (we will change our IP to that of target), and when the network will replay to our packet, it will reply to the spoofed IP, causing it to be flooded with ICMP packets. This is called indirect ICMP flooding, also known as smurfing. It is tougher to detect than a normal direct ICMP attack, and the network serves as amplifier, the larger the better, making the attack much stronger, since you have the power of many computers at your disposal, instead of just one. If the target is flooded with enough packets, it loses it ability to respond to genuine packets, resulting in a successful Denial of Service attack.


    SYN flooding

    The three way handshake (that didn't happen in our case)
    In SYN flooding, the attacker send the target a large number of TCP/SYN packets. These packets have a source address, and the target computer replies (TCP/SYN-ACK packet) back to the source IP, trying to establish a TCP connection. In ideal condition, the target receives an acknowledgement packet back from the source, and the connection established is in a fully open state. However, the attacker uses a fake source address while sending TCP packets to the victim, and the target's reply goes to an inexistent IP, and therefore, does not generate an acknowledgement packet. The connection is never established, and the target is left with a half open connection. Eventually, a lot of half open connections are created, and the target network gets saturated to the point where it does not have resources left to respond to the genuine packets, resulting in a successful DOS attack. Also, since the connections stay open for a while, the server loses its ability to work for a good amount of time after the attack has been stopped.

    Teardrop attack

    First of all - In computer networking, a mangled or invalid packet is a packet — especially IP packet — that either lacks order or self-coherence, or contains code aimed to confuse or disrupt computers, firewalls, routers, or any service present on the network. (source : Wikipedia)
    Now in  a teardrop attack, mangled IP packets are sent to the target. They are overlapping, over-sized, and loaded with payloads. Now various operating systems have a bug in their TCP/IP fragmentation re-assembly code. What that means, is when the OS tries to re-assemble the TCP/IP packets that it gets, a piece of code exploits a bug in the way the re-assembling process works, and the OS crashes. This bug has been fixed, and only Windows 3.1x, Windows 95 and Windows NT operating systems, as well as versions of Linux prior to versions 2.0.32 and 2.1.63 are vulnerable to this attack. This type of attack does not require much bandwidth on the user side, and has devastating effect for the targeted server.

    Botnets

    A small botnet
    Now, this is not an attack is such, rather, it is a way of carrying out the attacks more effectively. When carried out against a large server, the above attacks usually prove ineffective. Your home router is nothing when compared to the HUGE servers that big websites have, and handling a single PCs DOS effect can be a piece of cake. This leads to the need of a Distributed Denial of Service attack. In a distributed denial of service, hacking groups use their numbers as strength. For example, if you have 500 friends who know how to carry out a denial of service attack, then the combined impact is much more dangerous than that of a lone PC. However, it is not always possible to have 500 hackers next door, and not all of us are part of large black hat hacking organisations. 
    Try not to end up like this
    This is where the botnets steps in. Now the bad guys use tools called RATs (remote administration tools) to infect and get total control over computers over the internet. The RATs are a kind of trojan, and can lie there on your PC and you'll never find out. By the use of crypting, some hackers have mastered anti-virus evasion, and these RATs can lie undetected on your PC for years. This is 100% illegal. You can easily end up in jail for this, and I recommend that you stay away from this. But, its important that you are aware of the existence of such tools, and more importantly, what the hackers can do with them. Now lets assume you made a RAT and its has infected 10,000 people. You can actually control those 10,000 computers. Now there's this website server that you don't like, and you're this badass hacker who takes down stuff he doesn't like. No, you don't have a warehouse full of networking power (servers), but you do have ten thousand computers at your disposal, and this is called a botnet. You also have 5 friends who are hackers, and have similarly sized botnets. Such immense networking power can easily take down a large website for hours, if not days. The results of flooding packets from 50,000 computers can be catastrophic. With modern day firewalls, it is almost impossible to flood servers and take them down using one single computers, so while botnets are the most unethical entities, they are also the most powerful. Now here is a suggestion, Denial of Service attacks are easy to trace back (if you are a beginner), and even if you are good, there is always someone better, and you can't hide forever. So try not to send bad packets at random websites, you won't look good in orange 


    ~ lundi 28 avril 2014 0 commentaires

    Web Application Attack and Audit Framework (W3AF)- Tutorial


    Security is key point for every effective business, either you are running your own website or you are at job to manage the web application for your company you have to do little penetration testing to check the security of web application.
    Now a days exploit are available and update on daily basis for different web application services.

    While doing a penetration testing a pen tester must consider these exploit for different vulnerabilities.
    To find a vulnerabilities is not enough a pen-tester must check the parallel exploits that are available publicly for different services.


    w3af is a Web Application Attack and Audit Framework. The project goal is to create a framework to find and exploit web application vulnerabilities that is easy to use and extend. w3af is working for Become the best Open Source Web Application Exploitation Framework. It provides information about security vulnerabilities and aids in penetration testing efforts.

    The important fact of w3af is that it is available for all major operating system like Microsoft Windows, Linux, MAC OS, FreeBSD and OpenBSD etc. It is written in python programming language and provide both command line interface and graphical user interface.

    W3af_15

    W3af uses more than 130 plug-in to find vulnerabilities in web applications, after finding vulnerabilities like SQL injections, OS commanding, remote file inclusions (PHP), cross-site scripting (XSS), and unsafe file uploads, can be exploited in order to gain different types of access to the remote system.

    Download
    Tutorial
    Once you have all the prerequisites then you can start w3af as follows:
    $ ./w3af
    w3af>>>

    Type help will give you a list of options.


    w3af>>> help
    The following commands are available:

    help                  You are here. help [command] prints more specific help.
    url-settings       Configure the URL opener.
    misc-settings    Configure w3af misc settings.
    session             Load and save sessions.
    plugins             Enable, disable and configure plugins.
    start                 Start site analysis.
    exploit              Exploit a vulnerability.
    tools                 Enter the tools section.
    target               Set the target URL.
    exit                   Exit w3af.

    w3af>>>
    Now see this example:

    w3af/plugins>>> audit xss
    w3af/plugins>>> audit
    Enabled audit plugins:
    xss
    w3af/plugins>>> discovery webSpider,pykto,hmap
    w3af/plugins>>> discovery
    Enabled discovery plugins:
    webSpider
    pykto
    w3af/plugins>>> output console,htmlFile
    w3af/plugins>>> output
    Enabled output plugins:
    htmlFile
    console
    w3af/plugins>>> output config htmlFile
    w3af/plugin/htmlFile>>> view

    ~ mercredi 28 septembre 2011 0 commentaires