Monday, September 17, 2007

Phone Phreaking

Introduction
Phone phreaking is basically just hacking over a phone line. This could include phone line tapping, breaking into phone networks, gaining free long distance, and sometimes it is considered part of the realm of social engineering. Social engineering is gaining information by tricking people directly instead of hacking machines; you in other words "engineer using social tactics." In this post you will learn how to tap your own home phone line.


Tools needed:
Windows 95 dialer. exe ( RAR | EXE )
Free MP3 Recorder ( Main | Mirror)
A computer connected to a phone line... like what you did back in the days of Dialup.
Lets go back to the future using the Windows 95 Dialer.exe tool (It must be windows 95, NT/2000 will not work) Open it up and tell it to dial a letter. I normally put in "f".

This will bring up a new window that asks you to pick up the receiver. Just ignore that until you're done. You should hear the phone line in through your speakers.


The best time to listen in is to wait till someone starts dialing or after the parties have begun talking on the phone. If done too soon (like when you still have the tone) you will get a busy signal and it will hang up. Another practical use I have found for this program is when the answering machine picks up in another part of the house, I can hear the live recording by picking up just at the right moment.

I recommend getting a copy of Free MP3 Sound Recorder if you want to record the conversation. Any program will work that allows you to record windows internal sounds. (you could also use Audacity with a cable connecting your microphone to teh speaker, but unless you have a audio speaker you won't be able to here the conversation.
This will record the sound of the phone line allowing you to save it to mp3/wav format. Another recorder that I found to be pretty good was: http://www.roemersoftware.com/sound-recorder-comparison.html (get the free version)

Instructions for "Free MP3 Sound Recorder":
Click file--> New
Then Select Record and stereo checkboxes.
Click Ok and select the file format you want... I normally choose mp3.
Click Ok and select where you want to save the file.
A new window will come up saying "Do you want to start recording now?"
Select yes if you have the call on the line, or no if you have yet to make the call.

End Notes:
I have found that with practice I can have the line recording in thirty seconds (that is including the time to start each program). In many US states it is illegal to record a phone call without the consent at least one party. But you can find a complete list here: http://www.rcfp.org/taping/states.html

Sunday, August 26, 2007

Storm Worm - Now using youtube.

Some of you remember that I reported a while back that the Storm worm was using e-cards via Email to trick you into downloading. Now it has morphed to use a fake Youtube link.

http://www.youtube.com/watch?v=Ga4y9EQMuDe
(link text = http://www.youtube.com...., and the real link is http://XX.99.65.225/)

to get you to go to the Storm Worm website and download the worm. :-/

Full story:
SANS Internet Storm Center; Cooperative Network Security Community - Internet Security - isc

Friday, August 17, 2007

Password Cracking and Security: Part 2

Introduction:
This will show you how to break the encryption on a zip file, word document, and excel document. The tools and methods shown here are just some of the many ways to get a password. There are things called exploits which could allow an attacker to get in even faster... but for now lets take a look at Brute Force and Dictionary attacks. NOTE: This tutorial doesn't recommend you crack passwords that don't belong to you. It is meant be used for password recovery and password strength testing.

Tools needed:
Excel_crackers_setup.exe (mirror)
Zip Password Finder (mirror)
abc.doc (word doc I made with password... see if you can get access)


These programs have been tested and they work with not only the older versions of office, but also newer ones...

  1. Microsoft Word / Microsoft Excel
    This method will work on either a word or excel file, it doesn't matter which you choose.
    First create(or open) a password protected Microsoft Word or Excel document; type some information into it so that you will be able verify you have unlocked the document.
    To enable password click tools--> options --> security, and enter password, click ok and save the document. (Visual here)


  2. Next download and install excel_cracker_setup.exe
  3. You should get a
    window that looks like:
  4. In the name box type or click the icon and browse, to enter the password protected word/excel file you created.
  5. You have 2 options: Brute Force attack! and Dictionary attack (see Password cracking part 1 for more info). If you do a dictionary attack you must select a word file... and it has to be text. For this demonstration select only Brute Force attack

  6. Further options include:
    - All printable (meaning all characters able to be typed)
    - Latin small symbols [ a...z] (lowercase letter)
    - Latin capital symbols [A...Z] (UPPERCASE letters)
    - Digits [0...9] (numbers)
    - Special symbols [1@#$...] (can you guess this one?)
    - Space [ ] (its like outer space...)

  7. You can set the Minimum Length and Maximum Length of the passwords you want try. But here is where things get a little sticky. See chart below to see what I mean. (click to see it larger)


    A ten character password with both symbols and letters (no caps) will take over 960000 years to crack.
ZIP Archives
In order to crack zip archives it is very similar but here are the step by step instructions.
  1. Download: Zip Password Finder
  2. Once you have opened the program (it installs to the start menu),
  3. Click "Open File" and select the zip file you wish to crack.
  4. Next, pick the "charType Property" which will be the character set that is used for the Brute Force. (you should understand from the other demonstrations, so I don't have to re-list the distinctions.)
  5. You may also want to select "Max password Length:"
  6. Go get a drink and find something productive to do while you wait :-)

    END NOTES:
    The best thing that you can use this for is to test how fast someone could crack your password or if you have forgotten the password to a word, excel, or zip file. Once you have cracked (or failed to crack) your password, you can make an assessment as to whether or not you need to change it. (If your password is over 10 charters, I expect you know better than to wait 100+ years to find out it is safe :-P )

MORE TOOLS:
IBIOS (http://www.11a.nu/)....... BIOS cracking
Cain and Able................................ OS PWD cracker /Net spoofer
007PeepPassword..........................view password under asterisks
Archpr.................................... rar, zip, pkzip, ARJ/ACE + more
http://www.password-crackers.com.... good resource for free and paid tools.

Thursday, July 26, 2007

PDF Yesterday... Ecards today

I have found that this weeks Email spam Scam is E-cards...
the following "loving" ECards from my "friends" can be seen below:



It appears that this round of Spam is very Dangerous as can be seen in detail from a report by
SANS Internet Storm Center; Cooperative Network Security Community - Internet Security - isc

They said that it has been labeled "Storm worm"
and houses a collection of
-botnet malware
(allows virus master to control 100 or 1000s of machines at a time)
-a rootkit
(hides programs from antivirus and spyware detection software so no detection is even possible)
-NEW: Virtual Machine Detection
(harder to use a sandbox windows environment to test and understand the virus)
-Worming virus like activity
(allows program to hop from machine to machine uninvited)
-hiding behind a P2P style network
(uses its own network to spread)

This mix allows it to deal a perfected blow to any PC it is allowed to infect. What has changed the game for this virus/malware is the fact that when researches put it inside their Virtual Machines (the place they test the virus safely) nothing happened. The Virus didn't deploy and only rebooted the Virtual Machine.

Now I haven't personally tried these attachments, like I did with the PDF ones (see earlier post)
But I did notice that there are more attachments with these Emails and there volume is increased and not every Email has a attachment, it may have a link to a file to download.

Thats it for now... check back again to stay informed on more everyday security problems and to follow my security series.

Sunday, July 15, 2007

Password Cracking and Security: Part 1

Introduction:
Many times the only thing stopping a hacker from accesses your data is a username and/or password. A strong password will insure that nothing gets leaked. A password's strength can broken down into: numbers, letters(lower and UPPERCASE), symbols, and length.

Most hackers will try the default passwords first. (and I have to say I have recovered many a password by having that list handy) Examples include, but aren't limited to: admin, root, password, pass, password1, default, and.... so on and so forth. View larger sample (router default passwords)

Definitions:
If he can't get in with the default passwords he may step up the attack to a dictionary attack or brute force attack.

  • A Dictionary Attack -- which is where he takes a list of words from the dictionary and other sources(like acronyms, foreign words etc) and trys each one to see if it is the password. He may also add numbers such as a 1 or a 2 to the end for a quick check. If your password is a single word or a phrase, such as "hardcrack" or "notime" then the attacker will be inside your account(s) in a matter of hours or days.
  • Brute Force Attack -- this is where the attacker attempts every combination in the book, and out of the book. Normally he selects the category and length he wishes to try. The script he has made will then try an alphabetical/numeric/symbolic attempt 1 by 1. e.g aa, ab, ac... ax, ay, az, a1, a2, a3, ... a7, a8, a9, a0, a!, a@, a#..... Oh yeah, I can't forget to mention that he also has to try Uppercase and lower case letters. This can end up taking forever since time to try the passwords compounds itself.
    (Check back for Password Cracking and Security: Part 2 Word, Excel, and Zip brute force demonstration)
THE Protection TIPS:
The more combinations you use in your password the harder it will be to crack. The most secure passwords contain a mix of the items noted above. Now you may be thinking how in the world am I going to remember such a complicated password? Here are some tips:

  1. - Develop an algorithm for your passwords. The password to your "mail" could be MaIl6245 and the password for your computer could be cOmPuTeR26678837. With the algorithm being: Subject name, alternating upper and lower case, and then the corresponding numbers from a phone keypad.

  2. - Use geometric shapes to remember your password:






    Each button would be pressed and make up passwords that look hard, but really when you sit down to type are easy to remember. (Picture shows passwords: "e3dcft654" and "8ik./lo9")
  3. - Another way to remember your password is to write it down...
    BUT don't just leave the paper lying around for someone to find. Put it in your wallet, or other safe place (and that doesn't include your monitor) Plus, hide it in such a way as not to make it obvious. e.g. if your password was MaIl6245 mix it up --- put "MaIl" on one line and 6245 on another line on the index card.


  4. Don't type your password in straight. What I mean is type your password in backwards, out of sequence, and add extra keys to confuse the keyloggers. When you are on a computer there are programs called keyloggers that will log every stroke you make. It doesn't matter how strong your password is, if the computer has a keylogger, then the keylogger's master can get it easily.
    Also, use the mouse, not the arrow keys to move around in the password field. Most keyloggers that I have tested can't pick up mouse movements.
    For Example lets say you have a password of abc123 (though not especially safe, it is alphanumeric). If typed :Then it will show in the keylogger: 123xabnc
    And unless the keylogger can log backspace/left/right arrows then whoever looks at it will be confused, and hopefully pass you by.

    If you want to try out a keylogger I recommend:
    FREE:
    Tiny KL - http://home.rochester.rr.com/artcfox/TinyKL/ OR
    Actual Keylogger - http://www.download.com/3001-2092_4-10541792.html
    Or you can try out my all time favorite:
    $19.99
    Winspy - http://www.win-spy.com/ (feature list is amazing)

  5. - You may even want to use a password storage program. Firefox has a built in password manager which I recommend using --- so long as you add a master password (Tools--> Options, Security Tab, Check "use master password" and click "change"/"setup password"). You can also use Roboform which works well to remember Internet Explorer and Firefox passwords. Most of the time a password gets added by you typing it in and selecting you want Roboform or Firefox to remember it.

    What I did for a while with my passwords was I kept them in Firefox's list (practically all of my vital passwords were for websites) . Then I created a master password using symbols and letters and stored a hard copy of that in my wallet. For passwords that were not in the browser(like the screensaver) I just picked 1 tricky alpha/numeric/symbol password and used it over and over till I had memorized it --- that is one thing I have found true to remembering passwords, if you have to type it every time you start windows(however infrequent that may be :-P) you will tend to remember the password better.

    If you have passwords outside the browser (like to get into Windows) it is best to keep them in a protected password manger program or password protected Word or Excel document with auto recovery turned off (so no cache copies remain on disk) which is located on a keydisk(which can be hidden under your bed, the place every robber looks ;-P).

    Note: I personally don't trust any password manger program, and just use a combo of MS word, MS excel, and zip files to keep my passwords manged and safe.


    Now there are some people that argue that you need to have better Encryption for your passwords. Two good applications for that are Blowfish and TrueCrypt . If you need any help with them feel free to leave a comment, but for now I don't have room in this post to go into details about encryption. (both are free)


    Another problem with passwords that I have found is that people make a great secure password only to have a very simple password recovery question. Like their birthday. Chances are if they have a myspace or something else online where a birth date or father's name, age, favorite place to vacation is posted, etc. then they might as well have no password at all. A hacker can get your password just from those backdoors...

    This is why many companies and individuals have selected to use a security disk instead of passwords. Security disks(USB or Floppy) hold a password generated from the make up of a file or a longer password. The only way to log on to the computer is with that keydisk or the longer password thereby eliminating the need to type the password in each time. This allows you to select a password that you wouldn't ever think of using before. (e.g. you could make a password out of the 255 first characters of the definition of A in the Dictionary) TrueCrypt has some of these features.
End Notes: As you probably can tell, security is an ongoing, never ending
"black art". You are never completely secure. Hackers find exploits, create newer tools, and trick you with their looks and charms :-P. But what you have to do is take steps to be more secure; increase your security to the point that you are so hard to reach, you become not worth the time. Be creative. There is a saying "to prevent a robber you must think like a robber." The same goes for Hackers.

Stay informed, be alert, and if you think security has been compromised, You better pick a new PWD FAST. Trust no-one, not even your yourself.


EDIT INCLUDES MINOR GRAMmATICAL/SPELLING CHANGES.

Friday, July 13, 2007

PDF Viruses on Yahoo? nah-uh

During the last few weeks I have received about 3 PDF Containing Emails from people
I didn't know on my yahoo Email account. Then today while I was working at a customer's I was alerted to the fact that she had opened one of the PDF files, mistaking it for a legit attachment, so I knew I needed to find out whether it was dangerous or not.

I began searching for the answer to whether it was a virus or just spam. According to various sites and Antivirus software, this round is just a spamming ploy to make money.

I opened the PDF on my Windows XP PC and scanned it with AVG, and Norton (via yahoo's scanner.)
No virus was found, and the contents of the PDF showed:



The name of this particular file was "check_50290cba35810.pdf" but I have seen many other names.

I tried a simple Google search on SZSN, It appears that this Chinese company may be paying spammers in order to get to get the word out about there new seed and products. Header information could not verify the location of the spammer (no surprise). I can't help wondering if something was really happening with a virus this Morning and has yet to turn up.

But I can only guess the spammer is working out of China which ranks in the top 10 nations for illegal piracy and activity. The disguise of the PDF and the crooked print attempt to make it look more legitimate... to the spam blocker software.

This is something that has become more and more of a problem, spammers get paid to spam. These people have created a new profession which has a paycheck in the thousands or even millions.


Resources:
http://chris.pirillo.com/media/2007/07/02/pdf-viruses/

Thursday, July 5, 2007

Antivirus Test and Results in

After testing several Antivirus and spyware protection programs against over 174,770 viruses and malware, Virus.GR a list has been compiled on how well different security applications have held up:


Testing was done on an up to date Windows XP Professional SP2 on a P4 3000 Mhz, 1024MB DDRAM. Each program was customized to maximize its ability to detect and remove the nasties.

This test does not include DOS scanners and scanned file types:
SH, ELF, COM, EXE, PL, BAT, PRC, DOC, XLS, BIN, MDB, IMG, PPT, VBS, MSG, VBA, OLE, HTM, INI, SMM, TD0, REG, CLASS, HTA, JS, VI_, URL, PHP, WMF, HLP, XML, SCR, PIF, SHS, WBT, CSC, MAC, DAT, CLS, STI, INF, HQX, XMI, SIT.


And just for the record: Anyone trying to use Norton or Macafee and protect them self from viruses/malware is going to get infected soon or later (most likely sooner rather than later) ... which is why I am posting this list.

(list provided by virus.gr, partial information www.techdo.com)

1. Kaspersky version 7.0.0.43 beta - 99.23%
2.
Kaspersky version 6.0.2.614 - 99.13%
3.
Active Virus Shield by AOL version 6.0.0.308 - 99.13%
4.
ZoneAlarm with KAV Antivirus version 7.0.337.000 - 99.13%
5.
F-Secure 2007 version 7.01.128 - 98.56%
6.
BitDefender Professional version 10 - 97.70%
7.
BullGuard version 7.0.0.23 - 96.59%
8.
Ashampoo version 1.30 - 95.80%
9.
eScan version 8.0.671.1 - 94.43%
10.
Nod32 version 2.70.32 - 94.00%
11.
CyberScrub version 1.0 - 93.27%
12.
Avast Professional version 4.7.986 - 92.82%
13.
AVG Anti-Malware version 7.5.465 - 92.14%
14.
F-Prot version 6.0.6.4 - 91.35%
15.
McAfee Enterprise version 8.5.0i+AntiSpyware module - 90.65%
16.
Panda 2007 version 2.01.00 - 90.06%
17.
Norman version 5.90.37 - 88.47%
18.
ArcaVir 2007 - 88.24%
19.
McAfee version 11.0.213 - 86.13%
20.
Norton Professional 2007 - 86.08%

Then the following applications trailing behind:
21. Rising AV version 19.19.42 - 85.46%
22. Dr. Web version 4.33.2 - 85.09%
23. PC-Cillin 2007 version 15.00.1450 - 84.96%
24. Iolo version 1.1.8 - 83.35%
25. Virus Chaser version 5.0a - 79.51%
26. VBA32 version 3.11.4 - 77.66%
27. Sophos Sweep version 6.5.1 - 69.79%
28. ViRobot Expert version 5.0 - 69.53%
29. Antiy Ghostbusters version 5.2.1 - 65.95%
30. Zondex Guard version 5.4.2 - 63.79%
31. Vexira 2006 version 5.002.62 - 60.07%
32. V3 Internet Security version 2007.04.21.00 - 55.09%
33. Comodo version 2.0.12.47 beta - 53.94%
34. Comodo version 1.1.0.3 - 53.39%
35. A-Squared Anti-Malware version 2.1 - 52.69%
36. Ikarus version 5.19 - 50.56%
37. Digital Patrol version 5.00.37 - 49.80%
38. ClamWin version 0.90.1 - 47.95%
39. Quick Heal version 9.00 - 38.64%
40. Solo version 5.1 build 5.7.3 - 34.52%
41. Protector Plus version 8.0.A02 - 33.13%
42. PcClear version 1.0.4.3 - 27.14%
43. AntiTrojan Shield version 2.1.0.14 - 20.25%
44. PC Door Guard version 4.2.0.35- 19.95%
45. Trojan Hunter version 4.6.930 - 19.20%
46. VirIT version 6.1.75 - 18.78%
47. E-Trust PestPatrol version 8.0.0.6 - 11.80%
48. Trojan Remover version 6.6.0 - 10.44%
49. The Cleaner version 4.2.4319 - 7.26%
50. True Sword version 4.2 - 2.20%
51. Hacker Eliminator version 1.2 - 1.43%
52. Abacre version 1.4 - 0.00%