Being an Ethical Hacker is cool, isn't it ??? So grab a chance

Posted on:
tags: , , , , , , ,

Benefits of Ethical Hacking Certification

Hacking is a word that is mostly used by hackers. These hackers love to sit in front of computers and use resources to find out some information on the computer network of other people especially defense network. The hackers get into government’s and other organization’s computer network to gain some data or money from it directly or indirectly. So the role of an ethical hacker is to secure government’s or organization’s data and important information from these hackers. To do so, you need to have a certification of ethical hacking that gives you the authority to access others computer network for goods and security. So in this article, we have given some benefits of ethical hacking certification.

 Right to work for an organization :

An ethical hacking certification program gives you the right to work for an organization. Without ethical hacking certification, no organization will let you work for them because security of official data is extremely necessary for any organization. So they need a proof that you have learnt ethical hacking from a place that offers ethical hacking certification.

 Fight against terrorism:

After ethical hacking certification, you can fight against terrorism by gaining hold of terrorists through hacking. Nowadays, many terrorists use emails and other tools on the web before any terrorist activity. So on earning ethical hacking certification, you can secure your country by hacking the terrorists’ emails and their activities on the web.

 Authority to secure something from hackers: 

To secure data from hackers, you need to have a certification of ethical hacking that gives you the authority to access other computer networks for noble cause. For security reasons, no one gives the authority to secure their network and information from hackers as they believe only certified ethical hackers.

 A bright Career :

Of cource ! Certification of ethical hacker provides you with numerous career opportunities in the field of information security. These jobs are counted as reputed ones. Without certification, no organization will hire you as these jobs are related to their business and data security. So they can’t take risk of hiring a non certified ethical hacker.

 Get a chance to secure your motherland :

After this certification, you can secure your motherland from terrorist activity and this would be a life time opportunity for you. There are many certified ethical hackers who are working for Indian government in securing India from terrorists. So after the certification, you can also get a chance to do so.

The best institute for Ethical hacking course : Innobuzz

Source 

---------------------------------------------------------------------------------
Posted By Sundeep aka SunTechie

Sundeep is a Founder of Youth Talent Auzzar, a passionate blogger, a programmer, a developer, CISE and these days he is pursuing his graduation in Engineering with Computer Science dept.
Add Sundeep as a Friend on


 

Free online certified course on Cyber Crime Protection Program

Posted on:
tags: , , , , , ,

For all Security guy, here is an awesome certified exam on "Cyber Crime Protection Program" organised by Asian School of Cyber Law in collaboration with Data64.

This FREE program is a must for anyone with a computer, a smart phone, a PDA, a facebook account, an online banking account or even an email account.
This program will also help you understand:
  • What is cyber crime?
  • How to secure a laptop / desktop from hackers?
  • How to secure a smartphone from hackers?
  • How to secure a PDA from hackers?
  • How to secure your email / social networking account?
  • How to avoid becoming a victim of phishing?
The exam contained 20 questions and to get certificate you have to score at least 50%  i.e. 10 marks out of 20. Simple questions, just true and false options.
So, Guys go ahead and take the exam..
All The Best 
To begin, visit at the website 
Certificate of mine 

---------------------------------------------------------------------------------
Posted By Sundeep aka SunTechie

Sundeep is a Founder of Youth Talent Auzzar, a passionate blogger, a programmer, a developer, CISE and these days he is pursuing his graduation in Engineering with Computer Science dept.
Add Sundeep as a Friend on 

Hacking in cars, Experts gear up to make cars 'virus-free'

Posted on:
tags: , , , , , , , ,

Security experts say automakers have failed to adequately protect systems in vehicles, leaving those vulnerable to hacks by attackers.

A team of top hackers working for Intel Corp’s security division toil away in a West Coast garage searching for electronic bugs that could make automobiles vulnerable to lethal computer viruses.

Intel’s McAfee unit, which is best known for software that fights PC viruses, is one of a handful of firms that are looking to protect the dozens of tiny computers and electronic communications systems that are built into every modern car.


It’s scary business. Security experts say that automakers have so far failed to adequately protect these systems, leaving them vulnerable to hacks by attackers looking to steal cars, eavesdrop on conversations, or even harm passengers by causing vehicles to crash.

“You can definitely kill people,” said John Bumgarner, chief technology officer of the US Cyber Consequences Unit, a non-profit organisation that helps companies analyse the potential for targeted computer attacks on their networks and products.
To date there have been no reports of violent attacks on automobiles using a computer virus, according to SAE International, an association of more than 128,000 technical professionals working in the aerospace and the auto industries.

Yet, Ford spokesman Alan Hall said his company had tasked its security engineers with making its Sync in-vehicle communications and entertainment system as resistant as possible to attack.

“Ford is taking the threat very seriously and investing in security solutions that are built into the product from the outset,” he said.

And a group of US computer scientists shook the industry in 2010 with a landmark study that showed viruses could damage cars when they were moving at high speeds. Their tests were done at a decommissioned airport.
SAE International charged a committee of more than 40 industry experts with advising manufacturers on preventing, detecting and mitigating cyber attacks.
“Any cyber security breach carries certain risk,” said Jack Pokrzywa, SAE’s manager of ground vehicle standards. “SAE Vehicle Electrical System Security Committee is working hard to develop specifications which will reduce that risk in the vehicle area.”

The group of US computer scientists from California and Washington state issued a second report last year that identified ways in which computer worms and Trojans could be delivered to automobiles — via onboard diagnostics systems, wireless connections and even tainted CDs played on radios systems.

They did not say which company manufactured the cars they examined, but did say they believed the issues affected the entire industry, noting that many automakers use common suppliers and development processes.
The three big US automakers declined to say if they knew of any instances in which their vehicles had been attacked with malicious software or if they had recalled cars to fix security vulnerabilities.

Toyota Motor Corp, the world’s biggest automaker, said it was not aware of any hacking incidents on its cars.

“They’re basically designed to change coding constantly. I won’t say it’s impossible to hack, but it’s pretty close,” said Toyota spokesman John Hanson.

Officials with Hyundai Motor Co, Nissan Motor Co and Volkswagen AG said they could not immediately comment on the issue. A spokesman for Honda Motor Co said that the Japanese automaker was studying the security of on-vehicle computer systems, but declined to discuss those efforts.

A spokesman for the US Department of Homeland Security declined to comment when asked how seriously the agency considers the risk that hackers could launch attacks on vehicles or say whether DHS had learned of any such incidents.

The department helps businesses in the manufacturing and transportation industries secure the technology inside their products and investigates reports of vulnerabilities that could allow attacks.

Bruce Snell, a McAfee executive who oversees his company’s research on car security at the Beaverton, Oregon garage, said automakers are fairly concerned about the potential cyber attacks because of the frightening repercussions.

“If your laptop crashes you’ll have a bad day, but if your car crashes that could be life threatening,” he said. “I don’t think people need to panic now. But the future is really scary.”

A McAfee spokeswoman said that among those hackers working on pulling apart cars was Barnaby Jack, a well-known researcher who has previously figured out ways that criminals could force ATMs to spit out cash and cause medical pumps to release lethal doses of insulin. Makers of those products responded by saying they would work to improve security.

Computers on wheels
White hats are increasingly looking beyond PCs and data centers for security vulnerabilities that have plagued the computer industry for decades and focusing on products like cars, medical devices and electricity meters that run on tiny computers embedded in those products.


Automobiles are already considered “computers on wheels” by security experts. Vehicles are filled with dozens of tiny computers known as electronic control units, or ECUs, that require tens of millions of lines of computer code to manage interconnected systems including engines, brakes and navigation as well as lighting, ventilation and entertainment.

Cars also use the same wireless technologies that power cell phones and Bluetooth headsets, which makes them vulnerable to remote attacks that are widely known to criminal hackers.

“There is tons of opportunity for attack on car systems,” said Stuart McClure, an expert on automobile security who recently stepped down as worldwide chief technology officer of McAfee to start his own firm.

Security analysts fear that criminals, terrorists and spies are gradually turning their attention to embedded computers, many of which can be attacked using some of the same techniques as regular computers.

Automakers are rushing to make it easy to plug portable computers and phones to vehicles and connect them to the Internet, but in many cases they are also exposing critical systems that run their vehicles to potential attackers because those networks are all linked within the car.

“The manufacturers, like those of any other hardware products, are implementing features and technology just because they can and don’t fully understand the potential risks of doing so,” said Joe Grand, an electrical engineer and independent hardware security expert.

Grand estimates that the average auto maker is about 20 years behind software companies in understanding how to prevent cyber attacks.
Chrysler said it was addressing security issues with industry groups and outside organisations including Battelle Corp, a non-profit company that recently established an auto security research center in Columbia, Maryland known as CAVE, or the Center for Advanced Vehicle Environments.

CAVE, which declined to discuss its research on auto security, has hired hacking expert Tiffany Strauchs Rad, a professor at the University of Southern Maine. Last year, she was part of a team that identified flaws in prison networks which could enable hackers to remotely open or lock cell doors.

‘Self destruct’
Concerns about such possibilities emerged after a group of computer scientists from the University of California and the University of Washington published two landmark research papers that showed computer viruses can infect cars and cause them to crash, potentially harming passengers.


The group chose a fairly banal name, the Center for Automotive Embedded Systems Security. Yet their work is as imaginative as that of Q, the fictional scientist who supplies weapons to British secret agent James Bond.

They figured out how to attack vehicles by putting viruses onto compact discs. When unknowing victims try to listen to the CD, it infects the car radio, then makes its way across the network to more critical systems.

For instance, they came up with a combination attack dubbed “Self Destruct”. It starts when a 60-second timer pops up on a car’s digital dashboard and starts counting down. When it reaches zero the virus can simultaneously shut off the car’s lights, lock its doors, kill the engine and release or slam on the brakes.
In addition to designing viruses to harm passengers in infected vehicles, the academics were able to remotely eavesdrop on conversations inside cars, a technique that could be of use to corporate and government spies.

The research group disbanded after publishing two technical papers, in May 2010 and August 2011, that describe multiple types of attacks and ways to infect cars using Bluetooth systems, wireless networks as well as the car’s OnBoard Diagnostics port, which is also known as an OBD-II port.

One issue of concern is fighting ordinary PC viruses that could potentially infect cars when laptops and other devices are plugged into infotainment systems.

“Viruses are something that needs to be addressed directly. How we guard against that transfer to our system is a primary focus of our efforts,” said Toyota spokesman John Hanson.

Source


---------------------------------------------------------------------------------
Posted By Sundeep aka SunTechie

Sundeep is a Founder of Youth Talent Auzzar, a passionate blogger, a programmer, a developer, CISE and these days he is pursuing his graduation in Engineering with Computer Science dept.
Add Sundeep as a Friend on 


Hackers build their own mobile phone network at conference

Posted on:
tags: , , , , , , , ,




A custom mobile phone network came to life in the middle of Def Con as hackers showed off their technology skills in tribute to the infamous gathering's elite "ninjas."


A Def Con team bought a telecom company van and configured a "Ninja Tel" cellular phone network to pay homage to longtime hackers who have kept the spirit of the event alive and, admittedly, just to do something "over the top."
"People don't realize how much hacking has changed," said Def Con veteran Dan Kaminsky, known for discovering a perilous Internet bug that bears his name.

"This used to be a sub-culture of people who bonded over their fascination with technology," he continued. "Now, hacking has gone mainstream.
"A mom hacks her kid's grade at school and Rupert Murdoch gets called out for hacking."

The Ninja Tel team built 650 handsets powered by Google-backed Android software tailored to synch with the exclusive Ninja Tel network.

The smartphones were handed out as "badges" to members of the Def Con community whose hacker accomplishments or whose legacies in the 20-year-old annual gathering have earned them "ninja" status.

"The ninjas represent a group of phenomenally intelligent people who share a common interest and passion," said John Hering, head of Lookout Mobile security startup and part of the team behind Ninja Tel.
"They are a center point for the community at Def Con; it is a very special thing."
Ninja Tel mobile phones only work within range of the van, which is parked in the middle of the Def Con event that continues through Sunday in the Rio Hotel and Casino in Las Vegas.

Contact numbers for anyone with a Ninja Tel phone are automatically listed in handsets, which also allow callers to playfully battle one another with virtual karate moves in a spin on the child's game Rock, Paper, Scissor.

Ninja Tel has a geek "Easter egg" -- the woman who was the original voice for recorded AT&T information messages during landline days of decades gone by did the voice-overs for the hacker network.

"It really is a throwback to a more simplistic era of telephony," Hering said. "It looks like the Yellow Pages, but it is a really sophisticated Android operating system."
Ninja Tel phones could also be used to signal vending machines scattered about Def Con to pop out free beer or soda using wireless technology at close range.

"We've made it hackable from the ground up," Hering said of the handsets.
"You can build your own apps and customize the device to do some more interesting things."

The team at Ninja Tel declined to reveal how much was spent on the project, which was pulled off with the backing of Facebook, Zynga, Qualcomm, and Lookout.

"It's a pretty ambitious project to build your own Telco, effectively, and your own device from scratch," Hering said.

The hacker mobile network came as the sun set on a Def Con tradition, the exclusive annual party hosted by Ninja Networks.

Ninja Networks is rooted in the original hackers whose time at Def Con dates back decades to when it was an intimate assembly of technology renegades.

Kaminsky smiled at the notion of Ninja Tel, seeing it as hackers "social engineering" major companies into buying them a mobile phone network.

"There are many definitions of the word 'hacking,' " Kaminsky said. "This is hacking on a corporate scale."


---------------------------------------------------------------------------------
Posted By Sundeep aka SunTechie

Sundeep is a Founder of Youth Talent Auzzar, a passionate blogger, a programmer, a developer, CISE and these days he is pursuing his graduation in Engineering with Computer Science dept.
Add Sundeep as a Friend on 

Its Windows Security hackers !

Posted on:
tags: , , , ,

Three components of Windows Security:

LSA (Local Security Authority)
 
SAM (Security Account Manager)
 
SRM (Security Reference Monitor)







LSA (Local Security Authority)
LSA is the Central Part of NT Security. It is also known as Security Subsystem. The Local Security Authority or LSA is a key component of the logon process in both Windows NT and Windows 2000. In Windows 2000, the LSA is responsible for validating users for both local and remote logons. The LSA also maintains the local security policy.

During the local logon to a machine, a person enters his name and password to the logon dialog. This information is passed to the LSA, which then calls the appropriate authentication package. The password is sent in a nonreversible secret key format using a one-way hash function. The LSA then queries the SAM database for the User’s account information. If the key provided matches the one in the SAM, the SAM returns the users SID and the SIDs of any groups the user belongs to. The LSA then uses these SIDs to generate the security access token.

SAM (Security Account Manager)
The Security Accounts Manager is a database in the Windows operating system (OS) that contains user names and passwords. SAM is part of the registry and can be found on the hard disk.

This service is responsible for making the connection to the SAM database (Contains available user-accounts and groups). The SAM database can either be placed in the local registry or in the Active Directory (If available). When the service has made the connection it announces to the system that the SAM-database is available, so other services can start accessing the SAM-database.

In the SAM, each user account can be assigned a Windows password which is in encrypted form. If someone attempts to log on to the system and the user name and associated passwords match an entry in the SAM, a sequence of events takes place ultimately allowing that person access to the system. If the user name or passwords do not properly match any entry in the SAM, an error message is returned requesting that the information be entered again.

When you make a New User Account with a Password, it gets stored in the SAM File.

Windows Security Files are located at
“C:\Windows\System32\Config\SAM”
The moment operating system starts, the SAM file becomes inaccessible.

SRM (Security Reference Monitor)
The Security Reference Monitor is a security architecture component that is used to control user requests to access objects in the system. The SRM enforces the access validation and audit generation. Windows NT forbids the direct access to objects. Any access to an object must first be validated by the SRM. For example, if a user wants to access a specific file the SRM will be used to validate the request. The Security Reference Monitor enforces access validation and audit generation policy.

The reference monitor verifies the nature of the request against a table of allowable access types for each process on the system. For example, Windows 3.x and 9x operating systems were not built with a reference monitor, whereas the Windows NT line, which also includes Windows 2000 and Windows XP, was designed with an entirely different architecture and does contain a reference monitor.

Email hacking

Posted on:
tags: , , , ,

How Email Works?
Email sending and receiving is controlled by the Email servers. All Email service providers configure Email Server before anyone can Sign into his or her account and start communicating digitally. Once the servers are ready to go, users from across the world register in to these Email servers and setup an
Email account. When they have a fully working Email account, they sign into their accounts and start connecting to other users using the Email services.

Email Travelling Path
Let’s say we have two Email providers, one is Server1.com and other is Server2.in, ABC is a registered user in Server1.com and XYZ is a registered user in Server2.in.

ABC signs in to his Email account in Server1.com, he then writes a mail to the xyz@server2.in and click on Send and gets the message that the Email is sent successfully.

But what happens behind the curtains, the Email from the computer of abc@server1.com is forwarded to the Email server of Server1.com. Server1 then looks for server2.in on the internet and forwards the Email of the server2.in for the account of XYZ. Server2.in receives the Email from server1.com and puts it in the account of XYZ.

XYZ then sits on computer and signs in to her Email account. Now she has the message in her Email inbox.


Email Service Protocols
SMTP
SMTP stands for Simple Mail Transfer Protocol. SMTP is used when Email is delivered from an Email client, such as Outlook Express, to an Email server or when Email is delivered from one Email server to another. SMTP uses port 25.

POP3
POP3 stands for Post Office Protocol. POP3 allows an Email client to download an Email from an Email server. The POP3 protocol is simple and does not offer many features except for download. Its design assumes that the Email client downloads all available Email from the server, deletes them from the server and then disconnects. POP3 normally uses port 110.

IMAP
IMAP stands for Internet Message Access Protocol. IMAP shares many similar features with POP3. It, too, is a protocol that an Email client can use to download Email from an Email server. However, IMAP includes many more features than POP3. The IMAP protocol is designed to let users keep their Email on the server. IMAP requires more disk space on the server and more CPU resources than POP3, as all Emails are stored on the server. IMAP normally uses port 143.

Configuring an Email Server
Email server software like Post cast Server, Hmailserver, Surge mail, etc can be used to convert your Desktop PC into an Email sending server.
HMailServer is an Email server for Microsoft Windows. It allows you to handle all your Email yourself without having to rely on an Internet service provider (ISP) to manage it. Compared to letting your ISP host your Email, HMailServer adds flexibility and security and gives you the full control over spam protection.

Email Security
Now let’s check how secure this fast mean of communication is. There are so many attacks which are applied on Emails. There are people who are the masters of these Email attacks and they always look for the innocent peoplewho are not aware of these Email tricks and ready to get caught their trap.

You have to make sure that you are not an easy target for those people. You have to secure your Email identity and profile, make yourself a tough target.

If you have an Email Id Do not feel that it does not matters if hacked because there is no important information in that Email account, because you do not know if someone gets your Email id password and uses your Email to send a threatening Email to the Ministry or to the News Channels.

Attacker is not bothered about your data in the Email. He just wants an Email ID Victim which will be used in the attack. There are a lots of ways by which one can use your Email in wrong means, i am sure that you would have come across some of the cased where a student gets an Email from his friends abusing him or cases on Porn Emails where the owner of the Email does not anything about the sent Email.

Email Spoofing
Email spoofing is the forgery of an Email header so that the message appears to have originated from someone or somewhere other than the actual source. Distributors of spam often use spoofing in an attempt to get recipients to open, and possibly even respond to, their solicitations. Spoofing can be used legitimately.

There are so many ways to send the Fake Emails even without knowing the password of the Email ID. The Internet is so vulnerable that you can use anybody's Email ID to send a threatening Email to any official personnel.

Methods to send fake Emails
Open Relay Server
Web Scripts

Fake Emails: Open Relay Server
An Open Mail Relay is an SMTP (Simple Mail Transfer Protocol) server configured in such a way that it allows anyone on the Internet to send Email through it, not just mail destined ‘To’ or ‘Originating’ from known users.
An Attacker can connect the Open Relay Server via Telnet and instruct the server to send the Email.
Open Relay Email Server requires no password to send the Email.

Fake Emails: via web script
Web Programming languages such as PHP and ASP contain the mail sending functions which can be used to send Emails by programming Fake headers i.e.” From: To: Subject:”
There are so many websites available on the Internet which already contains these mail sending scripts. Most of them provide the free service.

Some of Free Anonymous Email Websites are:
Ø Mail.Anonymizer.name (Send attachments as well)
Ø FakEmailer.net
Ø FakEmailer.info
Ø Deadfake.com
Ø www.hackingtech.co.tv/index/0-93










>