10 Ramnit : Worm that loves Facebook

 "Ramnit"  the worm with multifaceted spreading capabilities,first detected on 2010 for infecting local systems. Now the hackers behind it have redesigned it into a more advanced kind of worm.The worm has already stolen 45000 facebook credentials and still on move.





It is also confirmed that this worm is able to bypass the two level authentication used by banking organizations and online money transfer.Below I have taken the snapshot of the code of the worm that was detected in 2010.
 It comes from online malicious sources and   creates infected .html files through that it infects the executable and .dll files. As,depicted in the video below.





But as the worm has spread its root to financial and social media so it a big concern.Users are advised to change there credentials in every 14 days.
Read more

31 A Beginner's Guide to Android Rooting | Easy Reference

Android in the one of the widely accepted OS in devices(phones,Tabs etc) these days because of its largely managed apps and control it give to its users.Where is honey so bears are there......
I mean because of its popularity it is one of the hotspot for attacker these days.So,I thought of sharing few security tips with my readers,for that the apps we need to work with will be functional on certain criteria that is we need to have root access on the device.Before going into the security part of it I would like to give my readers a basic idea about rooting.

What is Rooting in Android?

"Root" as you all may be knowing is related to Linux and it is analogous to administrator in Windows.So rooting an Android device means we get the full access and freedom on the functionality of the device,in windows language we can say we have the admininstrative previlage.So,the process by which we get the root access/previlage is called "Rooting".

Why we need Rooting?


1. Full access and control over the device.(Superuser access)

2. Make your device fast to your wish.

3. Add more apps of your choice.(Will be covered in the next Post)

4. Use the OS version of your choice.

Disclaimer: Root may cancel/void your warranty.Carry out the process at your own risk,the author will not be held responsible for any damage caused to your device.
How to root an Android device?

Instead of giving a detailed tutorial I will cover the basic overview of how this is exactly done and the tools and software associated with it.Here it is worth mentioning that all the android based devices do not have excatly the same rooting procedure.So,here I have listed out all the possible methods.

Note:Install Microsoft .Net Framework version 2.0 or greater.
         Enable USB debugging in device settings.
         Need USB drivers for your device and install it.
The first and foremost thing is to find the method which is compatible with your device(just Google it)

1.Rooting Android devices with SuperOneClick.

2.Rooting Android devices with Universal Androot

3.Rooting Android devices with Z4Root.

4.Rooting Android devices with flashRec

5.Rooting Android device using Easy Root.

6.Unrevoked Method:
If the above mentioned methods are not compatible with your device then you may try this method.This method is mostly used for HTC devices.You may download Unrevoker here.

 A Reference of how to "Root a HTC wildfire(Video Tutorial)".

You may need the below mentioned help before working with Unrevoker.
  
     * S-off tool  Revolutionary (Download)
    
     * You may need a Rom to get downgrade(Download)
   
     * Need to find the HBOOT version,as we may need it.


7.Rooting Android 2.3 Gingerbread devices with GingerBreak.

If the Android is 2.3 then no need to downgrade it to 2.2 and start rooting,you may see if your device is compatible with GingerBreak exploit.Follow the reference here as this may help you carry out the steps.

After you are done with rooting then you may install the desired OS version and add your custom ROM.

I hope this post will come to your help.If you feel that I need to add any thing else then feel free to drop a comment. :) 
Read more

6 Yersinia | Analyze and Test Deployed Networks

"Yersinia" a type of bacteria but here in context to this site it is  a  Network tool designed to analyze,test and monitor  the weakness in different network protocols listed with it.

Attack on the following Network Protocol are possible as listed below.

Recently Cisco VTP Dos exploit  included in the latest version:0.7.1
Home Page : http://www.yersinia.net
Read more

10 DroidSheep | Sidejacking & Android phones

What is DroidSheep?

DroidSheep is a mobile form of "Firesheep" and also derives the name from it also.It does the same as firesheep that is Http Session Hijacking a.k.a Sidejacking.


How does this works?

Droidsheep works as the same way as firesheep but the only difference is that it wroks from a smartphone.

What do you need to run DroidSheep on Android phones?


    1. Android 2.1 or greater.
    2. Phone should be rooted.
    3. LibPcap similar to winPcap in PC.
    4. Public Wifi access.

Installation:

The application can be obtained from two places

1.Android Market(Removed from here)

2.From the GET IT section of Droidsheep page.(Use this source)

Download DroidSheep Source code here

As droidsheep is no longer approved by android market so you need to follow the below video inorder to install it.




How to use droidsheep?

Inorder to use droidsheep ROOT previlages is most necessary.If you are unable to get this then try this.

Follow the below video to get an idea of how this application works.


If you find this post worth reading then do drop a comment or if you have any queries then let me know... :)
Read more

5 winAUTOPWN V2.7 | Windows Interactive exploit framework Tool

winAUTOPWN is a simple tool which works on windows platform and is quick in systems vulnerability exploitation.This is tool which takes less information from your side and does more effective work.



Why you should use this tool?

1. It takes simple inputs like IpAddress,Hostname,CMS Path

2. It also does a smart multi-threaded port scan (1 to 65535).

3. Exploits written by other writers can be added to it to evoke a remote shell from target box.

4.It helps the attacker to check the no of exploits it has used on the target box.

In the new version this tool has added few extra features like
  • Commandline parameters for Reverse Shell URL 
  • Mail-to,mail-from(Email server exploit)
Download
Read more

Delete this element to display blogger navbar

 
© 2011 SecurityHunk All Rights Reserved and Template by Fresh Blogger Templates