Showing posts with label engineering. Show all posts
Showing posts with label engineering. Show all posts

Friday, November 6, 2015

There are tons of websites to find a job, that's the thruth


 

There are tons of websites to find a job, that's the thruth

So? There has been a long time since my last post, I've been starting so many projects including some business and stuff and today I'm back to write about this topic which is not even close about the last posts.

So if you are looking for some networking or computing cheat, that's not your post :)

I'm here to think and write about job hunting websites and all about those things.

There was an age...


There was an age where sites like linkedin and infojobs were cool sites to find a job, but, to be honest the have lost that charming brand new magic and they are just a huge curriculum store.

And now what? what's the trend?

That's the point, there are no reference in this matter, it becomes a problem when you are trying to upload your CV to the Internet because you need to keep up-to-date from three to ten profiles in different websites which are roughly the same thing.

There are no fashion sites, the trend now is that there is no trend; and that's a real problem.


I've no tips about which site is the best, so that's my idea, create your own.
Maybe it looks a bit crazy, but it's just an idea.

My own site? What kind shit is that?

Ha ha! You may be right, it could be crappy if you do by the wrong way and the problem is... that there is no best-way but I think that this may be a good chance to take the attention about a head hunter / human resources crew if you make the difference by sending your CV just all-in-one by sending a URL.


Some examples?

I've no examples but I have some ideas to tell to you:

- Create a easy-quick-free site using services like blogger. This is easy to do and free, the only problem may be the low customization level.
            www.blogger.com

- Contact with cheap webhosting services like 1and1 "my web" or something like this, they are intended for small business but you can try it. They have medium customization level.
           www.1and1.com

- You can try too by contacting the MiniWeb guys, they are a brand new website design&hosting company, they just started a few months ago but they are doing quite well. You can contact them both in English or Spanish, you'll find a very cheap service packs. Can contact by facebook, twitter or send a message from the web form contact.
          www.miniwebspain.tk


We are legion

Friday, January 23, 2015

Mis distribuciones favoritas de Linux. Auditoria WiFi

Hola de nuevo

Hacía ya mucho tiempo del último post, muchos cambios en mi vida ultimamente pero estoy de vuelta :)

Hoy estamos aqui para hablar de las ultimas distribuciones live pensadas para auditoria inalámbrica.

Ha habido muchos cambios en este tiempo, muchos linux con muchas herramientas de auditoria wireless que ya vienen instalados y que se ejecutan live, sin necesidad de instalar linux en nuestro PC, persistentes (igual que live, pero que además te almacenan datos de una ejecución para otra) o si lo deseas instalandolo tradicionalmente; hoy hablaré de mis favoritas.

  • Xiaopan OS (pequeña y manejable)
  • WifiWay / WifiSlax (en realidad son la misma)
  • Kali (bestial, potente, enorme)

La peque, Xiaopan OS

Xiaopan Logo

Se descarga en inglés de http://sourceforge.net/projects/xiaopanos/   unos 70 Mb, tenies aqui toda la información en su web http://xiaopan.co/


De su sitio web leemos (traducción):

Xiaopan OS es una distribución  con una colección de herramientas forenses de penetración y seguridad inalmbricas, muy fácil de usar. Incluye herramientas avanzadas para administradores de red, profesionales de la seguridad y usuarios domesticos para probar la resistencia a ser pirateadas de sus propias wifis, con el objetivo de eliminar cualquier vulnerabilidad.
Xiaopan (0.4.7.2, última versión a dia de hoy)

Hice tres pruebas:
La primera, con mi PC de escritorio, funcionó genial ejecutandose live desde un USB, probé diferentes herramientas y opciones, todo perfecto. Distribución pequeña pero poderosa.
El segundo intento con un portatil, no fue capaz de detectar mi tarjeta de red, hice un montón de pruebas y probé muchas "soluciones" de foro de Xiaopan, no hubo forma.
Último intento: Con un mini-portatil de mi novia, igual que el anterior, no hubo forma.

Por tanto, puedo concluir que Xiaopan es una distribución muy pequeñita con un monton de opciones y utilidades pero necesita un pack mayor de controladores y drivers, sobre todo para tarjetas de red, ya que es su objetivo principal. Será una gran distribución linux para auditoria si sigue evolucionando en un futuro cercano. Eso espero.


WifiWay / WifiSlax

Esta es una distribución linux impresionante, me encanta, tiene un equilibrio perfecto entre el tamaño de la distribución y la cantidad de cosas que permite hacer.
Me encanta porque es lo suficientemente pequeña como para ser almacenada en un USB de estos baratos que puede haber por casa pero la cantidad de drivers y utilidades que tiene es impresionante, seguramente será una de las mejores y más completas distribuciones para auditoria wifi.

WifiSlax Logo

Podriamos llamarlas las distribuciones gemelas, podeis probar las dos, son bastante parecidas pero de vez en cuando va saliendo una versión de cada una de ellas, yo las utilizo indistintamente.


Se pueden descargar de http://www.wifislax.com/category/download/nuevas-versiones/
Además su pagina web tiene un montón de tutoriales y manuales en Español, muy bien explicados. Todos ellos además con imagenes y videos para que sea todo incluso aun mas facil, encontrareis todo lo que podais necesitar y aun mas.

Ambos linux funcionan genial tanto live como de forma persistente (evidentemente instalandolo tambien, incluso mejor, aunque no es necesario). Siempre suelo ir probando distribuciones de auditoria para ir viendo lo que ofrecen, pero cuando tengo que hacer algo serio voy directamente a estas, nunca dan problemas, funcionan, haces lo que necesitas y lo apagas, asi de facil.



Kali

Es, (según su propia web) el renacimiento del archiconocido BackTrack, si sabes del tema no necesitaras mas presentaciones.
BackTrack era el mejor y mas conocido linux para auditoria de seguidad (no solo wifi, de todo tipo) en el mundo, todo el mundo lo adora, por tanto, todos deberian estar encantados también con Kali.

Digo esto porque hay algunos cambios en su forma de funcionar (la inmensa mayoria son mejoras, claro) pero seguro que algún nostalgico del backtrack hecha en falta algun detalle.




Kali Logo
Descargate Kali de aqui https://www.kali.org/downloads/



 Hay un montón de versiones de  Kalis, para 32 bit, 64 bit, para ARMEL chips, para ARMHF chips... incluso tienes la opcion de bajarte un core de linux donde tu puedas irte personalizando tu propia versión de Kali, todo muy geek.


Resumiendo, es un linux enorme si hablamos de herramientas, funciones, utilidades...tiene mucho mas de lo que podrias aprender a utilizar en siete vidas, pero en mi opinión tiene demasiadas cosas para poderlo llevar en el tipico USB barato. Quiero decir, funciona estupendamente tanto live, instalado.... todo bien, pero es algo pesado.


Me suele gustar hacer una especie de resumen grafico de cada post para que todos podamos ver de un vistazo la idea general de estas distribuciones:

WifiSlax

Xiaopan
Kali



Xiaopan, te sentirás como Bart Simpson
WifiSlax, rápido y efectivo, sin chorradas.
Kali, enorme, poderoso, pontente, brutal.

En próximos post hablaremos de como hacerte un USB arrancable con linux, la cosa es actualmente mucho mas facil que antaño.


Somos legión.

Tuesday, January 20, 2015

My preferred linux distros. Wireless auditory

Hello there,

Long time ago from my last post, there were too many changes in my life but finally I'm back :)

Today we are here to discuss about current linux live distros for wireless auditory.

There were many changes during this while, lots of linux flavours with many wireless audit tools already installed and ready to run live, persistent or installed on your hard disks but today I will write for my favourites.

  • Xiaopan OS (the tiny one)
  • WifiWay / WifiSlax (actually, the same)
  • Kali (huge, a beast)

The tiny one, Xiaopan OS

Xiaopan Logo

You can download the ISO file from http://sourceforge.net/projects/xiaopanos/   just ~70 Mb and all the info about it at http://xiaopan.co/


From it's own website we get this comments:

Xiaopan OS is an easy to use security and penetration testing with a collection of wireless security and forensics tools. It includes a number of advanced tools for network administrators, security professionals and home users to test the strength of their wireless networks and eliminate any vulnerabilities.
Xiaopan (0.4.7.2 is the latest)

I've tested this distro three times:
The first one: my desktop computer, It worked great live from my USB device, I tested many tools and opcions, all working fine. It's tiny but powerful.
The second one with my laptop, it was unable to detect my wireless network interface, testing tons of "solutions" from the Xiaopan forums, end of story :(
The last one: With my girlfriend's notebook, same as the previous one, wireless interface not detected.

So, my conclusion is that Xiaopan is a very light linux distribution full of options and utilities but it needs a few more controllers and drivers to be widely compatible to many computers and devices. It will be great in the near future, I hope.


WifiWay / WifiSlax

These are awesome linux distributions that I love, it's light enough to be stored in a cheap USB device but has drivers, utilities....  enough to be a great penetration testing linux distribution.

WifiSlax Logo


We can call them the twin distributions, you can test both of them, they are likely the same but from time to time one of them releases a new version, so, I switch between them properly.

You can download it from http://www.wifislax.com/category/download/nuevas-versiones/
Its website has many tutorials and news it Spanish but you'll be able to translate it with no problem, all of them are plenty of photos and videos where you can find all then info you may need.

Both distributions will work great both live or persistent (obviously installed too). I used to test many linux distributions but I'm always  back to WifiSlax when I need to do something important, with no problems, no issues, just working quick and fine.


Kali

It's, (said by their own website) the rebirth of BackTrack, if you know, that's the only presentation that it needs.
BackTrack was the best well-known penetration testing linux distribution in the world, everybody loved it; and now, everybody should love Kali too.

I say that because there are a few changes in the way it works (most of them have improved it) but there are many nostalgic people who misses backtrack.


Kali Logo
You can download Kali here https://www.kali.org/downloads/



 There are many Kali versions, for 32 bit, 64 bit, for ARMEL chips, for ARMHF chips... eventualy you have the chance to download the core and build a custom version for your own.


In summary, it's a huge linux looking at the tools, functions, utilities... it has all you will need for seven lifes! But, it's (from my point) too big for live USB. I mean, it works live from USB but it's not as responsive and quick like WifiSlax



I always love to summarize with images to make things easier to think, that's my view of these distros:

WifiSlax

Xiaopan
Kali



Xiaopan, you'll feel like Bart Simpson
WifiSlax, quick and effective.
Kali, huge and powerful.

In the next post I will write about how to make your own linux USB bootable.

We are legion










Wednesday, April 18, 2012

Shutting down the Internet #OpBlackout

(Now you can access to the Spanish version of this post | Ya puedes leer la versión en Español de este post)

Hi there,
Hope you are doing well.

Does someone know what is the Operation Blackout?
Referring to the post title, this could mean "shutting down the internet" but the title is not 100% accurate.


We will proceed step by step.


What is a IP address?

In a easy way, is the registration plate of your PC. The only thing you should know is that you will share your registration plate with other users if you are sharing a router (like the ADSL router in your home)


What is a DNS Server?

In a short manner, a DNS Server is a address translator on the Internet.
When you type in your internet browser "www.mywebpage.com", your PC won't know what's that because
your PC only knows about IP addresses.

Then, the DNS will help your PC when translating:
www.mywebpage.com  ====>  12.34.56.78




How DNS Servers work?

There are only a few main dns servers, other DNS servers are working just by getting data from another DNS servers.
This is a distributed work which will improve the DNS translation performance.




Then, how can Anonymous shut down the internet?

Anonymous """""only?""""" need to bring down those root DNS servers and other will bring down in a domino effect.

Click here to get more information about root DNS Servers.

Why we say "only"?

There are many technical reasons that turns this attack very hard or even impossible.
The main reason is that these main DNS servers are implemented as clusters using Unycast but we won't explain this because this blog only explains the easy and basic hacking issues.

Next post: "Windows 8 will not allow SW non-MS SW" (English)
Siguiente post: "Windows 8 bloqueará programas de terceros" (Spanish)

We are legion

Sunday, April 15, 2012

CISPA (La nueva versión de SOPA)


!Hola a todos!

¿Vives en EE.UU.?


Si es así, tengo malas noticias para ti. Durante este mes un nuevo proyecto de ley está siendo preparado y se llamará "CISPA" ( Cyber Intelligence Sharing and Protection Act )

Puede obtener información oficial sobre la HR3523 aquí. También conocida como el proyecto de ley de Rogers-Ruppersberger.
Estoy muy preocupado por este nuevo proyecto de ley y espero que no seconvierta en ley en los EE.UU.

Mucha gente está escribiendo información acerca de este nuevo proyecto de ley lo que hasta donde yo sé, significará el regreso de SOPA, PIPA y ACTA juntas. Este proyecto de ley se quiere mostrar "distinto a SOPA", pero tiene un montón de temas similares. Por cierto, este nuevo look del proyecto SOPA+ACTA+PIPA ya ha recogido muchos seguidores entre ellos uno muy famoso, Facebook, que es el principal apoyo.

Hay muchos puntos de este proyecto de ley donde no es muy clara, pero explica que los ISPs serán capaces de interceptar comunicaciones privadas para enviar a la NSA (National Security Agency) y DOD's Cibercommand. .

La parte más peligrosa de este proyecto de ley es que algunas empresas serían capaces de espiar y controlar las conexiones de los usuarios sin necesidad de notificar esa actividad a que el usuario o el Gobierno. Por lo tanto, mucha gente piensa que este proyecto de ley se convertiría en una ley que permite el espionaje industrial.

Empresas como AT & T, IBM, Oracle, Symantec, Microsoft, EMC ... apoyarán CISPAdebido a que sus responsabilidades se reducirán en caso de problemas con la ley.

Incluso las empresas como Google o Facebook podían interceptar correos electrónicos y compartir entre ellos y el gobierno.

¿Quieres investigar más a fondo? Sigue este enlace

 

Realmente, esta es una mala ley, como SOPA y CISPA o, peor aún, y parece que va a pasar sin que la gente hable.

Si no estás en EE.UU. debes estar muy preocupado (como yo) porque la mayor parte de las leyes de EE.UU. se acaban "exportando" a otros países como España, Reino Unido, Alemania, Francia ...

Somos legión.


Siguiente Post"#OpBlackout, shutting down the internet" (Ingles)
Siguiente Post"#OpBlackout, desconecando internet" (Español)

Tuesday, April 10, 2012

Piratear la tarjeta de crédito de tu Xbox360

(Esta es la versión en Español de un post anterior en ingles | Now you can access to the English version of this post)

Hola a todos,

¿Has vendido tu antigua Xbox 360?

Si no golpeaste el disco con un martillo tengo malas noticias para ti.
Algunas investigaciones sobre la seguridad de los datos de Xbox 360 en la Universidad Drexel encontraron problemas de seguridad sobre el almacenamiento de datos de las tarjetas de crédito.

Incluso un "resetde fábrica" no sería suficiente para eliminar por completo los datos de la tarjeta de crédito. Habría que ser más exhaustivos con el fin derealizar un borrado completo.


¿Qué pasa con otros productos de Microsoft?

Este problema se reproduce en otros sistemas de Microsoft, como Windows.
Cuando se está formateando el disco duro en un sistema Windows, serás avisado de la eliminación de datos, pero, ¿eso es cierto?

La respuesta es "NO", durante el "formateo del disco" MS Windows sólo ajusta los datos como "no usado", pero la información permanece en el disco. Esta es la forma de trabajo en que algunas herramientas de recuperación de datos, estas herramientas leeran el disco completo, incluyendo los sectores marcados como no utilizados.


¿No vendiste tu Xbox y que quieres borrar sus datos?

En primer lugar debes quitar el disco de la Xbox 360, entonces, yo recomendaría algunas utilidades de disco como "Hiren Boot", "QMagic", "Partition Magic" .... todos ellos llevarán a cabo un formateo de bajo nivel de disco y esto implica el borrado completo.

Ahora ya se puede vender la Xbox  :)




¿Hay noticias relacionadas de Microsoft?

Hay algunas noticias sobre este tema, pero no está muy claro. Alguien dijo que MS está investigando el tema, pero no hay información oficial todavía.


Somos legión.



Siguiente post "CISPA (the new version of SOPA)" (Inglés)
Siguiente post "CISPA (La nueva versión de SOPA)" (Español)




PD: Este post llevó más tiempo debido a las vacaciones de Semana Santa en España

Monday, April 9, 2012

Hacking XBox360 card credit data

(Now you can access to the Spanish version of this post | Ahora puedes leer este post en Español)

Hi all,

Did you sold your old Xbox 360?

If you didn't hit the disc with a hammer, I've bad news for you.
Some investigations about Xbox 360 data security at Drexel University found security issues about the storage of credit card data.

Even a "full factory reset" will not be enough to completely delete your credit card data. You'll need to be more exhaustive in order to perform a full deletion.


What about other MS products?

This issue is reproduced in other Microsoft systems, like Windows.
When you're formatting your hard disk on a windows system, you will be noticed about the data deletion, but, that's true?

The answer is "NO",  during the "disk formatting" MS Windows is just setting the data as "unused" but the information remains in the disk. This is the way that some data recovery tools work, these tools will read the full disk including sectors labeled as unused.


Don't you sold your Xbox yet and you wanna erase your data?

First you should remove the disk from the Xbox360, then, I would recommend you some disk utilities like "Hiren's Boot", "Q Manager", "Partition disk manager".... all of them will perform a low level disk formatting and this implies low level disk erasing.

Now, you can sell it :)




Are there news related from Microsoft?

There are some news about this issue, but it's not very clear. Someone said that MS is investigating the issue but there are no official information yet.

We are legion.

Next post "CISPA (the new version of SOPA)" (English)
Next post "CISPA (La nueva versión de SOPA)" (Spanish)


P.S: This post took longer because the Semana Santa holidays in Spain :)





Monday, April 2, 2012

OpenVas vs Nessus (Spanish)


(Esta es la versión en Español de un articulo previo en Ingles | Now you can access the English version of this post)

¡Hola!

Hoy vamos a hablar de OpenVAS y Nessus, pero creo que vamos a empezar el post a partir de una idea más básica:


¿Qué es una vulnerabilidad?

Las vulnerabilidades también se conocen como "agujeros de seguridad". Un significado sencillo de estos agujeros puede ser: "los agujeros de seguridad se pueden ver como las puertas abiertas en un PC cuando usted se cree que estas puertas están cerradas"





 Realmente creo que la mayoría de la gente no sabe que estas puertas ni siquiera existen.











La mayoría de las vulnerabilidades no son fáciles de detectar por un ser humano, incluso un experto en seguridad puede no ser consciente de las vulnerabilidades de su PC.

Debemos saber que la mayoría de las vulnerabilidades son causadas por las aplicaciones software bien conocido como navegadores de Internet, aplicaciones de mensajería (como el MS Messenger, Skype, IRC ...).
Los correos electrónicos maliciosos son una gran fuente de riesgos para la seguridad también. Si estás preocupado sobre si su ordenador es vulnerable, deberías ejecutar un escáner de vulnerabilidades.



¿Qué es un análisis de vulnerabilidades?

De una manera simple, un análisis de vulnerabilidades es una herramienta script con una gran cantidad de plugins que son capaces de detectar las vulnerabilidades de forma automática.Cada plugin es un "módulo" capaz de detectar un tipo particular de vulnerabilidad.


OpenVAS y Nessus son los escáneres de vulnerabilidades.


Nessus

Nessus es un escáner de vulnerabilidades muy conocido.

Pros:


  • Fácil de instalar
  • Interfaz simple, que sólo tiene los elementos necesarios.
  • Mayores pruebas de calidad
  • Sólo una empresa que lo soporta
  • Mayor cantidad de plugins.


Contras:

  • Hay una edición casera (gratuita) pero es muy limitada
  • La edición profesional es muy cara.


Opinión:

Sólo he trabajado con la edición de casa, es fácil de usar.
Ok para llevar a cabo sus exploraciones en primer lugar para aprender acerca de este "mundo".
No tuve el placer de trabajar con Nessus "pagado"



OpenVAS


Pros:

    Open Vulnerability Assessment System
  • Completamente libre, y aun mejor, completamente de código abierto.
  • Usted será capaz de reprogramarlo, si desea hacerlo.
  • Ser libre significa y de código abierto implica que será soportado por muchas empresas.
  • Funciones más avanzadas que Nessus.
  • Es 100% operativa, usted podrá disfrutar de toda la potencia de OpenVAS, no como Nessus.
  • Cuenta con mejores herramientas de acceso, al igual que un cliente web, un cliente de la consola ...

Contras:

  • Es más difícil de instalar, de configurarlo y usarlo.
  • Un software libre de código abierto podía no  transmitir la confiabilidad de uno de pago.


Opinión:

Esta es mi favorita, con ella se podrá realizar exploraciones muy avanzadas. Es potente pero no es fácil de usar.

Somos legión

Siguiente post "Hacking XBox360 card credit data" (Inglés)
Siguiente post "Piratear la tarjeta de crédito de tu Xbox360" (Español) 

Saturday, March 24, 2012

PayPal is vulnerable, XSS (Spanish)

(Esta es la versión en Español de un post previo en ingles | This is the previous version of a post in English)

Hoy estamos aqui con el siguiente post sobre un tipo de haking.


Hace unos meses (sober Diciembre de 2011) dos hackers de India fueron capaces de ejecutar un ataque utiliando la URL del website de PayPal.
Eso no significa ni de lejos que hayan conseguido asaltar los servidores de esta empresa, no es esa la idea. Pero ellos podrian haber ejecutado algun tipo de ataque "Man in The Middle/Hombre en Medio" (MITM)




¿Porque y/o para que querria alguien ejecutar un ataque MITM?

Este es el punto más simple del post: para robar información sensible como pueden ser usuarios y contraseñas e incluso cuentas bancarias.








¿Que es un ataque MITM?


Vamos a suponer: Quiero ejecutar un ataque MITM entre un servidor de Google y el PC de un amigo.
Inicialmente necesetariamos algun programa o herramienta para "engañar" al PC de tu amigo (p.ej: Metasploit).
Cuando el acceda a www.google.com, realmente no estará accediendo a Google, el accederá a mi PC que estará camuflado como tal servidor mientras yo estoy conectado realmente al servidor de Google.

En la imagen superior, "Web Server" podria ser Google de nuestro ejemplo y "Victim" sería el PC de nuestro amigo.

En la imagen de la izquierda, la victima es "authorized user". El atacante dice al punto de acceso (AP) que él es la victima (el usuario autentico) y el atancante también le dice al usuario que él es el AP.

Te este modo, el atacante estará literalmente en el medio de la comunicación de datos.
Entonces, el usuario autentico pensará que está conectado directamente a la red corporativa pero el atacante estará revisando e incluso almacenando toda la información que transmita.



Entonces ¿Que es XSS?

XSS es un tipo de vulnerabilidad directamente relacionada con paginas y aplicaciones web que permiten al atacante introducir y obtener datos saltandose cualquier validación por parte del servidor.
De este tipo de vulnerabilidad pueden darse varios casos y tipos, veremos lo más sencillo.

A modo de resumen (si eres un hacker o experto en seguridad probablemente estas afirmaciones te producirán ardor de estomago, este blog siempre piensa en explicaciones sencillas para gente que no es experta)

- Si el hacker engaña al usuario remoto y usa sus datos para entrar en el servidor, es un ataque XSS no persistente.
- Si el hacker engaña al servidor y utiliza sus datos para conectarse con el cliente y obtener sus datos, es un ataque XSS persistente.

Para hacerse una idea del segundo tipo, una explicación gráfica:

Si ya quieres meterme más en el tema sobre XSS te remito aqui.
------------------------


Somos legión.
Siguiente post: "HOIC: new improved version of LOIC"

Friday, March 23, 2012

Reaver (WPS attack) and WPAMagicKey tools (Spanish)

wep wpa WPA 
(Esta es la versión en Español de un post reciente | This is the Spanish version of a previous post)



Hace unos meses se escucho: "WPA ha caido, lo hemos crackeado!"

Mentira cochina, es absolutamente falso, nadie ha crackeado este algoritmo de cifrado. Hoy, esta sera nuestra idea principal.
Por lo menos, nadie ha publicado nada sobre como crackear WPA. Hace ya mucho tiempo que se abrió la forma de crackear WEP pero todavía no es la hora de WPA (WPA2 va incluido cuando hablamos de WPA)
Hay algunas formas de acceder a redes wifi con WPA habilitado pero ninguno de ellos podria llegar a ser llamado "cracking" como tal:

- Capturar el handshake de WPA - TKIP (aircrack + diccionario): esto no es cracking porque necesitarías un diccionario a posteriori para poder obtener la contraseña. Sin diccionario previo, no serás capaz de obtener nada.
- Usar WPA Magic Key  (sin aircrack): Esta herramienta puede generar una lista de contarseñas por defecto para routers WiFi de los tipos WLAN_XXXX o JAZZTEL_XXXX y que además se cumpla de que nadie haya cambiando nunca su clave (son las que vienen por defecto). Esta herramienta no calcula la clave, simplemente la saca de una lista de candidatas.
- John The Ripper (para usar con aircrack): Puedes generar tus propios diccionarios if sabes el patron que va a seguir la contraseña y además no es una contraseña demasiado larga (menos de 4 - 5 caracteres), si es muy larga tu diccionario tendría un tamaño imposible de manejar, totalmente inmenso. (Ver la tabla y grafico a continuación)




De los calculos en la tabla anterior, puede ser una muy mala idea intentar crackear una clave por fuerza bruta en una red inalambrica WPA.

En el grafico anterior podemos comprobar que la mayor parte de las contraseñas suelen ser del tipo más complicado de sacar (de caracteres mezclados)

Entonces, ¿estamos bastante seguro de que nadie ha crackeado una WPA, no?

Desde el punto del vista del hacker, la diferencia más importante entre WEP y WPA is lo que se trasmite dentro del paquete IP. WPA nunca va a introducir en la transmisión ninguna información relativa a la clave maestra de la red, lo anterior no es correcto en el caso de las redes con cifrado WEP.

En el grafico siguiente podemos ver un pequeñisimo esbozo de como se contruyen los paquetes en base a claves que a su vez derivan de la clave original. De ahí que no haya datos de la clave original en la transmisión.

Ahora deberíamos aprender algo más de WPS (Wikipedia). La forma mas simple y sencilla para tener en mente lo que es WPS: "WPS es un botón". Si así como suena, es un botón que te deja conectarte a la Wifi, o no.
Finalmente, si nadie ha sido capaz de crackear una WPA, ¿Que demonios es reaver? ¿Que puede hacer por mi? ¿Voy a ser capaz de usar reaver?

- Reaver: Es una herramienta script que utiliza la vulnerabilidad WPS para engañar al router y hacerle crear que estamos haciendo una configuración remota del router, en la que le solicitamos algunos datos, como por ejemplo... que se yo... la contraseña?  :)
- Por lo que yo se, reaver solo va a poder ayudarte mientras la red esté utilizando TKIP (no soportado para AES, aun!!!)
- Previamente, antes de ejecutar "reaver" deberías ejecutar la herramienta "walsh", que es un script que te va a avisar de que redes inalambricas en tu alcance serían susceptibles de poder atarcarse.

Hay montones de video tutoriales sobre reaver... (mi favorito es el primero)
Video#1 (en este te van a explicar como instalar, es muy bueno, en Inglés)
Video#2

También podrias necesitar estas pistas

In la mayor parte de los casos podrás obtener reaver en distribuciones linux como BackTrack o WifiWay.
En alguno de los próximos post hablaremos de la nueva versión de WifiWay (v. 3)

Ya sabemos que no se debe utilizar para hackear, tienes que utilizar esto exclusivamente para seguridad, vale?

Somos legión

================================================================
Siguiente Post: "PayPal is vulnerable, XSS"

Google Hacking, cuidado con tu sitio web!!! (Spanish)

(Esta es una versión traducida de un post anterior en Ingles - This is the Spanish version from a previous one in English)

¡Hola!
Hace mucho tiempo del último post, he estado muy ocupado los últimos meses.
Estamos de vuelta otra vez a hablar de un estilo antiguo clásico de hacking: "Google Hacking".

Esta forma es muy simple ya que no requiere ninguna herramienta avanzada o software, se puede hacer simplemente con una conexión de módem de 56k a Internet (Aunque realmente espero que tu conexión es un poco más rápida!!)

Todos nosotros sabemos de los algoritmos de búsqueda avanzados y recolección de datos de gran potencia de Google, creo que Google es el buscador más avanzado tecnológicamente en el mundo en este momento (en los últimos 5 - 10 años).

Google es mucho más que un cuadro de texto y un botón de "Buscar", e incluso mucho más que un "voy a tener suerte" :)

Debemos saber que Google tiene capacidad de recoger datos de archivos que no sean clásicos de las páginas web html, cada día Google está detectando una gran cantidad de archivos pdf, doc, ... .

Google tiene muchas opciones y filtros de búsqueda avanzada, como la búsqueda por tipo de archivo, por parte de texto en una dirección web (url), por la extensión de archivo ...

Este mecanismo es simple como:

- Búsqueda de doc. Watson informa de un servidor
- Buscando información importante de los datos personales
- Búsqueda de archivos con cuentas de usuario
- Búsqueda de archivos con usuarios y contraseñas!!

Sí, por supuesto, toda esta información está ahí, tenemos libre acceso, a muchos archivos sólo a través de Google.

Puede acceder a la ayuda de Google con el fin de aprender "comandos" para llevar a cabo algunas búsquedas avanzadas.

Recientemente, este tipo de piratería informática fácil y simple fue utilizado contra muchos organismos de seguridad importantes de los EE.UU. y Europa Occidental.

Este método puede ser considerado "Ingeniería Social"

----------------------------------------------------------------------------------------------

Somos legión.
Siguiente post:
"Reaver (WPS attack) and WPAMagicKey tools"

PayPal is vulnerable, XSS

(There is another post in Spanish | Puedes acceder a la versión de post en Español aqui)
Today, here we are with the next post about a kind of hacking.


A few months ago (about December'11) two Indian hackers were able to launch an attack using the URL from the PayPal site.
That not means anything about the server breaking-into, this is not correct. But that could mean a "Man in the middle" attack (MITMA).









Why wanna do with a MITM attack?
Easy to know, to review and steal your sensitive information like user accounts and passwords, bank accounts...




What's a "man in the middle attack"??


We will supose: I want to launch a MITM between Google and a friend's pc. I'll need a software to "cheat" my friend's pc (i.e. Metasploit). When he writes google.com he won't access to google,he'll access to my pc camouflaged as Google web site and I will be connected to the real Google server.

In the image (right), "Web Server" could be Google in our example and the victim PC is our friend's PC.




In the image (left), the victim is "authorized user". The attacker say to the access point (AP) that he is the authorized user and the attacker say to user that he is the AP.



By the way, the attacker will be in the middle of the data traffic.

Thus, the authorized one will think that he is directly connected to the corporate LAN but the attacker will be seeing all his data transmission.







Then, what's XSS - (Cross Site Scripting)???


XSS is a kind of vulnerability directly related with websites and/or web applications that allows an attacker to send data bypassing server validations. This vulnerability could cause a few kinds of attacks: persistent, non-persistent...

In summary (if your an expert hacker you will feel stomach ache with this summary and definitions, it's just for let a simple definition for non-experts):

- If the hacker "cheat" the remote user and use its data to access the server data, it's non-persistent XSS attack
- If the hacker "cheat" the server admin user and use its data to access the client data, it persistent XSS attack

For the second type, this is a graphical explanation:


If you wanna get more advanced definitions about XSS, click here.
------------------------

We are legion.
Next post: "HOIC: new improved version of LOIC"

Tuesday, March 20, 2012

Reaver (WPS attack) and WPAMagicKey tools

wep wpa WPA
(There is a Spanish version of this post | haga click aqui para acceder a este post en Español)
Just a few months ago we heard:  "WPA is down, we've cracked it!"



That's absolutely wrong, no body has cracked this security algorithm. Today, this will be our main idea.
At least, no body had published anything about WPA cracking. It was long time ago from WEP cracking but not yet for WPA (of course, WPA2 is included)

There are some ways to access to a WPA wireless network, but none of them could be called "cracking":

- Capture the WPA - TKIP handshake (aircrack + dictionary): this is not cracking because you need a later dictionary attack to be able to get the password. If you have no dictionary, you won't be able to get the password.
- Use the WPA Magic Key dictionaries (w/o aircrack): This tool can generate the default password list for this router if your wireless is WLAN_XXXX or JAZZTEL_XXXX and you never changed your password.
- John The Ripper (to use with aircrack): You can generate your own dictionary if you know the password pattern and it's not very long (shorter than 4 - 5 characters), if it's long your dictionary will be huge and you won't be able to use it. (View table and pie chart below)




From the calculations in the table above, it could be a bad idea try to crack by using brute force attack in a WPA wireless network.


In the pie chart below you can check what most passwords are in the strongest group (mixed character type).





Then, I think still nobody cracked a WPA password, right?


From the hacker point of view, the most important difference between WEP and WPA is what they transmits on the IP package. A WPA packet is not transmitting any information about the network master key, this is not true about WEP encryption.

Now, we must learn about WPS (Wikipedia EN). The most simple&easy way to think what's WPS: "WPS is a button which allows us to connect (or not) to a WiFi".
Finally, if nobody was able to crack a WPA... what the hell is reaver? what the hell can it do for me? will I be able to use reaver?

- Reaver: Is a script-tool which will use a WPS vulnerability algorithm to "cheat" a router and get the WPA key.
- As far as I know, reaver will only be able to help you when your're using TKIP (not supported for AES yet)
- Previous to execute "reaver" you should execute the "walsh" script-tool. It's a "twin-app" what will tell you which wireless networks are vulnerable to this attack.

There are lots of video tutorials about reaver... (my favority one is the first video)
Video#1 (here you will learn how to install too, very interesting)
Video#2

You maybe need this tips.

In most cases you will get reaver from linux distributions like Backtrack or WifiWay.
We will talk soon about the new rease of WifiWay (v.3)

You mustn't use this information for hacking, you have to use it just for learn about security, right?

We are legion


================================================================
Next Post: "PayPal is vulnerable, XSS"

Wednesday, September 14, 2011

Differences between DDoSing/DoSing and hacking

Today we will talk about differences between DDoSing a service and hacking a server.

If you don't know what't DDoS and DoS, go to posts about LOIC and RefRef.
I asume all of we know what the hell is "hacking", now, we are all DoS experts :)

Could be DoS or DDoS considered a type of hacking? I think it is not, at all.
From my point of view, hacking is all actions that uses some security hole to break something in our systems.

By the way, if a guy is lauching a DoS attack, this guy is not breaking anything.
The attacker is not getting any information from our system, he is not thieving, he is not breaking.

Thus, why can be a DoS considered an illegal action? I can't understand that.
I think that arresting a guy for lauching a DoS attack is not correct at all.

I think we can explain it with a example:

===================================================================
You are going home after work.


When you arrive at home, a guy is in your house door, just "blocking" it.
Your door is not broken.
Should be this guy arrested? Is that correct?  I think not.


Instead that, you should think what you did to motivate this guy to block your house door.


You just may use other door or push him out of your door (this is just, reboot a service) and you will be able to use your house normally.
===================================================================

After the example, all of we may agree, DoS should not be considered illegal, because is not damaging anything, right?

"We are legion"
Next Post: "What the hell is Nessus? Fast overview"

Monday, September 12, 2011

"URGE" (Universal Rapid Gamma Emitter) Hijacking Twitter

(Spanish follows | Después en Español)

Today we will talk about the new tool called URGE. This is a tool to auto-tweet, just that.

Are you tired of trending topics from twitter never reflect our interests?
Are you tired of those trendings like "sex" or other non-actual topics?
Are you tired of twitter never reflects our world news or problems?




URGE is here to solve it, now you can tweet your news many times without the need of continous copy&paste&tweet.

This a hijacking tool:
 - NOT hacking, URGE is not exploiting any security hole.
 - NOT DoSing, it is not blocking twitter access.
 - NOT DDoSing, it is not coordinating a DoS.

Let's free the twitter trending topics!

"We are legion"
Next Post: "Differences between DDoSing/DoSing and hacking"

=================================================================

Hoy hablaremos sobre la nueva herramienta llamada URGE. Esta herramienta sirve para twitear automaticamente, solo eso.


Cansado de que los trending topics de twitter nunca reflejen tus intereses?
Cansado de esos trendings como "sexo" o otros desactualizados?
Cansado de que twitter nunca refleje los problemas y noticias mundiales?





URGE ha llegado para solucionarlo, ahora puedes twitear y retwitear tus noticias y novedades muchas veces sin la necesidad de copiar, pegar y twitear.

Esta es una herramienta de hijacking:
 - NO es hacking, URGE no está atancando a los sistemas de twitter.
 - NO es DoSing, no está bloqueando ni colapsando el sistema de twitter.
 - NO es DDoSing, no está coodinando ninguna ataque DoS.

Liberemos los trending topics de twitter!

"Somos legión"

Siguiente Post: "Differences between DDoSing/DoSing and hacking"



Friday, September 9, 2011

RefRef - Creating a huge army

(Spanish follows)

LOIC was retired due to most of the hacktivists who were arrested last year used this software.
Their connection data was tracked by police and they were finally arrested.
They should used several hidding methods like VPNs, proxies, connetion through cyber-cafe...

RefRef is the brand new weapon which is being tested from a few time ago. RefRef is called to replace LOIC (Low Orbit Ion Cannon) and upgrade its capabilities.

The weapon will be available for download from this month. First news about the tests reveals that RefRef have a lot of power :)

This new weapon offers new possibilities, due to it's based on JavaScript, this means that can be used from most platforms like computers, laptops, tablets, smartphones...
And maintains older ones like the possibility of creating "zombies", that is, to build up a bot-net and launch a huge attack at the same time.

RefRef has a new one advantage that turns it more powerful than LOIC, RefRef is able to perform SQL-i to create a devastating effect combined to the attack behavior from LOIC.


What is SQL-i?

Have you ever seen a web URL like this?

        www.myownweb.com/post?user=JohnDoh

Just try to change the parameter "user" to access to another data, something like:

        www.myownweb.com/post?user=MikeH

Yeah! You have completed your first SQL-i attack! :)
Of course, this is not representative for the RefRef behavior but this is the essence :)

Do you remember when people talk about "Web 2.0"?
I think "DDoS 2.0" is comming.


"We are legion"

PS: www.myownweb.com is just an example. Do not try to SQL-i attack this URL
Next Post: "URGE (Universal Rapid Gamma Emitter) Hijacking Twitter"
---------------------------------------------------------
Next topics:
- "URGE (Universal Rapid Gamma Emitter) Hijacking Twitter"
- "Operation Icarus"
- "Differences between DDoSing/DoSing and hacking"
- "Can we effectively hide our data connection?"
- "What the hell is Nessus?"


======================================================================
                      Spanish / Español:

LOIC ha sido retirado debido a que la mayor parte de los hacktivistas arrestados el año pasado habían utilizado esta aplicacion.
Los datos de su conexión fueron rastreados por la policia y fueron finalmente arrestados.
Deberían haber utilizado de forma combinada diversos metodos de ocultación de sus datos como VPNs, proxy y/o conexiones desde luegares publicos.


RefRef es la novedosa arma que está siendo probada desde hace algun tiempo. RefRef es el reemplazo de LOIC y mejorará sus capacidades.

Esta arma estara disponible para su descarga durante este mes. Las primeras noticias confirman  que es muy poderoso :)

Esta nueva arma ofrece nuevas posiblidades, debido a que esta basada en JS, esto implica que puede ser ejecutado desde diversas plataformas como ordenadores de sobremesa, portatiles, tables o telefonos de ultima generación.
Además mantiene las ventajas de LOIC como la posiblidad de crear PC zombis, esto es, crear una red de bots para preparar un ataque a gran escala.

RefRef tiene una novedad que la proporciona una gran ventaja frente a su predecesor, es capaz de atacar con SQL-i, lo que aumenta muchisimo sus capacidades.


¿Que es SQL-i?

¿Alguna vez habeis visto una direccion como esta?

        www.myownweb.com/post?user=JohnDoh

Probad a cambar el parametro "user" para intentar acceder a otros datos, algo así:

        www.myownweb.com/post?user=MikeH

Toma ya! Acabas de realizar tu primer ataque de injección SQL!
Por supuesto, esto no es representativo para RefRef, pero es la idea. :)

Recordais cuando se hablaba de la "Web 2.0"?
Pues os doy la bienvenida a "DDoS 2.0"


"Somos legion"

PD: www.myownweb.com no es más que un ejemplo. 
No intenteis atacar esta dirección, por favor.
Siguiente Post: "URGE (Universal Rapid Gamma Emitter) Hijacking Twitter"
---------------------------------------------------------
Proximos temas:
- "URGE (Universal Rapid Gamma Emitter) Hijacking Twitter"
- "Operación Icaro"
- "Diferencias entre DDoSing/DoSing y hacking"
- "Podemos ocultar de forma eficiente nuestros datos?"
- "Que coño es Nessus?"

Monday, September 5, 2011

Low Orbit Ion Cannon - One of the best weapons


(Spanish follows) (En Español a continuación)
--------------------------------------------------------------------------------------------------------------------------------
This post is dedicated to a great friend and journalist.

Today we will write about LOIC, one of the most used DDoS weapons on the internet.
But we will start from bottom to top.

What the hell is a "DoS"?

It stands for "Denial of Service", that means: it is to perform a huge number of requests to a server, a number enough to don't let the server to attend other request but yours.

A cool example could be a pub

When you go to ask for a pint of beer, the waiter could attend other people, but, if you ask for ten thousand pints of beer the waiter will become very busy to attend other request but yours.

Thus, what the hell is "DDoS"?

This stands for "Distributed Denial of Service", that means: it is to form a team and all of you perform a huge amount of requests, each one of you. This is to say, to perform several simultaneous "DoS" attacks.

I'll try to continue with the example of the pub.

If your friends and you go to a pub and all of you agrees to ask for ten thousand of pints at the same time, the waiter will become very busy, really overloaded.

Moreover, depending on the time you maintain this attack, the result of it may change.

A short time attack could be useful to know how the system can resist a stress load.
But, if the DoS or DDoS is maintained for a long time could cause a full system lock.

On our example in the pub:

If the waiter is working at full of his capacity during many time, he can suffer a heart attack and die.
(I really hope nobody will suffer a heart attack, it is just a example)

Now, we are DoS and DDoS experts :)

What is LOIC (Low Orbit Ion Cannon)?

LOIC is an application designed to perform stress tests on systems but it could be used to lauch a DoS or DDoS attack.
On the last version, it has many plugins that will allow you to perform very advanced attacks.
One of this plugins allows to let the control of your LOIC to another person, your PC becomes a "zombie" controlled by another PC.
If there is a PC controlling one million of zombies ... this is an army!!!

"We are legion"
Next Post: "RefRef - Creating a huge army"

====================================================================

Spanish / Español:

Este post está dedicado a un gran amigo y periodista.


Hoy vamos a escribir sobre LOIC, una de las armas DDoS más utilizadas en internet.
Pero vayamos de abajo a arriba.

¿Qué demonios es "DoS"?

Significa "Denegación de Servicio", esto es: ejecutar una enorme cantidad de peticiones a un servidor, un numero suficiente para no permitir al servidor que atienda ninguna peticion que no sea de las tuyas.

Un ejemplo chulo puede ser un bar

Cuando vas a pedirte una cerveza, el camarero puede ir atentiendo a otras personas, pero si pides diez mil pintas de cerveza el camarero estará un tiempo demasiado ocupado para poner cualquier pinta que no sea una de las tuyas.

Entonces, ¿Que demonios es "DDoS"?

Esto significa "Denegacion de Servicio Distribuido", eso es: que un equipo de atacantes ejecute una enorme cantidad de peticiones al mismo tiempo. es decir, varios DoS simultaneos.

Intentemos conitnuar con el ejemplo del bar.

Si tus amigos y tu vais a un bar y quedais de acuerdo para pedir diez mil pintas cada uno al mismo tiempo, el camarero estará muy ocupado, completamente sobrecargado de trabajo.

Ademas de todo esto, en función del tiempo que se mantenga el attack, el resultado del mismo podria variar mucho.

Un ataque breve puede ser muy util para saber como puede un sistema resistir una carga de estres.
Pero, si el DoS o el DDoS se matiene en un largo periodo de tiempo, es probable que el sistema acabe por caerse o bloquearse.

En nuestro ejemplo del bar:

Si el camarero esta trabajando a pleno rendimiento durante mucho tiempo, podria sufrir un paro cardíaco y morirse.
(Espero encarecidamente que nadie sufra un ataque cardíaco, tan solo es un ejemplo)

Ahora que somos expertos en DoS y DDoS :)

¿Que es LOIC?

LOIC is una aplicación diseñada para ejecutar ataques de estrers en diversos sistemas aunque puede ser facilmente utilizado para llevar a cabo un ataque DoS o DDoS.

En su última versión incluye una gran variedad de plugins que te permiten ejecutar ataques realmente complejos.
Uno de sus ultimos plugins permiten ceder el control de tu maquina a otro operador remoto, de forma que tu PC se convierte en un zombi.
Si hubiese un PC controlando un millón de zombis.... menudo ejercito!!!!.

"Somos legión"

Siguiente Post: "RefRef - Creating a huge army"

Thursday, September 1, 2011

AnonPlus is coming


Today I will think about  Anonymous and issues from last weeks.

Everybody already knows Anonymous and their fights against injustice all over the world.
Anonymous had protested all about other people but must protest about itself too.

Some weeks ago we heard about some news, some news of the Anonymous was banned from different social networks and/or other websites, like facebook or google plus.

I can't get this question out of my mind: "Why?"
- Could it be due to fight against corrupt governments?
- Could it be due to fight against corrupt companies?
- Could it be due to fight against corrupt all-types corrupt media?

I couldn't believe it when I heard that news.

But, I should forward and spread a news that appears just a few weeks ago, a new social network is comming, is being coded just now.
This social network will be absolutely free, the information will can be shared without censorship.

That will be great.

The information gets you powerful, the information gets you free.

At the moment we can access to http://www.anonplus.com


This website is available now with access to the anon-forums and the anon-chat (directly connected to some IRC servers to chat with other anons)

I think the most interesting zones in this web are: anonplus social network and other just dedicated to education about anon themes. Those two will let us to be informed people and we know that means: power and free :)

"We are legion"
Next Post: "LOIC - One of the best weapons"


Sunday, August 21, 2011

Enterprise hacking

Today we will think about enterprise hacking.


I really think most of companies had ever paid for hacking another ones.
Even more, there are some companies that have contracted some white-hat hackers to hack it self.

There are a huge amount of histories  about companies hacking other companies, governments hacking governments...

I think many people will recognize the history and the company:

--------------------------------------------------------------------------------------------------------------------------------
Some years ago, there was a company that had a problem, somebody was filtering strategic information out of the company (that was a very famous technological north american company)


The company paid some white-hat hackers to get all the information needed to hack itself, in order to get information needed to discover the "traitor".


They should do all needed in order to get the truth.


Those hacker attacked some personal email accounts, bank accounts, telephonic information... a lots of information to discover who was filtering data out of company.


Finally, the company was able to found the traitor, but he denounced to the company to breaking into his personal data and accounts. 


At the end, the company president and some directives were arrested about piracy issues.
BUT, those authorized hackers were arrested too.
--------------------------------------------------------------------------------------------------------------------------------

This controversial history didn't end with a fair finish, specially for the hackers, who are working as security computer experts.
They are not  breaking into another company to get some advantage from one to another.

We are surrounded of managers who only can think about money and numbers, keep out of them because you could be affected about their decisions.

If you are a computer expert, feel free to learn and improve. Feel free to work as a computer expert.
Most of hackers are cool, they rules!  :)

"We are legion"
Next Post: "AnonPlus is comming"

Sunday, August 14, 2011

How easy is to hack a server? (Part 2 out of 2)


Today we will talk about the second type of hacking.

From my point of view, this is the most powerful hacking type due to directly attacks the weakest point in every system, people.

There lots of ways to perform social attacks, sometimes we will get some information to directly exploit and access the target system, other times we will get some information in order to access other information, and using the second one, get access to the target system.

It depends on the system strength, we will need more or less information to obtain this access.

I will tell a history based on phishing to get access to a enterprise server in a short way:


We will suppose we know that we have access to the company "X", "X" is a big company with lots of manager hierarchies, most of the company employees could use "Linkedin"; scanning the company profiles we can find a guy who is fan of old stamps.


We must think that a big company employee probably access his email at working time.


Now we will build a website that looks serious about old stamps, like an antiquarian shop where buys and sells old stamps. At this website we will place a malicious frame in order to execute a web-client exploit.


Then we will send him an email full of stamp discounts related to a very exclusive stamp collection.
And.... "voilà": full access to the company network from the manager PC.



This is a very simple and short history in order to explain an example about how easy could be to hack an enterprise server.

We can get three steps in social hacking:
1) Get information
2) Preparing our trap
3) Exploit and access


We must know that time spent in the first step will improve our second step effectiveness
We must know that time spent in the second step will improve our third step effectiveness.

Between steps 2 and 3 can take a while, due to the company manager could be on holiday or very busy.

Now we can ask our question: How easy is to hack a enterprise server?

Very much.


"We are legion"
Next Post: "Enterprise Hacking"

Popular Posts