Showing posts with label scanner. Show all posts
Showing posts with label scanner. Show all posts

Tuesday, January 20, 2015

My preferred linux distros. Wireless auditory

Hello there,

Long time ago from my last post, there were too many changes in my life but finally I'm back :)

Today we are here to discuss about current linux live distros for wireless auditory.

There were many changes during this while, lots of linux flavours with many wireless audit tools already installed and ready to run live, persistent or installed on your hard disks but today I will write for my favourites.

  • Xiaopan OS (the tiny one)
  • WifiWay / WifiSlax (actually, the same)
  • Kali (huge, a beast)

The tiny one, Xiaopan OS

Xiaopan Logo

You can download the ISO file from http://sourceforge.net/projects/xiaopanos/   just ~70 Mb and all the info about it at http://xiaopan.co/


From it's own website we get this comments:

Xiaopan OS is an easy to use security and penetration testing with a collection of wireless security and forensics tools. It includes a number of advanced tools for network administrators, security professionals and home users to test the strength of their wireless networks and eliminate any vulnerabilities.
Xiaopan (0.4.7.2 is the latest)

I've tested this distro three times:
The first one: my desktop computer, It worked great live from my USB device, I tested many tools and opcions, all working fine. It's tiny but powerful.
The second one with my laptop, it was unable to detect my wireless network interface, testing tons of "solutions" from the Xiaopan forums, end of story :(
The last one: With my girlfriend's notebook, same as the previous one, wireless interface not detected.

So, my conclusion is that Xiaopan is a very light linux distribution full of options and utilities but it needs a few more controllers and drivers to be widely compatible to many computers and devices. It will be great in the near future, I hope.


WifiWay / WifiSlax

These are awesome linux distributions that I love, it's light enough to be stored in a cheap USB device but has drivers, utilities....  enough to be a great penetration testing linux distribution.

WifiSlax Logo


We can call them the twin distributions, you can test both of them, they are likely the same but from time to time one of them releases a new version, so, I switch between them properly.

You can download it from http://www.wifislax.com/category/download/nuevas-versiones/
Its website has many tutorials and news it Spanish but you'll be able to translate it with no problem, all of them are plenty of photos and videos where you can find all then info you may need.

Both distributions will work great both live or persistent (obviously installed too). I used to test many linux distributions but I'm always  back to WifiSlax when I need to do something important, with no problems, no issues, just working quick and fine.


Kali

It's, (said by their own website) the rebirth of BackTrack, if you know, that's the only presentation that it needs.
BackTrack was the best well-known penetration testing linux distribution in the world, everybody loved it; and now, everybody should love Kali too.

I say that because there are a few changes in the way it works (most of them have improved it) but there are many nostalgic people who misses backtrack.


Kali Logo
You can download Kali here https://www.kali.org/downloads/



 There are many Kali versions, for 32 bit, 64 bit, for ARMEL chips, for ARMHF chips... eventualy you have the chance to download the core and build a custom version for your own.


In summary, it's a huge linux looking at the tools, functions, utilities... it has all you will need for seven lifes! But, it's (from my point) too big for live USB. I mean, it works live from USB but it's not as responsive and quick like WifiSlax



I always love to summarize with images to make things easier to think, that's my view of these distros:

WifiSlax

Xiaopan
Kali



Xiaopan, you'll feel like Bart Simpson
WifiSlax, quick and effective.
Kali, huge and powerful.

In the next post I will write about how to make your own linux USB bootable.

We are legion










Monday, April 2, 2012

OpenVas vs Nessus (Spanish)


(Esta es la versión en Español de un articulo previo en Ingles | Now you can access the English version of this post)

¡Hola!

Hoy vamos a hablar de OpenVAS y Nessus, pero creo que vamos a empezar el post a partir de una idea más básica:


¿Qué es una vulnerabilidad?

Las vulnerabilidades también se conocen como "agujeros de seguridad". Un significado sencillo de estos agujeros puede ser: "los agujeros de seguridad se pueden ver como las puertas abiertas en un PC cuando usted se cree que estas puertas están cerradas"





 Realmente creo que la mayoría de la gente no sabe que estas puertas ni siquiera existen.











La mayoría de las vulnerabilidades no son fáciles de detectar por un ser humano, incluso un experto en seguridad puede no ser consciente de las vulnerabilidades de su PC.

Debemos saber que la mayoría de las vulnerabilidades son causadas por las aplicaciones software bien conocido como navegadores de Internet, aplicaciones de mensajería (como el MS Messenger, Skype, IRC ...).
Los correos electrónicos maliciosos son una gran fuente de riesgos para la seguridad también. Si estás preocupado sobre si su ordenador es vulnerable, deberías ejecutar un escáner de vulnerabilidades.



¿Qué es un análisis de vulnerabilidades?

De una manera simple, un análisis de vulnerabilidades es una herramienta script con una gran cantidad de plugins que son capaces de detectar las vulnerabilidades de forma automática.Cada plugin es un "módulo" capaz de detectar un tipo particular de vulnerabilidad.


OpenVAS y Nessus son los escáneres de vulnerabilidades.


Nessus

Nessus es un escáner de vulnerabilidades muy conocido.

Pros:


  • Fácil de instalar
  • Interfaz simple, que sólo tiene los elementos necesarios.
  • Mayores pruebas de calidad
  • Sólo una empresa que lo soporta
  • Mayor cantidad de plugins.


Contras:

  • Hay una edición casera (gratuita) pero es muy limitada
  • La edición profesional es muy cara.


Opinión:

Sólo he trabajado con la edición de casa, es fácil de usar.
Ok para llevar a cabo sus exploraciones en primer lugar para aprender acerca de este "mundo".
No tuve el placer de trabajar con Nessus "pagado"



OpenVAS


Pros:

    Open Vulnerability Assessment System
  • Completamente libre, y aun mejor, completamente de código abierto.
  • Usted será capaz de reprogramarlo, si desea hacerlo.
  • Ser libre significa y de código abierto implica que será soportado por muchas empresas.
  • Funciones más avanzadas que Nessus.
  • Es 100% operativa, usted podrá disfrutar de toda la potencia de OpenVAS, no como Nessus.
  • Cuenta con mejores herramientas de acceso, al igual que un cliente web, un cliente de la consola ...

Contras:

  • Es más difícil de instalar, de configurarlo y usarlo.
  • Un software libre de código abierto podía no  transmitir la confiabilidad de uno de pago.


Opinión:

Esta es mi favorita, con ella se podrá realizar exploraciones muy avanzadas. Es potente pero no es fácil de usar.

Somos legión

Siguiente post "Hacking XBox360 card credit data" (Inglés)
Siguiente post "Piratear la tarjeta de crédito de tu Xbox360" (Español) 

Thursday, March 29, 2012

OpenVas Vs Nessus

(Now you can access to the Spanish version of this post | Ya está disponible la versión en Español de este post)

Hi there!

Today we will talk about OpenVas and Nessus but I think we will start the post explaining from a most basic idea:


What's a vulnerability?

Vulnerabilities are also known as "security holes". A simple meaning of this holes can be this "Security holes can be saw as open doors in your PC when you are think that this doors are closed"







I really think that most people do not know that these doors do not even exist.










Now that we know that these doors exists, how can we close it?



Most of vulnerabilities are not easy to detect by a human, even a security expert can not be aware his/her own PC vulnerabilities.

We should know that most of vulnerabilities are caused by well know software applications like internet browsers, messenger apps (like MS Messenger, Skype, IRC...).

Malicious emails are a big source of security risks too.


If you're worried about if your computer is vulnerable, you should run a vulnerability scanner.



What's a vulnerability scan?

In a simple manner, a vulnerability scan is a script-tool with a huge amount of plugins which are able to detect vulnerabilities automatically.
Each plugin is a special "module" will be able to detect a particular kind of vulnerability.
Back to the post title, OpenVas and Nessus are vulnerability scanners.




Nessus
Nessus: Network Vulnerability Scanner

Nessus is a well known vulnerability scanner.

Pros:

  • Easy to install
  • Simple interface, it has just the neccesary items.
  • Higher quality tests
  • Only one support company
  • Higher amount of plugins.
Cons:

  • There are a home (free) edition is very limited
  • The professional edition is very expensive.
Opinion:
  • I only tried the home edition, it's easy-to-use. Ok to perform your first scannings for learning about this "world".
  • I had not the pleasure to work with Nessus "paid" editions :(

OpenVas

Pros:

Open Vulnerability Assessment System
  • Completely free and, more, completely open source. You will be able to recode it if you want to do it.
  • Being free and opensource means that it will supported by many companies.
  • It is able to implement more advanced funcions than Nessus.
  • It's 100% operative, you will be able to enjoy the full power of OpenVas, not like Nessus.
  • It has better access tools, like a web client, a console client...
Cons:
  • It's more difficult to install, to config and to use it.
  • A free-opensource software could not transmit the confiability than a "paid one".
Opinion:

  • This is my favourite one, with it you will be able to perform very advanced scans. It's powerful but not easy-to-use.


We are legion
Next post "Hacking XBox360 card credit data" (English)
Next post "Piratear la tarjeta de crédito de tu Xbox360" (Spanish)

Friday, March 23, 2012

Reaver (WPS attack) and WPAMagicKey tools (Spanish)

wep wpa WPA 
(Esta es la versión en Español de un post reciente | This is the Spanish version of a previous post)



Hace unos meses se escucho: "WPA ha caido, lo hemos crackeado!"

Mentira cochina, es absolutamente falso, nadie ha crackeado este algoritmo de cifrado. Hoy, esta sera nuestra idea principal.
Por lo menos, nadie ha publicado nada sobre como crackear WPA. Hace ya mucho tiempo que se abrió la forma de crackear WEP pero todavía no es la hora de WPA (WPA2 va incluido cuando hablamos de WPA)
Hay algunas formas de acceder a redes wifi con WPA habilitado pero ninguno de ellos podria llegar a ser llamado "cracking" como tal:

- Capturar el handshake de WPA - TKIP (aircrack + diccionario): esto no es cracking porque necesitarías un diccionario a posteriori para poder obtener la contraseña. Sin diccionario previo, no serás capaz de obtener nada.
- Usar WPA Magic Key  (sin aircrack): Esta herramienta puede generar una lista de contarseñas por defecto para routers WiFi de los tipos WLAN_XXXX o JAZZTEL_XXXX y que además se cumpla de que nadie haya cambiando nunca su clave (son las que vienen por defecto). Esta herramienta no calcula la clave, simplemente la saca de una lista de candidatas.
- John The Ripper (para usar con aircrack): Puedes generar tus propios diccionarios if sabes el patron que va a seguir la contraseña y además no es una contraseña demasiado larga (menos de 4 - 5 caracteres), si es muy larga tu diccionario tendría un tamaño imposible de manejar, totalmente inmenso. (Ver la tabla y grafico a continuación)




De los calculos en la tabla anterior, puede ser una muy mala idea intentar crackear una clave por fuerza bruta en una red inalambrica WPA.

En el grafico anterior podemos comprobar que la mayor parte de las contraseñas suelen ser del tipo más complicado de sacar (de caracteres mezclados)

Entonces, ¿estamos bastante seguro de que nadie ha crackeado una WPA, no?

Desde el punto del vista del hacker, la diferencia más importante entre WEP y WPA is lo que se trasmite dentro del paquete IP. WPA nunca va a introducir en la transmisión ninguna información relativa a la clave maestra de la red, lo anterior no es correcto en el caso de las redes con cifrado WEP.

En el grafico siguiente podemos ver un pequeñisimo esbozo de como se contruyen los paquetes en base a claves que a su vez derivan de la clave original. De ahí que no haya datos de la clave original en la transmisión.

Ahora deberíamos aprender algo más de WPS (Wikipedia). La forma mas simple y sencilla para tener en mente lo que es WPS: "WPS es un botón". Si así como suena, es un botón que te deja conectarte a la Wifi, o no.
Finalmente, si nadie ha sido capaz de crackear una WPA, ¿Que demonios es reaver? ¿Que puede hacer por mi? ¿Voy a ser capaz de usar reaver?

- Reaver: Es una herramienta script que utiliza la vulnerabilidad WPS para engañar al router y hacerle crear que estamos haciendo una configuración remota del router, en la que le solicitamos algunos datos, como por ejemplo... que se yo... la contraseña?  :)
- Por lo que yo se, reaver solo va a poder ayudarte mientras la red esté utilizando TKIP (no soportado para AES, aun!!!)
- Previamente, antes de ejecutar "reaver" deberías ejecutar la herramienta "walsh", que es un script que te va a avisar de que redes inalambricas en tu alcance serían susceptibles de poder atarcarse.

Hay montones de video tutoriales sobre reaver... (mi favorito es el primero)
Video#1 (en este te van a explicar como instalar, es muy bueno, en Inglés)
Video#2

También podrias necesitar estas pistas

In la mayor parte de los casos podrás obtener reaver en distribuciones linux como BackTrack o WifiWay.
En alguno de los próximos post hablaremos de la nueva versión de WifiWay (v. 3)

Ya sabemos que no se debe utilizar para hackear, tienes que utilizar esto exclusivamente para seguridad, vale?

Somos legión

================================================================
Siguiente Post: "PayPal is vulnerable, XSS"

WifiWay 2, hack the air!!! (Spanish)

(Versión traducida de un post antiguo - Old version from an old post (english))


Hoy vamos a hablar sobre "WifiWay".

WifiWay is una distribución de linux gratuita y abierta que es "la hija" de WifiSlax.
Esta es una distribución de linux bien conocida en relación con la auditoria wireless.

De la antigua, WifiSlax, WifiWay heredó montones de utilidades y herramientas, como el framework de aircrack, incluyendo airodump, aircrack, aireplay... etc
Estas herramientas eran geniales, pero no eran fáciles de usar para usuarios novatos o auditores con un bajo conocimiento.
 
Esta evolucionó a "WifiWay 1.0", esta distribución simplifica todo mucho con un script llamado airoscript y airoscript.es (versión en español) un archivo ".sh". Este script ayudó muchisimo a los usuarios para poner en marcha auditorías, sin la dificultad de largas secuencias en línea de comandos y un montón de claves "parámetro:valor"

WifiWay 1.0 tenía un problema, los ataques de diccionario no estaban automatizados y simplificados, aún.

Poco tiempo después, WifiWay 2.0 llegó y nos dieron una interfaz más simplificada y unas utilidades relacionadas con ataques de diccionario, eso incluye una nueva versión de airoscript, más fácil y más potente, una vez más.


 
Ahora, la versión actual es "WifiWay 2.0.3 final" un disto libre abierta y muy poderosa de Linux. Tiene un airoscript mejorado con el "cracking automático", que nos permite descifrar de forma automática o atacar a un punto de acceso inalámbrico cercano a nosotros, sí!, totalmente automatizado.

Podrá obtener más información acerca ello en http://www.wifiway.org/

No te olvides, sólo por la auditoría, nada de hackear al prójimo!
:)
Disfrutadlo!

"Somos legión"

Siguiente Post: "Google Hacking, cuidado con tu sitio web!!!"

Tuesday, March 20, 2012

Reaver (WPS attack) and WPAMagicKey tools

wep wpa WPA
(There is a Spanish version of this post | haga click aqui para acceder a este post en Español)
Just a few months ago we heard:  "WPA is down, we've cracked it!"



That's absolutely wrong, no body has cracked this security algorithm. Today, this will be our main idea.
At least, no body had published anything about WPA cracking. It was long time ago from WEP cracking but not yet for WPA (of course, WPA2 is included)

There are some ways to access to a WPA wireless network, but none of them could be called "cracking":

- Capture the WPA - TKIP handshake (aircrack + dictionary): this is not cracking because you need a later dictionary attack to be able to get the password. If you have no dictionary, you won't be able to get the password.
- Use the WPA Magic Key dictionaries (w/o aircrack): This tool can generate the default password list for this router if your wireless is WLAN_XXXX or JAZZTEL_XXXX and you never changed your password.
- John The Ripper (to use with aircrack): You can generate your own dictionary if you know the password pattern and it's not very long (shorter than 4 - 5 characters), if it's long your dictionary will be huge and you won't be able to use it. (View table and pie chart below)




From the calculations in the table above, it could be a bad idea try to crack by using brute force attack in a WPA wireless network.


In the pie chart below you can check what most passwords are in the strongest group (mixed character type).





Then, I think still nobody cracked a WPA password, right?


From the hacker point of view, the most important difference between WEP and WPA is what they transmits on the IP package. A WPA packet is not transmitting any information about the network master key, this is not true about WEP encryption.

Now, we must learn about WPS (Wikipedia EN). The most simple&easy way to think what's WPS: "WPS is a button which allows us to connect (or not) to a WiFi".
Finally, if nobody was able to crack a WPA... what the hell is reaver? what the hell can it do for me? will I be able to use reaver?

- Reaver: Is a script-tool which will use a WPS vulnerability algorithm to "cheat" a router and get the WPA key.
- As far as I know, reaver will only be able to help you when your're using TKIP (not supported for AES yet)
- Previous to execute "reaver" you should execute the "walsh" script-tool. It's a "twin-app" what will tell you which wireless networks are vulnerable to this attack.

There are lots of video tutorials about reaver... (my favority one is the first video)
Video#1 (here you will learn how to install too, very interesting)
Video#2

You maybe need this tips.

In most cases you will get reaver from linux distributions like Backtrack or WifiWay.
We will talk soon about the new rease of WifiWay (v.3)

You mustn't use this information for hacking, you have to use it just for learn about security, right?

We are legion


================================================================
Next Post: "PayPal is vulnerable, XSS"

Sunday, September 25, 2011

WifiWay 2, hack the air!

(Visit the brand new version of this old post in Spanish)
Today we will write about "WifiWay".

WifiWay is a free open linux distribution which is "the son" of the WifiSlax distribution.
This is a well known linux distribution related with wireless auditing.

From the older one, WifiSlax, WifiWay inherited a lot of utilities and tools, like the aircrack framework, including airodump, aircrack, aireplay... etc.

Those tools was great but they were not easy-to-use for new users or auditors with a low knowledge.

This distribution evolved to "WifiWay 1.0", that distribution was simplified with a ".sh" script called airoscript and airoscript.es (Spanish version); that script helped users to launch auditories without the difficulty of long command line sequences and lots of "parameter:values"

WifiWay 1.0 had an "hole", dictionary attacks was not automated and simplified, yet.

A few time ago, WifiWay 2.0 arrived and got us a more simplified interface and some utilities related with dictionary attacks; it included a new version of airoscript, easier and more powerful, again.



Now, the current version is "WifiWay 2.0.3 final" a free open powerful automated linux distribution. It has a improved airoscript with "auto crack" mode, it allows us to automatically crack or attack a wireless access point near to us, yeah!, full automated :)

You can get longer information about at  http://www.wifiway.org/

Hey man, don't forget, just for auditing, not hacking
 :)
Enjoy it!

"We are legion"
Next Post: "Google hacking, be careful with your website!"

Thursday, September 22, 2011

What the hell is Nessus? Fast overview

Today we will write about Nessus (from my point of view) the best vulnerability scanner.

There are many network scanners:
 * nmap: a very simple command line network scanner.
 * wireshark: a network sniffer, GUI and command line.
 * airodump: wireless scanner.
 * airsnort: an old wireless scanner.


There are many scanners, but none of them gets the level of nessus. This is my favourite one :)
Why?

Nessus is a free vulnerability scanner, you can use it as GUI or command line, no problem.

Nessus works as client <-> server. This is (in short), our nessus server will do the work which we launch from the nessus client.

The GUI client interface is very friendly and easy-to-use.
The command line has a powerful engine that allows us to integrate nessus with metasploit framework (we will talk about metasploit framework in later posts)

Once installed, up and running, we have a "light" version of nessus, it has only a few plugins available.

We have to go to the nessus website and register our nessus. (I asume we are NOT a company, just home users; companies should buy a enterprise version of nessus)

After register our nessus server, we can download all of plugins and full update our nessus engine.
Then we will have our nessus engine ready to run.

Thus, which is the functionality for this plugins?

Plugins are used as working modules, they are used to detect vulnerabilities, each one is dedicated to some type of vuln. Then, you should keep your plugins updated, in order to have the best vuln detection.

Nessus works in a three module manner:

- Policies: policies are used to define the scanner behavior, which IPs will be scanned...
- Scanners: this is the main nessus function, a scanner is a "policy running"
- Reports: a report is created after scanner execution, is the output of the scanner, listing all the vulns detected and the exploit, if it is available.


Those reports can be read by metasploit, to execute commands like "db_autopwn"     :)


"We are legion"
Next Post: "WifiWay2, hack the air!!!"(English)
Siguiente Post: "WifiWay2, hack the air!!!"(Español)

Popular Posts