For a long time now, wireless internet has become a much more popular way of surfing the internet or general networks for that matter. They have, essentially, allowed people to leave their homes with their laptop, palm pilot, tablet PC, or whatever it may be, and they are able to surf they are able to have the same possibilities they could have as if they were in their office or at home. In the beginning, wireless networking seemed like a pretty simple and basic idea,. Though, yes, it is a simple concept and is very convenient...it may be fairly convenient to someone who feels like “stealing" your signal. Or better yet, someone stealing your passwords because you figured, "O, I won't need 128-bit encryption, nobody will try to jack this shizzle." Well, my pitiful mistaken friend, the truth is that if you're computer is connected to a network of other computers...you are ultimately vulnerable to a number of dangerous things. Whether it be viruses, trojans, 'hackers', 'crackers', squirrels, or just nosy neighbors, you are VULNERABLE! Now you may be thinking, "Is there anything I can do to help protect myself on my wireless network?" As a matter-a-fact, yes, yes there is. There are several different methods of protecting yourself while you use a wireless LAN (Local Area Network). One of the most powerful being encryption. Whether it be WEP (Wired Equivalent Privacy), using 128-bit encryption, or even changing your SSID (Service Set Identifier). Any form of protection, is essentially keeping you one step closer from having your wireless signal stolen.
Changing your SSID
A Service Set Identifier (SSID) is a security measure that would allow someone to communicate with the 'base station'. It basically allows only someone with the same SSID to communicate with the station. Now figuring out this SSID is easy if it is left on default. All an attacker really has to do is just bruteforce the signal to figure out the password. Because most people will choose a password that is easy to remember, it doesn't always take an attacker too much time to gain access. And because of the fact that data packets are only encrypted, the SSID is broadcasted over in clear text. So basically, changing your SSID is a good idea though your new password should be much harder to guess than something like your name. Be sure to utilize the different characters on your keyboard.
WEP
Wired Equivalent Privacy, this is a widely used system that can be configured between none, 64-bit, and 128-bit. Though this may seem good, WEP has a huge security flaw. The fact that some with some patience can easily crack the WEP key with something like Airsnort is kind of discouraging. All one would have to do is collect millions of packets and eventually the WEP key can be cracked. You see, WEP uses what is called the RC4 algorithm to turn the information into infinite lengths of numbers. (RC4 is a.k.a. a stream cipher). Basically the sender and the receiver have the same key and when the receiver gets the encrypted packets the key is used to decipher it. All a passerby has to do is collect enough initialization vectors which are sent as 24-bit fields in the encrypted package and wait until a collision occurs between two IVs. Once someone get's enough IVs to figure out the plaintext, bam they can decipher the WEP key. To fix some of these flaws you can use WPA (WiFi Protected Access). Even this encryption method fixes the flaws in WEP, it is still semi-susceptible to DoS attacks. Though WEP isn't entirely secure, it is better than nothing and it is easy to activate on your wireless router. Just look in your corresponding manual.
Disable SSID Broadcasting
Most wireless routers will broadcast your SSID so someone 'authorized' to that service can access it via hotspot, etc.. Mainly you will find SSID broadcasts from larger businesses and not very likely to find it in homes. This is because of the fact that the SSID is not encrypted at all. So if someone really wanted to, it wouldn't be hard for them to intercept this message and get them one step closer to getting into your wireless network! So all-in-all, this feature is unnecessary to use in normal home use. This feature, although increasing your security, still allows your SSID to get by. This step is easy and is a good thing to disable on your router.
MAC Address Filtering
A network that does not have MAC address filtering turned on will allow anyone who knows the SSID to logon to the network. However, if one was to turn this filter on then when someone tries to get authenticated on the network they must first have their MAC address compared to the ones on the administrator's list. His/her list would consist of every MAC address of every client on the network. This feature is a convenient and easy way to increase your WLAN security risks. Though it is possible for an attacker to spoof a MAC address and gain access that way, MAC address filtering is a good feature to having running on any wireless network big or small.
Well...this essentially concludes this version of "Securing your Wireless Network" and this paper, by no means, completely secures your WLAN from attackers. Like I said in the beginning of the article, you are ultimately ALWAYS vulnerable. No matter how secure you think you are, you can always take one more step to making yourself even more secure. One must continue to stay up-to-date and secure on their WLAN and make all the proper updates and what have you in order to keep it even somewhat secure. Remember, you're never secure as you think you are.
www.iss.net
www.about.com
www.google.com!!!!
www.keyitsolutions.com
How to Exploit Compact Flash media on Enhanced CD
With the entitled information I've supplied, I ask that you not use this information directing to piracy. I wrote this information for you to store the extra content compacted on Digital Audio Disks, for personal use, and for backup reasons. Please respect the industry, and their content!
Hey it's me again; to tell you howto Rip out Enhanced CD Extras which are bundled inside of a single flash object on a Digital Audio Disk!
You maybe asking me, why do this? Well that's a good question, and it's simple to imply to. Did you know that Flash based extras on enhanced CDs aren't very widespread for others to take a look at? Or what about brothers on your network who are to poor to purchase these disks to even get a chance to look at behind the scenes, special footage, and bonus features? Or what about the people who can't access the Album itself, and have no resource to even look at it, and it maybe their favorite band? Or what about future CD Failure, and it snaps in half and then you permenantly lose the data in it's entrity? That would suck! - But I have good news! I'm here to teach you how it can be done, with just a few simple steps.
NOTE: enhanced CD's will display 2 signitures notifying you of that it's got more content on it, than just the Digital media tracks.these signitures are a Plus symbol, and also a Melody symbol.
What you need:
1: WinRAR (You can download the evaluation version @ www.rarlabs.com)
2: The CD Which contains the Flash object including the compacted features and extras
3: A CD-Rom Drive
Ok, Once winRAR has been downloaded and installed, please suceed to the following...
Alright so you've know got that Disk with the compact extras in a flash object, so You'll want to insert that into your CD Rom drive. Now let your computer see the disk. Now usually the Flash will deploy, but on some systems they don't catch the autorun.ini file. anyways, if the flash does deploy exit it. Now, goto Start>My Computer, Now here's where you'll see all of your drives and such. Locate the CD-Rom drive which your CD is in. now RIGHT CLICK on the drive and click winRARS feature "ADD TO ARCHIVE..." Now it'll bring you to a place to save it as, then a prompt will desplay from winRAR, Click browse, then designate the file to be saved to desktop. Then by default it'll be saved as "Archive" But you can rename it to whatever you want. Then once all is done, click Ok on the winRAR Console. Boom! Data has been successfully ripped, and all the movies, special features are yours to share with your friends who mosh to your music.
Hey it's me again; to tell you howto Rip out Enhanced CD Extras which are bundled inside of a single flash object on a Digital Audio Disk!
You maybe asking me, why do this? Well that's a good question, and it's simple to imply to. Did you know that Flash based extras on enhanced CDs aren't very widespread for others to take a look at? Or what about brothers on your network who are to poor to purchase these disks to even get a chance to look at behind the scenes, special footage, and bonus features? Or what about the people who can't access the Album itself, and have no resource to even look at it, and it maybe their favorite band? Or what about future CD Failure, and it snaps in half and then you permenantly lose the data in it's entrity? That would suck! - But I have good news! I'm here to teach you how it can be done, with just a few simple steps.
NOTE: enhanced CD's will display 2 signitures notifying you of that it's got more content on it, than just the Digital media tracks.these signitures are a Plus symbol, and also a Melody symbol.
What you need:
1: WinRAR (You can download the evaluation version @ www.rarlabs.com)
2: The CD Which contains the Flash object including the compacted features and extras
3: A CD-Rom Drive
Ok, Once winRAR has been downloaded and installed, please suceed to the following...
Alright so you've know got that Disk with the compact extras in a flash object, so You'll want to insert that into your CD Rom drive. Now let your computer see the disk. Now usually the Flash will deploy, but on some systems they don't catch the autorun.ini file. anyways, if the flash does deploy exit it. Now, goto Start>My Computer, Now here's where you'll see all of your drives and such. Locate the CD-Rom drive which your CD is in. now RIGHT CLICK on the drive and click winRARS feature "ADD TO ARCHIVE..." Now it'll bring you to a place to save it as, then a prompt will desplay from winRAR, Click browse, then designate the file to be saved to desktop. Then by default it'll be saved as "Archive" But you can rename it to whatever you want. Then once all is done, click Ok on the winRAR Console. Boom! Data has been successfully ripped, and all the movies, special features are yours to share with your friends who mosh to your music.
Essential Encryption Part I - PGP
-=[ About It ]=-
PGP is a popular public/private key encryption system used primarily in email. Its long key length and brilliant architecture make it perfect for hiding data you don't want read by third parties, and for establishing a secure mode of communication between two or more people.
PGP has a long and troubled history, which you can read about on its Wikipedia article [1]. Suffice it to say that it was the first consumer encryption program, and helped break down the absurd US encryption exportation laws in the mid-90s.
-=[ Getting It ]=-
The most popular implementation of PGP these days is GPG, the GNU Privacy Guard. It's free, so you can get it from their website [2]. It runs on every major platform, and also bsd :P I'm going to be covering Linux exclusively, as that's all I know, but just about everything is the same regardless of your OS.
It should either come with your distro or be available in the package repository. It's in Debian and Ubuntu apt, Portage, and comes with Slackware.
-=[Setting It Up ]=-
First thing after installing, you need to generate a public/private keypair:
$ gpg --gen-key
This should ask you some questions and then deposit a key in your private keystore (usually ~/.gpg/secring.gpg on nix). Make sure you generated a key correctly by listing your keys like this:
$ gpg --list-keys
You need to generate a revocation certificate now, in case your key is compromised or you (god forbid) lose it, or someone steals your usb key which you unwisely had your private key stored on (*cough**cough*) Really. You need to do this:
$ gpg --gen-revoke y3rk3y1d --output revocation-cert.asc
Replace 'y3rk3y1d' with your key ID, visible in --list-keys as follows:
pub 1024D/C1F5E7CE 2004-12-14
uid Someone
sub 1024g/07AACA92 2004-12-14
In this case, 'C1F5E7CE' is your public key ID. You probably want to export your ascii-armored public key so people can decrypt your messages and files, and also so you can email it to all your geek friends to show off:
$ gpg --armor --output PublicKey.asc --export y3rk3y1d
You should probably send it to a keyserver so anyone in the world can download it, should they need it. There is really no reason at all to not do this:
$ gpg --keyserver pgp.mit.edu --send-key y3rk3y1d
-=[ Using PGP for Local Encryption ]=-
-==[ Encryption ]==-
PGP uses public/private key cryptography, so things are usually encrypted in such a way that they can only be decrypted with a specific key. If you want to encrypt something so that only you can read it, simply encrypt it to yourself:
$ gpg --encrypt --recipient 'Kapitan' --output test.gpg test.txt
Of course replace 'Kapitan' with your name or your key ID. To encrypt a file to someone else, you first need to import their public key:
To download it from the MIT keyserver:
$ gpg --keyserver pgp.mit.edu --search-keys 'Their Name'
To import it from a file:
$ gpg --import theirkey.asc
Then encrypt it like before:
$ gpg --encrypt --recipient 'Their Name' --ouput test.gpg test.txt
You should end up with a file full of binary gibberish. To sign a file, use this command:
$ gpg --sign --clearsign test.txt
Signing is useful in that, theoretically, only the owner or the private key it is signed with can generate a valid signature for any one file, and changing that file in any way invalidates the signature.
-==[ Decryption ]==-
To decrypt a message, import their public key, and then use the --decrypt option:
$ gpg --decrypt ./test.gpg
If your friend encrypted their file correctly, you should now have the decrypted message in your working directory. To verify a signature, use the --verify option of gpg:
$ gpg --verify ./test.asc
It will either report a good signature or a bad signature. If it's a bad one, contact your friend over a secure medium.
-=[ Setting up your Email Client ]=-
Using PGP for local encryption is fine, but it was designed with the brilliant public/private key system it uses so that people could verify their identity one Usenet. Today, its most widespread use is in email signing and encryption.
-==[ mutt ]==-
One of the major reasons I use mutt is because of the excellent pgp support built into it. To get pgp to work on mutt, add this to your .muttrc:
set pgp_decode_command="gpg %?p?--passphrase-fd 0? --no-verbose --batch --output - %f"
set pgp_verify_command="gpg --no-verbose --batch --output - --verify %s %f"
set pgp_decrypt_command="gpg --passphrase-fd 0 --no-verbose --batch --output - %f"
set pgp_sign_command="gpg --no-verbose --batch --output - --passphrase-fd 0 --armor
--detach-sign --textmode %?a?-u %a? %f"
set pgp_clearsign_command="gpg --no-verbose --batch --output - --passphrase-fd 0 --armor
--textmode --clearsign %?a?-u %a? %f"
set pgp_encrypt_only_command="pgpewrap gpg --batch --quiet --no-verbose --output -
--encrypt --textmode --armor --always-trust --encrypt-to 0xC1F5E7CE -- -r %r -- %f"
set pgp_encrypt_sign_command="pgpewrap gpg --passphrase-fd 0 --batch --quiet --no-verbose
--textmode --output - --encrypt --sign %?a?-u %a? --armor --always-trust --encrypt-to
0xC1F5E7CE -- -r %r -- %f"
set pgp_import_command="gpg --no-verbose --import -v %f"
set pgp_export_command="gpg --no-verbose --export --armor %r"
set pgp_verify_key_command="gpg --no-verbose --batch --fingerprint --check-sigs %r"
set pgp_list_pubring_command="gpg --no-verbose --batch --with-colons --list-keys %r"
set pgp_list_secring_command="gpg --no-verbose --batch --with-colons --list-secret-keys %r"
set pgp_autosign=yes
set pgp_sign_as=0xC1F5E7CE
set pgp_replyencrypt=yes
set pgp_timeout=1800
set pgp_good_sign="^gpg: Good signature from"
Be sure to replace all the '0xC1F5E7CE's with your key identifier. mutt should now be able to encrypt, sign, or encrypt and sign any message that you send, with 'sign' being the default.
-==[ Thunderbird ]==-
To set Mozilla Thunderbird up to sign your messages, you'll have to use the Enigmail extention. Download it from their website [5], and then use the extention manager in Thunderbird to install it. The wizard is very straightforward, and should recognize all the keys we have already generated with the gpg command line client. Set it to sign your mail by default, and you should be ready to go.
PGP is a popular public/private key encryption system used primarily in email. Its long key length and brilliant architecture make it perfect for hiding data you don't want read by third parties, and for establishing a secure mode of communication between two or more people.
PGP has a long and troubled history, which you can read about on its Wikipedia article [1]. Suffice it to say that it was the first consumer encryption program, and helped break down the absurd US encryption exportation laws in the mid-90s.
-=[ Getting It ]=-
The most popular implementation of PGP these days is GPG, the GNU Privacy Guard. It's free, so you can get it from their website [2]. It runs on every major platform, and also bsd :P I'm going to be covering Linux exclusively, as that's all I know, but just about everything is the same regardless of your OS.
It should either come with your distro or be available in the package repository. It's in Debian and Ubuntu apt, Portage, and comes with Slackware.
-=[Setting It Up ]=-
First thing after installing, you need to generate a public/private keypair:
$ gpg --gen-key
This should ask you some questions and then deposit a key in your private keystore (usually ~/.gpg/secring.gpg on nix). Make sure you generated a key correctly by listing your keys like this:
$ gpg --list-keys
You need to generate a revocation certificate now, in case your key is compromised or you (god forbid) lose it, or someone steals your usb key which you unwisely had your private key stored on (*cough**cough*) Really. You need to do this:
$ gpg --gen-revoke y3rk3y1d --output revocation-cert.asc
Replace 'y3rk3y1d' with your key ID, visible in --list-keys as follows:
pub 1024D/C1F5E7CE 2004-12-14
uid Someone
sub 1024g/07AACA92 2004-12-14
In this case, 'C1F5E7CE' is your public key ID. You probably want to export your ascii-armored public key so people can decrypt your messages and files, and also so you can email it to all your geek friends to show off:
$ gpg --armor --output PublicKey.asc --export y3rk3y1d
You should probably send it to a keyserver so anyone in the world can download it, should they need it. There is really no reason at all to not do this:
$ gpg --keyserver pgp.mit.edu --send-key y3rk3y1d
-=[ Using PGP for Local Encryption ]=-
-==[ Encryption ]==-
PGP uses public/private key cryptography, so things are usually encrypted in such a way that they can only be decrypted with a specific key. If you want to encrypt something so that only you can read it, simply encrypt it to yourself:
$ gpg --encrypt --recipient 'Kapitan' --output test.gpg test.txt
Of course replace 'Kapitan' with your name or your key ID. To encrypt a file to someone else, you first need to import their public key:
To download it from the MIT keyserver:
$ gpg --keyserver pgp.mit.edu --search-keys 'Their Name'
To import it from a file:
$ gpg --import theirkey.asc
Then encrypt it like before:
$ gpg --encrypt --recipient 'Their Name' --ouput test.gpg test.txt
You should end up with a file full of binary gibberish. To sign a file, use this command:
$ gpg --sign --clearsign test.txt
Signing is useful in that, theoretically, only the owner or the private key it is signed with can generate a valid signature for any one file, and changing that file in any way invalidates the signature.
-==[ Decryption ]==-
To decrypt a message, import their public key, and then use the --decrypt option:
$ gpg --decrypt ./test.gpg
If your friend encrypted their file correctly, you should now have the decrypted message in your working directory. To verify a signature, use the --verify option of gpg:
$ gpg --verify ./test.asc
It will either report a good signature or a bad signature. If it's a bad one, contact your friend over a secure medium.
-=[ Setting up your Email Client ]=-
Using PGP for local encryption is fine, but it was designed with the brilliant public/private key system it uses so that people could verify their identity one Usenet. Today, its most widespread use is in email signing and encryption.
-==[ mutt ]==-
One of the major reasons I use mutt is because of the excellent pgp support built into it. To get pgp to work on mutt, add this to your .muttrc:
set pgp_decode_command="gpg %?p?--passphrase-fd 0? --no-verbose --batch --output - %f"
set pgp_verify_command="gpg --no-verbose --batch --output - --verify %s %f"
set pgp_decrypt_command="gpg --passphrase-fd 0 --no-verbose --batch --output - %f"
set pgp_sign_command="gpg --no-verbose --batch --output - --passphrase-fd 0 --armor
--detach-sign --textmode %?a?-u %a? %f"
set pgp_clearsign_command="gpg --no-verbose --batch --output - --passphrase-fd 0 --armor
--textmode --clearsign %?a?-u %a? %f"
set pgp_encrypt_only_command="pgpewrap gpg --batch --quiet --no-verbose --output -
--encrypt --textmode --armor --always-trust --encrypt-to 0xC1F5E7CE -- -r %r -- %f"
set pgp_encrypt_sign_command="pgpewrap gpg --passphrase-fd 0 --batch --quiet --no-verbose
--textmode --output - --encrypt --sign %?a?-u %a? --armor --always-trust --encrypt-to
0xC1F5E7CE -- -r %r -- %f"
set pgp_import_command="gpg --no-verbose --import -v %f"
set pgp_export_command="gpg --no-verbose --export --armor %r"
set pgp_verify_key_command="gpg --no-verbose --batch --fingerprint --check-sigs %r"
set pgp_list_pubring_command="gpg --no-verbose --batch --with-colons --list-keys %r"
set pgp_list_secring_command="gpg --no-verbose --batch --with-colons --list-secret-keys %r"
set pgp_autosign=yes
set pgp_sign_as=0xC1F5E7CE
set pgp_replyencrypt=yes
set pgp_timeout=1800
set pgp_good_sign="^gpg: Good signature from"
Be sure to replace all the '0xC1F5E7CE's with your key identifier. mutt should now be able to encrypt, sign, or encrypt and sign any message that you send, with 'sign' being the default.
-==[ Thunderbird ]==-
To set Mozilla Thunderbird up to sign your messages, you'll have to use the Enigmail extention. Download it from their website [5], and then use the extention manager in Thunderbird to install it. The wizard is very straightforward, and should recognize all the keys we have already generated with the gpg command line client. Set it to sign your mail by default, and you should be ready to go.
Essential Encryption Part II - Linux Loopback
-=[ About It ]=-
The most popular way to encrypt large amounts of data in Linux is to create an encrypted loopback device. These are very versitile, and can cypher anything from an mp3 file to a raid array. They're also very simple to use, once you know what you're doing.
-=[ How To Use Them ]=-
To use encrypted loopback devices, you need to have the correct options enabled in your kernel. Make sure you have the CONFIG_BLK_DEV_LOOP option enabled (in 'Device Drivers -> Block Devices' in menuconfig), and a cryptographic module installed, such as CONFIG_CRYPTO_AES_586 (In the Cryptographic API section). You'll also need the 'losetup' utility, but that should come with your distro.
Next, you need to have something to encrypt data into, called the cypher container. I'm going to use a 5MB file of random data:
$ dd if=/dev/urandom of=/tmp/vault bs=1M count=5
Use losetup to give your file a device node in '/dev'. Know that if you have an older version of losetup, I've found that the syntax for running the node through the cryptographic API may be different:
# losetup -e aes-128 /dev/loop0 /tmp/vault
Note that you can feed a drive device node to losetup instead of a file as a container to encrypt to an entire drive. losetup should then ask you for a password, and connect the device node. Next, you'll need a filesystem. Since this container is so small, not much else will fit, so we'll use ext2:
# mkfs.ext2 /dev/loop0
Then mount it:
# mkdir /mnt/vault
This creates a mountpoint at /mnt/vault
# mount /dev/loop0 /mnt/vault
This mounts the container. Anything you drop in /mnt/vault will be encrypted with 128-bit AES. Remember to umount it before you turn off your computer.
The most popular way to encrypt large amounts of data in Linux is to create an encrypted loopback device. These are very versitile, and can cypher anything from an mp3 file to a raid array. They're also very simple to use, once you know what you're doing.
-=[ How To Use Them ]=-
To use encrypted loopback devices, you need to have the correct options enabled in your kernel. Make sure you have the CONFIG_BLK_DEV_LOOP option enabled (in 'Device Drivers -> Block Devices' in menuconfig), and a cryptographic module installed, such as CONFIG_CRYPTO_AES_586 (In the Cryptographic API section). You'll also need the 'losetup' utility, but that should come with your distro.
Next, you need to have something to encrypt data into, called the cypher container. I'm going to use a 5MB file of random data:
$ dd if=/dev/urandom of=/tmp/vault bs=1M count=5
Use losetup to give your file a device node in '/dev'. Know that if you have an older version of losetup, I've found that the syntax for running the node through the cryptographic API may be different:
# losetup -e aes-128 /dev/loop0 /tmp/vault
Note that you can feed a drive device node to losetup instead of a file as a container to encrypt to an entire drive. losetup should then ask you for a password, and connect the device node. Next, you'll need a filesystem. Since this container is so small, not much else will fit, so we'll use ext2:
# mkfs.ext2 /dev/loop0
Then mount it:
# mkdir /mnt/vault
This creates a mountpoint at /mnt/vault
# mount /dev/loop0 /mnt/vault
This mounts the container. Anything you drop in /mnt/vault will be encrypted with 128-bit AES. Remember to umount it before you turn off your computer.
Blog Archive
-
▼
2013
(13)
-
▼
July
(13)
- Subway Surfers Hack – Unlimited Coins ...
- Farm Heroes Saga Hack Tool Posted by ...
- Texas HoldEm Poker Hack/Chips Generator 2013...
- Facebook Angry Birds Friends Hack Cheat Tool v9...
- Cheats FarmVille 2 Hack FarmVille 2, the sequel...
- DRAGON CITY HACK CHEAT 2013 – GET FREE GEMS, FO...
- Facebook Hack Candy Crush Saga Hack Tool...
- Criminal Case Hack & Cheats Tool [ NEW JUNE 2013 ]...
- UPDATED FB GAMES HACK: War Commander Hack tool cheat
- Hit Tennis 3 Hack Tool v3.00
- Avengers Alliance Hack ...
- Despicable Me: Minion R...
- Clash of Clans Hack Too...
-
▼
July
(13)
