Showing posts with label Linux. Show all posts
Showing posts with label Linux. Show all posts

Thursday, September 25, 2014

CVE-2014-6271 - Shellshock

,
Remotely Exploitable 'Bash Shell' Vulnerability Affects Linux, Unix and Apple Mac OS X
A Critical remotely exploitable vulnerability has been discovered in the widely used Linux and Unix command-line shell, known as Bash, aka the GNU Bourne Again Shell, leaving countless websites, servers, PCs, OS X Macs, various home routers, and many more open to the cyber criminals.

REMOTELY EXPLOITABLE SHELLSHOCK
The vulnerability (CVE-2014-6271) affects versions 1.14 through 4.3 of GNU Bash and being named as Bash Bug, and Shellshock by the Security researchers on the Internet discussions.

According to the technical details, a hacker could exploit this bash bug to execute shell commands remotely on a target machine using specifically crafted variables. “In many common configurations, this vulnerability is exploitable over the network,” Stephane said.

This 22-year-old vulnerability stems from the way bash handles specially-formatted environment variables, namely exported shell functions. When assigning a function to a variable, trailing code in the function definition will be executed.

BASH BUG AFFECTS MILLIONS OF SYSTEMS
While bash is not directly used by remote users, but it is a common shell for evaluating and executing commands from other programs, such as web server or the mail server. So if an application calls the Bash shell command via web HTTP or a Common-Gateway Interface (CGI) in a way that allows a user to insert data, the web server could be hacked.

In Simple words, If Bash has been configured as the default system shell, an attacker could launch malicious code on the server just by sending a specially crafted malicious web request by setting headers in a web request, or by setting weird mime types. Proof-of-concept code for cgi-bin reverse shell has been posted on the Internet.

Similar attacks are possible via OpenSSH,
“We have also verified that this vulnerability is exposed in ssh—but only to authenticated sessions. Web applications like cgi-scripts may be vulnerable based on a number of factors; including calling other applications through a shell, or evaluating sections of code through a shell.”
Stephane warned. But if an attacker does not have an SSH account this exploit would not work.
This is a serious risk to Internet infrastructure, just like Heartbleed bug, because Linux not only runs the majority of the servers but also large number of embedded devices, including Mac OS X laptops and Android devices are also running the vulnerable version of bash Software. NIST vulnerability database has rated this vulnerability “10 out of 10” in terms of severity.

HOW TO CHECK FOR VULNERABLE SHELL
To determine if a Linux or Unix system is vulnerable, run the following command lines in your linux shell:
  • env X="() { :;} ; echo shellshock" /bin/sh -c "echo completed"
  • env X="() { :;} ; echo shellshock" `which bash` -c "echo completed"
If you see the words "shellshock" in the output, errrrr… then you are at risk.

BASH BUG PATCH
You are recommended to disable any CGI scripts that call on the shell, but it does not fully mitigate the vulnerability. Many of the major operating system and Linux distribution vendors have released the new bash software versions today, including:

  • Red Hat Enterprise Linux (versions 4 through 7) and the Fedora distribution
  • CentOS (versions 5 through 7)
  • Ubuntu 10.04 LTS, 12.04 LTS, and 14.04 LTS
  • Debian
If your system is vulnerable to bash bug, then you are highly recommended to upgrade your bash software package as soon as possible.

More here
Read more →

Thursday, December 5, 2013

Administer samba shares via SWAT

,
Is it hard for you to play with smb.conf and other stuff? Are you afraid of doing any mistakes?
Then you have to think about using swat, the samba web administration tool.
We will first install samba, cifs-utils, swat and xinted, all needed for our SWAT installation.
sudo apt-get install samba cifs-utils swat xinetd
Then we will go ahead and enable swat in our internet service deamon,
sudo update-inetd --enable 'swat'
sudo dpkg-reconfigure xinetd
after xinetd, we will create the swat service.
sudo cat > /etc/xinetd.d/swat <<-EOF
service swat
{
port = 901
socket_type = stream
wait = no
user = root
server = /usr/sbin/swat
log_on_failure += USERID
disable = no
}
EOF
SWAT needs to have access to the smb.conf file to edit it automatically. We will now give those permissions and restart the xinetd service:
sudo chmod g+w /etc/samba/smb.conf
sudo chgrp adm /etc/samba/smb.conf
sudo service xinetd restart
By now you should be able to login to the administration tool via http://localhost:901/
Start sharing!
Read more →

How to generate entropy in few easy steps

,
You will possibly need this for a PGP key.. So how to generate entropy through a secure shell connection in an easy way?
You don`t have to smash the keyboard or move the mouse and stuff...

Install haveged, a simple entropy deamon.
apt-get install haveged
then type in -w with your bits:
haveged -w 4096
Now you can re-start your PGP-key entropy gatherer in order to finish quickly, right after it's done, you might consider removing haveged as i did.
apt-get remove haveged
Easy eh?
Read more →

Friday, November 15, 2013

Transmission deamon - 409: Conflict - Invalid session-id header

,

How to solve?
Remove the default /web from your URL:
http://www.example.com/transmission/web
to
http://www.example.com/transmission
Read more →

Saturday, November 2, 2013

Image to disk and vice versa on unix

,

Backup all your usb drivers or your disk drivers, or clone them using dd, the ultimate tool.
We will first list all our available disks, watching out not making any mistake.
fdisk -l
Then after the output, notice the /dev/sdA or /dev/hdA or /dev/sdB etc, take a note on what device you want to take backup from, then think about the location of it going, like a folder or in another device.
if stands for input file.
of stands for output file.
By issueing the following command, we will backup our second drive into ~/.
dd if=/dev/sdb of=~/test.img
To restore it, simply swap /dev/sdb with ~/test.img, so simple!
You can also change the block size by using the bs command, eg:
dd if=/dev/sdb of=~/test.img bs=512 
Read more →

Saturday, October 19, 2013

Vodaphone USB Broadband on Linux

,
What you will need:

  1. usb-modeswitch-2.0.1.tar.bz2
  2. usb_modeswitch-data
  3. libusb-1.x
Right after you install those files on your linux box, append these three lines in a terminal:
usb_modeswitch -WD -v 12d1 -p 1526 -n -M 555342437f0000000002000080000a11062000000000000100000000000000 -I -w 500
modprobe option
echo "12d1 14cf" > /sys/bus/usb-serial/drivers/option1/new_id
Open your network manager window, select Mobile Broadband, create a new connection and for connection settings leave them as default, just set the password to 1234.

Plug-in your Vodafone USB and that's it !
                                                                                                                                           [Source]

Read more →

Sunday, October 6, 2013

Disable ICMP ping responces on your linux box

,
Depends on the distribution you use you may be able to disable the ping responce in your box to add some complexity for the attackers or the 'bad guys'. In the video below i am going to show you how to append such configuration in your linux distro.
Disable ping reply
echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_all
Enable ping reply
echo 0 > /proc/sys/net/ipv4/icmp_echo_ignore_all
To make this permanent set the following into /etc/sysctl.conf
net.ipv4.icmp_echo_ignore_all = 1
ICMP Message Types
You can find more about ICMP here.

Read more →

Thursday, October 3, 2013

Enable TCP SYN cookie protection on your linux server

,
Normally when a client attempts to start a TCP connection to a server, the client and server exchange a series of messages which normally runs like this:
  1. The client requests a connection by sending a SYN (synchronize) message to the server.
  2. The server acknowledges this request by sending SYN-ACK back to the client.
  3. The client responds with an ACK, and the connection is established.
This is called the TCP three-way handshake, and is the foundation for every connection established using the TCP protocol.
A SYN flood attack works by not responding to the server with the expected ACK code. The malicious client can either simply not send the expected ACK, or by spoofing the source IP address in the SYN, causing the server to send the SYN-ACK to a falsified IP address - which will not send an ACK because it "knows" that it never sent a SYN.

The server will wait for the acknowledgement for some time, as simple network congestion could also be the cause of the missing ACK, but in an attack increasingly large numbers of half-open connectionswill bind resources on the server until no new connections can be made, resulting in a denial of service to legitimate traffic. Some systems may also malfunction badly or even crash if other operating system functions are starved of resources in this way.

The protection should be enabled by default in many distros.




Commands used:
sysctl -n net.ipv4.tcp_syncookies
nano /etc/sysctl.conf
sysctl -p

Read more →

Monday, July 29, 2013

Installing a LAMP server

,
LAMP is a combination of free, open source software. The acronym LAMP refers to the first letters of Linux (operating system), Apache HTTP Server, MySQL (database software), and PHP, Perl or Python, principal components to build a viable general purpose web server.

Install Linux:
just kidding...
  1. Install Apache:
  2. sudo apt-get install apache2
    After everything is finished, fire up a browser and type:
    http://localhost/
    you should see already a folder, if nothing is found then you have to re-install it. If you still can`t find a solution, drop a line below.
  3. Install PHP:
  4. sudo apt-get install php5 libapache2-mod-php5
    After everything is finished, we have to restart apache to get notified about php:
    sudo /etc/init.d/apache2 restart
  5. Install MySQL:
  6. sudo apt-get install mysql-server
    Then get access to console by typing:
    mysql -u root
    And change your password:
    mysql SET PASSWORD FOR 'root'@'localhost' = PASSWORD('P@$sw0rd');
    After that, install PHPMyAdmin:
    sudo apt-get install libapache2-mod-auth-mysql php5-mysql phpmyadmin
    Edit php.ini to work with phpmyadmin...
    gksudo gedit /etc/php5/apache2/php.ini
    And change this line:
    ;extension=mysql.so to extension=mysql.so
    Last thing is to restart apache to take care of MySQL too:
    sudo /etc/init.d/apache2 restart
    Go again at http://localhost and check what you've done!
Read more →

Tuesday, April 9, 2013

Kali linux - No action for laptop lid

,
So i was trying to figure out the actions of my laptop's lid without going in a deep mode terminal way again..., after a long search nothing seemed to be working..., tried several tools but none of them were actually changing the action of the lid.
So after some days i came accross the gnome-tweak-tool which i've already used in the past and now turns out to be really helpful...

apt-get install gnome-tweak-tool | gnome-tweak-tool

Under Shell you should be able to find:
'Laptop lid close action on battery'
'Laptop lid close action when on AC'

Again, this is a bug found in some hardware, if you haven't found the option in the menu then try this.
Read more →

Sunday, April 7, 2013

Backup - Restore MySQL databases easily

,
As an IT there should be enough computers running MySQL which you would like to take care or maybe advantage easier than just looking around the fs without idea...
Let's say you hack into a system and all you do is their database! Hah, i am kiding, though, we would like to backup this database for security reasons.... How's the fast way? or How can we do this in a script?


Below are some commands that may be handy from time to time for those who doesn't already know..


Backup MySQL Database
# mysqldump -u(username) –p(password) (databasename) > (dumpfile.sql)

Backup all MySQL Databases
# mysqldump -u(username) –p(password) --all-databases > (dumpfile.sql)

Backup a Remote MySQL Database
 # mysqldump -h(hostip) -u(username) –p(password) (databasename) > (dumpfile.sql)

Restore MySQL Database
# mysql -u(username) –p(password) (databasename) < (dumpfile.sql)

Restore a database that already exist on the target machine
# mysqlimport -u(username) –p(password) (databasename) < (dumpfile.sql)
Read more →

Saturday, March 16, 2013

Kali linux is here, deep penetration mode.

,

The most advanced penetration testing distribution, ever.


From the creators of BackTrack comes Kali Linux, the most advanced and versatile penetration testing distribution ever created. BackTrack has grown far beyond its humble roots as a live CD and has now become a full-fledged operating system. With all this buzz, you might be asking yourself:

What's new ?


Grab it !
Read more →

Saturday, January 26, 2013

How to: Install base ArchLinux, made simple

,

**I won't describe how to boot from usb/cd - just keep using another OS mate, :p

create partitions:
cfdisk /dev/sda
confirm partition:
fdisk -l /dev/sda
format partition:
mkfs.ext4 /dev/sda1 -L rootfs
mkswap /dev/sda2 -L swapfs
mount the first partition:
mount /dev/sda1 /mnt
check if you have internet connectivity using dhcp:
ip a
ip r
or else add static:
ip addr add 10.0.0.10/24 dev eth0
ip route add default via 10.0.0.200 dev eth0
confirm networking:
ip a
ip r
prepare rootfs:
mkdir -pv /mnt/var/lib/pacman
and install arch:
mkdir -pv /mnt//var/cache/pacman/pkg/
pacman -r /mnt --cachedir /mnt//var/cache/pacman/pkg/ -Sy base
sign keys:
rsync -rav /etc/pacman.d/gnupg/ /mnt/etc/pacman.d/gnupg/
bind mnt and change root:
mount --bind /dev /mnt/dev
mount --bind /sys /mnt/sys
mount --bind /proc /mnt/proc
chroot /mnt /bin/bash
edit fstab or use blkid:
nano /etc/fstab
/dev/sda1    /       ext4     defaults    0    1
/dev/sda2    none swap   defaults    0    1
change hostname:
echo ArchLinux > /etc/hostname
timezone and locale:
ln -s /usr/share/zoneinfo/Europe/Athens /etc/localtime
nano /etc/locale.gen and uncomment el_GR.UTF-8 etc...
locale-gen
create initramfs:
mkinitcpio -p linux
install grub:
grub-install --boot-directory=/mnt/boot /dev/sda
create grub.cfg:
grub-mkconfig -o /mnt/boot/grub/grub.cfg
add a menuentry:
nano /mnt/boot/grub/grub.cfg
eg:
menuentry "ArchLinux" {

    set root=(hd0,1)
    linux /boot/vmlinuz-linux root=/dev/sda1
    initrd /boot/initramfs-linux.img
}
reboot!
login and change root pwd:

passwd
---------
Up to here you should have a system running, if not please refer to Begginer's Guide.
---------
Some problems during installation:

  1. eth0 renames to some sort of enp2s1 or so - it's a bug (search tracker):
    You should rename enp2s1 to lan or something, how?
    nano /etc/udev/rules.d/10-network.rules
    then add:
     
    SUBSYSTEM=="net", ATTR{address}=="00:00:00:00:00:00", NAME="lan"
    then go at your network.service file to inform yor net svc to hold until it has been renamed:
    Requires=systemd-udev-settle.service
    After=systemd-udev-settle.service
    reboot - now you should see that eth0 dhpcd service failed to start:rm /etc/systemd/system/multi-user.target.wants/dhcpcd@eth0.service
    to remove eth0 svc from starting upon boot.
  2. Key signatures bypass:
    nano /etc/pacman.d/gnupg/gpg.conf
    change keyserver to:
    hkp://pgp.mit.edu:11371
    then hit this down to get keys:curl https://www.archlinux.org/{developers,trustedusers}/ |awk -F\" '(/pgp.mit.edu/) {sub(/.*search=0x/,"");print $1}' |xargs pacman-key --recv-keys
    after this:
    nano /etc/pacman.conf
    and change SigLevel to TrustAll or else untrusted source will occur.
---------
Up to here you should have a stable but somehow unsecure system running.
---------
Now install xorg:
pacman -Sy xorg
then kde:
pacman -Sy kde
reboot and start kde:
kdm

:) hf.
Read more →

Thursday, December 27, 2012

Some SSD tips i had saved a long time ago

,


Filesystem layer

The first of these is easy to do and can both improve performance and, more importantly, the longevity of your SSD by reducing unnecessary writes (keeping in mind the memory used in SSDs has limited write-rewrite cycles).

By default, many distributions including Ubuntu use the 'relatime' flag for updating file metadata when files are accessed, but you're unlikely to care about last access times. Additionally, Linux supports TRIM with Ext4. TRIM is important for maintaining the performance of an SSD over time as files are added, deleted and changed and lets the SSD know which blocks can be safely cleared. No distributions currently enable it by default, but it's simple to do by adding the 'discard' flag to any mounted SSDs.

To make all these changes, open up a terminal and run:

sudo nano -w /etc/fstab

Then for all SSD devices in your system remove 'relatime' if present and add 'noatime,nodiratime,discard' so it looks something like this:

/dev/sda/ext4 noatime,nodiratime,discard,errors=remount-ro 0 1

Scheduler
The scheduler helps organise reads and writes in the I/O queue to maximise performance. The default scheduler in the Linux kernel is CFQ (Completely Fair Queuing), which is designed with the rotational latencies of spinning platter drives in mind. So while it works well for standard hard drives, it doesn't work so well when it comes to SSDs.

Fortunately, the kernel comes with some other schedulers to play with, and here the deadline and NOOP schedulers are ideal. Both are basic schedulers that guarantee fast turnaround of I/O requests. NOOP is basically no scheduler at all, it's a basic FIFO (First In, First Out) queue whereas deadline does some sorting to guarantee read requests take priority over write, which is useful if you want to guarantee read responsiveness under heavy writes.

Changing scheduler is easy, and even better -- you can do it on a per-device basis if you have a mixed SSD and spinning platter hard drive system, using deadline for SSDs and CFQ for traditional drives. As CFQ is the default, change SSDs to use deadline by opening up a terminal and running:

sudo nano -w /etc/rc.local

Then add the following line for each SSD in your system:

echo deadline >/sys/block/sda/queue/scheduler

Changing 'sda' to 'sdb' and so on for each SSD device. If you only have SSDs in your system, you can instead set the global scheduler policy to apply to all devices at boot time.

For Ubuntu and other distributions using GRUB2, edit the /etc/default/grub file and add 'deadline' to the GRUB_CMDLINE_LINUX_DEFAULT line like so:

GRUB_CMDLINE_LINUX_DEFAULT="quiet splash elevator=deadline"

Then run 'sudo update-grub2'.


Swap and tmp
Linux is pretty good at only using swap if it really needs to, but even so if you're installing to an SSD and you have a mechanical hard drive in your system, be sure to put the swap partition on it instead of the SSD. If you've already installed Linux and allocated a swap partition on the SSD, you can simply set aside a partition on a spinning platter drive and edit your /etc/fstab swap entry to point to it instead. For example, assuming /dev/sdb is a normal hard drive:

/dev/sdb2 none swap sw 0 0

And reboot, or alternatively issue 'swapoff -a && swapon -a' to update on the fly. If you have a purely SSD system and lots of memory, you can disable swap almost entirely. Keep a swap partition available, but add the following to your /etc/rc.local file:

echo 0 > /proc/sys/vm/swappiness

And Linux won't use swap at all unless physical memory is completely filled.

Next, to reduce unnecessary writes to the SSD move the temp directories into a ram disk using the 'tmpfs' filesystem, which dynamically expands and shrinks as needed.

In your /etc/fstab, add the following:

tmpfs /tmp tmpfs defaults,noatime,mode=1777 0 0
tmpfs /var/spool tmpfs defaults,noatime,mode=1777 0 0
tmpfs /var/tmp tmpfs defaults,noatime,mode=1777 0 0

If you don't mind losing log files between boots, and unless you're running a server you can probably live without them, also add:

tmpfs /var/log tmpfs defaults,noatime,mode=0755 0 0

Considering that even everyday applications generate a lot of log files, it's not a bad idea to do this.


Applications
Any applications that write excessively to a hard drive are also candidates for moving data. Browsers are a fine example of this -- the browser cache is nice, but it'd work just as well from a spinning platter drive and save your SSD from thousands of writes a day that don't make a huge difference to you.

To move the cache in Firefox, in the browser type 'about:config', right-click anywhere and select New --> String, and add 'browser.cache.disk.parent_directory'. Edit the variable and point it to a directory on a non-SSD drive or, if you don't mind losing the cache between boots and you're using the tweaks above, point it to /tmp for a super-fast memory cache.

Moving the cache in Chrome is a little harder. The directory is hardcoded, but you can use symbolic links to point it to a directory on another drive or to /tmp. You'll find the cache under ~/.cache/chromium. You could also redirect the entire .cache directory, as many programs use this for caching data.

Have a look at other applications you use and see if you can redirect any unnecessary writes as well.


Partition alignment
Finally there's partition alignment, but this can only be done with a clean system before you install either Linux or Windows. Partition alignment is critical for SSDs as, being memory-based devices, data is written and read in blocks known as pages. When partitions aren't aligned, the block size of filesystem writes isn't aligned to the block size of the SSD, causing extra overhead as data crosses page boundaries.

Aligning partitions is simply a matter of ensuring the first partition starts on a clean 1MB boundary from the start of the disk, ensuring whatever block size the filesystem uses will align with the block size of the SSD (which can also vary). If you create partitions using Windows 7 on an empty drive, it will start partitions at the 1MB boundary automatically.

In Linux, simply run 'fdisk -cu (device)' on the drive you want to partition, press 'n' for new partition, 'p' for primary and enter a start sector of at least 2,048. The general rule is that the starting sector must be divisible by 512, but to cater for all variations of SSD page size and filesystem block size, 2,048 is a good idea (and equates to 1MB).
Read more →

Sunday, September 2, 2012

Apache start problem: Unable to open logs

,
Apache gave a friend some trouble the other night and i thought of sharing after fixing...
He gave me SSH and asked me to check what's going on.

service apache2 start
Unable to open logs.

After i ran through /var/logs i couldn't find apache2 directory.
Went back to apache2.conf to check if CustomLog command was given but the default value was there.
I simply created /var/logs/apache2 directory with write permisson and the problem was fixed.

mkdir /var/logs/apache2 |chmod 755 /var/logs/apache2

cheers!
Read more →

Compress gigafiles to megabytes...

,

KGB Archiver is a free open source software that can compresses 1GB file to 10MB file. KGB Archiver runs on Windows OS and Linux. Compression ratio of this software is very high. Time due to high compression levels, to compress a file goes high as the file size and increases the compression ratio may vary depending on the file format. Note: If you Compress a File from a High Size to a lower Size and you Send to your Friend, Your Friends must have KGB Archiver Installed on the System to decompress the File, After Decompressing, it will go back to its normal size.

Download
Read more →

Wednesday, August 15, 2012

Update your bt to r3

,

Yesterday backtrack 5 R3 came out, do you really need to burn another iso image for installation? hahah......
Update your system to current versions:

apt-get update
apt-get dist-upgrade



Now for 32bit version type:
apt-get install libcrafter blueranger dbd inundator intersect mercury cutycapt trixd00r artemisa rifiuti2 netgear-telnetenable jboss-autopwn deblaze sakis3g voiphoney apache-users phrasendrescher kautilya manglefizz rainbowcrack rainbowcrack-mt lynis-audit spooftooph wifihoney twofi truecrack uberharvest acccheck statsprocessor iphoneanalyzer jad javasnoop mitmproxy ewizard multimac netsniff-ng smbexec websploit dnmap johnny unix-privesc-check sslcaudit dhcpig intercepter-ng u3-pwn binwalk laudanum wifite tnscmd10g bluepot dotdotpwn subterfuge jigsaw urlcrazy creddump android-sdk apktool ded dex2jar droidbox smali termineter bbqsql htexploit smartphone-pentest-framework fern-wifi-cracker powersploit webhandler

Or for 64bit version:
apt-get install libcrafter blueranger dbd inundator intersect mercury cutycapt trixd00r rifiuti2 netgear-telnetenable jboss-autopwn deblaze sakis3g voiphoney apache-users phrasendrescher kautilya manglefizz rainbowcrack rainbowcrack-mt lynis-audit spooftooph wifihoney twofi truecrack acccheck statsprocessor iphoneanalyzer jad javasnoop mitmproxy ewizard multimac netsniff-ng smbexec websploit dnmap johnny unix-privesc-check sslcaudit dhcpig intercepter-ng u3-pwn binwalk laudanum wifite tnscmd10g bluepot dotdotpwn subterfuge jigsaw urlcrazy creddump android-sdk apktool ded dex2jar droidbox smali termineter multiforcer bbqsql htexploit smartphone-pentest-framework fern-wifi-cracker powersploit webhandler

Read more →

Wednesday, June 6, 2012

Make your Firefox browser shine!

,
You may have installed countless add-on in Firefox to enhance your using experience, but if you want to get the most out of your browser, you really have to go deep into about:config.

This page has almost every configuration Firefox has - hard to play with, take care.

So, jump into the "about:config" page by typing it in the URL field.



Here we go:
  1. Increasing ‘Save Link As‘ timeout period
  2. When you right click and select the ‘Save Link As…‘, the browser will request the content disposition header from the URL so as to determine the filename. If the URL did not deliver the header within 1 sec, Firefox will issue a timeout value. This could happen very frequently in a slow network connection environment. To prevent this issue from happening frequently, you can increase the timeout value so as to reduce the possibility of a timeout.

    Config name: Browser.download.saveLinkAsFilename
    Timeout Default: 1000
    Change to: > 1000

  3. Disable Extension Compatibility Check
  4. This is useful if you want to use an extension that is not supported by your version of Firefox badly. It is not recommended, but you can still do it at your own risk.

    Create new boolean: extensions.checkCompatibility
    Value: False
    Create new boolean: extensions.checkUpdateSecurity
    Value: False

  5. Increase Offline Cache
  6. If you do not have access to Internet most of the time, you might want to increase the offline cache so that you can continue to work offline. By default, Firefox caches 500MB of data from supported offline Web apps. You can change that value to whatever amount of your choice.

    Config name: browser.cache.offline.capacity
    Change to: > 512000

  7. Autofill Address in URL Bar
  8. Other than the smart location feature, you can also get your URL bar to autofill the address as you type the URL.

    Config name: browser.urlbar.autofill
    Change to: True

  9. Boost it !
  10. Config name: network.http.pipelining
    Change to: True

    Config name: network.http.proxy.pipelining
    Change to: True

    Config name: network.http.pipelining.maxrequests
    Change to: any value higher than 4, but not more than 8

    Config name: network.http.max-connections
    Change to: 96

    Config name: network.http.max-connections-per-server
    Change to: 32

  11. Lower The Physical Memory Used When Minimized
  12. This tweak is mainly for Windows users. When you minimize Firefox, it will send Firefox to your virtual memory and free up your physical memory for other programs to use. Firefox will reduce its physical memory usage, when minimized, to approximately 10MB (give or take some) and when you maximize Firefox it will take back the memory that it needs. The preference name does not exist and needs to be created.

    Create new boolean: config.trim_on_minimize
    Value: True

  13. Handling JavaScript Popups
  14. When you come across a site that executes a javascript open new window function, and if the popup window is without all the usual window features, i.e. back/forward/reload buttons, status bar etc, Firefox will automatically treat it as a popup and will not open it as a new tab. However, if you find this to be a nuisance and wanted to open all new windows in a new tabs, you can specify it via the browser.link.open_newwindow.restriction setting.

    Config name: browser.link.open_newwindow.restriction
    Change to:
    0 – open all links as how you have Firefox handle new windows
    1 – do not open any new windows
    2- open all links as how you have Firefox handle new windows unless the Javascript specify how to display the window

  15. Disable the session restore function
  16. Firefox 3 automatically saves your session every 10 secs so that whenever it crashes, it can restore all your tabs. While this is a useful feature, some of you might find it irritating. To disable this function, toggle the value of browser.sessionstore.enabled to False

    Config name: browser.sessionstore.enabled
    Change to: False

  17. Disable Antivirus Scanning
  18. This is mainly for Windows users. By default, Firefox 3 automatically scan the downloaded file with the default anti-virus application to make sure it is free of virus. If you download a big file, it could take a long time for the whole scanning process to complete. To increase the performance of the browser, you might want to consider disabling the anti-virus scanning via the browser.download.manager.scanWhenDone key.

    Config name: browser.download.manager.scanWhenDone
    Change to: False
Personally, i'm using chrome, have fun.
Read more →

Tuesday, May 15, 2012

Upgrading to the latest Backtrack version via the Terminal

,
The long awaited release of the BackTrack 5 R2 kernel has arrived. With a spanking brand new 3.2.6 kernel, a huge array of new and updated tools and security fixes, BT5 R2 will provide a more stable environment than ever before. Here’s how to get the new kernel and all of the updated goodness:

1. Update and upgrade your BT5 (R1) installation:
apt-get update 
apt-get dist-upgrade
apt-get install beef
reboot

2. Verify that you are running a 3.2.6 kernel:
uname -a

3. Install all of the new tools featured in BackTrack 5 R2:
apt-get install pipal findmyhash metasploit joomscan hashcat-gui golismero easy-creds pyrit sqlsus vega libhijack tlssled hash-identifier wol-e dirb reaver wce sslyze magictree nipper-ng rec-studio hotpatch xspy arduino rebind horst watobo patator thc-ssl-dos redfang findmyhash killerbee goofile bt-audit bluelog extundelete se-toolkit casefile sucrack dpscan dnschef

4. Add the new security updates repository to /etc/apt/sources.list, and run upgrade again.
echo "deb http://updates.repository.backtrack-linux.org revolution main microverse non-free testing" >> /etc/apt/sources.list 
apt-get update 
apt-get dist-upgrade

 5.Done! You are now ready to start your new version of backtrack, just before you go, make sure to stop some services that are on by default in R2:
/etc/init.d/apache2 stop
/etc/init.d/cups stop
/etc/init.d/winbind stop

update-rc.d -f cups remove 
update-rc.d -f apache2 remove 
update-rc.d -f winbind remove 

Cheers.
Read more →

Saturday, January 7, 2012

Bruteforce attack tool promises WPA in 4 hours

,
The WiFi Protected Setup protocol is vulnerable to a brute force attack that allows an attacker to recover an access point’s WPS pin, and subsequently the WPA/WPA2 passphrase, in just a matter of hours.
Reaver is a WPA attack tool developed by Tactical Network Solutions that exploits a protocol design flaw in WiFi Protected Setup (WPS). This vulnerability exposes a side-channel attack against Wi-Fi Protected Access (WPA) versions 1 and 2 allowing the extraction of the Pre-Shared Key (PSK) used to secure the network. With a well-chosen PSK, the WPA and WPA2 security protocols are assumed to be secure by a majority of the 802.11 security community.

Reaver has been designed to be a robust and practical attack against WPS, and has been tested against a wide variety of access points and WPS implementations.On average Reaver will recover the target AP's plain text WPA/WPA2 passphrase in 4-10 hours, depending on the AP. In practice, it will generally take half this time to guess the correct WPS pin and recover the passphrase.

WPS allows users to enter an 8 digit PIN to connect to a secured network without having to enter a passphrase. When a user supplies the correct PIN the access point essentially gives the user the WPA/WPA2 PSK that is needed to connect to the network. Reaver will determine an access point's PIN and then extract the PSK and give it to the attacker.


Get open source version of Reaver at Google Code.

Read more →