Trend Watch

WidgetBucks - Trend Watch - WidgetBucks.com
   
Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Sunday, July 29, 2007

Technological Singularity

Imagine a society where one could upload, or download a personality from a supercomputer, or increase intelligence by artificial means. This illustrates a society that transcends to the metaphysical, making conventional human ability obsolete. Think this as a far-fetched idea? Think again. Trans-humanism: the philosophical movement that merges technology with humans, eventually leading to the next evolution in the human cycle. This evolution results in sophistically engineered posthumans. Once humans advance anatomically and neurologically beyond genotypical, and phenotypical patterns they can no longer be named as biological humans.

One area of the Trans-humanist progressive expansion lies in the field of Neurotechnology or Neurobionics. Neurotechnology: a set of instruments that analyze and influence the brain, and central nervous system in a desired effect. Neurochips, the silicon devices that are implanted inside neurons connected to the brain, allow brain manipulation. Transhumanist movements lead to neurological advancements in these neurochips. Despite its many possible advantages, disadvantages appear that could lead us into a negative technological singularity.

With progressive movements in Neurotechnology and Neurobioncs, many advantages for the neurologically impaired increase. New medical instruments are being created in areas of Nanotechnology, Biotechnology, and Neurotechnology to help those with neurological disorders in ways that were not previously open for patients before. Some of the possible advancements include nanomachines that interact with anatomical structures of the brain, which perform microsurgery inside the neural network system on cancerous cells, or damaged tissue.

Nanomachines, or nanites are submicroscopic robots that can perform medical functions within bloodstreams, or neurons of a living organism. This includes intracellular surgery on tumors, and the removal of clotted material in living cells. Nanites can store gigabytes of medical information on human anatomy to preform such task. ("Nanites"). Brain Interface Chips could be used as chips that link with the nanomachines using the Central Nervous System, and send messages and tasks to 'Task Forces' from the Command Chip which is linked directly to the Interface Chip. There will most likely be a neurochip that acts as a command and control chip which feeds information from the Central Nervous System to nanomachines, in the brain to carry out different task, such as destroying viruses, speeding up the healing process from different wombs and tissue in the brain; to detailed information from a database on human anatomy to perform microsurgery on areas such as the eyes, ears, and nerve repair.

"Aside from the more obvious tasks of destroying a virus, speeding the healing process from wounds, and taking out cancerous cells, the nanomachines would help in creating much healthier and fitter people for specific jobs such as astronauts, soldiers etc." It may even be possible to explore the brain and use the information to one day awakens the apparently dormant parts of the human mind. (Langley, Jason). If these nanomachines where to preform such complex task, they would have to have advance artifical intelligence; or intelligence that would require a task to be done by a human.

Different type of intelligence that would be incorporate into these machines would depend on the task it is carrying out. For example algorithms are certain rules to solve a problem, while heuristics are general steps that humans take in order to solve a problem without the knowledge of success; or trail and error type problem solving. One could assume that both of these methods would be incorporate into these nanomachines for advance problem solving abilities. (Levive, Talking Tech pg 49-50). Artificial intelligence in the neural network system allows for other technological advances such as nanobombs to blow up, and destroy tumors inside the nervous system on the submicroscopic level without human surgery. People with neurological diseases such as Cerebral Palsy can be treated with advance technological advances in neuroprothetics, with promising results from animal testing.("Neurobionics What The"). "Neurobionics has a future in neuroprothetics and robotics." ("Neurobionics What the"). Neurons are specialized cells that carry out messages through an electrochemical process throughout different regions of the brain. ("Types of Neurons"). Neurochips has a promising future for people with learning disabilities and neurological disorders. Neurochips can manipulate external mechanical devices such as a prosthetic arms, legs, and even paralyzed muscles. ("Foundation For People"). Neurochips stimulates single neurons, or group of neurons in the biological neural network system. Many great steps has been made in sensory substitution in recent years. Especially in areas in vision due to the increase knowledge of the visual system and eye implants. ("Brain Implant"). Sensory substitution is the principle that transform characteristic of one sensory modality into a stimuli of another sensory modality. ("Sensory Substitution"). Implantation of electrodes deep inside the brain can "recalibrate" areas of normal function by constant weak electrical simulation to certain areas for sensory modality. ("Trudeau, Michelle") This has important advantages for people with Alzheimer's disease, because silicon chips implanted inside the brain can mimic the hippocampus. The hippocampus is an area known in the brain for storing and creating memory. This chip could potentially aid people suffering from memory loss form new memories, and store old memories for longer periods of time. ("Sandhand, Lakshi"). Neurochips might also substantially increase the intelligence of mentally disabled people. The thought that people have would this new found freedom, could open up a virtual pandoras box of chaos which will be explained later. Other possibilities for paralyzed patients are neurosensors that would be connected by electrodes and fiber optics cable into the motor cortex which would allow that person to manipulate their electronic environment around them. Such as operating a computer by thought alone, turning on and off light switches in their house, to manipulating their oven's heat temperature. ("Brain Implants ..2").

If history shares any economic relationships with the past one may argue that those who foresee these changes and can ride the technological wave may have much to invest in. Biologist have came a long way achieving great success in the Human Genome Project, which has sped up sequencing of DNA by many magnitudes .According to Kurzweil an analysis of the history of technological evolution is exponential contrary to intuitive linear view. “So we won’t experience 100 years of progress in the 21st century– it will be more like 20,000 years of progression.” (“Kurzweil”). The “returns” which involves microchip speed and cost-effectiveness also obeys this law, The Law of Accelerating Returns. Mathematically there should even be an exponential growth within the rate of exponential growth. Futurist predict that within a few decades machine intelligence or artificial intelligence will transcend human intelligence. Technological change would be so rapid, and significantly profound that it would forever change the fabric of human history. As discussed previously these changes include merges with biological and non-biological technology, and possibly ultra-intelligent software, and intelligence.

Mathematically exponential trends in the past were so flat that there appeared to be no trend. Lack of technological expectations have been fulfilled. Most long term forecast of technological feasibility in the future is underestimated in the power of evolutions. This is the paradigm based on intuitive linear view of technological progression rather than exponential historical view of technological progression. Kurzweil mathematically predicts that we will see 100 years worth of technological progression in 25 years. Rapidly accelerated technological progression and societal change due to the event of superhuman intelligence would change society in one night, more than society has changed in 1,000 years. This fast pace movement would be so advance, that whatever we predict to happen now in the pre-singularity age, will probably be surpassed in the post Singularity age due to smarter than human intelligence. The uncertainty in the direction of this technological progression is called Singularity.

"Within thirty years, we will have the technological means to create superhuman intelligence. Shortly after, the human era will end." ("Vinge, Vernor"). "The theory of transformation states that humans will incorporate AI into their own biology."("Artificial Intelligence Theory"). Neurochips implanted into the human mind, can increase intelligence far surpass any human on earth. With this intelligence, humans can create smarter than human intelligent supercomputers, and robots. In return these supercomputers, and robots can create smarter supercomputers and robots, and so on, and so forth, until humans become totally obsolete. This would steepen the have from the have nots. The upper class elite could increase their intelligence, and life years by artificial means, while the lower and middle class go without, which means they would become obsolete themselves causing societal problems. Genetically engineered posthumans or greater than humans would outclass, out smart, and out preform "normal" human intellect, and human ability. Another possibility in this singularity future is mind downloading, and uploading onto a supercomputer. Basically this allows a user to download their mind, and reconstruct it down to the single neuron onto an artificial hardware for a cloned brained of that user. Essentially creating many conscious minds, and possibly souls of the person.("Bostrom, Nick"). Doing so creates many bioethical, and societal problems. For example, Ray in the year 2055 downloads his mind onto a supercomputer creating an exact copy of his mind. Doing so creates two of the same Rays, both of them swearing they are the original Ray. Who would be the real Ray? What ethical laws does this create? Does this make the second Ray a real person, and a law abiding person, or entity? Should the second Ray [downloaded version] be treated the same as a human, is this Ray human? How will this effect the original Ray? Does the second Ray have a soul? What happens if someone else uploads this Ray into their body? Do they become the same Ray? Do they think the same way? Do they now have the same souls? ("Kadmon, Adam"). The questions that are brought up with Neurochips are its insidious usages. If a person with Alzheimer's disease is implanted with a chip that mimics the hippocampus then how will that person know that the memory they have is of their own? With the implanted Neurochip, could come implantation of false memories. Memories the person never had. This could be used for massive brain washing, political propaganda, assassinations, and cover ups. The person with this implanted chip, may not even own their own mind. These chips can alter emotions, and actions of the user against their own will for desired effects of an euphoric feeling. In a future scenario an unknown homeless person could be beaten up, have his memory erased, implanted with a neurochip, having fond memories of a family he never had. While in reality this person assassinated a prominent political leader with skill and knowledge that allowed him to do so inserted into his neurons; doing so he thought he was in a skiing trip in CO. with his unknown family, swearing he killed no one [a possibility].

Another possibility is that humans can be implanted with chips that has the internet, making our brains online. Allowing us to surf the web mentally, and commutate with other uses telepathically. Dangers of this would include the question would we even own our own brain at this time? Would we have to pay for our minds? What if our minds get a virus? Could someone hack into our brain, and steal our memories, knowledge, experience and IQ? What security measures would we have to pay the Federal Government to have firewalls, and anti-virus programs installed into our minds [technology joke]? If one chooses not to have this technological progression incorporated into their body would they be left behind? What kind of world would it be like if humans were genetically engineered into the very best posthumans society could produce? It would leave everyone else without these golden genetics behind. Foreign and domestic governments could use this technology to create a dystopian government system [humans are destructive remember]? A world government system that has eliminated war, crime, poverty, and depression by creating a homogenous high-tech society across the entire world and social system , based on the principles of a technological utopia that creates a society free of care.

The irony of this is, in order to achieve this utopia, many things will possibly be eliminated including "family, cultural diversity, art, literature, religion and philosophy." ("Brave New World"). This singularity and dystopian future could also put the inferior and elite in different caste systems. Creating inequality in our society, but achieving certain societal "goals". ("Brave New World"). The monster we create could be the monster that destroys us. "Humans are constrained to only a few types of change acceptable, although the rational parts of our mind often remind us that change can be good." ("Kadmon, Adam"). Even though this technology is a double edge sword, we have the choice to choose where it will lead our society, we can bring our society into singularity break down, or singularity posterity. The choice is ours.

"Ex machina Libertas" means technology will set you free. This means that rationally applied technology will improve human conditions. ("Slogans"). But on the other hand "Eritis sicut dii", means that you shall be as gods. Which is similar to Genesis 3:5 comparing the relationship between the snake, and Eve, with technology representing the neo-fruit of knowledge opening our eyes to both good and evil knowledge.("Slogans ..2"). Which makes it up to humans to decide if Transhumanist movements in Neurotechnology , and technology will lead our society into a horrific melt-down into a singularity.

Who are we? What do we want? What defines us? What is it that defines you? Besides the biological aspect, that makes us humans? Why is our species so special? What makes us special? Why do humans want to recreate themselves? What is so special about our culture, social aspect, and lives? Why do we want to create something better than ourselves? Why do we want to create something that would make our lives so easy that we would no longer have to do manual labor, and make all human ability obsolete? One must ask themselves would they like to live in a world that would be ruled by machines, and technology? If we are lucky nature will forgive us, and our higher species will put us into cages, and make us do tricks for treats.

Security That Nets Malicious Web Sites

Have you ever wondered how fraudulent or malicious websites can rank highly on search engines like Google or Yahoo?


Queensland University of Technology IT researcher Professor Audun Josang said a website's ranking was determined by the number of people who visited the site - the more hits the higher the ranking.

But this system is fraught with danger and can be easily manipulated directing people to unreliable, low quality and fraudulent sites, according to Professor Josang.

"Just because a website ranks highly on a search engine doesn't mean it's a good website, in fact highly ranked websites can be malicious websites," he said.

To safeguard against this type of threat, Professor Josang believes the answer is to develop a new type of internet security system based on "reputation" where a community of users can rank the quality of a website.

He said this could then be used to warn others from visiting that site.

"For example most people are able to recognise a website that tries to trick them into giving confidential information (a phishing attack) when they see it," he said.

"With this system, aware users can rate such websites as malicious and as a result a phishing site will be quickly and universally recognised as dangerous, warning unsuspecting users against visiting that site."

Professor Josang said using this "social control" approach could provide protection against this type of online threat, by preventing attacks before they occurred.

"Social control methods, also known as soft security, adhere to common ethical norms by parties in a community.

"They make it possible to identify and sanction those participants who breach the norms and to recognise and reward members who adhere to them."

Professor Josang said in today's technologically advanced world of business, high ranking of a company's web page was a crucial factor for its success.

"This is why the control of search engines is so important and why it can be financially worthwhile for businesses to manipulate the system."

The central idea of Professor Josang's research is to take search engines one step further and by using them to make the internet a safe place to interact and transact.

"This project is about a new type of internet security that can be supported by search engines. There is a deception waiting for you around every corner on the internet and the technology we develop will protect people from that.

"I think in the future reputation systems, integrated into search engines, can be used to weed out such websites by giving them a low ranking and thereby making them invisible to unsuspecting users."

Wednesday, June 13, 2007

Closing Open Holes

With the spread of Hackers and Hacking incidents, the time has come, when not only system administrators of servers of big companies, but also people who connect to the Internet by dialing up into their ISP, have to worry about securing their system. It really does not make much difference whether you have a static IP or a dynamic one, if your system is connected to the Internet, then there is every chance of it being attacked.


This manual is aimed at discussing methods of system security analysis and will shed light on as to how to secure your standalone (also a system connected to a LAN) system.


Open Ports: A Threat to Security?


In the Netstat Tutorial we had discussed how the netstat -a command showed the list of open ports on your system. Well, anyhow, before I move on, I would like to quickly recap the important part. So here goes, straight from the netstat tutorial:


Now, the ??a? option is used to display all open connections on the local machine. It also returns the remote system to which we are connected to, the port numbers of the remote system we are connected to (and the local machine) and also the type and state of connection we have with the remote system.


For Example,


C:\windows>netstat -a


Active Connections


Proto Local Address Foreign Address State

TCP aditya:1031 dwarf.box.sk:ftp ESTABLISHED

TCP aditya:1036 dwarf.box.sk:ftp-data TIME_WAIT

TCP aditya:1043 banners.egroups.com:80 FIN_WAIT_2

TCP aditya:1045 mail2.mtnl.net.in:pop3 TIME_WAIT

TCP aditya:1052 zztop.boxnetwork.net:80 ESTABLISHED

TCP aditya:1053 mail2.mtnl.net.in:pop3 TIME_WAIT

UDP aditya:1025 *:*

UDP aditya:nbdatagram *:*



Now, let us take a single line from the above output and see what it stands for:


Proto Local Address Foreign Address State

TCP aditya:1031 dwarf.box.sk:ftp ESTABLISHED


Now, the above can be arranged as below:


Protocol: TCP (This can be Transmission Control Protocol or TCP, User Datagram Protocol or UDP or sometimes even, IP or Internet Protocol.)


Local System Name: aditya (This is the name of the local system that you set during the Windows setup.)


Local Port opened and being used by this connection: 1031


Remote System: dwarf.box.sk (This is the non-numerical form of the system to which we are connected.)


Remote Port: ftp (This is the port number of the remote system dwarf.box.sk to which we are connected.)


State of Connection: ESTABLISHED



?Netstat? with the ??a? argument is normally used, to get a list of open ports on your own system i.e. on the local system. This can be particularly useful to check and see whether your system has a Trojan installed or not. Yes, most good Antiviral software are able to detect the presence of Trojans, but, we are hackers, and need to software to tell us, whether we are infected or not. Besides, it is more fun to do something manually than to simply click on the ?Scan? button and let some software do it.


The following is a list of Trojans and the port numbers which they use, if you Netstat yourself and find any of the following open, then you can be pretty sure, that you are infected.



Port 12345(TCP) Netbus

Port 31337(UDP) Back Orifice


For complete list, refer to the Tutorial on Trojans at: hackingtruths.box.sk/trojans.txt



AND WHAT?


Now, the above tutorial resulted in a number of people raising questions like: If the 'netstat -a' command shows open ports on my system, does this mean that anyone can connect to them? Or, How can I close these open ports? How do I know if an open port is a threat to my system's security of not? Well, the answer to all these question would be clear, once you read the below paragraph:


Now, the thing to understand here is that, Port numbers are divided into three ranges:


The Well Known Ports are those from 0 through 1023. This range or ports is bound to the services running on them. By this what I mean is that each port usually has a specific service running on it. You see there is an internationally accepted Port Numbers to Services rule, (refer RFC 1700 Here) which specifies as to on what port number a particular service runs.


For Example,

By Default or normally FTP runs on Port 21. So if you find that Port 21 is open on a particular system, then it usually means that that particular system uses the FTP Protocol to transfer files. However, please note that some smart system administrators delibrately i.e. to fool lamers run fake services on popular ports. For Example, a system might be running a fake FTP daemon on Port 21. Although you get the same interface like the FTP daemon banner, response numbers etc, however, it actually might be a software logging your prescence and sometimes even tracing you!!!


The Registered Ports are those from 1024 through 49151. This range of port numbers is not bound to any specific service. Actually, Networking utlites like your Browser, Email Client, FTP software opens a random port within this range and starts a communication with the remote server. A port number within this range is the reason why you are able to surf the net or check your email etc.


If you find that when you give the netstat -a command, then a number of ports within this range are open, then you should probably not worry. These ports are simply opened so that you can get your software applications to do what you want them to do.


These ports are opened temporarily by various applications to perform tasks. They act as a buffer transfering packets (data) received to the application and vis-a-versa. Once you close the application, then you find that these ports are closed automatically.


For Example,

when you type www.hotmail.com in your browser, then your browser randomly chooses a Registered Port and uses it as a buffer to communicate with the various remote servers involved.


The Dynamic and/or Private Ports are those from 49152 through 65535. This range is rarely used, and is mostly used by trojans, however some application do tend to use such high range port numbers. For Example,Sun starts their RPC ports at 32768.


So this basically brings us to what to do if you find that Netstat gives you a couple of open ports on your system:


1. Check the Trojan Port List and check if the open port matches with any of the popular ones. If it does then get a trojan Removal and remove the trojan.


2. If it doesn't or if the Trojan Remover says: No trojan found, then see if the open port lies in the registered Ports range. If yes, then you have nothing to worry, so forget about it.



HACKING TRUTH:


A common technique employed by a number of system administrators, is remapping ports. For example, normally the default port for HTTP is 80. However, the system administrator could also remap it to Port 8080. Now, if that is the case, then the homepage hosted at that server would be at:


http://domain.com:8080 instead of

http://domain.com:80


The idea behind Port Remapping is that instead of running a service on a well known port, where it can easily be exploited, it would be better to run it on a not so well known port, as the hacker, would find it more difficult to find that service. He would have to port scan high range of numbers to discover port remapping.


The ports used for remapping are usually pretty easy to remember. They are choosen keeping in mind the default port number at which the service being remapped should be running. For Example, POP by default runs on Port 110. However, if you were to remap it, you would choose any of the following: 1010, 11000, 1111 etc etc


Some sysadmins also like to choose Port numbers in the following manner: 1234,2345,3456,4567 and so on... Yet another reason as to why Port Remapping is done, is that on a Unix System to be able to listen to a port under 1024, you must have root previledges.



Firewalls


Use of Firewalls is no longer confined to servers or websites or commerical companies. Even if you simply dial up into your ISP or use PPP (Point to Point Protocol) to surf the net, you simply cannot do without a firewall. So what exactly is a firewall?


Well, in non-geek language, a firewall is basically a shield which protects your system from the untrusted non-reliable systems connected to the Internet. It is a software which listens to all ports on your system for any attempts to open a connection and when it detects such an attempt, then it reacts according to the predefined set of rules.


So basically, a firewall is something that protects the network(or systen) from the Internet. It is derived from the concept of firewalls used in vehicles which is a barrier made of fire resistant material protecting the vehicle in case of fire.


Now, for a better 'according to the bible' defination of a firewall: A firewall is best described as a software or hardware or both Hardware and Software packet filter that allows only selected packets to pass through from the Internet to your private internal network. A firewall is a system or a group of systems which guard a trusted network( The Internal Private Network from the untrusted network (The Internet.)


NOTE: This was a very brief desciption of what a firewall is, I would not be going into the details of their working in this manual.


Anyway,the term 'Firewalls', (which were generally used by companies for commerical purposes) has evolved into a new term called 'Personal Firewalls'. Now this term is basically used to refer to firewalls installed on a standalone system which may or may not be networked i.e. It usually connects to an ISP. Or in other words a personal firewall is a firewall used for personal use.


Now that you have a basic desciption as to what a firewall is, let us move on to why exactly you need to install a Firewall? Or, how can not installing a firewall pose a threat to the security of your system?


You see, when you are connected to the Internet, then you have millions of other untrusted systems connected to it as well. If somehow someone found out your IP address, then they could do probably anything to your system. They could exploit any vulnerability existing in your system, damage your data, and even use your system to hack into other computers.


Finding out someone'e IP Address is not very difficult. Anybody can find out your IP, through various Chat Services, Instant Messengers (ICQ, MSN, AOL etc), through a common ISP and numerous other ways. Infact finding out the IP Address of a specific person is not always the priority of some hackers.


What I mean to say by that is that there are a number of Scripts and utilities available which scan all IP addresses between a certain range for predefined common vulnerabilities. For Example, Systems with File Sharing Enabled or a system running an OS which is vulnerable to the Ping of Death attack etc etc As soon as a vulnerable system is found, then they use the IP to carry out the attacks.


The most common scanners look for systems with RAT's or Remote Administration Tools installed. They send a packet to common Trojan ports and display whether the victim's system has that Trojan installed or not. The 'Scan Range of IP Addresses' that these programs accept are quite wide and one can easily find a vulnerable system in the matter of minutes or even seconds.


Trojan Horses like Back Orifice provide remote access to your system and can set up a password sniffer. The combination of a back door and a sniffer is a dangerous one: The back door provides future remote access, while the sniffer may reveal important information about you like your other Passwords, Bank Details, Credit Card Numbers, Social Security Number etc.


If your home system is connected to a local LAN and the attacker manages to install a backdoor on it, then you probably have given the attacker the same access level to your internal network, as you have. This wouls also mean that you will have created a back door into your network that bypasses any firewall that may be guarding the front door.


You may argue with me that as you are using a dial up link to your ISP via PPP, the attacker would be able to access your machine only when you are online. Well, yes that is true, however, not completely true. Yes, it does make access to your system when you reconnect, difficult, as you have a dynamic Internet Protocol Address. But, although this provides a faint hope of protection, routine scanning of the range of IP's in which your IP lies, will more often than not reveal your current Dynamic IP and the back door will provide access to your system.



HACKING TRUTH:


Microsoft Says: War Dialer programs automatically scan for modems by trying every phone number within an exchange. If the modem can only be used for dial-out connections, a War Dialer won't discover it. However, PPP changes the equation, as it provides bidirectional transportmaking any connected system visible to scanners?and attackers.



PROTECTING YOURSELF


So how do I protect myself from such Scans and unsolicitated attacks? Well, this is where Personal Firewalls come in. They just like their name suggests, protect you from unsolicitated connection probes, scans, attacks.


They listen to all ports for any connection requests received (from both legitimate and fake hosts) and sent (by applications like Browser, Email Client etc.) As soon as such an instance is recorded, it pops up a warning asking you what to do or whether to allow the connection to initiate or not. This warning message also contains the IP which is trying to initiate the connection and also the Port Number to which it is trying to connect i.e. the Port to which the packet was sent. It also protects your system from Port Scans, DOS Attacks, Vulnerability attacks etc. So basically it acts as a shield or a buffer which does not allow your system to communicate with the untrusted systems directly.


Most Personal Firewalls have extensive logging facilities which allows you to track down the attackers. Some popular firewalls are:


  1. BlackICE Defender : An IDS for PC's. It's available at http://www.networkice.com.

  2. ZoneAlarm: The easiest to setup and manage firewall. Get it for free at: www.zonelabs.com


Once you have installed a firewall on your system, you will often get a number of Warnings which might seem to be as if someone is trying to break into your system, however, they are actually bogus messages, which are caused by either your OS itself or due to the process called Allocation of Dynamic IP's. For a details description of these two, read on.



Many people complain that as soon as they dial into their ISP, their firewall says that such and such IP is probing Port X. What causes them?


Well, this is quite common. The cause is that somebody hung up just before you dialed in and your ISP assigned you the same IP address. You are now seeing the remains of communication with the previous person. This is most common when the person to which the IP was assigned earlier was using ICQ or chat programs, was connected to a Game Server or simply turned off his modem before his communication with remote servers was complete.


You might even get a message like:

Such and Such IP is trying to initaite a Netbios Session on Port X. This again is extrememly common. The following is an explanation as to why it happens, which I picked up a couple of days ago: NetBIOS requests to UDP port 137 are the most common item you will see in your firewall reject logs.


This comes about from a feature in Microsoft's Windows: when a program resolves an IP address into a name, it may send a NetBIOS query to IP address. This is part of the background radiation of the Internet, and is nothing to be concerned about.


What Causes them?


On virtually all systems (UNIX, Macintosh, Windows), programs call the function 'gethostbyaddr()' with the desired address. This function will then do the appropriate lookup, and return the name.


This function is part of the sockets API. The key thing to remember about gethostbyaddr() is that it is virtual. It doesn't specify how it resolves an address into a name. In practice, it will use all available mechanisms. If we look at UNIX, Windows, and Macintosh systems, we see the following techniques:


DNS in-addr.arpa PTR queries sent to the DNS server

NetBIOS NodeStatus queries sent to the IP address lookups in the /etc/hosts file

AppleTalk over IP name query sent to the IP address

RPC query sent to the UNIX NIS server

NetBIOS lookup sent to the WINS server


Windows systems do the /etc/hosts, DNS, WINS, and NodeStatus techniques. In more excruciating detail, Microsoft has a generic system component called a naming service.


All the protocol stacks in the system (NetBIOS, TCP/IP, Novel IPX, AppleTalk, Banyan, etc.) register the kinds of name resolutions they can perform. Some RPC products will likewise register an NIS naming service. When a program requests to resolve an address, this address gets passed onto the generic naming service. Windows will try each registered name resolution subsystem sequentially until it gets an answer.


(Side note: User's sometimes complained that accessing Windows servers is slow. This is caused by installing unneeded protocol stacks that must timeout first before the real protocol stack is queried for the server name.).


The order in which it performs these resolution steps for IP addresses can be configured under the Windows registry key


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\ServiceProvider.



Breaking Through Firewalls


Although Firewalls are meant to provide your complete protection from Port Scan probes etc there are several holes existing in popular firewalls, waiting to be exploited. In this issue, I will discuss a hole in ZoneAlarm Version 2.1.10 to 2.0.26, which allows the attacker to port scan the target system (Although normally it should stop such scans.)


If one uses port 67 as the source port of a TCP or UDP scan, ZoneAlarm will let the packet through and will not notify the user. This means, that one can TCP or UDP port scan a ZoneAlarm protected computer as if there were no firewall there IF one uses port 67 as the source port on the packets.


Exploit:

UDP Scan:

You can use NMap to port scan the host with the following command line:

nmap -g67 -P0 -p130-140 -sU 192.168.128.88

(Notice the -g67 which specifies source port).


TCP Scan:

You can use NMap to port scan the host with the following command line:

nmap -g67 -P0 -p130-140 -sS 192.168.128.88

(Notice the -g67 which specifies source port).



Tuesday, June 12, 2007

WHO ARE HACKERS ?

I feel it is necessary to clarify the term hacker. Perhaps your definition of a hacker has been influenced and tainted over the years. There have been various computer related activities attributed to the term “hacker”, but were greatly  misunderstood. Unfortunately for the people who are truly defined within the underground tech world as a “hacker” this is an insult to them.

There are various types of “hackers”, each with their own agenda. My goal is to help protect you from the worst of them.

Anarchist Hackers

These are the individuals who you should be weary of. Their sole intent on system infiltration is to cause damage or use information to create havoc. They are primarily the individuals who are responsible for the majority of system attacks against home users. They are more likely to be interested in what lies on another person’s machine for example yours.

Mostly you’ll find that these individuals have slightly above computer skill level and consider themselves hackers. They glorify themselves on the accomplishments of others. Their idea of classing themselves as a hacker is that of acquire programs and utilities readily available on the net, use these programs with no real knowledge of how these applications work and if they manage to “break” into someone’s system class themselves as a hacker. These individuals are called “Kiddie Hackers.”

They use these programs given to them in a malicious fashion on anyone they can infect. They have no real purpose to what they are doing except the fact of saying “Yeah! I broke into name here> computer!” It gives them bragging rights to their friends.

If there is any damage to occur in a system being broken into these individuals will accomplish it.

These individuals are usually high school students. They brag about their accomplishments to their friends and try to build an image of being hackers.

Hackers

A hacker by definition believes in access to free information.They are usually very intelligent people who could care very little about what you have on your system. Their thrill comes from system infiltration for information reasons. Hackers unlike“crackers and anarchist” know being able to break system security doesn’t make you a hacker any more than adding 2+2 makes you a mathematician. Unfortunately, many journalists and writers have been fooled into using the word ‘hacker.” They have attributed any computer related illegal activities to the term “hacker.”

Real hackers target mainly government institution. They believe important information can be found within government institutions. To them the risk is worth it. The higher the security the better the challenge. The better the challenge the better they need to be. Who’s the best keyboard cowboy? So to speak!

These individuals come in a variety of age classes. They range from High School students to University Grads. They are quite adept at programming and are smart enough to stay out of the
spotlight.

They don’t particularly care about bragging about their accomplishments as it exposes them to suspicion. They prefer to work from behind the scenes and preserve their anonymity.

Not all hackers are loners, often you’ll find they have a very tight circle of associates, but still there is a level of anonymity between them. An associate of mine once said to me “if they say they are a hacker, then they’re not!”

Crackers

For definition purposes I have included this term. This is primarily the term given to individuals who are skilled at the art of bypassing software copyright protection. They are usually highly skilled in programming languages.

“Know your enemy and know yourself and you will always be victorious...”

They are often confused with Hackers. As you can see they are similar in their agenda. They both fight security of some kind, but they are completely different “animals.”

And What

Being able to attribute your attacks to the right type of attacker is very important. By identifying your attacker to be either an Anarchist Hacker or a Hacker you get a better idea of what you’re up against.

FeedBack