Tuesday, April 14, 2020

Networking | Routing And Switching | Tutorial 2 | 2018


Welcome to my 2nd tutorial of the series of networking. In this video I've briefly described peer to peer network (P2P). Moreover, you'll see how to make a peer to peer network? How it's working? How we can intercept traffic over the network by using Wireshark? and many more. Wireshark tool is integrated with eNSP so it'll be installed automatically when you install the eNSP. On the other hand, you can install the Wireshark for your personal use from its website.

What is Peer to Peer (P2P) network? 

As when devices are connected with each other for the sake of communication that'll be known as a Network. Now what is peer to peer network? In P2P network each and every device is behaving like a server and a client as well. Moreover They are directly connected with each other in such a way that they can send and received data to other devices at the same time and there is no need of any central server in between them.

There is a question that mostly comes up into our minds that  Is it possible to capture data from the network? So the answer is yes. We can easily captured data from the network with the help of tools that have been created for network troubleshooting, so whenever there will be some issues happening to the network so we fixed that issues with the help of tools. Most usable tool for data capturing that every network analyst used named Wireshark but there are so many other tools available over the internet like SmartSniff, Ethereal, Colasoft Capsa Network Analyze, URL Helper, SoftX HTTP Debugger and many more.

What is Wireshark?

Wireshark is an open source network analyzer or sniffer used to capture packets from the network and tries to display the brief information about the packets. It is also used for software and communication protocol development. Moreover, Wireshark is the best tool to intercept the traffic over the network.

eLearnSecurity recently sat down with Chloé Messdaghi, discussing her journey from business consultant to cyber security professional.

Chloe is the VP of strategy at Point Three Security. She is a security research advocate who strongly believes that information security is a humanitarian issue. Besides her passion to keep people safe and empowered both on and offline, she is driven to fight for hacker rights. She's the founder of WomenHackerz and the president and cofounder of Women of Security and heads the San Francisco Bay area chapter.

Like so many others who are interested in a career in cyber security, Chloé showed an interest in technology at an early age then was curious about how cyber crime fit into her university studies on terrorism.

Unfortunately, like many women, Chloé was initially ignored. "I think the first time I realized that I want to be in the (hacker) community was probably when I was in the sixth grade," she said. "I was in a computer class and I remember going up to my instructor saying, I want to learn what hackers do. Can you show me? And he's like, Oh, that's so cute, but that's for boys."

Fighting Discrimination in the InfoSec Community

After Chloé joined her first cyber security firm, she quickly used her research background to immerse herself in the security world. Yet she still faced discrimination that would attempt to define her career:

"When I first started, I just didn't know that I was dealing with discrimination here and there. So, if I would go to a meeting, I would be treated differently. If I was in a boardroom, I'd be treated differently. For example, if you're in a room and you bring up a thought or an idea, everyone ignores it until the male says the exact same line and they applaud it."

Navigating Discrimination and Abuse

Chloé hears weekly from women in cyber security who have been discriminated against or sexually assaulted by their superiors. They are confused about how to navigate chain of command and human resources after such experiences.

People who are sexually assaulted "go to HR on their own to tell someone and within a couple of weeks they are let go from their job. And what happens is they go through their Slack, they go through their emails, they try to prove that that person wasn't capable of doing their job. And so, then what happens is that when you're getting fired, people sign that NDA."

Facing Discrimination Together

While women face discrimination in male-dominated industries like cyber security every day, Chloé wants everyone to know they have support, and there are groups who are willing to help. That's one reason she started WomenHackerz and Women of Security have chapters around the world and offer spaces where women can share their stories and learn from the experiences of others.

For more information, check out the WomenHackerz and Women of Security websites.



More info


Monday, April 13, 2020

How Do I Get Started With Bug Bounty ?

How do I get started with bug bounty hunting? How do I improve my skills?



These are some simple steps that every bug bounty hunter can use to get started and improve their skills:

Learn to make it; then break it!
A major chunk of the hacker's mindset consists of wanting to learn more. In order to really exploit issues and discover further potential vulnerabilities, hackers are encouraged to learn to build what they are targeting. By doing this, there is a greater likelihood that hacker will understand the component being targeted and where most issues appear. For example, when people ask me how to take over a sub-domain, I make sure they understand the Domain Name System (DNS) first and let them set up their own website to play around attempting to "claim" that domain.

Read books. Lots of books.
One way to get better is by reading fellow hunters' and hackers' write-ups. Follow /r/netsec and Twitter for fantastic write-ups ranging from a variety of security-related topics that will not only motivate you but help you improve. For a list of good books to read, please refer to "What books should I read?".

Join discussions and ask questions.
As you may be aware, the information security community is full of interesting discussions ranging from breaches to surveillance, and further. The bug bounty community consists of hunters, security analysts, and platform staff helping one and another get better at what they do. There are two very popular bug bounty forums: Bug Bounty Forum and Bug Bounty World.

Participate in open source projects; learn to code.
Go to https://github.com/explore or https://gitlab.com/explore/projects and pick a project to contribute to. By doing so you will improve your general coding and communication skills. On top of that, read https://learnpythonthehardway.org/ and https://linuxjourney.com/.

Help others. If you can teach it, you have mastered it.
Once you discover something new and believe others would benefit from learning about your discovery, publish a write-up about it. Not only will you help others, you will learn to really master the topic because you can actually explain it properly.

Smile when you get feedback and use it to your advantage.
The bug bounty community is full of people wanting to help others so do not be surprised if someone gives you some constructive feedback about your work. Learn from your mistakes and in doing so use it to your advantage. I have a little physical notebook where I keep track of the little things that I learnt during the day and the feedback that people gave me.


Learn to approach a target.
The first step when approaching a target is always going to be reconnaissance — preliminary gathering of information about the target. If the target is a web application, start by browsing around like a normal user and get to know the website's purpose. Then you can start enumerating endpoints such as sub-domains, ports and web paths.

A woodsman was once asked, "What would you do if you had just five minutes to chop down a tree?" He answered, "I would spend the first two and a half minutes sharpening my axe."
As you progress, you will start to notice patterns and find yourself refining your hunting methodology. You will probably also start automating a lot of the repetitive tasks.

More articles

FOCA V3.4.7 Released! #FearTheFOCA What's New? @Fear_The_Foca

La nueva versión de FOCA ya está en la calle lista para que empieces a jugar con ella. Como ya habíamos anunciado mi compañero Fran Ramírez y yo en nuestro CodeTalk de novedades de FOCA, se acaba de publicar la nueva versión, la FOCA v3.4.7 con las características ya anunciadas., y alguna más.

Figura 1: FOCA v3.4.7 Released! What's new?

Por si aún no has visto el CodeTalk For Developer que hicimos Fran Ramírez y yo sobre las novedades de FOCA, lo tienes aquí mismo para que te lo veas estos días si tienes un ratito.


Figura 2: CodeTalk For Developers: Novedades de FOCA


En él estuvimos hablando, además de todas las novedades en que estábamos trabajando, de esta nueva versión 3.4.7. que ya puedes descargar de la sección de Releases de nuestro GitHub de FOCA. Aquí mismo te la dejamos listo para que la descargues.

Figura 3: Release FOCA v3.4.7 en GitHub, compilada y con  código fuente

En el artículo de hoy vamos a aprovechar y hacer un repaso de todas estas nuevas funciones que hemos añadido en esta nueva versión donde, como característica principal, se ha incluido DIARIO para el análisis de malware de los documentos, apoyándose en tecnología Machine Learning. Como habréis visto, nuestros compañeros llevan tiempo usando Machine Learning aplicado a ciberseguridad y hemos metido una de las funciones desarrolladas en nuestra querida FOCA.

Figura 4: Machine Learning Aplicado a Ciberseguridad
de  0xWord con Carmen Torrano, Paloma Recuero, Fran Ramírez,
José Torres y Santiago Hernández

Podéis ver más detalles de su funcionamhttps://github.com/ElevenPaths/FOCAiento desde la propia web de DIARIO. Para acometer estos cambios y realizar una integración a medida, hemos considerado pertinentes una serie de modificaciones que facilitan su uso, que extienden la funcionalidad de FOCA, que sigue siendo básicamente como se explica en el libro que escribimos junto con Chema Alonso de Pentesting con FOCA 2ª Edición.

Figura 5:Libro de  Pentesting con FOCA 2ª Edición en 0xWord
de Chema Alonso con colaboración de Ioseba Palop, Manu Fernández,
Pablo González, Enrique Rando, Rubén Alonso y Juanma Moreno

La primera de ellas es la actualización del árbol lateral, creando la entrada 'Document Analysis'. Eso se debe a que no solo se pueden analizar metadatos de documentos como siempre, sino que también se podrá además comprobar diferentes sistemas de detección de malware en ellos. De esta manera, se le da un concepto más amplio para cualquier futura implementación que se quiera realizar.

Figura 6: Document Analysis

También se puede apreciar que al igual que existía un 'Metadata Summary', se ha incluido un resumen de los ficheros analizados por DIARIO, catalogando aquellos documentos en los que se ha encontrado malware, y en los que no.

Figura 7: Malware Summary

Y ahora, la vista de detalle de un documento no solo incluye la información de metadatos encontrados, sino que incluye también la predicción de malware. Ambos tipos de información siempre y cuando se hayan analizado, ya que este análisis se realiza de manera independiente. Como se puede apreciar en la imagen, aparecerá una advertencia en el caso de que el análisis de metadatos y/o de malware esté pendiente.

Figura 8: Información detallada de un documento

¿Cómo se realiza el análisis de malware de uno o varios documentos? De la misma manera en la que se analizan los metadatos. Basta con ir al listado de ficheros añadidos, y utilizando el menú contextual, pulsar la opción de 'Analyze Malware' para analizar el fichero o ficheros seleccionados, o 'Analyze All Malware' para analizar todos los del listado.

Figura 9: Analizando malware con DIARIO en todos los documentos

Cabe destacar que no todos los ficheros pueden ser analizados. Para esto deben estar descargados previamente, no haber sido analizados y que tengan una extensión compatible con DIARIO. Estas extensiones son 'pdf', 'docx', 'xlsx', 'doc', y 'xls'. En este vídeo tenéis información más detallada de DIARIO.


Figura 10: DIARIO. Una nueva forma de analizar malware.

Pero estas no son las únicas novedades. Además de los ya habituales fixes de versiones anteriores y la mejora y limpieza de código, esta nueva versión incluye mejoras en la extracción de metadatos, como el análisis de imágenes embebidas en ficheros PDF.

Figura 11: Extracción de metadatos en imágenes embebidas en ficheros PDF

¡Aprovechad estos días de estar en casa y probad la nueva funcionalidad! Si son tus primeros pasos con FOCA, aquí puedes consultar una pequeña guía. Y recuerda que puedes seguir al día las novedades en nuestra Cuenta de Twitter Oficial de FOCA: @Fear_The_Foca

Fear the FOCA!

Autor: Ioseba Palop, Main FOCA Contributor.


Figura 12: Contactar con Ioseba Palop

Continue reading


Advanced Penetration Testing • Hacking The World'S Most Secure Networks Free PDF

Related word
  1. Hacking Tools Pc
  2. Hacking Tools 2020
  3. Pentest Tools For Ubuntu
  4. Hacking Tools For Beginners
  5. Install Pentest Tools Ubuntu
  6. Top Pentest Tools
  7. Tools For Hacker
  8. Hacking Tools Kit
  9. Top Pentest Tools
  10. Blackhat Hacker Tools
  11. Hack Tools Online
  12. Pentest Tools For Mac
  13. Hacking Tools Windows
  14. Pentest Tools Bluekeep
  15. Hacker Tools Windows

Fragroute


"fragroute intercepts, modifies, and rewrites egress traffic destined for a specified host, implementing most of the attacks described in the Secure Networks "Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection" paper of January 1998. It features a simple ruleset language to delay, duplicate, drop, fragment, overlap, print, reorder, segment, source-route, or otherwise monkey with all outbound packets destined for a target host, with minimal support for randomized or probabilistic behaviour. This tool was written in good faith to aid in the testing of network intrusion detection systems, firewalls, and basic TCP/IP stack behaviour." read more...

Website: http://monkey.org/~dugsong/fragroute

Continue reading