Friday, 21 January 2011

First DOS based virus celebrates silver jubilee

Yesterday the world celebrated the silver jubilee of DOS based computer viruses, yep, 25 years ago 2 Pakistani brothers Basit & Amjad Alvi wrote what would become an inspiration for the future virus writer - The Brain Virus. It was initially a copyright protection measure which protected their proprietary software from piracy by replacing the boot sector of an infected floppy disk with malicious code , thus moving the real boot code to another part of disk. It also slowed disk access & some unfortunate disks were rendered useless by it. Furthermore, all other floppies that were inserted on the infected machine would get infected but Brain did not copy itself to hard disk drives.
The flipside? Well..The Lahore-based Alvi brothers were upright about their actions & even included far their names and business address in the malware code.

Welcome to the Dungeon
© 1986 Basit & Amjad (pvt) Ltd.BRAIN COMPUTER SERVICES
730 NIZAB BLOCK ALLAMA IQBAL TOWN
LAHORE-PAKISTAN
PHONE :430791,443248,280530.
Beware of this VIRUS....
Contact us for vaccination............ $#@%$@!!

The virus infected machines in even US & UK, quite peculiar for a malware that was targeted at copyright violators. Times have changed..This virus was targeted at copyright violators, & was a curious attempt for the motivated, by the motivated. But today, every other virus would evolve into a Zombie botnet client.
As quoted by EL Reg

“Thanks to Alvi brothers could never have imagined we'd get here, even though they arguably helped pave a small part of the way towards a world of Windows malware. “
Like This post ?  You can buy me a Beer :)
Posted by XERO. ALL RIGHTS RESERVED. 

Friday, 21 January 2011 by Lucky · 0

Thursday, 20 January 2011

Linux Bot owned – Vulnerability makes botnet at Risk

Trojan.Jnanabot, or alternately as OSX/Koobface made waves in security scene when it was discovered that it can Linux Bot owned – Vulnerability makes botnet at Risk - theprohack.com attack  Linux/Mac OSX machines (Windows ones included). The trojan once installed, hid itself inside an invisible folder & communicated using strong encryptions. The host can be forced to perform vanilla attacks like DDOS, Facebook profile status updates (obviously fake ones) & some other ones. Holy crap, i m forced to eat my words back .. Now out of blue,researchers at Symnatec uncovered a specific weaknesses in the bot's p2p functionality that may allow rival criminals to remotely hijack the botnet or plant files on the victim's hard drive.

“Even though it's encrypted and even though it was written in Java to make it cross-platform, it was still vulnerable to basically a directory transversal exploit,”

exclaimed Dean Turner, director of Symantec's Global Intelligence Network. He added -

“From a technical perspective, it goes to show that even if you have all those things where you're building in a secure platform, if you're not building application security into your malware, other bad guys will probably take advantage of it.”

P2P function is designed to make botnets harder to take down by providing multiple channels of communication. Once a website sends a single GET request to an infected host, it can discover all the info needed to upload any file to any location on host, furthermore,attackers can then install a simple backdoor & can totally own the machine.

Bot stats - theprohack.com

Interestingly, statistics by Symnatec show that the bot’s favorite host platform is Windows - 85 % & Mac comes 2nd by 15 % . They didn't show any infections on Linux machines. Speaking of botnets, you might want to read about Project Blackout too ..

source : El Reg

Like This post ?  You can buy me a Beer :)

Posted by XERO. ALL RIGHTS RESERVED.

Thursday, 20 January 2011 by Lucky · 0

Wednesday, 19 January 2011

Welcome to Version 3.0

Hi folks .. Prohack is back :)

I believe you will be pissed off as the website was experiencing a lot of ups & down recently, broken feeds, unfinished redirections, error 404, error 500 .. the list goes on.. My move on wordpress was quite shaky ( bad dns resolution, non availability of internet, exams..jesus ) & the only thing I can say as of now is that I am back to blogger, this time with quite minimalistic look, which will be updated with time (as i tweak css in my free time). Prohack has changed, yep, a lot. The new template is designed by splashytemplates & i kind of liked it. Its quite low on resources & saves my happy ass & time as of now.

Please review my website & suggest improvements, till then, welcome to Prohack ver.3.0

 

 

- Rishabh Dangwal

 

Like This post ?  You can buy me a Beer :)

Posted by XERO. ALL RIGHTS RESERVED.

Wednesday, 19 January 2011 by Lucky · 0

Saturday, 1 January 2011

Errata guide to Ettercap GUI - through trial, error & experience.

Ettercap is one of the best sniffing tools available to day, but when it comes to using it on non-security-distro's on Noobs guide to Ettercap GUI - through trial, error & experience. - theprohack.com which it is not pre-configured to use with like Fedora , you might land into some problems like me. It all started on a sunny day when I actually thought to try it on Fedora Linux.

PS : I wont be covering ncurses as its quite easy & offers little to no hassles in operations, gave me no errors in operation strangely.

Anyways..I installed ettercap it by typing -

[root@zion xero]#su
Password:
[root@zion xero]# yum install ettercap

or

[root@zion xero]# yum install ettercap-gui

( I actually had problems with this one..)

Yum resolved dependencies & installed it, I ran it on my local lan network assuming to run it on default configuration.

[root@zion xero]# ettercap -T -Q -M ARP //192.168.1.3

It successfully captured all the packets & I was able to get details about capturing.   The real problems started when I started to run it on GUI mode.

[root@zion xero]# ettercap –G

Ettercap - looks promising - theprohack.com

well, the gtk gui popped up & prompted me to the stuff. I quickly pressed shift + U to choose network interface ( in this case my local lan network hooked up to my roommates laptops ), & chose 'eth0' the default Ethernet interface. I went ahead by scanning for hosts by pressing "ctrl + s" & bam..it crashed.

ettercap NG-0.7.3 copyright 2001-2004 ALoR & NaGA

Ooops ! This shouldn't happen...

Segmentation Fault...

Please recompile in debug mode, reproduce the bug and send a bugreport

Bam..segmentation fault - theprohack.com

okay..I got it..it might need to be crashing cause it has not been updated since a long time. Ah well, I compromised it by scanning partially for hosts & then running it. Again, I chose the host, added it to my target,mitm & started ARP poisoning (using the menu) & then started with unified sniffing.

I got nothing.

Realizing it was not backtrack, I sensibly closed it ( rearping the network..not by deliberately closing it like windows users do by abusing the [X] button) & opened etter.conf

[root@zion xero]# vi /etc/etter.conf

& uncommented the iptables option to look like this

# if you use iptables:
redir_command_on = "iptables -t nat -A PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"
redir_command_off = "iptables -t nat -D PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"

saved it, ran it again.

Again, the same drill, partial hosts scanning,target selection,mitm,arping,sniffing.

bang, I got nothing..again.
I looked at the console output & found -

[root@zion xero]#
ettercap NG-0.7.3 copyright 2001-2004 ALoR & NaGA

iptables v1.3.3: can't initialize iptables table `nat': Permission denied (you must be root)
Perhaps iptables or your kernel needs to be upgraded.

wow..I am running the program as root , edited the read only file as root & all i got was to upgrade my kernel ? bullshit! Anyways..back to etter.conf , this time I changed the privileges to 0

[privs]
ec_uid = 0                # nobody is the default
ec_gid = 0                # nobody is the default

The program ran & the error went away :)

but still..i was unable to capture anything in the GUI mode, guess the more user friendly you make it, the more hassles you add with it...sheesh. I was into new stuff like after 10 minutes of waiting I got this -

SEND L3 ERROR: 44 byte packet (0800:06) destined to 192.168.xxx.xxx was not forwarded (libnet_write_raw_ipv4(): -1 bytes written (Operation not permitted)

great...now this was what I was talking about. Now this really got me moving. Its not like everyday when you can target a network in CUI using one command of a program but using a GUI has a lot of strings attached.

Now I did everything very carefully, although I was still not able to figure out the real reason of "Segmentation Fault problem" , but I guess everything works fine if you do it like this -

Configure etter.conf like I stated above, set uid to 0 & uncomment iptables section.

run ettercap using kdesu, yep ran it with elevated privileges in kde environment to avoid "cant initialize iptables error".

[root@zion xero]# kdesu ettercap -G

give your password , & choose network interface (shift + U).

Once done, please be patient, open a new terminal window, change to root & type this command (forwards packets, avoids error :P ) -

[root@zion xero]# echo "1" > /proc/sys/net/ipv4/ip_forward

ettercap now works - theprohack.com

it will avoid the "SEND L3 ERROR" . Once done, do your drill & you will be "finally" able to capture data using GUI. For the rest of elites out there, I guess

[root@zion xero]# ettercap -T -Q -M arp:remote -i eth0 /192.168.1.3/ //

final

seems to work :) man..what a trip.. I would choose wireshark over it anyday..

Happy new year once again..

Untitled-2

 

Like This post ?  You can buy me a Beer :)

Posted by XERO. ALL RIGHTS RESERVED.

Saturday, 1 January 2011 by Lucky · 0

Friday, 31 December 2010

Happy New Year 2011

Hi friends.. A very happy new year 2011 to all of you. My exams are over & I will be back to blogging soon, sorry for almost no updates. Perhaps I was just waiting in time to settle all the scene wars & post some new stuff. I have made some new friends, met some old ones & wish to continue our journey of knowledge with you, & just you folks only.

Prohack wishes you a very happy new year :)

May this new year, you all be showered with the best almighty has to offer, & he shall empower you to fulfill your new year resolutions :D amen..

 

Rishabh Dangwal

www.theprohack.com

Friday, 31 December 2010 by Lucky · 0

Sunday, 28 November 2010

Basics of Assembly – Part 1

Indeed: the basics!! Before I start out with something really technical, I thought to clear all the basics which are neededBasics of Assembly – Part 1 for anyone who is new to reversing. What I am going to teach here is far from being complete but it will be covering  almost everything which you will need later on. To being with, An Assembler is the start and the end of all programming languages & that’s not an exaggeration. To my knowledge, all the computer languages are translated to binary & can be decompiled /disassembled in assembly. You might be having some programming experience in high level languages like C/C++, Java, .NET, which have relatively clear syntaxes, but when it comes to assembly (& LISP..i will come to it some time later) its a different ball game altogether. Assembly is the world of mnemonics, numbers &   abbreviations and numbers and that’s where it all turns sour for many of us...But trust me, this is a basic & simple guide to assembly & you will be able to quickly grasp basics of it.

PS: all the values which we will be talking about from now on will be in Hexadecimal...Unless specified :P I will be covering Bits & bytes & registers this time..

I. Starting with Bits and bytes:

BIT - The smallest possible piece of data in computing can be either 0 or a 1. Put a bunch of bits together & tada..You will have a 'binary number system'

For e.g. 
00000001 = 1       00000010 = 2             00000011 = 3     etc.



BYTE – A byte has 8 bits & can have a maximal value of 255 (0-255). We use the 'hexadecimal number system' for an easier reading of binary number system which is a 'base-16 system', while binary is a 'base-2 system'




  • WORD –A word = 2 bytes put together or 16 bits & can have a maximal value of 0FFFFh (or 65535d).


  • DOUBLE WORD –A double word = 2 words together or 32 bits & can have a max value = 0FFFFFFFF (or 4294967295d).


  • KILOBYTE –1000 bytes?! Nah, it’s actually 1024 bytes.


  • MEGABYTE –Again, not just 1 million bytes, but 1024*1024 or 1,048,578 bytes or 1024 KB.



II. A case of Registers:



Registers can be viewed as a placeholder in memory where we can put something; in simpler terms these are “special places” in your computer's memory where we can store data. View it as a little box, where we can put something: a name, a number, a sentence. Fact: Today’s WinTel (windows + Intel) CPU’s have 9 registers of 32 bit



Their names are:




EAX:     Extended Accumulator Register	        EBX:	 Extended Base Register
ECX: Extended Counter Register EDX: Extended Data Register
EDI: Extended Destination Index ESI: Extended Source Index
EBP: Extended Base Pointer ESP: Extended Stack Pointer
EIP: Extended Instruction Pointer



Generally the size of the registers is 32bit (=4 bytes) & they can hold data from 0-FFFFFFFF (unsigned). In earlier days registers did what their name meant...Like ECX = Counter, but nowadays you can almost use any register you like for a counter or stuff (except counter functions, which I will be covering as we progress). There's one more thing you have to know about registers: although they are all 32bits large, some parts of them (16bit or even 8bit) can not be addressed directly as modern processors work n 32 bit protected mode.


The possibilities are:




32bit Register	16bit 	8bit 
EAX AX     AH/AL
EBX BX     BH/BL
ECX CX     CH/CL
EDX DX     DH/DL
ESI SI     -----
EDI DI     -----
EBP             BP     -----
ESP SP     -----
EIP             IP     -----



To understand the above table lets consider a fictional value (my birthdate) as an example in hexadecimal & store it in register as –




30 Oct 1989





This can be written as:  30101989



Converting it in hexadecimal: 0x30101989



EAX = 30101989




Now as EAX (Extended AX) is 32 bit so it can store 30101989, therefore it consists of 2 AX registers which are of 16 bit each:




AX	AX
3010 1989



 


& each AX is made of A H (Accumulator high) & A L (Accumulator Low) registers of value 8 bit each, taking AX = 3010 as example -




AH     AL

30     10




Similarly for AX = 1989




AH	AL
19 89



So we can say EAX is the name of the 32bit register, AX is the name of the "Low Word" (16bit) of EAX and AL/AH (8bit) are the “names” of the "Low Part" and “High Part” of AX. By the way if you have not forgot  , 4 bytes is 1 DWORD, 2 bytes is 1 WORD.



Please Note: make sure you at least read the following about registers. It’s quite practical to know it although not that important. Also, the coming section may be a bit cryptic but will be explained in the followup tutorial.Since you are clear with the above, I guess we can make a distinction regarding size:



Byte-size registers: As the name says, these register are all exactly 1 byte (8 bits) in size & obviously it doesn’t means that the whole (32bit) register is fully loaded with data! Empty spaces in a register are just filled with zeroes.




AL and AH	BL and BH
CL and CH DL and DH



Word-size registers: Are 1 word (= 2 bytes = 16 bits) in size. A word-sized register is constructed of 2 byte-sized registers. Again, we can Segment registers:their purpose:




  • General purpose registers:




AX - ‘accumulator’:		used to do mathematical operation & store strings.
BX - 'base': used in conjunction with the stack
CX - 'counter' used to count a value a number of times
DX - 'data': here the remainder of mathematical operations is stored
DI - 'destination index': i.e. a string will be copied to DI
SI - 'source index': i.e. a string will be copied from SI




  • Index registers:




BP	-	'base pointer' : points to a specified position on the stack 

SP - 'stack pointer': points to a specified position on the stack




  • Segment registers:




CS	-	 'code segment' :	instructions an application has to execute 
DS - 'data segment' : the data your application needs
ES - 'extra segment': points to the active extra-segment
SS - 'stack segment': here we'll find the stack




  • Special: IP   -   'instruction pointer':   points to the next instruction. Just leave it alone



Double-word size registers: If you find an 'E' in front of a 16-bits register, it means that you are dealing with a 32-bits register. So, AX = 16-bits; EAX = the 32-bits version of EAX.



I believe I have covered registers this time, I will be covering Stack & instructions in my next article. Stay tuned & keep reversing



Like This post ?  You can buy me a Beer :)



Posted by XERO. ALL RIGHTS RESERVED.

Sunday, 28 November 2010 by Lucky · 0

Monday, 15 November 2010

Update on Indian Scene while on vacation

Hi Friends..Sorry for long inactivity, I was busy in my personal projects & the mess which is called college life (i mean the good old exam time) :P . In the mean time a lot has happened in the security scene, which I believe you guys will be aware of if you are following My friends at Facebook, If not, I will be providing a brief review of latest happenings. First of all, November edition of Hacker5 is out & you can subscribe the wonderful magazine from here.

hacker5 - theprohack.com

Secondly, NBC has proudly launched its venture of hacking which will be taught by some really good folks, No bullshit of basics, this is hard core. Coming down to the best news, Indishell is back :) . As signed by

[SiLeNtp0is0n], stRaNgEr , inX_rOot , NEO H4cK3R , DarkL00k , G00g!3 W@rr!0r , str1k3r, co0Lt04d , ATUL DWIVEDI , Jackh4xor , Th3 RDX & Lucky ;

Indishell aims to provide an intellectually stimulating environment where members can learn, communicate ideas and represent their concerns while supporting the advancement of the internet, technology and freedom.

I will be updating my blog as I get time, right now, I m kind of quite busy (writing an operating system :P as my final year project) , will catch you guys as soon as possible.

 

Keep learning.

like this post ? you can buy me a beer :)

Posted by XERO. ALL RIGHTS RESERVED

Monday, 15 November 2010 by Lucky · 2

All Rights Reserved by Pro Hack . Copyright 2008 - 20011. Template by Bloggermint .