Welcome to HaCkEr-BrAdRi

HaCkEr-BrAdRi you Quality Software's Free of Cost with full version Keep Visiting and Keep enjoying . . . Don't Forget To Comment on Posts.

HaCkEr-BrAdRi Features

HaCkEr-BrAdRi provide you cracked,registered, serial key, and much more for free

HaCkEr-BrAdRi Update Daily

Our Team Update Blog Daily Or Twice A Day With latest and Cool Stuff For You For Free Download . . .

HaCkEr-BrAdRi Give You Big Variety Of Software's

HaCkEr-BrAdRi Provide You Latest and registered software's. . .

HaCkEr-BrAdRi

A Solution Of Your Needs

Showing posts with label E-Book's. Show all posts
Showing posts with label E-Book's. Show all posts

Hacking Exposed 6th Edition - Network Security Secrets and Solutions

Hacking Exposed 6th Edition - Network Security Secrets and Solutions

AT A GLANCE

Casing the Establishment
Case Study . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2
IAAAS—It’s All About Anonymity, Stupid . . . . . . . . . . . . . . . . . . . . . . . . . . . 2
Tor-menting the Good Guys . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2

1 Footprinting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
What Is Footprinting? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
Why Is Footprinting Necessary? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Internet Footprinting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Step 1: Determine the Scope of Your Activities . . . . . . . . . . . . . . . . . . 10
Step 2: Get Proper Authorization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Step 3: Publicly Available Information . . . . . . . . . . . . . . . . . . . . . . . . . 11
Step 4: WHOIS & DNS Enumeration . . . . . . . . . . . . . . . . . . . . . . . . . . 24
Step 5: DNS Interrogation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34
Step 6: Network Reconnaissance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42

 2 Scanning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43
Determining If the System Is Alive . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44
Determining Which Services Are Running or Listening . . . . . . . . . . . . . . . . 54
Scan Types . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55
Identifying TCP and UDP Services Running . . . . . . . . . . . . . . . . . . . . 56
Windows-Based Port Scanners . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62
Port Scanning Breakdown . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67
xiv Hacking Exposed 6: Network Security Secrets & Solutions
Detecting the Operating System . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69
Active Stack Fingerprinting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69
Passive Stack Fingerprinting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 77

3 Enumeration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 79
Basic Banner Grabbing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 81
Enumerating Common Network Services . . . . . . . . . . . . . . . . . . . . . . . . . . . . 83
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 148


Part II System Hacking
Case Study: DNS High Jinx—Pwning the Internet . . . . . . . . . . . . . . . . . . . . . 152
4 Hacking Windows . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 157
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 159
What’s Not Covered . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 160
Unauthenticated Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 160
Authentication Spoofi ng Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 161
Remote Unauthenticated Exploits . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 172
Authenticated Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 179
Privilege Escalation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 179
Extracting and Cracking Passwords . . . . . . . . . . . . . . . . . . . . . . . . . . . 181
Remote Control and Back Doors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 193
Port Redirection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 198
Covering Tracks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 199
General Countermeasures to Authenticated Compromise . . . . . . . . 202
Windows Security Features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 206
Windows Firewall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 206
Automated Updates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 206
Security Center . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 208
Security Policy and Group Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 209
Bitlocker and the Encrypting File System (EFS) . . . . . . . . . . . . . . . . . 211
Windows Resource Protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 212
Integrity Levels, UAC, and LoRIE . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 213
Data Execution Prevention (DEP) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215
Service Hardening . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215
Compiler-based Enhancements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 219
Coda: The Burden of Windows Security . . . . . . . . . . . . . . . . . . . . . . . . 220
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 221

5 Hacking Unix . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 223
The Quest for Root . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 224
A Brief Review . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 224
Contents xv
Vulnerability Mapping . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 225
Remote Access vs. Local Access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 225
Remote Access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 226
Data-Driven Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 231
I Want My Shell . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 245
Common Types of Remote Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . 250
Local Access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 275
After Hacking Root . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 292
What Is a Sniffer? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 295
How Sniffers Work . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 296
Popular Sniffers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 297
Rootkit Recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 307
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 308


Part III Infrastructure Hacking
Case Study: Read It and WEP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 312 

6 Remote Connectivity and VoIP Hacking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 315
Preparing to Dial Up . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 316
War-Dialing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 318
Hardware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 318
Legal Issues . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 320
Peripheral Costs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 320
Software . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 320
Brute-Force Scripting—The Homegrown Way . . . . . . . . . . . . . . . . . . . . . . . . 336
A Final Note About Brute-Force Scripting . . . . . . . . . . . . . . . . . . . . . . 346
PBX Hacking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 348
Voicemail Hacking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 352
Virtual Private Network (VPN) Hacking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 358
Basics of IPSec VPNs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 362
Voice over IP Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 368
Attacking VoIP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 369
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 385

7 Network Devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 387
Discovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 388
Detection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 388
Autonomous System Lookup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 392
Normal traceroute . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 393
traceroute with ASN Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 393
show ip bgp . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 394
Public Newsgroups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 395
Service Detection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 396

xvi Hacking Exposed 6: Network Security Secrets & Solutions
Network Vulnerability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 401
OSI Layer 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 402
OSI Layer 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 404
OSI Layer 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 417
Misconfi gurations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 422
Route Protocol Hacking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 429
Management Protocol Hacking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 439
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 443

8 Wireless Hacking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 445
Wireless Footprinting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 447
Equipment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 447
War-Driving Software . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 453
Wireless Mapping . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 458
Wireless Scanning and Enumeration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 462
Wireless Sniffers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 463
Wireless Monitoring Tools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 466
Identifying Wireless Network Defenses and Countermeasures . . . . . . . . . . 470
SSID . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 471
MAC Access Control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 472
Gaining Access (Hacking 802.11) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 475
SSID . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 476
MAC Access Control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 477
WEP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 478
Attacks Against the WEP Algorithm . . . . . . . . . . . . . . . . . . . . . . . . . . . 479
Tools That Exploit WEP Weaknesses . . . . . . . . . . . . . . . . . . . . . . . . . . . 480
LEAP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 484
WPA . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 486
Attacks Against the WPA Algorithm . . . . . . . . . . . . . . . . . . . . . . . . . . . 487
Additional Resources . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 488
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 491

9 Hacking Hardware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 493
Physical Access: Getting in the Door . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 494
Hacking Devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 501
Default Confi gurations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 505
Owned Out of the Box . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 505
Standard Passwords . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 505
Bluetooth . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 506
Reverse Engineering Hardware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 506
Mapping the Device . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 506
Sniffi ng Bus Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 508
Firmware Reversing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 510
JTAG . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 513
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 514

Contents xvii
Part IV Application and Data Hacking
Case Study: Session Riding . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 516

10 Hacking Code . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 519
Common Exploit Techniques . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 520
Buffer Overfl ows and Design Flaws . . . . . . . . . . . . . . . . . . . . . . . . . . . 520
Input Validation Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 527
Common Countermeasures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 530
People: Changing the Culture . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 530
Process: Security in the Development Lifecycle (SDL) . . . . . . . . . . . . 532
Technology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 539
Recommended Further Reading . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 541
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 542

11 Web Hacking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 543
Web Server Hacking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 544
Sample Files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 546
Source Code Disclosure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 546
Canonicalization Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 547
Server Extensions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 548
Buffer Overfl ows . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 550
Web Server Vulnerability Scanners . . . . . . . . . . . . . . . . . . . . . . . . . . . . 551
Web Application Hacking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 553
Finding Vulnerable Web Apps with Google . . . . . . . . . . . . . . . . . . . . . 553
Web Crawling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 555
Web Application Assessment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 556
Common Web Application Vulnerabilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . 570
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 584

12 Hacking the Internet User . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 585
Internet Client Vulnerabilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 586
A Brief History of Internet Client Hacking . . . . . . . . . . . . . . . . . . . . . . 586
JavaScript and Active Scripting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 590
Cookies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 591
Cross-Site Scripting (XSS) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 592
Cross-Frame/Domain Vulnerabilities . . . . . . . . . . . . . . . . . . . . . . . . . . 594
SSL Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 595
Payloads and Drop Points . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 598
E-Mail Hacking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 599
Instant Messaging (IM) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 603
Microsoft Internet Client Exploits and Countermeasures . . . . . . . . . 604
General Microsoft Client-Side Countermeasures . . . . . . . . . . . . . . . . 609
Why Not Use Non-Microsoft Clients? . . . . . . . . . . . . . . . . . . . . . . . . . . 614

xviii Hacking Exposed 6: Network Security Secrets & Solutions
Socio-Technical Attacks: Phishing and Identity Theft . . . . . . . . . . . . . . . . . . . 615
Phishing Techniques . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 616
Annoying and Deceptive Software: Spyware, Adware, and Spam . . . . . . . 619
Common Insertion Techniques . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 620
Blocking, Detecting, and Cleaning Annoying and
Deceptive Software . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 622
Malware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 623
Malware Variants and Common Techniques . . . . . . . . . . . . . . . . . . . . 623
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 635


syngress - stealing the network how to own the box Free Download

Syngress - Stealing the Network How to own the box


Thomson - Guide to Linux Shell Script Programming Free Download

Thomson - Guide to Linux Shell Script Programming


Hack Proofing Linux Free Download Linux Ebook

Hack Proofing Linux Free Download


Unix and Linux Commands guide free download full Second Edition

Introduction to the Command Line

The Fat-Free Guide to Unix and Linux Commands
                                                                                                        Second Edition


  

Contents at a Glance

Introduction ................................................................................. 13

 Section 1: Overview of Unix, Linux and BSD Architecture ............. 17
 
Section 2: Command Line Basics .................................................. 25
 
Section 3: Advanced Shell Features and Commands .................... 45
 
Section 4: Text Editing and Extraction .......................................... 67
 
Section 5: Users, Groups, and Security ......................................... 89
 
Section 6: Process Control and Scheduling .................................. 115
 
Section 7: Startup and Shutdown .............................................. 131
 
Section 8: Network Commands.................................................. 149
 
Section 9: Hardware Management Commands .......................... 177
 
Section 10: File Systems ............................................................ 187
 
Section 11: Backup and Restore Commands ............................... 203
 
Section 12: Monitoring and Troubleshooting ............................. 211
 
Section 13: Printing Commands ................................................. 235
 
Section 14: Software Installation ............................................... 243
 
Section 15: System Administration Utilities ................................ 257
 
Appendix A: Bash Shortcut Keys ................................................ 261
 
Appendix B: Command Line Cheat Sheet ................................... 263
 
Appendix C: Command Cross Reference ..................................... 267

Free Download Advanced Linux Programming PDF

Free Download Advanced Linux Programming PDF



Contents At a Glance
I Advanced UNIX Programming
with Linux


1 Getting Started

2 Writing Good GNU/Linux Software

3 Processes

4 Threads

5 Interprocess Communication

II Mastering Linux

6 Devices

7 The /proc File System

8 Linux System Calls

9 Inline Assembly Code

10 Security

11 A Sample GNU/Linux Application

III Appendixes

A Other Development Tools

B Low-Level I/O

C Table of Signals

D Online Resources

E Open Publication License Version 1.0

F GNU General Public

Click Here To Read Online or Download

Hacking: An Analysis of Current Methodology

1 Abstract

Hacking has become a significant threat to networks exposed to the Internet. In order to
prevent systems from being hacked, the methods used by hackers must be well
understood. Hackers begin by selecting and footprinting a target network. Once the
target network is mapped, hackers proceed to map vulnerabilities and gain access by
cracking passwords, using stack-smashing attacks, or spoofing the IP address of trusted
machines. Hackers can then sniff internal network traffic or find other hosts that contain
vital company secrets. Finally, a hacker can clean up system logs in order to conceal the
fact that an attack occurred. In this paper we explain how each of these attack techniques
is carried out.

2  Introduction

The Internet has become a widely used medium for companies, schools, and governments
to share data. Because of the need to exchange electronic information, most computer
networks are connected and exposed to traffic on the Internet. With this exposure comes
security concerns. Hackers are a significant threat because often all that lies between a
hacker and a company’s internal secrets may be a poorly administered firewall or border
router.
How significant is this threat? A sampling of traffic into and out of a network over a few
days will often show hundreds, perhaps thousands of potentially malicious data packets.
Hundreds of hacking web sites have been born over the past years providing information
ranging from how to spoof email to how to gain root access on web servers. Hackers
need not understand the technology behind their methods; they can simply download a
script and go to work. In essence, the threat of a network being attacked is significant
and should not be taken lightly because even the novice hacker is capable of launching a
potentially damaging attack.
How can hackers be stopped? To answer this question, it is important to understand how
a hacker attacks a system. From footprinting to log cleanup, a hacker’s methodology
must be well understood so that firewalls and Intrusion Detection Systems (IDS) can be
built to prevent or detect future attacks.

Footprinting: What is it and How Do You Erase Them

Abstract

Footprinting is one of a hacker’s best friends. In this paper I will discuss just exactly what footprinting is, how it affects your privacy, and how to erase your footprints. Footprinting can cause severe damage to a business and your personal life. I t can also be beneficial for you and your business. I will show you how it can be a necessary evil for you so you can protect your computer life
.

UNIX Administration A Comprehensive Sourcebook for Effective Systems and Network Management

Contents

Section I UNIX Administration
1 UNIX — Introductory Notes
1.1 UNIX Operating System
1.2 User’s View of UNIX
1.3 The History of UNIX
1.3.1 Berkeley Standard Distribution — BSD UNIX
1.3.2 System V or ATT UNIX
1.4 UNIX System and Network Administration
1.4.1 System Administrator’s Job
1.4.2 Computing Policies
1.4.3 Administration Guidelines
1.4.3.1 Legal Acts
1.4.3.2 Code of Ethics
1.4.3.3 Organizations
1.4.3.4 Standardization
1.4.4 In This Book

2 The UNIX Model — Selected Topics
2.1 Introduction
2.2 Files
2.2.1 File Ownership
2.2.2 File Protection/File Access
2.2.2.1 Access Classes
2.2.2.2 Setting a File Protection
2.2.2.3 Default File Mode
2.2.2.4 Additional Access Modes
2.2.3 Access Control Lists (ACLs)
2.2.4 File Types
2.2.4.1 Plain (Regular) File
2.2.4.2 Directory
2.2.4.3 Special Device File
2.2.4.4 Link
2.2.4.5 Socket
2.2.4.6 Named Pipe
2.2.4.7 Conclusion
2.3 Devices and Special Device Files
2.3.1 Special File Names
2.3.2 Special File Creation
2.4 Processes
2.4.1 Process Parameters
2.4.1.1 Process Types
2.4.1.2 Process Attributes
2.4.1.3 File Descriptors
2.4.1.4 Process States
2.4.2 Process Life Cycles
2.4.2.1 Process Creation
2.4.2.2 Process Termination
2.4.3 Process Handling
2.4.3.1 Monitoring Process Activities
2.4.3.2 Destroying Processes
2.4.3.3 Job Control

3 UNIX Administration Starters
3.1 Superuser and Users
3.1.1 Becoming a Superuser
3.1.2 Communicating with Other Users
3.1.3 The su Command
3.2 UNIX Online Documentation
3.2.1 The man Command
3.2.2 The whatis Database
3.3 System Information
3.3.1 System Status Information
3.3.1.1 The uname Command
3.3.1.2 The uptime Command
3.3.1.3 The dmesg Command
3.3.2 Hardware Information
3.3.2.1 The HP-UX ioscan Command
3.3.2.2 The Solaris prtconf Command
3.3.2.3 The Solaris sysdef Command
3.4 Personal Documentation
3.5 Shell Script Programming
3.5.1 UNIX User Shell
3.5.2 UNIX Shell Scripts
3.5.2.1 Shell Script Execution
3.5.2.2 Shell Variables
3.5.2.3 Double Command-Line Scanning
3.5.2.4 Here Document
3.5.2.5 Few Tips

4 System Startup and Shutdown
4.1 Introductory Notes
4.2 System Startup
4.2.1 The Bootstrap Program
4.2.2 The Kernel Execution
4.2.3 The Overall System Initialization
4.2.3.1 rc Initialization Scripts
4.2.3.2 Terminal Line Initialization
4.2.4 System States
4.2.5 The Outlook of a Startup Procedure
4.2.6 Initialization Scripts
4.3 BSD Initialization
4.3.1 The BSD rc Scripts
4.3.2 BSD Initialization Sequence
4.4 System V Initialization
4.4.1 The Configuration File /etc/inittab
4.4.2 System V rc Initialization Scripts
4.4.3 BSD-Like Initialization
4.5 Shutdown Procedures
4.5.1 The BSD shutdown Command
4.5.2 The System V shutdown Command
4.5.3 An Example

5 UNIX Filesystem Management
5.1 Introduction to the UNIX Filesystem
5.2 UNIX Filesystem Directory Organization
5.2.1 BSD Filesystem Directory Organization
5.2.2 System V Filesystem Directory Organization
5.3 Mounting and Dismounting Filesystems
5.3.1 Mounting a Filesystem
5.3.1.1 The mount Command
5.3.2 Dismounting a Filesystem
5.3.3 Automatic Filesystem Mounting
5.3.4 Removable Media Management
5.4 Filesystem Configuration
5.4.1 BSD Filesystem Configuration File
5.4.2 System V Filesystem Configuration File
5.4.3 AIX Filesystem Configuration File
5.4.4 The Filesystem Status File
5.5 A Few Other Filesystem Issues
5.5.1 Filesystem Types
5.5.2 Swap Space — Paging and Swapping
5.5.3 Loopback Virtual Filesystem
5.6 Managing Filesystem Usage
5.6.1 Display Filesystem Statistics: The df Command
5.6.2 Report on Disk Usage: The du Command
5.6.3 Report on Disk Usage by Users: The quot Command
5.6.4 Checking Filesystems: The fsck Command

6 UNIX Filesystem Layout
6.1 Introduction
6.2 Physical Filesystem Layout
6.2.1 Disk Partitions
6.2.2 Filesystem Structures
6.2.3 Filesystem Creation
6.2.3.1 The mkfs Command
6.2.3.2 The newfs Command
6.2.3.3 The tunefs Command
6.2.4 File Identification and Allocation
6.2.4.1 Index Node (inode)
6.2.4.2 File Allocation
6.2.5 Filesystem Performance Issues
6.2.5.1 File Storage vs. File Transfer
6.2.5.2 Reserved Free Space
6.3 Logical Filesystem Layout
6.3.1 Logical Volume Manager — AIX Flavor
6.3.2 Logical Volume Manager — HP-UX Flavor
6.3.3 Logical Volume Manager — Solaris Flavor
6.3.4 Redundant Array of Inexpensive Disks (RAID)
6.3.5 Snapshot
6.3.5.1 The Volume Snapshot
6.3.5.2 The Filesystem Snapshot
6.3.6 Virtual UNIX Filesystem
6.4 Disk Space Upgrade

7 User Account Management
7.1 Users and Groups
7.1.1 Creation of User Accounts
7.1.2 User Database — File /etc/passwd
7.1.3 Group Database — File /etc/group
7.1.4 Creating User Home Directories
7.1.5 UNIX Login Initialization
7.1.5.1 Intialization Template Files
7.1.5.2 User Login Initialization Files
7.1.5.3 Systemwide Login Initialization Files
7.1.5.4 Shell Initialization Files
7.1.5.5 Setting the Proper Ownership
7.1.6 Utilities to Create User Accounts
7.2 Maintenance of User Accounts
7.2.1 Restricted User Accounts
7.2.2 Users and Secondary Groups
7.2.3 Assigning User Passwords
7.2.4 Standard UNIX Users and Groups
7.2.5 Removing User Accounts
7.3 Disk Quotas
7.3.1 Managing Disk Usage by Users
7.4 Accounting
7.4.1 BSD Accounting
7.4.2 System V Accounting
7.4.3 AIX-Flavored Accounting

8 UNIX System Security
8.1 UNIX Lines of Defense
8.1.1 Physical Security
8.1.2 Passwords
8.1.3 File Permissions
8.1.4 Encryption
8.1.5 Backups
8.2 Password Issues
8.2.1 Password Encryption
8.2.2 Choosing a Password
8.2.3 Setting Password Restrictions
8.2.4 A Shadowed Password
8.2.4.1 Usual Approach
8.2.4.2 Other Approaches
8.3 Secure Console and Terminals
8.3.1 Traditional BSD Approach
8.3.2 The Wheel Group
8.3.3 Secure Terminals — Other Approaches
8.4 Monitoring and Detecting Security Problems
8.4.1 Important Files for System Security
8.4.2 Monitoring System Activities
8.4.3 Monitoring Login Attempts
8.4.3.1 The su Log File
8.4.3.2 History of the Root Account
8.4.3.3 Tracking User Activities

And Many More 

Dictionary of Networking

Introduction

Networks are currently one of the fastest growing and most important developments in
the computer industry. Not only are more and more PCs becoming parts of networks, but
networked PCs are being incorporated into larger enterprise-wide applications so that everyone
in a company can access and share data.
With the expanding technology of networking comes the terminology to describe it.
This
Dictionary of Networking
provides definitions for all the terms you will encounter
when dealing with networks of any type.

Who Should Use This Book?

This book is designed to meet the needs of people who work with networks, communications,
and mobile computing systems. Whether you are networking previously unconnected
computers or downsizing from a mainframe, this book is for you. And if you are
studying for one of the network certification exams, you will find this book to be an essential
reference.
Network users of all levels are barraged with an almost bewildering array of terms, abbreviations,
and acronyms in books, magazine and newspaper articles, advertisements,
and their day-to-day conversations. Jargon is a useful shorthand, but it can easily become
incomprehensible and unmanageable, even to the most seasoned network administrator.

Linux Network Administrators Guide

2. Sources of Information...................................................................................................................................2
2.1. Documentation Available via FTP....................................................................................................3
2.2. Documentation Available via WWW...............................................................................................3
2.3. Documentation Available Commercially.........................................................................................3
2.4. Linux Journal and Linux Magazine..................................................................................................4
2.5. Linux Usenet Newsgroups................................................................................................................4
2.6. Linux Mailing Lists..........................................................................................................................5
2.7. Online Linux Support.......................................................................................................................6
2.8. Linux User Groups............................................................................................................................6
2.9. Obtaining Linux................................................................................................................................7
3. File System Standards........................................................................................9
4. Standard Linux Base...............................................................................................10
5. About This Book.................................................................................................11
6. The Official Printed Version................................................................................................13
7. Overview..........................................................................................................................15
8. Conventions Used in This Book...................................................................................................................17
9. Submitting Changes......................................................................................................................................18
10. Acknowledgments..........................................................................................................19
10.1. The Hall of Fame................................................................................................19
Chapter 1. Introduction to Networking..........................................................................................................21
1.1. History........................................................................................................................22
1.2. TCP/IP Networks.................................................................................................23
1.2.1. Introduction to TCP/IP Networks................................................................................23
1.2.2. Ethernets................................................................................................................24
1.2.3. Other Types of Hardware.............................................................................................25
1.2.4. The Internet Protocol......................................................................................................27
1.2.5. IP Over Serial Lines........................................................................................................28
1.2.6. The Transmission Control Protocol.....................................................................................28
1.2.7. The User Datagram Protocol........................................................................................29
1.2.8. More on Ports...................................................................................................................29
1.2.9. The Socket Library....................................................................................................30
1.3. UUCP Networks.....................................................................................................31
1.4. Linux Networking......................................................................................................................................32

And Many More . . . .
 Click Here To Download / Read online

Securing Linux

 Main Topics Of The Book

  • Local security measures
● Protecting against common remote attacks

● What to do after an attack, cleanup

● Having and following a Security Policy

Network Security using Linux

Table of Contents

Network Security using Linux.........................................................
Credits.............................................................................................X
Preface............................................................................................xii
Who is this book for?......................................................................................xiii
How the book was written..............................................................................xiii

Chapter 1..........................................................................................1
TCP/IP Fundamentals.........................................................................................1
Layers.................................................................................................................2
TCP/IP Addressing.............................................................................................3
Subnetting with CIDR...................................................................................6
Subnetting with VLSM..................................................................................7
TCP/IP Version 6...............................................................................................8
IPv6 and the Kernel.....................................................................................11
Constructing Packets........................................................................................14
TCP Communication........................................................................................16
Any port will do...........................................................................................18
What does a router really do?...........................................................................18
Open Source Linux Routers........................................................................20
Is a Linux router secure?..................................................................................22
Shutting off the unwanted services.............................................................22

Chapter 2........................................................................................24
Firewalling the Network...................................................................................24
Isn’t a router a firewall?...................................................................................26
IP v6 and IPTables...........................................................................................28
Patch-O-Matic.............................................................................................29
Firewalling 101................................................................................................31
Papers Please....................................................................................................34
The Penguin Builds a Wall...............................................................................34
TOC p:v
Bastille Linux...................................................................................................36
Free is good......................................................................................................37
IPCOP..........................................................................................................38
Firestarter.....................................................................................................40
Shorewall.....................................................................................................41
Web Based Tools.........................................................................................43
Commercial Firewalls......................................................................................44
Astaro..........................................................................................................44
Smoothwall..................................................................................................46
Gibraltar.......................................................................................................47
Resources.....................................................................................................50

Chapter 3........................................................................................52
IP Tables, Rules and Filters..............................................................................52
Chain Syntax...........................................................................................53
Rules.......................................................................................................53
Building of a Basic Rule..............................................................................54
Demonstrating rules................................................................................55
Advanced Rules...........................................................................................56
Matching Connection States...................................................................56
Configuring NAT...................................................................................57
Defending Against Basic Attacks ..........................................................59
Examing The Rules ................................................................................60
Strengthen Your Rules with ROPE .......................................................60
Your Basic Firewall.....................................................................................62
Firewall Testing...........................................................................................63
Firewall Script........................................................................................65
Resources.....................................................................................................72

Chapter 4........................................................................................73
Updating Linux................................................................................................73
RPMs................................................................................................................73
Red Hat Up2date..............................................................................................81
TOC p:vi
YUM.................................................................................................................84
APT..................................................................................................................86
What is a kernel update?..................................................................................87
How do I tell which kernel I have installed?...................................................88
How do I update the kernel?............................................................................88
Alternative Security Kernels............................................................................90
Keeping the LID on.....................................................................................91
Resources.....................................................................................................92

Chapter 5........................................................................................93
Encryption or protecting your Data..................................................................93
What is encryption?..........................................................................................93
What is this alphabet soup?..............................................................................94
How does encryption work?............................................................................95
What are keys all about?..................................................................................96
Why do I need encryption?..............................................................................98
How do I use GPG?..........................................................................................98
Managing keys...........................................................................................106
Revoking a Key....................................................................................106
Key Signing Parties..............................................................................107
Additional Notes About GnuPG................................................................108
Securing Data with SSH.................................................................................109
What is OpenSSH?.........................................................................................109
The basics of SSH..........................................................................................111
What else can SSH do?.............................................................................112
SSH Port Forwarding ...............................................................................115
What is a X.509 Certificate?..........................................................................118
Make Your Own Certificates.....................................................................118
Are You Certified?....................................................................................119
How to use the Certificate.........................................................................125
Secure Socket Layer.......................................................................................128
SSL and Apache.............................................................................................128
TOC p:vii
Resources...................................................................................................129

Chapter 6......................................................................................130
Detecting Intruders.........................................................................................130
Deploying an IDS...........................................................................................131
What is Snort..................................................................................................132
Building a Sensor...........................................................................................133
Secure Communications.................................................................................138
Making the Pig Fly.........................................................................................139
Installing MySQL......................................................................................139
Installing Snort..........................................................................................144
Snort Configuration...................................................................................146
Syslog Notes..............................................................................................147
Configuring Snort’s New Database...........................................................149
Starting the Pig..........................................................................................152
Apache.......................................................................................................153
Installing PHP............................................................................................154
Snort on ACID...........................................................................................156
Securing the Pig.........................................................................................160
Multiple NIC cards...............................................................................161
Rules? What Rules?.......................................................................................162
Updating the Rules...............................................................................166
Deploying Snort.............................................................................................167
Tapping the network..................................................................................168
Where to place Snort.................................................................................171
Managing Snort..............................................................................................171
Webmin.....................................................................................................171
Snort Center...............................................................................................173
Resources:..................................................................................................173

Chapter 7......................................................................................174
Virtual Private Networks................................................................................174
IPsec...........................................................................................................174
TOC p:viii
L2TP..........................................................................................................176
PPTP..........................................................................................................177
VPN Utilities..................................................................................................177
PPTP Client...............................................................................................177
OpenSwan..................................................................................................181
Installing and Configuring Openswan.......................................................183
Certificates and Keys............................................................................184
Configuration........................................................................................186
Resources...................................................................................................188

Chapter 8......................................................................................190
Logging for Fun and Profit............................................................................190
NTP for Linux...........................................................................................192
Monitoring and Analyzing the Logs.........................................................195
What to Look for..................................................................................202
Tuning Syslog.......................................................................................202
Rotating Logs........................................................................................204
Syslog Improved...................................................................................206
Securing Syslog Traffic........................................................................208
Windows to Syslog Converters............................................................208
Configuration Guides...........................................................................208
Sawmill.................................................................................................209
Logwatch..............................................................................................211
Swatch...................................................................................................213
LogSurfer..............................................................................................216
Nagios...................................................................................................217
Resources...................................................................................................219

Chapter 9......................................................................................220
Summary........................................................................................................220
Appendix 1...................................................................................223
INDEX..........................................................................................226

McGraw Hill HackNotes Windows Security Portable Reference eBook

Reference Center
Hacking Fundamentals: Concepts . . . . . . . . . . . . . . . . . . . . RC 2
ICMP Message Types . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . RC 5
Common Ports and Services . . . . . . . . . . . . . . . . . . . . . . . . . RC 7
Common NetBIOS Name Table Definitions . . . . . . . . . . . . RC 12
Windows Security Fundamentals: Concepts . . . . . . . . . . . RC 13
Windows Default User Accounts . . . . . . . . . . . . . . . . . . . . . RC 14
Windows Authentication Methods . . . . . . . . . . . . . . . . . . . RC 15
Common Security Identifiers (SIDs) . . . . . . . . . . . . . . . . . . . RC 16
Windows NT File System Permissions . . . . . . . . . . . . . . . . RC 17
Useful Character Encodings . . . . . . . . . . . . . . . . . . . . . . . . . RC 18
Testing for Internet Information Services
ISAPI Applications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . RC 21
Security Related Group Policy Settings . . . . . . . . . . . . . . . . RC 22
Useful Tools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . RC 26
Quick Command Lines . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . RC 28
WinPcap / libpcap Filter Reference . . . . . . . . . . . . . . . . . . . RC 29
nslookup Command Reference . . . . . . . . . . . . . . . . . . . . . . . RC 30
Microsoft Management Console . . . . . . . . . . . . . . . . . . . . . . RC 31
Online References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . RC 32
Part I
Hacking Fundamentals
■ 1 Footprinting: Knowing Where to Look . . . . . . . . . . . . . . . . . . . . . . . . 3
Footprinting Explained . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
Footprinting Using DNS . . . . . . . . . . . . . . . . . . . . . . . . 4
Footprinting Using Public
Network Information . . . . . . . . . . . . . . . . . . . . . . . . 10
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
v
■ 2 Scanning: Skulking About . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Scanning Explained . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
How Port Scanning Works . . . . . . . . . . . . . . . . . . . . . . 14
Port Scanning Utilities . . . . . . . . . . . . . . . . . . . . . . . . . . 21
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30
■ 3 Enumeration: Social Engineering, Network Style . . . . . . . . . . . . . . . 31
Enumeration Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
DNS Enumeration (TCP/53, UDP/53) . . . . . . . . . . . . 35
NetBIOS over TCP/IP Helpers (UDP/137,
UDP 138, TCP/139, and TCP/445) . . . . . . . . . . . . . 37
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48
■ 4 Packet Sniffing: The Ultimate Authority . . . . . . . . . . . . . . . . . . . . . . 49
The View from the Wire . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 50
Windows Packet Sniffing . . . . . . . . . . . . . . . . . . . . . . . 50
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 57
■ 5 Fundamentals of Windows Security . . . . . . . . . . . . . . . . . . . . . . . . . 59
Components of the Windows Security Model . . . . . . . . . . . 60
Security Operators: Users and User Contexts . . . . . . 60
Authentication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
Windows Security Providers . . . . . . . . . . . . . . . . . . . . 69
Active Directory and Domains . . . . . . . . . . . . . . . . . . . 70
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 71
Part II
Windows 2000 and 2003 Server Hacking Techniques & Defenses
■ 6 Probing Common Windows Services . . . . . . . . . . . . . . . . . . . . . . . . 75
Most Commonly Attacked Windows Services . . . . . . . . . . . 76
Server Message Block Revisited . . . . . . . . . . . . . . . . . . 76
Probing Microsoft SQL Server . . . . . . . . . . . . . . . . . . . 89
Microsoft Terminal Services /
Remote Desktop (TCP 3389) . . . . . . . . . . . . . . . . . . 93
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96
■ 7 Hacking Internet Information Services . . . . . . . . . . . . . . . . . . . . . . . 97
Working with HTTP Services . . . . . . . . . . . . . . . . . . . . . . . . . 98
Simple HTTP Requests . . . . . . . . . . . . . . . . . . . . . . . . . 98
Speaking HTTP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99
Delivering Advanced Exploits . . . . . . . . . . . . . . . . . . . 100
Introducing the Doors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 102
The Big Nasties: Command Execution . . . . . . . . . . . . 102
A Kinder, Gentler Attack . . . . . . . . . . . . . . . . . . . . . . . . 115
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117
vi HackNotes Windows Security Portable Reference
Part III
Windows Hardening
■ 8 Understanding Windows Default Services . . . . . . . . . . . . . . . . . . . . 121
Windows Services Revealed . . . . . . . . . . . . . . . . . . . . . . . . . . 122
The Top Three Offenders . . . . . . . . . . . . . . . . . . . . . . . . 122
Internet Information Services/
World Wide Web Publishing Service . . . . . . . . . . . 122
Terminal Services . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 123
Microsoft SQL Server / SQL
Server Resolution Service . . . . . . . . . . . . . . . . . . . . . 123
The Rest of the Field . . . . . . . . . . . . . . . . . . . . . . . . . . . . 123
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 134
■ 9 Hardening Local User Permissions . . . . . . . . . . . . . . . . . . . . . . . . . . 135
Windows Access Control Facilities . . . . . . . . . . . . . . . . . . . . . 136
File System Permissions . . . . . . . . . . . . . . . . . . . . . . . . . 136
Local Security Settings . . . . . . . . . . . . . . . . . . . . . . . . . . 146
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 154
■ 10 Domain Security with Group Policies . . . . . . . . . . . . . . . . . . . . . . . . 155
Group Policy Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 156
Group Policy Application . . . . . . . . . . . . . . . . . . . . . . . 157
Working with Group Policies . . . . . . . . . . . . . . . . . . . . 157
Working with Group Policies in Active Directory . . . . . . . . 163
Editing Default Domain Policies . . . . . . . . . . . . . . . . . 164
Controlling Who Is Affected by
Group Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165
Using the Group Policy Management
Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 166
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 168
■ 11 Patch and Update Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . 169
History of Windows Operating System Updates . . . . . . . . . 170
Automatic or Manual? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 171
How to Update Windows Manually . . . . . . . . . . . . . . 172
Manual Updates in Disconnected
Environments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173
Windows Update: What’s in a Name? . . . . . . . . . . . . 173
How to Update Windows Automatically . . . . . . . . . . 174
Verifying Patch Levels:
The Baseline Security Analyzer . . . . . . . . . . . . . . . . 177
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 179
Contents vii
Part IV
Windows Security Tools
■ 12 IP Security Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 183
IP Security Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 184
Working with IPSec Policies . . . . . . . . . . . . . . . . . . . . . . . . . . 185
Default Policies: Quick and Easy . . . . . . . . . . . . . . . . . 186
Advanced IPSec Policies . . . . . . . . . . . . . . . . . . . . . . . . 191
Troubleshooting Notes . . . . . . . . . . . . . . . . . . . . . . . . . 197
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197
■ 13 Encrypting File System . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 199
How EFS Works . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 200
Public Key Cryptography and EFS . . . . . . . . . . . . . . . 200
User Encryption Certificates . . . . . . . . . . . . . . . . . . . . . 201
Implementing EFS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 202
Adding Data Recovery Agents . . . . . . . . . . . . . . . . . . . 203
Configuring Auto-Enroll User Certificates . . . . . . . . . 205
Setting Up Certificate Server . . . . . . . . . . . . . . . . . . . . . 206
Using Encrypting File System . . . . . . . . . . . . . . . . . . . . 209
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 212
■ 14 Securing IIS 5.0 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 213
Simplifying Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 214
The IIS Lockdown Tool . . . . . . . . . . . . . . . . . . . . . . . . . 215
How the IIS Lockdown Tool Works . . . . . . . . . . . . . . 217
URLScan ISAPI Filter Application . . . . . . . . . . . . . . . . 218
Disabling URLScan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 220
IIS Metabase Editor . . . . . . . . . . . . . . . . . . . . . . . . . . . . 221
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 222
■ 15 Windows 2003 Security Advancements . . . . . . . . . . . . . . . . . . . . . . 223
What’s New in Windows 2003 . . . . . . . . . . . . . . . . . . . . . . . . 224
Internet Information Services 6.0 . . . . . . . . . . . . . . . . . 224
More Default Security . . . . . . . . . . . . . . . . . . . . . . . . . . 227
Improved Security Facilities . . . . . . . . . . . . . . . . . . . . . 232
Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 233
■ Index . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 235

Linux Firewall and Proxy Server How To

 

Table of Contents
Firewall and Proxy Server
HOWTO................................................................................................................1

Mark Grennan, mark@grennan.com.......................................................................................................1
1. Introduction..........................................................................................................................................1
2. Understanding Firewalls......................................................................................................................1
3. Firewall Architecture ..........................................................................................................................1
4. Setting up the Linux Filtering Firewall ...............................................................................................1
5. Software requirements.........................................................................................................................1
6. Preparing the Linux system.................................................................................................................1
7. IP filtering setup (IPFWADM)............................................................................................................2
8. IP filtering setup (IPCHAINS).............................................................................................................2
9. Installing a Transparent SQUID proxy................................................................................................2
10. Installing the TIS Proxy server..........................................................................................................2
11. The SOCKS Proxy Server.................................................................................................................2
12. Advanced Configurations..................................................................................................................2
13. Making Management Easy................................................................................................................2
14. Defeating a Proxy Firewall................................................................................................................2
15. APPENDEX A − Example Scripts....................................................................................................2
16. APPENDEX B − An VPN RC Script for RedHat.............................................................................2
1. Introduction..........................................................................................................................................3
1.1 Feedback............................................................................................................................................3
1.2 Disclaimer .........................................................................................................................................3
1.3 Copyright...........................................................................................................................................3
1.4 My Reasons for Writing this..............................................................................................................4
1.5 Further Readings................................................................................................................................4
2. Understanding Firewalls......................................................................................................................4
2.1 Firewall Politics.................................................................................................................................5
How it create a security policy...................................................................................................5
2.2 Types of Firewalls..............................................................................................................................5
Packet Filtering Firewalls...........................................................................................................6
Proxy Servers..............................................................................................................................6
Application Proxy.......................................................................................................................6
SOCKS Proxy.............................................................................................................................7
3. Firewall Architecture ..........................................................................................................................7
3.1 Dial−up Architecture.........................................................................................................................7
3.2 Single Router Architecture................................................................................................................7
3.3 Firewall with Proxy Server................................................................................................................7
3.4 Redundent Internet Configuration.....................................................................................................8
4. Setting up the Linux Filtering Firewall ...............................................................................................8
4.1 Hardware requirements......................................................................................................................9
5. Software requirements.........................................................................................................................9
5.1 Selecting a Kernel..............................................................................................................................9
5.2 Selecting a proxy server.....................................................................................................................9
6. Preparing the Linux system...............................................................................................................10
6.1 Compiling the Kernel.......................................................................................................................10
6.2 Configuring two network cards.......................................................................................................11
6.3 Configuring the Network Addresses................................................................................................11
6.4 Testing your network.......................................................................................................................13
6.5 Securing the Firewall.......................................................................................................................14
7. IP filtering setup (IPFWADM)..........................................................................................................15
8. IP filtering setup (IPCHAINS)...........................................................................................................17
9. Installing a Transparent SQUID proxy..............................................................................................19
10. Installing the TIS Proxy server........................................................................................................19
10.1 Getting the software.......................................................................................................................19
10.2 Compiling the TIS FWTK.............................................................................................................19
10.3 Installing the TIS FWTK ..............................................................................................................19
10.4 Configuring the TIS FWTK...........................................................................................................19
The netperm−table file..............................................................................................................20
The /etc/services file.................................................................................................................23
11. The SOCKS Proxy Server...............................................................................................................23
11.1 Setting up the Proxy Server...........................................................................................................23
11.2 Configuring the Proxy Server........................................................................................................23
The Access File.........................................................................................................................23
The Routing File.......................................................................................................................24
11.3 Working With a Proxy Server........................................................................................................25
Unix..........................................................................................................................................25
MS Windows with Trumpet Winsock......................................................................................25
Getting the Proxy Server to work with UDP Packets...............................................................26
11.4 Drawbacks with Proxy Servers......................................................................................................26
12. Advanced Configurations................................................................................................................26
12.1 A large network with emphasis on security...................................................................................27
The Network Setup...................................................................................................................27
The Proxy Setup........................................................................................................................28
13. Making Management Easy..............................................................................................................29
13.1 Firewall tools...........................................................................................29
.1..3...2. ..G..e..n..e..r.a..l. .t.o..o..l.s.....................................................................................30
15.1 RC Script useing GFCC.................................................................................................................30
15.2 GFCC script...................................................................................................................................31
15.3 RC Script without GFCC This is the firewall rules set built my hand. It does not use GFCC......32
16. APPENDEX B − An VPN RC Script for RedHat...........................................................................36

Linux Security Guidelines


Table of content


LEGAL NOTICE & DISCLAIMER .................................................................2
DOCUMENT VERSION HISTORY....................................................................3
RELATED DOCUMENTS..................................................................................3
LIST OF TABLES.................................................................................................................5
SUMMARY........................................................................................................................6
1. INTRODUCTION......................................................................................7
1.1. PURPOSE AND SCOPE ..............................................................7
1.2. ASSUMPTIONS .........................................................................7
1.3. INTENDED AUDIENCE......................................................................7
2. PHYSICAL SECURITY............................................................................8
2.1. BIOS PASSWORD .........................................................................8
2.2. PLACE SERVERS IN A CONTROLLED AREA................................................8
2.3. PREVENT SERVERS FROM BEING BOOTED THROUGH OTHER MEDIUM ........................8
2.4. SERVERS ARE TO BE PLACED IN RACKS WITH LOCKING MECHANISMS ......................9
2.5. CONCEAL CABLING AND POWER OUTLETS ................................................9
3. INSTALLATION AND CONFIGURATION.........................................................................................10
3.1. INSTALL FROM A CLEAN FORMATTED DRIVE ...................................................10
3.2. PARTITIONS ............................................................................................10
3.3. CUSTOM INSTALLATION.....................................................................................10
3.4. PATCHES.................................................................................................11
3.5. INSTALLING PATCHES........................................................................11
4. LINUX OPERATING SYSTEM HARDENING ...............................................12
4.1. ACCOUNTS ...................................................................................12
4.2. ACCOUNTS POLICY...........................................................................12
4.3. REMOVING UNNECESSARY ACCOUNTS.........................................................13
4.4. ROOT ACCOUNT...................................................................................13
4.5. SERVICES AND PORTS ............................................................................14
4.6. SECURING XINETD....................................................................15
4.7. SECURING "/ETC/SERVICES" FILE ......................................................16
4.8. DISALLOW ROOT LOGIN FROM DIFFERENT CONSOLES ..........................................17
4.9. BLOCKING SU TO ROOT...........................................................................17
Linux Security Guideline BruCERT
5
4.10. TCPWRAPPERS................................................................................................17
4.11. IPTABLES ....................................................................................................................................18
4.12. DETECTING SUID/SGID PROGRAMS......................................................................18
4.13. HIDING SYSTEM INFORMATION......................................................................................................19
4.14. OTHER UTILITIES ..........................................................................................19
4.15. TRIPWIRE ................................................................................................19
4.16. SENTRY TOOLS.....................................................................................20
4.17. BASTILLE ................................................................................................20
5. CONCLUSION ...........................................................................................21
REFERENCES............................................................................................................22