Showing posts with label tutorial. Show all posts
Showing posts with label tutorial. Show all posts

Sunday, 16 September 2012

How to install Tor on Bactrack 5 R2

Hai, long time no see...
Now, i want to share how to install Tor on Backtrack 5 R2. For your information Tor is free software and an open network that helps you defend against a form of network surveillance that threatens personal freedom and privacy, confidential business activities and relationships, and state security known as traffic analysis.

Tor is an open source Anonymous Internet tool. It protects your personal identification from tracking systems by changing the source IP address frequently. Application will create many virtual tunnels through the tor network.

Oke, now i will show you a video that explain how to install Tor on Backtrack 5 R2 step by step. I've tried to practice and succeed




 Ok, good luck with your practice..

Saturday, 15 September 2012

Advanced Information Gathering using Maltego

After we learn about Information Gathering now we will learn about Advanced Information Gathering. So, what is Advanced Information Gathering? Advanced Information Gathering is more than just Information Gathering.

Advanced Information Gathering is more complex than Information Gathering. We search more information about the target. According to the given task, do advanced information gathering about one of website. We can use maltego to gathering more information about website.

First, open the maltego application...



Thursday, 13 September 2012

Privilege Escalation Mutillidae in Backtrack using Brute Force and LFI

Okay,,now we learn about privelege escalation. What is privelege escalation?
Privilege escalation is the act of exploiting a bug, design flaw or configuration oversight in an operating system or software application to gain elevated access to resources that are normally protected from an application or user.

There are two kinds of privilege escalation: Vertical and Horizontal.
  • Vertical privilege escalation requires the attacker to grant himself higher privileges. This is typically achieved by performing kernel-level operations that allow the attacker to run unauthorized code.
  • Horizontal privilege escalation requires the attacker to use the same level of privileges he already has been granted, but assume the identity of another user with similar privileges. For example, someone gaining access to another person's online banking account would constitute horizontal privilege escalation. 
One of the example of privelege escalation is brute force. Brute force (also known as brute force cracking) is a trial and error method used by application programs to decode encrypted data such as passwords or Data Encryption Standard (DES) keys, through exhaustive effort (using brute force) rather than employing intellectual strategies.   

What is LFI? A local file inclusion (usually called “LFI”) is a webhacking technique that allow simply to include files from a local location. That means that we can include a file that is outside of the web directory (if we got rights), and execute PHP code. 

Now i will show you Privilege Escalation Mutillidae in Backtrack using Brute Force and LFI, so you can try it yourself.

Installing Mutillidae on Backtrack

Okay, now we will try to install mutillidae. What is mutillidae? Mutillidae is a free and open source web application for website penetration testing and hacking which was developed by Adrian “Irongeek” Crenshaw and Jeremy “webpwnized” Druin. It is designed to be exploitable and vulnerable and ideal for practicing your Web Fu skills like SQL injection, cross site scripting, HTML injection, Javascript injection, clickjacking, local file inclusion, authentication bypass methods, remote code execution and many more based on OWASP (Open Web Application Security) Top 10 Web Vulnerabiltie

1. The first step is to make sure you've installed apache and mysql. Backtrack is usually already installed in the beginning. You just run it from the application menu.

2.  And then, open the folder /var/www mutillidae and download files with a command like below.

cd /var/www
wget http://sourceforge.net/projects/mutillidae/files/mutillidae-project/LATEST-mutillidae-2.3.5.zip/download

Saturday, 8 September 2012

How to install nessus on Backtrack 5

After Website Information Gathering, the second task is explain How to install Nessus on Backtrack. 
Okey, for your informastion Nessus is a proprietary comprehensive vulnerability scanning program. It is free of charge for personal use in a non-enterprise environment. Its goal is to detect potential vulnerabilities on the tested systems.

Oke, let's try to install Nessus..

1. Download the installation packet from the official page at www.nessus.org. But you can also just type the command below to your terminal if you already are connected to the Internet.

root@bt:~# apt-get install nessus

Information Gathering

The first thing we should do when starting penetration testing or hacking is gather information. In Information Security ussualy called Information Gathering step. Information Gathering is the basic thing in hacking. Information Gathering is the process of gathering as much information from the target which we will test. Informastion Gathering is divided into two, Technical and Non-Technical.
  • Technical Information Gathering is the process of gathering information that is technical, such as the use of tools.
  • Non-Technical Information Gathering is the process of gathering information that is non technical, for example, personal approach to the target.
Technical Information Gathering was divided into two techniques, Active and Passive. 
  • Active Information Gathering is is a collection of information directed towards a target, such as scan directly to the target.
  • Passive Information Gathering is a collection of information that does not lead directly to a target, such as using different media, ie googling.

Next, i will try to practice Information Gatherig in my network.

Friday, 7 September 2012

Installing & Connecting Ubuntu in VirtualBox ~ Part 2

After we successfully installed the Ubuntu in VirtualBox, then we will tried to connecting the Ubuntu in VirtualBox with Backtrack.

1. First step, open the VirtualBox Manager. And choose the Ubuntu Virtual Machine.



Thursday, 6 September 2012

Installing & Connecting Ubuntu in VirtualBox ~ Part 1

Okey, after we tried to install Windows in VirtualBox, then we will try to install Ubuntu in VirtualBox to be used for Penetration Test Laboratory. We must prepare VirtualBox-4.2, Ubuntu 10.10, and Backtrack to do that.

This is steps to Installing & Connecting Ubuntu in VirtualBox


1. Firts step, open the VirtualBox Manager. Then click start to Create New Installation.


Installing & Connecting Windows in VirtualBox ~ Part 2

Okay, now Windows XP already installed on virtualbox, then we will try to connect Backtrack OS with Windows XP that contained in VirtualBox.

1. First, open the VirtualBox Manager.




Installing & Connecting Windows in VirtualBox ~ Part 1

Okay, after we finished installing virtualbox on backtrack, then the next we will create Penetration Test Laboratory using VirtualBox which we installed earlier.

Things that we need to create Penetration Test Laboratory is VirtualBox-4.2, Windows XP SP3,  and Backtrack 5 R2.

Steps to Installing & Connecting Windows in VirtualBox

1.  Open VirtualBox Manager