Artikel getaggt mit USB

How easy it is to hack a Gmail , yahoo and a Hotmail password !

googlenotebookIn a follow up to my previous tutorial on how you can hack your Girlfriends or your friends yahoo password I am writing a follow up on how easy it is to hack your yahoo password with either a just little effort.

I will divide the whole group of net surfers in three basic parts.

  1. Absolute beginners.
  2. Regulars
  3. Experts

lets talk about the Beginners first.

This category of people usually do not have a lot knowledge of internet passwords and how they work. For instance this category will most likely use the save my password button on a public computer.

Lets crack their password first.

  1. Your partner, child, or pet’s name, possibly followed by a 0 or 1 (because they’re always making you use a number, aren’t they?)
  2. The last 4 digits of your social security number.
  3. 123 or 1234 or 123456.
  4. “password”
  5. Your city, or college, football team name.
  6. Date of birth – yours, your partner’s or your child’s.
  7. “god”
  8. “letmein”
  9. “money”
  10. “love”

Statistically speaking that should probably cover about all you beginners. But don’t worry. If I didn’t get it yet it will probably only take a few more minutes before I do…

Hackers, and I’m not talking about the ethical kind, have developed a whole range of tools to get at your personal data. And the main impediment standing between your information remaining safe, or leaking out, is the password you choose. (Ironically, the best protection people have is usually the one they take least seriously.)

One of the simplest ways to gain access to your information is through the use of aBrute Force Attack. This is accomplished when a hacker uses a specially written piece of software to attempt to log into a site using your credentials. Insecure.org has a list of the Top 10 FREE Password Crackers right here.

Now moving on to the second category

  • You probably use the same password for lots of stuff right?
  • Some sites you access such as your Bank or work VPN probably have pretty decent security, so I’m not going to attack them.
  • However, other sites like the Hallmark e-mail greeting cards site, an online forumyou frequent, or an e-commerce site you’ve shopped at might not be as well prepared. So those are the ones I’d work on.
  • So, all we have to do now is unleash Brutus, wwwhack, or THC Hydra on their server with instructions to try say 10,000 (or 100,000 – whatever makes you happy) different usernames and passwords as fast as possible.
  • Once we’ve got several login+password pairings we can then go back and test them on targeted sites.
  • But wait… How do I know which bank you use and what your login ID is for the sites you frequent? All those cookies are simply stored, unencrypted and nicely named, in your Web browser’s cache.

And how fast could this be done? Well, that depends on three main things, the length and complexity of your password, the speed of the hacker’s computer, and the speed of the hacker’s Internet connection.

Assuming the hacker has a reasonably fast connection and PC here is an estimate of the amount of time it would take to generate every possible combination of passwords for a given number of characters. After generating the list it’s just a matter of time before the computer runs through all the possibilities – or gets shut down trying.

Pay particular attention to the difference between using only lowercase characters and using all possible characters (uppercase, lowercase, and special characters – like @#$%^&*). Adding just one capital letter and one asterisk would change the processing time for an 8 character password from 2.4 days to 2.1 centuries.

Password Length All Characters Only Lowercase
3 characters
4 characters
5 characters
6 characters
7 characters
8 characters
9 characters
10 characters
11 characters
12 characters
13 characters
14 characters
0.86 seconds
1.36 minutes
2.15 hours
8.51 days
2.21 years
2.10 centuries
20 millennia
1,899 millennia
180,365 millennia
17,184,705 millennia
1,627,797,068 millennia
154,640,721,434 millennia
0.02 seconds
.046 seconds
11.9 seconds
5.15 minutes
2.23 hours
2.42 days
2.07 months
4.48 years
1.16 centuries
3.03 millennia
78.7 millennia
2,046 millennia

Remember, these are just for an average computer, and these assume you aren’t using any word in the dictionary. If Google put their computer to work on it they’d finish about 1,000 times faster.

Now, I could go on for hours and hours more about all sorts of ways to compromise your security and generally make your life miserable – but 95% of those methods begin with compromising your weak password. So, why not just protect yourself from the start and sleep better at night?

Believe me, I understand the need to choose passwords that are memorable. But if you’re going to do that how about using something that no one is ever going to guess AND doesn’t contain any common word or phrase in it.

Here are some password tips:

  1. Randomly substitute numbers for letters that look similar. The letter ‘o’ becomes the number ‘0?, or even better an ‘@’ or ‘*’. (i.e. – m0d3ltf0rd… like modelTford)
  2. Randomly throw in capital letters (i.e. – Mod3lTF0rd)
  3. Think of something you were attached to when you were younger, but DON’T CHOOSE A PERSON’S NAME! Every name plus every word in the dictionary will fail under a simple brute force attack.
  4. Maybe a place you loved, or a specific car, an attraction from a vacation, or a favorite restaurant?
  5. You really need to have different username / password combinations for everything. Remember, the technique is to break into anything you access just to figure out your standard password, then compromise everything else. This doesn’t work if you don’t use the same password everywhere.
  6. Since it can be difficult to remember a ton of passwords, I recommend usingRoboform. It will store all of your passwords in an encrypted format and allow you to use just one master password to access all of them. It will also automatically fill in forms on Web pages, and you can even get versions that allow you to take your password list with you on your PDA, phone or a USB key. If you’d like to download it without having to navigate their web site here is the direct download link.
  7. Once you’ve thought of a password, try Microsoft’s password strength tester to find out how secure it is.

Another thing to keep in mind is that some of the passwords you think matter leastactually matter most. For example, some people think that the password to their e-mail box isn’t important because “I don’t get anything sensitive there.” Well, that e-mail box is probably connected to your online banking account. If I can compromise it then I can log into the Bank’s Web site and tell it I’ve forgotten my password to have it e-mailed to me. Now, what were you saying about it not being important?

Often times people also reason that all of their passwords and logins are stored on their computer at home, which is save behind a router or firewall device. Of course, they’ve never bothered to change the default password on that device, so someone could drive up and park near the house, use a laptop to breach the wireless network and then try passwords from this list until they gain control of your network – after which time they will own you!

Now I realize that every day we encounter people who over-exaggerate points in order to move us to action, but trust me this is not one of those times. There are 50 other ways you can be compromised and punished for using weak passwords that I haven’t even mentioned.

I also realize that most people just don’t care about all this until it’s too late and they’ve learned a very hard lesson. But why don’t you do me, and yourself, a favor and take a little action to strengthen your passwords and let me know that all the time I spent on this article wasn’t completely in vain.

There are a lot of other techniques like Sql injection , Rat , ActiveX and a lot others.hacking the third category password will not only be tedious but very dangerous.Lets say that it is quite possible still.Depending on the type of person it would not take more than a day to break his password in most cases.I will write an advance tutorial expaining how this can be achieved.

Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Tiny USB Office – Portable Office Suite With Many Useful Applications

Do you love to have an Office suite which is around 2.5MB in size? Then you should check out Tiny USB Office. Tiny USB Office is a small and improved productivity office suite. It consists of many useful standalone applications that you might need everytime. So you can carry them on your USB drive and use them on different machines without installation.

Tiny USB Office suite can be used to create word documents, transfer files, create Excel sheets, email your friends, chat on MSN, create PDF files etc.

Tiny USB Office features many programs, which are accessible with one click with the included Qsel portable program launcher software:

PDF Producer – Create PDF files from Text files
Mempad – Tree-style outliner software
KPad – RTF Editor
CSVed – CSV file editor and Database creation tool
TedNotepad – Robust text editor with many features
Spread32 – mini-Excel with basic features
Qsel – Portable program launcher
100k Zipper – Basic Compression Utility
NPopUK – Email Client Software
PixaMSN – Tiny standalone MSN Messenger clone
DSdel – Secure file shredder Software
HFS – HTTP File Server to send and receive files
DScrypt – Text encryption program
FTP Wanderer – File Transfer Utility
EVE Vector Editor – Flowchart Creation Application
XPass – Password Recovery tool

You can carry Tiny USB Office in your USB as it occupies very less space. I can strongly tell you that it will be very useful and handy.

Download Tiny USB Office

Tags: , , , ,

Fancy Folder USB drive !

Folderix Drives look just like the normal folders with the added USB advantage. Want to show off your collegues that you are that 39th floor windows genuine geek with the sexy look.

This one is just for you.

Tags: , , , ,

Portable Applications. Portable Softwares on a USB drive !

Portable applications are convenient to carry, easy to use self contained applications which does not need to be installed on to the computer. You can carry those software around with you on a portable device such as USB flash drive, portable hard drive or iPod, and use on any Windows computer.

Portable applications must not require any kind of formal installation onto a computer’s permanent storage device to be executed, and can be stored on a removable storage device such as USB flash drive, enabling it to be used on multiple computers. The application settings are stored with, and can be carried around with, the software. Truly portable applications do not add anything to the local disk or registry. Portable applications leaves a zero or near-zero footprint on any PC it’s run on after being used. When you plug the portable device on to a computer, you will have access to your software and personal data just as you would on your own PC.
Portable applications/software uses a launcher for each portable program. The launcher takes care of starting the programs with settings from the USB drive, and saving the data back to it, keeping your privacy.

With Portable applications on your thumb drive, you can carry your web browser with bookmarks, calendar with appointments, email client with contacts and settings, instant messenger with buddy list, office suite along with your documents and presentations, antivirus program and other computer utilities, and more.

There are many portable application suites such as U3 and PortableApps.com available for Windows Desktops, which provides the portable platform. I personally prefer PortableApps.com. The website has a very friendly user community, in case you need any assistance. PortableApps.com provides an open platform which is 100% free to use, free to copy and free to share. The 1MB PortableApps.com Platform is just 1MB in size which provides the basic platform for the Portable Apps. Do you have an 513MB USB drive? Then you can have very good collection of portable applications on your wallet or key chain!
PortableApps.com Suite™ contains the basic platform and a great collection of portable open applications including a Firefox browser, Thunderbird email client, OpenOffice.org suite, Sunbird calendar/scheduler, Pidgin instant messaging client, ClamWin antivirus, CoolPlayer+ audio player, sudoku game, KeePass password manager, Sumatra PDF reader, minesweeper clone, backup utility and integrated menu, all pre-configured to work portably. Just push your portable device on to a computer and you’re ready to start working on your applications.

All versions of the PortableApps.com Suite include the integrated PortableApps.com Menu and the PortableApps.com Backup utility along with a set of custom icons, an autoplay configuration, folders and a quick start shortcut.

Each of the Portable Applications have a launcher bundled in it which leaves no personal information behind on the machine you run it on, so you can take your favourite browser along with all your favourite bookmarks and extensions with you wherever you go.

I have been a PortableApps user for sometime. The only installations I did on my laptop are AVG Free 8.0 anti virus, ZoneAlarm ForceField and CC PDF Converter. The rest of the applications are open source and portable running off my local hard disk. I do have a copy of all those portable programs in the USB Flash Drive (SanDsk Micro 8GB), ready to run from any computer. I have placed an link to the PortableAppsMenu in the Windows startup so that I can easily click and launch the portable apps.

Last month I screwed up my Vista booting while trying to configure Ubuntu. I simply reinstalled Vista, installed AVG and ZoneAlarm, and copied the Portable Apps from my USB and I am all set with my own application configuration, without anymore installations.

I use the following applications from PortableApps.com. You can see the complete list at PortableApps.com Applications page.

Mozilla Firefox Portable

Firefox Portable is a full featured latest version of Mozilla Firefox web browser, currently 3.0.1. This leaves no personal information behind the computer. You can carry your bookmarks, history, extensions and saved passwords with you wherever you go.

Mozilla Thunderbird Portable

With the Portable version of the popular email client Mozilla Thunderbird, you can take your email, address book and account settings with you. If you prefer using an email client, carry Portable Thunderbird with you. I don’t use a client nowadays, happy with Google Apps. But I do use the client version as an offline backup of my emails. I hope to even get rid of that when Google come up with GMail Offline, using Google Gears.

Mozilla Sunbird Portable

Sunbird Portable is a standalone calendaring and task management application built on the same technology as the Firefox web browser. It’s easy to use and makes keeping your calendar and tasks up-to-date a breeze. You can take your schedule and to do lists with you wherever you go.

OpenOffice.org Portable

OpenOffice.org Portable is the OpenOffice complete office suite, which includes a word processor, spreadsheet, presentation tool, drawing package and database. You can take all your documents and everything you need to work with them wherever you go.

Pidgin Portable

Pidgin (formerly Gaim) is a multi-protocol instant messaging client that works with AOL Instant Messenger, ICQ, MSN Messenger, Yahoo! and more. You can log into multiple networks all with the same program. All your IM settings and buddy lists are self-contained, so it leaves no personal information behind on the machine you run it on. Pidgin Portable supports the two most popular encryption plugins for Pidgin, packaged as portable installers that automatically work with Pidgin Portable.

Notepad++ Portable

Notepad++ Portable is the handy Notepad++ text editor with great features.

FileZilla Portable

FileZilla Portable is the popular FileZilla FTP client packaged as a portable app. FileZilla supports resume on both downloads and uploads, timeout detection, firewall support, etc. with an intuitive drag and drop interface.

GIMP Portable

GIMP, the GNU Image Manipulation Program, is an open source image editing package for Windows for such tasks as photo retouching, image composition and image authoring.

InfraRecorder Portable

InfraRecorder is a free CD/DVD burning solution for Microsoft Windows. You can cerate custom data, audio and mixed-mode projects and record them to physical discs as well as disc images. InfraRecorder supports recording to dual-layer DVDs. Using InfraRecorder you can erase rewritable discs, record disc images (ISO and BIN/CUE), create disc copies, on the fly, import session data from multi-session discs and add more sessions to them, and save audio and data tracks to files (.wav, .wma, .ogg, .mp3 and .iso)

JkDefrag Portable

JkDefrag Portable is an easy to use fast disk defragmenter and optimizer. Its a lightweight application capable of defragmenting very full harddisks or defragment very large files.

KeePass Password Safe Portable

KeePass is a open source password manager or safe which helps you to manage your passwords in a secure way. You can put all your passwords in one database, which is locked with one master key or a key-disk. So you only have to remember one single master password or insert the key-disk to unlock the whole database. The databases are encrypted using the best and most secure encryption algorithms currently known (AES-256 and Twofish).

Lightscreen Portable

Lightscreen Portable is an easy to use screenshot application for creating screenshots of the current desktop or parts of it. You can save the screenshot’s wherever you desire on your portable device. You can also save your screenshots in many formats (PNG, JPEG, GIF) and supports delayed screenshots.

CoolPlayer+ Portable

CoolPlayer+ Portable is an easy to use audio player with a simple User Interface. It has an advanced Playlist editor, supports Internet streaming, ID3 Multitagger, File Renaming, fast mp3->wav converter, MAD mpeg engine, OGG Vorbis support, Winamp input plugins support, etc..

VLC Media Player Portable

VLC media player is a highly portable multimedia player for various audio and video formats as well as DVDs, VCDs, and various streaming protocols. It can also be used as a server to stream in unicast or multicast in IPv4 or IPv6 on a high-bandwidth network.

AudioCity Portable

Audacity is an easy-to-use audio editor and recorder for Windows. You can record live audio on the go. You can convert tapes and records into digital recordings or CDs. You can edit, splice, and mix sounds together or change the speed or pitch of a recording.

BonkEnc Portable

BonkEnc Portable is an open source audio extractor, encoder, and converter. You can use BonkEnc to extract audio files from CDs, encode and re-encode audio files to a lower bitrate, and convert audio files to and from various formats, including MP3, Ogg Vorbis, MP4/AAC and FLAC

PNotes Portable

PNotes is an easy to use sticky note manager with group notes, font effects within individual notes and words, customisable alarms.

Sumatra PDF Portable

Sumatra PDF is a slim, free, open source PDF viewer for Windows with a minimalistic design. It’s small and starts up very fast.

7-Zip Portable

7-Zip is a file archiver utility for Windows with high compression ratio in new 7z format with LZMA compression. For ZIP and GZIP formats 7-Zip provides compression ratio that is 2-10 % better than ratio provided by PKZip and WinZip. 7-ZIP can create self-extracting capability for 7z format with a powerful File Manager.

ClamWin Portable

ClamWin is a Free Antivirus for Microsoft Windows with a graphical user interface to the Clam AntiVirus engine. ClamWin has high detection rates for viruses and spyware. You can download regular virus database updates. ClamWin Free Antivirus is a standalone Virus Scanner and does not include an on-access real-time scanner. So you need to manually scan a file in order to detect a virus or spyware.

XAMPP Server

XAMPP is an integrated server package of Apache, MySQL, PHP and Perl that all run from a removable drive. Everything is preconfigured and ready to go just by unzipping or installing it.

XAMPP easily integrates with the PortableApps.com Suite by using the XAMPP Launcher and installing XAMPP in the root directory of your portable device.

I have configured the XAMPP Server successfully to run from my USB drive. I now carry the server and my development websites/blogs in my thumb drive ready to work from anywhere. If you come across any issue and need further assistance, contact me.

Websites Offering Applications in PortableApps.com Format

The following sites also provides software confirming to the PortableApps format. You may need to check the legacy of such software before downloading and using them.

Tags: , ,

Hacking Applications that run on a USB drive !

There have been quite a collection of applications ported to run on USB flash disks. Most of these applications seem innocent enough, however some are deliberatly developed to get around IT software use policies in the workplace, such as P2P filesharing applications, instant messaging applications, FTP clients and podcast managers to name a few. Although these can be seen as a moderate security risk in the wrong hands they are more of a nuisance. However a new breed of applications are making their way to a USB drive near you that you should be more concerned with.

Applications which are used by security professionals (and hackers alike) to test the security of their networks and scan for vulnerabilities now have the capability to run independently from a USB flash drive and no longer require that WinPCap or other third-party packet capture drivers to be installed on a system. Applications such as Nmap, Ethereal, Showtraf, TCPDump, Nemesis and John the Ripper are now appearing online via sites in a modified form that contain an internal packet driver that is loaded when the application is launched.

What this means is that a hacker no longer needs to even have a laptop with them in order to compromise a network, simply bring a USB flash drive in a company and plug it into the USB drive of an available system.

Nmap *

Nmap is a free open source tool used for network exploration and vulnerability auditing. Using Nmap a user can quickly scan large networks as well as target specific hosts. Nmap uses IP packets in unique ways to figure ouw what hosts are available on a given network and can determine what operating system it is running as well as determine what services (including versions) it is running and can also discover what type of packet filters and firewalls are in use.

Ethereal *

Ethereal is a free protocal analyzer, also called a packet sniffer that is used for network troubleshooting, analysis and protocol development. The tool allows the user to see all traffic being passed over a network when putting a network card into what is known as “promiscuous mode”.

Showtraf *

Showtraf is a tool that monitors network traffic on a network and displays the traffic continuously via a GUI.

TCPDump *

TCPDump is similar in functionality to Ethereal, however works via the command line and does not have a graphical user interface. The application allows the user to intercept and display TCP/IP and other packets transmitted and received over a network.

Nemesis *

Nemesis works on the command line and is used for packet crafting and injection. It is used primarily for testing Network Intrusion Detection Systems, firewalls and IP stacks and other networking tasks.

John the Ripper *

John the Ripper is a password cracking tool which works to detect weak password. There are several other password cracking tools that run via USB, in fact most can. Interestingly many anti-virus applications will detect the presence of these files and quarantine them, however all one needs to do is temporarily disable the anti-virus which most users have the rights to do and it can be run without a problem.

Netpass *

Netpass is a utility used to recover network passwords on Windows 98/ME, however can also discover other passwords on XP such as .NET Passport passwords etc.

Slurp

A “podslurping” application that allows users to copy large quantities files from a system in a matter of seconds. A version that simply audits a system as an example of how such an application works is downloadable from here.

This is just a sampling of security related applications that can be run directly from a USB drive, this is by no means complete. More applications are appearing on a daily basis that can run straight from a USB flash drive. Although this can be incredibly convenient it can also prove to be a severe security issue for network administrators. With the strong focus of network security being focused on the perimeter also known as “The Great Wall Syndrome,” endpoint security has taken a back seat. Given that 70% of security breaches and data thefts occur behind the firewall and increasing cases of data theft in the news, it is time for IT professionals to seriously reconsider their endpoint security strategy.

Simple Solutions : Endpoint Security and USB Lock Down

Disabling USB ports is not difficult, however in a corporate environment this can cause problems, as many USB removable media devices are critical to business productivity. To provide granular access controls, there are products such as DeviceWall’s endpoint security solution, which allow administrators to decide who can plug-in what devices and whether they should have read/write access to these devices.

* I am not linking to the actual modified applications on purpose, primarily because although these can be used to assist in securing your network, can also be used for nefarious purposes…of course they are not difficult to find

Tags: , , ,