online marketing
Showing posts with label projects. Show all posts
Showing posts with label projects. Show all posts

Tuesday, December 13, 2011

A Guide to Internet Security: Becoming an Uebercracker




Author: Christopher Klaus <cklaus@shadow.net>
Date: December 5th, 1993.
Version: 1.1

  This is a paper will be broken into two parts, one showing 15 easy steps
to becoming a uebercracker and the next part showing how to become a
ueberadmin and how to stop a uebercracker.  A uebercracker is a term phrased
by Dan Farmer to refer to some elite (cr/h)acker that is practically
impossible to keep out of the networks.

Here's the steps to becoming a uebercracker.

Step 1. Relax and remain calm. Remember YOU are a Uebercracker.

Step 2. If you know a little Unix, you are way ahead of the crowd and skip
past step 3.

Step 3. You may want to buy Unix manual or book to let you know what
ls,cd,cat does.

Step 4. Read Usenet for the following groups: alt.irc, alt.security,
comp.security.unix.  Subscribe to Phrack@well.sf.ca.us to get a background
in uebercracker culture.

Step 5. Ask on alt.irc how to get and compile the latest IRC client and
connect to IRC.

Step 6. Once on IRC, join the #hack channel. (Whew, you are half-way
there!)

Step 7. Now, sit on #hack and send messages to everyone in the channel
saying "Hi, Whats up?". Be obnoxious to anyone else that joins and asks
questions like "Why cant I join #warez?"

Step 8. (Important Step) Send private messages to everyone asking for new
bugs or holes. Here's a good pointer, look around your system for binary
programs suid root (look in Unix manual from step 3 if confused). After
finding a suid root binary, (ie. su, chfn, syslog), tell people you have a
new bug in that program and you wrote a script for it.  If they ask how it
works, tell them they are "layme". Remember, YOU are a UeberCracker. Ask
them to trade for their get-root scripts.

Step 9. Make them send you some scripts before you send some garbage file
(ie. a big core file). Tell them it is encrypted or it was messed up and
you need to upload your script again.

Step 10. Spend a week grabbing all the scripts you can. (Dont forget to be
obnoxious on #hack otherwise people will look down on you and not give you
anything.)

Step 11. Hopefully you will now have atleast one or two scripts that get
you root on most Unixes. Grab root on your local machines, read your
admin's mail, or even other user's mail, even rm log files and whatever
temps you. (look in Unix manual from step 3 if confused).

Step 12. A good test for true uebercrackerness is to be able to fake mail.
Ask other uebercrackers how to fake mail (because they have had to pass the
same test). Email your admin how "layme" he is and how you got root and how
you erased his files, and have it appear coming from satan@evil.com.

Step 13. Now, to pass into supreme eliteness of uebercrackerness, you brag
about your exploits on #hack to everyone. (Make up stuff, Remember, YOU are
a uebercracker.)

Step 14. Wait a few months and have all your notes, etc ready in your room
for when the FBI, Secret Service, and other law enforcement agencies
confinscate your equipment. Call eff.org to complain how you were innocent
and how you accidently gotten someone else's account and only looked
because you were curious. (Whatever else that may help, throw at them.)

Step 15. Now for the true final supreme eliteness of all uebercrackers, you
go back to #hack and brag about how you were busted.  YOU are finally a
true Uebercracker.


Now the next part of the paper is top secret.  Please only pass to trusted
administrators and friends and even some trusted mailing lists, Usenet
groups, etc. (Make sure no one who is NOT in the inner circle of security
gets this.)

This is broken down on How to Become an UeberAdmin (otherwise know as a
security expert) and How to stop Uebercrackers.

Step 1. Read Unix manual ( a good idea for admins ).

Step 2. Very Important.  chmod 700 rdist; chmod 644 /etc/utmp. Install
sendmail 8.6.4.  You have probably stopped 60 percent of all Uebercrackers
now.  Rdist scripts is among the favorites for getting root by
uebercrackers.

Step 3. Okay, maybe you want to actually secure your machine from the
elite Uebercrackers who can break into any site on Internet.

Step 4. Set up your firewall to block rpc/nfs/ip-forwarding/src routing
packets. (This only applies to advanced admins who have control of the
router, but this will stop 90% of all uebercrackers from attempting your
site.)

Step 5. Apply all CERT and vendor patches to all of your machines. You have
just now killed 95% of all uebercrackers.

Step 6. Run a good password cracker to find open accounts and close them.
Run tripwire after making sure your binaries are untouched. Run tcp_wrapper
to find if a uebercracker is knocking on your machines.  Run ISS to make
sure that all your machines are reasonably secure as far as remote
configuration (ie. your NFS exports and anon FTP site.)

Step 7. If you have done all of the following, you will have stopped 99%
of all uebercrackers. Congrads! (Remember, You are the admin.)

Step 8. Now there is one percent of uebercrackers that have gained
knowledge from reading some security expert's mail (probably gained access
to his mail via NFS exports or the guest account.  You know how it is, like
the mechanic that always has a broken car, or the plumber that has the
broken sink, the security expert usually has an open machine.)

Step 9. Here is the hard part is to try to convince these security experts
that they are not so above the average citizen and that by now giving out
their unknown (except for the uebercrackers) security bugs, it would be a
service to Internet.  They do not have to post it on Usenet, but share
among many other trusted people and hopefully fixes will come about and
new pressure will be applied to vendors to come out with patches.

Step 10.  If you have gained the confidence of enough security experts,
you will know be a looked upto as an elite security administrator that is
able to stop most uebercrackers.  The final true test for being a ueberadmin
is to compile a IRC client, go onto #hack and log all the bragging and
help catch the uebercrackers. If a uebercracker does get into your system,
and he has used a new method you have never seen, you can probably tell
your other security admins and get half of the replies like - "That bug
been known for years, there just isn't any patches for it yet. Here's my
fix." and the other half of the replies will be like - "Wow.  That is very
impressive. You have just moved up a big notch in my security circle."
VERY IMPORTANT HERE:  If you see anyone in Usenet's security newsgroups
mention anything about that security hole, Flame him for discussing it
since it could bring down Internet and all Uebercrackers will now have it
and the million other reasons to keep everything secret about security.


Well, this paper has shown the finer details of security on Internet. It has
shown both sides of the coin.  Three points I would like to make that would
probably clean up most of the security problems on Internet are as the
following:

1.  Vendors need to make security a little higher than zero in priority.
If most vendors shipped their Unixes already secure with most known bugs
that have been floating around since the Internet Worm (6 years ago) fixed
and patched, then most uebercrackers would be stuck as new machines get
added to Internet.  (I believe Uebercracker is german for "lame copy-cat
that can get root with 3 year old bugs.") An interesting note is that
if you probably check the mail alias for "security@vendor.com", you will
find it points to /dev/null.  Maybe with enough mail, it will overfill
/dev/null.  (Look in manual if confused.)

2.  Security experts giving up the attitude that they are above the normal
Internet user and try to give out information that could lead to pressure
by other admins to vendors to come out with fixes and patches.  Most
security experts probably don't realize how far their information has
already  spread.

3.  And probably one of the more important points is just following the
steps I have outlined for Stopping a Uebercracker.


Resources for Security:
   Many security advisories are available from anonymous ftp cert.org.
Ask archie to find tcp_wrapper, security programs.  For more information
about ISS (Internet Security Scanner), email cklaus@shadow.net.


Acknowledgements:

   Thanks to the crew on IRC, Dan Farmer, Wietse Venema, Alec Muffet, Scott
Miles, Scott Yelich, and Henri De Valois.


Copyright:

This paper is Copyright 1993, 1994.  Please distribute to only trusted
people.  If you modify, alter, disassemble, reassemble, re-engineer or have
any suggestions or comments, please send them to:

cklaus@shadow.net


Ipad



The iPad is a tablet computer designed and marketed by Apple for Internet browsing, media consumption, gaming, and light content creation. Released in April 2010, it established a new class of devices between smartphones and laptops.
              Similar to the older (and smaller) iPod Touch and iPhone, the iPad runs a modified version of the iPhone OS and is controlled by a multi-touch LCD sensitive to fingertips, instead of a stylus as with earlier tablet computers.  It runs iPad-specific applications as well as those written for the iPhone and iPod Touch, including e-book readers.
          The iPad uses Wi-Fi or a 3G data connection to browse the Internet, load and stream media, and install software.  A USB cable is required to sync the iPad with iTunes on a personal computer.

   SOFTWARE

              Like the iPhone, with which it shares a development environment (iPhone SDK, or software development kit, version 3.2 onwards),  the iPad only runs its own software, software downloaded from Apple's App Store, and software written by developers who have paid for a developer's license on registered devices.  The iPad runs almost all third-party iPhone applications, displaying them at iPhone size or enlarging them to fill the iPad's screen.  Developers may also create or modify apps to take advantage of the iPad's features. Application developers use iPhone SDK for developing applications for iPad.

  AUDIO AND OUTPUT
           Dual speakers housed inside the iPad provide mono sound via two small sealed channels in the interior speaker assembly that direct the sound outwards toward the three audio ports carved into the bottom-right of the unit. The microphone is within the device. A volume switch is on the right side of the unit, and a 3.5 mm TRS connector audio-out jack provides stereo sound for headphones on the top-left corner of the device. The iPad supports normal headphones and models with microphones, volume controls, or both. Microphones can be used for voice recording.
The built-in Bluetooth 2.1 + EDR interface supports the HSP, A2DP, and HID profiles, which allow wireless headphones and keyboards to be used with the iPad. However, the iPhone OS does not currently support the OBEX file transfer protocol.
iPad video output over VGA is set to 1024 x 768 using a 720p scan rate.

   SCREEN AND INPUT

The touchscreen is a 25 cm (9.7 in) liquid crystal display (1024 × 768 pixels, 132 ppi, XGA) with fingerprint–resistant and scratch-resistant glass. Like the iPhone, the iPad is designed to be controlled by bare fingers; normal gloves and styli that prevent electrical conductivity may not be used  although there are special gloves and styli designed for this use.
The display responds to two other sensors: an ambient light sensor to adjust screen brightness and a 3-axis accelerometer to sense iPad orientation and switch between portrait and landscape modes. Unlike the iPhone and iPod touch built-in applications, which work in three orientations (portrait, landscape-left and landscape-right), the iPad built-in applications support screen rotation in all four orientations (the three aforementioned ones along with upside-down), ] meaning that the device has no intrinsic "native" orientation; only the position of the home button changes. Most third-party iPad applications also support these four orientations.
The iPad has a switch to lock out this screen rotation function (reportedly to prevent unintended rotation when the user is lying down).  There are a total of four physical switches, including a home button below the display that returns the user to the main menu, and three plastic physical switches on the along with the screen rotation lock.

   CONNECTIVITY

The iPad can use Wi-Fi network trilateration from Skyhook Wireless to provide location information to applications such as Google Maps.  The 3G model contains A-GPS while both models have a digital compass.
The back of the Wi-Fi model iPad is made of contoured aluminum with black plastic buttons. The Wi-Fi + 3G model also has a black plastic accent on top of the device which helps with 3G radio sensitivity.

   POWER AND BATTERY

The iPad uses an internal rechargeable lithium-ion polymer battery. The batteries are made in Taiwan by Simplo Technology, which makes 60% of them, and Dynapack International Technology.  The iPad is designed to be charged with a high current (2 amperes) using the included USB 10 W power adapter. While it can be charged by a standard USB port from a computer, these typically provide lower current (500 milliamperes or 1 ampere). As a result, if the iPad is turned on while being charged with a normal USB computer port, it will charge much more slowly, if at all.
Apple claims that the iPad's battery can provide up to 10 hours of video, 140 hours of audio playback, or one month on standby. The battery loses capacity over time and is not designed to be user-replaceable. As in the battery-replacement program for iPod and the original iPhone, Apple will replace an iPad that does not hold an electrical charge with a refurbished iPad for a fee of US$99.

 STORAGE AND SIM

            The iPad was released with three options for internal storage size: a 16, 32, or 64 GB flash drive. All data are stored on the flash drive and there is no option to expand storage. Apple sells a camera connection kit with an SD card reader, but it can only be used to transfer photos and videos.
The side of the Wi-Fi + 3G model has a micro-SIM slot (not mini-SIM). The 3G model may be used with an AT&T data plan that does not require a contract,  Unlike the iPhone, which is usually sold locked to specific carriers, the 3G iPad is sold unlocked and can be used with any compatible GSM carrier. In the U.S., data network access via T-Mobile's network is limited to slower EDGE cellular speeds because T-Mobile's 3G Network uses different frequencies.

   APPLICATIONS

           Apple developed the iPad with an improved functionality over that of the iPhone and iPod Touch. The iPad comes with several applications such as Safari, Mail, Photos, Video, YouTube, iPod, iTunes, App Store, iBooks, Maps, Notes, Calendar, Contacts, and Spotlight Search.  These applications were borrowed from iPhone’s third generation OS, but improved for the iPad. However, the iPad doesn’t run the iPhone’s 3.1.2 OS and neither the Mac OS X, but an improved version of the third generation iPhone OS, iPhone OS v3.2. Moreover, the iPad will receive the latest iPhone OS, iPhone OS 4 within the fall of 2010.
The iPad syncs with iTunes on a Mac or Windows PC. Apple ported its iWork suite from the Mac to the iPad, deleting several features in the process, and sells the Pages, Numbers, and Keynote apps in the App Store.  Although the iPad is not designed to replace a cellphone, a user can pair it with a Bluetooth headset and place phone calls over Wi-Fi or 3G using a VoIP application.

Ambiophonics




Ambiophonics (not to be confused with Ambisonics) is a method in the public domain that                     employs digital signal processing (DSP) and two loudspeakers directly in front of the listener in order to improve reproduction of stereophonic and 5.1 surround sound for music, movies, and games in home theaters, gaming PCs, workstations, or studio monitoring applications. First implemented using mechanical means in 1986 [1][2], today a number of hardware and VST plug-in makers offer Ambiophonic DSP [3]. Ambiophonics eliminates crosstalk inherent in the conventional “stereo triangle” speaker placement, and thereby generates a speaker-binaural soundfield that emulates headphone-binaural, and creates for the listener improved perception of “reality” of recorded auditory scenes. A second speaker pair can be added in back in order to enable 360° surround sound reproduction. Additional surround speakers may be used for hall ambience, including height, if desired.

Ambiophonics, stereophonics, and human hearing
In stereophonics, the reproduced sound is distorted by crosstalk, where signals from either speaker reach not only the intended ear, but the opposite ear, causing comb filtering that distorts timbre of central voices, and creating false “early reflections” due to the delay of sound reaching the opposite ear. In addition, auditory images are bounded between left (L) and right (R) speakers, usually positioned at ±30° with respect to the listener, thereby including 60°, only 1/6 of the horizontal circle, with the listener at the center. (It should be noted that human hearing can locate sound from directions not only in a 360° circle, but a full sphere.)
Ambiophonics eliminates speaker crosstalk and its deleterious effects. Using ambiophonics, auditory images can extend in theory all the way to the sides, at ±90° left and right and including the front hemi-circle of 180°, depending on listening acoustics and to what degree the recording has captured the interaural level differences (ILD) and the interaural time differences (ITD) that characterize two-eared human hearing. Most existing two channel discs (LPs as well as CDs) include ILD and ITD data that cannot be reproduced by the stereo loudspeaker “triangle” due to inherent crosstalk. When reproduced using ambiophonics, such existing recordings’ true qualities are revealed, with natural solo voices and wider images, up to 150° in practice.
It is also possible to make new recordings using binaurally-based main microphones, such as an ambiophone,[3] which is optimized for Ambiophonic reproduction (stereo-compatible) since it captures and preserves the same ILD and ITD that one would experience with one’s own ears at the recording session. Along with life-like spatial qualities, more correct timbre (tone color) of sounds is preserved. Use of ORTFJecklin Disk, and sphere microphones without pinna (outer ear) can produce similar results. (Note that microphone techniques such as these that are binaural-based but without pinna also produce compatible results using conventional speaker-stereo, 5.1 surround, and mp3 players.)
[edit]Roots & research
Ambiophonics is an amalgam of new research and previously known psychoacoustic principles and binaural technologies. This knowledge has enabled audio recording and reproduction that approaches the realistic soundfield at the ears of the listener that is comparable to what one would perceive in a concert hall, movie scene, or game environment. This level of high-fidelity was not realizable until human hearing and acoustics principles were thoroughly researched, and affordable PCs with sufficient processing speed became available. At the Casa Della Musica at the University of Parma, Italy, or at the listening lab at Filmaker Technology, Pennsylvania USA, ambiophonics, ambisonics, stereophonics, 5.1 2D surround, and hybrid full-sphere 3D systems can be compared for the abilities of these methods to convey the spatiality and tone color of real perception. Developers have provided many scientific papers and downloadable tools for implementing ambiophonics free of charge for personal use.[4]
[edit]Results & limitations
By repositioning speakers closer together, and using digital signal processing (DSP) such as free RACE (Recursive Ambiophonic Crosstalk Elimination) or similar software,[5] ambiophonic reproduction is able to generate wide auditory images from most ordinary CDs/LPs/DVDs or MP3s of music, movies, or games and, depending upon the recording, restore the life-like localization, spatiality, and tone color they have captured. For most test subjects, results are dramatic, suggesting that Ambiophonics has the potential to revitalize interest in high-fidelity sound reproduction, both in stereo and surround.
Additionally, ambiophonics provides for the optional use of concert-hall or other ambience impulse response convolution to generate hall ambience signals for virtually any number and any placement of surround speakers.[6][7] But ambiophonics is not for theaters, auditoriums, or any large groups. Ambiophonics can usually accommodate more than one listener since one can move back and forth along the line bisecting the speakers. Precisely because of the higher level of envelopment along this line, the loss of realism when one moves away from the center line is more dramatic in the case of Ambiophonics than stereo. The listening area can be enlarged with ambience convolution, whereby surround speakers mimic the contributions of concert-hall walls.
Ambiophonics methods can be implemented in ordinary laptops, PCs, soundcards, hi-fi amplifiers, and even modest loudspeakers with consistent phase response, especially in any crossover regions. Neither true-binaural (dummy head with pinna) recordings nor head tracking are required, as with headphone-binaural listening. Commercial products now implement ambiophonics DSP, although tools for use on PCs are also available online.[4]
[edit]Surround sound
In practice in its simplest two-speaker implementation, ambiophonic reproduction unlocks auditory cues for images of up to 150° horizontally (azimuth), depending on the binaural cues captured in existing stereo recordings. Multi-channel recordings made with ambiophone-like microphone arrays to make 5.1-compatible DVD/SACD recordings can be reproduced using just four speakers (a center speaker is obviated in ambiophonic layouts). Allowing for the human hearing “cone of confusion” at each side, a full 360° degree circle of perceived sound localization has been measured within ±5° of actual source azimuth, reproducing life-like spatial envelopment and timbre (contributed by accurate directional provenance of early reflections) of multi-channel music, movies, and game content.[3][8][9]
Especially in the case of stereo content where ambience has been purposely reduced (because a natural level coming from front 60°-only is perceived as too much), additional signals for surround speakers can be produced using a measured hall impulse response, convolved in a PC with the two front channel signals. For full ambiophonic replay, one PC can provide the DSP for 4-channel crosstalk-cancellation and four or more (up to 16 depending on the PC) surround speakers.[10]
The development of ambiophonics is the work of several researchers and companies including Ralph Glasgal, founder of the Ambiophonic Institute; Dr. Angelo Farina, University of Parma; Robin Miller, Filmaker Technology; Waves Audio; Dr. Roger West, Soundlab; Dr. Radomir Bozovic, TacT Audio; and Prof. Edgar Choueiri, Princeton University.

Tuesday, October 11, 2011

Hackers Target Facebook Third Party Applications To Invade Your Online Privacy




Most internet users wouldn't consider their Facebook account to be a real security risk.  For the most part, this is true, as Facebook.com is generally safe in terms of the information it gathers.  However, there's a loophole in Facebook's security that hackers are able to use to potentially access and even alter private information on your profile.
In 2007, Facebook introduced its wildly popular application development program.  This program allows third party developers, both companies and individuals, to create applications.  There are currently just over fourteen thousand Facebook applications including everything from cookbooks to virtual zoos.  While this means there's a diversity of great content available to users, it also means that personal information (which each application has access to) is in a wide variety of hands, and this creates security concerns.
How Applications Access Your Private Information
Every time you choose to add an application, Facebook asks you to confirm that you want to let this program both know who you are and access your information.  It's impossible for anyone to  add any application without agreeing to this set of terms.  Once you click okay, that application can technically access quit a bit of public and private profile information. 
While all of the most private information are kept on Facebook servers and require security authentication, a lot of info is available to applications you add. 
According to Facebook's Developers Terms of Use, this can include
". . . your name, your profile picture, your birthday, your hometown location, your current location, your political views, your activities, your interests, your relationship status, your dating interests, your relationship interests, your summer plans, your Facebook user network affiliations, your education history, your work history, copies of photos in your Facebook Site photo albums, and a list of user IDs mapped to your Facebook friends." 
Not only that, but you don't even have to add an application for it to be able to access your information; they can also learn your info whenever any of your friends add the program.  With all this information available, it's easy to see why many are concerned for their privacy. 
The Threat
For the most part, the danger doesn't come from the application developers themselves, but from hackers who may be able to infiltrate and misuse information collected by applications, especially those written by individual developers instead of companies.    2600, a hacker periodical, published an article detailing how to easily compromise three Facebook apps:  Moods, Superwall and Free Gifts.  These loopholes discussed only allow for minor security breaches, nothing really malicious.  For instance, hackers can change the sender and recipient of Superwall posts and free gifts.  There's even a Youtube video of someone changing another user's mood. Clearly, this is not a top level security threat, yet.  If a loophole exists, though, malicious minds can find a way to exploit it, and it's possible that a serious security risk is en route. 
It's important to note that the problem isn't with Facebook, or even with Applications in general, but with certain applications which don't use safe data practices.  The three applications mentioned earlier are exploitable because they use easily modifiable form sheets to collect data.  Other applications, and all the content published by Facebook itself are safe from hackers.  The real difficulty comes in trying to decipher which applications are safe, and how to make sure that you're not at risk.
What to Do
It's hard to find good solutions to the threat posed by Facebook third party applications.   The first thing to do is to make sure that you don't sign up for applications of questionable background.  Each program developer has a profile on Facebook that you can view to gain information about who they are and how to contact them.  This is the best way to find out what, if any, security protocols they use.  Pick applications that are made by reputable developers, and don't add every application that you're invited to.  Also, be judicious about who you add as a friend.  Remember that applications can access your information if any one of your friends signs up.   The more friends you have, the more applications that have access to your data, and the greater the potential of it falling into the wrong hands. 
Many people feel that the best way to ensure privacy is from the top up.  After all, the most certain way to close hacker back doors is for Facebook to take charge, or hold applications to more stringent security requirements.  At present, Facebook's terms of service clearly state that they are not responsible for the actions of third party developers.  Many users are voicing their concern over this policy, and its ramifications for information security, both to Facebook and the applications that they use.
If you think that you have been the victim of "apps hacking," then you should contact both Facebook and the application developer immediately, to alert them to this potential security flaw.  It's also probably a good idea to avoid that application, and others by the same publisher, as they may pose a continued security risk to your online privacy.
While hackers might be able to access some personal information through Facebook third party applications, being vigilant is the key to staying safe on the internet.
 

Emi Crops This Blog is Designed by SAN Bro's
Nufail IK
, Sahad NK and Adil Shereef
Thanks to DASH | © 2011