Sunday, 25 March 2012

Virus Dissemination

VIRUS DISSEMINATION

In today's world where everyone is attached with the tools and applications of the modern era, where the technology facilitates every persons in all aspects throughout the world in different manners according to their goals and objectives. In the process to facilitate the people in this era Internet and Network Technologies plays a great role the main role of this is it combines and connects people in a couple of seconds no matter how far they are physically.

Internet facilitates peoples in Business, Banking, Education, Medical, Bio-Medical Technologies, Security Personnel, Government bodies etc etc. so in this global mess there are several kinds of risks involved. This main risk and threat is on information sharing and UN-authorize access of the information, Simply called Hacking.

There are three types of Hackers White Hat hackers, Greay Hat hackers and Black Hat hackers in this post i.e. related to Virus Dissemination we are talking about Black Hat Hackers.


BLACK HAT HACKERS:

Black Hat Hackers are the persons also know as "Intruders" who hackes the information that is not for them simply the stole the information and compromises the computer systems by using various kinds of tools and techniques. This is not an issue that we start talking here about the tolls and techniques they are using to hack the information simply want to say that "If you think that you have a safe lock where you keep the important things safely, then there is a key you have to access the safe after locking it". It's just like if there is a lock then there should a key to open it if there is no key then there is no safe or secure mechanism to call a safe, lock or anything else.

Virus Dissemination is a process of a Malicious software that attaches itself to other software. (virus, worms, Trojan Horse, Time bomb, Logic Bomb, Rabbit and Bacterium are examples of malicious software that destroys the system of the victim.

Several Trojan-generator tools enable hackers to create their own Trojans. Such toolkits help hackers construct Trojans that can be customized. These tools can be dangerous and can backfire if not executed properly. New Trojans created by hackers usually have the added benefit of passing undetected through virus-scanning and Trojan-scanning tools because they don’t match any known signatures. Some of the Trojan kits available in the wild are Senna Spy Generator, the Trojan Horse Construction Kit v2.0, Progenic Mail Trojan Construction Kit, and Pandora’s Box.

Viruses and worms can be used to infect a system and modify a system to allow a hacker to gain access. Many viruses and worms carry Trojans and backdoors. In this way, a virus or worm is a carrier and allows malicious code such as Trojans and backdoors to be transferred from system to system much in the way that contact between people allows germs to spread.

A virus and a worm are similar in that they’re both forms of malicious software (malware). A virus infects another executable and uses this carrier program to spread itself. The virus code is injected into the previously benign program and is spread when the program is run. Examples of virus carrier programs are macros, games, email attachments, Visual Basic scripts, and animations. A worm is similar to a virus in many ways but does not need a carrier program. A orm can self-replicate and move from infected host to another host. A worm spreads from system to system automatically, but a virus needs another program in order to spread.
 
Viruses and worms both execute without the knowledge or desire of the end user.
 
Types of Viruses
 
Viruses are classified according to two factors: what they infect and how they infect. A virus can infect the following components of a system:
i) System sectors
ii) Files
iii) Macros (such as Microsoft Word macros)
iv) Companion files (supporting system files like DLL and INI files)
v) Disk clusters
vi) Batch files (BAT files)
vii) Source code
 
A virus infects through interaction with an outside system. Viruses need to be carried by another executable program. By attaching itself to the benign executable a virus can spread fairly quickly as users or the system runs the executable. Viruses are categorized according to their infection technique, as follows:

Polymorphic Viruses These viruses encrypt the code in a different way with each infection and can change to different forms to try to evade detection.
 
Stealth Viruses These viruses hide the normal virus characteristics, such as modifying the original time and date stamp of the file so as to prevent the virus from being noticed as a new file on the system.
 
Fast and Slow Infectors These viruses can evade detection by infecting very quickly or very slowly. This can sometimes allow the program to infect a system without detection by an antivirus program.
 
Sparse Infectors These viruses infect only a few systems or applications.
 
Armored Viruses These viruses are encrypted to prevent detection.
 
Multipartite Viruses These advanced viruses create multiple infections.
 
Cavity (Space-Filler) Viruses These viruses attach to empty areas of files.
 
Tunneling Viruses These viruses are sent via a different protocol or encrypted to prevent detection or allow it to pass through a firewall.
 
Camouflage Viruses These viruses appear to be another program.
 
NTFS and Active Directory Viruses These viruses specifically attack the NT file system or Active Directory on Windows systems.

Note: This information is purely for educational purpose not for any experimental or destructive purpose or to effect any organization, government and any other person. So please kindly do not use it in un ethical manner. Rest you will find yourself in trouble.

References: All the references taken from my C|EH (Certified Ethical Hacker) book. I am glad to share the little knowledge with those people who really want to learn and serve in proper and ethical manner.

"I would like to pay my regards to my esteemed professor Mr. Muhammad Ayaz Ghazi & my friend Mr. Adnan Fayyaz for their unconditional efforts and attention regarding my studies specially in Network Security and the Specialized Server side."

 Thanks & Best Regards,
--
Syed Muhammad Ahmed
ahmedccna110@gmail.com
 
  

Monday, 19 March 2012

How communication effects in Business.

Well this sounds is really good because as the title describe itself it's completely about communication. First thing before starting the formal posting I want to tell you is that let's imagine that you invited someone to meet up and discuss your problem and issues with him or her what you will do.

i- Treat him/her in good manner.
ii- Communicate with him/her wisely and gently.
iii- Tell him/her about your ongoing issues.
iv- Give him/her the complete information regarding your ensuing matter.
v- Tell all these things in short and complete manner. (no repetitions).

Alright If it is & you will do the same then I must say you are right. now compare these things in business terminology what exactly it is. It is a professional conversation no matter about meeting, about product, about campaign, about solutions, about technical aspects or anything like that. 

Yes Now come to the main part of this post the purpose to tell you the above-things are just to prepare your mind about what communication is. In business communication plays a role of "Backbone" or you call it a Spinal Cord of business. If you did not satisfy your customer you will no more able to get the contract ask for the service and these things will come after many things first I would like to mention in this post that you will miss the chance to interact with the customer or the client or the party next time. It is a big loss for you and your business as well.

That why in Business we follow some rules and regulation for the communication that is know as "7c's of Business Communication". Below it is described in detail what is this along-with the details.

The message is said to be effective when the receiver understands the same meaning that the sender was intended to convey. For any communication in business, in order to be effective, it must have seven qualities. These seven attributes are called seven C’s of effective business communication. (All these attribute starts with the alphabet ‘C’ so are called 7 C’s)

Seven C’s of Effective Business Communication

  1. Correctness
  2. Clarity
  3. Conciseness
  4. Completeness
  5. Consideration
  6. Concreteness
  7. Courtesy
  1. Correctness

    At the time of encoding, if the encoder has comprehensive knowledge about the decoder of message, it makes the communication an ease. The encoder should know the status, knowledge and educational background of the decoder. Correctness means:
    • Use the right level of language
    • Correct use of grammar, spelling and punctuation
    • Accuracy in stating facts and figures
    Correctness in message helps in building confidence.
  2. Clarity

    Clarity demands the use of simple language and easy sentence structure in composing the message. When there is clarity in presenting ideas, it’s easy for the receiver/decoder to grasp the meaning being conveyed by the sender/encoder.
    Clarity makes comprehension easier.
  3. Conciseness

    A concise message saves time of both the sender and the receiver. Conciseness, in a business message, can be achieved by avoiding wordy expressions and repetition. Using brief and to the point sentences, including relevant material makes the message concise. Achieving conciseness does not mean to loose completeness of message.
    Conciseness saves time.
  4. Completeness

    By completeness means the message must bear all the necessary information to bring the response you desire. The sender should answer all the questions and with facts and figures. and when desirable, go for extra details.
    Completeness brings the desired response.
  5. Consideration

    Consideration demands to put oneself in the place of receiver while composing a message. It refers to the use of You attitude, emphases positive pleasant facts, visualizing reader’s problems, desires, emotions and his response.
    Consideration means understanding of human nature.
  6. Concreteness

    Being definite, vivid and specific rather than vague, obscure and general leads to concreteness of the message. Facts and figures being presented in the message should be specif.
    Concreteness reinforces confidence.
  7. Courtesy

    In business, almost everything starts and ends in courtesy. Courtesy means not only thinking about receiver but also valuing his feelings. Much can be achieved by using polite words and gestures, being appreciative, thoughtful, tactful, and showing respect to the receiver. Courtesy builds goodwill.


    I hope that you will enjoy reading the post and find it informative and valuable. I would like to thank GOD for the blessings my devoted Father Syed Mansoor Hussain Kazmi for his ultimate support and bid contribution in my studies my esteemed teachers specially Mr. Ayaz Ghazi. I learned alot from all of them and last but not the least Prof who taught me the Business Communication course he is one of the greatest teacher I meet in my life. Thanks from the bottom of my heart.

    Ref:  http://notesdesk.com/notes/business-communications/the-seven-cs-of-effective-business-communication/

Monday, 7 November 2011

Introduction & some important concepts



HUMAN COMPUTER INTERACTION






 

CONCEPT OF TASK ANALYSIS

Task: A task is a goal having some specific order of actions to achieve some goal and if we talk about the task analysis it is simply the method to analyze the people jobs that what are they doing why are they doing and what is the result if against their actions.
Simply in task analysis we have to analyze people or some agents that perform some work on a specific domain or application of their work system in order to obtain or achieve their goal.

HIERARCHICAL TASK ANALYSIS

The above stated diagram shows the concept of HTA i.e. hierarchical task analysis it is the concept in which we study the entire system of actions more closely how it performs action to accomplish the different task in order to achieve the goal more in this analysis we study the about what the task requirement is the environment of the task and the behavior.

GOMS

The abbreviation of GOMS is Goal Operated Method of Selecting Roles where goal is what the user wants to achieve from a system or the operation they do perform and the method is about to split your goal or task into sub goals that helps to determine the things more closely “what to do” and “How to do it” and the selection of the methods at the best of his level according to accomplish the task more effectively and accurately.
NEED OF GOMS
Well as defined above in the definition of goms we have to follow goms rules for an interactive design of an application and to provide complete feedback for the users who have some issues regarding the application or the interface we design this goms methods solve to many problems like if there is an application or a software that records inventory and it’s a complete financial application so the user have to know that where should they start using it and how to record the inventory and other financial transaction that creates right effect to the company financial statement then we provide it some guideline no manner that it would base upon interactive video or just a help file.

WATERFALL MODEL

The waterfall model that is in the Design process describes the waterfall model is a sequential design process, often used in software development processes, in which progress is seen as flowing steadily downwards (like a waterfall) through the phases of Conception, Initiation, Analysis, Design, Construction, Testing, Production Implementation and Maintenance.
This model describe very important things that includes the need of the system you are going to design, How the system in going to help or assist the users which you are going to design, some detailed design and usability references, then we have to test the each unit of the software because sometime the software we are going to design is performing the task in different chunks of information so we have to test each of the unit, Integration and testing in which we add some help guidelines and then error handling of the software.

INTERACTIVE SYSTEM LIFECYCLE

The only difference of Waterfall model and Interactive system life cycle is we cannot assume the linear system feedback in the interactive system lifecycle there is a lot of feedback in this system cycle that’s why this design is different from the tradition interactive system lifecycle.
USAGE:
We can use this design model when we are designing any application or computerized system for any organization I think that this will help and assist the designer a lot to understand the organizational task and the behavior of the agents that are performing several different task to achieve the goal.

STAKEHOLDERS

Stakeholders are the persons who are related to the systems success or the failure of the system the system will have many stakeholders of different types.
                                                         i.            Primary
                                                        ii.            Secondary
                                                      iii.            Tertiary
                                                      iv.            Facilitating

SOFTWARE GUIDELINES

There are the few screenshots of the software that is Intuit Quickbooks used for record keeping and financial record keeping in organizations.

USABILITY CONCEPT

The term usability determines that how any product can be used by the users that are using this product in order to achieve some specific goals.
Here we talk about the Mobile phone so the purpose of mobile phone is to make calls and send text messages nothing except this so the main usability of the mobile phone is to make calls and sending the text messages this is the prior goal of this product. Now we come into the properties of the usability of the mobile phone i.e. a product that is a mobile a user who uses and experience the mobile phone for making calls and text messages, the task and the set of task that is similar which is defined above and the goal this is making a calls. The next thing is the criteria of usability may change or subject to change according to time and requirement for instance in late times we only have cell phone that did only task as prescribed above but now these phones turned to be an smartphone like sending mails and using the office applications as well.

PRINCIPALS OF USABILITY

There are three principals of usability that are learnability the ease of using the system and achieve the maximum from it this principal applied to the Mobile phone then the ease of using the system is that the user can easily dial numbers and the numbers are arranged in such manner that user can easily dialed it and recognize the digit printed on it as well as the character print on it that helps user to learn more quickly and also makes the product more interactive and the users are going to enjoy the usage of the product and likes such product , the second principal is Flexibility that refers how much the product is capable to perform same task in different manner like in mobile users not only communicate through voice, text now they can also communicate through variety of things like video, emails, blogs and some other social applications like facebook, twiter and msn.
The last one is Robustness that refers to the support that provides users a direction to achieve the goal or to assist them this is also available in the mobile phones now and getting more enhance day by day.

Sunday, 17 July 2011

Web Application Vulnerability Scanners

Web Application Vulnerability Scanners are tools designed to automatically scan web applications for potential vulnerabilities. These tools differ from general vulnerability assessment tools in that they do not perform a broad range of checks on a myriad of software and hardware. Instead, they perform other checks, such as potential field manipulation and cookie poisoning, which allows a more focused assessment of web applications by exposing vulnerabilities of which standard VA tools are unaware.
A Web Application Scanner Tool Functional Specification is available.

Contents

[hide]

Web Applications Issues

  • Scripting issues
  • Sources of input: forms, text boxes, dialog windows, etc.
  • Multiple Charset Encodings (UTF-8, ISO-8859-15, UTF-7, etc.)
  • Regular expression checks
  • Header integrity (e.g. Multiple HTTP Content Length, HTTP Response Splitting)
  • Session handling/fixation
  • Cookies
  • Framework vulnerabilities(Java Server Pages, .NET, Ruby On Rails, Django, etc.)
  • Success control: front door, back door vulnerability assessment
  • Penetration attempts versus failures

Technical vulnerabilities

  • Unvalidated input:
    • Tainted parameters - Parameters users in URLs, HTTP headers, and forms are often used to control and validate access to sentitive information.
    • Tainted data
  • Cross-Site Scripting flaws:
    • XSS takes advantage of a vulnerable web site to attack clients who visit that web site. The most frequent goal is to steal the credentials of users who visit the site.
  • Content Injection flaws:
    • Data injection
    • SQL injection - SQL injection allows commands to be executed directly against the database, allowing disclosure and modification of data in the database
    • XPath injection - XPath injection allows attacker to manipulate the data in the XML database
    • Command injection - OS and platform commands can often be used to give attackers access to data and escalate privileges on backend servers.
    • Process injection
  • Cross-site Request Forgeries

Security Vulnerabilities

  • Denial of Service
  • Broken access control
  • Path manipulation
  • Broken session management (synchronization timing problems)
  • Weak cryptographic functions, Non salt hash

Architectural/Logical Vulnerabilities

  • Information leakage
  • Insufficient authentification
  • Password change form disclosing detailed errors
  • Session-idle deconstruction not consistent with policies
  • Spend deposit before deposit funds are validated

Other vulnerabilities

  • Debug mode
  • Thread Safety
  • Hidden Form Field Manipulation
  • Weak Session Cookies: Cookies are often used to transit sensitive credentials, and are often easily modified to escalate access or assume another user's identify.
  • Fail Open Authentication
  • Dangers of HTML Comments

Related Links

Tuesday, 31 May 2011

Updating and Installing Nessus on BackTrack 5

One of my favorite tools in my toolbox is the Vulnerability Scanner Nessus, in part because of it’s accuracy and because I’m part of one of the teams that works adding new cool stuff to it during the day. So I was super happy to see it included as part of Backtrack. Ever since I started working professionally in security Nessus has been part of my toolkit, once nessuscmd was out it became more integral in to my workflow because I could automate stuff for my customers. Before I had to always follow some weird procedures some times to get Nessus installed on the early versions of Backtrack and those procedures where always prone to breaking when I had to update to a latest version. I would like to share how to activate your copy of Nessus in Backtrack and some of the caveats that are present when activating it depending of your setup. The first step is to have Bactrack installed as a virtual machine on your pentest/audit rig or installed locally on the hard drive of the machine. Do not try to activate by running it from the bootable DVD or from a USB Drive if you intend of using it on several physical machines because the registration process marries the activation to that specific host. So moving the VM from one host to another or the USB drive depending on how you configured Backtrack is more than likely to require re-activation of your copy of Nessus. So one of the first thing you need to do if using a professional feed go to http://support.tenable.com and log in and go in to Manage Activation Codes and get your professional feed activation code. If you will be using a Home Feed you will have to go to http://www.nessus.org/products/nessus/nessus-plugins/obtain-an-activation-code and register for a Home Feed, you will receive your activation code to the email you provided. Once you have the activation code you can proceed to activate it on your Backtrack Machine running as root: 

root@bt:~# /opt/nessus/bin/nessus-fetch --register M4D0-EWWQ-1EZU-3KSN
Your activation code has been registered properly - thank you.
Now fetching the newest plugin set from plugins.nessus.org...
Your Nessus installation is now up-to-date.
If auto_update is set to 'yes' in nessusd.conf, Nessus will
update the plugins by itself.
And yes the activation code in the example if a fake one for demonstration purposes only.
The next step is to add an admin user on this box so it can connect, create profiles, policies and launch scans:"
root@bt:~# /opt/nessus/sbin/nessus-adduser
Login : carlos
Login password : 
Login password (again) : 
Do you want this user to be a Nessus 'admin' user ? (can upload plugins, etc...) (y/n) [n]: y
User rules
----------
nessusd has a rules system which allows you to restrict the hosts
that carlos has the right to test. For instance, you may want
him to be able to scan his own host only.
Please see the nessus-adduser manual for the rules syntax
Enter the rules for this user, and enter a BLANK LINE once you are done : 
(the user can have an empty rules set)
Login             : carlos
Password         : ***********
This user will have 'admin' privileges within the Nessus server
Rules             :
Is that ok ? (y/n) [y] 
User added