BackBox Linux 2.01 (Penetration Testing Distribution) Released


Earlier we have talked about BackBox Linux. Now a days it has became a very common penetration testing distribution. Now we have version 2.01 of BackBox Linux. 

Brief About BackBox :-
BackBox is a Linux distribution based on Ubuntu. It has been developed to perform penetration tests and security assessments. Designed to be fast, easy to use and provide a minimal yet complete desktop environment, thanks to its own software repositories, always being updated to the latest stable version of the most used and best known ethical hacking tools. The new release include features such as Ubuntu 11.04, Linux Kernel 2.6.38 and Xfce 4.8.0.

What's New In This Release:-
  • System upgrade
  • Performance boost
  • New look
  • Improved start menu
  • Bug corrections
  • New sections such as Forensic Analysis, Documentation & Reporting and Reverse Engineering
  • New Hacking tools and updated tools such as dradis 2.8, ettercap 0.7.4.2, john 1.7.8, metasploit 4.2, nmap 5.51, set 2.5.2, sleuthkit 3.2.1, w3af 1.0, weevely 0.5, wireshark 1.6.3, etc.

To Download BackBox Click Here



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Japan Developing ‘seek and destroy’ Virus To Combat Cyber Attacks



The Japanese Ministry of Defence is in the process of creating software which will enable it to observe cyber attacks and defend against them. According to sources the three-year $2.3 million project was outsourced to Japanese technology firm named Fujitsu. It said that best is a good offence so Fujitsu is developing a ‘seek and destroy’ virus for the Japanese government, one that it hopes will identify and combat cyber attacks. Already U.S. and China have put similar countermeasures in place. Japan has faced a tough time in online security in the recent past, with numerous cyber attacks in 2011 that crippled everything from local government portals, to the parliament, Biggest Defense Contractor Mitsubishi and so on. 
$2.3 million project is still ongoing, and for now, the virus is still in closed environment testing stages. Relevantly, the country would have to make amendments to its laws to allow for the manufacture of the ethical virus, with all virus development still an illegal activity.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Philippine Govt Sites Hacked By PrivateX (#OpSecure)


A hacker group named PrivateX launched massive cyber attack on the very 1st day of 2012 & temporarily shut down several Philippine government websites including the office of the vice-president. This group has also hacked into the Philippine Nuclear Research Institute website and redirect the users to Pastehtml.com and and called for intensified information security in the country.
Vice President Jejomar Binay said hackers calling themselves the PrivateX group brought down his official website for 15 hours Sunday and denied access to mostly migrant Filipinos checking on his office's activities.
Though PrivateX assured that "nothing was lost during the process of this defacement."



Message Of The Hacker On The Deface Page:-
"Greetings World, Happy New Year!
Months had passed when we first wired our sentiments and growing passion of concern to intensify the Information Security here in the Philippines. Occupants of the west are still on the move and in no such time, Manila, will be the center of unethical activities in Asia. For some reasons that is untold, they choose the Philippines to organize a legion
that will nullify the entire Philippine Cyberspace. This is what we are afraid of.
The medium of our emphasis in calling out the government's action toward cyber security, and our actions in which this defacement is performed. A change in our society pointing out the role to authorize each and every Filipino citizen through education that is recognizable by its function to contrive in the economy and innovating more concepts in Information Security.
We lay our hands on the fight against corruption and the call of the #InfoSec. In as much as we offer our wants to oversee every Filipino people have their knowledge to produce and live productively in which the people become other than themselves, and others may discover the Philippines that contain potentials other than it appears.
This is a Note of Understanding from the crew and its assurance that nothing was lost during the process of this defacement.


We are Anonymous, 
We are legion, We don't forgive, 
We don't forget, United as one, Divided by zero,
Expect us."







SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

European Union (EU) Requested CBI To Join Cyber Security Project Worth $52.5 Billion



European Union (EU) has invited India to participate in a mega cyber security and cyber crime project worth 52.5 billion dollar (Rs 3.62 lakh crore) to secure economic and security interests of various countries globally. 
India has been asked to join a select group of nations to be involved in this research and information technology driven innovation project. Apart from US, Brazil and South Africa are other partners of EU in this project that will be kicked off shortly. The project that has counter-terrorism as a key component is likely to be part of a separate pact that EU and India will sign early next month at the twelfth summit between two sides.
As per the proposed pact, India and EU apart from other members would jointly fund as well as research on cyber crime and cyber security issues across the world. 
The project is intended to develop protocols and systems for preventing terror attacks physically and on information highway, an external affairs ministry official told Financial Chronicle on condition of anonymity. This massive project to be implemented over next eight years include securing electrical power systems by identifying the vulnerability, put in place defence systems and restoration in case of disruption. The project will also lead to protection of critical defence and civilian economic infrastructure from cyber attacks.
Risk prediction, analysis and reaction to critical infrastructure, is also expected to be put in place through this project. Private, public sector companies and government agencies would be involved in this project. Two rounds of consultation have already been completed between both India and EU on concluding the cyber crime and cyber security pact in February 2012. India and European Union will explore cooperation between CBI and EU’s home department for training on tackling cyber crime, establish single point of contact and also do joint research in the mega innovation project.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

WiFi Protected Setup Is Vulnerable, Reaver Can Find-out The WPA Passphrase


                                                (Image Source- theprojectxblog)

Austrian information security student and researcher Stefan Viehböck released details of a vulnerability in the WiFi Protected Setup (WPS) standard that enables attackers to recover the router PIN, a security firm has published an open-source tool capable of exploiting the vulnerability. The tool, known as Reaver, has the ability to find the WPS PIN on a given router and then recover the WPA passphrase for the router, as well.

Brief Overview & Description:-
Reaver performs a brute force attack against an access point's WiFi Protected Setup pin number. Once the WPS pin is found, the WPA PSK can be recovered and alternately the AP's wireless settings can be reconfigured. While Reaver does not support reconfiguring the AP, this can be accomplished with wpa_supplicant once the WPS pin is known. 
Reaver targets the external registrar functionality mandated by the WiFi Protected Setup specification. Access points will provide authenticated registrars with their current wireless configuration (including the WPA PSK), and also accept a new configuration from the registrar. In order to authenticate as a registrar, the registrar must prove its knowledge of the AP's 8-digit pin number. Registrars may authenticate themselves to an AP at any time without any user interaction. Because the WPS protocol is conducted over EAP, the registrar need only be associated with the AP and does not need any prior knowledge of the wireless encryption or configuration. Reaver performs a brute force attack against the AP, attempting every possible combination in order to guess the AP's 8 digit pin number. Since the pin numbers are all numeric, there are 10^8 (100,000,000) possible values for any given pin number. However, because the last digit of the pin is a checksum value which can be calculated based on the previous 7 digits, that key space is reduced to 10^7 (10,000,000) possible values. 
The key space is reduced even further due to the fact that the WPS authentication protocol cuts the pin in half and validates each half individually. That means that there are 10^4 (10,000) possible values for the first half of the pin and 10^3 (1,000) possible values for the second half of the pin, with the last digit of the pin being a checksum.  Reaver brute forces the first half of the pin and then the second half of the pin, meaning that the entire key space for the WPS pin number can be exhausted in 11,000 attempts. The speed at which Reaver can test pin numbers is entirely limited by the speed at which the AP can process WPS requests. Some APs are fast enough that one pin can be tested every second; others are slower and only allow one pin every ten seconds. Statistically, it will only take half of that time in order to guess the correct pin number. 

For more information and to see the research paper by Stefan Click Here

To Download Reaver Click Here



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Now You Have To Pay $1,000 If You Caught In Cyber-Bullying


New York Assemblywoman Jane Corwin has announced that she has authored and will introduce legislation to create the crime of cyber-bullying in the state of New York. This follows no the heels of the suicide of 14-year-old Jamey Rodemeyer after years of being bullied, including cyber-bullied.

Specifically, the bill creates the crime of cyber-bullying as a misdemeanor punishable by a fine of up to $1,000 and/or up to one year imprisonment. Furthermore, the legislation defines cyber-bullying as any repeated acts of abusive behavior communicating or causing communication to be sent by mechanical or electronic means, including posting statements on the Internet, or sending messages through a computer network. Such abusive behavior includes messages that are taunting, threatening, intimidating, insulting, tormenting, humiliating, embarrassing or sexually explicit, as well as other forms of hate mail.

Corwin stated that “Bullying is a long-standing problem among school-aged children in New York State, and throughout the nation. With the increasing accessibility of electronic means of communication, bullying has transformed from a predominantly school-based issue to a broader societal problem. Jamey’s story shocked our community – and other small communities across the nation – to its very core, and we cannot allow cyber-bullying to continue without penalty. We must take a firm stand against this destructive and devastating behavior.”

Roughly 28% of students between the ages of 12 and 18 have reported bullying; however, when it comes to cyber-bullying, that number is closer to 42% with 35% of students being threatened online.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Web Application Vulnerability Scanner


Wavsep, the Web Application Vulnerability Scanner Evaluation Project is a vulnerable web application designed to help assessing the features, quality and accuracy of web application vulnerability scanners. This evaluation platform contains a collection of unique vulnerable web pages that can be used to test the various properties of web application scanners. 
This version is now integrated with ZAP-WAVE and a *database schema installer* and has been implemented using JEE, mostly composed out of JSP pages. 16 new test cases and passive exposures such as: information disclosure, antiCSRF tokens, secret vectors, insert statements, etc. have been added! Wavsep has been tested on tomcat 6.0.x, alongside MySQL 5.5.x and has been developed using Eclipse 3.6.x (*helios*).

To Download wavsep Click Here





SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...