SSLSmart is a highly flexible and interactive tool aimed at improving efficiency and reducing the false positives during SSL testing. Among other things, SSLSmart simply an advanced and highly flexible Ruby based smart SSL cipher enumeration tool. It is an open source, cross platform, free tool. It was programmed because a number of tools on the Windows platform allow users to test for supported SSL ciphers suites, but most only provide testers with a fixed set of cipher suites. Further testing is performed by initiating an SSL socket connection with one cipher suite at a time, an inefficient approach that leads to false positives and often does not provide a clear picture of the true vulnerability of the server. SSLSmart is designed to combat these shortcomings.
Features:-
Content Scan (default): Exact server response can be seen in HTML and Text forms for each cipher suite selected for the test URL. Basically, it shows various server error messages received for weak cipher suites from live systems.
CONNECT Scan: Focuses only on success or failure of SSL socket connection with various cipher suites. This behavior does not offer any advantage over existing SSL testing tools and is thus likely to have similar issues with false positives. However, this scan is faster and consumes fewer network and CPU resources.
Dynamic Cipher Suite Support: Most SSL testing tools provide a fixed set of cipher suites. SSLSmart hooks into Ruby OpenSSL bindings and offers dynamic “on the fly” cipher suite generation capabilities.
Certificate Verification: SSLSmart performs server certificate verification. It uses the Firefox Root CA Certificate4 repository to perform Root CA verification. Additional Root CA Certificates can be added to the rootcerts.pem file or a custom .pem file can be supplied for Root CA Certificate verification.
Proxy Support: SSLSmart provides web proxy support. For results to be accurate, it is important to use a transparent proxy5.
Reporting: Reports can be generated in XML, HTML and Text formats along with their verbose versions. Verbose report versions include complete application response for each cipher suite and full details of the server certificate.
API’s: Monkey patched Ruby API’s that form the backbone of SSLSmart can be consumed to write custom Ruby scripts for quick tests. These API’s can be consumed by users who work with the SSLSmart gem.
Supported Platforms:-
SSLSmart has been tested to work on the following platforms and versions of Ruby:
Windows: Ruby 1.8.6 with wxruby6 (2.0.0) and builder7 (2.1.2).
Linux: Ruby 1.8.7/1.9.1 with wxruby (2.0.0) and builder (2.1.2).
TeamViewer 7 for Windows was released about a month ago now the Ver 7 is available for Linux though its a beta release. TeamViewer is an application for remote control, desktop sharing and file transfer between computers, great for meetings, presentations, support and more. It runs on Windows, Mac OSX, Linux (even though it comes in a .deb or .rpm, it uses Wine which comes bundled with it) as well as Android or iPhone. The application is free for personal use only.
What is New In TeamViewer 7 :-
Enhanced multi-monitor support
An integrated screenshot tool
Record presentations
Save connection settings per Computer (store individual connection settings for each computer in your Computers & Contacts list) - see the first screenshot in the post
Instant meeting (you can start your meeting even before adding any participants - ideal for preparation and testing)
Scheduled meetings
Mobile participation via Android / iOS client
File Box (make files available for download during meeting)
Highly critical Zero-day vulnerability found in Windows 7. This security flaws can be exploited via Apple Safari browser. This was first made public via a twitter user named w3bd3vil
"<iframe height='18082563'></iframe> causes a BSoD [blue screen of death] on win 7 x64 via Safari. Lol!"
It is reported that vulnerability affects fully patched Windows 7 Professional 64-bit and cautioned that other versions may be affected. The remotely exploitable vulnerability, caused by an error in win32k.sys, enables a hacker to run arbitrary code -- such as malware -- on a victim's machine when he or she visits a specially crafted Web page using Safari. Specifically, the Web page would simply need to contain an iFrame -- an HTML element that is typically used to pull content from other sources onto a Web page -- with an overly large "height" attribute.
The experience of signing in to your PC with touch has traditionally been a cumbersome one. In a world with increasingly strict password requirements—with numbers, symbols, and capitalization—it can take upwards of 30 seconds to enter a long, complex password on a touch keyboard. To get rid of all these stuffs Microsoft is introducing a new technology. Using that you can login ti your Windows 8 PC with a picture password. Likely designed for touchscreens, users are prompted with a familiar picture of their choice and asked to make a series of finger gestures on the screen to setup password protection. Microsoft recommends that users pick at least three gestures and can choose between a circle, a tap and a line drawn between two points. When a user logs into a Windows 8 machine using Picture Password, they simply have to replicate the correct placement, order and direction of all gestures.
Microsoft dictates the set of three different gestures after research showed that login time was cut from 17 seconds using free form gestures to 4 seconds using preset gestures. Users don’t have to be 100 percent accurate with the placement of the gestures as the image is broken up into a grid and the combination of replicating the three gestures is assigned a percentage score each time the login process is attempted through an algorithm. If the score is 90 percent or above, the user gains access to the system. Microsoft also outlined how security is increased with the Picture Password method. For instance, if a user creates a six-character text password with at least one uppercase letter and one number, there would be 7 billion combinations available. However, if a user creates a picture password with six gestures using only taps, that number increases to 1.3 trillion combinations. Even further, reducing the amount of gestures to five and including at least one circle and one line gesture within the group increases the number of combinations to approximately 70 trillion. The Windows engineering team has just started building the Picture Password functionality and hopes to include it within the final version of Windows 8 likely released during 2012.
You can find more information about this article on the Windows 8 Developer Blog
Zero day vulnerability in Adobe Acrobat Reader has been fixed. There have been reports of two critical vulnerabilities being actively exploited in limited, targeted attacks in the wild against Adobe Reader 9.x on Windows. These vulnerabilities (CVE-2011-2462, referenced in Security Advisory APSA11-04, and CVE-2011-4369) could cause a crash and potentially allow an attacker to take control of the affected system.
While these vulnerabilities exist in Adobe Reader X (10.1.1) and earlier versions for Windows and Macintosh, Adobe Reader 9.4.6 and earlier 9.x versions for UNIX, and Adobe Acrobat X (10.1.1) and earlier versions for Windows and Macintosh, there is no immediate risk to users of Adobe Reader and Acrobat X for Windows (with Protected Mode/Protected View enabled), Adobe Reader and Acrobat X or earlier versions for Macintosh, and Adobe Reader 9.x for UNIX based on the current exploits and historical attack patterns.
Adobe recommends users of Adobe Acrobat 9.4.6 and earlier 9.x versions for Windows update to Adobe Acrobat 9.4.7. Because Adobe Reader X Protected Mode and Adobe Acrobat X Protected View would prevent an exploit of the type currently targeting these vulnerabilities (CVE-2011-2462 and CVE-2011-4369) from executing, we are planning to address these issues in Adobe Reader and Acrobat X for Windows with the next quarterly security update for Adobe Reader and Acrobat, scheduled for January 10, 2012. We are planning to address these issues in Adobe Reader and Acrobat X and earlier versions for Macintosh as part of the next quarterly update scheduled for January 10, 2012. An update to address these issues in Adobe Reader 9.x for UNIX is planned for January 10, 2012.
Tor 0.2.3.9-alpha introduces initial IPv6 support for bridges, adds a "DisableNetwork" security feature that bundles can use to avoid touching the network until bridges are configured, moves forward on the pluggable transport design, fixes a flaw in the hidden service design that unnecessarily prevented clients with wrong clocks from reaching hidden services, and fixes a wide variety of other issues.
Features:-
Clients can now connect to private bridges over IPv6. Bridges still need at least one IPv4 address in order to connect to other relays. Note that we don't yet handle the case where the user has two bridge lines for the same bridge (one IPv4, one IPv6). Implements parts of proposal 186.
New "DisableNetwork" config option to prevent Tor from launching any connections or accepting any connections except on a control port.
Bundles and controllers can set this option before letting Tor talk to the rest of the network, for example to prevent any connections to a non-bridge address. Packages like Orbot can also use this option to instruct Tor to save power when the network is off.
Clients and bridges can now be configured to use a separate "transport" proxy. This approach makes the censorship arms race easier by allowing bridges to use protocol obfuscation plugins. It implements the "managed proxy" part of proposal 180 (ticket 3472).
When using OpenSSL 1.0.0 or later, use OpenSSL's counter mode implementation. It makes AES_CTR about 7% faster than our old one (which was about 10% faster than the one OpenSSL used to provide). Resolves ticket 4526.
Add a "tor2web mode" for clients that want to connect to hidden services non-anonymously (and possibly more quickly). As a safety measure to try to keep users from turning this on without knowing what they are doing, tor2web mode must be explicitly enabled at compile time, and a copy of Tor compiled to run in tor2web mode cannot be used as a normal Tor client. Implements feature 2553.
Add experimental support for running on Windows with IOCP and no kernel-space socket buffers. This feature is controlled by a new "UserspaceIOCPBuffers" config option (off by default), which has no effect unless Tor has been built with support for bufferevents, is running on Windows, and has enabled IOCP. This may, in the long run, help solve or mitigate bug 98.
Use a more secure consensus parameter voting algorithm. Now at least three directory authorities or a majority of them must vote on a given parameter before it will be included in the consensus. Implements proposal 178.
Major Bugfixes:-
Hidden services now ignore the timestamps on INTRODUCE2 cells.
They used to check that the timestamp was within 30 minutes of their system clock, so they could cap the size of their replay-detection cache, but that approach unnecessarily refused service to clients with wrong clocks. Bugfix on 0.2.1.6-alpha, when the v3 intro-point protocol (the first one which sent a timestamp field in the INTRODUCE2 cell) was introduced; fixes bug 3460.
Only use the EVP interface when AES acceleration is enabled, to avoid a 5-7% performance regression. Resolves issue 4525; bugfix on 0.2.3.8-alpha.
Privacy/Anonymity Features (bridge detection):-
Make bridge SSL certificates a bit more stealthy by using random serial numbers, in the same fashion as OpenSSL when generating self-signed certificates. Implements ticket 4584.
Introduce a new config option "DynamicDHGroups", enabled by default, which provides each bridge with a unique prime DH modulus to be used during SSL handshakes. This option attempts to help against censors who might use the Apache DH modulus as a static identifier for bridges. Addresses ticket 4548.
Ettercap is a multipurpose sniffer/interceptor/logger (like Wireshark) for switched LAN. It supports active and passive dissection of many protocols (even ciphered ones) and includes many feature for network and host analysis. It is a suite for man-in-the-middle attacks on LAN. It featuressniffing of live connections, content filtering on the fly and many other interesting tricks.
Official Change Log:-
Fixed resource depletion issue
Buffer access out-of-bounds issues
Multiple buffer overflows
Multiple memory leaks
Multiple files with obsolete code
Fixed SEND L3 errors experienced by some users
Fixed a compilation error under Mac OS X Lion
Updated build system
Interface:
All this feature are integrated with a easy-to-use and pleasureful ncurses/gtk interfaces. (see screenshots)
Microsoft Security Essentials (MSE) beta, labelled 4.0.1111.0 is now available. Microsoft has released a new public beta of its free Security Essentials anti-malware and anti-virus software for Windows. The product is to to guard against viruses, spyware, and other evil software. It provides real-time protection for your home or small business PCs.
Microsoft Security Essentials is free and designed to be simple to install and easy to use. It runs quietly and efficiently in the background so you don't have to worry about interruptions or making updates. Microsoft Security Essentials 4.0.1111.0 is compatible with Windows XP SP3, Vista SP1 or later, Windows 7 SP1.
The beta of the next major release of MSE features a simplified user interface designed to make it easier to use. It includes a "new and improved protection engine" that Microsoft says provides better detection and cleanup capabilities for finding and removing security threats. Additionally, malware infections that Microsoft considers to be high impact are now automatically removed without requiring any interaction from users. As with all development releases, use in production environments and on mission critical systems is not advised. Microsoft asks users testing the release to provide feedback and report any bugs they find on the Microsoft Security Essentials Answers forum.
To Download MSE Beta Click Here (Windows Live or Microsoft Connect ID required to download)
Windows Phone 7 Connector is a simple, easy-to-use application designed to sync your favorite media files from your Mac, with your Windows Phone 7 or Zune HD. You can also sync photos and videos you captured on your phone with your Mac, and when needed, update your Windows Phone 7 software. Microsoft’s latest release of the Windows Phone 7 Connector is said to fix a number of bugs, including the spotty connectivity that a number of users have reported.
Features:-
•Full sync and import support for Apple Aperture software
•Drag and drop import of files from Browse Device
•Ringtone transfer support (for phones running Windows Phone 7.5 or later)
•Improved video conversion process with user configuration options
•Support for Windows Phone Marketplace (for phones running Windows Phone 7.5 or later)
•Localization support for 13 additional languages
•Improvements to backup and restore operations
•Improved configuration for podcast sync and photo import
•Improved iTunes import support in certain languages
•Improved metadata support for videos
Fixes :-
•Added additional error codes and help references for device update
•Resolved connectivity issues with certain devices
•Resolved album art display issues for certain device
For More Information & to Download Windows Phone 7 Connector For Mac Click Here
A remote code execution vulnerability has been discovered in the Microsoft Windows TCP/IP stack. This vulnerability occurs when Windows processes a continuous flow of specially crafted UDP packets. An attacker could exploit this vulnerability by sending a continuous flow of specially crafted UDP packets to a closed port on a target system, resulting in an integer overflow. Successful exploitation could allow attackers to run arbitrary code with kernel mode privileges. This could allow attackers to install programs; view, change, or delete data; or create new accounts with full user rights.
Microsoft released a temporary fix for the recently found Applocker bypass vulnerabilities that allows untrusted users to bypass security measures preventing them from running unauthorized applications.
Brief About Applocker:-
AppLocker allows administrators to restrict the applications that can be run on computers running Windows 7 and Windows Server 2008. But end users can easily override the restrictions by invoking a variety of automated script features, including macros in Microsoft Office. Programming flags such as SANDBOX_INERT and LOAD_IGNORE_CODE_AUTHZ_LEVEL could even allow malware stashed in temporary folders to be executed.
Microsoft released a hotfix to correct this flaw. "This hotfix might receive additional testing," Microsoft's advisory stated. "Therefore, if you are not severely affected by this problem, we recommend that you wait for the next software update that contains this hotfix."
After Nokia drive get hacked now the Nokia XDA developper has confirmed that Nokia Map get hackedNokia Maps and is now available for all Windows Phone 7 (WP7) devices . The new app launched with the Lumia 710 and 800 would very soon be available for other WP7 devices as well according to Nokia, but now you can test it out now by downloading the XAP file.
The app can only be installed in a unlocked WP7 device (dev-unlock or ChevronWP7 Labs). Nokia Maps is was developed specifically for their new line of WP7 phones and Nokia were banking on this as one of their key selling points. Now that two exclusive apps have already been leaked at a very early stage even before the phones hit the market, it hurt the sales of the new devices as they loose some of the exclusivity. At this point, Nokia can’t really do much about this, but just wait and hope that the new Lumia duo has enough going for it for them to stand out in the competition.
RTCA is a Windows forensic analysis tool, registry, audit logs and files. RTCA basically is a standalone and portable application for extraction and analysis investigation, can be used in local configuration report or analysis after extraction. As it analysis after extraction analysis is fast and accurate.
Features of RTCA:-
Compatible with Windows XP, Vista, 2003, 2008, 7, 8 32-bit (64-bit version will be compiled) and 90% ok under Wine.
Can be run in command line.
Processing and copies of registry files (damaged registry too).
System information: bootKeys/syskey, security features, serials MS…
Applications, updates, list of services, drivers, and USB…
UserAssist (command history performed by each user).
Applications at startup.
Network configuration, wireless and SSID.
List of accounts, users and hash passwords.
Passwords stored in the registry (eg VNC).
Most Recent Used historical paths.
Registry Viewer Lite.
Processing of local logs file, evt (Windows= Vista) and log ( format linux / unix). file system extraction (file and directory) : acls, hidden and protected system state.
Files explorer lite.
Processes and associated network ports.
Synthesis (audit logs, file and registry) sort by date.
Hcon is the spirit of gaining & sharing knowledge. It is the platform for the people who want to learn and share knowledge with freedom, and of course it is the platform for me and my group to share our knowledge with the world and learn more.
Description:-
Security testing Frameworks based on deferent bases. contains 100 of tools for perform tasks like recon ,social engineering , vulnerability assessment , exploitation , code auditing, reporting , etc. currently available for windows for XP , vista, 7 and also it has a portable edition. This framework has been designed and developed by Ashish Mistry (Information Security Researcher & Trainer)
Features:-
Most of the part of HSTF is semi-automated but you still need your brain to work it out. It can be use in web developing / debugging & all IT security testing stages, it has tools for
Macrium Reflect Free v5 is the latest free disaster recovery solution software that allows windows user performing disk image and hard disk cloning on their hard disk data in an easily recovered backup file. However, Macrium Reflect free version have limited functionality only like disk imaging, disk cloning, access images in Windows Explorer, and scheduled backups features only.
Features of Macrium Reflect:-
A free disaster recovery solution for your home computer
Protect your personal documents, photos, music and emails
Clone your hard disk and create disk images in the safe knowledge that everything is securely saved in an easily recovered backup file
Simple and easy-to-use interface
Backup disk images
Clone disk images
Mount or open disk images in Windows Explorer
Create recovery media to boot and restore backup images
Operating system supported:-
Windows XP, Vista, 7 or Windows 8, and the installer includes both 32-bit and 64-bit builds.
Microsoft has tweaked the use of memory in Windows 8 to help people juggle more applications and files with less physical RAM. In the latest Building Windows 8 blog, Bill Karagounis, group program manager for Microsoft's Performance team, detailed some of the tricks that the company has employed in the new OS to optimize the use of memory.
One such trick is memory combining. Windows applications can reserve multiple chunks of system memory, not just what for they need now but what for they may need in the future. The more apps that do this, the more memory used up.
Memory combining searches system RAM for duplicate content and then frees up the duplicates to hold just a single copy. If an app needs that freed-up memory in the future, Windows provides what's called a "private copy." Such a process can make anywhere from 10s to 100s of megabytes available, according to Karagounis.
A healthy amount of system RAM is also taken up by Windows services. Open Task Manager, click on the Services tab, and you'll see the sheer number of services chewing up precious memory. To make Windows 8 more memory efficient, Microsoft has removed 13 different services, changed a number of others from automatic to manual, and moved still others into a "Start on Demand" mode so they're not eating up memory from the get-go.
Yet another trick was to find various core but low-level components that have been in Windows for almost 20 years and consolidate certain ones so they don't take up as heavy a memory footprint as they would individually.
Finally, Windows 8 will be smarter about which allocated memory to keep and which to free up. For example, antivirus programs need memory when they check on files opened by other applications. Since this is typically a one-time allocation, that specific chunk of memory probably wouldn't be needed again by the AV software. As such, Windows 7 might free up that RAM for something else if memory became scare. But such an action could drag down performance.
Instead, "In Windows 8, any program has the ability to allocate memory as 'low priority,' Karagounis said. "This is an important signal to Windows that if there is memory pressure, Windows can remove this low priority memory to make space, and it doesn't affect other memory required to sustain the responsiveness of the system."
Overall, the new memory optimization should coax better performance out of PCs with an ample supply of RAM but also benefit those with only 1 or 2 gigabytes of memory. As an example, Karagounis looked at the Netbook that Windows president Steven Sinofsky used in a demo at the company's recent Build conference. Comparing the PC's memory usage under Windows 7 and Windows 8 under the same conditions, Karagounis found that Windows 7 chewed up 404MB of RAM, while Windows 8 used only 281MB.
The tweaks will also squeeze more juice out of tablets and other lower-powered devices that don't hold much physical RAM, explained Karagounis. The more RAM a device contains, the more battery power it chews up. Manufacturers of Windows 8 devices can now get by with less physical memory, thereby delivering more life on a single battery charge.
For more information and to see the windows 8 Official Blog Click Here
BreakTheSecurity released the Hash Code Cracker Version 1.2. Description:-
This password cracker is developed for PenTesters and Ethical hackers.
Please Use this software for legal purposes(Testing the Password
Strength).
Features:-
This software will crack the MD5, SHA1,NTLM(Windows Password) hash codes. Supports All platforms(windows XP/7,Linux,..).
V1.2 Change log:-
Included Online cracking Support
Minimum Requirements:-
Java Runtime Environment: JRE 1.6 should be installed.(you can get
it from oracle.com)
How to Run the Application:-
Download the .zip file and extract.
Extract the zip file.
Open the Terminal or command prompt.
Navigate to the path of Extracted zip file (i mean HashCodeCracker
Folder) in Terminal/CMD.
Type this command "java -jar HashCodeCracker.jar".
Now the application will run.
Spyware Help Center have several test computers running different operating systems. They test each virus on Windows 7, Windows Vista and Windows XP, in order to see how each virus behaves on each operating system then they test the virus removal software that recommend against the viruses on each operating system.
Long awaited Windows 8 came closer to us. Today Microsoft released the first windows 8 preview for all. It can be free;y downloaded from Microsoft, Any one can have Windows 8, an early look at the next-generation OS. The downloads, which range from 2.8GB to 4.8GB in size, come with no restrictions, a company spokeswoman confirmed earlier in the day.
According To Microsoft:-
The Windows Developer Preview is a pre-beta version of Windows 8 for developers. These downloads include prerelease software that may change without notice. The software is provided as is, and you bear the risk of using it. It may not be stable, operate correctly or work the way the final version of the software will. It should not be used in a production environment. The features and functionality in the prerelease software may not appear in the final version. Some product features and functionality may require advanced or additional hardware, or installation of other software.
World's famous torrent engine u Torrent server compromised. Windows down-loader for u Torrent has benn replaced with a fake anti virus named "scareware"
According to the Bit Torrent Blog:-
This morning at approximately 4:20 a.m. Pacific Daylight Time (UTC -7), the uTorrent.com and BitTorrent.com Web servers were compromised. Our standard Windows software download was replaced with a type of fake antivirus “scareware” program.
Just after 6:00 a.m. Pacific time, we took the affected servers offline to neutralize the threat. Our servers are now back online and functioning normally.
We have completed preliminary testing of the malware. Upon installation, a program called ‘Security Shield” launches and pops up warnings that a virus has been detected. It then prompts a user for payment to remove the virus. We recommend anyone who downloaded software between 4:20 a.m. and 6:10 a.m. Pacific time run a security scan of their computer.
We take the security of our systems and the safety of our users very seriously. We sincerely apologize to any users who were affected.
Clarification: This only affects users who downloaded software specifically from utorrent.com or bittorrent.com between the hours above this morning. Users who previously downloaded our software are not affected.
Update #2: After further analysis, we don’t believe BitTorrent.com or the BitTorrent Mainline/Chrysalis clients were part of the incident.