Showing posts with label attack. Show all posts
Showing posts with label attack. Show all posts

Wednesday, June 14, 2017

Posted by beni in , , | June 14, 2017

5 Attack Methodology


There are a few schools of thought when it comes to attack methodologies�the plan of attack that a hacker adopts when it comes to penetration testing a network. There are a few variances here and there but most people agree that a good methodology to adopt involves more or less five (5) steps:
  • Reconaissance
  • Scanning and Enumeration
  • Gaining Access (and Escalation of Privileges)
  • Maintaining Access
  • Covering Your Tracks
The preceding steps are the official attack methodology proposed by the EC-Council in its Certified Ethical Hacker (CEH) certification. For the purpose of the rest of the lessons, well stick to these steps, unless something else comes along.

Lets look at these steps a little more in-depth:
RECONNAISSANCE
Reconnaissance is the act of gathering information. An attacker will attempt to gather as much information about a target (a company, a web site, or a platform) as they can. This reconnaissance can be either passive or active. For instance, an attacker wanting to gather information passively might perform some extremely thorough and pointed internet searches to find out as much as possible about a company. They might try to find Organization Charts, personnel listings, contact information.
BackTrack has some excellent reconnaissance tools built into it and well discuss them more in-depth in the next lesson. Also, well discuss a few tools that I think happen to do excellent jobs in the passive act of reconnaissance.
When we discuss active reconnaissance, however, were typically speaking about an attacker who is scanning ports or services in order to obtain more in-depth knowledge about his victim. Walking along firewall rules and dumpster diving are other examples of this kind of reconnaissance.
SCANNING AND ENUMERATION
Utilizing port scanners, vulnerability scanners and performing war dialing are all examples of what an attacker would use to accomplish this task. Were going to focus a lot of our time on nmap and nessus during these lessons but well determine if there are any other scanning tools that help perform these tasks better.
GAINING ACCESS (AND ESCALATION OF PRIVILEGES)
This step in an attack methodology is where the actual hack or attack takes place. The attacker launches some sort of attack against a service, a port, a login, etc. and is able to gain access to the system.
MAINTAINING ACCESS
Once an attacker penetrates a system, they will most likely want to return for future use and theyll want to make sure that the system is easier to gain access next time. This is performed through the use of tools like rootkits and Trojan Horses that leave backdoors into systems.
COVERING YOUR TRACKS
Once you have implemented an attack, taken control of a box and left yourself a backdoor to enter any time you like, you need to cover your tracks and hide all signs you were ever there. This includes emptying of logs and wiping of system data.
SUMMARY
All right. Now that weve determined what steps make up our attack methodology, lets take an in-depth look at Reconnaissance.

Wednesday, April 12, 2017

Posted by beni in , , , , , , , , , | April 12, 2017

A Facebook’s notification to aware people about suspected cyber attack


A Facebook�s notification to aware people about suspected cyber attack:

newsofcrime.blogspot.com
Don�t ignore a notification on Facebook by the Facebook that warns its users that their accounts are targeted or compromised by Associate in Nursing attacker suspected of functioning on behalf of a nation-state. 
Along with different emotions, Facebook has recently launched the notification that warns the user if it finds his/her Facebook account has been targeted by an attacker functioning on behalf of a nation-state.

�Starting these days, well give notice you if we tend to believe your account has been targeted or compromised by an attacker suspected of functioning on behalf of a nation-state,� Alex Stamos, chief security officer at Facebook, said on October seventeen.

He added, �While weve forever taken steps to secure accounts that we tend to believe to own been compromised, we tend to set to point out this extra warning if weve a robust suspicion that an attack may well be government-sponsored. we tend to try this as a result of these styles of attacks tend to be a lot of advanced and dangerous than others, and that we powerfully encourage affected individuals to require the actions necessary to secure all of their online accounts.�

The company has conjointly processed that the warning isnt associated with any compromise of Facebooks platform or systems, which having an account compromised during this manner could indicate that users� computers or mobile devices are infected with malware.

�Ideally, those that see this message should pay attention to make or replace these systems if potential,� the safety officer said.

However, at now, the Facebook continues to be unable to elucidate however they attribute bound attacks to suspected attackers, so as to safeguard the integrity of our ways and processes.

�We attempt to use this warning solely in things wherever the proof powerfully supports our conclusion. we tend to hope that these warnings can assist those individuals in want of protection, and that we can still improve our ability to stop and find attacks of all types against individuals on Facebook,� 

Search