If your online life is divided at different locations; like office and home, you may be wanting to synchronize different files and folders, which are located at your office computer, your home PC, your laptop and your USB drives.
There are many options. Simple copy and paste. But that is too crude.
A few freeware like Allway Sync etc. They are nice but, somehow, I am always skeptical of using third party software.
Now Microsoft has released latest version of SyncToy 2.0 beta for letting you synchronize your files. It is free and comes from a trustworthy source like Microsoft. And so, I like it. With this, you can easily copy, move, rename, and delete files between folders and computers so as to achieve perfect synchronization
9/15/09
Test Computer for Installed KeyLoggers
Apart from Phishing, Keyloggers are one of the key factors contributing to the rise of cases of Identity theft in recent times. Keyloggers are not the old hardware types anymore, which could easily be spotted by a careful visual inspection of your computer wires and cables.
Today’s keyloggers are smart. They have the capabilities to hide themselves deep into your software applications and operate from there. And they are easy to install and control for a remote person, thanks to some careless attitude of many of the victims.
How to check, if your computer already has a Keylogging Software installed?
Many of the Security Software suites available today are able to detect most of the common keylogging software. As soon as some keylooger is attempted to be installed on your system, your security suite warns you about that and you can take appropriate action.
But, are you sure that your security software is capable of identifying keylogging activities? There is a simple test software available from Zemana, which lets you simulate a keylogger on your computer. You can download it absolutely free and run it on your computer. If your security software is able to detect it, then you may be confident about the effectiveness of that against keyloggers, otherwise it is time to have a second look at your choice of security software.
My Testing of Zemana
I have been using Norton 360 on my Laptop and it was not able to intercept this keylogging simulator software. But at the same time, I am also using KeyScrambler, which encrypts the data you enter through your keyboard. I was happy to note that all the text, which Zemana Keylogging Simulator could cpature was the encrypted text and not the actual keystrokes.
Thus, KeyScrambler was actually performing its job quite effectively and I was protected against such Keylogging activities.
Nice tool, and I recommend you to give it a try to test, if any keylogger is installed onto your system. You never know, when huge surprise start staring on your face.
Download Zemana Keylogging Simulator Test
Today’s keyloggers are smart. They have the capabilities to hide themselves deep into your software applications and operate from there. And they are easy to install and control for a remote person, thanks to some careless attitude of many of the victims.
How to check, if your computer already has a Keylogging Software installed?
Many of the Security Software suites available today are able to detect most of the common keylogging software. As soon as some keylooger is attempted to be installed on your system, your security suite warns you about that and you can take appropriate action.
But, are you sure that your security software is capable of identifying keylogging activities? There is a simple test software available from Zemana, which lets you simulate a keylogger on your computer. You can download it absolutely free and run it on your computer. If your security software is able to detect it, then you may be confident about the effectiveness of that against keyloggers, otherwise it is time to have a second look at your choice of security software.
My Testing of Zemana
I have been using Norton 360 on my Laptop and it was not able to intercept this keylogging simulator software. But at the same time, I am also using KeyScrambler, which encrypts the data you enter through your keyboard. I was happy to note that all the text, which Zemana Keylogging Simulator could cpature was the encrypted text and not the actual keystrokes.
Thus, KeyScrambler was actually performing its job quite effectively and I was protected against such Keylogging activities.
Nice tool, and I recommend you to give it a try to test, if any keylogger is installed onto your system. You never know, when huge surprise start staring on your face.
Download Zemana Keylogging Simulator Test
UltraVPN – Free VPN Service for Blocked Sites
There are many forms of Internet censorship. Many a times, a corporate environment, a schools administrations or University IT department blocks the use of certain websites to enable them to restrict the use of Internet. Many a times the IT department blocks the use of chat clients like MSN and Yahoo thinking that they are a big time wasters and affect the productivity of their employees.
Besides that, there are many users, which are overly concerned about their privacy while using Internet and want to hide as many details as possible including their IP and other details.
If you are also working in such an environment and want to access blocked websites, or you want to hide your IP while browsing over Internet, then you may consider using Virtual Private Network, or VPN services. There are lots of VPN services available on Internet using different mode of operations. Some of them are free, while others are paid solution.
UltraVPN is one such Free VPN Service.
What is UltraVPN
UltraVPN is a client/server SSL VPN solution based on OpenVPN. It works by encrypting and anonymizing your network connection. You have to register first on their website and then you can download the free VPN client absolutely free. It simply sits on your system tray. Whenever you want your browsing session to be secured and encrypted, you can just right click it and choose “connect” to use this free VPN service.
Your browsing data passes through the secured servers of UltraVPN, and your privacy is protected.
Is UltraVPN Secure
There are always concerns about the sharing your private browsing data with a third party. However, UltraVPN is an open source applications, which ensures that you can be sure about the source code of the application. However, you have to generate and keep faith in them about the security of your private data, when using this useful free VPN service.
There is yet another concern about the speed of your browsing, because now there is another layer between you and your target webpage. It depends on user to user, and you are advised to keep this factor in mind while opting to use it.
[Download UltraVPN]
Besides that, there are many users, which are overly concerned about their privacy while using Internet and want to hide as many details as possible including their IP and other details.
If you are also working in such an environment and want to access blocked websites, or you want to hide your IP while browsing over Internet, then you may consider using Virtual Private Network, or VPN services. There are lots of VPN services available on Internet using different mode of operations. Some of them are free, while others are paid solution.
UltraVPN is one such Free VPN Service.
What is UltraVPN
UltraVPN is a client/server SSL VPN solution based on OpenVPN. It works by encrypting and anonymizing your network connection. You have to register first on their website and then you can download the free VPN client absolutely free. It simply sits on your system tray. Whenever you want your browsing session to be secured and encrypted, you can just right click it and choose “connect” to use this free VPN service.
Your browsing data passes through the secured servers of UltraVPN, and your privacy is protected.
Is UltraVPN Secure
There are always concerns about the sharing your private browsing data with a third party. However, UltraVPN is an open source applications, which ensures that you can be sure about the source code of the application. However, you have to generate and keep faith in them about the security of your private data, when using this useful free VPN service.
There is yet another concern about the speed of your browsing, because now there is another layer between you and your target webpage. It depends on user to user, and you are advised to keep this factor in mind while opting to use it.
[Download UltraVPN]
Crack, Recover or Remove Lost or Forgotten Password in Excel
Passwords are your key to security. We have often advised against the use of weak passwords and not to repeat them at different websites and applications. But using strong passwords has its own inconveniences and hassles.
There are many instances when you may need to crack or recover a lost or forgotten passwords. For instance, an employee might have just left your company and that important client spreadsheet created by him last Friday had a password only known to him. Or you yourself had a locked an important Excel file with a strong password and you are not remembering it just because it is already six months back. Orone of your family members has put a not-so-easy password on your important file.
Or may be, you just want to break the Excel password of a colleague’s file.
We just found a nice tool to crack or recover passwords from Microsoft Excel Files with ease.Petri IT Knowledgebase Team has come out with an Excel Password recovery, which does the job of cracking Excel Passwords in a few clicks.
They have a useful step-by-step guide to help you out for recovering excel passwords. This guide outlines how to use a simple Excel password recovery application to crack lost or forgotten passwords, allowing you to unlock password-encrypted Microsoft Excel documents quickly as possible.
There are many instances when you may need to crack or recover a lost or forgotten passwords. For instance, an employee might have just left your company and that important client spreadsheet created by him last Friday had a password only known to him. Or you yourself had a locked an important Excel file with a strong password and you are not remembering it just because it is already six months back. Orone of your family members has put a not-so-easy password on your important file.
Or may be, you just want to break the Excel password of a colleague’s file.
We just found a nice tool to crack or recover passwords from Microsoft Excel Files with ease.Petri IT Knowledgebase Team has come out with an Excel Password recovery, which does the job of cracking Excel Passwords in a few clicks.
They have a useful step-by-step guide to help you out for recovering excel passwords. This guide outlines how to use a simple Excel password recovery application to crack lost or forgotten passwords, allowing you to unlock password-encrypted Microsoft Excel documents quickly as possible.
How To Publish an ASP.NET Website from a Command Line
To test the tools which we develop on the team, at times I need to build a website and publish it. I use a simple way of publishing websites from the command line that saves me a LOT of time so thought I would share it.
Launch notepad and copy paste the code below and save it as Publish.cmd file. Run visual studio command prompt (as administrator) and run the publish.cmd.
1: @ECHO OFF
2: set WEB_ROOT=C:\inetpub\wwwroot\mytestsite
3: set PROJECT_ROOT=D:\Source\website
4:
5: echo Publishing site %PROJECT_ROOT% to %WEB_ROOT%
6:
7: del /S /Q %WEB_ROOT%\*.* || goto Error
8: rmdir /S /Q %WEB_ROOT%\ || goto Error
9: aspnet_compiler -p "%PROJECT_ROOT%" /v /commercesite /d "%WEB_ROOT%" || goto Error
10:
11: goto Success
12: :Error
13: echo Site was not published
14:
15: goto End
16:
17: :Success
18: echo Site published successfully
19:
20: :End
If there aren’t any errors the site will be published successfully as shown below
C:\Windows\system32>D:\Source\website\publish.cmd
Publishing site D:\Source\website to c:\inetpub\wwwroot\mytestsite Utility to precompile an ASP.NET application
Copyright (C) Microsoft Corporation. All rights reserved.
Site published successfully
C:\Windows\system32>
Modify the above script parameters appropriately to publish your site successfully!
Launch notepad and copy paste the code below and save it as Publish.cmd file. Run visual studio command prompt (as administrator) and run the publish.cmd.
1: @ECHO OFF
2: set WEB_ROOT=C:\inetpub\wwwroot\mytestsite
3: set PROJECT_ROOT=D:\Source\website
4:
5: echo Publishing site %PROJECT_ROOT% to %WEB_ROOT%
6:
7: del /S /Q %WEB_ROOT%\*.* || goto Error
8: rmdir /S /Q %WEB_ROOT%\ || goto Error
9: aspnet_compiler -p "%PROJECT_ROOT%" /v /commercesite /d "%WEB_ROOT%" || goto Error
10:
11: goto Success
12: :Error
13: echo Site was not published
14:
15: goto End
16:
17: :Success
18: echo Site published successfully
19:
20: :End
If there aren’t any errors the site will be published successfully as shown below
C:\Windows\system32>D:\Source\website\publish.cmd
Publishing site D:\Source\website to c:\inetpub\wwwroot\mytestsite Utility to precompile an ASP.NET application
Copyright (C) Microsoft Corporation. All rights reserved.
Site published successfully
C:\Windows\system32>
Modify the above script parameters appropriately to publish your site successfully!
How to: Restart a Remote Server Using Command Prompt
In our team am responsible for setting up and maintaining test servers. At times the servers are remotely located and doesn’t respond and you need to restart them. You can contact helpdesk which would involve some time. I found an easy way to do it so thought I would share it.
Launch command prompt (as administrator) and run the below command. User should have administrator permissions on the server.
1: SHUTDOWN /r /f /t 0 /m \\ /c ""
/r Shutdown and restart the computer.
/f Force running applications to close without forewarning users.
/t xxx Set the time-out period before shutdown to xxx seconds.
The valid range is 0-600, with a default of 30.
/m \\computer Specify the target computer.
/c "comment" Comment on the reason for the restart or shutdown.
If there aren’t any issues the system will be restarted
1: C:\Windows\system32>;SHUTDOWN /r /f /t 0 /m \\xyz /c "Hotfix Installation"
Modify the above script parameters appropriately to copy the files successfully!
Launch command prompt (as administrator) and run the below command. User should have administrator permissions on the server.
1: SHUTDOWN /r /f /t 0 /m \\
/r Shutdown and restart the computer.
/f Force running applications to close without forewarning users.
/t xxx Set the time-out period before shutdown to xxx seconds.
The valid range is 0-600, with a default of 30.
/m \\computer Specify the target computer.
/c "comment" Comment on the reason for the restart or shutdown.
If there aren’t any issues the system will be restarted
1: C:\Windows\system32>;SHUTDOWN /r /f /t 0 /m \\xyz /c "Hotfix Installation"
Modify the above script parameters appropriately to copy the files successfully!
Haraldscan – BlueTooth Discovery Scanner
The scanner will be able to determine Major and Minor device class of device, as well as attempt to resolve the device’s MAC address to the largest known Bluetooth MAC address Vendor list.
The goal of this project is to obtain as many MAC addresses mapped to device vendors as possible.
Requirements
* Python 2.6
* Pybluez
* PySQLite
Installation
1. Unpack to a directory
2. Run python haraldscan -b to build database
3. python haradscan [Options] to run Harald Scan
You can download Haraldscan here:
haraldscan-0.3.tar.gz
haraldscan_osx-0.3.tar.gz – Mac OS X Testing Version
Or read more here.
The goal of this project is to obtain as many MAC addresses mapped to device vendors as possible.
Requirements
* Python 2.6
* Pybluez
* PySQLite
Installation
1. Unpack to a directory
2. Run python haraldscan -b to build database
3. python haradscan [Options] to run Harald Scan
You can download Haraldscan here:
haraldscan-0.3.tar.gz
haraldscan_osx-0.3.tar.gz – Mac OS X Testing Version
Or read more here.
SWFScan – Free Flash Application Security Scanner
HP SWFScan is a free tool developed by HP Web Security Research Group, which will automatically find security vulnerabilities in applications built on the Flash platform.
HP is offering SWFScan because:
* Their research shows that developers and increasingly implementing applications built on the Adobe Flash platform without the required security expertise.
* As a result, they are seeing a proliferation of insecure applications being deployed on the web.
* A vulnerable application built on the Flash platform widens your website’s attack surface creating more opportunity for malicious hackers.
How SWFScan works and what vulnerabilities it finds:
* Decompiles applications built on the Adobe Flash platform to extract the ActionScript code and statically analyzes it to identify security issues such as information disclosure.
* Identifies and reports insecure programming and deployment practices and suggests solutions.
* Enables you to audit third party applications without requiring access to the source code.
You can download SWFScan here:
SwfScan.msi
Or read more here.
HP is offering SWFScan because:
* Their research shows that developers and increasingly implementing applications built on the Adobe Flash platform without the required security expertise.
* As a result, they are seeing a proliferation of insecure applications being deployed on the web.
* A vulnerable application built on the Flash platform widens your website’s attack surface creating more opportunity for malicious hackers.
How SWFScan works and what vulnerabilities it finds:
* Decompiles applications built on the Adobe Flash platform to extract the ActionScript code and statically analyzes it to identify security issues such as information disclosure.
* Identifies and reports insecure programming and deployment practices and suggests solutions.
* Enables you to audit third party applications without requiring access to the source code.
You can download SWFScan here:
SwfScan.msi
Or read more here.
9/2/09
Graudit – Code Audit Tool Using Grep
Graudit is a simple script and signature sets that allows you to find potential security flaws in source code using the GNU utility grep. It’s comparable to other static analysis applications like RATS, SWAAT and flaw-finder while keeping the technical requirements to a minimum and being very flexible.
Usage
Graudit supports several options and tries to follow good shell practices. For a list of the options you can run graudit -h or see below. The simplest way to use graudit is;
graudit /path/to/scanYou can download Graudit v1.1 here:
graudit-1.1.tar.bz2
Or read more here.
Usage
Graudit supports several options and tries to follow good shell practices. For a list of the options you can run graudit -h or see below. The simplest way to use graudit is;
graudit /path/to/scanYou can download Graudit v1.1 here:
graudit-1.1.tar.bz2
Or read more here.
IKECrack – IKE/IPSec Authentication Cracking Tool
IKECrack is an open source IKE/IPSec authentication crack tool. This tool is designed to bruteforce or dictionary attack the key/password used with Pre-Shared-Key [PSK] IKE authentication. The open source version of this tool is to demonstrate proof-of-concept, and will work with RFC 2409 based aggressive mode PSK authentication.
IKE Agressive Mode BruteForce Summary
Aggressive Mode IKE authentication is composed of the following steps:
1.Initiating client sends encryption options proposal, DH public key, random number [nonce_i], and an ID in an un-encrypted packet to the gateway/responder.
2.Responder creates a DH public value, another random number [nonce_r], and calculates a HASH that is sent back to the initiator in an un-encrypted packet. This hash is used to authenticate the parties to each other, and is based on the exchange nonces, DH public values, the initiator ID, other values from the initiator packet, and the Pre-Shared-Key [PSK].
3.The Initiating client sends a reply packet also containing a HASH, but this response is normally sent in an encrypted packet.
IKECrack utilizies the HASH sent in step 2, and attempts a realtime bruteforce of the PSK. This involves a HMAC-MD5 of the PSK with nonce values to determine the SKEYID, and a HMAC-MD5 of the SKEYID with DH pubkeys, cookies, ID, and SA proposal. In practice, SKEYID and HASH_R are calculated with the Hash cipher proposed by the initiator, so could actually be either SHA1 or MD5 in HMAC mode.
Project Details
IKECrack utilizes components from the following OpenSource/PublicDomain programs:
•MDCrack
•Ron Rivest’s MD5
•Simeon Pilgrim’s Reverse MD5
•MD5 and HMAC-MD5 PerlMods
•libpcap
Performance
Initial testing with Perl based IKECrack shows numbers of 18,000 tests per second with a PIII 700, and can bruteforce 3 chars of ucase/lcase/0-9 in 13 seconds.
MDCrack [a MD5 bruteforce tool] can achieve 1.5 million keys per second with pure MD5 and a PIII 700. PSK bruteforcing consists of 4 MD5’s, and 4 64 byte XORs….but should still be able to achieve 375,000 IKE keys per second. Preliminary tests in C have shown 26,000 keys per second with un-optimized routines. I’m hoping that Simeon Pilgrim’s MD5 routines will speed this up a bit more.
You can download IKECrack here:
ikecrack-snarf-1.00.pl
Or read more here.
IKE Agressive Mode BruteForce Summary
Aggressive Mode IKE authentication is composed of the following steps:
1.Initiating client sends encryption options proposal, DH public key, random number [nonce_i], and an ID in an un-encrypted packet to the gateway/responder.
2.Responder creates a DH public value, another random number [nonce_r], and calculates a HASH that is sent back to the initiator in an un-encrypted packet. This hash is used to authenticate the parties to each other, and is based on the exchange nonces, DH public values, the initiator ID, other values from the initiator packet, and the Pre-Shared-Key [PSK].
3.The Initiating client sends a reply packet also containing a HASH, but this response is normally sent in an encrypted packet.
IKECrack utilizies the HASH sent in step 2, and attempts a realtime bruteforce of the PSK. This involves a HMAC-MD5 of the PSK with nonce values to determine the SKEYID, and a HMAC-MD5 of the SKEYID with DH pubkeys, cookies, ID, and SA proposal. In practice, SKEYID and HASH_R are calculated with the Hash cipher proposed by the initiator, so could actually be either SHA1 or MD5 in HMAC mode.
Project Details
IKECrack utilizes components from the following OpenSource/PublicDomain programs:
•MDCrack
•Ron Rivest’s MD5
•Simeon Pilgrim’s Reverse MD5
•MD5 and HMAC-MD5 PerlMods
•libpcap
Performance
Initial testing with Perl based IKECrack shows numbers of 18,000 tests per second with a PIII 700, and can bruteforce 3 chars of ucase/lcase/0-9 in 13 seconds.
MDCrack [a MD5 bruteforce tool] can achieve 1.5 million keys per second with pure MD5 and a PIII 700. PSK bruteforcing consists of 4 MD5’s, and 4 64 byte XORs….but should still be able to achieve 375,000 IKE keys per second. Preliminary tests in C have shown 26,000 keys per second with un-optimized routines. I’m hoping that Simeon Pilgrim’s MD5 routines will speed this up a bit more.
You can download IKECrack here:
ikecrack-snarf-1.00.pl
Or read more here.
Trafscrambler – Anti-sniffer/IDS Tool
Features
•Injection of packets with bogus data and with randomly selected bad TCP cksum or bad TCP sequences
•Userland binary(tsctrl) for controlling trafscrambler NKE
•SYN decoy – sends out number of SYN pkts before the original SYN pkt
•TCP reset attack – sends out RST/FIN pkt with bad sequence
•Pre-connection SYN – sends out SYN with wrong TCP-checksum
•Post-connection SYN – sends out fake SYN after connection establishment
•Zero Window – send out pkt with “0” window set.
You can download Trafscrambler 0.2 here:
trafscrambler-0.2.tgz
Or read more here.
•Injection of packets with bogus data and with randomly selected bad TCP cksum or bad TCP sequences
•Userland binary(tsctrl) for controlling trafscrambler NKE
•SYN decoy – sends out number of SYN pkts before the original SYN pkt
•TCP reset attack – sends out RST/FIN pkt with bad sequence
•Pre-connection SYN – sends out SYN with wrong TCP-checksum
•Post-connection SYN – sends out fake SYN after connection establishment
•Zero Window – send out pkt with “0” window set.
You can download Trafscrambler 0.2 here:
trafscrambler-0.2.tgz
Or read more here.
How to Change JKS KeyStore Private Key Password
Use following keytool command to change the key store password >keytool -storepasswd -new [new password ] -keystore [path to key stor...
-
AIX Environment Procedures The best way to approach this portion of the checklist is to do a comprehensive physical inventory of the server...
-
Address Resolution Protocol (ARP) provides IP-to-MAC (32-bit IP address into a 48-bit Ethernet address) resolution. ARP operates at Layer 2 ...