4/09/2011

NESSUS - Vulnerability Scanner

First thing you should do is a nessus registration. Go to this link and select the home user http://tenable.com/products/nessus/nessus-plugins/obtain-an-activation-code . An email will be sent to you with the activation code. Now download and install both the Nessus Server and Client from their website. Register using the code provided in the mail.

NMAP


Nmap is a great tool for scanning networks, specific ips, finding out which ports are open etc. Its available for Windows and Linux. Its pre installed on Backtrack. Its an awesome tool to have.


4/07/2011

Understanding TCP/IP using Wireshark


I feel that it is best to use a packet sniffing tool like wireshark to understand TCP/IP. The following picture shows the layers of TCP/IP and the protocols involved.

4/04/2011

Puzzle 10

A spy is trying to send a secret message,I`m trying to decode it,,can you help me?
He sent these messages:
Lado Mado Bado
Nado Sado Mado
Kado Bado Fado
One of these messages(not as in above order) means:Plan excuted successfully.
other message means:Mission dangerously excuted.
and the third message means:Abort mission immediately.
Now....what does "Lado" mean?

Puzzle 9

Barbera's daughter is my daughter's mother. Who am I to Barbera?

Snort

Snort is also a very popular packet sniffer. It does not prevent attacks, but logs the traffic so that we can get information as to what happened.

Tcpdump

Tcpdump is a packet analyzer for linux. It allows the user to intercept and display TCP/IP and other packets being transmitted or received over a network to which the computer is attached.

4/03/2011

Some useful commands

ls                       lists the files and directories

ls -a                     lists the hidden files and directories (files can be made hidden by using a . in front of its   name)

netstat -an     lists the open ports

netstat -rn     displays the internal routing table


pwd                current directory location in terminal

last                  displays the last users who logged into the system and the time in which they did so

lsmod              displays the kernel modules loaded

sudo                super user, previlege escalation

apt-get            installation package (eg. apt-get install gedit)

gunzip 'file'    unzipping file    

tar -xvf 'file'   untaring file

man                if you don't know what a program does for eg. nmap, type man nmap, it will give a lot 
                          of info

uname -a       System info 


df -H              Disk usage

vi                   to view a file

nano              easier tool to view a file than vi


cat                 view a file in the current shell itself i.e; without opening another tab


strings           view text data in a dump file (eg. captured by tcpdump with .dmp extension)


lsof                list open files


gedit             probably the most user friendly text editor, install it using apt-get install gedit

chmod          change mode eg. chmod +x filename creates an exe file

grep             search for data inside a file (eg. grep indy filename displays all lines with indy in it)

4/01/2011

File Recovery

Suppose you have the dd of the hard disk. You can recover any file you want from it.

fls sda.dd    (sda is just an example)

Puzzle 8:Shiekh's inheritence

An Arab sheikh tells his two sons to race their camels to a distant city to see who will inherit his fortune. The one whose camel is slower wins. After wandering aimlessly for days, the brothers ask a wise man for guidance. Upon receiving the advice, they jump on the camels and race to the city as fast as they can.
What did the wise man say to them?