IP

Friday, January 21, 2011

Null session attack




In short, Null session attack is an exploit that uses unauthenticated NetBIOS connections to enumerate a target host.
Previously, you learnt about Ethical Hacking, Spoofing, Phishing, Hacking, Password crackers etc. Keeping this informative and educative series on, today i would like to describe to you about Null Session Attacks and how they can let your computer be compromised in no time. I will also write about the ways by which you can protect your computers/servers against the same.
Windows machines allows remote users to login remotely to a machine running the server service. This login can then be used to use a shared resource, such as a printer or any other shared directory etc. Once the user is logged in their connection to the remote machine is referred to as a “session”. The number of open sessions in a windows machine can be checked using multiple ways, one of the most widely used way is by exploring the open sesions using ” Computer Management” as shown in the figure below.
Open Sessions on your computer
Open Sessions on your computer
Usually Microsoft Windows Servers run many services and programs. Some of these services then communicate with other windows servers to complete some specific tasks. For such communications and tasks to complete successfully, windows servers also logs into a remote windows server using a blank username and password. This is referred as a “Null Session”.
However, its not only always the genuine servers that can login to the remote server but also hackers who have enough skills can do so and its not that tough either. They can use this to obtain NetBios information from this machine, and to perform various other exploits against this machine. This is referred to as a “Null Session Attack”.
To carry out a Null Session attack , all that a hacker needs is cmd.exe ( command prompt ) and PSTools ( Available from Sysinternals). If you have the IP Address of your target follow the steps below to create a Null Session Login to the remote machine.
1.) At Run , Type cmd
2.) At the command prompt, enter the following
net use \\IP ADDRESS\ipc$ /user:administrator
For eg. If the target address is 72.233.2.54 type in net use \\72.233.2.54\ipc$ /user:administrator
3.) If you receive the message ” The command was successfully executed”, it means that you have logged in using a Null Session.
4.) Now, if you wish, you can get loads of information about this system.Information that can be obtained includes user IDs, share names, security policy settings, users currently logged in and more. The Windows registry can even be tapped remotely with the right tools.
5.) Lets try getting hold of the valid usernames for this remote system. For this, you would need a tool called PsTools from Sysinternals. Download it from here.
6.) Once you have downloaded the zip file, extract and copy the files “psexec” and “psloggedon” to the ‘C:\Windows\System32′ folder.
7.) Enter at the command prompt the command
psexec \\IP ADDRESS -u administrator psloggedon \\IP ADDRESS
If the computer you have identified as a target is not sufficiently protected, you should get all the users logged on to this computer.

How to protect your computer from a Null Session Attack?

Null Session Attacks are mostly carried out on ports 139 and 445 on aWindows PC. Therefore the best option is to is to simply block SMB communications by limiting traffic on TCP ports 139 and 445 (excluding NT which doesn’t use 445) to trusted networks. I know it seems painfully obvious, but people still have unprotected Windows systems out there for the taking. A basic firewall and host-based IPS can do wonders for this.
If you use Windows XP, install service pack 3 without any delays. SP3 has an improved firewall which prevents null session attacks, so that at least if someone tries to login to your computer over the internet, it is blocked.

Thursday, January 20, 2011

Hide your real IP address and surf the internet safely.


An Internet Protocol address (IP address) is a numerical label assigned to each device (e.g., computer, printer) participating in a computer network that uses the Internet Protocol for communication. An IP address serves two principal functions: host or network interface identification and location addressing. Its role has been characterized as follows: "A name indicates what we seek. An address indicates where it is. A route indicates how to get there.


There is many tools available , i am giving you few tools introduction here ,rest will give you in next few post.


Quick Hide IP 1.0




Quick Hide IP 1.0 portable | 4.4 MB

If you want to use internet anonymously and hide your ip to trace. Here is a great tool for you. Quick Hide IP protects your online identity by hiding your IP address and replacing with a proxy server IP address.You will appear to access the internet from a different location, not your real location. So all websites you are visiting see the IP address of the proxy server instead of your own IP address.



Key Features
  1. Hide your IP address from the web sites you visit.
  2. Fully compatible with Internet Explorer, Chrome, Firefox, Opera.
  3. Easy way to change proxy settings on the fly.
  4. Automatically switch IP address every X minutes for better anonymous surfing.
  5. Choose your favorite hidden geographic location all around the world.
  6. Advanced proxy list testing and management.




Easy-Hide-IP 3.7.4




Click to see larger images

Hide IP 'Hide my IP' edition is the worlds most advanced IP changer to bypass virtually any form of censorship or internet traffic blocking imposed on you by your ISP, your company or by third parties. Your internet traffic is routed through remote servers. Only the IPs of the remote servers will appear your ISP's log file, not the sites you have visited. Easy Hide IP protects your identity by replacing your real IP address with a different one. You will appear to access the internet from a different location, not your own. Your real location is never revealed. Change / hide IP address. Choose your geographic location. Access to our high speed servers. Automatically hide IP every X minutes. Works with Internet Explorer, Firefox and Chrome. Download Torrents safely by hiding your IP address Just start the application, select an IP address to use and click on the 'Hide IP' button.
 NotMyIP – The simplest online anonymity tool



NotMyIP is a FREE tool that help overcome censorship and browse anonymously by hiding your IP address. It  uses only high quality proxies and works with ALL browsers (Internet Explorer, Firefox, Opera, Chrome, etc). No need for manual configuration or additional plug-ins or add-ons. NotMyIP is the free version of our PREMIUM product, Anonymity Gateway!

Important!

  • NotMyIP is free for non-commercial use.
  • By using NotMyIP you agree NOT to use the product for any illegal purpose, or in violation of any local, state, national, or international law, including, without limitation, laws governing intellectual property and other proprietary rights, and data protection and privacy.

Support NotMyIP!

If NotMyIP helps you browse anonymously and to overcome censorship in your country you may consider supporting the project by donations or by purchasing our premium product, Anonymity Gateway. Please contact us at info@privacy-gateway.com for donations and any questions you may have.
NotMyIP

Comparison between Privacy-Gateway products

Feature

NotMyIP


Anonymity Gateway

Anonymity Shield

Browsers

ALL (Internet Explorer, Firefox, Chrome, Opera, Safari)ALL (Internet Explorer, Firefox, Chrome, Opera, Safari)Internet Explorer Toolbar

US Premium Proxies

3 IP addresses15 IP addresses15 IP addresses

UK Premium Proxies

-3 IP addresses3 IP addresses

Germany Premium Proxies

-2 IP addresses-

Ireland Premium Proxies

-1 IP addresses-

France Premium Proxies

-1 IP addresses-

Canada Premium Proxies

-1 IP addresses-

Clean online tracks

NoYesNo

Block invasive code

NoYesNo

Compatible with Windows XP/Vista

YesYesYes

Add your own proxy

NoYesYes

Price

FREE$33 / yearStarting from $5.95 / month

Download

 Click Here!Click Here!  Click Here!

More about NotMyIP – the simplest solution to mask your IP

How many times did you say: “Oh, I wish this was not my IP”or “I want to hide my IP address” or “I want to mask my IP address” so you can bypass certain Internet restrictions and view content that is blocked for users in your area.
If you answered these questions at least “Some times” or “Many times” than we have the solution for you. Not My IP is an online privacy protection software that hides your real online identity from cyber thieves. Your online identity is given by your IP address, which provides plenty information about you. By providing you different proxies from all over the world, Not my IP will allow you to access websites that were blocked for you until now, to vote and comment on forums you were banned before, and further more to prevent other people (organizations) to follow you online.
If you answered these questions “Never” we would recommend you to think twice. Every Internet user needs this kind of online privacy protection solutions. Every Internet user should be aware of the online dangers they face online. Whether we like it or not, the thieves are around the corner, waiting to collect your personal data, information which you might want to keep it confidential, as it should be. Mask your real IP address and you will not have to worry for these anymore.

Not my IP provides only high quality proxies

The high speed proxies included in Not my IP will not make you feel that you are using a proxy which is different from yours. And if this feeling is absent, the benefits of using this mask ip application are as present as could be. You do not have to worry anymore that someone is following you online and knows all your browsing habits. Just hide your IP and enjoy safe and secure anonymous web surfing!

The simplest mask IP solution

The clean user interface and the easy usage of the application make Not my IP the simplest hide IP solution. Only by pressing one button you will start to surf anonymously. One simple advanced section is also available allowing you to choose the countries you would like to receive proxies from. That’s all: simple as 123, isn’t it? Every Internet user can use Not my IP, no matter what experience he or she has in this field. Just press one button and stop worrying for your online identity. Press another button and get your real identity back. I bet you will enjoy browsing the web securely and anonymously with Not my IP, the simplest tool to mask ip.