As we all know that wireless networks are spread at each
and every part of the world starting
from personal home to corporate business, schools/universities, cafes etc..
Major merit of wireless network is of eliminating the big and tidy cables which
acquires space and not spoiling the look of your working area. But as we all
know that each coin has two sides. There are demerits of wireless networks as
well. It comes with high possibility of attacks on it. In this article I am
going to describe different techniques of wireless attacks from the world and
what we should do to prevent those attacks on wireless networks.
Everything about threat intelligence, blue team, red team, pentesting, security audit, security review, testing and assessment.
Saturday, December 28, 2013
Wednesday, December 11, 2013
Firewall Unleashed
Introduction
Firewalls are used to monitor and control the inbound and
outbound traffic on the protected network. They have an ability to block
and allow the internal as well as external services within the network.
Before allowing access to the service, a firewall may also force the
client / user to pass through an authentication. Sometimes a firewall
can be also used in IPSEC tunnels as a platform. It monitors
security-related events.
Labels:
iptable,
iptable firewall,
iptables,
linux,
linux firewall,
linux iptables
Monday, December 2, 2013
Transport Layer Security - Part 2 SSL
Introduction
I have already discussed about SSL in my previous article. Here I will be explaining you SSLv3. It is developed by Netscape company .In this section I will discuss on SSLv3.
I have already discussed about SSL in my previous article. Here I will be explaining you SSLv3. It is developed by Netscape company .In this section I will discuss on SSLv3.
General SSL Architecture
It is designed to secure end-to-end service on the internet. I will illustrate that SSL is not a single handed protocol. It is a layer of more than one protocol such as
a. SSL record protocol
b. SSL handshake protocol
c. SSL change cipher spec protocol
d. SSL alert protocol
Sunday, November 17, 2013
Suspicious File Analysis With PEFRAME
In this article I am going to conduct a walk through with a nice python tool named PeFrame. This tool should be an analyst’s first choice in order to analysis a piece of static malware. I am going to discuss each and every feature provided by this tool and I will also show you why it is important to find information through the malware.
Thursday, November 14, 2013
Transport Layer Security - Part 1
This is a non-technical guide which will make you familiar with the transport layer. The main purpose of writing this guide is to point out why we need major security implementation on the transport layer. What if the components of this layer get compromised?
Tuesday, November 5, 2013
Scalpel : Data Recovery From Byte Strings
In digital forensics, file carving is an essential process. It is a technique in which investigator uses databases of headers as well footers. These headers and footers contain byte strings. So, suppose you have 5 JPEG files. So all those 5 files will have same header & footer byte strings. So this tool carves data by analyzing that byte string. This Is an advance tool as it also carves file even after its metadata is removed.
Monday, November 4, 2013
Phishing Countermeasures Unleashed
Monday, October 28, 2013
SSL Unleashed
In this article I am going to tell you everything about SSL that what it is why we need it, technical and non technical aspects of SSL etc.. This article covers the introduction, SSL certificate, Encryption, process of encryption and how your browser interact and trust that certificate provided by the website you are visiting.
Existence of SSL
There are basically 2 aspects of SSl. One is Encryption and second is Identification. Now encryption is what you hide the content of the data sent from one machine to another machine. It is done by changing the content of the data in identical to garbage form which is human readable but not human understandable. It is exactly like speaking in different languages with what one person is not familiar. I am Indian if someone speaks in Russian language, it is not understandable by me. So here Russian language is like encrypted language for me. However if I get a translator and he/she translates that Russian language into Hindi then I can say that now that is understandable by me. So it is said that message has been decrypted. Identification is related to trust. In the previous scenario, how can I trust the translator who is converting Russian language to Hindi? Is she/he legitimate ? Can I trust him/her? In the digital world, it is something like this. Your machine has to trust the SSL certificate (security mechanism), provided by the website via an SSL certificate issuing vendor.
Labels:
encryption,
https,
secure http,
ssl,
ssl certificate,
ssl encryption
Subscribe to:
Posts (Atom)