Dangerous Malware Has the Ability to Root Your Smartphones

A new malicious adware is here to make your lives harder. Kemoge adware has the ability to do some serious damage to your precious smartphone by rooting it and then flooding it with tons of ads.


There is no dearth of malware that are designed to serve unwanted ads in your mobile phone and steal your user information. Some of them just stick to severing tons of ads and don’t cause any harm. The security firm FireEye has reported a malware that belongs to the other class.

The malicious adware, dubbed Kemoge, can do some serious damage to your Android phones. Apart from serving the intrusive ads, Kemoge has the ability to root your devices and make them more vulnerable to attacks.

Just like every other malware and adware, Kemoge spreads by hiding itself under the hood of some popular app. Then via the route of 3rd-party app stores, it reaches the smartphones of users and starts causing the harm.


It should be noted that if you are downloading the apps from stores other than Google Play store, you need to be extra careful as they don’t employ the security steps taken by Google.


Here’s a flowchart that shows how Kemoge adware works and its lifecycle. In the first step, using third party apps app stores and web/ad promoted installation, the malicious adware gets installed on phones.


In the second step, the adware collects local info collection for aggressive ad serving and then roots the device. After opening the back door for exploits, the adware can remotely control the app, allowing app installations, uninstall and launching any app.

The Kemoge adware is infecting the smartphones over 20 countries and it’s possible that it originated from China.

The users are advised users not to install apps from 3rd-party sites. You should also keep your phones up to date to close these known root exploits.

Friday, 9 October 2015
Posted by Sivapriya
Tag :

What Is the Difference: Viruses, Worms, Ransomware, Trojans, Bots, Malware, Spyware.

If you are among the ones who consider malware, worms, viruses to be the same thing then you’re on the wrong track. Read further, and improve your knowledge about these terms.

If you’re a regular or even an occasional computer user, then you might’ve heard the terms like Viruses, Worms, Trojans, Bots, Malware, Spyware, etc. But honestly speaking, we consider all these to be a Virus, no matter, whatever be their type. But have you ever tried to acknowledge, what is the difference between these terms, although they are meant to harm your device, steal your data or spy on you, have you ever thought why they are named so differently. Basically, terms like Viruses, Trojans are all types of malicious software or simply ‘Malware’.

Now, the first and foremost question arises, where did these terms came from?

Clearly, they are not some out of the world aliens, in fact the real truth is that they were not even created with an intention to harm someone.

The history of malware attacks goes back to 1949, when John von Neumann, first developed the theoretical base for self-duplicating automation programs, but the technical implementation was not feasible at that time. The term ‘Computer Virus’ was first used by Professor Leonard M. Adleman in 1981, while in conversation with Fred Cohen.

The first computer virus named ‘Brain’ was coded by two brothers Basit Farooq Alvi and Amjad Farooq Alvi, who were from Lahore, Pakistan. Brain was meant to infect storage media based on MS-DOS FAT file systems. It was originally designed to infect the IBM PC, it replaced the boot sector of its floppy disk with the virus. The virus program changed the disk label to ©Brain and the defected boot sectors displayed this message:

Welcome to the Dungeon (c) 1986 Basit & Amjads (pvt) Ltd VIRUS_SHOE RECORD V9.0 Dedicated to the dynamic memories of millions of viruses who are no longer with us today – Thanks GOODNESS!! BEWARE OF THE er..VIRUS : this program is catching program follows after these messages….$#@%$@!!

However, as you may presume, there was no evil intention behind this. Alvi brothers said in their interview with TIME magazine, they created the virus only to protect their medical software from piracy, aimed at copyright infringement acts.

Coming back to Malware, these are malicious software designed to harm a computer which may or may not be connected to a network. Malware only get in to action when there is a computer involved in the game otherwise the term Malware is of no use.



Malware are of the following types:

Worms: These programs have the ability to replicate themselves. Their sole objective is to increase their population and transfer themselves to another computers via the internet or through storage media, all the work is done like a top secret mission hiding their movement from the user. They don’t cause any harm to the computer, their replicating nature consumes hard drive space, thus slow down the machine. Some of the notable worms are, SQL Blaster which slowed the internet for a small period of time, Code Red took down almost 359,000 websites.

Viruses: They also have the ability to replicate themselves, but they do damage files on the computer they attack. Their main weakness lies in the fact, they can get into action only if they have the support of a host program, otherwise they’re just like a defeated warrior. They stick themselves to songs, videos, and executable files and travel all over the internet. W32.Sfc!mod, ABAP.Rivpas.A, Accept.3773 are some of the examples of Virus programs.

The Virus Gang:

  • File Viruses
  • Macro Viruses
  • Master Boot Record Viruses
  • Boot sector Viruses
  • Multi-Partite Viruses
  • Polymorphic Viruses
  • Stealth Viruses

Feel free to Google anyone of them if you like.

Trojans: Basically, Trojans are no Viruses, and are not meant to damage or delete files on your system. Their sole task is to provide to a backdoor gateway for malicious programs or malevolent users to enter your system and steal your valuable data without your knowledge and permission. JS.Debeski.Trojan is an example of Trojan.

They are named after the ‘Trojan Horse’ tale, in which Greeks entered the city of Troy with the help of a wooden horse which was meant to be a gift, but turned out to be a sweet poison, as depicted in the movie Troy.

The Trojan Gang:

  • Remote Access Trojans
  • Data Sending Trojans
  • Destructive Trojans
  • Proxy Trojans
  • FTP Trojans
  • Security Software Disabler Trojans
  • Denial-Of-Service Attack Trojan

Adware: Adware are used to display advertisements in the programs. They generally come attached with software programs that are free to use as they are the only source of revenue for the developers of those software programs. Adware can’t be completely called as Malware as they have no intention to harm your machine, they only track what advertisements you’re more interested in, so as to display the relevant advertisements on your screens.

Spyware: These programs also come attached with other freeware software, track your browsing and other personal details and send it to a remote user. They can also facilitate installation of unwanted software from the internet. Unlike Adware, they work as a standalone program and do their operations silently.

Spam: You get very irritated when you receive unwanted emails from unknown senders, these are called Spams or junk mails. And the process of flooding the internet with the same message is called Spamming, is done for the purpose of commercial advertising. These junk mails may sometimes contain Viruses or Trojans that enter your system as soon as you open the mail.

Bots: Bots or Robots are automated processes that are designed to interact over the internet without the need of human interaction. They can be used for good and bad intentions. An evil minded person can create a malicious Bot that is capable of infecting the host on its own. After transmitting itself to the host device, a Bot creates a connection with central servers which act as the command centers for the infected hosts attached to that network, called Botnet.

Their skills include stealing passwords, logging keystrokes, analyzing network traffic, relay spam, launch DoS (Denial of Service) attacks and open back doors on infected hosts. These Bots can be seen as the advanced form of Worms, their infection rate and tactic is more effective than those of Worms. These malicious Bots are created after a lot of hard work done by their malignant creators.

Ransomware: These type of malware alter the normal operation of your machine, thus barring you to use it properly. Thereafter, these programs display warning messages asking for money to get your device back to normal working condition.

After reading all this, you might be thinking why people create Malware. Here are some reasons which may compel a coder to write malware codes:

  • Take control of a person’s computer for personal or professional reasons.
  • To get financial benefits.
  • To steel confidential data.
  • To prove their point regarding a security breach can be done on a system.
  • To take down an individual computer or a complete network.

and many more….

How can you protect your Computer :

  • Keep your system up to date.
  • Use genuine software.
  • Install an antivirus software and update it regularly.
  • Set-up a firewall, may it be custom as provided by antivirus software. Windows has an in-built firewall option in case you don’t want to use a custom firewall.
  • Never open unknown emails that generally reside in your Spam folder.
  • Never open unknown links, use online website safety checker tools if you’re not sure to open a website.

By taking these simple measures, you can effectively keep your machine free from Malware and other potential threats.
Thursday, 8 October 2015
Posted by Sivapriya
Tag :

How to Protect Your Wi-Fi Router From Hacking Using Simple Tricks



These are the times when anything and everything digital is prone to hack. From ATM to connected cars, and from satellites to the so-called secured government offices, hackers are laughing all the way. So, the blatant use of the specification “unhackable”, which today, has become the USP for the products by almost all the brands, doesn’t come as a surprise.
Many people are now aware and take good measures for their online safety, but safeguarding the Wi-Fi router still lies low at the priority list of the most. The reasons may range from lack of knowledge to mere carelessness, but your home router’s security is as important as your front door’s because it is the foremost target of hackers trying to invade through your system.
Now, as you might be knowing How to Increase Your Wi-Fi speed by choosing correct Wi-Fi Channel, here are the simple ways to strengthen your Wi-Fi router’s security from hack attacks.
1. Enable WPA2 (WI-Fi Protected Access)
Ok, this is the first and foremost thing to do for everyone who has or plans to buy a router. It provides encryption to your system and its variant WPA-PSK can be found in home networks. Those who use old routers, they might be having WEP or Wired Equivalent Privacy security, and trust us, it is no better than zero security.
2. Create a Strong SSID Network Name
Do not use the router’s default network name like D-Link or Netgear. Hackers have specific tools like rainbow table to bust into your network just by knowing your default SSID name.
3. Use a Strong Password or Passphrase Maybe
Well, no talk on security can circumvent the importance of strong passwords. Do you know if you increase your password’s length to just one more character, the chances of the hacker cracking your code with probabilistic ways are reduced by hundreds. (I’m just being modest, it is way too high).
4. Firewall of Your Router
Well, if you have it, then Use it. It is the router’s inbuilt protection system to make it somewhat obscure from the hacker’s view. Also, new routers come with ‘stealth mode’ firewalls.
5. Turn Off UPnP
The Universal Plug and Play protocol (UPnP) which is meant to establish easy connection with devices in the vicinity can make your router vulnerable and make it a potential target for the hackers (results could be DoS attacks as well).
Not all the routers are susceptible to UPnP exploitation, but why take the risk.
6. Use VPN
A personalized VPN service for your router is the way to go if you are willing to shed a few bucks for your important data. VPN works by giving your location anonymity on its server and even creates its own firewall to protect your network traffic.
Also, VPN is a better alternative than the router’s remote management feature which exposes its web-based interface on the Internet.
7. Enable Logging Feature
The logging feature in your router keeps an account of the log attempts  from all IP addresses and give you all the connection attempt details. This could help you monitor any ongoing suspicious activity.
8. Use Security Services
You can also use cloud-based security services like OpenDNS to screen the traffic through your router. You simply have to configure your network to the online service’s nameserver rather than those used by your ISP.
These web-based services help you to monitor as well as encrypt the traffic through your router.
Although, you can’t make your device hack proof, but with these simple techniques you could make your router safer than it was before.
Wednesday, 30 September 2015
Posted by Sivapriya
Tag :

Configure Terminal Server

Configure Terminal Server



1. Configure an IP address on the ethernet interface
cisco(config)# int fa0/0
cisco(config-if)# ip add 192.168.1.50 255.255.255.0
cisco(config-if)# no shut

2. Create a loopback interface
cisco(config)# int lo0
cisco(config-if)# ip add 1.1.1.1 255.0.0.0

3. Configure the line based on the “show line” output. 
* If enabled, the port will be accessible through the network on TCP port 20xx where xx is the TTY of the port on the router
cisco(config)# line 1 16
cisco(config-line)# no exec  //unwanted signals from the attached device do not launch.
cisco(config-line)# exec-timeout 0 0 //disable the line timeout period
cisco(config-line)# logging synchronous
cisco(config-line)# transport input all 

4. Configure default route
cisco(config)# ip route 0.0.0.0 0.0.0.0 192.168.1.1
cisco(config)# ip default-gateway 192.168.1.1  
// ip default-gateway is configured as well in case routing is not enabled. E.g. the terminal server is in ROMMON mode as a result of a bad reboot after power outage.

5. Enable telnet line
cisco(config)# line vty 0 4
cisco(config-line)# password cisco
cisco(config-line)# login

6. Configure host and line mapping
*e.g. Router A is connected to line 1
cisco(config)# ip host RouterA 2001 1.1.1.1



Thursday, 2 July 2015
Posted by Anonymous

How to use VPCS with GNS3 in Ubuntu

How to use VPCS with GNS3 in Ubuntu

1.Download vpcs from here VPCS 0.20a

2.Extract and look for vpcs32.linux(for 32-bit systems) and vpcs64.linux (for 64-bit systems)

3.Fire up the Terminal and issue following command 
chmod +x vpcs32.linux

4.Then we'll open and configure startup.vpc in gedit 

gedit startup.vpc 


5.Now configure startup.vpc according to your requirement. For example I'll add just two hosts for this tutorial.
Host 1 (VPCS1) with Ip 192.168.1.10/24 and 192.168.1.99 as its gateway.
Host 2 (VPCS2) with Ip 192.168.1.11/24 and 192.168.1.99 as its gateway.

** add # to the rest of the lines.


6.Now lets start VPCS by issuing the following command within the terminal.
 ./vpcs32.linux

7.Use show command to see all the configured ip addresses.


8. We are done with VPCS configuration part, minimize the vpcs window, and lets configure port settings for VPCS on GNS3.

Fire up GNS3 (run gns3 as a root).

9.This is a optional step where I'll be adding symbols to PC hosts.


10.Add computer symbol from 'available symbol' to 'customized nodes'
    on name = anyname ie, PC1
    on type  = Cloud
    click ok
Do the same for PC2


11.Drag and Drop PC1 and PC2 into the GNS3 Workboard.
    Double click on PC1
    click on 'C1'
    go to tab 'NIO UDP'
    hold....
    go back to Step 7
    Check the LPORT and RPORT

12.On Local port add rport value
    on Remote port add lport value
    on Remote host add 127.0.0.1
    click add
    Do the same for PC2 (again check the respective ports)



13. Lets add a Ethernet switch to the GNS3 workboard and check the connectivity between the two hosts.
  

14. Maximize vpcs window and lets ping to each host to check the connectivity between them.
     To navigate from 1 pc to another, simply type the number


As you see, a successful connectivity has been established between the two hosts.  

Wednesday, 1 July 2015
Posted by Anonymous

Enable SSH in Switch And Router

Enable SSH in Switch And Router


Assuming the IP address, enable password and default route are in place, the additional steps needed are as follows:

1. Configure a domain name
cisco(config)# ip domain-name cisco.com

2. Configure the RSA key generation for encryption
cisco(config)# crypto key generate rsa
* it may prompt user for the key length generated in the range of 360 to 2048. Default is 512-bit.

3. Configure authentication method
a) Using local database
cisco(config)# username cisco password cisco

OR

b) Using Radius server
cisco(config)# aaa new-model
cisco(config)# aaa authentication login Radius_Server group radius
cisco(config)# radius-server host 192.168.1.155

4. Configure the terminal line
cisco(config)# line vty 0 4
cisco(config-line)# login local                                            // using local database

OR

cisco(config-line)# login authentication Radius_Server          //using radius server
cisco(config-line)# transport input ssh

Monday, 29 June 2015
Posted by Anonymous
Tag :

How To Run Linux Router Vyatta in GNS3

How to run Linux Router Vyatta in GNS3

What is the Vyatta ?
Vyatta is bringing innovation and affordability to the networking industry by delivering advanced routing and security in a software-based network OS that scales from the branch office to the service provider edge. Vyatta has decoupled networking software from proprietary hardware allowing users to leverage the price and performance advantages of standard x86-based hardware and components as well as Citrix XenServer and VMWare virtual or cloud environments.
http://www.vyatta.com/

In this tutorial brezular shows us how to install Vyatta 6.1 Core LiveCD on Qemu image and run it from GNS3.

1. Download Vyatta Core 6.1 LiveCD iso (You need to fill short questionnaire for Vyatta download)

Vyatta download    http://www.vyatta.com/downloads/index.php

2. Create Qemu qcow2 image

/usr/local/bin/qemu-img create -f qcow2 ./vyatta6.1vc.img 1G

3. Boot Qemu image with Vyatta 6.1 LiveCD

 /usr/local/bin/qemu -boot d -hda ./vyatta6.1vc.img -cdrom ./vyatta-livecd_VC6.1-2010.08.20_i386.iso -m 512

login/password: vyatta/vyatta

4. Install Live CD

To install Live CD to Qemu image enter this command (as user vyatta)

install-system

The tutorial is opened and it walk you through installation process:

Would you like to continue? (Yes/No) [YES]: Enter

Partition (Auto/Union/Parted/Skip) [Auto]: Enter

Install the image on? [sda]: Enter

This will destroy all data on /dev/sda. 
Continue? (Yes/No) [No]: Yes

How big of root partition should I create? (1000MB – 1074MB) [1074]MB: Enter

I found the following configuration files 
/opt/vyatta/etc/config/config.boot 
Which one should I copy to sda? [/opt/vyatta/etc/config/config.boot] Enter

Enter password for administrator account 
Enter vyatta password: your_password 
Retype vyatta password: your_password

Which drive should GRUB modify the boot partition on? [sda]: Enter

Done! 
Now you successfully install Vyatta.

5. Adapt Vyatta NIC behavior to GNS3 Qemuwrapper

GNS3 qemuwrapper always changes MAC address of presented NIC during the boot of Qemu instance. Vyatta is programmed to save MAC address of existing ethernet interfaces. If MAC address of particular NIC is changed (by GNS3 qemuwrapper) Vyatta preserves the interface with old MAC and create new interface with new MAC. 

Each time Qemu instace is restarted the number of interfaces doubled.

These are my steps how to solve it (it must be a better solution but I didn’t find any with Google search):

a) Enable root account on Vyatta 6.1

thank to Tim Peerlings blog   http://www.timpeerlings.nl/enable-root-account-on-vyatta-6-1/

vyatta$ configure 
vyatta#set system login user root authentication plaintext-password test 
vayata# commit 
vyatta# save

exit

Now you should switch to user root:

su 
Password: test

b) Remove vyatta_net_name script (root account needed)

cd /lib/udev/ 
mv ./vyatta_net_name ./vyatta_net_name_backup 
rm ./vyatta_net_name

6. Setup serial console login 

thanks to Petr’s blog    http://linux.xvx.cz/2009/08/debian-with-grub2-and-serial-connection/ 

This configuration redirects output to serial ttyS0 and allows you to use Console in GNS3. 
Login as root with su command and modify grub configuration file:

vim /etc/default/grub

Change the lines in configuration file according to these lines
# This file is sourced by update-grub, and its variables are propagated 
# to its children in /etc/grub.d/

GRUB_DEFAULT=0 
GRUB_TIMEOUT=0 
GRUB_DISTRIBUTOR=`lsb_release -i -s 2> /dev/null || echo Debian` 
GRUB_CMDLINE_LINUX_DEFAULT=”console=tty0 console=ttyS0,9600n8″

# Uncomment to disable graphical terminal (grub-pc only) 
GRUB_TERMINAL=serial 
GRUB_SERIAL_COMMAND=”serial –speed=9600 –unit=0 –word=8 –parity=no –stop=1″

# Uncomment if you don’t want GRUB to pass “root=UUID=xxx” parameter to Linux 
#GRUB_DISABLE_LINUX_UUID=true
Now update grub with command:

update-grub

7. Setup GNS3 for Vyatta qemu image

- Start GNS3 
- Edit-> Preferences-> Qemu-> Qemu Host

Check Kvm option only if your processor supports hardware virtualization. Check Kqemu option only if it is installed and running. If you are not sure with these options let them unchecked otherwise Qemu will be not started.

You need also set Qemu general settings like path to qemu, qemu-img and qemuwrapper.

- Edit-> Preferences-> Qemu-> General Settings

Login to Vyatta:
login/password: vyatta/your_password

8. Conclusion
Brezular has  made a video to prove functionality of Yvatta Qemu image. In this video three Vyatta Qemu instances run RIP routing protocol.

Tuesday, 23 June 2015
Posted by Anonymous
Tag :

widget

Pageviews

Cloud Label

Blogumulus by Roy Tanck and Amanda Fazani

- Copyright © 2013 Redback IT Academy -- Powered by Redback - Designed by @ Redback Studio -