<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4696655655122167049</id><updated>2011-11-28T06:15:49.909+05:30</updated><title type='text'>Information Security Saga</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://infosecsage.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4696655655122167049/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://infosecsage.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Shashank</name><uri>http://www.blogger.com/profile/01783352202320808541</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_ataXKuJ11t8/SqjRnqoK1eI/AAAAAAAABwQ/QFhnja8SSnE/S220/DSC00056.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4696655655122167049.post-3480897238187700851</id><published>2010-03-09T14:54:00.002+05:30</published><updated>2010-03-09T14:57:13.729+05:30</updated><title type='text'>Nice presentation on Enterprise Security</title><content type='html'>The presentation consist of worth knowing information about the State of Enterprise Security. Download it from &lt;a href="http://www.symantec.com/content/en/us/about/presskits/SES_report_Feb2010.pdf"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4696655655122167049-3480897238187700851?l=infosecsage.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecsage.blogspot.com/feeds/3480897238187700851/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infosecsage.blogspot.com/2010/03/nice-presentation-on-enterprise.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4696655655122167049/posts/default/3480897238187700851'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4696655655122167049/posts/default/3480897238187700851'/><link rel='alternate' type='text/html' href='http://infosecsage.blogspot.com/2010/03/nice-presentation-on-enterprise.html' title='Nice presentation on Enterprise Security'/><author><name>Shashank</name><uri>http://www.blogger.com/profile/01783352202320808541</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_ataXKuJ11t8/SqjRnqoK1eI/AAAAAAAABwQ/QFhnja8SSnE/S220/DSC00056.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4696655655122167049.post-8973582623619530694</id><published>2010-02-24T10:45:00.005+05:30</published><updated>2010-02-24T11:25:31.944+05:30</updated><title type='text'>ADS Alternate Data Stream.</title><content type='html'>Alternate data streams (ADS) are a relatively unknown compatibility feature of NTFS. ADS have the ability to fork file data into existing files without affecting their functionality, or size.&lt;br /&gt;&lt;br /&gt;This feature helps an attacker to hide malicious files on victims machine.&lt;br /&gt;&lt;br /&gt;In the screenshot below I have created a test.txt file in ADS directory which already contains nc.exe the malicious executable.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_ataXKuJ11t8/S4S4hCmtcyI/AAAAAAAAB6M/UKi1hISDq3I/s1600-h/1.bmp"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 197px;" src="http://4.bp.blogspot.com/_ataXKuJ11t8/S4S4hCmtcyI/AAAAAAAAB6M/UKi1hISDq3I/s320/1.bmp" border="0" alt=""id="BLOGGER_PHOTO_ID_5441677127544828706" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now I will hide the nc.exe using ADS.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_ataXKuJ11t8/S4S6Q8pqfiI/AAAAAAAAB6U/KxJm_KuahtY/s1600-h/2.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 142px;" src="http://4.bp.blogspot.com/_ataXKuJ11t8/S4S6Q8pqfiI/AAAAAAAAB6U/KxJm_KuahtY/s320/2.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5441679050091953698" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As you can see in the screenshot nc.exe is no where in the ADS directory.&lt;br /&gt;&lt;br /&gt;Now to see the hidden nc.exe in test.txt:malicious.exe run the command &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;start ./test.txt:malicious.exe&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;For more details follow link &lt;a href="http://www.infosecwriters.com/texts.php?op=display&amp;id=53"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4696655655122167049-8973582623619530694?l=infosecsage.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecsage.blogspot.com/feeds/8973582623619530694/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infosecsage.blogspot.com/2010/02/ads-alternate-data-stream.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4696655655122167049/posts/default/8973582623619530694'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4696655655122167049/posts/default/8973582623619530694'/><link rel='alternate' type='text/html' href='http://infosecsage.blogspot.com/2010/02/ads-alternate-data-stream.html' title='ADS Alternate Data Stream.'/><author><name>Shashank</name><uri>http://www.blogger.com/profile/01783352202320808541</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_ataXKuJ11t8/SqjRnqoK1eI/AAAAAAAABwQ/QFhnja8SSnE/S220/DSC00056.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_ataXKuJ11t8/S4S4hCmtcyI/AAAAAAAAB6M/UKi1hISDq3I/s72-c/1.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4696655655122167049.post-1444393972857115536</id><published>2010-02-06T23:14:00.005+05:30</published><updated>2010-02-06T23:24:41.350+05:30</updated><title type='text'>Playing with TOR</title><content type='html'>My friend wanted to listen &lt;a href="http://www.pandora.com/"&gt;Pandora radio&lt;/a&gt;.To make it happen I came across this link and it worked.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.how-to-hide-ip.info/2009/08/08/how-to-use-an-ip-from-a-specific-country-while-running-tor/"&gt;How To Use An IP From A Specific Country While Running Tor&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Also found some useful information. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.how-to-hide-ip.info/2009/02/10/pros-and-cons-of-using-tor/"&gt;Pros and Cons of using Tor&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4696655655122167049-1444393972857115536?l=infosecsage.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecsage.blogspot.com/feeds/1444393972857115536/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infosecsage.blogspot.com/2010/02/playing-with-tor.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4696655655122167049/posts/default/1444393972857115536'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4696655655122167049/posts/default/1444393972857115536'/><link rel='alternate' type='text/html' href='http://infosecsage.blogspot.com/2010/02/playing-with-tor.html' title='Playing with TOR'/><author><name>Shashank</name><uri>http://www.blogger.com/profile/01783352202320808541</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_ataXKuJ11t8/SqjRnqoK1eI/AAAAAAAABwQ/QFhnja8SSnE/S220/DSC00056.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4696655655122167049.post-1900754401753950830</id><published>2010-02-06T21:55:00.007+05:30</published><updated>2010-02-06T22:41:40.135+05:30</updated><title type='text'>Proxychains Nice tool to scan anonymously.</title><content type='html'>Tor is wonderful tool to visit the websites anonymously but what about scanning an IP anonymously.I found this useful tool called as &lt;a href="http://proxychains.sourceforge.net"&gt;proxychains&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;ProxyChains is a tool for TCP tunneling via HTTP/HTTPS and SOCKS4/SOCKS5 proxy servers. It allows to run SSH,VNC,FTP,TELNET or any other program from behind proxy server.&lt;br /&gt;&lt;br /&gt;1. To use it first download it from:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:10;"&gt; &lt;a href="http://proxychains.sourceforge.net/" target="_blank"&gt;http://proxychains.sourceforge.net&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;2. Now we need to unpack ProxyChains:&lt;br /&gt;&lt;br /&gt;hacks# tar -xzvf proxychains-3.1.tar.gz&lt;br /&gt;&lt;br /&gt;You should see a directory named proxychain-3.1. Make this new directory your working directory and issue the following commands at your terminal:&lt;br /&gt;&lt;br /&gt;hacks/proxychains-3.1# ./configure&lt;br /&gt;hacks/proxychains-3.1# make&lt;br /&gt;hacks/proxychains-3.1# make install&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;3. Now, it is ready to use.&lt;br /&gt;&lt;br /&gt;hacks# proxychains nmap -sS 192.168.0.112&lt;br /&gt;&lt;br /&gt;Enjoy the anonymity.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4696655655122167049-1900754401753950830?l=infosecsage.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecsage.blogspot.com/feeds/1900754401753950830/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infosecsage.blogspot.com/2010/02/proxychains-nice-tool-to-scan.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4696655655122167049/posts/default/1900754401753950830'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4696655655122167049/posts/default/1900754401753950830'/><link rel='alternate' type='text/html' href='http://infosecsage.blogspot.com/2010/02/proxychains-nice-tool-to-scan.html' title='Proxychains Nice tool to scan anonymously.'/><author><name>Shashank</name><uri>http://www.blogger.com/profile/01783352202320808541</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_ataXKuJ11t8/SqjRnqoK1eI/AAAAAAAABwQ/QFhnja8SSnE/S220/DSC00056.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4696655655122167049.post-8576623069030825622</id><published>2009-09-10T15:59:00.000+05:30</published><updated>2009-09-10T17:12:02.478+05:30</updated><title type='text'>SANS STAR Comprehensive Packet Analysis...Not a Big Deal</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_ataXKuJ11t8/SqjlJD7vB2I/AAAAAAAABw8/3LnP8oIHja0/s1600-h/star.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 187px;" src="http://2.bp.blogspot.com/_ataXKuJ11t8/SqjlJD7vB2I/AAAAAAAABw8/3LnP8oIHja0/s320/star.JPG" alt="" id="BLOGGER_PHOTO_ID_5379801698731493218" border="0" /&gt;&lt;/a&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Recently I took the SANS STAR Comprehensive Packet Analysis Exam.This exam is basically targeted for Incident Response analysts, firewall and network administrators, analysts responsible for packet and network analysis and packet stream recovery. I am happy with scoring 100 p c. For the listing visit the link below.&lt;br /&gt;&lt;/div&gt;&lt;a href="http://www.giac.org/star/listings/Security/556"&gt;&lt;br /&gt;http://www.giac.org/star/listings/Security/556&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4696655655122167049-8576623069030825622?l=infosecsage.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecsage.blogspot.com/feeds/8576623069030825622/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infosecsage.blogspot.com/2009/09/sans-star-comprehensive-packet.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4696655655122167049/posts/default/8576623069030825622'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4696655655122167049/posts/default/8576623069030825622'/><link rel='alternate' type='text/html' href='http://infosecsage.blogspot.com/2009/09/sans-star-comprehensive-packet.html' title='SANS STAR Comprehensive Packet Analysis...Not a Big Deal'/><author><name>Shashank</name><uri>http://www.blogger.com/profile/01783352202320808541</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_ataXKuJ11t8/SqjRnqoK1eI/AAAAAAAABwQ/QFhnja8SSnE/S220/DSC00056.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_ataXKuJ11t8/SqjlJD7vB2I/AAAAAAAABw8/3LnP8oIHja0/s72-c/star.JPG' height='72' width='72'/><thr:total>1</thr:total></entry></feed>
