Showing posts with label Network. Show all posts
Showing posts with label Network. Show all posts

Thursday, July 5, 2007

Computer threat - continued

Another threat to the computer and network as follows:

Denial of Service (DoS)
    This type entangling the hacker and or a certain party to send a number of ICMP echo request to the broadcast address. Remember that the address of sender request have been disguised so difficult to tracks.
    Protection to the network can be done by selection to the reciprocation of ICMP echo, another way is do not activate the directed broadcast at the router. Permit out package only and the sender address same with internal network address. This is important to the network security
    The other level of Denial of Service(DoS) is Distributed Denial of Service (DDoS).
    This type will increase the traffic and combine the bandwidth from some of host to one target host or network.
Spoofing
    Is the creation of TCP/IP packets using somebody else's IP address. Routers use the "destination IP" address in order to forward packets through the Internet, but ignore the "source IP" address. That address is only used by the destination machine when it responds back to the source.
Broadcast Amplification
    By using broadcast amplification, an attacker can direct machines at one site to flood another site with network packets. If huge amounts of packets are sent to a site, it goes down under the load, causing denial of service. To prevent this technique from being used, the document's authors suggest that companies turn off the capability to forward directed broadcast or multicast traffic.
TCP SYN attack
    is an attack based on bogus TCP connection requests, created with a spoofed source IP address, sent to the attacked system. Connections are not completed, thus soon it will fill up the connection request table of the attacked system, preventing it from accepting any further valid connection request.

    The source host for the attack sends a SYN packet to the target host. The target hosts replies with a SYN/ACK back to the legitimate user of the forged IP source address.

    Since the spoofed source IP address is unreachable, the attacked system will never receive the corresponding ACK packets in return, and the connection request table on the

    Attacked system will soon be filled up.The attack works if the spoofed source IP address is not reachable by the attacked system. If the spoofed source IP address where reachable by the attacked system, then the legitimate owner of the source IP address would respond with a RST packet back to the target host, closing the connection and defeating the attack.

    TCP SYN flood is a denial of service attack that sends a host more TCP SYN packets than the protocol implementation can handle.

    This is a resource starvation DoS attack because once the connection table is full, the server is unable to service legitimate requests.

Friday, June 29, 2007

Computer threat - Network Security

Every TCP package have 'flag bit’ defining content and intention of each package.

Example:
    A package with flag bit contain "SYN or SYNCHRONIZE" will undertake to conduct initiation connection from sender to recipient. A package with flag bit contain "ACK" will undertake to inform receiver about sender information.
    While a TCP package with beet flag contain "FIN" or "FINISH" undertaking to stop connection from sender to recipient.
To build a TCP connection, need data transfer package between two host, transfer of this data recognized by the name of "TCP Three-Way Handshake" as below picture.


Computer Network Threat

Threat is very harmful to the entire system and also by application at internal and external network.

The threat as follows:

Remote Login - this matter happened when someone capable to connect to a computer and have ability to control to several things related to resource found on the host or computer.

Application Backdoors - some program have special ability to access with long distance (remote access). Some bug program, exactly contain a backdoor or hidden access providing level control the computer and program.

SMTP session hijacking - SMTP is most commonly method used to deliver E-mail. By getting E-mail mailing-list, someone can deliver undesirable E-mail to thousands of or more users. This matter is called unsolicited junk mail or spam.

Spamming conducted with joining SMTP server which not suspect, then deliver thousands of E-mail called redirecting process, so that complicate to detect who is the real sender of the Mail Spam.

Operating system bugs – In application, some operation system have conducive security gap to be exploited illegally.

E-mail bombs - is an Individual attack, someone send hundreds or thousands of E-mail to one address so the victim E-mail cannot accept E-mail anymore.

Macro - To make simple or facilitate procedure an application, many application program permit us to make command which can be run by the program (script). By exploiting ability of script or macro, attacker can cause damage of data at computer.

Virus – Most known to make trouble at computer. The growth of virus from method, way of, making, effectiveness, damage storey, and also speed of spreading is different each other.

Redirect bombs – Hacker or Cracker can use ICMP to change direction of information and attack to other router.

Source routing - At many case, a data package which work through one or some network determined by router pass to route information by the router, but sometime hacker used the package as the real sender.

Another type of computer attack are from (next posted about this) :
    Denial of Service (DoS)
    Spoofing
    Broadcast Amplification
    TCP SYN

The method to run the threat above, can be conducted variously including using virus.

Monday, June 25, 2007

Network security - protecting PC

Tapping by hacker is an annoying problem when we are on surfing internet.

We have to learn how to hack but shall be used for protection from attack.

Following is tips and some software assisting to protect PC from online tapping.

Often we forget to protect our PC “attacking” from online tapping when we surf the internet.

Many civil people feel enough in protecting its PC with a program a kind of firewall desktop and anti spy firewall.


In fact, still many gap at firewall which you used, can be exploited by online watcher hacking on your PC

Below is a tips to protect PC from internet tapping in a LAN party, W-LAN or home connection as my experience.

Activated your Firewall:
In course of online tapping or infection, usually the first step do by hacker is collect information and data concerning victim to be tapped. Usually hacker use information compiler tools like “ Nmap” ( http://www.insecure.org/nmap), hereinafter hacker will check open port at victim PC and also TCP/IP package sent from PC into Network. This matter to get specific information is called print finger from victim PC.



The others way, hacker usually try to get deeper information by delivering an E-mail bait to victim (victim will open the e-mail through Microsoft Outlook program which integrated in its Windows). From bait E-mail answered, hence hacker directly can check what kind of E-mail software and server client install in victim PC.

A lot of “software bug” site, discuss about weak of E-mail software and server client according to each version, but I’m not talking about that weak at this post.

So how to avoid that attack ?
The way of which you can use as protection early is firewall desktop. If you do not wish to use special firewall or commercial, hence you enough activate personal firewall that found on Windows XP service pack 2. Comprehend firewall application path and activity which you use in order not to harm you.

Ascertaining your pc clear of Virus and Trojan, before install the firewall.
Configure your firewall with carefully in each application requiring to access online and also access sharing file in existing network.

Encrypt the Important Folder and WebMail connection.
After getting information about victim PC, usually hacker can start tapping, it is of course with two important tools that is " Ethereal" and "ARP-Spoofer". With ARP-Spoofer, hacker can take information which pass by victim PC with Gateway Internet access and that information package can be opened with “Ethereal (http://www.ethereal.com)”.

To overcome matter above, we have to encrypt our Webmail connection through https band. Do not use http band, better avoid to use ftp band and telnet, because can be sabotaged by hacker. You can use SSH connection to replace ftp band or the telnet. The existing constraint is there is very rare web server providing https service and the SSH.

One of the common Mail which use HTTPS is GMail. Whereas for the important and confidential folder in the PC better do Encrypt. Its data content with right click on folder that you want to Encrypt, its way open part: Properties – Advanced – Encrypt content to protect data. But this matter can be done if your XP windows system file is use NTFS type. By use NTFS system file, we also can block out to access rights access certain consumer.

Use Good Firewall.
With DNS spoofing, hacker can do deflection instructing PC victim to spurious website. This deflection is easy to do because DNS protocol is not have any security mechanism. This matter can be prevented by using good firewall application.

At firewall nowadays, usually DNS cache keep with elegantly, so when we ever visit to previous website, hence DNS spoofing we can prevent.

Recognize to access autoexec at registry
If hacker have succeeded tap your pc, usually they always prepare backdoor to facilitate hacking access in other opportunity. One of the effort draw up backdoor is by altering victim pc system file. But this matter can be easy to detect to through antivirus program.

The way of more realistic to all hacker by placing Trojan in our PC, then run through one of the "Autoexec" what running with autoexec in other Windows system. In anticipating this matter, which we do with install additional tools “Autorun” from Sysinternalsi (http://www.systernals.com).

With this tool can display lot of autoexec exist in our system. Autoruns also can show signature from autoexec exist in our pc system. If found autoexec entry which unknown and identify as trigger Trojan, hence Autoruns can turn off it. With this tool, we assisted in eliminating against backdoor which is possible left by hacker in our pc.

Besides trick above, to avoid tapping, suggested do not use User Administrator when surf in internet, then arrange your explorer internet security setting to High Level Security setting.

And don't forget to always Update your Windows, especially when newest update improve many Security system on your PC.

Monday, June 4, 2007

Internet Protocol keyword

Most Windows have the ability to define Internet Protocol (IP) packet filters for protocol numbers. IP packet filters are commonly used to restrict traffic in and out of each interface.

We used this Protocol number to configure firewalls, routers and proxy. Next session i want to write about network firewall. This is as reference only, so if you want to know more about this visit the associated, like Microsoft, cisco, etc..etc


Internet Protocol Number:

Decimal

Keyword

Protocol

0


Reserved

1

ICMP

Internet Control Message

2

IGMP

Internet Group Management

3

GGP

Gateway-To-Gateway

4

IP

IP in IP (Encapsulation)

5

ST

Stream

6

TCP

Transmission Control

7

UCL

UCL

8

EGP

Exterior Gateway Protocol

9

IGP

Any Private Interior Gateway

10

BBN-RCC-MON

BBN RCC Monitoring

11

NVP-II

Network Voice Protocol

12

PUP

PUP

13

ARGUS

ARGUS

14

EMCON

EMCON

15

XNET

Cross Net Debugger

16

CHAOS

Chaos

17

UDP

User Datagram

18

MUX

Multiplexing

19

DCN-MEAS

DCN Measurement Subsystems

20

HMP

Host Monitoring

21

PRM

Packet Radio Measurement

2

XNS-IDP

Xerox NS IDP

23

TRUNK-1

Trunk-1

24

TRUNK-2

Trunk-2

25

LEAF-1

LEAF-1

26

LEAF-2

LEAF2

27

RDP

Reliable Data Protocol

28

IRTP

Internet Reliable Transaction

29

ISO-TP4

ISO Transport Protocol Class 4

30

NETBLT

Bulk Data Transfer Protocol

31

MFE-NSP

MFE Network Services Protocol

32

MERIT-INP

MERIT Internodal Protocol

33

SEP

Sequential Exchange Protocol

34

3PC

Third Party Connect Protocol

35

IDPR

Inter-Domain Policy Routing Protocol

36

XTP

XTP

37

DDP

Datagram Delivery Protocol

38

IDPR-CMTP

IDPR Control Message Transport Protocol

39

TP++

TP++ Transport Protocol

40

IL

IL Transport Protocol

41

SIP

Simple Internet Protocol

42

SDRP

Source Demand Routing Protocol

43

SIP-SR

SIP Source Route

44

SIP-FRAG

SIP Fragment

45

IDRP

Inter Domain Routing Protocol

46

RSVP

Reservation Protocol

47

GRE

General Routing Encapsulation

48

MHRP

Mobile Host Routing Protocol

49

BNA

BNA

50

SIPP-ESP

SIPP Encap Security Payload

51

SIPP-AH

SIPP Authentication Header

52

I-NLSP

Integrated Net Layer Security TUBA

53

SWIPE

IP With Encryption

54

NHRP

NBMA Next Hoop Resolution Protocol

55 - 60


Unassigned

61


Any Host Internal Protocol

62

CFTP

CFTP

63


Any Local Network

64

SAT-EXPAK

SATNET and Backroom EXPAK

65

KRYPTOLAN

Kryptolan

66

RVD

MIT Remote Virtual Disk Protocol

67

IPPC

Internet Pluribus Packet Core

68


Any distributed File System

69

SAT-MON

SATNET Monitoring

70

VISA

VISA Protocol

71

IPCV

Internet Packet Core Utility

72

CPNX

Computer Protocol Network Executive

73

CPHB

Computer Protocol Heart Beat

74

WSN

Wang Span Network

75

PVP

Packet Video Protocol

76

BR-SAT-MON

Backroom SATNET Monitoring

77

SUN-ND

SUN ND PROTOCOL-Temporary

78

WB-MON

WIDEBAND Monitoring

79

WB-EXPAK

WIDEBAND Expak

80

ISO-IP

ISO Internet Protocol

81

VMTP

VMTP

82

SECURE-VMTP

Secure - VMTP

83

VINES

VINES

84

TTP

TTP

85

NSFNET-IGP

NSFNET-IGP

86

DGP

Dissimilar Gateway Protocol

87

TCF

TCF

88

IGRP

IGRP

89

OSPFIGP

OSPFIGP

90

SPRITE-RPC

Sprite RPC Protocol

91

LARP

Locus Address Resolution Protocol

92

MTP

Multicast Transport Protocol

93

AX.25

AX.25 Frames

94

IPIP

IP-within-IP Encapsulation Protocol

95

MICP

Mobile Internetworking Control Pro

96

SCC-SP

Semaphore Communication Sec. Pro

97

ETHERIP

Ethernet-within-IP Encapsulation

98

ENCAP

Encapsulation Header

99


Any Private Encryption Scheme

100

GMTP

GMTP

101-254


Unassigned

255


Reserved






Saturday, June 2, 2007

Blog reaction exchange

The intention of tagged train or exchange link is to increase your Technorati rating as well as your Google PR and other search engines. That's why every blogger need to exchange link with others blog.

On my review a view month ago, Most bloggers I know have great trouble exchanging links with other blogs, this is also happened with me. So I Just developed this strategy and this strategy called "Blog reaction exchange". It's simple to set up and in theory will work extremely well (if you do as well the blog reaction will shown soon, and the link post will shown under "link to this post" in your joining content), so must leave comment and leave your content posted address once you joined. We need that participants visit yours and leave comment on your joining post.

The rule:

  • Tell on your posted, you are invited by whom and make a little bit about his/her blog as introduce, but remember, make the link point to the content, not to home site(i.e: I was invited by: Beyond Technology etc..etc...) see the link: http://it-matters-job.blogspot.com/2007/06/blog-reaction.html)

  • Make tag that you think would like to participate. Write a little bit about your friends blog.(for example:My tag - Only GOD keeps me going. This is talking about etc..etc, Or Why you invite him/her and tell a little bit about your friend blog, whatever belong to their blog

  • Every your new blog reaction from this train must visit and leave comment in related content

  • Please do not copy and paste about this post, you have to rewrite and make something different. As my review, when Google detect duplicate post it will be impact to our page rank.

  • Make your rule, but point 1,2,4 must included, because this is my rule abut blog friends promotion or just follow my rule but remember point 4
So, now this is my promotion blog, to make their blog reaction:
  • [B][E][A][U][T][I][F][U][L]
    This is a blog who love shopping, a lot of interested things on her blog. She is very welcome to the visitor, especially who leave comment. Check it now..!

  • Nastasshea
    This is about her fairy tale, Something fun on her blog, her posted is unpredictable. That's why i often visit her blog. Visit now and you can found a different out there.

  • Wildheart's Work...
    Her name is Joe Cheray, She is the owner and manager of Kansans and Friends In Weight Loss. This is her miscellanious creative works blog. She just tagged me with anothers train.

  • C e l l T e c h H u b . . .
    This blog covers a wide range of topics - from 2G/3G network insights to value added service implementation in cellular systems,from SS7 signaling basics to the most recent 3G mobile phone reviews

  • Bajaenergy / Energy BLOG
    It is an Energy Data Warehouse, you can find news, stats, reports, interviews, videos, etc .. all update to students, companies, universities, whatever who likes to know more about energy sector.

  • A Nice Place In The Sun
    She is a children's writer working on the publication of two easy readers! While researching agents, books, publishers, and writing. She decided to start a blog for parents about children's books, with articles of interest to parents, and book reviews. So visit her..!

  • Cafe Noche - by Miss Nice
    She is my new friend and members in my MyBlogLog community. The 1st thing that I remember from her is the description of her blog "Whatever matters to me gets put up on my blog". I Like the posted about Dubai, nice place for vacation.

  • Free Books Yaro Starak - By Jennie VW
    This Blog all material from E-Book Yaro Starak. Tips for Blogger to earn Money. She has a tips to earn money on blog. Why you blog?, what is your Goal? and how to make money online?. This is the content you can found out there. Even her blog just started, i like to shared and get blog succeed with her. Do you?

  • I Love Tangerine! - By Sleeping Princes
    She is a twisted little loony in a whirl of confusion. The descriptions of this blog is "Of all the pain, the greatest pain is to love, but to love in vain" This is her another blog, Her permanent blog is : Sleeping Princess, so want to know her site?

  • Odlum Online - Web Page Design For Everyone - By Andrew Odlum
    Odlum Online is devoted to exploring the internet and explaining all of the elements of web page design in an easy to understand way. Come learn along with him as he will try to make web page design accessible to everyone.

  • Love Forever
    FAITH, HOPE, LOVE, THESE THREE, BUT THE GREATEST OF THESE IS LOVE. WHAT IS THAT LOVE TRUTHFULLY? PLEASE CLICK AND READ "LOVE" IN BLOG ARCHIVE. Thank's...! "This Blog contain about love and some module study about problem of which can assist others as one of the forming of love.

  • Il protagonista
    This is about personal Blog

  • Flexible life
    Life is easy. Handle it with care. Never Surrender!



    • Note: If you are not in above list, you can participate also, just leave comment and i will check your site asap, once i review about your site added you to the list.

Tuesday, May 29, 2007

Computer Port list

What is Computer port ?

An interface on a computer to which you can connect a device. Personal computers have various types of ports. Internally, there are several ports for connecting disk drives, display screens, and keyboards.

Externally, personal computers have ports for connecting modems, printers, mice, and other peripheral devices.

Almost all personal computers come with a serial RS-232C port or RS-422 port for connecting a modem or mouse and a parallel port for connecting a printer.


On PCs, the parallel port is a Centronics interface that uses a 25-pin connector. SCSI (Small Computer System Interface) ports support higher transmission speeds than do conventional ports and enable you to attach up to seven devices to the same port.

In TCP/IP and UDP networks, an endpoint to a logical connection. The port number identifies what type of port it is.

For Network administrator must know about the computer Port, to identify network attack and network function purposed.

Below is a general computer port list and the service port name:

Service Name

Port Number

Windows Services


Browsing
DHCP Lease
DHCP Manager
Directory Replication
DNS Administration
DNS Resolution
Event Viewer
File Sharing
Logon Sequence
NetLogon
Pass Through Validation
Performance Monitor
PPTP
Printing
Registry Editor
Server Manager
Trusts
User Manager
WinNT Diagnostics
WinNT Secure channel
Wins Replication
Wins Manager
Wins Registration
Direct Hosting of SMB over TCP/IP

UDP:137,138
UDP:67,68
TCP:135
UDP:138 TCP:139
TCP:135
UDP:53
TCP:139
TCP:139
UDP:137,138 TCP:139
UDP:138
UDP:137,138 TCP:139
TCP:139
TCP:1723 IP Protocol:47 (GRE)
UDP:137,138 TCP:139
TCP:139
TCP:139
UDP:137,138 TCP:139
TCP:139
TCP:139
UDP:137,138 TCP:139
TCP:42
TCP:135
TCP:137
TCP,UDP:445


Service Name

Port Number

Windows Load balancing System
(WLBS) & convoy for cluster Control



Convoy
WLBS

UDP:1717
UDP:2504

Microsoft Exchange

Client/Server Comm.
Exchange Administrator
IMAP
IMAP (SSL)
LDAP
LDAP (SSL)
MTA – X.400 over TCP/IP
POP3
POP3 (SSL)
RPC
SMTP
NNTP
NNTP (SSL)

TCP:135
TCP:135
TCP:143
TCP:993
TCP:389
TCP:636
TCP:102
TCP:110
TCP:995
TCP:135
TCP:25
TCP:119
TCP:563

Windows Terminal
Services

RDP Client (Microsoft)
ActiveX Client (TSAC)

ICA Client (Citrix)
Terminal Server

IPSec
ISAKMP
ESP
AH

Karberos
Karberos

RSVP
RSVP

TCP:3389
TCP:80,3389
TCP:1494
TCP:3389


UDP:500
IP Protocol 50
IP Protocol 51


TCP;UDP:88


IP Protocol:46






Linux Software RAID

Introduction The main goals of using redundant arrays of inexpensive disks (RAID) are to improve disk data performance and provide data re...