Thursday, March 18, 2010

Using iwspy linux tools

You use iwspy to get statistics from specific wireless nodes. With iwspy, you
can list the addresses associated with a wireless network interface and get
link-quality information for each. The syntax is as follows:
iwspy interface [+] DNSNAME | IPADDR | HWADDR [...]
iwspy interface off
Let’s look at each one of the parameters.
DNSNAME | IPADDR: Use this parameter to set an IP address or DNS
name (using the name resolver).
HWADDR: Use this parameter to set a hardware (MAC) address.
Plus sign (+): Use this parameter to add a new set of addresses to
the end of the current.
off: Use this parameter to remove the current list of addresses and to
disable the spy functionality.

Using iwpriv linux tools

iwpriv is the companion tool to iwconfig. Again, you use iwpriv to configure
optional (private) parameters for a wireless network interface. You use
iwpriv for parameters and settings specific to each driver, as opposed to
iwconfig, which deals with generic ones. The syntax is as follows:
iwpriv interface private-command [I] [private-parameters]
iwpriv interface –all
iwpriv interface roam {on,off}
iwpriv interface port {ad-hoc,managed,N}
Using the iwpriv command without any parameters lists the available private
commands for each interface and the parameters required.
Let’s look at each one of the parameters.
private-command [I] [private-parameters]: Use the specified
private-command on the interface. The I parameter, which stands for
an integer, is the integer to pass to the command as a Token Index. Your
driver documentation should specify the value for the integer, otherwise
leave the value out.
The command may optionally take or require arguments, and may display
information. The following paragraphs provide information on the
arguments.
-a/--all: Use this parameter to execute and display all the private
commands that don’t require any arguments, for example, read only.
roam: Use this parameter to enable or disable roaming, when supported.
port: Use this parameter to read or configure the port type.
Using iwlist
iwlist allows you to display more detailed information from a wireless interface
than you can get with iwconfig. For instance, you can get the ESSID,
node name, frequency, signal quality and strength and bit data and error rate.
The syntax is as follows:
iwlist interface scanning
iwlist interface frequency
iwlist interface rate
iwlist interface key
iwlist interface power
iwlist interface txpower
iwlist interface retry
iwlist –-help
iwlist –version
Let’s look at each one of the parameters.
scan[ning]: Use this parameter to specify the access points and ad-hoc
cells in range. For example, the following enables scanning.
iwlist wlan0 scan
Run this command and you may see something like the following:
wlan0 Scan completed:
Cell 01 – Address: 00:02:2D:8F:09:8D
ESSID:”pdaconsulting”
Mode:Master
Frequency:2.462GHz
Quality:0/88 Signal level:-50 dBm Noise level:-
092 dBm
Encryption key:off
Bit Rate:1Mb/s
Bit Rate:2Mb/s
Bit Rate:5.5Mb/s
Bit Rate:11Mb/s
freq[uency]/channel: Use this parameter to specify the list of available
frequencies for the device and the number of defined channels.
rate/bit[rate]: Use this parameter to list the bit-rates supported by
the device.
key/enc[ryption]: Use this parameter to list the supported encryption
key sizes and to display all the available encryption keys.
power: Use this parameter to list the various Power Management attributes
and modes of the device.
txpower: Use this parameter to list the various Transmit Powers available
on the device.
retry: Use this parameter to list the transmit retry limits and retry lifetime
on the device.
--version: Use this parameter to display the version of the tools, as
well as the recommended and current Wireless Extensions version for
the tool and the various wireless interfaces.

Using iwconfig linux tools

You use iwconfig to configure a wireless network interface. If you’re familiar
with the ifconfig command, the iwconfig command is similar but works
only with wireless interfaces. You use iwconfig to set the network interface
parameters, such as frequency. As well, you can use iwconfig to set the
wireless parameters and display statistics. The syntax is as follows:
iwconfig interface [essid X] [nwid N] [freq F] [channel C]
[sens S] [mode M] [ap A] [nick NN]
[rate R] [rts RT] [frag FT] [txpower T]
[enc E] [key K] [power P] [retry R]
[commit]
iwconfig --help
iwconfig --version
Let’s look at each one of the parameters.
essid: Use the ESSID parameter to specify the ESSID or Network Name.
For example, the following specifies that you want to set the ESSID for
the wireless adapter to ANY for wardriving.
iwconfig eth0 essid any
nwid/domain: Use the Network ID parameter to specify the network ID
or Domain ID. For example, the following specifies that you want to disable
Network ID checking.
iwconfig eth0 nwid off
freq/channel: Use this parameter to set the operating frequency or
channel. A value below 1,000 represents the channel number, while a
value over is the frequency in Hz. For example, the following specifies
that you want to set the frequency to 2.422 GHz.
iwconfig eth0 freq 2.422G
Or for example, the following specifies that you want to use
channel three.
iwconfig eth0 channel 3
sens: Use this parameter to set the sensitivity threshold. For example,
the following specifies the level as 80 dBm.
iwconfig eth0 sens -80
mode: Use this parameter to set the operating mode of the device. The
operating mode is one of the following:
• Ad-hoc: no Access Point.
• Managed: more than one Access Point, with roaming.
• Master: synchronization master or an Access Point.
• Repeater: node forwards packets between other wireless nodes.
• Secondary: node acts as a backup master or repeater.
• Monitor: the node acts as a passive monitor and only receives
packets.
• Auto: self-explanatory.
For example, the following specifies that the network is infrastructure
mode.
iwconfig eth0 mode managed
ap: Use this parameter to force the card to register to the Access Point
given by the address. Use off to re-enable automatic mode without
changing the current Access Point, or use any or auto to force the card
to re-associate with the current best Access Point. For example, the following
forces association with the access point with the hardware
address of 00:60:1D:01:23:45.
iwconfig eth0 ap 00:60:1D:01:23:45
nick[name]: Use this parameter to set the nickname or station name.
For example, the following sets the nickname to Peter Node.
iwconfig eth0 nickname Peter Node
rate/bit[rate]: Use this parameter to set the bit-rate in bits per
second for cards supporting multiple bit rates. For example, the following
sets the bit rate to 11 Mbps.
iwconfig eth0 rate 11M
rts[_threshold]: Use this parameter to turn RTS/CTS on or off. For
example, the following turns RTS/CTS off.
iwconfig eth0 rts off
frag[mentation_threshold]: Use this parameter to turn fragmentation
on or off. For example, the following specifies a maximum fragment
size of 512K.
iwconfig eth0 frag 512
key/enc[ryption]: Use this parameter to turn encryption or scrambling
keys on or off and to set the encryption mode. For example, the following
specifies an encryption key.
iwconfig eth0 key 0123-4567-89
power: Use this parameter to set the power management scheme and
mode. For example, the following disables power management.
iwconfig eth0 power off
txpower: Use this parameter to set the transmit power in dBm for cards
supporting multiple transmit powers. For example, the following set the
transmit power to 15 dBm.
iwconfig eth0 txpower 15
If you are unfamiliar with dBM as a measurement, refer to www.atis.org/
tg2k/_dbm.html for a definition.
retry: Use this parameter to set the maximum number of MAC retransmission
retries. For example, the following specifies to retry 16 times.
iwconfig eth0 retry 16
commit: Use this parameter to force the card to apply all pending
changes rather than waiting for the issuance of an ifconfig command.
For example, the following specifies to commit the changes.
iwconfig eth0 commit
Link quality: Use this parameter to display the quality of the link.
Signal level: Use this parameter to show the received signal strength.
Noise level: Use this parameter to display the background noise level.
invalid nwid: Use this parameter to detect configuration problems or
the existence of an adjacent network.
invalid crypt: Use this parameter to display the number of packets
that the hardware couldn’t decrypt.
invalid misc: Use this parameter to display other packets lost in relation
with specific wireless operations.
There you have it. Remember you can get more information by using the
man command.

Using Linux Wireless Extension and Wireless Tools

The Linux Wireless Extension and Wireless Tools are an open source project
sponsored by Hewlett Packard. The Wireless Extension is a generic application
programming interface (API) that gives you information and statistics
about the user space. Wireless Tools is a set of tools that use the Wireless
Extensions. The Wireless Tools are:
iwconfig: Changes the basic wireless parameters.
iwpriv: Changes the Wireless Extensions specific to a driver (private).
iwlist: Lists addresses, frequencies, and bit rates.
iwspy: Gets per-node link quality.
We explore these tools in turn in the following sections. For each tool, we
provide an illustrative example. If you want to really understand the command
and its many parameters, however, please check out the man page for
the syntax and other information about any of these commands. If you have a
Web browser, you can use Google.
Linux Wireless Extensions are powerful additions to your ethical hacking
utility belt. Linux Wireless Extensions are available from http://pcmcia-cs.
sourceforge.net/ftp/contrib. Look for the entry wireless_tools.27.tar.gz
near the bottom of the available documents and programs. Wireless Extensions
v.14 is bundled in the 2.4.20 kernel, and v.16 is in the 2.4.21 kernel.
iwlist and the others are great tools. They get their information from the
standard kernel interface /proc/net/wireless. But these tools provide only
a snapshot in time; they do not provide statistics over time. If you favor the
Windows platform, you can use a great tool like NetStumbler (we cover this
tool in depth in Chapter 9). But when you work with Linux, you want to find a
better link-monitoring tool. The other tools in this section provide more functionality
than iwconfig, iwpriv, iwlist, and iwspy.

open ports - Xavi7968 Solos 4610 RD telefonica router




for start you need to find out your router model,then you find your router ip by typing in cmd console ipconfig then in your browser you will type your router ip something like that:






after that find port configuration select both protocols tcp/udp select your port that you wish to
open:

Wednesday, March 17, 2010

Understanding Standards

1.ISO 17799
2. COBIT
3. SSE-CMM
4. ISSAF
5.OSSTMM

ISO 17799
The ISO/IEC 17799 is an internationally adopted “code of practice for information
security management” from the International Organization for Standardization
(ISO). The international standard is based on British Standard BS-799.
You can find information about the standard at www.iso.org.
ISO/IEC 17799 is a framework or guideline for your ethical hack — not a true
methodology — but you can use it to help you plan. The document does not
specifically deal with wireless, but it does address network-access control.
The document is a litany of best practices at a higher level than we would
want for a framework for ethical hacking.
One requirement in the document is to control access to both internal and
external networked services. To cover this objective, you need to try to connect
to the wireless access point and try to access any resource on the wired
network.
The document also requires that you ensure there are appropriate authentication
mechanisms for users. You can test this by attempting to connect to a
wireless access point (AP). When there is Open System authentication (see
Chapter 16) you need not do any more work. Obviously no authentication
is not appropriate authentication. APs with shared-key authentication may
require you to use the tools shown in Chapter 15 to crack the key. If the AP is
using WPA security, then you will need to use another tool, such as WPAcrack.

COBIT
COBIT is an IT governance framework. Like ISO 17799, this framework will
not provide you with a testing methodology, but it will provide you with the
objectives for your test.
You can find information about COBIT at www.itgi.org/.

Using SSE-CMM
Ever heard of the CERT? (Give you a hint: It’s not a breath mint or a candy.)
It’s the Computer Emergency Response Team that’s part of the Software
Engineering Institute (SEI) at Carnegie Mellon University in Pittsburgh,
Pennsylvania. Well, the SEI is known for something else: It developed a
number of capability maturity models (CMM) — essentially specs that can give
you a handle on whether a particular system capability is up to snuff. The SEI
included a CMM just for security — the Systems Security Engineering CMM
(SSE-CMM for short). Now, the SSE-CMM won’t lay out a detailed method of
ethical hacking, but it can provide a framework that will steer you right. The
SSE-CMM can help you develop a scorecard for your organization that can
measure security effectiveness.
You can find out about SSE-CMM at www.sei.cmu.edu/.
The Computer Emergency Response team also sends out security alerts and
advisories. The CERT has a methodology as well — OCTAVE. OCTAVE stands
for Operationally Critical Threat, Asset, and Vulnerability Evaluation. You can
use OCTAVE as a methodology to build a team, identify threats, quantify vulnerabilities,
and develop an action plan to deal with them.
You can find OCTAVE at www.cert.org/octave

ISSAF
The ISSAF details a process that includes the following steps:
1. Information gathering
a. Scan
b. Audit
2. Analysis and research
3. Exploit and attack
4. Reporting and presentation
These steps correspond to our Ten Commandments of Ethical Hacking. For
each of the steps just given, the document identifies appropriate tasks and
tools. For example, the scanning step lists the following tasks:
Detect and identify the wireless network
Test for channels and ESSID
Test the beacon broadcast frame and recording of broadcast information
Test for rogue access points from outside the facility
IP address collection of access points and clients
MAC address collection of access points and clients
Detect and identify the wireless network
The document recommends you use programs such as Kismet, nmap, and
ethereal as tools for Step 1.
You also will find information in the document on the software you can use
and the equipment you will need to build or acquire to do your assessment
of your organization’s wireless-security posture.
The document we reviewed was a beta version, but it shows promise and is
worth watching. You can find the ISSAF at www.oissg.org/issaf.

OSSTMM
You’ll find that the OSSTMM gathers the best practices, standard legal issues,
and core ethical concerns of the global security-testing community — but
this document also serves another purpose: consistent definition of terms.
The document provides a glossary that helps sort out the nuances of vulnerability
scanning, security scanning, penetration testing, risk assessment,
security auditing, ethical hacking, and security hacking. The document also
defines white-hat, gray-hat, and black-hat hackers, so that by their metaphorical
hats ye shall know them. But even more importantly (from your viewpoint
as an ethical-hacker-to-be), it provides testing methodologies for wireless
security, distilled in the following bullets:
Posture review: General review of best practices, the organization’s
industry regulations, the organization’s business justifications, the organization’s
security policy, and the legal issues for the organization and
the organization’s regions for doing business.
Electromagnetic radiation (EMR) testing: Testing of the electromagnetic
radiation emitted from wireless devices.
802.11 wireless-networks testing: Testing of access to 802.11 WLANs.
Bluetooth network testing: Testing of Bluetooth ad-hoc networks.
Wireless-input-device testing: Testing of wireless input devices, such as
mice and keyboards.
Wireless-handheld testing: Testing of handheld wireless devices, such
as personal digital assistants and personal electronic devices.
Cordless-communications testing: Testing of cordless communications
communication devices, such as cellular technology.
Wireless-surveillance device testing: Testing of wireless surveillance or
monitoring devices, such as cameras and microphones.
Wireless-transaction device testing: Testing of wireless-transaction
devices, such as uplinks for cash registers and other point of sale
devices in the retail industry.
RFID testing: Testing of RFID (Radio Frequency Identifier) tags.
Infrared testing: Testing of infrared communications communication
devices.
Privacy review: General privacy review of the legal and ethical storage,
transmission, and control of data, based on employee and customer
privacy.
Each step has associated tasks that provide more detail and specific tests. As
well, each step has a table that outlines the expected results. For example,
expected results for Step 3 include these:
Verification of the organization’s security policy and practices — and
those of its users.
Identification of the outermost physical edge of the wireless network.
Identification of the logical boundaries of the wireless network.
Enumeration of access points that lead into the network.
Identification of the IP-range (and possibly DHCP-server) of the wireless
network.
Identification of the encryption methods used for data transfer.
Identification of the authentication methods of exploitable “mobile
units” (that is, the clients) and users.
Verification of the configuration of all devices.
Determination of the flaws in hardware or software that facilitate attacks.
Obviously, you need to cut and paste these tests according to your needs.
For instance, should your organization not have infrared, then you would
skip Step 11.
The OSSTMM is available from www.isecom.org/osstmm/.

Network attacks Software attacks

When it comes to the nitty-gritty bits and bytes, there are a lot of techniques
the bad guys can use to break inside your wireless realm or at least leave it
limping along in a nonworking state. Network-based attacks include
Installing rogue wireless APs and “tricking” wireless clients into connecting
to them
Capturing data off the network from a distance by walking around, driving
by, or flying overhead
Attacking the networking transactions by spoofing MAC addresses (masquerading
as a legitimate wireless user), setting up man-in-the-middle
(inserting a wireless system between an AP and wireless client) attacks,
and more
Exploiting network protocols such as SNMP
Performing denial-of-service (DoS) attacks
Jamming RF signals

As if the security problems with the 802.11 protocol weren’t enough, we now
have to worry about the operating systems and applications on wireless-client
machines being vulnerable to attack. Here are some examples of software
attacks:
Hacking the operating system and other applications on wireless-client
machines
Breaking in via default settings such as passwords and SSIDs that are
easily determined
Cracking WEP keys and tapping into the network’s encryption system
Gaining access by exploiting weak network-authentication systems
 
[URL=http://s06.flagcounter.com/more/6xL][IMG]http://s06.flagcounter.com/count/6xL/bg=FFFFFF/txt=000000/border=CCCCCC/columns=3/maxflags=20/viewers=0/labels=0/[/IMG][/URL] Locations of visitors to this page