Sunday, September 25, 2011

The Simple Mass WEP and WPA Cracker

If there is Piata Scanner for scanning and cracking mass SSH (Secure Shell), there is also Wifite.py for mass WEP (Wired Equivalent Privacy) and WPA (Wi-Fi Protected Access) cracking. Wait, wait… say what??

You read me right! There is Wifite.py for mass WEP and WPA cracking. Wifite.py is a cool tool coded in python which makes cracking WIFI passwords and security easier. It can be executed by using the command line python wifite.py or ./wifite.py. To see a list of command lines with detailed information for the script, you can just type in the terminal ./wifite.py –help or python wifite.py –help.

The tool is customizable to be automated with only a few arguments. Cool ey? Yeah, but it should always be noted that it requires Aicrack-ng suite which is used for auditing wireless networks and also needs macchanger which is of course  available via apt-get install.

What makes this tool easier is that it also has a GUI mode which runs by default after executing the script if it has a python-tk module. So far, the tool works good on my Backtrack 5 R1 and my Ubuntu 10.04 and a must have for Wi-Fi ninja geeks out there. It also works great with Blackbuntu. Not to mention that it also has a built in updater and can be updated by the command line ./wifite.py –upgrade or python wifite.py –upgrade.

Wifite.py was also mentioned in New York Times' article "New Hacking Tools Pose Bigger Threats to Wi-Fi Users" last February 16, 2011.

If you want to download the python script, click here.


About the Contributor:

Shipcode is a prolific blogger of ROOTCON and at the same time an InfoSec enthusiast from Cebu. He was inspired to join ROOTCON as part of the core team to share his knowledge in information security.  He encourages other like minded individuals to come forward and share their knowledge through blogging right here at ROOTCON Blog section. Email your contributions to info[at]rootcon[dot]org.


ROOTCON is managed by like minded InfoSec professionals across the Philippines.  All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Tuesday, September 20, 2011

Demystifying a Backdoor Shell


Last July 29, 2011, I was able to give a talk about Backdoor Shells and IRC (Internet Relay Chat) Bots in Techbar Cebu for the Cebu Linux Users Group (CEGNULUG) Talk.  In the said talk I explained and showed what a backdoor shell is and how it can be a chronic threat to all websites. I also showed how to run an IRC Bot using the backdoor shell I have. The purpose of my topic was to promote security awareness and to give idea about the backdoor shell’s hidden danger.

So what is a backdoor shell? A backdoor shell is a piece of code in PHP, ASP, JSP, etc. which can be uploaded to a site to gain access to files stored on the website. Once it is uploaded, the cracker could use it to edit, delete, and download any files on the website, or could even upload their own.

Now, there are many ways of how a site gets backdoored, it could be due to website vulnerability attacks or exploits like SQLI (Structured Query Language Injection), RFI (Remote File Inclusion), LFI (Local File Inclusion), FTP (File Transfer Protocol) Bruteforce Attacks, Sniffing, XSS (Cross Site Scripting), etc. There are many to mention but these are the most common attacks.

PHP Backdoor shells are the most used backdoor shells because most of the websites are coded in PHP. These kind of backdoor shells are like terminal emulators wherein you can execute UNIX and bash commands which allow crackers and defacers to manipulate the server or the operating system your website is currently hosted.


So how risky could it be? Well first of all, your site could get defaced on the index page which is really shameful or the cracker could use the website as a scam page or a phishing site. Shells could also be used to gain the root access of the site if it’s a Linux server. Crackers could also use your site for spamming and for hosting their botnets. Crackers could spread the backdoor shell across your files for backup purposes. And worst of all, the site could then be used to host their denial-of-service (DoS) or distributed denial-of-service attack (DDoS) shells (ex. host booter).


According to Zone-H, they archived 1,419,203 defaced web­sites. Linux became the most used OS for web servers and of course the pre­ferred target for the defacers. Why? Because of certain benefits and many things a defacer or a cracker could play around like putting a backdoor shell on it. 

What Zone-H archived only accounts to those defaced websites that were submitted to them by defacers, thus there are still unaccounted websites out there which are not leaked just for the cracker or defacer’s compensation. We just could not deny the fact that there are still websites out there wherein the administrator is not aware of such cyber espionage.

Now the question is, “Is your website one of those unaccounted websites with backdoors?”


About the Contributor:
Shipcode is a prolific blogger of ROOTCON and at the same time an InfoSec enthusiast from Cebu. He was inspired to join ROOTCON as part of the core team to share his knowledge in information security.  He encourages other like minded individuals to come forward and share their knowledge through blogging right here at ROOTCON Blog section.


ROOTCON is managed by like minded InfoSec professionals across the Philippines.  All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
Read More

Sunday, September 04, 2011

ROOTCON 5 Full Page Ad Published in "The Freeman"

(Click Image to Enlarge)

The image above paints a thousand words. This one (1) full page ad is published in "The Freeman" (Cebu newspaper) today, dated September 4, 2011 (Sunday).

Thanks to James Arthur Oliva for the photos and his models. Thanks also to Paul Villacorta for the graphic works.

Kudos to you guys for supporting ROOTCON!


About the Contributor:
A self-confessed blogger minus the coffee. He maximizes his skills in consultancy, project management, professional networking, social media campaigns and very active in conceptualizing things. To date he already conducted several IT / Information Security events as his passion since 2007. Currently he's working as a Technical Support Specialist in a local company.

ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.



Read More

Saturday, September 03, 2011

[UPDATE] RC 5 Panelist

We have identified our list of panelist for the upcoming ROOTCON 5 Panel Discussion.

Day 1:  InfoSec State In The Philippines

Oliver Cam - Development and General Manager InfoWeapons Inc.

Roland Dela Paz - Security and Threat Researcher at TrendMicro

Atty. Al Vitangcol - Lawyer specializing in e-Commerce law.

Jaime Licauco - Security Professional that holds CISSP and GSEC certification

Day 2: Cyber Terrorism What Is Our Stand

Paul Sabanal - Security Research at IBM Security Systems, speaker at BlackHat Briefings

Sven Herpig - Professor and a PhD student specilizing CyberWarfare

Chris Boyd - Senior Threat Researcher at GFI, holds a title of Microsoft MVP for Computer Security

Berman Enconado - Senior Software Engineer at GFI

More updates on the ROOTCON 5 Panel Discussion will be published soon.

Read More

Thursday, September 01, 2011

ROOTCON Panel Discussion

Sad to say that one of our speakers backed-out at a very last minute. Due to very limited time, we don't have enough time to look for another replacement, and our speakers on the waiting list cannot do the talk because of very limited time to prepare for their presentation

And as a replacement, we will be having a ROOTCON Panel Discussion both on Day 1 and Day 2. Panel Discussion is a very good alternative in finding speakers, as this will create an interaction and a healthy discussion between our selected panelist and con-goers.

Our Panel Topics for this years conference are the following:

InfoSec State in the Country (Philippines) - Day 1
Cyber Terrorism What Is Our Stand - Day 2

Selected Panelist will be debating / discussing this two high-end topics during the panel discussion and at the same time get inputs from the audience.

Our Panelist will be announced on Friday.

Stay Tuned for Updates.


Read More

Sunday, August 21, 2011

Reminiscing the Hacker’s Manifesto


Have you guys heard of the Hacker’s Manifesto?

Probably some of you may say yes and some may say no. But for those of you who haven’t heard of it, it’s an essay written by Loyd Blankenship (a.k.a. The Mentor, stylized as +++The Mentor+++).

It’s also known as the “The Conscience of a Hacker” which was written on January 8, 1986 which followed after the arrest of Loyd and was published in an underground ezine (online magazine) Phrack.

So who is Loyd Blankenship a.k.a The Mentor? He is a well known American computer hacker and writer since the 80’s and was a member of the hacker groups, “Extasyy Elite” and “Legion of Doom”. He also wrote the game “Cyberpunk” which was seized by the Secret Service.

It is believed that the “Hacker’s Manifesto” is the cornerstone and the foundation of the hacker culture and the article also gave some insight into the psychology of early hackers.

The Manifesto states that hackers hack out of curiosity and that they want to learn more.

Hackers don’t learn to hack, they hack to learn.

The article reflects the attitude and the personality of the hackers in the early 80’s and 90’s. During these days, being a script kiddie was moderately cool, packet wars were in and lame DOS attacks like WinNUKE and the ath0++ modem drop were cool.

Phreaking also became a mainstream during these days and that sharing of knowledge like cracking, cryptography, programming (C++, VB, Delphi, C, Pascal, Assembly, Python, PERL, Bash and so on), network security, Linux, Windows, UNIX, etc. became the main topics in IRC.

The essay of Loyd was also quoted in the 1995 Movie entitled “Hackers”. Mentor received a credit from this movie. Also a poster about the said article appears in the movie "The Social Network" on the wall of Mark Zuckerberg's dorm room.

Below is the complete essay of +++The Mentor+++:

Loyd Blankenship a.k.a +++The Mentor+++


The Hacker’s Manifesto

Another one got caught today, it's all over the papers. "Teenager Arrested in Computer Crime
Scandal", "Hacker Arrested after Bank Tampering"...

Damn kids. They're all alike.

But did you, in your three-piece psychology and 1950's technobrain, ever take a look behind the eyes of the hacker? Did you ever wonder what made him tick, what forces shaped him, what may have molded him?

I am a hacker, enter my world...

Mine is a world that begins with school... I'm smarter than most of the other kids, this crap they teach us bores me...

Damn underachiever. They're all alike.

I'm in junior high or high school. I've listened to teachers explain for the fifteenth time how to reduce a fraction. I understand it. "No, Ms. Smith, I didn't show my work. I did it in my head..."

Damn kid. Probably copied it. They're all alike.

I made a discovery today. I found a computer. Wait a second, this is cool. It does what I want it to. If it makes a mistake, it's because I screwed it up. Not because it doesn't like me... Or feels threatened by me.. Or thinks I'm a smart ass.. Or doesn't like teaching and shouldn't be here...

Damn kid. All he does is play games. They're all alike.

And then it happened... a door opened to a world... rushing through the phone line like heroin through an addict's veins, an electronic pulse is sent out, a refuge from the day-to-day incompetencies is sought... a board is found. "This is it... this is where I belong..." I know everyone here... even if I've never met them, never talked to them, may never hear from them again... I know you all...

Damn kid. Tying up the phone line again. They're all alike...

You bet your ass we're all alike... we've been spoon-fed baby food at school when we hungered
for steak... the bits of meat that you did let slip through were pre-chewed and tasteless. We've been dominated by sadists, or ignored by the apathetic. The few that had something to teach found us willing pupils, but those few are like drops of water in the desert.

This is our world now... the world of the electron and the switch, the beauty of the baud. We make use of a service already existing without paying for what could be dirt-cheap if it wasn't run by profiteering gluttons, and you call us criminals. We explore... and you call us criminals. We seek after knowledge... and you call us criminals. We exist without skin color, without nationality, without religious bias... and you call us criminals. You build atomic bombs, you wage wars, you murder, cheat, and lie to us and try to make us believe it's for our own good, yet we're the criminals.

Yes, I am a criminal. My crime is that of curiosity. My crime is that of judging people by what they say and think, not what they look like. My crime is that of outsmarting you, something that you will never forgive me for.

I am a hacker, and this is my manifesto. You may stop this individual, but you can't stop us all... after all, we're all alike.



About the Contributor:

Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.



ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Friday, August 19, 2011

NodeZero supports ROOTCON 5

We are glad that we have NodeZero as Media Partner for ROOTCON 5.


As a brief introduction, NodeZero is Ubuntu based linux designed as a complete system which can also be used for penetration testing.
NodeZero uses Ubuntu repositories so your system will be always up to date.

NodeZero is packaged with around 300 tools for penetration testing and set of basic services which are needed in penetration testing.

This is a good tool you ought not to miss!

Proof of their support for ROOTCON 5:

Follow our friend at http://netinfinity.org/


Grab a copy on September 9 and 10, 2011 at Parklane International Hotel, Cebu City, Philippines.

About the Contributor:
A self-confessed blogger minus the coffee. He maximizes his skills in consultancy, project management, professional networking, social media campaigns and very active in conceptualizing things. To date he already conducted several IT / Information Security events as his passion since 2007. Currently he's working as a Technical Support Specialist in a local company.



ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Thursday, August 18, 2011

Cool Ubuntu Shell Account


Good news for Ubuntu fans and shell enthusiasts out there. Nvita.org is offering a Ubuntu shell account that provides users with access to softwares and services like GCC (GNU Compiler Collection), IRC access, Irrsi, background processes, FTP (File Transfer Protocol), and text editors (like nano and vi) for free.

Yes! You are not dreaming, this is true and not only that, the shell account could also be used for tunneling. Honestly, I do love their service because I love free stuffs. This kind of project really conforms to the philosophy of Richard Stallman about Open Source and Free Software. This is the power of Linux and the GNU Project!


NVITA (Northern Virginia Information Technology Association) deserves recognition for their excellent shell project which has the latest Ubuntu 11.04 as its Operating System (Linux Ubuntu 2.6.35-22-generic-pae #33-Ubuntu SMP Build Server). Unlike other shell providers, NVITA also allows users to install packages with their permission.

But there are some flaws in their project because they allow too much background which could possibly be used for illegal activities. We could not deny the fact that some users may tend to abuse their privileges as a user like using it for udpflooding, tcpflooding, hosting botnets, scanning SSH, etc. because of allowing too much background processes. Maybe next time they should put some limit to prevent abuses in their server.

But in the long run, NVITA is still one of the best shell account providers for allowing us to connect to their server with good services despite the said flaws. NVITA offered free shells which are not meant to be abused but meant for a purpose thus we should use it ethically. It’s now up to the user where he wants to use it as long as it does not violate the ethical laws of Internet and computers.



About the Contributor:

Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.



ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved.Designated trademarks, brands and articles are the property of their respective owners.

Read More

Tuesday, August 16, 2011

Thoughts on the Operation Shady Rat



Let it be known that the year 2011 is best described as the Year of the Hackers. And I know, one way or another you will agree or disagree with me. But hey! The media publicized these sophisticated security attacks targeting CIA, US Senate, Sony, PBS, Philippine Congress and the list continues. All of these attacks are attributed to hacker groups such as AntiSec, Anonymous and LulzSec.
What is very surprising from these groups is that most of their members are teens just like Topiary who recently posted on bail.
These attacks and media whoring already existed in the past but it’s only now that it has been the center of attention and worst it gained a lot of followers on what will be their next target as most of them have their own social network page on Facebook and Twitter.
In other news, Dmitri Alperovitch, Vice President of Threat Research at the Cyber-Security Firm of McAfee recently posted a blog entitled “Revealed: Operation Shady Rat” which demystified a five year hacking campaign which infiltrated the computer systems of national governments, global corporations, oil companies, and other profit and non-profit organizations. The campaign which took down 72 targets, making it perhaps the largest concerted hacking attempt in history, McAfee said. Government agencies in India, South Korea, Taiwan, and the U.S. were also attacked, plus high-profile targets like the International Olympic Committee.

I have been quiet for a couple of days because of constant research of this unprecedented cyber-espionage campaign which was discovered in the year 2006 because of the logs which was discovered by McAfee. In fact, some people blame China and Russia behind this espionage but it should be noted that McAfee disclaimed that China or Russia is responsible for this and that they also declined to reveal the source where the “Shady RAT” came from.

I’m not really sure who suggested that China should be blamed for this but I think they blamed some of the Chinese hackers because of the recent information gathering they made. It is said that in the past years, they have stolen highly confidential information that is kept secret in supercomputers in the US. But the Chinese government denied its involvement of the said campaign.

Some people may also say that it’s the Russian government because of the unforgotten Cold War between the US but then again it is really unfair to point our fingers to Russia and China because of insufficient evidence against them. All countries are innocent until proven guilty.

I guess McAfee has unleashed a new media storm because of their discovery since 2006. Their rival company, Symantec also posted its own analysis of the campaign and was skeptical of its impact. "Is the attack described in Operation Shady RAT a truly advanced persistent threat? I would contend that it isn’t, especially when you consider the errors made in configuring the servers and the relatively non-sophisticated malware and techniques used in this case," Symantec's Hon Lau wrote in a blog post.

"Sure the people behind it are persistent but no more than the myriad of other malware groups out there such as Zeus, Tidserv, and others like them," said Lau.

Although, it is highly controversial and questionable why McAfee discovered this campaign before any antivirus company or government agency; but could it be possibly an excuse to put blame on China? That I’m not sure of and I lay my hands off regarding this case.

To our valuable readers, I’ll give you a room for your opinions and views regarding this campaign. If you ask me, I have 60% trusts on this revelation. Whether this is true or not, there are questions that will cloud up our minds. So are we ready for this cyber espionage and cyber terrorism?
Philippines is not included in the list but who knows?





About the Contributor:
Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.

ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved.Designated trademarks, brands and articles are the property of their respective owners.
Read More