Sunday, August 30, 2020

What Is A Vpn And How Is It Works ?

What Is A VPN?

VPN stands for Virtual Private Network, and maybe you have heard or read that term in association with privacy and geolocation. In this article we will learn and look into what exactly is it how does it work and what can it do for you.

How Does A VPN Work?

Let me explain it now but before we dive into VPNs, let me tell you a little bit about how the internet works now. At home, you have probably got some router or modem from your telephone company or your internet service provider. Then that is connected to your desktop, maybe by an Ethernet cable, to your smartphone over Wi-Fi, perhaps to your laptop over Wi-Fi and so on.

Inside your house when you do a laptop talk or your PC talk or your phone talk that is part of your private network, and that does not go out onto the internet. It stays inside your house, but the moment you open a web page somewhere out on the internet that data flows through your modem down into your local phone company or ISP and then out across the internet.

It will travel across the internet until it gets to the server the server will then reply with some information that will come back through the internet into your local telecommunications provider or ISP down through to your modem and then back onto your PC or your Android smartphone.

Now, while all that data is rushing around the internet, it needs to know where it is going and the things to know where they are going. They need an address it is the same with the postal service is the same when you want to go and visit somebody. It is the same with data on the internet.

There are different layers of addressing or different types of addressing that go on, but at the highest level, each of these packets of information has what is called an IP address. The IP address is you have probably seen them there those four digits from 0 to 255 with dots in between them so maybe like 178.304.67.

The modem or your router has probably been assigned an IP address from your ISP and what happens in is that when your data goes through the internet every piece of equipment, it touches every router every server it touches knows that your IP address. It is done that is not because they are trying to spy on you but because trying to connect collect data about the number of people that clicked into their website.

What a VPN does is it allows you to create a tunnel a connection from your home computer to a server somewhere else in the world. The connection is encrypted, and then when I access something on the Internet, it goes through that tunnel and then it arrived at that other server and then it goes on to the Internet, and it will finally arrive at the web server or the service. Your IP address will no longer be your IP address. The IP address of the VPN server protects your IP.

If you use a VPN, first of all, your local telecommunications provider and your local government have no idea about the sites that you are accessing. When you go through the VPN, it is all encrypted. VPN allows you to connect to another server in another country.


@£√£RYTHING NT

Related articles


  1. Hacker
  2. Android Hack Tools Github
  3. Physical Pentest Tools
  4. Nsa Hack Tools Download
  5. Termux Hacking Tools 2019
  6. Pentest Reporting Tools
  7. How To Install Pentest Tools In Ubuntu
  8. Hack Tools Download
  9. Hacker Tools 2019
  10. Hack Tools For Pc
  11. Hacker Tools Linux
  12. Hacking Tools Usb
  13. Pentest Tools Kali Linux
  14. Hacking Tools For Beginners
  15. Hack Tools For Ubuntu
  16. Hacking Tools For Windows
  17. Beginner Hacker Tools
  18. Hack And Tools
  19. Android Hack Tools Github
  20. Hacking Tools For Windows 7
  21. Hacking Tools
  22. Underground Hacker Sites
  23. Hack Apps
  24. Bluetooth Hacking Tools Kali
  25. Pentest Tools Bluekeep
  26. Hacking Tools Usb
  27. Top Pentest Tools
  28. Hacker Techniques Tools And Incident Handling
  29. New Hack Tools
  30. Hack Tools For Games
  31. Wifi Hacker Tools For Windows
  32. Hacker Tools Apk Download
  33. Usb Pentest Tools
  34. Hack Website Online Tool
  35. Hacking Tools 2020
  36. Hacker Tool Kit
  37. Pentest Tools Github
  38. Pentest Tools Android
  39. Hak5 Tools
  40. Wifi Hacker Tools For Windows
  41. Hackrf Tools
  42. Hacker Tools For Ios
  43. Hak5 Tools
  44. Pentest Tools Linux
  45. Hacker Tools For Pc
  46. Pentest Tools
  47. Hack App
  48. Hacker Tools For Windows
  49. Pentest Tools Website
  50. Hack Tool Apk No Root
  51. Hacking Tools For Mac
  52. Black Hat Hacker Tools
  53. Hacking App
  54. Pentest Tools Download
  55. Bluetooth Hacking Tools Kali
  56. Wifi Hacker Tools For Windows
  57. Pentest Tools Website
  58. Wifi Hacker Tools For Windows
  59. Best Hacking Tools 2019
  60. Hacker Tools Apk Download
  61. Hack Rom Tools
  62. Hack Tools
  63. Hacking Tools Name
  64. Hacking Tools For Mac
  65. Hacker Tools Linux
  66. Hacker Tools Software
  67. Hacker Tools Hardware
  68. Tools 4 Hack
  69. Hacking Tools For Windows
  70. Android Hack Tools Github
  71. Hacking Tools For Windows
  72. Hacking Tools 2019
  73. Top Pentest Tools
  74. Hack Tools For Pc
  75. Pentest Tools Url Fuzzer
  76. Pentest Tools List
  77. Hacking Tools Pc
  78. Hacking Tools 2020
  79. Pentest Tools Kali Linux
  80. Hacker Tool Kit
  81. Easy Hack Tools
  82. Pentest Tools Website
  83. Hacker Tools 2019
  84. Hack Tools For Games
  85. Hacker Tools Online
  86. Nsa Hacker Tools
  87. Hack Tools 2019
  88. Hack Tools For Windows
  89. Hacks And Tools
  90. Hacking Tools For Pc
  91. Hacker Tools Apk Download
  92. Tools Used For Hacking
  93. Hacker Tools Github
  94. Hack Tools
  95. Pentest Tools Framework
  96. Nsa Hack Tools Download
  97. Hack Tools 2019
  98. Hacker Tools Hardware
  99. Game Hacking
  100. How To Install Pentest Tools In Ubuntu
  101. World No 1 Hacker Software
  102. Pentest Tools Port Scanner
  103. Hacking Tools Github
  104. Hack Tools For Games
  105. Nsa Hacker Tools
  106. Blackhat Hacker Tools
  107. Hack Tools Pc
  108. Hacking Apps
  109. Hacking Tools Download
  110. Free Pentest Tools For Windows
  111. Hacking Tools For Pc
  112. Hacker Tools 2020
  113. Pentest Tools For Android
  114. Hack Tools For Games
  115. Hacks And Tools
  116. Hacker Security Tools
  117. Ethical Hacker Tools
  118. Pentest Tools
  119. Kik Hack Tools
  120. Pentest Tools Windows
  121. Pentest Recon Tools
  122. Hacking Tools
  123. Hacker Tools Hardware
  124. Hacker Search Tools
  125. Hacking Tools Free Download
  126. Pentest Tools Nmap
  127. What Are Hacking Tools

OWASP API Security Project Media Coverage



A list of must read articles on OWASP API Security Project

Related articles


  1. Hacking Tools And Software
  2. Hacks And Tools
  3. Ethical Hacker Tools
  4. Hacking Tools Windows
  5. Hacking Tools Name
  6. Hack Tools Online
  7. Hack Tools Online
  8. Pentest Tools Subdomain
  9. Hacker Tools Hardware
  10. Hacker Tools Windows
  11. Hacker Tools For Windows
  12. Blackhat Hacker Tools
  13. Physical Pentest Tools
  14. Hackrf Tools
  15. Pentest Tools Windows
  16. Hacker Tools Apk Download
  17. Kik Hack Tools
  18. Pentest Automation Tools
  19. Pentest Tools Url Fuzzer
  20. Hack App
  21. Computer Hacker
  22. Hacking Tools Download
  23. Underground Hacker Sites
  24. Hacking Tools Pc
  25. Hacker Tools Github
  26. Growth Hacker Tools
  27. Hacker Tools Linux
  28. Pentest Tools For Ubuntu
  29. Tools Used For Hacking
  30. Hacker Tools For Mac
  31. Pentest Tools Online
  32. Hacking Tools Download
  33. Nsa Hack Tools Download
  34. Hacking Tools Hardware
  35. Pentest Tools List
  36. Pentest Automation Tools
  37. Hacker Tools Online
  38. Hackrf Tools
  39. Hacker Tools Apk Download
  40. Termux Hacking Tools 2019
  41. Nsa Hacker Tools
  42. Pentest Tools Framework
  43. Hacking Tools Hardware
  44. Hacking App
  45. Hack And Tools
  46. Game Hacking
  47. World No 1 Hacker Software
  48. Hacker Tool Kit
  49. Hacking Tools Usb
  50. Pentest Tools Download
  51. Pentest Tools Linux
  52. Hacker Tools Apk
  53. Pentest Tools Website
  54. Wifi Hacker Tools For Windows
  55. How To Install Pentest Tools In Ubuntu
  56. Blackhat Hacker Tools
  57. Hacking Tools Name
  58. Hacking Tools For Kali Linux
  59. Pentest Tools Review
  60. Hack Tools For Pc
  61. Black Hat Hacker Tools
  62. Hacker Search Tools
  63. Install Pentest Tools Ubuntu
  64. Pentest Box Tools Download
  65. Best Pentesting Tools 2018
  66. Easy Hack Tools
  67. Pentest Tools List
  68. Hack Tools For Mac
  69. Hacker Tools Mac
  70. Pentest Tools List
  71. Hacking Tools Windows
  72. Hacker Hardware Tools
  73. Hacker Tools For Pc
  74. Pentest Tools Review
  75. Kik Hack Tools
  76. Hacker Tools For Mac
  77. Hack Tools Download
  78. Physical Pentest Tools
  79. Pentest Tools Kali Linux
  80. Hacking Tools For Mac
  81. Hacking App
  82. Tools For Hacker
  83. Free Pentest Tools For Windows
  84. Hack Rom Tools
  85. Physical Pentest Tools
  86. Pentest Reporting Tools
  87. Pentest Tools Bluekeep
  88. Free Pentest Tools For Windows

CEH Practical: Information-Gathering Methodology

 

Information gathering can be broken into seven logical steps. Footprinting is performed during the first two steps of unearthing initial information and locating the network range.


Footprinting

Footprinting is defined as the process of establishing a scenario or creating a map of an organization's network and systems. Information gathering is also known as footprinting an organization. Footprinting is an important part of reconnaissance process which is typically used for collecting possible information about a targeted computer system or network. Active and Passive both could be Footprinting. The example of passive footprinting is assessment of a company's website, whereas attempting to gain access to sensitive information through social engineering is an example of active information gathering. Basically footprinting is the beginning step of hacker to get hacked someone because having information about targeted computer system is the main aspect of hacking. If you have an information about individual you wanna hack so you can easily hacked that individual. The basic purpose of information gathering is at least decide what type of attacks will be more suitable for the target. Here are some of the pieces of information to be gathered about a target
during footprinting:
  • Domain name
  • Network blocks
  • Network services and applications
  • System architecture
  • Intrusion detection system
  • Authentication mechanisms
  • Specific IP addresses
  • Access control mechanisms
  • Phone numbers
  • Contact addresses
Once this information is assemble, it can give a hacker better perception into the organization, where important information is stored, and how it can be accessed.

Footprinting Tools 

Footprinting can be done using hacking tools, either applications or websites, which allow the hacker to locate information passively. By using these footprinting tools, a hacker can gain some basic information on, or "footprint," the target. By first footprinting the target, a hacker can eliminate tools that will not work against the target systems or network. For example, if a graphics design firm uses all Macintosh computers, then all hacking software that targets Windows systems can be eliminated. Footprinting not only speeds up the hacking process by eliminating certain tool sets but also minimizes the chance of detection as fewer hacking attempts can be made by using the right tool for the job. Some of the common tools used for footprinting and information gathering are as follows:
  • Domain name lookup
  • Whois
  • NSlookup
  • Sam Spade
Before we discuss these tools, keep in mind that open source information can also yield a wealth of information about a target, such as phone numbers and addresses. Performing Whois requests, searching domain name system (DNS) tables, and using other lookup web tools are forms of open source footprinting. Most of this information is fairly easy to get and legal to obtain.

Footprinting a Target 

Footprinting is part of the preparatory pre-attack phase and involves accumulating data regarding a target's environment and architecture, usually for the purpose of finding ways to intrude into that environment. Footprinting can reveal system vulnerabilities and identify the ease with which they can be exploited. This is the easiest way for hackers to gather information about computer systems and the companies they belong to. The purpose of this preparatory phase is to learn as much as you can about a system, its remote access capabilities, its ports and services, and any specific aspects of its security.

DNS Enumeration

DNS enumeration is the process of locating all the DNS servers and their corresponding records for an organization. A company may have both internal and external DNS servers that can yield information such as usernames, computer names, and IP addresses of potential target systems.

NSlookup and DNSstuff

One powerful tool you should be familiar with is NSlookup (see Figure 2.2). This tool queries DNS servers for record information. It's included in Unix, Linux, and Windows operating systems. Hacking tools such as Sam Spade also include NSlookup tools. Building on the information gathered from Whois, you can use NSlookup to find additional IP addresses for servers and other hosts. Using the authoritative name server information from Whois ( AUTH1.NS.NYI.NET ), you can discover the IP address of the mail server.

Syntax

nslookup www.sitename.com
nslookup www.usociety4.com
Performing DNS Lookup
This search reveals all the alias records for www.google.com and the IP address of the web server. You can even discover all the name servers and associated IP addresses.

Understanding Whois and ARIN Lookups

Whois evolved from the Unix operating system, but it can now be found in many operating systems as well as in hacking toolkits and on the Internet. This tool identifies who has registered domain names used for email or websites. A uniform resource locator (URL), such as www.Microsoft.com , contains the domain name ( Microsoft.com ) and a hostname or alias ( www ).
The Internet Corporation for Assigned Names and Numbers (ICANN) requires registration of domain names to ensure that only a single company uses a specific domain name. The Whois tool queries the registration database to retrieve contact information about the individual or organization that holds a domain registration.

Using Whois

  • Go to the DNSStuff.com website and scroll down to the free tools at the bottom of the page.
  • Enter your target company URL in the WHOIS Lookup field and click the WHOIS button.
  • Examine the results and determine the following:
    • Registered address
    • Technical and DNS contacts
    • Contact email
    • Contact phone number
    • Expiration date
  • Visit the company website and see if the contact information from WHOIS matches up to any contact names, addresses, and email addresses listed on the website.
  • If so, use Google to search on the employee names or email addresses. You can learn the email naming convention used by the organization, and whether there is any information that should not be publicly available.

Syntax

whois sitename.com
whois usociety4.com

Related news
  1. Hacking Tools Mac
  2. Pentest Tools Linux
  3. Hacker
  4. Hacker Hardware Tools
  5. Hacker Techniques Tools And Incident Handling
  6. Hacking Tools Hardware
  7. New Hack Tools
  8. Hacking Tools Github
  9. Hacker Tools Apk
  10. Hack Apps
  11. Hack Tools For Games
  12. Hacker Search Tools
  13. What Are Hacking Tools
  14. Hacker Hardware Tools
  15. Hack Tools
  16. Hackrf Tools
  17. Hacker Tools 2019
  18. Hacking Tools For Windows 7
  19. Hack Tools
  20. What Are Hacking Tools
  21. Pentest Tools For Mac
  22. Hacker Tools For Mac
  23. Hacker Tools List
  24. Hacker Tools For Ios
  25. Hacker Tools 2019
  26. Hacker Security Tools
  27. Hacker Tools List
  28. Hacker Tools 2019
  29. Hacking Tools Usb
  30. Hacking Tools Software
  31. World No 1 Hacker Software
  32. Pentest Tools For Windows
  33. Hack App
  34. Pentest Tools Port Scanner
  35. Pentest Tools Find Subdomains
  36. Hacker Tools Apk
  37. Hacking Tools For Mac
  38. Hack Apps
  39. Hack Tools For Mac
  40. Hack Tool Apk No Root
  41. Pentest Tools Website Vulnerability
  42. Hacking Tools Github
  43. Hacking Tools Pc
  44. Underground Hacker Sites
  45. Hacks And Tools
  46. Hacker Tools Linux
  47. Hack Tools For Windows
  48. Pentest Automation Tools
  49. Pentest Tools Apk
  50. Hacking Tools Software
  51. World No 1 Hacker Software
  52. Hacking Tools Name
  53. Termux Hacking Tools 2019
  54. Best Hacking Tools 2020
  55. Hacker Tools Apk
  56. Beginner Hacker Tools
  57. Hacking Tools Usb
  58. Computer Hacker
  59. Hacking Tools For Beginners
  60. Hacker Tools Free
  61. Pentest Tools Apk
  62. Github Hacking Tools
  63. Hack And Tools
  64. Pentest Tools Kali Linux
  65. Computer Hacker
  66. Blackhat Hacker Tools
  67. Hacker Tools For Mac

Saturday, August 29, 2020

CEH: Gathering Network And Host Information, Types Of Scan


In Hacking the main focus is over gathering the information about victim or victim's machine. Which will help to find out which type of exploit will works according to the given circumstances. Gathering the network and host information means to find out by which network, the which victim's machine is connected and communicating over the network. Moreover, scanning is also performed for gathering information about open and closed ports. After that they'll able to find the vulnerabilities in the target system and try to get access to the system.

Types Of Scan

As a CEH you should know the scan types and uses:

SYN

SYN scan doesn't complete the TCP three way handshake that is why it is known as a half-open scan. An attacker send a SYN packet to the victim machine if SYN/ACK packet is received back to attacker, then it clarify that the port is listening due to the acknowledgment by the victim that it has completed the connection. While if the attacker is received the RST/ACK packet then it assumed that the port is closed or open.


XMAS

XMAS scan works only on target system that has the RFC 793 development of TCP/IP and it doesn't works against any version of windows.
XMAS scan send a packet with by setting up the FIN, URG and PSH flags of the TCP header. The function of this scan is if the port is active there will be no response but if the port is closed the target responds with a RST/ACK packet.


FIN

A FIN scan send a packet by setting up only the FIN flag of the TCP. This scan is similar to XMAS scan. FIN scan receives no response if the port is active while if the port is closed it receives the RST/ACK packet.


NULL 

NULL scan is also similar to the XMAS scan. But the only difference is that it sends a packet without setting up the any flag of TCP header. NULL scan receives no response if the port is open but if the port is closed it receives the RST/ACK packet.


IDLE

It is just like spoofing an IP address by sending a SYN packet to the victim's machine to find out which services are available over the system. This scan is completed with the help of another system called as "Zombie" (that is not receiving or transmitting any information).


Related news