Сүүлийн үед залхуу хүрээд элдэв юм бичихгүй их л удлаа.
Өнөөдөр харин энд тэндхийн мэдээ уншиж байсан чинь ЖЖ Хэндрикс гэдэг нөхөр нэгэн та биднийхээр сайн мэдэх Nintendo-ийн тоглоомийг 17 500$ оор авсан байна.
The 17,500$ Video Game
Тоглоом нь жирийн л нэг тоглоом: Алтан шаргал өнгөтэй, нийт 6 мин 21 сек үргэлжилдэг, мөн 3 хэсэгтэй. Гол онцлог нь Nintendo зориулсан тоглоомуудын нэгэн тэмцээнд түрүүлж байсан.
Миний хувьд хамгийн үнэтэй тоглоом гэвэл 9-р ангидаа Гутлын 22-н тэнд байсан Анун төвөөс 25$ оор Fifa98-ийг хамаг байдаг бүх мөнгөө худлан үнэн ярин байж цуглуулж авч байсан. Хайран мөнгө. :)
Хамгийн сүүлд гэвэл STEAM Counter-Strike 1.6-ийн багцыг 10$оор авсан юм байна.
Хүмүүс яаж сэтгэхээрээ нэг тоглоомыг 17 500$ оор авдаг байна.
Jul 7, 2009
Apr 26, 2009
TOP 10 Vulnerability Checker Tools
In recently, a hacking interest are being developed quickly. There are many ways as SQL-Injection, Code Injection, and so on. When a programmer writes a code, he or she should think about all of these. I am just gonna write about TOP 10 useful hacking tools and how they works because we can check our programs ourselves. It means we can find vulnerabilities and fix it.
1. Nmap
(http://nmap.org/download.html)
Nmap (Network Mapper) is a free open source utility for network exploration or security auditing. It was designed to rapidly scan large networks, although it works fine against single hosts. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services those hosts are offering, what operating systems they are running.
2. Nessus Remote Security Scanner
(http://www.nessus.org/)
Nessus is the worlds most popular vulnerability scanner used in over 75,000 organizations world-wide. Many of the worlds largest organizations are realizing significant cost savings by using Nessus to audit business-critical enterprise devices and applications.
3. John the Ripper
(http://www.openwall.com/john/)
John the Ripper is a fast password cracker. Its primary purpose is to detect weak Unix passwords. Besides several crypt password hash types most commonly found on various Unix flavors, supported out of the box are Kerberos AFS and
Windows NT/2000/XP/2003 LM hashes, plus several more with contributed patches.
4. Nikto
(http://www.net-security.org/software.php?id=223)
Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items. Scan items and plugins are frequently updated and can be automatically updated. Nikto is a good CGI scanner, there are some other tools that go well with Nikto.
5. SuperScan
Powerful TCP port scanner, pinger, resolver. If you need an alternative for nmap on Windows with a decent interface, I
suggest you check this out, it’s pretty nice.
6. p0f
P0f can identify the operating system on:
- machines that connect to your box (SYN mode),
- machines you connect to (SYN+ACK mode),
- machine you cannot connect to (RST+ mode),
- machines whose communications you can observe.
Basically it can fingerprint anything, just by listening, it doesn’t make ANY active connections to the target machine.
7. Wireshark
Wireshark is a GTK+-based network protocol analyzer, or sniffer, that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and to give Wireshark features that are missing from closed-source sniffers.
8. Yersinia
Yersinia is a network tool designed to take advantage of some weakeness in different Layer 2 protocols. It pretends to be a solid framework for analyzing and testing the deployed networks and systems.
9. Eraser
Eraser is an advanced security tool, which allows you to completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns.
10. PuTTY
PuTTY is a free implementation of Telnet and SSH for Win32 and Unix platforms, along with an xterm terminal emulator. A must have for any h4. 0r wanting to telnet or SSH from Windows without having to use the crappy default MS command
line clients.
Before, I used NMAP, Nessus, John the Ripper and PuTTy. PuTTy is also useful for SSH and Telnet connection. I think the best program is Nessus because it can show what kind of holes and bugs is in my program and what I should do. You guys should try do use yourself. I mean these programs are very useful.
1. Nmap
(http://nmap.org/download.html)
Nmap (Network Mapper) is a free open source utility for network exploration or security auditing. It was designed to rapidly scan large networks, although it works fine against single hosts. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services those hosts are offering, what operating systems they are running.
2. Nessus Remote Security Scanner
(http://www.nessus.org/)
Nessus is the worlds most popular vulnerability scanner used in over 75,000 organizations world-wide. Many of the worlds largest organizations are realizing significant cost savings by using Nessus to audit business-critical enterprise devices and applications.
3. John the Ripper
(http://www.openwall.com/john/)
John the Ripper is a fast password cracker. Its primary purpose is to detect weak Unix passwords. Besides several crypt password hash types most commonly found on various Unix flavors, supported out of the box are Kerberos AFS and
Windows NT/2000/XP/2003 LM hashes, plus several more with contributed patches.
4. Nikto
(http://www.net-security.org/software.php?id=223)
Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items. Scan items and plugins are frequently updated and can be automatically updated. Nikto is a good CGI scanner, there are some other tools that go well with Nikto.
5. SuperScan
Powerful TCP port scanner, pinger, resolver. If you need an alternative for nmap on Windows with a decent interface, I
suggest you check this out, it’s pretty nice.
6. p0f
P0f can identify the operating system on:
- machines that connect to your box (SYN mode),
- machines you connect to (SYN+ACK mode),
- machine you cannot connect to (RST+ mode),
- machines whose communications you can observe.
Basically it can fingerprint anything, just by listening, it doesn’t make ANY active connections to the target machine.
7. Wireshark
Wireshark is a GTK+-based network protocol analyzer, or sniffer, that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and to give Wireshark features that are missing from closed-source sniffers.
8. Yersinia
Yersinia is a network tool designed to take advantage of some weakeness in different Layer 2 protocols. It pretends to be a solid framework for analyzing and testing the deployed networks and systems.
9. Eraser
Eraser is an advanced security tool, which allows you to completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns.
10. PuTTY
PuTTY is a free implementation of Telnet and SSH for Win32 and Unix platforms, along with an xterm terminal emulator. A must have for any h4. 0r wanting to telnet or SSH from Windows without having to use the crappy default MS command
line clients.
Before, I used NMAP, Nessus, John the Ripper and PuTTy. PuTTy is also useful for SSH and Telnet connection. I think the best program is Nessus because it can show what kind of holes and bugs is in my program and what I should do. You guys should try do use yourself. I mean these programs are very useful.
Mar 24, 2009
Database security
Database security is one of the most effective and major security. I am going to write about MySQL and how to supply security of it because it is most popular database in the world. It is often used with PHP, Java, and etc on the Internet.
If it was installed default, there are some vulnerability. Example: root user doesn't have password, and it is befall able to buffer over attacks, so it means default MySQL database is easy to accessible for attackers.
Security requirements:
In order to achieve the highest possible level of security, the installation and configuration of MySQL should be performed in accordance with the following security requirements:
* MySQL database must be executed in a chrooted environment;
* MySQL processes must run under a unique UID/GID that is not used by any other system process;
* Only local access to MySQL will be allowed;
* MySQL root's account must be protected by a hard to guess password;
* The administrator's account will be renamed;
* Anonymous access to the database (by using the nobody account) must be disabled;
* All sample databases and tables must be removed.
Network security:
As with securing a network, securing a database by looking at the various layers that are involved is an effective approach. Security of databases can be defined as preventing unauthorized or accidental disclosure, alteration, or destruction of data.
Network design incorporates the three layers of a Web application running on different servers, usually set apart by firewalls that have specific rules to only let traffic through to the specific port on a specific server at whichever layer that the user is trying to access:
Internet -> Firewall -> Web -> Firewall -> Application -> Firewall -> Database
Something else that it should demonstrate is that it is very costly to implement such a design because firewalls and servers are not cheap. Oftentimes, a sys admin will choose a compromise, combining the application and database servers. This isn’t ideal from a security perspective; nevertheless, it is a vast improvement over leaving a sensitive database facing the Internet directly.
Access Control:
Access to information contained in the tables must be properly regulated. This can be done with control over direct access to the tables, and also through views. Views and privileges assigned to the views can be created to limit users to only see specified portions of data contained within a table.
In order to fully implement a secure MySQL database, it is necessary to learn the MySQL access control system. There are four privilege levels that apply:
1. Global: these privileges apply to all databases on a server.
2. Database: these privileges apply to all tables in a database.
3. Table: these apply to all columns within a table.
4. Column: these apply to individual columns in a table.
The usage of these commands is varied:
GRANT priv_type [(column_list)] [, priv_type [(column_list)] ...]
ON {tbl_name | * | *.* | db_name.*}
TO user_name [IDENTIFIED BY [PASSWORD] 'password']
[, user_name [IDENTIFIED BY 'password'] ...]
[REQUIRE
NONE |
[{SSL| X509}]
[CIPHER cipher [AND]]
[ISSUER issuer [AND]]
[SUBJECT subject]]
[WITH [GRANT OPTION | MAX_QUERIES_PER_HOUR # |
MAX_UPDATES_PER_HOUR # |
MAX_CONNECTIONS_PER_HOUR #]]
REVOKE priv_type [(column_list)] [, priv_type [(column_list)] ...]
ON {tbl_name | * | *.* | db_name.*}
FROM user_name [, user_name ...]
Role-based authentication should be considered when adding access to any database. Typical roles for access include administrator, user, programmer and operator.
Encryption:
The sensitivity of the data will logically determine the need for the use of encryption. There are a few things to consider when thinking about implementing encryption:
1. Will the data stored in the database need to be encrypted or just the user passwords?
2. Will you need to encrypt the data only in the local instance of the database, or do you need to also encrypt the data in transit?
Many of the standard secure database design principles apply to MySQL. Of course, it has many of its own intricacies that need to be understood and audited carefully before any database is fully implemented. Lastly, it is important to keep in mind that other layers of security apply when hosting a database, such as network and operating system security.
In last, I used some internet resources as http://www.securityfocus.com, MYSQL forum, WikiPedia.
If it was installed default, there are some vulnerability. Example: root user doesn't have password, and it is befall able to buffer over attacks, so it means default MySQL database is easy to accessible for attackers.
Security requirements:
In order to achieve the highest possible level of security, the installation and configuration of MySQL should be performed in accordance with the following security requirements:
* MySQL database must be executed in a chrooted environment;
* MySQL processes must run under a unique UID/GID that is not used by any other system process;
* Only local access to MySQL will be allowed;
* MySQL root's account must be protected by a hard to guess password;
* The administrator's account will be renamed;
* Anonymous access to the database (by using the nobody account) must be disabled;
* All sample databases and tables must be removed.
Network security:
As with securing a network, securing a database by looking at the various layers that are involved is an effective approach. Security of databases can be defined as preventing unauthorized or accidental disclosure, alteration, or destruction of data.
Network design incorporates the three layers of a Web application running on different servers, usually set apart by firewalls that have specific rules to only let traffic through to the specific port on a specific server at whichever layer that the user is trying to access:
Internet -> Firewall -> Web -> Firewall -> Application -> Firewall -> Database
Something else that it should demonstrate is that it is very costly to implement such a design because firewalls and servers are not cheap. Oftentimes, a sys admin will choose a compromise, combining the application and database servers. This isn’t ideal from a security perspective; nevertheless, it is a vast improvement over leaving a sensitive database facing the Internet directly.
Access Control:
Access to information contained in the tables must be properly regulated. This can be done with control over direct access to the tables, and also through views. Views and privileges assigned to the views can be created to limit users to only see specified portions of data contained within a table.
In order to fully implement a secure MySQL database, it is necessary to learn the MySQL access control system. There are four privilege levels that apply:
1. Global: these privileges apply to all databases on a server.
2. Database: these privileges apply to all tables in a database.
3. Table: these apply to all columns within a table.
4. Column: these apply to individual columns in a table.
The usage of these commands is varied:
GRANT priv_type [(column_list)] [, priv_type [(column_list)] ...]
ON {tbl_name | * | *.* | db_name.*}
TO user_name [IDENTIFIED BY [PASSWORD] 'password']
[, user_name [IDENTIFIED BY 'password'] ...]
[REQUIRE
NONE |
[{SSL| X509}]
[CIPHER cipher [AND]]
[ISSUER issuer [AND]]
[SUBJECT subject]]
[WITH [GRANT OPTION | MAX_QUERIES_PER_HOUR # |
MAX_UPDATES_PER_HOUR # |
MAX_CONNECTIONS_PER_HOUR #]]
REVOKE priv_type [(column_list)] [, priv_type [(column_list)] ...]
ON {tbl_name | * | *.* | db_name.*}
FROM user_name [, user_name ...]
Role-based authentication should be considered when adding access to any database. Typical roles for access include administrator, user, programmer and operator.
Encryption:
The sensitivity of the data will logically determine the need for the use of encryption. There are a few things to consider when thinking about implementing encryption:
1. Will the data stored in the database need to be encrypted or just the user passwords?
2. Will you need to encrypt the data only in the local instance of the database, or do you need to also encrypt the data in transit?
Many of the standard secure database design principles apply to MySQL. Of course, it has many of its own intricacies that need to be understood and audited carefully before any database is fully implemented. Lastly, it is important to keep in mind that other layers of security apply when hosting a database, such as network and operating system security.
In last, I used some internet resources as http://www.securityfocus.com, MYSQL forum, WikiPedia.
Jun 2, 2008
Tomcat-аас болж азаартсан нь
Би ер нь JAVA болон JSP дээр л програмаа бичдэг. Тэгээд үүнээсээ болоод TOMCAT-ийг л вэб сервер болгож ашгилдаг. Тэгсэн чинь саяхан tomcat маань серверийн IP-г муухай азаартуулдаг байна шдээ. Вэб серверээ би нэг дотоод IP болох A1.A2.A3.A4 гэж давиад түүн дээрээ Real IP болох B1.B2.B3.B4 гэсэн IP-г NAT хийгээд интернэтэд байршуулсан юм. Түүнчлэн DNS дээр CCCC.CC гэсэн домайн хаягийг B гэсэн IP руу зааж өгсөн. Гаднаас орж буй систем уул нь A гэсэн IP-г огт мэдэхгүй харин B гэсэн IP-аар л хандах учиртай шүүдээ. C гэсэн домайнаар хандахаар DNS нь B гэсэн IP-г л зааж өгнө.
Вэб браузераар хандаж байгаа үед энэхүү асуудал бидэнд учрахгүй. Харин элдэв HACKING TECHNOLOGY ашиглаж байгаа хүнд бол гаргаж ирээд байнлээ.
жишээ нь:
telnet cccc.cc 80 гэж ороод
HEAD / HTTP/1.0 эсвэл GET / HTTP/1.0
гээд үз
тэгхэд
Ингээд чи баригдав уу!!!
Энийг яаж сэргийлэх вэ?? За эхлээд гол асуудлаа бичье.
telnet www.yahoo.com 80
GET / HTTP/1.0
гээд үзээрэй. Энэ үед URL огт гарч ирэхгүйгээр www.yahoo.com-ийн үндсэн хуудасны HTML SOURCE код гараад ирнэ.
Яагаад минийхийг азаартуулж байж yahoo-г гаргаж ирэхгүй байна??
Вэб браузер дээр http://www.yahoo.com гээд үзья. Тэгсэн чинь хуудас маань зүгээр гарч ирч мөн URL нь http://www.yahoo.com/ гээд байна.
За тэгвэл http://cccc.cc/ гээд үзья. Тэгтэл index.jsp-д байгаа миний хийсэн хуудас маань гараад ирлээ. Харин URL дээр http://cccc.cc/index.jsp болчихсон байна. Яагаад араас нь index.jsp -ийг залгаад байна.
HTTP/1.1 302 Moved Temporarily
Location: http://A1.A2.A3.A4/index.jsp
Content-Length: 0
Server: Apache-Coyote/1.1
Connection: close
Гээд гарч ирээд байгаа нь автоматаар http://A1.A2.A3.A4/index.jsp гэсэн хаягруу REDIRECT хийгээд байгаа учраас л миний IP гарч ирээд байгаа юм байна. Энэ нь TOMCAT-ийн онцлог ч юм уу BUG ч юм уу.
Энэ асуудлыг өөрийнхөөрөө шийдсэн минь
import java.io.*;
import javax.servlet.*;
import javax.servlet.http.*;
public class homePage extends HttpServlet{
public void doGet(HttpServletRequest request,HttpServletResponse response)
throws IOException, ServletException{
response.sendRedirect("http://CCCC.CC/index.jsp");
}
}
гэсэн java servlet бичнэ.
Одоо бичсэн servlet ээ тухайн вэбийн web.xml -д зааж өгнө.


гэсэн бичлэг хийнэ.
Одоо харин хуучин гарж байсанаа дахиад үзье
telnet cccc.cc 80
GET / HTTP/1.0
HTTP/1.1 302 Moved Temporarily
Location: http://CCCC.CC/index.jsp
Content-Length: 0
Server: Apache-Coyote/1.1
Connection: close
гээд гараад ирлээ. Эврика болчихлоо.
Одоо яасан. Бас нэг асуудал гарлаа.
Би web.xml дээ servlet-н зааж өгөөгүй болхоор үндсэн / ээр нөгөө зураг (*.jpg, *.gif, etc) болон бусад файл маань гарж ирхээ больчихлоо одоо яах вэ?
:((
Санаа зоволтгүй.
web.xml дээ бүх хэргэлдэг файлын өргөтгөлөө tomcat-н ерөнхий web.xml-д заасан MIME ээр болгохоор заагаад л өгчих.

за одоо боллоо. Яг сайхан ажиллаж чадлаа.
Болойшдээ...
Вэб браузераар хандаж байгаа үед энэхүү асуудал бидэнд учрахгүй. Харин элдэв HACKING TECHNOLOGY ашиглаж байгаа хүнд бол гаргаж ирээд байнлээ.
жишээ нь:
telnet cccc.cc 80 гэж ороод
HEAD / HTTP/1.0 эсвэл GET / HTTP/1.0
гээд үз
тэгхэд
HTTP/1.1 302 Moved Temporarily
Location: http://A1.A2.A3.A4/index.jsp
Content-Length: 0
Server: Apache-Coyote/1.1
Connection: close
Ингээд чи баригдав уу!!!
Энийг яаж сэргийлэх вэ?? За эхлээд гол асуудлаа бичье.
telnet www.yahoo.com 80
GET / HTTP/1.0
гээд үзээрэй. Энэ үед URL огт гарч ирэхгүйгээр www.yahoo.com-ийн үндсэн хуудасны HTML SOURCE код гараад ирнэ.
Яагаад минийхийг азаартуулж байж yahoo-г гаргаж ирэхгүй байна??
Вэб браузер дээр http://www.yahoo.com гээд үзья. Тэгсэн чинь хуудас маань зүгээр гарч ирч мөн URL нь http://www.yahoo.com/ гээд байна.
За тэгвэл http://cccc.cc/ гээд үзья. Тэгтэл index.jsp-д байгаа миний хийсэн хуудас маань гараад ирлээ. Харин URL дээр http://cccc.cc/index.jsp болчихсон байна. Яагаад араас нь index.jsp -ийг залгаад байна.
HTTP/1.1 302 Moved Temporarily
Location: http://A1.A2.A3.A4/index.jsp
Content-Length: 0
Server: Apache-Coyote/1.1
Connection: close
Гээд гарч ирээд байгаа нь автоматаар http://A1.A2.A3.A4/index.jsp гэсэн хаягруу REDIRECT хийгээд байгаа учраас л миний IP гарч ирээд байгаа юм байна. Энэ нь TOMCAT-ийн онцлог ч юм уу BUG ч юм уу.
Энэ асуудлыг өөрийнхөөрөө шийдсэн минь
import java.io.*;
import javax.servlet.*;
import javax.servlet.http.*;
public class homePage extends HttpServlet{
public void doGet(HttpServletRequest request,HttpServletResponse response)
throws IOException, ServletException{
response.sendRedirect("http://CCCC.CC/index.jsp");
}
}
гэсэн java servlet бичнэ.
Одоо бичсэн servlet ээ тухайн вэбийн web.xml -д зааж өгнө.


Одоо харин хуучин гарж байсанаа дахиад үзье
telnet cccc.cc 80
GET / HTTP/1.0
HTTP/1.1 302 Moved Temporarily
Location: http://CCCC.CC/index.jsp
Content-Length: 0
Server: Apache-Coyote/1.1
Connection: close
гээд гараад ирлээ. Эврика болчихлоо.
Одоо яасан. Бас нэг асуудал гарлаа.
Би web.xml дээ servlet-н зааж өгөөгүй болхоор үндсэн / ээр нөгөө зураг (*.jpg, *.gif, etc) болон бусад файл маань гарж ирхээ больчихлоо одоо яах вэ?
:((
Санаа зоволтгүй.
web.xml дээ бүх хэргэлдэг файлын өргөтгөлөө tomcat-н ерөнхий web.xml-д заасан MIME ээр болгохоор заагаад л өгчих.
Болойшдээ...
My favorite jokes
JOKE #1
- Do you wanna chat?
- I'm busy.
- Hello, busy. I'm Baldan!...
JOKE #2
Boy: "Daddy? How did I come into this world?"
Dad: "Well, my child, some day I'll have to tell you any way.
Boy:"So why not today? Please!"
Dad: "OK, but listen carefully." "Mom and Dad met each other in a cyber cafe. In the restrooms of that cyber cafe, dad connected to mom. Mom at that time made some downloads from dad's memory stick. When dad finished uploading we discovered we used no firewall. Since it was too late to cancel or delete, nine months later we ended up with a virus."
- Do you wanna chat?
- I'm busy.
- Hello, busy. I'm Baldan!...
JOKE #2
Boy: "Daddy? How did I come into this world?"
Dad: "Well, my child, some day I'll have to tell you any way.
Boy:"So why not today? Please!"
Dad: "OK, but listen carefully." "Mom and Dad met each other in a cyber cafe. In the restrooms of that cyber cafe, dad connected to mom. Mom at that time made some downloads from dad's memory stick. When dad finished uploading we discovered we used no firewall. Since it was too late to cancel or delete, nine months later we ended up with a virus."
Subscribe to:
Posts (Atom)