ပုံထဲကလုိ Kali ရဲ႕ Terminal မွာ Matrix effect ေလးျမင္ခ်င္တယ္ဆုိရင္ sudo apt-get install cmatrix ကုိရုိက္ေပးရုံပါပဲ။ Y/N လုိ႔ျပရင္ y ကုိရုိက္ထည့္ျပီး Confirm လုပ္ေပးဖုိ႔လိုပါလိမ့္မယ္။ တကယ္လုိ႔ အဆင္မေျပခဲ့ဘူးဆုိရင္ ကြ်န္ေတာ္ အရင္တင္ထားတဲ့ပုိ႔စ္ အတုိင္းလုပ္ေပးဖုိ႔လုိပါလိမ့္မယ္။ အားလုံး အုိေကျပီဆုိ Terminal မွာ cmatrix လုိ႔ရုိက္လုိက္တာနဲ႔ Matrix effect ကုိျမင္ရပါျပီ။
Read more »
11/20/2013
How to Install Ubuntu Software Center in Kali Linux
Ubuntu Software Center က Default အေနနဲ႔Kali မွာမပါလာဘူး။ အဲဒါေၾကာင့္လုိအပ္မယ့္ repository package ေတြကုိ update လုပ္ေပးရပါတယ္။ အရင္ဆုံး Kali ရဲ႕ Source.list ကုိျပင္ေပးရပါမယ္။ Computer>File System> etc/apt/source.list ကုိသြားျပီး leafpad နဲ႔ဖြင့္လုိက္ပါ။ အဲဒီထဲက list မွာ ေအာက္လုိျပင္ေပးလုိက္ပါ။
......................................................................................................................
deb http://http.kali.org/ /kali main contrib non-free
deb http://http.kali.org/ /wheezy main contrib non-free
deb http://http.kali.org/kali kali-dev main contrib non-free
deb http://http.kali.org/kali kali-dev main/debian-installer
deb-src http://http.kali.org/kali kali-dev main contrib non-free
deb http://http.kali.org/kali kali main contrib non-free
deb http://http.kali.org/kali kali main/debian-installer
deb-src http://http.kali.org/kali kali main contrib non-free
deb http://security.kali.org/kali-security kali/updates main contrib non-free
deb-src http://security.kali.org/kali-security kali/updates main contrib non-free
......................................................................................................................................................
ျပီးရင္ Terminal မွာ apt-get update အရင္လုပ္ေပးပါ။ အဲဒါျပီးရင္ apt-get install software-center နဲ႔ update လုပ္ေပးဖုိ႔လုိပါတယ္။ ကြ်န္ေတာ္ဆီမွာေတာ့ error တက္လုိ႔ apt-get install software-center မရုိက္ခင္ apt-get -f install ကုိရုိက္ေပးရေသးတယ္။ အဲဒီ update step ေတြက အခ်ိန္ေပးရလုိ႔ သည္းခံဖုိ႔ေတာ့လုိလိမ့္မယ္ဗ်။ မေစာင့္ခ်င္ဘူးဆုိရင္ အစကတည္းက မလုပ္တာအေကာင္းဆုံးပဲဗ်ဳိ႕။ အားလုံး ေအာင္ျမင္တယ္ဆုိရင္ Kali မွာ Applications>System Tools>Administration>Software Center ကေန Ubuntu Software Center ကုိအသုံးျပဳလုိ႔ရပါျပီ။
[screenshot]
Read more »
......................................................................................................................
deb http://http.kali.org/ /kali main contrib non-free
deb http://http.kali.org/ /wheezy main contrib non-free
deb http://http.kali.org/kali kali-dev main contrib non-free
deb http://http.kali.org/kali kali-dev main/debian-installer
deb-src http://http.kali.org/kali kali-dev main contrib non-free
deb http://http.kali.org/kali kali main contrib non-free
deb http://http.kali.org/kali kali main/debian-installer
deb-src http://http.kali.org/kali kali main contrib non-free
deb http://security.kali.org/kali-security kali/updates main contrib non-free
deb-src http://security.kali.org/kali-security kali/updates main contrib non-free
......................................................................................................................................................
ျပီးရင္ Terminal မွာ apt-get update အရင္လုပ္ေပးပါ။ အဲဒါျပီးရင္ apt-get install software-center နဲ႔ update လုပ္ေပးဖုိ႔လုိပါတယ္။ ကြ်န္ေတာ္ဆီမွာေတာ့ error တက္လုိ႔ apt-get install software-center မရုိက္ခင္ apt-get -f install ကုိရုိက္ေပးရေသးတယ္။ အဲဒီ update step ေတြက အခ်ိန္ေပးရလုိ႔ သည္းခံဖုိ႔ေတာ့လုိလိမ့္မယ္ဗ်။ မေစာင့္ခ်င္ဘူးဆုိရင္ အစကတည္းက မလုပ္တာအေကာင္းဆုံးပဲဗ်ဳိ႕။ အားလုံး ေအာင္ျမင္တယ္ဆုိရင္ Kali မွာ Applications>System Tools>Administration>Software Center ကေန Ubuntu Software Center ကုိအသုံးျပဳလုိ႔ရပါျပီ။
[screenshot]
ကြ်န္ေတာ့္ဆီမွာ ရေနပါျပီ။ မရဘူးဆုိရင္ တစ္ခုခုမွားေနလုိ႔ျဖစ္ပါလိမ့္မယ္။ :D
Labels:
Kali,
Linux,
Tips and Tricks,
Ubuntu
11/19/2013
Veil AV Evasion Part I [Installation]
FUD လုပ္တဲ့ Tool ေတြထဲမွာ Veil ကနာမည္ရေနတဲ့တစ္ခုပါ။ ဒီပုိ႔စ္မွာ Veil ကုိအင္စေတာ့လုပ္နည္း ေရးသားသြားပါမယ္။ Windows မွာဆုိရင္ေတာ့ Python ကုိ install လုပ္ေပးဖုိ႔လုိတာေပါ့ေနာ္။ Windows မွာ install လုပ္ပုံကုိေတာ့ မရွင္းျပေတာ့ပါဘူး။ အလုပ္ရွဳပ္လုိ႔။ :D ကြ်န္ေတာ္ကေတာ့ Kali မွာစမ္းသပ္ထားပါတယ္။ Kali မွာရရင္ Backtrack မွာလည္းအတူတူပဲျဖစ္ပါတယ္။ Veil အေၾကာင္းအေသးစိတ္ဖတ္ခ်င္ရင္ Veil Official Site မွာအေသးစိတ္ေလ့လာႏုိင္ပါတယ္။ အုိေက။ အရင္ဆုံး လုိအပ္တဲ့ဖုိင္ကုိ ေဒါင္းထားလုိက္ပါ။ ဖုိင္ဆုိး္ကလည္း 600 KB ေလာက္ပါပဲ။
Veil Download: [Github] [Mirror] [Mirror]
Download လုိက္ျပီးရလာတဲ့ဖုိင္ကုိ Desktop မွာထားမယ္ဆုိရင္ Terminal ကေန cd Desktop လုိ႔ေျပာင္းေပးေပါ့ေနာ္။ ေဒါင္းထားတဲ့ဖုိင္က Home မွာဆုိရင္လုပ္စရာမလုိပါဘူး။ အရင္ဆုံး zip ကုိ extract လုပ္ေပးရပါမယ္။
unzip Veil-master.zip
ျပီးရင္ ေအာက္ကအတုိင္း ဆက္သြားရုံပါပဲ။
cd ./Veil-master/setup/
chmod 775 setup.sh
./setup.sh
ဒါဆုိရင္ ေအာက္ကလုိ installation လုပ္ေနပါလိမ့္မယ္။ ဒီအဆင့္မွာအခ်ိန္နည္းနည္းေပးရပါမယ္။ ျပီးတဲ့အထိေစာင့္ေပးေပါ့ဗ်ာ။ ကြ်န္ေတာ္ဆီမွာေတာ့ တက္လုိက္က်လုိက္နဲ႔ေတာ္ေတာ္ၾကာသြားတယ္။ ကလိခ်င္တယ္ဆုိရင္ ဇြဲေတာ့ရွိဖုိ႔လုိတာေပါ့ဗ်ာ။ :)
Download လုပ္တာေအာင္ျမင္ျပီဆုိရင္ ေအာက္ကလုိ Box ေလးက်လာပါျပီ။ က်န္တာကေတာ့ Windows မွာလုိပဲ Next>> နဲ႔ဆက္သြားရုံပါပဲ။
ကြ်န္ေတာ္ဆီမွာေတာ့ အားလုံး ေအာင္ျမင္ပါျပီ။ ok, ဒါဆုိရင္ Terminal မွာ ကြ်န္ေတာ္တုိ႔ လက္ရွိေရာက္ေနတဲ့ Directory ကေန ./Veil.py command နဲ႔ Veil ကုိသုံးလုိ႔ရပါျပီဗ်ာ။ ဒါကေတာ့ ./Veil.py ကုိေခၚလုိက္ရင္ျမင္ရမယ့္ပုံပါ။
list ကုိေခၚၾကည့္ရင္ ေအာက္ကလုိ option ေတြကုိျမင္ရပါမယ္။
option ေတြကေတာ့ အမ်ားၾကီးပဲဗ်။ အဲဒီကေန RAT, Virus, Keylogger, Backdoor စတဲ့ Tool ေတြကုိ FUD ျဖစ္ေအာင္ ဖန္တီးႏုိင္ပါတယ္။ Coming Soon :D
My Next post: How to Make FUD
Read more »
Veil Download: [Github] [Mirror] [Mirror]
Download လုိက္ျပီးရလာတဲ့ဖုိင္ကုိ Desktop မွာထားမယ္ဆုိရင္ Terminal ကေန cd Desktop လုိ႔ေျပာင္းေပးေပါ့ေနာ္။ ေဒါင္းထားတဲ့ဖုိင္က Home မွာဆုိရင္လုပ္စရာမလုိပါဘူး။ အရင္ဆုံး zip ကုိ extract လုပ္ေပးရပါမယ္။
unzip Veil-master.zip
ျပီးရင္ ေအာက္ကအတုိင္း ဆက္သြားရုံပါပဲ။
cd ./Veil-master/setup/
chmod 775 setup.sh
./setup.sh
ဒါဆုိရင္ ေအာက္ကလုိ installation လုပ္ေနပါလိမ့္မယ္။ ဒီအဆင့္မွာအခ်ိန္နည္းနည္းေပးရပါမယ္။ ျပီးတဲ့အထိေစာင့္ေပးေပါ့ဗ်ာ။ ကြ်န္ေတာ္ဆီမွာေတာ့ တက္လုိက္က်လုိက္နဲ႔ေတာ္ေတာ္ၾကာသြားတယ္။ ကလိခ်င္တယ္ဆုိရင္ ဇြဲေတာ့ရွိဖုိ႔လုိတာေပါ့ဗ်ာ။ :)
Download လုပ္တာေအာင္ျမင္ျပီဆုိရင္ ေအာက္ကလုိ Box ေလးက်လာပါျပီ။ က်န္တာကေတာ့ Windows မွာလုိပဲ Next>> နဲ႔ဆက္သြားရုံပါပဲ။
ကြ်န္ေတာ္ဆီမွာေတာ့ အားလုံး ေအာင္ျမင္ပါျပီ။ ok, ဒါဆုိရင္ Terminal မွာ ကြ်န္ေတာ္တုိ႔ လက္ရွိေရာက္ေနတဲ့ Directory ကေန ./Veil.py command နဲ႔ Veil ကုိသုံးလုိ႔ရပါျပီဗ်ာ။ ဒါကေတာ့ ./Veil.py ကုိေခၚလုိက္ရင္ျမင္ရမယ့္ပုံပါ။
list ကုိေခၚၾကည့္ရင္ ေအာက္ကလုိ option ေတြကုိျမင္ရပါမယ္။
option ေတြကေတာ့ အမ်ားၾကီးပဲဗ်။ အဲဒီကေန RAT, Virus, Keylogger, Backdoor စတဲ့ Tool ေတြကုိ FUD ျဖစ္ေအာင္ ဖန္တီးႏုိင္ပါတယ္။ Coming Soon :D
My Next post: How to Make FUD
FUD Crypter Basic
ဒီပုိ႔စ္မွာ ကြ်န္ေတာ္ Crypter အေၾကာင္းကုိ ကြ်န္ေတာ္နားလည္မိသေလာက္
ေရးၾကည့္ပါမယ္။ Crypter ဆုိတာကေတာ့ ကြ်န္ေတာ္တုိ႔ ဖန္တီးလုိက္တဲ့ Virus,
RAT, Keylogger စတဲ့ Tool ေတြကုိ Antivirus ေတြမသိေအာင္ လုပ္ထားတဲ့
ေဆာ့ဝဲလ္တစ္ခုလုိ႔ ေျပာႏုိင္ပါတယ္။ Crypter အလုပ္လုပ္တာကေတာ့
ကုိယ္လုပ္ထားတဲ့ Tool ရဲ႕ source code ေတြကုိ antivirus ေတြမသိေအာင္
ဝွက္လုိက္တာပဲျဖစ္ပါတယ္။ Antivirus ေတြအေနနဲ႕ Virus တစ္ခုကုိ Detect
ျဖစ္ဖုိ႔ အဲဒီေဆာ့ဝဲလ္ရဲ႕ souce code ေတြကုိ split အရင္လုပ္ျပီး သံသယရွိတဲ့
string ေတြကုိလုိက္ရွာပါတယ္။ ဥပမာ souce code ထဲမွာ file ေတြကုိ မတာရား
ေကာ္ပီကူးခုိင္းတဲ့ code ေတြပါဝင္ေနတာမ်ဳိးေပါ့။ ဒါဆုိရင္ antivirus က အဲဒီ
program ကုိ detection ျဖစ္ျပီး ကုိယ္ရဲ႕ RAT ဟာ အဖ်က္ခံရမွာပါ။
FUD Crypter
FUD ဆုိတာက Fully UnDetectable ကုိရည္ညြန္းတာပါ။ FUD Crypter အလုပ္လုပ္ပုံကုိ ကြ်န္ေတာ္အနည္းငယ္ရွင္းျပပါမယ္။ ကြ်န္ေတာ္တုိ႔ program တစ္ခုေရးလုိက္တယ္ဆုိပါစုိ႔။ ေအာက္မွာနမူနာေလးၾကည့္ပါ။
Original Exe Crypted Exe
001————- 010 101————-110
100|Original File|000 > -> Cryptor -> -> 010|Original File|110
010————- 111 110————-010
FUD ဆုိတာက Fully UnDetectable ကုိရည္ညြန္းတာပါ။ FUD Crypter အလုပ္လုပ္ပုံကုိ ကြ်န္ေတာ္အနည္းငယ္ရွင္းျပပါမယ္။ ကြ်န္ေတာ္တုိ႔ program တစ္ခုေရးလုိက္တယ္ဆုိပါစုိ႔။ ေအာက္မွာနမူနာေလးၾကည့္ပါ။
Original Exe Crypted Exe
001————- 010 101————-110
100|Original File|000 > -> Cryptor -> -> 010|Original File|110
010————- 111 110————-010
ဒါက ဘာကုိဆုိလုိတာလဲဆုိေတာ့ File Size ၾကီးသြားတာကုိေျပာတာပါ။ ဒါေၾကာင့္
ေယဘုယ်အားျဖင့္ FUD Crypter ေတြဟာ AV ေတာ္ေတာ္မ်ားမ်ားေတြကုိ bypass
လုပ္ႏုိင္ေပမယ့္ ဖုိင္ဆုိဒ္ၾကီးတာကုိေတာ့ လုပ္လုိ႔မရပါဘူး။ ဥပမာ original
exe ရဲ႕ file size က 10KB ရွိတယ္ဆုိရင္ crypt လုပ္ဖုိ႔က ေနာက္ထပ္ 100 KB
လုိအပ္မွာျဖစ္ပါတယ္။ ဒါေၾကာင့္ 10 KB ရွိတဲ့ program တစ္ခုဟာ 110 KB
ေလာက္ရွိသြားပါမယ္။ 10 ဆေလာက္ကုိၾကီးသြားတာ။ ကြ်န္ေတာ္ကေတာ့ FUD ေတြဘာေတြမလုပ္ဖူးေတာ့ အတိအက်ေတာ့မသိဘူးရယ္။
ကြ်န္ေတာ္တုိ႔ အေနနဲ႔ original exe ရဲ႕ file size ကုိအတိအက်သိခဲ့မယ္ဆုိရင္
FUD Crypter ကုိသိႏုိင္တာေပါ့ေနာ္။ ဒါေပမယ့္ ခုေနာက္ပုိင္း AV ေတြလည္း FUD
ေတြကုိ Detect ျဖစ္လာပါျပီ။ တကယ့္ကုိ FUD ျဖစ္တဲ့ Tool တစ္ခုဟာ Public
မွာမရွိႏုိင္ပါဘူး။ ရွိမယ္ဆုိရင္လည္း AV ကသိမွာျဖစ္ပါတယ္။ ပုံမွန္ FUD
တစ္ခုဟာ Public ျဖစ္ျပီး ၂ ရက္ ၃ ရက္အတြင္း AV Detect ျဖစ္ပါတယ္။ ဒါေၾကာင့္
FUD ျဖစ္တဲ့ Tool တစ္ခုကုိ ရွာဖုိ႔ဆုိရင္ Hackforum ေတြထဲမွာသာ
ရွာလုိ႔ရပါလိမ့္မယ္။ Skill ရွိတဲ့ programmer တစ္ေယာက္ေယာက္ကထြင္ထားျပီး
public မလုပ္ေသးခင္ေပါ့။ ကုိယ့္လုပ္ထားတဲ့ (ဒါမွမဟုတ္ ရထားတဲ့) RAT တစ္ခု
FUD ျဖစ္/မျဖစ္ http://scanner.novirusthanks.org
မွာသြားျပီးစစ္ေဆးၾကည့္ႏုိင္ပါတယ္။ အဲဒီမွာ Do not distribute the sample
ဆုိတဲ့ check box ကုိေတာ့ check လုပ္ထားေပါ့ေနာ္။
ေနာက္ထပ္အေရးၾကီးတဲ့ဟာတစ္ခုကေတာ့ ကုိယ့္ရဲ႕ FUD ကုိ http://www.virustotal.com မွာသြားျပီး မစစ္ေဆးမိဖုိ႔ပါပဲ။ သူ႕ဆီမွာသြားျပီး စစ္ေဆးလုိ႔ကေတာ့ အဲဒီ နမူနာဖုိင္ကုိ auto distrubute
လုပ္ပစ္လုိက္မွာပါ။ ဒါဆုိရင္ ကုိယ္လုပ္ထားတဲ့ RAT ဟာ FUD
မျဖစ္ႏုိင္ေတာ့ပါဘူး။ ကြ်န္ေတာ္တုိ႔ အေနနဲ႔ FUD ေတြကုိ
အင္တာနက္မွာရွာၾကည့္ႏုိင္ပါတယ္။ public မဟုတ္ဘဲ indivual ပုံစံ
ရွယ္ထားတာမ်ဳိးေပါ့။ ကြ်န္ေတာ္အေနနဲ႕ FUD တစ္ခုကုိဘယ္လုိလုပ္မွာလဲဆုိတာ
ေျပာျပခ်င္ေပမယ့္ ေသခ်ာမလုပ္ဖူးေသးလုိ႔ အေသးစိတ္မေျပာျပႏုိင္ပါဘူး။ BT ကေန
အဲလုိအေကာင္တစ္ခုလုပ္လုိ႔ရတယ္လုိ႔ေတာ့ ေတြ႕ဖူးတယ္။
ဒါေပမယ့္ အေသးစိတ္မစမ္းဖူးေတာ့ အမ်ားၾကီးမေျပာျပႏုိင္တာ
နားလည္ေပးၾကပါခင္ဗ်။ Veil ကုိသုံးျပီး FUD တစ္ခုျပဳလုပ္နည္းကုိ အဆင္ေျပရင္ ဆက္ေရးပါအုံးမယ္။ ဒီပုိ႔စ္ကုိေတာ့ FUD Crypter Basic
အျဖစ္သာရည္ရြယ္ပါတယ္။
MSF မွာကြ်န္ေတာ္ရဲ႕ကုိယ္ပုိင္ Thread ေလးကုိျပန္ကူးထားပါသည္။
Read @ http://www.4sectors.com/forum/showthread.php?tid=1117&pid=3784#pid3784
My Next Post: Veil AV Evasion Part I [Installation]
Labels:
FUD
11/18/2013
Automatically starting X with GDM in Backtrack
ကြ်န္ေတာ္တုိ႔ Backtrack5 မွာ Boot တက္လုိက္ရင္ အျခား Windows, Ubuntu တုိ႔လုိ username, password ရုိက္ေပးရမယ့္ Login Screen ကုိတန္းမေရာက္ဘူးဗ်။ အဲဒီအစား Command line ကေန usernae, password ကုိရုိက္ေပးရတယ္။ ျပီးတာေတာင္ startx လုိ႔ရုိက္ေပးရေသးတယ္။ ကြ်န္ေတာ္အစကမသိလုိ႔ အင္စေတာ့လုပ္ျပီးတာေတာင္ ဘယ္နားကေနဝင္ရမွန္းမသိလုိ႔ ေတာ္ေတာ္တုိင္ပတ္ဖူးတယ္။ ေလထွာ။ :D အခု Tool ေလးကုိအသုံးျပဳျပီး သူမ်ား OS ေတြလုိ password ရုိက္ရမယ့္ေနရာမွာ လူလုိသူလုိျဖစ္ေအာင္ ေျပာင္းၾကည့္မယ္ဗ်ာ။ :P
အရင္ဆုံး Terminal ကေန apt-install gdm လုိ႔ရုိက္လုိက္ပါ။ ဒါဆုိ သူ႕ဟာသူဆက္လုပ္သြားပါလိမ့္မယ္။ သိပ္မၾကာပါဘူး။ Done ဆုိျပီးေပၚလာရင္ ေတာ္ေတာ္ဟုတ္ေနပါျပီ။
အုိခီ ျပီးရင္ အလုပ္ျဖစ္မျဖစ္ Terminal မွာ gdm ဆုိျပီးရုိက္ၾကည့္လုိက္ပါ။ ေအာင္ျမင္တယ္ဆုိရင္ Logon Screen ကုိျပေပးပါလိမ့္မယ္။ ေနာက္ Terminal ကေန nano /etc/init/gdm.conf ဆုိျပီးသြားရင္လည္းရတယ္။ ဒါမွမဟုတ္ Computer>File System>etc>init>gdm.conf ဆီကုိသြားျပီး အဲဒီ gdm.conf ဖုိင္ကုိဖြင့္လုိက္ပါ။ ဒါဆုိရင္ အထဲမွာ config ဖုိင္ကုိေတြ႔ရပါမယ္။ မူလအတုိင္းဆုိရင္ ေအာက္ကအတုိင္းျဖစ္ပါလိမ့္မယ္။
# gdm - GNOME Display Manager
#
# The display manager service manages the X servers running on the
# system, providing login and auto-login services
description "GNOME Display Manager"
author "William Jon McCann <mccann@jhu.edu>"
start on (filesystem
and started dbus
and (drm-device-added card0 PRIMARY_DEVICE_FOR_DISPLAY=1
or stopped udevtrigger))
stop on runlevel [016]
emits starting-dm
env XORGCONFIG=/etc/X11/xorg.conf
script
if [ -n "$UPSTART_EVENTS" ]
then
[ ! -f /etc/X11/default-display-manager -o "$(cat
/etc/X11/default-display-manager 2>/dev/null)" = "/usr/sbin/gdm" ] ||
{ stop; exit 0; }
# Check kernel command-line for inhibitors
for ARG in $(cat /proc/cmdline)
do
case "${ARG}" in
text|-s|s|S|single)
plymouth quit || : # We have the ball here
exit 0
;;
esac
done
fi
if [ -r /etc/default/locale ]; then
. /etc/default/locale
export LANG LANGUAGE
elif [ -r /etc/environment ]; then
. /etc/environment
export LANG LANGUAGE
fi
export XORGCONFIG
exec gdm-binary $CONFIG_FILE
end script
အဲဒီမွာ အနီနဲ႕ျပထားတဲ့ code line ေတြကုိဖ်က္ေပးရပါတယ္။ ျပီးရင္ Save ေပါ့ဗ်ာ။ ဒါဆုိရင္ ေအာက္ပါအတုိင္းျဖစ္သြားပါမယ္။
# gdm - GNOME Display Manager
#
# The display manager service manages the X servers running on the
# system, providing login and auto-login services
description "GNOME Display Manager"
author "William Jon McCann <mccann@jhu.edu>"
start on (filesystem
and started dbus
and (drm-device-added card0 PRIMARY_DEVICE_FOR_DISPLAY=1
or stopped udevtrigger))
stop on runlevel [016]
emits starting-dm
env XORGCONFIG=/etc/X11/xorg.conf
script
export XORGCONFIG
exec gdm-binary $CONFIG_FILE
end script
အုိခီ ျပီးရင္ BT ကုိ reboot လုပ္ေပးလုိက္ေပါ့ေနာ္။ Terminal ကေန reboot ဆုိရင္ရပါျပီ။ :D ဒါဆုိရင္ Boot တက္လာတာနဲ႔ ေအာက္ကလုိ ေတြ႕ရပါမယ္။
Warning: တစ္ခုခုမွားလုပ္မိရင္ Login ဝင္မရတာမ်ဳိးျဖစ္တတ္ပါတယ္။ အာ့ေၾကာင့္ ဒီနည္းကုိစမ္းမယ္ဆုိ account အသစ္တစ္ခုလုပ္ျပီးမွစမ္းပါ။ Code:
useradd -m -g users -G admin,video,disk,games,cdrom -s /bin/bash test_user
ေနာက္ စမ္းမယ့္ gdm.conf ဖုိင္ကုိလည္း Backup လုပ္ထားပါ။ Code:
cp /etc/init/gdm.conf /etc/init/gdm.conf.backup
Labels:
Backtrack,
Linux,
Tips and Tricks
11/17/2013
Install Gerix Wifi Crackrer in Backtrack/Kali/Ubuntu
Linux ကေန Wifi Network ကုိ attack လုပ္မယ္ဆုိရင္ ဒီေကာင္နဲ႔လည္းစမ္းၾကည့္ေပါ့ဗ်ာ။ ကြ်န္ေတာ္ကေတာ့ BT မွာ test လုပ္ထားပါတယ္။ Kali မွာဆုိရင္လည္း အတူူပါပဲ။ Ubuntu ဆုိရင္ေတာ့ sudo ခံေပးလုိက္ပါ။ အရင္ဆုံး လုိအပ္မယ့္ Tool ကုိ ေဒါင္းရေအာင္။ size ကေသးေသးမုိ႔ အဆင္ေျပမွာပါ။
wget http://www.clshack.it/nopaste/gerix-wifi-cracker-ng-2.0-bt7.deb
ျပီးရင္ ေအာက္ကအတုိင္း Install လုပ္ေပးရုံပါပဲ။ Ubuntu မွာဆုိရင္ ေရွ႕က sudo ခံေပးပါ။ တကယ္လုိ႔ အဆင္မေျပဘူးဆုိရင္ Ubuntu အတြက္ mkdir / pentest / wireless / wifi-gerix-cracker-ng အဲလုိ Dir တစ္ခုလုပ္ေပးပါ။ BT/Kali မွာေတာ့ အဆင္ေျပပါတယ္။ dpkg -i gerix-wifi-cracker-ng-2.0-bt7.deb
Install ျပီးတာနဲ႔ ေအာက္က command တစ္ခုနဲ႔ Run ေပးလုိက္ရင္ရပါျပီ။ Ubuntu မွာဆုိ sudo ခံေပးေပါ့ေနာ္။ :D
python /usr/share/gerix-wifi-cracker-ng/gerix.py
or
python /pentest/wireless/gerix-wifi-cracker-ng/gerix.py
ဒါဆုိရင္ ေအာက္ကလုိ Gerix Wifi Crackrer ကုိအသုံးျပဳႏုိင္ပါျပီ။
Labels:
Backtrack,
Kali,
Linux,
Ubuntu,
Wireless Hacking Tools
Installing uTorrent in Linux
ကြ်န္ေတာ္ကေတာ့ Backtrack5 မွာ test လုပ္ျပထားပါတယ္။ Kali မွာလည္း
အဆင္ေျပမွာပါ။ Ubuntu ဆုိရင္ေတာ့ sudo command သုံးေပးရမယ္ထင္တယ္။
လုိအပ္မယ့္ ဖုိင္ကုိေတာ့ http://www.utorrent.com/downloads/linux
ကေန ubuntu နဲ႔ျပထားတဲ့ tar ဖုိင္ကုိပဲဆြဲလုိက္ပါ။ ဖုိင္ဆုိဒ္ကေတာ့ 2.1 MB
ေလာက္ရွိပါမယ္။ ျပီးရင္ လြယ္လြယ္ကူကူ Desktop မွာပဲသိမ္းထားလုိက္ပါ။
ပုံထဲကလုိ ဖုိင္ကုိေျဖဖုိ႔ tar -xvf yourfilename.tar.gz ကုိသုံးပါ။ ဖုိင္နာမည္ကေတာ့ မိမိေဒါင္းတဲ့ ဗားရွင္းအလုိက္ကြဲႏုိင္ပါတယ္။
ျပီးရင္ ေအာက္ကလုိ Directory change ေပးလုိက္ပါ။
cd utorrent-server-alpha-v3 3
cd utorrent-server-alpha-v3 3
ေနာက္ ls ေခၚၾကည့္လုိက္ရင္ utserver ဆုိတာကုိေတြ႕ရပါမယ္။ လုပ္ေပးရမွာက
./utserver လုိ႔ရုိက္ေပးပါ။
./utserver လုိ႔ရုိက္ေပးပါ။
ဒီေနရာမွာေတာ့ ကြ်န္ေတာ္ဆီမွာ error တက္တယ္ဗ်။ ဒါေၾကာင့္ Desktop ေပၚမွာ
extract ျဖစ္ေနတဲ့ Folder ကုိဖြင့္ျပီး utserver ဖုိင္ကုိ Properties ကေန
permission မွာ Read/Write ေပးလုိက္ပါ။ ျပီးရင္ ခုနက command ./utserver
ကုိျပန္လုပ္ၾကည့္ေပါ့ေနာ္။ error မတက္ေတာ့ဘူးဆုိတာ သိဖုိ႔ ခုနက extract
ျဖစ္ေနတဲ့ဖုိလ္ဒါထဲမွာ resume.dat, settings.dat စတဲ့ဖုိင္ေတြတုိးလာရင္
သိႏုိင္တယ္ဗ်။ အစကေတာ့ အဲဒီဖုိင္ေတြမရွိဘူးေပါ့ေနာ္။ ဒါဆုိရင္ utorrent
installation ေအာင္ျမင္ျပီလုိ႔ေျပာႏုိင္ပါျပီ။ အဲသလုိမျဖစ္ရင္
ခုနကလုိေသခ်ာျပန္စစ္ၾကည့္ေပါ့ေနာ္။ ကြ်န္ေတာ္အရင္က kali
မွာစမ္းတာအဆင္မေျပလုိ႔ လက္ေလ်ာဖူးတယ္။ အုိေက ျပီးရင္ browser ကေန
localhost:8080/gui လုိ႔ရုိက္ထည့္လုိက္ပါ။ password ေတာင္းပါမယ္။ username
မွာ admin ပါ။ password မွာေတာ့ခ်န္ထားလုိက္ပါ။ ဒါဆုိရင္ ေအာက္ကလုိ Linux
မွာ utorrent ကုိသုံးလုိ႔ရပါျပီ။
Labels:
Backtrack,
Kali,
Linux,
Tips and Tricks,
Ubuntu
11/16/2013
How to activate IIS on Windows 8
IIS Service ကုိ Windows 8 မွာ အသုံးျပဳခ်င္တယ္ဆုိရင္ လြယ္ပါတယ္။ ေအာက္က ကြ်န္ေတာ္ျပတဲ့အတုိင္းလုပ္လုိက္ရုံပါပဲခင္ဗ်။ Windows 7 မွာေတာ့ လုိအပ္မယ့္ package ေတြကုိေဒါင္းဖုိ႔လုိမယ္ထင္တယ္။ ေသခ်ာမစမ္းရေသးလုိ႔ေနာက္မွ
ျပန္ေရးေတာ့မယ္။ အရင္ဆုံး Windows 8 မွာ Windows Key+R ကေန Run ကုိေခၚလုိက္ပါ။ ျပီးရင္ Run ကေန control panel လုိ႔ရုိက္ျပီးသြားလုိက္ေပါ့။ အဲဒီမွာ Programs ကေန Turn Windows features on or off ကုိေရြးလုိက္ပါ။ အဲဒီကမွ Internet information Services ေအာက္က Web Management Tools နဲ႕World Wide Web Services ကုိအမွန္ျခစ္ေပးလုိက္ျပီး OK ကုိႏွိပ္လုိက္ရင္ရပါျပီ။ Save လုပ္တာကုိခဏေစာင့္လုိက္ပါ။ ျပီးရင္ Internet Explorer မွာ localhost လုိ႔ရုိက္ထည့္လုိက္ရင္
IIS Service ကုိျမင္ရပါျပီ။ ေအာက္မွာ ပုံေတြကုိ step by step ျပထားပါတယ္။ ပုံကုိတစ္ခ်က္ၾကည့္လုိက္ရင္ နားလည္သြားပါလိမ့္မယ္။
ျပန္ေရးေတာ့မယ္။ အရင္ဆုံး Windows 8 မွာ Windows Key+R ကေန Run ကုိေခၚလုိက္ပါ။ ျပီးရင္ Run ကေန control panel လုိ႔ရုိက္ျပီးသြားလုိက္ေပါ့။ အဲဒီမွာ Programs ကေန Turn Windows features on or off ကုိေရြးလုိက္ပါ။ အဲဒီကမွ Internet information Services ေအာက္က Web Management Tools နဲ႕World Wide Web Services ကုိအမွန္ျခစ္ေပးလုိက္ျပီး OK ကုိႏွိပ္လုိက္ရင္ရပါျပီ။ Save လုပ္တာကုိခဏေစာင့္လုိက္ပါ။ ျပီးရင္ Internet Explorer မွာ localhost လုိ႔ရုိက္ထည့္လုိက္ရင္
IIS Service ကုိျမင္ရပါျပီ။ ေအာက္မွာ ပုံေတြကုိ step by step ျပထားပါတယ္။ ပုံကုိတစ္ခ်က္ၾကည့္လုိက္ရင္ နားလည္သြားပါလိမ့္မယ္။
[Screenshot]
Labels:
IIS,
Tips and Tricks,
Windows 8
11/14/2013
FruityWifi in Kali
FruityWifi ဆုိတာ wireless network auditing tool တစ္ခုပါပဲ။ ဒီေကာင္က
Debian based linux platform ေတြမွာအလုပ္ျဖစ္ပါတယ္။ Kali Linux, Kali Linux
ARM (Raspberry Pi), Raspbian (Raspberry Pi) ေတြမွာလည္း Run လုိ႔ရမွာပါ။
ကြ်န္ေတာ္ကေတာ့ Kali မွာစမ္းထားပါတယ္။ အေသးစိတ္ ကုိယ့္ဘာသာကလိ။
Download: FruityWifi in Kali
Mirror: Mediafire
Mirror: Rghost
ရလာတဲ့ဖုိင္ကုိ Desktop မွာထားျပီး အရင္ဆုံး unzip လုပ္ပါ။ သုံးရမယ့္ command ကေတာ့
cd Desktop
unzip FruityWifi-master.zip
ဒါဆုိ Desktop မွာ FruityWifi-master ဆုိတဲ့ Folder ေလးရပါမယ္။ အထဲမွာ install-FruityWifi.sh ဆုိတဲ့ဖုိင္ေလးကုိ run ေပးရပါမယ္။ အဲဒီဖုိင္ကုိ run ဖုိ႔ ဒီတုိင္းမရေသးပါဘူး။ အာ့ဒါေၾကာင့္ install-FruityWifi.sh ဖုိင္ကုိ right-click>Properties>Permissions(tab) ေအာက္မွာ execute ဆုိတာေလးကုိ အမွန္ျခစ္ေပးရပါတယ္။ ျပီးရင္ အဲဒီဖုိင္ကုိ Open လုိက္ျပီး Run in Terminal ကုိေရြးလုိက္ပါ။
[screenshot]
လုိအပ္တဲ့ဖုိင္ေတြကုိ ေဒါင္းေနပါလိမ့္မယ္။ ဒီအဆင့္မွာ ေတာ္ေတာ္ၾကာသြားတယ္။ ကြန္မေကာင္းရင္ေတာ့ ေဆးလိပ္ကေလးဖြာ ဒါမွမဟုတ္တစ္ခုခုေမာ့ေနလုိက္ဗ်ာ။
Read more »
Download: FruityWifi in Kali
Mirror: Mediafire
Mirror: Rghost
ရလာတဲ့ဖုိင္ကုိ Desktop မွာထားျပီး အရင္ဆုံး unzip လုပ္ပါ။ သုံးရမယ့္ command ကေတာ့
cd Desktop
unzip FruityWifi-master.zip
ဒါဆုိ Desktop မွာ FruityWifi-master ဆုိတဲ့ Folder ေလးရပါမယ္။ အထဲမွာ install-FruityWifi.sh ဆုိတဲ့ဖုိင္ေလးကုိ run ေပးရပါမယ္။ အဲဒီဖုိင္ကုိ run ဖုိ႔ ဒီတုိင္းမရေသးပါဘူး။ အာ့ဒါေၾကာင့္ install-FruityWifi.sh ဖုိင္ကုိ right-click>Properties>Permissions(tab) ေအာက္မွာ execute ဆုိတာေလးကုိ အမွန္ျခစ္ေပးရပါတယ္။ ျပီးရင္ အဲဒီဖုိင္ကုိ Open လုိက္ျပီး Run in Terminal ကုိေရြးလုိက္ပါ။
[screenshot]
လုိအပ္တဲ့ဖုိင္ေတြကုိ ေဒါင္းေနပါလိမ့္မယ္။ ဒီအဆင့္မွာ ေတာ္ေတာ္ၾကာသြားတယ္။ ကြန္မေကာင္းရင္ေတာ့ ေဆးလိပ္ကေလးဖြာ ဒါမွမဟုတ္တစ္ခုခုေမာ့ေနလုိက္ဗ်ာ။
Ok, ျပီးျပီဆုိရင္ Computer>File System ကုိဖြင့္ၾကည့္ပါ။ FruityWifi
ဆုိတဲ့ ဖုိလ္ဒါေလးေရာက္ေနပါလိမ့္မယ္။ ဒါဆုိရျပီ။ Browser ကုိဖြင့္ျပီး
localhost/FruityWifi/ လုိ႔ေခၚလုိက္ရင္ ေအာက္ကလုိေပၚလာပါမယ္။ username: admin password: admin
ဒါကေတာ့ အထဲကုိေရာက္တဲ့အခါ ျမင္ရပုံ။
Labels:
Kali,
Wireless Hacking Tools
Fern wifi Cracker- A Wireless Penetration Testing Tool
MSF မွာ ကြ်န္ေတာ္ေရးထားတဲ့ Thread ေလးကုိျပန္ရွယ္လုိက္ပါတယ္။ Wifi ကုိကလိခ်င္တဲ့ သူေတြအတြက္ပါ။ Tutorial ပုံစံထက္ Tool ကုိ Install
လုပ္နည္းေလာက္ပဲျပပါမယ္။ Ubuntu-based အတြက္ဆုိေပမယ့္ Linux platform
ေတာ္ေတာ္မ်ားမ်ားမွာ Run ႏုိင္ပါတယ္။ တကယ္လုိ႔ Windows plaform မွာ Run
ခ်င္ရင္ေတာ့ ေအာက္ကဟာေတြလုိအပ္ပါတယ္။
Requirement for Windows Platform
-python
-python-qt4
-macchanger
-aircrack-ng
-xterm
-subversion
ကြ်န္ေတာ္ကေတာ့ Kali Linux မွာပဲစမ္းျပထားပါတယ္။ လုိအပ္တဲ့ဖုိင္ကုိ အရင္ေဒါင္းလုိက္ပါ။
Download: Fern wifi Cracker ေဒါင္းျပီးရင္ ဖုိင္ကုိ Desktop မွာထားျပီး Install လုပ္ဖုိ႔ ထုံးစံအတုိင္း ေအာက္ကလုိ ရုိက္ပါ။
cd Desktop
dpkg -i Fern-Wifi-Cracker_1.2_all.deb
Installation ျပီးတာနဲ႔ Kali ရဲ႕ Applications>Other>Fern wifi Cracker ဆုိတာကုိေတြ႕ရပါျပီ။
ကြ်န္ေတာ္အျပည့္အစုံေသခ်ာလုပ္ခ်င္ေပမယ့္ ကြ်န္ေတာ့္ Router က WPA နဲ႔ဆုိေတာ့ (ကုိယ့္တုိင္ဆင္ထားတာဆုိေတာ့ သိေနတယ္ေလ :D ) အခ်ိန္ေပးရမွာစုိးတာနဲ႔ ဆက္မလုပ္ေတာ့ပါဘူး။ Monitor Mode ကုိေျပာင္းဖုိ႔ airmon-ng start wlan0 ကုိ Terminal ကေနသြားေပးရပါတယ္။ က်န္တာကေတာ့ ကုိယ့္ဘာသာပဲ ဆက္ကလိၾကေပါ့ဗ်ာ။
Read my post at: http://www.4sectors.com/forum/showthread.php?tid=980
Read more »
Requirement for Windows Platform
-python
-python-qt4
-macchanger
-aircrack-ng
-xterm
-subversion
ကြ်န္ေတာ္ကေတာ့ Kali Linux မွာပဲစမ္းျပထားပါတယ္။ လုိအပ္တဲ့ဖုိင္ကုိ အရင္ေဒါင္းလုိက္ပါ။
Download: Fern wifi Cracker ေဒါင္းျပီးရင္ ဖုိင္ကုိ Desktop မွာထားျပီး Install လုပ္ဖုိ႔ ထုံးစံအတုိင္း ေအာက္ကလုိ ရုိက္ပါ။
cd Desktop
dpkg -i Fern-Wifi-Cracker_1.2_all.deb
Installation ျပီးတာနဲ႔ Kali ရဲ႕ Applications>Other>Fern wifi Cracker ဆုိတာကုိေတြ႕ရပါျပီ။
ကြ်န္ေတာ္အျပည့္အစုံေသခ်ာလုပ္ခ်င္ေပမယ့္ ကြ်န္ေတာ့္ Router က WPA နဲ႔ဆုိေတာ့ (ကုိယ့္တုိင္ဆင္ထားတာဆုိေတာ့ သိေနတယ္ေလ :D ) အခ်ိန္ေပးရမွာစုိးတာနဲ႔ ဆက္မလုပ္ေတာ့ပါဘူး။ Monitor Mode ကုိေျပာင္းဖုိ႔ airmon-ng start wlan0 ကုိ Terminal ကေနသြားေပးရပါတယ္။ က်န္တာကေတာ့ ကုိယ့္ဘာသာပဲ ဆက္ကလိၾကေပါ့ဗ်ာ။
Read my post at: http://www.4sectors.com/forum/showthread.php?tid=980
Labels:
Kali,
Linux,
Pen-Testing,
Wireless Hacking Tools
11/13/2013
All Linux Commands
alias Create an alias â¢
a
apropos Search Help manual pages (man -k)
apt-get Search for and install software packages (Debian/Ubuntu)
aptitude Search for and install software packages (Debian/Ubuntu)
aspell Spell Checker
awk Find and Replace text, database sort/validate/index
b
basename Strip directory and suffix from filenames
bash GNU Bourne-Again SHell
bc Arbitrary precision calculator language
bg Send to background
break Exit from a loop â¢
builtin Run a shell builtin
bzip2 Compress or decompress named file(s)
c
cal Display a calendar
case Conditionally perform a command
cat Concatenate and print (display) the content of files
cd Change Directory
cfdisk Partition table manipulator for Linux
chgrp Change group ownership
chmod Change access permissions
chown Change file owner and group
chroot Run a command with a different root directory
chkconfig System services (runlevel)
cksum Print CRC checksum and byte counts
clear Clear terminal screen
cmp Compare two files
comm Compare two sorted files line by line
command Run a command – ignoring shell functions â¢
continue Resume the next iteration of a loop â¢
cp Copy one or more files to another location
cron Daemon to execute scheduled commands
crontab Schedule a command to run at a later time
csplit Split a file into context-determined pieces
cut Divide a file into several parts
d
date Display or change the date & time
dc Desk Calculator
dd Convert and copy a file, write disk headers, boot records
ddrescue Data recovery tool
declare Declare variables and give them attributes â¢
df Display free disk space
diff Display the differences between two files
diff3 Show differences among three files
dig DNS lookup
dir Briefly list directory contents
dircolors Colour setup for `ls’
dirname Convert a full pathname to just a path
dirs Display list of remembered directories
dmesg Print kernel & driver messages
du Estimate file space usage
e
echo Display message on screen â¢
egrep Search file(s) for lines that match an extended expression
eject Eject removable media
enable Enable and disable builtin shell commands â¢
env Environment variables
ethtool Ethernet card settings
eval Evaluate several commands/arguments
exec Execute a command
exit Exit the shell
expect Automate arbitrary applications accessed over a terminal
expand Convert tabs to spaces
export Set an environment variable
expr Evaluate expressions
f
false Do nothing, unsuccessfully
fdformat Low-level format a floppy disk
fdisk Partition table manipulator for Linux
fg Send job to foreground
fgrep Search file(s) for lines that match a fixed string
file Determine file type
find Search for files that meet a desired criteria
fmt Reformat paragraph text
fold Wrap text to fit a specified width.
for Expand words, and execute commands
format Format disks or tapes
free Display memory usage
fsck File system consistency check and repair
ftp File Transfer Protocol
function Define Function Macros
fuser Identify/kill the process that is accessing a file
g
gawk Find and Replace text within file(s)
getopts Parse positional parameters
grep Search file(s) for lines that match a given pattern
groupadd Add a user security group
groupdel Delete a group
groupmod Modify a group
groups Print group names a user is in
gzip Compress or decompress named file(s)
h
hash Remember the full pathname of a name argument
head Output the first part of file(s)
help Display help for a built-in command â¢
history Command History
hostname Print or set system name
i
iconv Convert the character set of a file
id Print user and group id’s
if Conditionally perform a command
ifconfig Configure a network interface
ifdown Stop a network interface
ifup Start a network interface up
import Capture an X server screen and save the image to file
install Copy files and set attributes
j
jobs List active jobs â¢
join Join lines on a common field
k
kill Stop a process from running
killall Kill processes by name
l
less Display output one screen at a time
let Perform arithmetic on shell variables â¢
ln Create a symbolic link to a file
local Create variables â¢
locate Find files
logname Print current login name
logout Exit a login shell â¢
look Display lines beginning with a given string
lpc Line printer control program
lpr Off line print
lprint Print a file
lprintd Abort a print job
lprintq List the print queue
lprm Remove jobs from the print queue
ls List information about file(s)
lsof List open files
m
make Recompile a group of programs
man Help manual
mkdir Create new folder(s)
mkfifo Make FIFOs (named pipes)
mkisofs Create an hybrid ISO9660/JOLIET/HFS filesystem
mknod Make block or character special files
more Display output one screen at a time
mount Mount a file system
mtools Manipulate MS-DOS files
mtr Network diagnostics (traceroute/ping)
mv Move or rename files or directories
mmv Mass Move and rename (files)
n
netstat Networking information
nice Set the priority of a command or job
nl Number lines and write files
nohup Run a command immune to hangups
notify-send Send desktop notifications
nslookup Query Internet name servers interactively
o
open Open a file in its default application
op Operator access
p
passwd Modify a user password
paste Merge lines of files
pathchk Check file name portability
ping Test a network connection
pkill Stop processes from running
popd Restore the previous value of the current directory
pr Prepare files for printing
printcap Printer capability database
printenv Print environment variables
printf Format and print data â¢
ps Process status
pushd Save and then change the current directory
pwd Print Working Directory
q
quota Display disk usage and limits
quotacheck Scan a file system for disk usage
quotactl Set disk quotas
r
ram ram disk device
rcp Copy files between two machines
read Read a line from standard input â¢
readarray Read from stdin into an array variable â¢
readonly Mark variables/functions as readonly
reboot Reboot the system
rename Rename files
renice Alter priority of running processes
remsync Synchronize remote files via email
return Exit a shell function
rev Reverse lines of a file
rm Remove files
rmdir Remove folder(s)
rsync Remote file copy (Synchronize file trees)
s
screen Multiplex terminal, run remote shells via ssh
scp Secure copy (remote file copy)
sdiff Merge two files interactively
sed Stream Editor
select Accept keyboard input
seq Print numeric sequences
set Manipulate shell variables and functions
sftp Secure File Transfer Program
shift Shift positional parameters
shopt Shell Options
shutdown Shutdown or restart linux
sleep Delay for a specified time
slocate Find files
sort Sort text files
source Run commands from a file `.’
split Split a file into fixed-size pieces
ssh Secure Shell client (remote login program)
strace Trace system calls and signals
su Substitute user identity
sudo Execute a command as another user
sum Print a checksum for a file
suspend Suspend execution of this shell â¢
symlink Make a new name for a file
sync Synchronize data on disk with memory
t
tail Output the last part of file
tar Tape ARchiver
tee Redirect output to multiple files
test Evaluate a conditional expression
time Measure Program running time
times User and system times
touch Change file timestamps
top List processes running on the system
traceroute Trace Route to Host
trap Run a command when a signal is set(bourne)
tr Translate, squeeze, and/or delete characters
true Do nothing, successfully
tsort Topological sort
tty Print filename of terminal on stdin
type Describe a command â¢
u
ulimit Limit user resources â¢
umask Users file creation mask
umount Unmount a device
unalias Remove an alias â¢
uname Print system information
unexpand Convert spaces to tabs
uniq Uniquify files
units Convert units from one scale to another
unset Remove variable or function names
unshar Unpack shell archive scripts
until Execute commands (until error)
uptime Show uptime
useradd Create new user account
userdel Delete a user account
usermod Modify user account
users List users currently logged in
uuencode Encode a binary file
uudecode Decode a file created by uuencode
v
v Verbosely list directory contents (`ls -l -b’)
vdir Verbosely list directory contents (`ls -l -b’)
vi Text Editor
vmstat Report virtual memory statistics
w
wait Wait for a process to complete â¢
watch Execute/display a program periodically
wc Print byte, word, and line counts
whereis Search the user’s $path, man pages and source files for a program
which Search the user’s $path for a program file
while Execute commands
who Print all usernames currently logged in
whoami Print the current user id and name (`id -un’)
wget Retrieve web pages or files via HTTP, HTTPS or FTP
write Send a message to another user
x
xargs Execute utility, passing constructed argument list(s)
xdg-open Open a file or URL in the user’s preferred application.
yes Print a string until interrupted
. Run a command script in the current shell
!! Run the last command again
Linux User ေတြအတြက္ပါ တခ်ဳိ႕ဟာေတြက Window မွာလဲသုံးလို႔ရပါတယ္ း) ဘာပဲျဖစ္ျဖစ္ စမ္းျပီးလုပ္ၾကည့္ၾကပါ ဘာမွမျဖစ္ပါဘူး ျဖစ္လဲ အလြန္ဆုံး ကေတာ့ OS ျပန္တင္ရုံပါပဲ ဟီး
Read more »
11/11/2013
Secure Sockets Layer (SSL) Explaination
ကြ်န္ေတာ္တုိ႔ ဆုိဒ္ေတြကုိဝင္ၾကည့္တဲ့အခါ url မွာ http နဲ႔ https ဆုိျပီးေတြ႕ဖူးပါလိမ့္မယ္။ ဥပမာ Gmail, Facebook, Paypal တုိ႔ကုိဝင္ၾကည့္ရင္ https ဆုိျပီး ေသာခတ္ထားတဲ့ပုံကုိေတြ႕ရပါမယ္။ သေဘာကေတာ့ https protocol နဲ႔သြားေနတဲ့ဆုိတဲ့သေဘာပါပဲ။ http ဆုိတာက client နဲ႕ web server ကုိဆက္သြယ္ေပးတဲ့ standard protocol ျဖစ္ျပီး https ဆုိတာကေတာ့ "secure communication" ကုိ ကုိယ္စားျပဳပါတယ္။ ဒီပုိ႔စ္မွာ http နဲ႕ https အေၾကာင္းကုိ ရွင္းျပသြားပါမယ္။ ဘာသာျပန္လုိက္တာလုိ႔ေျပာရင္ ပုိမွန္မယ္ထင္တယ္။ ဟီး :D
ကြ်န္ေတာ္တုိ႔ https အေၾကာင္းမေျပာခင္ အေျခခံက်တဲ့ http အေၾကာင္းအရင္ သြားၾကည့္ရေအာင္။ Client ဘက္မွာ point A လုိ႔သတ္မွတ္ျပီး Server ဘက္ကုိေတာ့ point B လုိ႔ဆုိၾကပါစုိ႔။ ပုံမွာ point A ကေန message တစ္ခုပုိ႔လုိက္မယ္ေပါ့ဗ်ာ။ ဒီနည္းမွာ A ကေနတစ္ခုခုပုိ႔မယ္ဆုိရင္ plain text (mypass) အျဖစ္သာတုိက္ရုိက္ပုိ႔လုိက္တာျဖစ္ပါတယ္။ ရုိးရုိး message အတြက္ သိပ္ျပသနာမရွိေပမယ့္ ကြ်န္ေတာ္တုိ႔ password လုိမ်ဳိးအေရးၾကီးတဲ့ session ေတြသြားမယ္ဆုိရင္ ျပသနာစလာပါျပီ။ ပုံထဲကလုိ A နဲ႔ B ၾကားကေန မသာမာသူ Attacker က ၾကားဝင္ျပီးဒုကၡလွလွေပးသြားႏုိင္ပါတယ္။
ေအာက္မွာေတာ့ https အလုပ္လုပ္ပုံကုိ ေတြ႕ျမင္ႏုိင္ပါတယ္။ ဒီနည္းလမ္းမွာက်ေတာ့ Security ပုိေကာင္းသြားပါျပီ။ A ကေနတစ္ခုခုပုိ႔မယ္ဆုိ plain text (mypass) လုိ႔တုိက္ရုိက္မျပဘဲ decrypted လုပ္ထားတဲ့ (xz54p6kd) အျဖစ္သာ ပုိ႔မွာျဖစ္ပါတယ္။ ဒီေတာ့ ၾကားကမသာမာသူအေနနဲ႔ အမွန္အကန္ password ကုိမရႏုိင္ေတာ့ပါဘူး။
https ေတြကုိသက္ဆုိင္ရာ owner ေတြအေနနဲ႔ SSL certificate ဝယ္ယူျပီး အသုံးျပဳႏုိင္ပါတယ္။ SSL အသုံးျပဳတဲ့အတြက္ online မွာေငြေခ်တာမ်ဳိးလုိ အေရးၾကီးတဲ့ session ေတြအတြက္လုံျခဳံေစပါတယ္။ SSL မွာ အဲဒီဆုိဒ္ရဲ႕ owner နဲ႔ဆုိင္တဲ့ unique and authenticated information ေတြပါဝင္ပါတယ္။ ေသာ့ပုံကုိကလစ္ျပီး ၾကည့္လုိက္ပါ။ Verify By ဘာညာဆုိျပီးေတြ႕ရမွာျဖစ္ပါတယ္။ ဒါေၾကာင့္ Verify လုပ္တဲ့အဖြဲ႕ကုိၾကည့္ျပီး ကြ်န္ေတာ္တုိ႔အေနနဲ႔ အဲဒီဆုိဒ္ရဲ႕ Security ကုိယုံၾကည္မွဳ ရေစမွာျဖစ္ပါတယ္။
SSL မွာ encryption အေနနဲ႕ RSA algorithm ကုိအေျခခံျပီး အလုပ္လုပ္ပါတယ္။ ေျပာရရင္ SSL certificate မွာ public နဲ႔ private key ဆုိျပီးႏွစ္မ်ဳိးနဲ႔လုပ္သြားပါတယ္။ public ကေတာ့ encrypt လုပ္ဖုိ႔၊ private ကေတာ့ decrypt လုပ္ဖုိ႔ေပါ့။ ကြ်န္ေတာ္တုိ႔ Browser ကေန secure ျဖစ္တဲ့ site ကုိခ်ိတ္လုိက္တဲ့အခါ Server ဘက္ကေနျပီးေတာ့ ဘေရာက္ဆာဆီကုိ encrypt လုပ္ဖုိ႔ public key ကုိပုိ႔ေပးပါတယ္။ public key ကေတာ့ လူတုိင္းအတြက္ပါ။ ဘေရာက္ဆာကေနပုိ႔ေပးလုိက္တဲ့ဟာကုိမွ server ဘက္မွာျပန္ private key အျဖစ္ decrypt လုပ္ပစ္ပါတယ္။ ဒီေလာက္ဆုိရင္ SSL အလုပ္လုပ္ပုံကုိ အေတာ္အသင့္ သေဘာေပါက္သြားလိမ့္မယ္လုိ႔ ေမ်ာလင့္ပါတယ္။
SSL အလုပ္ လုပ္မလုပ္ဆုိတာ အဲဒီဆုိဒ္ရဲ႕ url မွာ ေသာ့ပုံေလးကုိၾကည့္ျပီးသိႏုိင္ပါတယ္။ ပုံက အစိမ္းေရာင္ေလးနဲ႔ျပရမွာပါ။ တကယ္လုိ႔ အနီေရာင္သမ္းေနရင္ေတာ့ certificate expire ျဖစ္ေနလုိ႔ျဖစ္ပါလိမ့္မယ္။ ေနာက္တခါ paypal လုိဆုိဒ္ေတြထဲသြားရင္ url မွာ https ရွိ/မရွိတစ္ခ်က္ၾကည့္လုိက္ပါ။ တကယ္လုိ႔ အဲဒါေတြမရွိဘူးဆုိရင္ Phishing attack နဲ႔ ခံရဖုိ႔ မ်ားမွာပါ။
Ref: gohacking
Read more »
ကြ်န္ေတာ္တုိ႔ https အေၾကာင္းမေျပာခင္ အေျခခံက်တဲ့ http အေၾကာင္းအရင္ သြားၾကည့္ရေအာင္။ Client ဘက္မွာ point A လုိ႔သတ္မွတ္ျပီး Server ဘက္ကုိေတာ့ point B လုိ႔ဆုိၾကပါစုိ႔။ ပုံမွာ point A ကေန message တစ္ခုပုိ႔လုိက္မယ္ေပါ့ဗ်ာ။ ဒီနည္းမွာ A ကေနတစ္ခုခုပုိ႔မယ္ဆုိရင္ plain text (mypass) အျဖစ္သာတုိက္ရုိက္ပုိ႔လုိက္တာျဖစ္ပါတယ္။ ရုိးရုိး message အတြက္ သိပ္ျပသနာမရွိေပမယ့္ ကြ်န္ေတာ္တုိ႔ password လုိမ်ဳိးအေရးၾကီးတဲ့ session ေတြသြားမယ္ဆုိရင္ ျပသနာစလာပါျပီ။ ပုံထဲကလုိ A နဲ႔ B ၾကားကေန မသာမာသူ Attacker က ၾကားဝင္ျပီးဒုကၡလွလွေပးသြားႏုိင္ပါတယ္။
ေအာက္မွာေတာ့ https အလုပ္လုပ္ပုံကုိ ေတြ႕ျမင္ႏုိင္ပါတယ္။ ဒီနည္းလမ္းမွာက်ေတာ့ Security ပုိေကာင္းသြားပါျပီ။ A ကေနတစ္ခုခုပုိ႔မယ္ဆုိ plain text (mypass) လုိ႔တုိက္ရုိက္မျပဘဲ decrypted လုပ္ထားတဲ့ (xz54p6kd) အျဖစ္သာ ပုိ႔မွာျဖစ္ပါတယ္။ ဒီေတာ့ ၾကားကမသာမာသူအေနနဲ႔ အမွန္အကန္ password ကုိမရႏုိင္ေတာ့ပါဘူး။
https ေတြကုိသက္ဆုိင္ရာ owner ေတြအေနနဲ႔ SSL certificate ဝယ္ယူျပီး အသုံးျပဳႏုိင္ပါတယ္။ SSL အသုံးျပဳတဲ့အတြက္ online မွာေငြေခ်တာမ်ဳိးလုိ အေရးၾကီးတဲ့ session ေတြအတြက္လုံျခဳံေစပါတယ္။ SSL မွာ အဲဒီဆုိဒ္ရဲ႕ owner နဲ႔ဆုိင္တဲ့ unique and authenticated information ေတြပါဝင္ပါတယ္။ ေသာ့ပုံကုိကလစ္ျပီး ၾကည့္လုိက္ပါ။ Verify By ဘာညာဆုိျပီးေတြ႕ရမွာျဖစ္ပါတယ္။ ဒါေၾကာင့္ Verify လုပ္တဲ့အဖြဲ႕ကုိၾကည့္ျပီး ကြ်န္ေတာ္တုိ႔အေနနဲ႔ အဲဒီဆုိဒ္ရဲ႕ Security ကုိယုံၾကည္မွဳ ရေစမွာျဖစ္ပါတယ္။
SSL မွာ encryption အေနနဲ႕ RSA algorithm ကုိအေျခခံျပီး အလုပ္လုပ္ပါတယ္။ ေျပာရရင္ SSL certificate မွာ public နဲ႔ private key ဆုိျပီးႏွစ္မ်ဳိးနဲ႔လုပ္သြားပါတယ္။ public ကေတာ့ encrypt လုပ္ဖုိ႔၊ private ကေတာ့ decrypt လုပ္ဖုိ႔ေပါ့။ ကြ်န္ေတာ္တုိ႔ Browser ကေန secure ျဖစ္တဲ့ site ကုိခ်ိတ္လုိက္တဲ့အခါ Server ဘက္ကေနျပီးေတာ့ ဘေရာက္ဆာဆီကုိ encrypt လုပ္ဖုိ႔ public key ကုိပုိ႔ေပးပါတယ္။ public key ကေတာ့ လူတုိင္းအတြက္ပါ။ ဘေရာက္ဆာကေနပုိ႔ေပးလုိက္တဲ့ဟာကုိမွ server ဘက္မွာျပန္ private key အျဖစ္ decrypt လုပ္ပစ္ပါတယ္။ ဒီေလာက္ဆုိရင္ SSL အလုပ္လုပ္ပုံကုိ အေတာ္အသင့္ သေဘာေပါက္သြားလိမ့္မယ္လုိ႔ ေမ်ာလင့္ပါတယ္။
SSL အလုပ္ လုပ္မလုပ္ဆုိတာ အဲဒီဆုိဒ္ရဲ႕ url မွာ ေသာ့ပုံေလးကုိၾကည့္ျပီးသိႏုိင္ပါတယ္။ ပုံက အစိမ္းေရာင္ေလးနဲ႔ျပရမွာပါ။ တကယ္လုိ႔ အနီေရာင္သမ္းေနရင္ေတာ့ certificate expire ျဖစ္ေနလုိ႔ျဖစ္ပါလိမ့္မယ္။ ေနာက္တခါ paypal လုိဆုိဒ္ေတြထဲသြားရင္ url မွာ https ရွိ/မရွိတစ္ခ်က္ၾကည့္လုိက္ပါ။ တကယ္လုိ႔ အဲဒါေတြမရွိဘူးဆုိရင္ Phishing attack နဲ႔ ခံရဖုိ႔ မ်ားမွာပါ။
Ref: gohacking
Labels:
Knowledges,
SSL
11/10/2013
Linux Command chmod Explaination
ကြ်န္ေတာ္တုိ႔ hacking ပုိင္းကုိေလ့လာတဲ့အခါ Linux Command
ေတြကုိေမ့ထားလုိ႔ရပါဘူး။ လူသုံးမ်ားတဲ့ BT/Kali ဆုိတာေတြက Linux-based
ျဖစ္ပါတယ္။ Linux ကုိတကယ့္ pro အဆင့္မဟုတ္ရင္ေတာင္ basic command
ေလာက္ေတာ့သိထားသင့္တာေပါ့ဗ်ာ။ ဟုတ္မလားမသိဘူး။
အုိခီ ကြ်န္ေတာ္ကေတာ့ chmod commad အေၾကာင္း
ေတြ႕မိသေလာက္ျပန္ရွယ္လုိက္ပါတယ္။ chmod ဆုိတာကေတာ့ linux မွာ
file/directory ေတြကုိ read/write/execue လုပ္ေပးႏုိင္တဲ့ command
တစ္ခုပါပဲ။ ဘရားသားတုိ႔ shell မွာ deface တင္ရင္ 755 လားမသိဘူး။ အရင္
command ေပးရတာ သိမွာပါ။ 
Why we need to change permissions of a file/directory?
ရွင္းပါတယ္။
-script ေတြကုိ execute လုပ္ႏုိင္ဖုိ႔၊
-program ေတြကုိမွန္မွန္ကန္ကန္ အလုပ္လုပ္ႏုိင္ဖုိ႔၊
-ဖုိင္ေတြကုိ လုိအပ္ခ်က္အရ edit ျပန္လုပ္ႏုိင္ဖုိ႔၊
How can we change permissions for a file/directory?
နည္းလမ္းႏွစ္ခုရွိပါတယ္။ Numerical method ရယ္ Alpha method ရယ္ဆုိျပီး။
Numerical method မွာ အေျခခံအားျဖင့္ 3 ခုရွိပါမယ္။
4 – read ( r)
2 – write (w)
1 – execute (x)
နည္းနည္း အက်ယ္ခဲ်လုိက္ရရင္
7 = 4+2+1 (read/write/execute)
6 = 4+2 (read/write)
5 = 4+1 (read/execute)
4 = 4 (read)
3 = 2+1 (write/execute)
2 = 2 (write)
1 = 1 (execute)
ဥပမာအေနနဲ႕ ဖုိင္တစ္ခုကုိ သက္ဆုိင္ရာ နံပါတ္အလုိက္ခုလုိ permission ေျပာင္းသြားပါမယ္။
chmod 400 mydoc.txt – read by owner
chmod 040 mydoc.txt – read by group
chmod 004 mydoc.txt – read by anybody (other)
chmod 200 mydoc.txt – write by owner
chmod 020 mydoc.txt – write by group
chmod 002 mydoc.txt – write by anybody
chmod 100 mydoc.txt – execute by owner
chmod 010 mydoc.txt – execute by group
chmod 001 mydoc.txt – execute by anybody
Alpha method ကေတာ့ Windows နဲ႔ဆင္ပါတယ္။ Windows မွာဆုိ cmd ကေန rw ဘာညာေပါ့။ Linux မွာဆုိရင္
w--Write
x--eXecute
r—Read
u -- User
g -- Group
o – Others
a- all
+ Add specified permissions to the mention user/group/others/all
- Remove specified permissions from the mention user/group/others/all
= replicate the permission to other class of the group/user/others.
ဒါဆုိ အေတာ္အသင့္ သေဘာေပါက္သြားမယ္ထင္ပါတယ္။ Alpha method နဲ႔ပတ္သက္ျပီး နည္းနည္းရွင္းျပအုံးအံ့။
Example: -rw-r–r–
ပုံထဲက File Type ကေတာ့အမ်ဳိးမ်ဳိးကြဲျပားႏုိင္ပါတယ္။ .deb, .rpm ဘာညာေပါ့။ ေနာက္က်န္တဲ့သုံးခုကေတာ့ permission ပုိင္းေတြပါ။ အုိေက ေခါင္းရွဳပ္သြားျပီလားမသိဘူး။ ကြ်န္ေတာ္ကေတာ့ ေရးေနရင္း လည္လာသလုိပဲ။ ဟီး။ ဟုတ္ကဲ့ User မွာ permission နဲ႔ပတ္သက္ျပီး ႏွစ္ခုကြဲသြားပါမယ္။ Group, Other (A, B ဆုိၾကပါစုိ႕) ဆုိပါေတာ့။
A=User ထဲကဖုိင္ေတြကုိ Group ေတြအလုိက္ permission ေပးႏုိင္ျခင္း။
B=User ထဲကဖုိင္ေတြကုိ အျခားေသာ user ေတြကုိ permission ေပးႏုိင္ျခင္း။
-rw-r–r– ရဲ႕ permission ေတြကေတာ့ ေအာက္လုိျဖစ္ပါတယ္။
-rw-r–r–
rw- For the owner
r– For the group where user belongs
r– For all other users
Numerical method ကုိျပန္သြားျပီး နိဂုံးခ်ဳပ္အေနနဲ႔ 755 chmod ကုိျပန္ၾကည့္လုိက္ရင္ ခုလုိျဖစ္မွာပါ။
read, write and execute permissions to user =7
read and execute permissions to group =5
read and execute permissions to others=5
ေပါင္းလုိက္ေတာ့ 755 ေပါ့။ ဒါဆုိရင္ ဘာျဖစ္လုိ႔ 755 command ေပးရသလဲဆုိတာ သိေလာက္ပါျပီ။
Ref: http://www.linuxnix.com/
ကြ်န္ေတာ္ Forum မွာတင္ထားတာေလးကုိ ျပန္ရွယ္ေပးလုိက္တာပါ။
Read more »
Why we need to change permissions of a file/directory?
ရွင္းပါတယ္။
-script ေတြကုိ execute လုပ္ႏုိင္ဖုိ႔၊
-program ေတြကုိမွန္မွန္ကန္ကန္ အလုပ္လုပ္ႏုိင္ဖုိ႔၊
-ဖုိင္ေတြကုိ လုိအပ္ခ်က္အရ edit ျပန္လုပ္ႏုိင္ဖုိ႔၊
How can we change permissions for a file/directory?
နည္းလမ္းႏွစ္ခုရွိပါတယ္။ Numerical method ရယ္ Alpha method ရယ္ဆုိျပီး။
Numerical method မွာ အေျခခံအားျဖင့္ 3 ခုရွိပါမယ္။
4 – read ( r)
2 – write (w)
1 – execute (x)
နည္းနည္း အက်ယ္ခဲ်လုိက္ရရင္
7 = 4+2+1 (read/write/execute)
6 = 4+2 (read/write)
5 = 4+1 (read/execute)
4 = 4 (read)
3 = 2+1 (write/execute)
2 = 2 (write)
1 = 1 (execute)
ဥပမာအေနနဲ႕ ဖုိင္တစ္ခုကုိ သက္ဆုိင္ရာ နံပါတ္အလုိက္ခုလုိ permission ေျပာင္းသြားပါမယ္။
chmod 400 mydoc.txt – read by owner
chmod 040 mydoc.txt – read by group
chmod 004 mydoc.txt – read by anybody (other)
chmod 200 mydoc.txt – write by owner
chmod 020 mydoc.txt – write by group
chmod 002 mydoc.txt – write by anybody
chmod 100 mydoc.txt – execute by owner
chmod 010 mydoc.txt – execute by group
chmod 001 mydoc.txt – execute by anybody
Alpha method ကေတာ့ Windows နဲ႔ဆင္ပါတယ္။ Windows မွာဆုိ cmd ကေန rw ဘာညာေပါ့။ Linux မွာဆုိရင္
w--Write
x--eXecute
r—Read
u -- User
g -- Group
o – Others
a- all
+ Add specified permissions to the mention user/group/others/all
- Remove specified permissions from the mention user/group/others/all
= replicate the permission to other class of the group/user/others.
ဒါဆုိ အေတာ္အသင့္ သေဘာေပါက္သြားမယ္ထင္ပါတယ္။ Alpha method နဲ႔ပတ္သက္ျပီး နည္းနည္းရွင္းျပအုံးအံ့။
Example: -rw-r–r–
ပုံထဲက File Type ကေတာ့အမ်ဳိးမ်ဳိးကြဲျပားႏုိင္ပါတယ္။ .deb, .rpm ဘာညာေပါ့။ ေနာက္က်န္တဲ့သုံးခုကေတာ့ permission ပုိင္းေတြပါ။ အုိေက ေခါင္းရွဳပ္သြားျပီလားမသိဘူး။ ကြ်န္ေတာ္ကေတာ့ ေရးေနရင္း လည္လာသလုိပဲ။ ဟီး။ ဟုတ္ကဲ့ User မွာ permission နဲ႔ပတ္သက္ျပီး ႏွစ္ခုကြဲသြားပါမယ္။ Group, Other (A, B ဆုိၾကပါစုိ႕) ဆုိပါေတာ့။
A=User ထဲကဖုိင္ေတြကုိ Group ေတြအလုိက္ permission ေပးႏုိင္ျခင္း။
B=User ထဲကဖုိင္ေတြကုိ အျခားေသာ user ေတြကုိ permission ေပးႏုိင္ျခင္း။
-rw-r–r– ရဲ႕ permission ေတြကေတာ့ ေအာက္လုိျဖစ္ပါတယ္။
-rw-r–r–
rw- For the owner
r– For the group where user belongs
r– For all other users
Numerical method ကုိျပန္သြားျပီး နိဂုံးခ်ဳပ္အေနနဲ႔ 755 chmod ကုိျပန္ၾကည့္လုိက္ရင္ ခုလုိျဖစ္မွာပါ။
read, write and execute permissions to user =7
read and execute permissions to group =5
read and execute permissions to others=5
ေပါင္းလုိက္ေတာ့ 755 ေပါ့။ ဒါဆုိရင္ ဘာျဖစ္လုိ႔ 755 command ေပးရသလဲဆုိတာ သိေလာက္ပါျပီ။
Ref: http://www.linuxnix.com/
ကြ်န္ေတာ္ Forum မွာတင္ထားတာေလးကုိ ျပန္ရွယ္ေပးလုိက္တာပါ။
Labels:
Knowledges,
Linux,
Tips and Tricks
Subscribe to:
Posts (Atom)











































