welcome

Have a new tricks fun of world!
Showing posts with label firewall hacking. Show all posts
Showing posts with label firewall hacking. Show all posts

Wednesday, 20 June 2012

How to Hack Firewall?


To hack any firewall we use allowed ports in Trojan, virus or exploit for communication.
(port 21,22,25,80,8080 etc.)
Bypassing Firewall or Proxy using SOCK Proxies*
Proxies
It is a program which stays in-between the user's system and internet. The request sends
by the user's system are processed by the proxy and then forward to the destination
server. Proxies are used to distribute the internet access among the nodes. Most of the
firewalls comes with inbuilt proxy feature. Firewall proxies increases security for the
organisation.
SOCKS
SOCKS stands for "SOCKetS", these are proxies used for tunneling the connection over
the internet for better security. Tunneling provides a protective shield for the data passing
over the internet. Since, the data is encrypted it is neither understood by the firewall or
the content filters.
Now I shall discuss how one can make use of SOCKS to bypass the firewall / proxies.
Let's assume you want to download music / video files using KaZaa Lite (File Sharing
Software) or chat using MSN or Yahoo without getting caught by the system
administrator.
136 Copyright ©2009 Leo Impact Security Services Pvt Ltd
Install a SOCKS client on your system
The list of SOCKS Client are as follows:
Http-Tunnel - Commercial - http://www.http-tunnel.com/html/
Hopster - Freeware - http://www.hopster.com/deutsch/
Use one among the free SOCKS proxy (FreeProxy or Hopster). our personal choice is
Hopster.
Configure SOCKS client to accept connections from the application (KaZaa or MSN
etc)
Configure Hopster to listen on port 1080/TCP (default port) on your local system. Set
your internet proxy address on the SOCK client so that it can connect to it. Click on the
link below to view the screenshot:
Screenshot1:
In Hopster you also have to set options to accept connection from application like
KaZaaLite. View screenshot for details.
Configure the application (KaZaa / MSN ) to connect to SOCKS proxy
The application must be configured to connect to the local loopback IP address
(127.0.0.1) on port 1080/TCP. View the screenshot of KaZaa being configured to connect
to the local SOCKS proxy.
137 Copyright ©2009 Leo Impact Security Services Pvt Ltd
Once KaZaa has the connection established with the SOCK proxy, you can see the data
transfer status both on KaZaa and as well as Hopster. View the screenshot for details.
How a SOCKS proxy work?
A SOCKS Client sitting on your system acts as a proxy server between your application
and your corporate firewall/proxy. This SOCKS client when receive a particular request
for the user system, it tunnel the request through http port to the main SOCK proxy
server. Since, http port is usually allowed through the firewall / proxy, the tunnel is not
detected by the security devices. The main SOCKS proxy then process the request and
sends back the data through the http port back to the client machine.
The whole sequence of data flow is given below:
Step1: Application/User Sends Request -------------- >> SOCKS Client
Step2: SOCKS Client Sends Request ---------------- >> Corporate Proxy / Firewall (as
HTTP request)
Step3: Corporate Proxy / Firewall Sends Request ---- >> SOCKS Proxy (Main SOCKS
Server)
Step4: SOCKS Server Processes the Request
Step5: SOCKS Server sends back data -------------- >> Corporate Proxy / Firewall
138 Copyright ©2009 Leo Impact Security Services Pvt Ltd
Step6: Corporate Proxy / Firewall sends back data --- >> SOCKS Client
Step7: SOCKS Client sends back data --------------- >> Application /User
Note: Similarly one can bypass the corporate firewall / proxy and run any application
(MSN/Yahoo/IRC) or visit any sites using this method.
Video URL: www.thesecretofhacking.com/vd/ch13/cs1

What is Firewall? Top 5 Firewall Applications:


A firewall is a part of a computer system or network that is designed to block
unauthorized access while permitting authorized communications. It is a device or set of
devices configured to permit, deny, encrypt, decrypt, or proxy all (in and out) computer
traffic between different security domains based upon a set of rules and other criteria.
Firewalls can be implemented in either hardware or software, or a combination of both.
Firewalls are frequently used to prevent unauthorized Internet users from accessing
private networks connected to the Internet, especially intranets. All messages entering or
leaving the intranet pass through the firewall, which examines each message and blocks
those that do not meet the specified security criteria.
There are several types of firewall techniques:
1. Packet filter: Looks at each packet entering or leaving the network and accepts or
rejects it based on user-defined rules. Packet filtering is fairly effective and
transparent to users, but it is difficult to configure. In addition, it is susceptible to
IP spoofing.
2. Application gateway: Applies security mechanisms to specific applications, such
as FTP and Telnet servers. This is very effective, but can impose a performance
degradation.
3. Circuit-level gateway: Applies security mechanisms when a TCP or UDP
connection is established. Once the connection has been made, packets can flow
between the hosts without further checking.
4. Proxy server: Intercepts all messages entering and leaving the network. The proxy
server effectively hides the true network addresses.

Top 5 Firewall Applications:
1. Tiny Personal Firewall
2. ZoneAlarm
3. NetWatcher 2000
4. ConSeal PC Firewall
5. Sygate Personal Firewall
How firewall works:
Every firewall have rules to allow/deny ports for incoming and outgoing communication.
Why Firewall Security?
There are many creative ways that unscrupulous people use to access or abuse
unprotected computers:
Remote login - When someone is able to connect to your computer and control it
in some form. This can range from being able to view or access your files to
actually running programs on your computer.
Application backdoors - Some programs have special features that allow for
remote access. Others contain bugs that provide a backdoor, or hidden access,
that provides some level of control of the program.
SMTP session hijacking - SMTP is the most common method of sending e-mail
over the Internet. By gaining access to a list of e-mail addresses, a person can
send unsolicited junk e-mail (spam) to thousands of users. This is done quite often
by redirecting the e-mail through the SMTP server of an unsuspecting host,
making the actual sender of the spam difficult to trace.
Operating system bugs - Like applications, some operating systems have
backdoors. Others provide remote access with insufficient security controls or
have bugs that an experienced hacker can take advantage of.
Denial of service - You have probably heard this phrase used in news reports on
the attacks on major Web sites. This type of attack is nearly impossible to counter.
What happens is that the hacker sends a request to the server to connect to it.
When the server responds with an acknowledgement and tries to establish a
session, it cannot find the system that made the request. By inundating a server
with these unanswerable session requests, a hacker causes the server to slow to a
crawl or eventually crash.
E-mail bombs - An e-mail bomb is usually a personal attack. Someone sends you
the same e-mail hundreds or thousands of times until your e-mail system cannot
accept any more messages.
Macros - To simplify complicated procedures, many applications allow you to
create a script of commands that the application can run. This script is known as a
macro. Hackers have taken advantage of this to create their own macros that,
depending on the application, can destroy your data or crash your computer.

Viruses - Probably the most well-known threat is computer viruses. A virus is a
small program that can copy itself to other computers. This way it can spread
quickly from one system to the next. Viruses range from harmless messages to
erasing all of your data.
Spam - Typically harmless but always annoying, spam is the electronic equivalent
of junk mail. Spam can be dangerous though. Quite often it contains links to Web
sites. Be careful of clicking on these because you may accidentally accept a
cookie that provides a backdoor to your computer.
Redirect bombs - Hackers can use ICMP to change (redirect) the path information
takes by sending it to a different router. This is one of the ways that a denial of
service attack is set up.
Source routing - In most cases, the path a packet travels over the Internet (or any
other network) is determined by the routers along that path. But the source
providing the packet can arbitrarily specify the route that the packet should travel.
Hackers sometimes take advantage of this to make information appear to come
from a trusted source or even from inside the network! Most firewall products