Las Vegas Strip and Downtown by Night

Posted by EM@KING.NET

From neon lights to outdoor shows, this nighttime walking/driving tour of Vegas dazzles. Experience the spectacular water fountains of the Bellagio, the pirate ships at Treasure Island, the majesty of Paris and Venice, and the erupting volcanoes at the Mirage. The itinerary adapts each evening to offer the best of Las Vegas, including: the Gamblers Museum, downtown's "Glitter Gulch," and the famous Fremont Street Experience light show. ...

Morning Whale Watch

Posted by EM@KING.NET

During this two-hour whale watch, the Teralani searches for the Pacific humpback whale. Each winter, the Pacific humpback whale migrates from Alaska to the waters off the coast of Maui. These "gentle giants" are one of Maui's most prized visitors with their spectacular breaching and tail slapping. Throughout whale season (December 15 - April 15), the Teralani departs each day from Kaanapali for a daily excursion. A marine naturalist is onboard to offer insights and education on the humpback whale. ...

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Firewall Configuration

Posted by Anonymous On 6/19/2009 12:14:00 AM 0 comments
It's been a while since I configure a firewall for a new office setup. So here's just a review for myself as well.

The setup of firewall is still the same process for last couple of years, maybe for the last 5-10 years. The only different in my humble opinion is they improve the GUI management interface instead of using the telnet program through the console. You configure the internal IP address e.g 192.168.1.1 255.255.255.0 for your firewall, external IP address for the external interface
and set the routing in the firewall. Where the route should point to your router IP address, not the external IP of the firewall. This is a common mistake when setting up a new firewall.

For route example: IP address 0.0.0.0 point to router IP 1.2.3.4 as your gateway.

Create a test policy:
Source: ANY
Destination: ANY
Service: ANY

Please Note: You should create a GROUP for your service to manage allowed ports to get out of your network. Same approach for incoming traffic, you create a GROUP and add the ports you allow to get in to your network.

You can also use your firewall as DHCP Server. I recommend this to entrepreneurs and small business for them to save money for the time being.


Our Security Tip of the Week is courtesy of the Department of Homeland Security.

"If you are ever trapped in a fire, be prepared to crawl. Smoke and heat rise. The air is clearer and cooler near the floor. Try to escape through a door. If it's not hot, open slowly and ensure fire and/or smoke is not blocking your escape route. If your escape route is blocked, shut the door immediately and use an alternate escape route, such as a window. If you cannot escape through a window, hang a white or light-colored sheet outside the window, alerting fire fighters of your presence."

Hackers launch phishing attack on Facebook users

Posted by Anonymous On 5/15/2009 12:01:00 AM 0 comments
If you have a Facebook account, you need to read this article. This is another phishing incident that was reported today courtesy by Reuters.com.

"Hackers launched an attack on Facebook's 200 million users on Thursday, successfully gathering passwords from some of them in the latest campaign to prey on members of the popular social networking site.

Facebook spokesman Barry Schnitt said on Thursday that the site was in the process of cleaning up damage from the attack.

He said that Facebook was blocking compromised accounts.

Schnitt declined to say how many accounts had been compromised.

The hackers got passwords through what is known as a phishing attack, breaking into accounts of some Facebook members, then sending e-mails to friends and urging them to click on links to fake websites.

Those sites were designed to look like the Facebook home page. The victims were directed to log back in to the site, but actually logged into the one controlled by the hackers, unwittingly giving away their passwords.

The purpose of such attacks is generally identify theft and to spread spam.

The fake domains include www.151.im, www.121.im and www.123.im. Facebook has deleted all references to those domains." (2009, Reuters.com)

Whaddya have IE issue after installing KB963027?

Posted by Anonymous On 5/13/2009 12:27:00 AM 0 comments
We do automatic update for Microsoft Security Updates on a weekly schedule. This is to minimize risk of exposure against known vulnerability, patching the hole (threat) as soon as possible. Though this is not the perfect approach, well there is no perfect approach to secure your environment anyway.

Again, minimizing risk according to your business acceptable loss. You need to do Risk Assessment first to determine the acceptable loss in ($) dollar value and ask your management "What Business are we in?" then you can create directives on how you can implement countermeasures. As always, countermeasures solution should be below the value of assets that you are trying to protect.

Going back to the subject. After installing KB963027 on April 15, 2009. My customers started complaining not able to connect to some websites they normally visit. A good example, a website that authenticate their credentials to do their daily tasks. Another user, not able to visit Adobe website. Another user, not able to visit Facebook website.

For the Facebook access. I suppose to not assist the user because this is not allowed in the business environment but I'm curious to fix it anyway. I was able to correct it by resetting the IE settings back to "Reset all Zones to default level". Click on Tools, Internet Options, click the Security tab to see the "Reset all Zones to default level" button.

For the first 2 websites problem, I need to remove the KB963027 patch to the workstation to fix the problem. Go to Control Panel, double click on "Add or Remove programs" icon, scroll down and look for the patch you would like to uninstall. After uninstalling the KB963027, they can access the website again.

Other alternative solutions:
- Install the IE 8.0 and trust the website, you should be able to access the website again.
- Using Google Chrome, I have no problem using Google Chrome going these websites.

Common Criteria of Information Technology Security Evaluation

Posted by Support @ Whaddya.com On 5/08/2009 01:06:00 AM 0 comments
If you are looking to address your business Risk Management Concept Flow, read the Common Criteria of Information Technology Security Evaluation published September 2006.

Here's the pdf link: 

Whaddya know how to remove Spyware Protect 2009 Alert?

Posted by Anonymous On 4/27/2009 08:37:00 PM 1 comments
Disclaimer: Please ask for assistance to your local computer technician if you're not technical to follow this article. I will try to make it as friendly as possible for you to follow.

I've got some questions from our visitors on how to remove the Spyware Protect 2009 Alert program in your workstation. I know it's annoying to see this pop-up, well you come to the right place to get additional information on how to get rid of this program on your workstation.

If you have an active Symantec Anti-Virus software installed to your workstation and still got this virus warning, you are most likely infected.


Then your computer start showing Spyware Protect 2009 alert (in red color) message, that your computer is being attaked 
by an Internet Virus. It could be a password-stealing attack, a trojan - dropper or similar. Do you want to block this attack? Yes or No. Don't bother to answer this quesion, this is malware program you probably get it from a malicious website for example freebie games download, musics sharing website, news portal website that shows random advertisement, etc.

and the malware will follow another Spyware alert! 
again in red annoying color. You have the option to "Activate Spyware Protect 2009" or "Stay unprotected". Don't select any of these options, just reset your workstation or hold-on power off button.

When I run a tool "hijackit" from TrendMicro. I was able to see 
this new entry from 01 - Hosts: 
91.212.65.122 browser-security.microsoft.com, antiwareprotect.com and 
www.antiwareprotect.com

For a quick check of WHOIS record: antiwareprotect.com is on privacy protect. We should all block this website from our network, or the ISP should be smart enough to block this website going out the Internet. That save us some trouble. Well, that's another article to write.

What to check in your windows registry to stop this annoying pop-up in your windows system? With the help of regedit tool, built-in with your windows operating system you might be able to correct this problem. The malware program normally use your Program Run at Windows Startup. 

How to remove a startup application? Most malware or spyware bot launching from the registry keys. To remove it, delete their value associated with the program you want to remove. In this case we want to remove the sysguard.exe file in your windows registry. Using regedit tool, you should be able to see the sysguard.exe to the following location.

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
or
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
or
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
or
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]

Example location:
Then open a DOS command prompt to delete the sysguard.exe file in your windows folder. Or search the entire drive C or D, for example "dir sysguard.exe /s". This command will search your entire drive including sub-folder for sysguard.exe file.
Restart your computer and check if you still see the Spyware AntiVirus 2009 Alert in your windows system.

References:
  • ThreatExpert's awareness of the file "sysguard.exe", read here.
  • Manage the Programs Run at Windows Startup, read here.
If you have additional information to share, please post it here. Thank you.
I was reading this article from eWeek this morning and I would like to share this to IT Consultants and other-related consulting business that the CyberSecurity Act 2009 will might change the way they do business. I hope for the better.

Text of S.773 as Introduced in Senate
Cybersecurity Act of 2009
"A bill to ensure the continued free flow of commerce within the United States and with its global trading partners through secure cyber communications, to provide for the continued development and exploitation of the Internet and intranet communications for such purposes, to provide for the development of a cadre of information technology specialists to improve and maintain effective cybersecurity defenses against disruption, and for other purposes." (2009, OpenCongress.org)

I like Section 7. Licensing and Certification of Cybersecurity Professional. This enforce the mandatory licensing as a provider of cybersecurity services. This will help us easily justify the continuing education for IT Consultants.

The Section 13. Cybersecurity competition and challenge. Their main objective is to attract, identity, evaluate, and recruit talented individuals for the Federal information technology workforce and stimulate innovation in vasic and applied cybersecurity research, technology development and prototype demostration that have the potential for application to the Federal information technology activities of the Federal Government. At this time, there is no check list of what types of competitions and challenges for the contest. The Director will establish different competition and targeting High school students, Undergraduate, Graduate, Academic and research institutions.

The Defcon (yearly black hat security conference) is providing a variety of contest in cybersecurity such as Capture the Flag, Defcon Bots, Defcon Shoot formerly known as Wardriving contest with my team won 1st place, read the article at Wardrive.com, and other technology-related contest.

You may also visit SANS.org for other security information, training and papers written by security minded professionals.

Whaddya know how to check the area code of your callers?

Posted by Anonymous On 4/09/2009 01:50:00 AM 0 comments
I'm wondering how to find out where my callers are coming from? I forget the website address that I used in the past to check my callers origin. So I searched the Internet for this specific service. Though I wasn't successful of getting the one I know, blessing in disguise I've found ReversePhoneDetective.com service.

According to the website:
"Discover who's calling! Whether you're researching a phone bill, tracing a unwanted caller, or verifying address, Reverse Phone Detective make it fast and easy to conduct a phone search." (2009, ReversePhoneDetective.com)

When I test their service, they can tell if the phone number is mobile or landlline and the location of the caller. Since I am only using the basic service, you can actually pay to receive a full report for only $14.95 or Premium Membership unlimited Reverse Phone lookups for 1 year.

Check it out yourself and post your feedback here.

Thank you,
KING.NET

Conficker April 1st - April Fools Virus

Posted by Anonymous On 3/30/2009 11:19:00 PM 3 comments
When you first bought your computer (workstation) or your laptop, did you set your Automatic Updates to install Microsoft Security Updates daily?

Did you install anti-virus software and download updates daily?

If you have not done it lately, it's highly recommended to download the latest Windows Security Updates and run anti-virus live update for your workstation. This is to minimize risk of exposure, patch vulnerabilty and close known exploit. This coming April 1st, April fools day a virus known as The Conficker Worm will start attacking computers connected to the network and Internet. I don't know the attack pattern, in the past the attacker created a botnet to disabled known website through Destributed Denial of Service (DDoS) Attack. The method of attack might be different as they know that most businesses added security measures against this type of attack.
This is the time to run Windows Update, update your antibot software, and update your anti-virus software.

Here's how to check you workstation via Microsoft OneCare online service.
For Windows XP, please use this link:
http://onecare.live.com/site/en-us/default.htm

For Windows Vista, please use this link:
http://onecare.live.com/site/en-us/center/whatsnew.htm

To run the online tool, you need to use Microsoft Internet Explorer 6.0+ browser. I'm not surprise that they don't support Google Chrome or Firefox to run this tool. Click on Full Scan, it will take a while to complete the scan depending on how many files you have in your workstation. Be patient.

After the scan, read the report.

Norton website provide detailed information about The Conficker Worm.

What to do if you are infected? Here's a three (A, B, C) different approach to correct this problem. Click the one appropriate for your workstation.

For more information, please visit the following website:

Post your comments and suggestions here. Thank you.

More Security Loopholes Found In Google Docs

Posted by Anonymous On 3/26/2009 01:11:00 AM 0 comments
If you're heavily using Google Docs (just like me) for sharing documents, you need to read this article from TechCrunch.com. The current issue is related to sharing documents, embedded pictures and archiving your documents. For details, continue reading the article.

"Security consultant Ade Barkah checked in with us to alert us to a couple of serious security issues associated to Google Docs, the web-based office software from the world’s most famous search engine company, giving a whole new meaning to its mission to make the world’s information universally accessible. On his blog on software, infrastructure and security, Barkah outlines no less than three issues that he discovered while investigating some potential security lapses." (2009, TechCrunch.com)
I received this unsolicited email from Domain Notice asking me to complete and return by fax a form regarding notification for my business address (MyBusinessAddress.com) search engine subscriptions. Click the image on your left side to see the actual message. According to the email, this is a courtesy reminder to register my domain name search engine listing so my customers can locate me on the web. I guess I have to send them a post card.

This is why I have my domain name, I am using my email address @KING.NET to let them know how to get in touch with me.

And the email has this notice, it will expire on this date (today)! Laugh out load.

Google, Yahoo, MSN and other related search engine add your website for free. Why bother spending $75 for 1 year, $119 for 2 years, $199 for 5 years and $295 for 10 years.


Here's the link:

I always recommend the top 3 search engines for adding your website. Again, this is free and no need to spend your hard earned dollar for search engine. Go out and buy yourself a strawberry ice-cream for reading this blog.
This is a definition of Phishing I've got from wikipedia.org.

"In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. Communications purporting to be from popular sexual web sites (YouTube, Facebook, MySpace, Windows Live Messenger), auction sites (eBay), online banks (Wells Fargo, Bank of America, Chase), online payment processors (PayPal), or IT Administrators (Yahoo, ISPs, corporate) are commonly used to lure the unsuspecting. Phishing is typically carried out by e-mail or instant messaging, and it often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. Even when using server authentication, it may require skill to detect that the website is fake. Phishing is an example of social engineering techniques used to fool users, and exploits the poor usability of current web security technologies. Attempts to deal with the growing number of reported phishing incidents include legislation, user training, public awareness, and technical security measures. A phishing technique was described in detail in 1987, and the first recorded use of the term "phishing" was made in 1996. The term is a variant of fishing, probably influenced byphreaking, and alludes to baits used to "catch" financial information and passwords." (2009, Wikipedia.org)

How to do you minimize exposure to Phishing?
In my humble opinion, you don't actually expose yourself they will find you through public forums, email, newsletters, social networking sites, and other open access websites.

Here's a few tips for you, a practical way (common sense):
  1. Don't post your email to the public forums, community and other related message boards.
  2. When you receive a "phishing" emails, don't click on the link attached to the email. Open a new Internet browser and type the official web address of your bank. For example, if an email is asking you to update your bank profile (account information). Visit your bank official website e.g. http://www.bankofamerica.com/ for BOA, http://www.citicards.com/ for CitiBank, etc.
  3. Similar to no.1, don't post other sensitive information to the public forums e.g. Your phone number, mobile number, home address, etc.

That's what I have right now. Please post your comments for additional information that you would like to share to our readers.

Thank you,
KING.NET
Name.com offers another layer of security to protect their customer using Verisign Identity Protection (VIP) Services. The two-factor authentication is something you know (username and password) and something you have (device) to access your information. This is an excellent move by Name.com management to help protect their customers domain portfolio.

The service is called NameSafe. Yes, it is a service that you need to pay Name.com for $19.95 per year. The security device will cost you $5 one time fee. Once you receive your security device (or credential as they call it), you need to register your device Serial ID and follow the instruction. You will be done in under 10 minutes.

What do you expect with this NameSafe service?
  • Better security protecting your domain names.
  • Self-learning fraud detection.
  • You can use this device (credential) to any VIP Network members. Though you have to check the cost to use this service with other VIP Network. See here who's in VIP Network Members.
  • And Security Security Security!

I think Name.com is pioneer in domain name industry to provide a two-factor authentication. I know some registrars that provides additional service where you need to call their support hotline for you to make changes of DNS, Contact Information or other domain-related changes you need. This will take some time to complete, depending on how quickly the customer service response to your call. What if you leave outside USA? Then you have to pay internaltional phone bills unless you have VOIP service in place. Definitely Namesafe service is your alternative ways to protect your domain name porfolio.

I used the same technology (two-factor authentication) managing my Paypal account but I don't have to spend $19.95 per year for using this service. I only pay for the device $5 one time fee.

I use NeedName.com Enom Technology Partner (ETP) and Moscom.com (GoDaddy) for my domains. I need to call them and find out if I can get additional layer of security for my domain portfolio. Wish me luck.

How to ignore a Security Warning - Unknown Publisher

Posted by Anonymous On 12/25/2008 01:06:00 AM 0 comments
I don't recommend ignoring a Security Warning - Unknown Publisher when you visit a website. Perform this task if you only knew the website, a good example is the administrator or webmaster forgot to update the digital certificate of their website. Now you are getting the unknown publisher error when you visit the website.

Here's how to fix this issue :
  • Visit the website again, ignore the existing error.
  • In IE 7.0 or later, click on Tools, Internet Options.
  • In Internet Options, click on Security tab.
  • In Security, click on Local Intranet, then Sites
  • In Local Intranet, the "Automatically detect intranet network" is checked.
  • Uncheck it, click OK
  • In Internet Options, click OK
  • Now try the website again, it should work for you.

Share your thought, join our group here: http://www.RandomPage.com/Group/Help and http://www.RandomPage.com/Group/Technology

Whaddya know how to hide shared folders in Windows 2003 Server?

Posted by Anonymous On 12/09/2008 01:00:00 AM 0 comments

Overview from Microsoft:

Windows 2003 Access-based Enumeration makes visible only those files or folders that the user has the rights to access. When Access-based Enumeration is enabled, Windows will not display files or folders that the user does not have the rights to access.

Where to download Access-based Enumeration?

http://www.microsoft.com/downloads/details.aspx?FamilyId=04A563D9-78D9-4342-A485-B030AC442084&displaylang=en#filelist

Or search Access-based Enumeration from Microsoft website.

Installing Windows 2003 Access-based Enumeration Setup Wizard:

  • Double click on ABEUI.msi file.  Click Next to continue.
  • In License Agreement, you normally select “I Agree” to proceed the install.
  • Select the Installation Folder and choose Everyone, click Next to continue.
  • Select “I will enable Access-based Enumeration on individual shared folders.” Click Next
  • The installer is ready to install, click Next.
  • Click on Close to finish.

Then what? Follow this procedure to complete.

  • Create a new group or use existing group to manage folder shared security access. Add member to this group.
  • Share a folder
  • Right click on shared folder, properties. Here you will see a new tab named “Access-based Enumeration”. If you don’t see it, you need to install the program.
  • Put check on “Enable access-based enumeration on this shared folder”. Click OK
  • And test it.

That’s all, easy huh! If you still need assistance, visit http://www.RandomPage.com/group/Help post questions and someone will assist you.


Whaddya Know How to remove Browser Hijacker?

Posted by Anonymous On 9/29/2008 01:53:00 AM 0 comments
Do you have one of this issue when you browse the Internet using your default MS Internet Explorer?
  • When you open your Internet Browser, you receive persistent website asking you to install an Anti-Virus program from unknown antivirus company.

  • When you open your Internet Browser, website's start popping up.

  • When you surf the Internet, your workstation start showing relevant ads.

  • You can't change your default home page.

If yes, you're Internet access was hijacked. So how do you fix it, that's your next question?

If you are not familiar on how to fix this issue, it is highly recommended to seek professional IT help. You can check with your local Best Buy or Circuit City for technical support, even better check with your local community.

Here's my personal solution to fix "hijacked browser". I will try to make it easy for you to follow.

  1. First download "Hijack This" tool courtesy by Trend Micro. You can download this from CNet Download (http://www.download.com/) website.
  2. When you're in download website, in search form type "hijack this" (without quote) and hit [Enter] key or the magnifying glass to begin the search. It will shows other program related to Micro Trend "hijack this" tool. As of this date, the latest version is Trend Micro Hijack This 2.0.0 for Windows. Click on download now.
  3. Save this program to your temp folder e.g. c:\temp\
  4. Open your Windows Explorer, go to c:\temp\ and double click on HJTInstall program.
  5. Click on Run to start the installation.
  6. It will ask you for the installation path, just accept the default c:\Program Files\Trend Micro\HijackThis and click on Install to continue.
  7. Accept the User License Agreement, click on I Accept.
  8. After the installation, the system will display Welcome to HijackThis program.

You're ready to begin removing spyware to your workstation. WARNING: Sorry, I have to warn you. This tool directly can delete files to your registry and might damage your workstation, be careful.

Click the Do a system scan and save a logfile, it will show you bunch of programs running on your workstation. Before you do anything here, check the latest installation of programs in your c:\program files\ directory. Sort them by install date, you will see the latest programs added to your computer. Go to the subdirectory and see what .exe file available and compare this to the logfile you have from running the Hijack This tool.

I'm using an example of malicious (spyware) program listed below:

  • C:\Program Files\MSX ; which has msx.exe file
  • C:\Program Files\Applications ; found wcs.exe, wcm.exe, iebtm.exe and iebtmm.exe files.

In Hijack This tool, I found them listed as one of the 04 - HKLM\..., I put check on them and click on "Fix checked". The tool will remove this to your computer.

Completely the program in folder. Open your Windows Explorer, go to C:\Program Files\ folder and delete the offending subfolders.

Restart your computer, and check your Internet Explorer to see if your surfing experience is back to normal. Good luck to you and don't forget to us know (Email EM @KING.NET) if this procedure help out.

Solution:
To resolve the problem, perform the following tasks in this order:
  1. Enable Premium AntiSpam
  2. Confirm that Premium AntiSpam is set to reject spam messages
  3. Stop Symantec Mail Security services.
  4. Fix possible license problems.
  5. Fix possible ruleset corruption problems.
  6. Restart Symantec Mail Security services.
  7. Reinstall your licenses.
  8. Reset IIS to remove any cached values.
To enable Premium AntiSpam
  1. In the Symantec Mail Security for Microsoft Exchange interface, in the left pane, click Policies.
  2. In the middle pane, click Premium AntiSpam Settings.
  3. Check Enable Premium AntiSpam.

To confirm that Premium AntiSpam is set to reject spam messages

  1. In the Symantec Mail Security for Microsoft Exchange interface, in the left pane, click Policies.
  2. In the middle pane, click Premium AntiSpam Settings.
  3. Under If message is Spam, check Reject the message.

The document, Overview of Premium AntiSpam in Symantec Mail Security for Microsoft Exchange includes information about the Premium AntiSpam actions.

Source: Symantec.com

Google Chrome vulnerable to carpet-bombing flaw

Posted by Anonymous On 9/04/2008 01:47:00 AM 0 comments
After just a few hours of launching Google Chrome beta internet browser, here's a quick discovery of it's vulnerability through webkit and java bug.

---
Google’s shiny new Web browser is vulnerable to a carpet-bombing vulnerability that could expose Windows users to malicious hacker attacks.

Just hours after the release of Google Chrome, researcher Aviv Raff discovered that he could combine two vulnerabilities — a flaw in Apple Safari (WebKit) and a Java bug discussed at this year’s Black Hat conference — to trick users into launching executables direct from the new browser.

Whaddya know? Wardrive.com Wardriving after six years.

Posted by Anonymous On 8/25/2008 08:07:00 PM 4 comments
It's been six years after learning wireless security and it's vulnerabilities. My team (WirelessCon members TheWatcher, Chris, wetw3rx and dataworm) won the first wardriving contest in Defcon Las Vegas Year 2002 and 2nd Runner-up for Year 2003. I have no contact with the rest of WirelessCon team since 2003. I hope they are doing good.

Some of the tools for Wireless Security:
Freeware for Windows:
  • Aerosol has been tested to work on D-Link, LinkSys, Belkin, US Robotics, SMC, Netgear, HP HN210W USB and Intel Anypoint Wireless
  • ApSniff has been tested to work on DWL-650 and LinkSys, it requires you to manually change the SSID to blank.
  • Network Stumbler works on the following cards using the Hermes chipstes such as Lucent Technologies WaveLAN/IEEE(Agere ORiNOCO), Dell TrueMobile 1150 Series (PCMCIA and mini-PCI), Avaya Wireless PC Card, Toshiba Wireless LAN Card (PCMCIA and built-in), Compaq WL110, Cabletron/Enterasys Roamabout, Elsa Airlancer MC-11, ARtem ComCard 11Mbps , IBM High Rate Wireless LAN PC Card, and 1stWave 1ST-PC-DSS11IS, DSS11IG, DSS11ES, DSS11EG
  • WLAN Expert is a wireless client utility designed to work with the PRISM chipset by Intersil. The Linksys WPC11 is the only client card I've tested, although many manufacturers use this silicon. Intersil counts Alcatel, Cisco, Compaq, Nokia, Nortel, Samsung and Siemens among its OEMs.
  • AirSnare is an intrusion detection program to help you monitor your wireless network. AirSnare is another tool to add to your Wireless Intrusion Detection Toolbox. AirSnare will alert you to unfriendly MAC addresses on your network and will also alert you to DHCP requests taking place. If AirSnare detects an unfriendly MAC address you have the option of tracking the MAC address's access to IP addresses and ports or by launching Ethereal upon a detection.
  • Packetyzer or Packet Analyzer for windows user interface for the Ethereal packet capture and dissection library. Packetyzer is distributed together with winpcap and Ethereal. Packetyzer includes special support for analyzing 802.11 networks including signal strength displays and SSID discovery and logging. Packetyzer is open source software and is distributed under the GNU General Public License.
  • PocketWarrior This is wardriving software for PRISM that run on PocketPC 2002. Pocketwarrior is now released under GPL.
  • AirScannerSniff passwords from your Pocket PC As a network administrator, you want to protect your users' confidential data. What better way to do this than to stroll down the hall with Airscanner(TM) Mobile Sniffer hidden in your pocket? Thanks to our support for Ethereal packet capture format, grabbing your user's passwords out of the airwaves is as easy as watching a movie! Your users unintentionally send their passwords through the air in clear text, so it is better that you discover this first before a malicious drive-by hacker does it for you. Airscanner(TM) Mobile Sniffer also works in promiscuous mode, so you can also discover unauthorized users who may be associating with one of your access points. Audit WLANs from your PDA Are you tired of dragging your laptop all over campus to audit your WLAN? Simply slip Airscanner(TM) Mobile Sniffer into your pocket, and you are ready to go. Airscanner(TM) Mobile Sniffer packs the power of a full-scale sniffer into an application for portable devices. Once your Windows CE device is linked to the network, Airscanner(TM) Mobile Sniffer monitors all activity within a given segment. In addition, Airscanner(TM) Mobile Sniffer allows you to set your own filters, allowing you to monitor only the information you need.

NOTE: Airscanner software is free for personal, non-commercial use. Business, government or educational use requires a purchased license. Multiple U.S. patents pending.

Freeware for UNIX/Linux:

  • Airsnort is one of the first tool to came out discovering insecurity of wireless network. AirSnort is a wireless LAN (WLAN) tool which cracks encryption keys on 802.11b WEP networks. AirSnort operates by passively monitoring transmissions, computing the encryption key when enough packets have been gathered.
  • WEPCrack is Perl based tool. WEPCrack is a tool that cracks 802.11 WEP encryption keys using the latest discovered weakness of RC4 key scheduling.
    bsd-airtools is a package that provides a complete toolset for wireless 802.11b auditing. Namely, it currently contains a bsd-based wep cracking application, called dweputils (as well as kernel patches for NetBSD, OpenBSD, and FreeBSD). It also contains a curses based ap detection application similar to netstumbler (dstumbler) that can be used to detect wireless access points and connected nodes, view signal to noise graphs, and interactively scroll through scanned ap's and view statistics for each. It also includes a couple other tools to provide a complete toolset for making use of all 14 of the prism2 debug modes as well as do basic analysis of the hardware-based link-layer protocols provided by prism2's monitor debug mode.
  • Wellenreiter is a GTK/Perl program for discovering and auditing 802.11b wireless networks. It has an embedded statistics engine for the common parameters provided by wireless drivers, enabling you to view details about the consistency and signal strength of the network. It can be used to discover access-points, networks, and ad-hoc cards. It will detect essid broadcasting or non-broadcasting networks in every channel, the manufacturer, WEP, and automatically-switching frequencies.
  • Kismet Kismet is a 802.11b wireless network sniffer. It is capable of sniffing using almost any wireless card supported in Linux, including Prism2 based cards supported by the Wlan-NG project (Linksys, Dlink, Rangelan, etc), cards which support standard packet capture via libpcap (Cisco), and limited support for cards without RF Monitor support. NOTE: This scanner has the capability to scan non-broadcast access point (AP).
  • AirTraf is a package with many features. It is enabled to operate as a standard real-time data gathering tool for solving location specific problems, as well as operating as a long-term data gathering tool for your wireless networked organization.
  • WaveStumbler is console based 802.11 network mapper for Linux. It reports the basic AP stuff like channel, WEP, ESSID, MAC etc. It has support for Hermes based cards(Compaq, Lucent/Agere, ... ). It still in development but tends to be stable.
  • Prismstumbler is a wireless LAN (WLAN) which scans for beaconframes from accesspoints. Prismstumbler operates by constantly switching channels an monitors any frames recived on the currently selected channel. There are several other applications that does this already. Most of them requires a Lucent/Orinco card and uses the autohoming mode in those card. Autohoming requires that the SSID on the AP is set, there is however AP that are setup so that SSID is have to be known by the client hence they cant be seen with that method.
  • WepLab is a tool to review the security of WEP encryption in wireless networks from an educational point of view. Several attacks are available so it can be measured the efectiveness and minimun requirements of each one. Currently in Linux operating environment only and under GNU General Public Licensing (GPL).
  • Aircrack yet another WEP cracking tool for Linux courtesy by divine
    Chopchop First release of chopchop. WEP cracker which uses the AP to decipher packets. Easiest one are ARP's. Takes 10-20s. Included within patches for wlan-ng to inject packets in monitor mode. Tool courtesy by Korek
  • AiroPeek. The industry's first and only Real-Time Expert Wireless LAN Analyzer.
  • Sniffer Wireless Description: Wireless LAN applications provides a flexible and productive work environment for mobile employees as well as effective public access such as airports and hotels. Whether your are deploying wireless LAN for your employees or as a service, you need a management and deployment solution starting with the site survey to the overall management. Sniffer Wireless is a comprehensive solution for IEEE 802.11b wireless LAN applications and deployments. Sniffer Wireless provides the same powerful network monitoring, capturing, decoding, and filtering capabilities you have experienced on other networking topologies.
  • Wireless Security Advisor (WSA) WSA is an IBM research prototype of an 802.11 wireless LAN security auditor, running on Linux on an iPAQ PDA. WSA automatically audits a wireless network for proper security configuration, to help network administrators close any vulnerabilities before the hackers try to break in. While there are other 802.11 network analyzers out there (wlandump, ethereal, Sniffer), these tools are aimed at protocol experts who want to capture wireless packets for detailed analysis. WSA is intended for the more general audience of network installers and administrators, who want a way to easily and quickly verify the security configuration of their networks, without having to understand any of the details of the 802.11 protocols.
  • Wireless Scanner Wireless Scanner provides automated detection and security analyses of wireless networks that use 802.11b WLAN (Wi-Fi) access points and clients. Wireless Scanner performs a number of tests on wireless networks and connected infrastructure to determine if security vulnerabilities are present
  • AirMagnet - The AirMagnet Handheld represents a new generation of wireless network administration and diagnostic tools. Built from the ground up to help network professionals administer and troubleshoot WLANs, it provides a robust set of tools in a single, highly usable application that operates on a Pocket PC.
  • WaveRunner is a Linux™-powered HP iPAQ™ Pocket PC that verifies 802.11b deployments while detecting the rogue access points and clients that compromise the performance and security of enterprise networks. The Fluke Networks WaveRunner gives you the visibility for managing your wireless networks. This palm-sized device lets you see what's happening in every corner of your business. As you detect, deploy and support wireless, you need a tool as mobile as you are.
  • vxSniffer is a complete network monitoring tool for Windows CE-based devices.

Features include:

  1. User defined filtering capability.
  2. View summary and detail packet data.
  3. Save trace packets for later analysis.
  4. Operates on all Handheld 2000 HPCs and Pocket PCs.
  5. Windows CE 3.0 or later required.
  6. Requires an ethernet adapter with a NDIS compatible driver.

How much is vxSniffer? vxSniffer is licensed software and is available for a 30 day FREE evaluation period.

  • WSP100 Remote 802.11b Sniffer is an Ethernet connected 802.11b packet sniffer. Because it connects with Ethernet, the WSP100 can be used with any type of computer, not just laptops, and avoids the driver compatibility issues most wireless packet sniffers suffer from.
  • The LinkFerret monitoring tools provide all of the essential wireless monitoring functionality, including signal monitoring, channel scannning, and WEP decryption. It has the frame capture functionality that is typically found only in monitoring products many times its cost.
  • AirDefense is a thought leader and innovator of wireless LAN security and operational support solutions. Founded in 2001, AirDefense has pioneered the concept of 24x7 monitoring of the airwaves and now provides the most advanced solutions for rogue WLAN detection, policy enforcement, intrusion protection and WLAN health monitoring. As a key element of wireless LAN security, AirDefense complements wireless VPNs, encryption and authentication.
  • CommView for WiFi is a special edition of CommView designed for capturing and analyzing network packets on wireless 802.11a/b/g networks. It gathers information from the wireless adapter and decodes the analyzed data.CommView for WiFi is a comprehensive and affordable tool for WLAN administrators, security professionals, network programmers, or anyone who wants to have a full picture of the WLAN traffic. This application runs under Windows 2000/XP and requires a compatible wireless network adapter. To view the list of the adapters that have been tested and are compatible with CommView for WiFi

    WinAirsnort 2.0 includes now many new features and enhancements for the 802.11g WiFi network.

Java Wireless Sniffer

  • Mobnet is a free, open source wireless ethernet sniffer/analyzer written in Java. It is licensed under the GNU General Public License. It was designed with handheld devices like the iPaq in mind, but will run just as well on a desktop or laptop.

Mac wireless Sniffer

  • MacStumbler - Wireless scanning tool for the Apple Airport. MacStumbler is a small utility I wrote to emulate the functionality of projects like netstumbler, bsd-airtools, and kismet. It's meant purely for educational or auditing purposes, although many people enjoy using these types of programs to check out how many networks are in their area, usually known as war driving.
  • KisMAC is a stumbler application for MacOS X, that puts your card into the monitor mode. Unlike most other applications for OS X we are completely invisible and send no probe requests.
  • iStumbler is a free, open source tool for finding 802.11b & 802.11g wireless networks. iStumbler combines a compact Aqua user interface with visual feedback of signal strength and encryption.iStumbler scans by sending out probe packets via an Apple interface Access Points MAY respond to these probes but they might also be configured as private networks.

PALM Sniffer
NetChaser v1.0 - Wireless sniffer for Palm Tungsten C Handheld courtesy by Bits n Bolts.

iPAQ Sniffer
pocketWiNc™ - is a revolutionary WiFi™ connectivity tool that makes it easier for users to find and connect to WiFi networks, access the internet, and send and receive e-mail.

Note: Updated.

  • 20020624 update.
  • 20020719 added mognet java wireless sniffer.
  • 20020810 added MacStumbler and AirMagnet.
  • 20020901 added WaveRunner, AirTraf, vxSniffer
  • 20021027 added AirSnare and WaveStumbler.
  • 20021110 added Packetyzer and WSP100 Remote 802.11b Sniffer. Submitted by watersco.
  • 20021217 added PocketWarrior by dataworm.
  • 20030301 added LinkFerret by dpebert
  • 20030427 added AirScanner by fogez
  • 20030531 added KisMac by waldo1979
  • 20030724 added Airdefense by TheWatcher
  • 20030820 added NetChaser for Palm Tungsten C by TheWatcher
  • 20031017 added pocketWiNc™ for iPAQ by azri
  • 20031204 updated link for MacStumbler noted by Jim Lewinson
  • 20040209 updated link for Prismstumbler submitted by TheWatcher
  • 20040415 updated link for iStumbler submitted by TheWatcher
  • 20040511 updated link for CommView for WiFi by Globus
  • 20040710 updated link for Weplab by TheWatcher
  • 20040913 updated link for Aircrack by TheWatcher
  • 20041007 updated link for chopchop by TheWatcher
  • 20051213 updated link for WinAirsnort 2.0 by TheWatcher

Ok I've changed my phone service from Verizon to Vonage to save some $ to my pocket. The setup takes a while due to my firewall configuration preventing Vonage to establish connection.

If you're geek enough to configure your cable modem, then here's a simple guide to customize your Firewall policy to allow Vonage service or VOIP service to go out. And if you can't configure your Firewall, I suggest that you get in touch with your local computer tech guys for assistance.

I have a cable modem SBG900 Surfboard Gateway configuring the firewall using the following policies:

Outgoing Policies
VONAGE_dns Port 53 UDP
VONAGE_tftp Port 21, 69, 2400 UDP
VONAGE_http Port 80 UDP
VONAGE_ntp Port 123 UDP
VONAGE_sip Port 5061 UDP

Incoming and Outgoing Policies
VONAGE_rtp (voice) traffic Port 10000-20000 UDP. When a call is made, a random port between 10000 and 20000 is used for RTP (Voice) traffic.
Post your comments.
Thank you.
First things first: Connect through one of the following social gadget tools below:

Visit RandomPage.com

http://www.twitter.com/kingnet
http://www.randompage.com/profile/king

Pastor.TV

FairfaxCity.com

Michigan.TV


For Advertising Inquiry, please send email to EM [@] KING.NET. Thank you.

Link to KING.NET
(Cut and Paste html code)


KING.NET Web Buzz - Information Network