C - Basic Introduction

C is a general-purpose high level language that was originally developed by Dennis Ritchie for the Unix operating system. It was first implemented on the Digital Equipment Corporation PDP-11 computer in 1972.

The Unix operating system and virtually all Unix applications are written in the C language. C has now become a widely used professional language for various reasons.
  • Easy to learn
  • Structured language
  • It produces efficient programs.
  • It can handle low-level activities.
  • It can be compiled on a variety of computers.

Facts about C

  • C was invented to write an operating system called UNIX.
  • C is a successor of B language which was introduced around 1970
  • The language was formalized in 1988 by the American National Standard Institue (ANSI).
  • By 1973 UNIX OS almost totally written in C.
  • Today C is the most widely used System Programming Language.
  • Most of the state of the art software have been implemented using C

Why to use C ?

C was initially used for system development work, in particular the programs that make-up the operating system. C was adoped as a system development language because it produces code that runs nearly as fast as code written in assembly language. Some examples of the use of C might be:
  • Operating Systems
  • Language Compilers
  • Assemblers
  • Text Editors
  • Print Spoolers
  • Network Drivers
  • Modern Programs
  • Data Bases
  • Language Interpreters
  • Utilities

Worth to know about C language

Oracle is written in c
Core libraries of android are written in c
MySQL is written in c
Almost every device drivers is written in c
Major part of the browser is written in c
Unix operating system is developed in c
C is the world's most popular programming language

For students :-

• C is important to build programming skills
• C covers basic features of all programming language
• Campus recruitment process
• C is the most popular language for hardware dependent programming

C Program File

All the C programs are written into text files with extension ".c" for example hello.c. You can use "vi" editor to write your C program into a file.
This tutorial assumes that you know how to edit a text file and how to write programming instructions inside a program file.

C Compilers

When you write any program in C language then to run that program you need to compile that program using a C Compiler which converts your program into a language understandable by a computer. This is called machine language (i,e. binary format). So before proceeding, make sure you have C Compiler available at your computer. It comes along with all flavors of Unix and Linux.
If you are working over Unix or Linux then you can type gcc -v or cc -v and check the result. You can ask your system administrator or you can take help from anyone to identify an available C Compiler at your computer.
If you don't have C compiler installed at your computer then you can use below given link to download a GNU C Compiler and use it.

codeblock - http://www.codeblocks.org/downloads/2
turbo c++ - https://developerinsider.co/download-turbo-c-for-windows-7-8-8-1-and-windows-10-32-64-bit-full-screen/

Make Your Computer Welcome you

To use this trick, follow the instructions given below:-

Step 1: Click on Start. Navigate to All Programs, Accessories and Notepad.

Step 2: Copy and paste the exact code given below.

 Dim speaks, speech
 speaks=”Welcome to your PC, Username”
 Set speech=CreateObject(“sapi.spvoice”)
 speech.Speak speaks

Step 3: Replace Username with your own name.

Step 4: Click on File Menu, Save As, select All Types in Save as Type option, and save the file as Welcome.vbs or “*.vbs”.

Step 5: Copy the saved file.

Step 6: Navigate to C:Documents and SettingsAll UsersStart MenuProgramsStartup (in Windows XP) and to C:Users
 {User-Name}AppDataRoamingMicrosoftWindowsStart MenuProgramsStartup (in Windows 8, Windows 7 and Windows Vista) if C: is your System drive. AppData is a hidden folder. So, you will need to select showing hidden folders in Folder options to locate it.

Step 7: Paste the file.

Now when the next time you start your computer, Windows will welcome you in its own computerized voice.

How to Delete your Google Web History ?

Step 1 : Visit your Google History page at https://google.com/history

Alternatively, you can click the gear icon on the upper right corner of a search results page, and then go to Search history.

Step 2 : Click on the gear icon again, and then go to Settings.

Step 3 : Click on the delete all link. You’ll be prompted for a confirmation. Click on Delete all again, and your entire search history is gone!

Step 4 : (optional): Click on the Turn off button on the Settings page to stop Google from storing your history again.

If you don’t want to delete your entire history, you can select individual items from the History main page, and delete them.

Create an Undeletable and Unrenamable folders in Windows

Try to make a new folder in windows & give it name con, aux, lpt1, lpt2, lpt3 up to lpt9. you won’t be allowed to create folder with above mentioned names, Because they are reserved words in windows.

How To Create Undeletable And Unrenamable Folders ?

Step 1: Open Command Prompt. Press Win+R, type cmd and click Enter

Step 2: Remember you cannot create Undeletable & unrenamable folder in your root directory (i.e. where the windows is installed)

Step 3: Type D: or E: in CMD and hit Enter

Step 4: Type -
 md con
and hit enter (md – make directory)

Step 5: You may use other words such asaux, lpt1, lpt2, lpt3 up to lpt9 instead of con in above step.

Step 6: Open that directory, you will see the folder created of name con.

Step 7: Try to delete that folder or rename that folder windows will show the error message.

How to delete that folder ?

It is not possible to delete that folder manually but you can delete this folder by another way mentioned below.

Step 1: Open Command Prompt

Step 2: Type D: ( if u created this type of folder in D: drive) & hit enter

Step 3: Type rd con(rd – remove directory)

Step 4: Open that directory and the folder will not appear because it is removed.

How To Create Android Apps Without Coding ?

As you all know that Android is one of most used mobile platform in the world. Android is free and open source operating system so one can easily customize this operating system. If you have much experience or thought about android app’s but don’t have any coding experience then this post is going to benefit you! You can easily create android app’s without any coding.

How To Create Android Apps Without Coding

There are lots of websites available on the internet to create android apps without anycoding but will tell you about the conventional ones only. Just follow the procedure to create your android app free and without any coding.

Features :-

These are the best sites for android application making without any coding :

#1 AppsGeyser

AppsGeyser is a FREE service that converts your content into an App and makes your money. Your app will have all you need including messaging, social sharing, tabsand full support for HTML5 enhancements. But forget about the app, Apps geyser helps you to build a business and profit from mobile!

#2 Appypie

Appy Pie is the fastest growing cloud based Mobile Apps Builder Software (App Maker) that allows users with no programming skills, to create Android & iPhone applications for mobiles and smartphones; and publish to Google Play & iTunes. With Appy Pie, there is no need to install or download anything, you can just drag & drop app pages to create your mobile app online. Once the App is published, you will receive an HTML5 based hybrid app that works with Android, iPhone, iPad, Windows Phone and Blackberry

#3 Buzztouch

Buzztouch is an open source “app engine” that powers tens of thousands of iPhone, iPad, and Android applications. Buzztouch is used in conjunction with the iOS and Androidsoftware developer kits (SDK’s).The BtCentral Control Panel is open source web-based software that is used to administer mobile apps created using Buzztouch.

#4 Appyet

Using AppYet, anyone can create a professional Android app. There’s no programming knowledge required, only take a few minutes to build your first app. All you need to provide is links to RSS/Atom feed or website, they are automatically converted into stunning 100% pure native apps for Android. You have freedom to list/sell the app on Google Play and many other Android Markets.

#5 Appclay

AppClay , conceived and created by core development experts at ShepHertz Technologies, is an esteemed intuitive interface that enables each one of us- become an App developer effortlessly without any coding, software installation, maintenance and financial investment. Anyone can use AppClay to create HTML5 and ANDROID native Apps supported by all widely popular devices.

AppsGeyser and above listed websites are the best sites for android app making without any coding. These sites provide you to create many types of apps like Website, Page, Browser, Youtube app ( for you channel ), HTML code, TV, Photo, News, Book, Audio, Wallpaper and Quiz apps etc. In order to make these apps, you need to create the free account on this website. After this, you have to select you app category mentioned above later on you will have to select app name description about your application. After all these things you have to click on Create App button. After in few minutes you will be able to download your created app in app format. You can also further update your app.





HTML 5 for extra Features.
Earn money by your apps.
Modify apps at any time.
No Need Of Coding.
No Cost.

8 Premium Android Apps to Get Unlimited VPN for FREE

What is a VPN?

The full form of VPN is Virtual Private Network. In simple words, it means a virtual network in which the user remains anonymous and remains untraceable from the website trackers.

Using VPN, you can change your ip address to any other ip address.

By default, an ip address can be used to determine the location of the user he is browsing from.

Hence, the ability to change ip address enables you to change your location to virtually any place in the world.

That is why this is called Virtual Private Network. You may be browsing from your home but you can choose any location around the world as your browsing location.

It has many important uses due to it’s advantages.

Features and Advantages of using VPN:
Hides your original IP Address and Changes IP Address so that you can surf anonymously.

Unblocks any websites blocked by your ISP, Administrators or by law or court orders.
Protects your identity over a Wi-Fi Network so that hackers cannot get into your private files.

Protects you from visiting sites having Malwares.

Helps to browse Google Play without country restrictions to download unavailable apps in your country.

Tricks to Get Unlimited Free VPN:

Well, before I jump into the main article, let me clarify this, there are two ways to enjoy unlimited free vpn, the ethical and the unethical ways.

The ethical ways includes services that are provided for free and will remain free forever.

The unethical ways are those whose services are by default not free but have been modified and unlocked so that the premium services can be used without paying for them.

We are sharing both the ways for you here, it is entirely your decision which to choose and to stick on.

We strongly recommend using the ethical ones, and also suggest you to buy their premium services to support them.
100% Free to Use VPN Apps with Limited Features:

Let’s move on to the 100% Free VPN Services first.

Use Super:

This VPN app is a simple app with minimum modifications or settings. Just install and run. Each session is of 60 minutes after that you have to manually renew the session for free with just a click of a button.

Use Cloud Unlimited:

CloudVPN is yet another app just like SuperVPN that you can use for accessing Free and Unlimited VPN Service. It has a one click connection button to connect to their servers.

Use Flash Free Proxy App:

The main advantage of this VPN app over other free to use Apps is that it lets you choose the server of your choice, while others are just click to connect where you only get connected to the server they provide. FlashVPN servers are available on USA, England and Japan to give you more privacy.

Use Hola Free App:

This is the most functional of all the Free VPN Apps available on Play Store. You can choose from 190 countries to fake your location. At the time of writing this post this app has got 10 million downloads in the Play Store with 4.3 out of 5 ratings.

Premium Unlocked VPN Apps:

The apps given above are our handpicked Free VPN app suggestions to fake your location, mask and change your ip address all for 100% Free.

But let me tell you, these apps lack the Premium Features which are only available to the Paid versions of the apps.
Hence, we present you some exclusive premium unlocked apps which can be used to get unlimited free vpn. Check these out.
Use HideMyIP Premium Unlocked Apk:
HideMyIP is the best VPN Solution for all Android Users due to it’s fastest servers. Their subcriptions are a bit difficult to afford, but here we are sharing with you HideMyIP Premium Unlocked APK through which you can access to the HideMyIP Premium servers for free.

Use Hotspot Shield Unlimited Elite Unlocked Apk:

Hotspot Shield Android App is a brilliant app for using VPN Services. By default it is a paid app. But we are sharing a modded Elite Version Apk of Hotspot Shield that you can download and enjoy Unlimited free VPN.

Hotspot Shield
Use HideNinja Elite Unlocked APK:

HideNinja VPN is protected with 256-bit AES encryption algorithm making it one of the most secure vpn apps you can rely on. HideNinja is normally not available for free, but, as usual, we have HIdeNinja Unlocked version of the Premium Elite. So enjoy full protection.

Use Droid Premium Modded Apk:

DroidVPN is another popular app for Android Users specially because it gives daily free access to its Services with a limit of 100 MB Per Day. But don’t worry, we are sharing with you a premium DroidVPN apk that you can use for unlimited acess to the free servers.
Note: The paid servers are not available.

YOU MAY ALSO LIKE: LIFI, an optical wireless network, is 100 times faster than WIFI

Conclusion:

That’s all about VPN, both paid and free. But if you ask me what service I recommend you to go for then I will say buy a premium service.

Among all other VPN services, you can check out the most popular and affordable HideMyIP VPN and it will satisfy all your basic needs. Subscriptions start from as low as 7$ per month.

How to Hack a Website: Online Example

More people have access to the internet than ever before. This has prompted many organizations to develop web-based applications that users can use online to interact with the organization. Poorly written code for web applications can be exploited to gain unauthorized access to sensitive data and web servers.

In this article, we will introduce you to web applications hacking techniques and the counter measures you can put in place to protect against such attacks.

What is a web application? What are Web Threats?
A web application (aka website) is an application based on the client-server model. The server provides the database access and the business logic. It is hosted on a web server. The client application runs on the client web browser. Web applications are usually written in languages such as Java, C#, and VB.Net, PHP, ColdFusion Markup Language, etc. the database engines used in web applications include MySQL, MS Server, PostgreSQL, SQLite, etc.
Most web applications are hosted on public servers accessible via the Internet. This makes them vulnerable to attacks due to easy accessibility. The following are common web application threats.
  • SQL Injection – the goal of this threat could be to bypass login algorithms, sabotage the data, etc.
  • Denial of Service Attacks– the goal of this threat could be to deny legitimate users access to the resource
  • Cross Site Scripting XSS– the goal of this threat could be to inject code that can be executed on the client side browser.
  • Cookie/Session Poisoning– the goal of this threat is to modify cookies/session data by an attacker to gain unauthorized access.
  • Form Tampering – the goal of this threat is to modify form data such as prices in e-commerce applications so that the attacker can get items at reduced prices.
  • Code Injection – the goal of this threat is to inject code such as PHP, Python, etc. that can be executed on the server. The code can install backdoors, reveal sensitive information, etc.
  • Defacement– the goal of this threat is to modify the page been displayed on a website and redirecting all page requests to a single page that contains the attacker’s message.
How to protect your Website against hacks?
An organization can adopt the following policy to protect itself against web server attacks.
  • SQL Injection– sanitizing and validating user parameters before submitting them to the database for processing can help reduce the chances of been attacked via SQL Injection. Database engines such as MS SQL Server, MySQL, etc. support parameters, and prepared statements. They are much safer than traditional SQL statements
  • Denial of Service Attacks – firewalls can be used to drop traffic from suspicious IP address if the attack is a simple DoS. Proper configuration of networks and Intrusion Detection System can also help reduce the chances of a DoS attack been successful.
  • Cross Site Scripting – validating and sanitizing headers, parameters passed via the URL, form parameters and hidden values can help reduce XSS attacks.
  • Cookie/Session Poisoning– this can be prevented by encrypting the contents of the cookies, timing out the cookies after some time, associating the cookies with the client IP address that was used to create them.
  • Form tempering – this can be prevented by validating and verifying the user input before processing it.
  • Code Injection - this can be prevented by treating all parameters as data rather than executable code. Sanitization and Validation can be used to implement this.
  • Defacement – a good web application development security policy should ensure that it seals the commonly used vulnerabilities to access the web server. This can be a proper configuration of the operating system, web server software, and best security practices when developing web applications.

Web server attack tools

Some of the common web server attack tools include;
  • Metasploit– this is an open source tool for developing, testing and using exploit code. It can be used to discover vulnerabilities in web servers and write exploits that can be used to compromise the server.
  • MPack– this is a web exploitation tool. It was written in PHP and is backed by MySQL as the database engine. Once a web server has been compromised using MPack, all traffic to it is redirected to malicious download websites.
  • Zeus– this tool can be used to turn a compromised computer into a bot or zombie. A bot is a compromised computer which is used to perform internet-based attacks. A botnet is a collection of compromised computers. The botnet can then be used in a denial of service attack or sending spam mails.
  • Neosplit – this tool can be used to install programs, delete programs, replicating it, etc.
How to avoid attacks on Web server
An organization can adopt the following policy to protect itself against web server attacks.
  • Patch management– this involves installing patches to help secure the server. A patch is an update that fixes a bug in the software. The patches can be applied to the operating system and the web server system.
  • Secure installation and configuration of the operating system
  • Secure installation and configuration of the web server software
  • Vulnerability scanning system– these include tools such as Snort, NMap, Scanner Access Now Easy (SANE)
  • Firewalls can be used to stop simple DoS attacks by blocking all traffic coming the identify source IP addresses of the attacker.
  • Antivirus software can be used to remove malicious software on the server
  • Disabling Remote Administration
  • Default accounts and unused accounts must be removed from the system
  • Default ports  & settings (like FTP at port  21) should be changed to custom port & settings (FTP port at 5069)
Hacking Activity: Hack a WebServer
In this practical scenario, we are going to look at the anatomy of a web server attack. We will assume we are targeting  We are not actually going to hack into it as this is illegal. We will only use the domain for educational purposes
Information gathering
We will need to get the IP address of our target and find other websites that share the same IP address.


Based on the above results, the IP address of the target is 69.195.124.112
We also found out that there are 403 domains on the same web server.
Our next step is to scan the other websites for injection vulnerabilities. Note: if we can find a SQL vulnerable on the target, then we would directly exploit it without considering other websites.
  • Enter the into your web browser. This will only work with Bing so don’t use other search engines such as google or yahoo
  • Enter the following search query
ip:69.195.124.112 .php?id=



As you can see from the above results, all the websites using GET variables as parameters for SQL injection have been listed.
The next logic step would be to scan the listed websites for SQL Injection vulnerabilities. You can do this using manual SQL injection or use tools listed in this article on SQL Injection.
Uploading the PHP Shell
We will not scan any of the websites listed as this is illegal. Let’s assume that we have managed to login into one of them.
  • Open the URL where you uploaded the dk.php file.
  • You will get the following window
Once you have access to the files, you can get login credentials to the database and do whatever you want such as defacement, downloading data such as emails, etc.
  • Web server stored valuable information and are accessible to the public domain. This makes them targets for attackers.
  • The commonly used web servers include Apache and Internet Information Service IIS
  • Attacks against web servers take advantage of the bugs and Misconfiguration in the operating system, web servers, and networks
  • Popular web server hacking tools include NeosploitMPack, and ZeuS.
  • A good security policy can reduce the chances of been attacked

How to Hack a Web Server

Customers usually turn to the internet to get information and buy products and services. Towards that end, most organizations have websites.Most websites store valuable information such as credit card numbers, email address and passwords, etc. This has made them targets to attackers. Defaced websites can also be used to communicate religious or political ideologies etc.

In this article, we will introduce you towebservers hacking techniques and how you can protect servers from such attacks.
Web server vulnerabilities
A web server is a program that stores files (usually web pages) and makes them accessible via the network or the internet. A web server requires both hardware and software. Attackers usually target the exploits in the software to gain authorized entry to the server. Let’s look at some of the common vulnerabilities that attackers take advantage of.
  • Default settings– These settings such as default user id and passwords can be easily guessed by the attackers. Default settings might also allow performing certain tasks such as running commands on the server which can be exploited.
  • Misconfigurationof operating systems and networks – certain configuration such as allowing users to execute commands on the server can be dangerous if the user does not have a good password.
  • Bugs in the operating system and web servers– discovered bugs in the operating system or web server software can also be exploited to gain unauthorized access to the system.
In additional to the above-mentioned web server vulnerabilities, the following can also led to unauthorized access
  • Lack of security policy and procedures– lack of a security policy and procedures such as updating antivirus software, patching the operating system and web server software can create security loop holes for attackers.
Types of Web Servers
The following is a list of the common web servers
  • Apache– This is the commonly used web server on the internet. It is cross platform but is it’s usually installed on Linux. Most  websites are hosted servers.
  • Internet Information Services (IIS)It is developed by Microsoft. It runs on Windows and is the second most used web server on the internet. Most asp and aspx websites are hosted on IIS servers.
  • Apache Tomcat – Most Java server pages (JSP) websites are hosted on this type of web server.
  • Other web servers – These include Novell's Web Server and IBM’s Lotus Domino servers.
Types of Attacks against Web Servers
Directory traversal attacks– This type of attacks exploits bugs in the web server to gain unauthorized access to files and folders that are not in the public domain. Once the attacker has gained access, they can download sensitive information, execute commands on the server or install malicious software.
  • Denial of Service Attacks– With this type of attack, the web server may crash or become unavailable to the legitimate users.
  • Domain Name System Hijacking – With this type of attacker, the DNS setting are changed to point to the attacker’s web server. All traffic that was supposed to be sent to the web server is redirected to the wrong one.
  • Sniffing– Unencrypted data sent over the network may be intercepted and used to gain unauthorized access to the web server.
  • Phishing– With this type of attack, the attack impersonates the websites and directs traffic to the fake website. Unsuspecting users may be tricked into submitting sensitive data such as login details, credit card numbers, etc.
  • Pharming– With this type of attack, the attacker compromises the Domain Name System (DNS) servers or on the user computer so that traffic is directed to a malicious site.
  • Defacement– With this type of attack, the attacker replaces the organization’s website with a different page that contains the hacker’s name, images and may include background music and messages.

Effects of successful attacks

  • An organization’s reputation can be ruined if the attacker edits the website content and includes malicious information or links to a porn website
  • The web server can be used to install malicious software on users who visit the compromised website. The malicious software downloaded onto the visitor’s computer can be a virus, Trojan or Botnet Software, etc.
  • Compromised user data may be used for fraudulent activities which may lead to business loss or lawsuits from the users who entrusted their details with the organization



Hacking Activity: Launch a DOS attack

In this practical scenario, we are going to use Nemesy to generate data packets and flood the target computer, router or server.
As stated above, Nemesy will be detected as an illegal program by your anti-virus. You will have to disable the anti-virus for this exercise.
  • Unzip it and run the program Nemesy.exe
  • You will get the following interface

 Enter the target IP address, in this example; we have used the target IP we used in the above example.
HERE
  • 0 as the number of packets means infinity. You can set it to the desired number if you do not want to send, infinity data packets
  • The size field specifies the data bytes to be sent and the delay specifies the time interval in milliseconds.

Click on send button
You should be able to see the following results



The title bar will show you the number of packets sent
Click on halt button to stop the program from sending data packets.
You can monitor the task manager of the target computer to see the network activities.
  • A denial of service attack’s intent is to deny legitimate users access to a resource such as a network, server etc.
  • There are two types of attacks, denial of service and distributed denial of service.
  • A denial of service attack can be carried out using SYN Flooding, Ping of Death, Teardrop, Smurf or buffer overflow
  • Security patches for operating systems, router configuration, firewalls and intrusion detection systems can be used to protect against denial of service attacks.

DoS attack tools

The following are some of the tools that can be used to perform DoS attacks.
  • Nemesy– this tool can be used to generate random packets. It works on windows. . Due to the nature of the program, if you have an antivirus, it will most likely be detected as a virus.
  • Land and LaTierra– this tool can be used for IP spoofing and opening TCP connections
  • Blast
  • Panther- this tool can be used to flood a victim’s network with UDP packets.
  • Botnets– these are multitudes of compromised computers on the Internet that can be used to perform a distributed denial of service attack.
DoS Protection: Prevent an attack
An organization can adopt the following policy to protect itself against Denial of Service attacks.
  • Attacks such as SYN flooding take advantage of bugs in the operating system. Installing security patches can help reduce the chances of such attacks.
  • Intrusion detection systems can also be used to identify and even stop illegal activities
  • Firewalls can be used to stop simple DoS attacks by blocking all traffic coming from an attacker by identifying his IP.
  • Routers can be configured via the Access Control List to limit access to the network and drop suspected illegal traffic.
Hacking Activity: Ping of Death
We will assume you are using Windows for this exercise. We will also assume that you have at least two computers that are on the same network. DOS attacks are illegal on networks that you are not authorized to do so. This is why you will need to setup your own network for this exercise.
Open the command prompt on the target computer
Enter the command ipconfig. You will get results similar to the ones shown below

Switch to the computer that you want to use for the attack and open the command prompt
We will ping our victim computer with infinite data packets of 65500
Enter the following command


HERE,
  • “ping” sends the data packets to the victim
  • “10.128.131.108” is the IP address of the victim
  • “-t” means the data packets should be sent until the program is stopped
  • “-l” specifies the data load to be sent to the victim
You will get results similar to the ones shown below
Flooding the target computer with data packets doesn’t have much effect on the victim. In order for the attack to be more effective, you should attack the target computer with pings from more than one computer.
The above attack can be used to attacker routers, web servers etc.
If you want to see the effects of the attack on the target computer, you can open the task manager and view the network activities.
  • Right click on the taskbar
  • Select start task manager
  • Click on the network tab
  • You will get results similar to the following



If the attack is successful, you should be able to see increased network activities.


DoS (Denial of Service) Attack Tutorial: Ping of Death, DDOS

What is DoS Attack?

DOS is an attack used to deny legitimate users access to a resource such as accessing and website, network, emails, etc. or making it extremely slow. DoS is the acronym for Denial oService. This type of attack is usually implemented by hitting the target resource such as a web server with too many requests at the same time. This results in the server failing to respond to all the requests. The effect of this can either be crashing the servers or slowing them down.
Cutting off some business from the internet can lead to significant loss of business or money. The internet and computer networks power a lot of businesses. Some organizations such as payment gateways, e-commerce sites entirely depend on the internet to do business.
In this tutorial, we will introduce you to what denial of service attack is, how it is performed and how you can protect against such attacks.
Types of Dos Attacks
There are two types of Dos attacks namely;
  • DoS– this type of attack is performed by a single host
  • Distributed DoS– this type of attack is performed by a number of compromised machines that all target the same victim. It floods the network with data packets.

How DoS attacks work
Let’s look at how DoS attacks are performed and the techniques used. We will look at five common types of attacks.
Ping of Death
The ping command is usually used to test the availability of a network resource. It works by sending small data packets to the network resource. The ping of death takes advantage of this and sends data packets above the maximum limit (65,536 bytes) that TCP/IP allows. TCP/IP fragmentation breaks the packets into small chunks that are sent to the server. Since the sent data packages are larger than what the server can handle, the server can freeze, reboot, or crash.
Smurf
This type of attack uses large amounts of Internet Control Message Protocol (ICMP) ping traffic target at an Internet Broadcast Address. The reply IP address is spoofed to that of the intended victim. All the replies are sent to the victim instead of the IP used for the pings. Since a single Internet Broadcast Address can support a maximum of 255 hosts, a smurf attack amplifies a single ping 255 times.  The effect of this is slowing down the network to a point where it is impossible to use it.
Buffer overflow
A buffer is a temporal storage location in RAM that is used to hold data so that the CPU can manipulate it before writing it back to the disc. Buffers have a size limit. This type of attack loads the buffer with more data that it can hold. This causes the buffer to overflow and corrupt the data it holds. An example of a buffer overflow is sending emails with file names that have 256 characters.
Teardrop
This type of attack uses larger data packets. TCP/IP breaks them into fragments that are assembled on the receiving host. The attacker manipulates the packets as they are sent so that they overlap each other. This can cause the intended victim to crash as it tries to re-assemble the packets.
SYN attack
SYN is a short form for Synchronize. This type of attack takes advantage of the three-way handshake to establish communication using TCP. SYN attack works by flooding the victim with incomplete SYN messages. This causes the victim machine to allocate memory resources that are never used and deny access to legitimate users.

How to Crack Wireless Networks

WEP cracking
Cracking is the process of exploiting security weaknesses in wireless networks and gaining unauthorized access. WEP cracking refers to exploits on networks that use WEP to implement security controls. There are basically two types of cracks namely;
  • Passive cracking– this type of cracking has no effect on the network traffic until the WEP security has been cracked. It is difficult to detect.
  • Active cracking– this type of attack has an increased load effect on the network traffic. It is easy to detect compared to passive cracking. It is more effective compared to passive cracking.

WPA Cracking

·         WPA uses a 256 pre-shared key or passphrase for authentications. Short passphrases are vulnerable to dictionary attacks and other attacks that can be used to crack passwords. The following tools can be used to crack WPA keys.
General Attack types
  • Sniffing– this involves intercepting packets as they are transmitted over a network. The captured data can then be decoded using tools such as Cain & Abel.
  • Man in the Middle (MITM) Attack– this involves eavesdropping on a network and capturing sensitive information.
  • Denial of Service Attack– the main intent of this attack is to deny legitimate users network resources. FataJack can be used to perform this type of attack.

Cracking Wireless network WEP/WPA keys

It is possible to crack the WEP/WPA keys used to gain access to a wireless network. Doing so requires software and hardware resources, and patience. The success of such attacks can also depend on how active and inactive the users of the target network are.
We will provide you with basic information that can help you get started. Backtrack is a Linux-based security operating system. It is developed on top of Ubuntu. Backtrack comes with a number of security tools. Backtrack can be used to gather information, assess vulnerabilities and perform exploits among other things.
Some of the popular tools that backtrack has includes;
  • Metasploit
  • Wireshark
  • Aircrack-ng
  • NMap
  • Ophcrack
Cracking wireless network keys requires patience and resources mentioned above. At a minimum, you will need the following tools
wireless network adapter with the capability to inject packets (Hardware)
  • Be within the target network’s radius. If the users of the target network are actively using and connecting to it, then your chances of cracking it will be significantly improved.
  • Sufficient knowledge of Linux based operating systems and working knowledge of Aircrack and its various scripts.
  • Patience, cracking the keys may take a bit of sometime depending on a number of factors some of which may be beyond your control. Factors beyond your control include users of the target network using it actively as you sniff data packets.

How to Secure wireless networks

In minimizing wireless network attacks; an organization can adopt the following policies
  • Changing default passwords that come with the hardware
  • Enabling the authentication mechanism
  • Access to the network can be restricted by allowing only registered MAC addresses.
  • Use of strong WEP and WPA-PSK keys, a combination of symbols, number and characters reduce the chance of the keys been cracking using dictionary and brute force attacks.
  • Firewall Software can also help reduce unauthorized access.

Hacking Activity: Crack Wireless Password

In this practical scenario, we are going touseCain and Abel to decode the stored wireless network passwords in Windows. We will also provide useful information that can be used to crack the WEP and WPA keys of wireless networks.

Featured Post

List in Python

  List are just like dynamic array, declared in other languages( like vector in c++ and array list in java ). A single list may contain data...