Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Monday, April 4, 2016

Tails - Get your privacy back

Tails, because there is never too much security!tailslinux


Almost all O.S. (Operating systems) like Windows, Mac, Ios, Ubuntu, Android, etc will track you and send your details to other persons.

This means that for you to become secure, first and foremost you will need to increase your privacy.

On this post I will guide you step by step on how to achieve this.
Following this steps, In the end you will get a fully working O.S. running on your computer from a pen drive!

The system that I will recommend you to use is named Tails, it is a Unix based system, specially design to keep your online activity anonymous.

You are going to need a Internet connection to download the ISO and a Pen drive (4gb is enough for what you will need)

Lets start with the instructions

Step by step guide to create a bootable Pen disk with Tails the anonymous system


Tails USB

end-to-end encryption

end-to-end encryption and its importance


end-to-end encryption

Hello, this article will focus on end-to-end encryption. I will briefly explain what it is, why you should use it, and how to use end-to-end encryption to send your data.

Lets start with some basics:
End-to-end encryption means that data (including communications data) is encrypted at your end, and decrypted only at the intended recipient’s end. The important point is that no ‘middle man’ who can access your unencrypted data is involved. Because a middle man can always be regarded as suspect, end-to-end-encryption should be seen as an absolute must if you care about security.

A case in point is Microsoft, who while they encrypt all emails and files held in SkyDrive, also hold the encryption keys, and used these to unlock the emails and files of its 250 million worldwide users for inspection by the NSA. 

Basically, services that encrypt your data on their servers, rather than you encrypting your own data on your own machine, should be strongly avoided.
The terrifying scale of the NSA’s attack on public cryptography and its deliberate weakening of common international encryption standards has demonstrated that no proprietary software can be trusted; even software specifically designed with security in mind. It is now a proven fact that the NSA has co-opted or coerced hundreds of technology companies into building backdoors into their programs, or otherwise weakening security in order to allow the NSA access. US and UK companies are particularly suspect, although the reports make it clear that company’s across the world have acceded to NSA demands.

The problem with proprietary software is not just that as sole developers and owners, companies can be fairly easily approached and convinced to play ball with the NSA, but that their source code is kept secret, making it easy to add to or modify in dodgy ways without anyone noticing.

The best answer to this problem is to use free open source software (FOSS). Often jointly developed by disparate and otherwise unconnected individuals, the source code is available to everyone to examine and peer-review, thereby minimizing the chances that it has been tampered with. Ideally this code should also be compatible other implementations, in order to minimize the possibility of a back-door being built in.

It is of course possible that NSA agents have infiltrated open source development groups and introduced malicious code without anyone’s knowledge, and the sheer amount of code that many projects involve means that it is often almost impossible to fully peer-review all of it.

Still, despite these potential pitfalls, FOSS remains the most reliable and least likely to be tampered with software available, and if you truly care about privacy you should try to use it exclusively (up to and including using FOSS Operating Systems such as Linux).

On this Article I tell you how to obtain and use PGP to encrypt your files LINK

As always, If you enjoyed this article please do share it by using the social buttons below (Facebook, Twitter, Stumbleupon, etc)

Really soon, I will update with another news article, a onion website review, some downloads, good tips, etc. you will need to pass by again to see what changed.

Stay tuned I will upload something new very soon, thanks.

Saturday, March 5, 2016

DoS and DDoS attacks - Basics


DoS and DDoS attacks - Basic notionsDDoS


DoS or (Denial of services) attacks are a way to exploit a user resources in a way the “services ” become unavaliable.

While DDoS stands for (Distributed Denial of Service) attacks. Are the same as DoS except that they use hundreds, or even thousands of machines to flood the services and cause the malfunction.

Usually this is performed by flooding the service with ICMP packets forcing a server to respond to the request by the attackers (this is achieved by the need to reply to the ICMP packet). Other attacks including sending malformed ICMP packets, flooding the site with resource requests, or SYN flood attacks.


Despite the ICMP traffic uses the TCP protocol, this kind of attack will not work on a Tor network. There are hundreds of reasons for .onion websites and markets to become unavailable, but rest assure a ICMP attack is not one of them.


But when this kind of attack is targeted at the Clearnet for example against www.facebook.com. Over and over again they keep being successful.


Or another method of achieving the same result- Ping of death attack (catchy name right!)ping-of-death


This attack is accomplished in two different ways, the first method is quite obvious, just send too many packages to flood the system. A system using Windows as the absolute packet size limit of 64K (65535 bytes).


This means that if you are able to send packets larger then the 64k limit, it will either completely crash down the system, or it will enable the attacker to successfully perform a privilege escalation attack. Flooding the site with requests for resources (videos, pictures, login requests, etc.)


To prevent this attacks you need to focus more on the hardware control then the implementations with the site itself. If you are hosting and managing both, the server and the website, you should try to enable ingress filtering over your network, to stop some of the attacks on the spot. If you use the backscatter traceback method  you will be able to do just that.


Also take care to block the ICMP packets looking for your external interface (the WAN). Take special attention to block all the "unallocated source address'".


Following these steps you will not stop a DDoS, but you certainly will weaken the effect.




Tools for DDos and DoS attacks


Microsoft PIN revolution the new “advance”

Hello, if you recently upgraded for Windows 10. You may have noticed this notification: pin notification
“Using a PN is faster and more secure than a password – we think you'll love it.”

This got me thinking, how can a 4 digits PIN code ever be safer then a long password with all the rules they require nowadays. 8 characters or more, special symbols, numbers, etc.

I could not figure it out, so I had to do some research on the topic, and this is what I found out in the end.

First and foremost the “PIN” code will not directly increase the security of your computer, but it definitely increases the security of your online account with Microsoft.

How is it possible?

  • The PIN is only used to log in a particular computer, but does not guarantee access to the all the accounts that the owner may have used on that computer before.



  • The idea seems to be: In case shit happens and someone manage to enter this PC he will only have access to this single computer, but will leave the rest of the network safe.


Thursday, March 3, 2016

Silk Road is dead. What next?

On this article I will talk about Silk Road from the beginning to the end, and I will talk about what's coming now that Silk Road is dead.

1- What Silk Road was
2- What happened to Silk Roadsilk road logo
3- Consequences
4- Whats happening now

1- Silk Road was a dark net Market best know for selling all kinds of drugs Worldwide.
Silk Road was launched on February of 2011 and operated under the Tor network.
The original onion address was http://silkroadvb5piz3r.onion untill it got seized by the FBI back in 2013

Silk_Road_Seized

 

2- What happened to Silk Road was that it got really big, the media started to be all over it and it got the attention of the US government.
After grabbing the atenttion from autoritys, small dealers started to get caught and convicted here and there.
Untill finally the FBI was able to locate the real location of the server, from there they infiltrated deep on the website and eventually were able to arrest the supposed owner/creator/administrator Ross William Ulbricht AKA"Dread Pirate Roberts"ross ulbritch linkedin
3- A consequence of all this, was that the Dark Web gained notoriety, more and more Illegal markets started to emerge. Inclusive soon after the FBI closed the Silk Road Market the Silk Road 2 Market was created by three administrators of the original Silk Road website relaunched it under the name Silk Road 2, this website was operational from Nov 06 2013 untill Nov 06 2014.
Silk Road 3 would follow, but this one was just a rebrand of another Dark Web Market "Diabolus"
4- What we have now is a crazy uprising of new dark web markets. It seems that for each market the authorities take down, 2 more appear to replace them.silk-road-2

 



Saturday, February 27, 2016

Useful information and tips

After some time I decided to give you some more good tips, so here they are:

 

 

USEFUL STUFF YOU SHOULD KNOW


● IF YOU JUST WANT TO BROWSE THE WEB ANONIMOUSLY THEN TOR CAN ACT AS YOUR VPN BUT DO NOT USE THIS FOR ANY OTHER REASON SUCH AS MARKET PLACES, CARDING ETC YOU WILL REALLY REQUIRE A STRONGER SECURITY SUCH AS VYPRVPN AND SOCKS

● I RECOMMEND FIREFOX TO BE YOUR NUMBER ONE CHOICE BROWSER WHEN DOING CARDING OR ANY ILLEGAL ACTIVITY I HAVE NOTICED THIS ONE TO BE THE EASIEST TO CLEAN (WITH CCLEANER)

● GOOGLE CHROME STILL HAS COOKIES EVEN THOUGH YOU HAVE RAN IT THROUGH CCLEANER (MANUAL CLEAN IS REQUIRED) I DO NOT RECOMMEND CHROME ANYWAY

● VIP72 HAS SOCKS THAT COME AND GO OFFLINE FOR EXAMPLE DAYTIME IN THE UK THERE ARE LOADS OF UK SOCKS.

BUT AT NIGHT THEY DROP BY A LOT SO ALWAYS TRY TO HIT THE COUNTRY YOU NEED IN THERE “DAYTIME” HOURS

● PAYPAL’S SECURITY CAN SEE THE FOLLOWING
IP - TIME ZONE - KEYBOARD LANGUAGE - HDD SERIAL - PC ACCOUNT NAME

 

VyprVPNYearlyProSpecial_468x60_EN

 

Thursday, February 25, 2016

steganography use it to hide a text file on a image

Now Iam going to teach you a very easy way to hide a text document inside an image file.
This process is called steganography. I already talked about it in this previous post LINK but I did not give any tutorial.
Iam making one now with step by step instructions and some visual help :)
The best part about this, is that you do not need any special software to do it! a simple comand line under Windows will do the trick.

Lets Start the Instructions:


For this tutorial I am going to hide a text file inside a jpg image.
step11- Choose an image and a text document
1.2- Create a new folder on your hard drive, in my case I named my folder "a"
1.3- copy the text and the image file inside the folder, to make it easier in further steps you can rename the files with short names like 1 for the image and 2 for the text.

Ok step one is done, now you should have something on your computer similar to the image on the left.

 

 

 




Step 22-
Open a Command Prompt window. To do this go to the start menu and write cmd, then just click on the Command Prompt icon (I suggest you press CTRL+SHIFT and click the icon to run as an administrator)
If a new window with letters appeared then you are almost done! (Image on the right).

 

 

3- To proceed we need to locate and access the folder where we have our files. To navigate through the command prompt you need to use the cd command. Write cd\ and press the enter key.
3.1- Continue and write cd a (if a is the name of the folder you created on the first step)
3.2- You are inside the folder a. But just to make sure everything is in place write dir and press enter.
3.3- You are going to see the name of the image and the text document. If you renamed them as I said, you got 1.jpg and 2.txt
insert the following command: copy /b 1.jpg + 2.txt hiddentext.jpg
Press enter

 

deep web (basics, myths and opinion)

The deep web.deepweb

First and foremost, if you are new to the theme and have no idea about it, I recommend you read this previous article I made where you can read how to enter on the deep web.

http://www.securityfreak.info/security/deep-web/

 

If you already know hot to enter the deep web you can skip it and start reading this post :)



Wednesday, February 24, 2016

Hansa Market on the deep/dark web

'Login __ HANSA Market' - hansamkt2rr6nfg3_onion_loginHello, in this post Iam going to tell you about one of my favorite markets on the deep/dark web.
The Hansa Market.
Here is the onion link: http://hansamkt2rr6nfg3.onion/

First I will start with the basics, what is a dark web market?
Basically a dark web market is a webpage located on the Tor network, using a .onion domain.
You can only access it using the Tor network. And on this "market" users can sell goods and services to eachother under a big level of anonymity.

Monday, February 15, 2016

How to Use PGP

First I will give you a brief description on what PGP is:

Basically PGP stands for Pretty Good Privacy, it is a program that allows the user to encrypt and decrypt any type of data. The most common use  (at least on the dark net) is to encrypt the text messages you send, particularly between vendors and customers .

It is vital not to send your details unencrypted because odds are you are getting watched by someone you don’t want to know the contents of the message.

Now back to PGP:

Saturday, February 13, 2016

Steganography

Another good form of encryption is steganography which is the act of hiding data within text, graphic files, or audio files.

The purpose of this method is so that nobody will know that there is a private message inside the medium (photo, document, etc.) because it is hidden.

Let’s say Bob wants to send private messages to Steve over a public forum read by numerous people. Bob grabs a picture, puts a hidden message inside and uploads it to the website. nobody knows the message is there except for Steve, which is able to save the picture to his computer and read the message hidden inside.

Forensic examiners will need to be looking at each individual file to determine if steganography was used. So for example if you have 1000 pictures, they will need to go through each and every one to determine which ones have steganography and which ones do not.

Using steganography is as easy as downloading the right software from the internet.

I started up by downloading one of the more popular freeware tools out now: F5, then moved to a tool called SecurEngine, which hides text files within larger text files, and lastly a tool that hides files in MP3s called MP3Stego. I also tested one commercial steganography product, Steganos Suite. These tools may contain backdoors as with all encryption programs therefor should not be used with data you are trying to hide from any party that may hold the decryption key.

what is Computer encryption

Computer encryption is based on the science of cryptography, which has been used as long as humans have wanted to keep information secret. The earliest forms of encryption where the scytale’s and the creation of cipher texts. These forms of cryptography would rely on both parties knowing the key used or the correct cipher before the message could be delivered. Here's an example of a typical cipher, with a grid of letters and their corresponding numbers:

1 2 3 4 5
1 A B C D E
2 F G H I/J K
3 L M N O P
4 Q R S T U
5 V W X Y Z


If a general wanted to send the message “I love ponies” he would write the series of corresponding numbers: 42 13 43 15 51 53 43 33 42 51 34. Only the person with this cipher text would be able to reach the message. Now obviously, to make the message more difficult to decipher, the letters inside the table would be arranged differently. Computer encryption uses algorithms to alter plain text information into a form that is unreadable. Most people believe that AES will be a sufficient encryption standard for a long time coming: A 128‐bit key, for instance, can have more than 300,000,000,000,000,000,000,000,000,000,000,000 key combinations. Today’s AES standard is AES 256bit encryption which has 256 ^ 2 possible combinations.
As we said before, there are many reasons for encryption. One purpose of encryption is the act of transforming data from a state that is readable to a state that cannot be read by a third party that does not have permission. The result of the process is encrypted information (in cryptography, referred to as ciphertext).

The reverse process, i.e., to make the encrypted information readable again, is referred to

as decryption (i.e., to make it unencrypted). It is also important to know that the word  ncryption can implicitly refer to the decryption process. For example, if you get an encryption program, it encrypts information as well as decrypts it.

There are two types of encryption that should be used for two different purposes: symmetric (private key encryption) and asymmetric (public key encryption). Symmetric encryption is used the most because it is fast, easy to use, and is the most widely needed. You will use this form of encryption when there is only one password being used (such as TrueCrypt or another simple file encryption utility).

Asymmetric encryption on the other hand uses two keys, one to encrypt information and the other to decrypt the information.

Encryption

Encryption is the process of encoding messages (or information) in such a way that eavesdroppers or hackers cannot read it, but that authorized parties can.

Using cryptography three purposes are fulfilled:

1- confidentiality

2- integrity

3- non‐repudiation.

Encryption has long been used by militaries and governments to facilitate secret communication. It is now commonly used in protecting information within many kinds of civilian systems. Also, many compliance laws require encryption to be used in businesses to ensure that confidential client data be secured if the device or data is stolen. In this section I will be talking about using encryption for confidentiality and integrity. Non‐repudiation is used, but is not normally implemented for our purposes.

Setting up TrueCrypt, Encrypted Hidden Volumes

If you save anything on your computer, it is likely that you do not want just anyone to be able to see what you have saved. You want a way to protect that information so that you can access it, and absolutely no one else except those you trust. Therefore, it makes sense to set up a system which protects your information and safeguards it against prying eyes.
The best such system for this is called "True Crypt". "True Crypt" is an encryption software program which allows you to store many files and directories inside of a single file on your harddrive.
Further, this file is encrypted and no one can actually see what you have saved there unless they know your password.
This sounds extremely high tech, but it is actually very easy to set up. We are going to do so, right now:

1. Go to http://www.truecrypt.org/downloads (or go to www.truecrypt.org, and click on "Downloads")
2. Under "Latest Stable Version", under "Windows 7/Vista/XP/2000", click "Download"
3. The file will be called "True Crypt Setup 7.0a.exe" or something similar. Run this file.
4. If prompted that a program needs your permission to continue, click "Continue".
5. Check "I accept and agree to be bound by these license terms"
6. Click "Accept"
7. Ensure that "Install" is selected, and click "Next"
8. click "Install"
9. You will see a dialog stating "TrueCrypt has been successfully installed." Click "Ok"
10. Click "No" when asked if you wish to view the tutorial/user's guide.
11. Click "Finish"
At this point, TrueCrypt is now installed. Now we will set up truecrypt so that we can begin using it to store sensitive information.

1. Click the "Windows Logo"/"Start" button on the lower left corner of your screen.
2. Click "All Programs"
3. Click "TrueCrypt"
4. Click the "TrueCrypt" application

And now we can begin:
1. click the button "Create Volume"
2. Ensuring that "Create an encrypted file container" is selected, click "Next"
3. Select "Hidden TrueCrypt volume" and click "Next".
4. Ensuring that "Normal mode" is selected, click "Next"
5. Click on "Select File"
Note which directory you are in on your computer. Look at the top of the dialog that has opened and you will see the path you are in, most likely the home directory for your username. An input box is provided with a flashing cursor asking you to type in a file name. Here, you will type in the following filename:
random.txt
You may of course replace random.txt with anything you like. This file is going to be created and will be used to store many other files inside.
Do NOT use a filename for a file that already exists. The idea here is that you are creating an entirely new file.
It is also recommended though not required that you "hide" this file somewhere less obvious. If it is in your home directory, then someone who has access to your computer may find it easier. You can also choose to put this file on any other media, it doesn't have to be your hard disk. You could for example save your truecrypt file to a usb flash drive, an sd card, or some other media. It is up to you.
6. Once you have typed in the file name, click "Save"
7. Make sure "Never save history" is checked.
8. Click "Next"
9. On the "Outer Volume" screen, click "Next" again.
10. The default Encryption Algorithm and Hash Algorithm are fine. Click "Next"
11. Choose a file size.
In order to benefit the most from this guide, you should have at least 10 gigabytes of free disk space. If not, then it is worth it for you to purchase some form of media (such as a removable harddrive, a large sd card, etc.) in order to proceed. TrueCrypt can be used on all forms of digital media not just your hard
disk.
If you choose to proceed without obtaining at least ten gigabytes of disk space, then select a size that you are comfortable with (such as 100 MB).
Ideally, you want to choose enough space to work with. I recommend 20 GB at least. Remember that if you do need more space later, you can always create additional TrueCrypt volumes using exactly these same steps.

12. Now you are prompted for a password. THIS IS VERY IMPORTANT. READ THIS CAREFULLY
*** READ THIS SECTION CAREFULLY ***

The password you choose here is a decoy password. That means, this is the password you would give to someone under duress. Suppose that someone suspects that you were accessing sensitive information and they threaten to beat you or worse if you do not reveal the password.
THIS is the password that you give to them.
When you give someone this password, it will be nearly impossible for them to
prove that it is not the RIGHT password.
Further, they cannot even know that there is a second password.

Here are some tips for your password:

A. Choose a password you will NEVER forget. It may be ten years from now that you need it.
Make it simple, like your birthday repeated three times.

B. Make sure it seems reasonable, that it appears to be a real password. If the password is something stupid like "123" then they may not believe you.
C. Remember that this is a password that you would give to someone if forced. It is *NOT* your actual password.
D. Do not make this password too similar to what you plan to really use. You do not want someone to guess your main password from this one.
And with all of this in mind, choose your password. When you have typed it in twice, click "Next".

13. "Large Files", here you are asked whether or not you plan to store files larger than 4 GIGABYTES.
Choose "No" and click "Next"
14. "Outer Volume Format", here you will notice some random numbers and letters next to where it says "Random Pool". Go ahead and move your mouse around for a bit. This will increase the randomness and give you better encryption. After about ten seconds of this, click "Format".
15. Depending on the file size you selected, it will take some time to finish formatting.
"What is happening?"
TrueCrypt is creating the file you asked it to, such as "random.txt". It is building a file system contained entirely within that one file.
This file system can be used to store files, directories, and more.
Further, it is encrypting this file system in such a way that without the right password it will be impossible for anyone to access it.
To *anyone* other than you, this file will appear to be just a mess of random characters. No one will even know that it is a truecrypt volume.
16. "Outer Volume Contents", click on the button called, "Open Outer Volume"
An empty folder has opened up. This is empty because you have yet to put any files into your truecrypt volume.

*** *** DO NOT PUT ANY SENSITIVE CONTENT HERE *** ***

This is the "Decoy". This is what someone would see if you gave them the password you used in the previous step. This is NOT where you are going to store your sensitive data. If you have been forced into a situation where you had to reveal your password to some individual, then that individual will see whatever is in this folder. You need to have data in this folder that appears to be sensitive enough to be protected by truecrypt in order to fool them. Here are some important tips to keep in mind:

A. Do NOT use porn. Adult models can sometimes appear to be underaged, and this can cause you
to
incriminate yourself unintentionally.
B. Do NOT use drawings/renderings/writings of porn. In many jurisdictions, these are just as illegal
as
photographs.
C. Good choices for what to put here include: backups of documents, emails, financial documents,
etc.
D. Once you have placed files into this folder, *NEVER* place any more files in the future. Doing so may damage your hidden content.
Generally, you want to store innocent data where some individual looking at it would find no cause against you, and yet at the same time they would understand why you used TrueCrypt to secure that data.
Now, go ahead and find files and store them in this folder. Be sure that you leave at least ten gigabytes free. The more the better.
When you are all done copying files into this folder, close the folder by clicking the "x" in the top right corner.
17. click "Next"
18. If prompted that "A program needs your permission to continue", click "Continue"
19. "Hidden Volume", click "Next"
20. The default encryption and hash algorithms are fine, click "Next"
21. "Hidden Volume Size", the maximum available space is indicated in bold below the text box.
Round
down to the nearest full unit. For example, if 19.97 GB
is available, select 19 GB. If 12.0 GB are available, select 11 GB.
22. If a warning dialog comes up, asking "Are you sure you wish to continue", select "Yes"
23. "Hidden Volume Password"

*** IMPORTANT READ THIS ***
Here you are going to select the REAL password. This is the password you will NEVER reveal to ANYONE else under any circumstances. Only you will know it. No one will be able to figure it out or even know that there is a second password. Be aware that an individual intent on obtaining your sensitive information may lie to you and claim to be able to figure this out. They cannot.
It is HIGHLY recommended that you choose a 64 character password here. If it is difficult to remember a 64 character password, choose an 8 character password and simply repeat it 8 times. A date naturally has exactly 8 numbers, and a significant date in your life repeated 8 times would do just fine.
24. Type in your password twice, and click "Next"
25. "Large Files", select "Yes" and click "Next".
26. "Hidden Volume Format", as before move your mouse around for about ten seconds randomly,
and
tehn click "Format".
27. If prompted "A program needs your permission to continue", select "Continue"
28. A dialog will come up telling you that the hidden TrueCrypt volume has been successfully
created.
Click "Ok"
29. Click "Exit"
Congratulations! You have just set up an encrypted file container on your hard drive. Anything you store here will be inaccessible to anyone except you.
Further, you have protected this content with TWO passwords. One that you will give to someone under threat, and one that only you will know. Keep your real password well protected and never write it down or give it to anyone else for any reason.
Now, we should test BOTH passwords.

disable your swap space on Windows 7

*This instructions are recommended for advanced users only. If you are not comfortable doing this, you may
safely skip this step.*
Instructions are less verbose than usual, as these steps are intended for advanced users only. If you do not fully understand these instructions, skip this step.
1. From Control Panel, go to "System and Security".
2. Click on "System", and then choose "Advanced system settings" in the left-most menu.
3. Under the "Advanced" tab, under "Performance", click "Settings".
4. Under this "Advanced" tab, under "Virtual Memory", click "Change"
5. Uncheck "Automatically manage paging file sizes for all drives"
6. Select "No paging file"
7. Save, reboot, and follow these same first 5 steps to confirm that "No paging file" is still selected.
This means that you have successfully disabled your swap. This means that *nothing* from RAM will be inadvertently saved to your harddrive.
To resume using SWAP again, simply click "Automatically manage paging file size for all drives."
You can switch between these two modes as you desire.
Generally speaking, your computer will run fine without a swap file, provided you have enough RAM.