Hãçkêrs Beginners Basics


Гео и язык канала: не указан, не указан
Категория: не указана


This is a sub channel of @hackersworldunite for repost of beginners basics essentials on how to become a hacker
Join the main channel @hackersworldunite

Связанные каналы  |  Похожие каналы

Гео и язык канала
не указан, не указан
Категория
не указана
Статистика
Фильтр публикаций




Summary

A denial of service attack’s intent is to deny legitimate users access to a resource such as a network, server etc.

There are two types of attacks, denial of service and distributed denial of service.

A denial of service attack can be carried out using SYN Flooding, Ping of Death, Teardrop, Smurf or buffer overflow

Security patches for operating systems, router configuration, firewalls and intrusion detection systems can be used to protect against denial of service attacks.




Enter the target IP address, in this example; we have used the target IP we used in the above example.
HERE,

0 as the number of packets means infinity. You can set it to the desired number if you do not want to send, infinity data packets

The size field specifies the data bytes to be sent and the delay specifies the time interval in milliseconds.

Click on send button
You should be able to see the following results




Hacking Activity: Launch a DOS attack

In this practical scenario, we are going to use Nemesy to generate data packets and flood the target computer, router or server.
As stated above, Nemesy will be detected as an illegal program by your anti-virus. You will have to disable the anti-virus for this exercise.

Download Nemesy from http://packetstormsecurity.com/files/25599/nemesy13.zip.html

Unzip it and run the program Nemesy.exe

You will get the following interface


Telegram banned the first channel
So we created a new one

Join Here Link Will Be Expired Within 2hrs

https://t.me/joinchat/GmeeGf-fkq1hNjA0

NB: First channel got banned. So check if you're in this new one.


the attack is successful, you should be able to see increased network activities.




Flooding the target computer with data packets doesn’t have much effect on the victim. In order for the attack to be more effective, you should attack the target computer with pings from more than one computer.
The above attack can be used to attacker routers, web servers etc.
If you want to see the effects of the attack on the target computer, you can open the task manager and view the network activities.

Right click on the taskbar

Select start task manager

Click on the network tab

You will get results similar to the following




HERE,

“ping” sends the data packets to the victim

“10.128.131.108” is the IP address of the victim

“-t” means the data packets should be sent until the program is stopped

“-l” specifies the data load to be sent to the victim

You will get results similar to the ones shown below


For this example, we are using Mobile Broadband connection details. Take note of the IP address. Note: for this example to be more effective, and you must use a LAN network.
Switch to the computer that you want to use for the attack and open the command prompt
We will ping our victim computer with infinite data packets of 65500
Enter the following command

ping 10.128.131.108 –t |65500




Hacking Activity: Ping of Death

We will assume you are using Windows for this exercise. We will also assume that you have at least two computers that are on the same network. DOS attacks are illegal on networks that you are not authorized to do so. This is why you will need to setup your own network for this exercise.
Open the command prompt on the target computer
Enter the command ipconfig. You will get results similar to the ones shown below


DoS Protection: Prevent an attack

An organization can adopt the following policy to protect itself against Denial of Service attacks.

Attacks such as SYN flooding take advantage of bugs in the operating system. Installing security patches can help reduce the chances of such attacks.

Intrusion detection systems can also be used to identify and even stop illegal activities

Firewalls can be used to stop simple DoS attacks by blocking all traffic coming from an attacker by identifying his IP.

Routers can be configured via the Access Control List to limit access to the network and drop suspected illegal traffic.


DoS attack tools

The following are some of the tools that can be used to perform DoS attacks.

Nemesy– this tool can be used to generate random packets. It works on windows. This tool can be downloaded from http://packetstormsecurity.com/files/25599/nemesy13.zip.html . Due to the nature of the program, if you have an antivirus, it will most likely be detected as a virus.

Land and LaTierra– this tool can be used for IP spoofing and opening TCP connections

Blast– this tool can be downloaded from http://www.opencomm.co.uk/products/blast/features.php

Panther– this tool can be used to flood a victim’s network with UDP packets.

Botnets– these are multitudes of compromised computers on the Internet that can be used to perform a distributed denial of service attack.


Those who just joined us should tap on the pinned message


We'll soon continue with the rest


Smurf
This type of attack uses large amounts of Internet Control Message Protocol (ICMP) ping traffic target at an Internet Broadcast Address. The reply IP address is spoofed to that of the intended victim. All the replies are sent to the victim instead of the IP used for the pings. Since a single Internet Broadcast Address can support a maximum of 255 hosts, a smurf attack amplifies a single ping 255 times. The effect of this is slowing down the network to a point where it is impossible to use it.

Buffer overflow
A buffer is a temporal storage location in RAM that is used to hold data so that the CPU can manipulate it before writing it back to the disc. Buffers have a size limit. This type of attack loads the buffer with more data that it can hold. This causes the buffer to overflow and corrupt the data it holds. An example of a buffer overflow is sending emails with file names that have 256 characters.

Teardrop
This type of attack uses larger data packets. TCP/IP breaks them into fragments that are assembled on the receiving host. The attacker manipulates the packets as they are sent so that they overlap each other. This can cause the intended victim to crash as it tries to re-assemble the packets.

SYN attack
SYN is a short form for Synchronize. This type of attack takes advantage of the three-way handshake to establish communication using TCP. SYN attack works by flooding the victim with incomplete SYN messages. This causes the victim machine to allocate memory resources that are never used and deny access to legitimate users.

Показано 20 последних публикаций.

3 845

подписчиков
Статистика канала