Kamis, 30 Desember 2010

Map of Network Security Technology ( Part 2 )

Certificate Authority / PKI
 
# Certificate Authority. Certificate Authority (CA) is an organization that provides and managing security credentials and public keys for encryption & decryption news. Certificates that are managed in the public keys that strengthens authentication, privacy & non-repudiation. # File & Session Encryption. Encryption is a process where the data on change its so hard to be open and understood by people who do not have authoritas for it. Sophisticated computer algorithms used in the process encrypt & dekrip when in need. # VPN & Cryptographic Communications. Virtual Private Network (VPN) enable secure communications over a public network the Internet. This is very save costs for companies with mobile workers or branches of companies, so that communication can be performed without the need to use the telephone network costly private. # Secure Web Servers.Tool that allows us to provide web services in an engineering environment so that security holes in its minimum. # Single Sign On. Software package that helps users to access the multiple computers without the need to remember many passwords. Single Sign On on basically does not change the underlying process, but hide the differences there through an additional software layer. # Web Application Security. Web application security will protect their web applications and resources available from the threats on the Internet, like, steal company assets, credit card theft, etc. deface sites. This is done detect / deter hacking techniques in this area.

 Vulnerability Testing

# Vulnerability Scanners - Host Based. Tool for menchek settings of the system to determine whether it is appropriate / consistent with corporate security policy. This tool commonly used by auditors.
# Real-Time Security Awareness, Response & Threat Management. RTSA allows a security manager to see what is happening in the company that uses a lot of equipment from multiple vendors in real-time through a console. RTSA help reduce the number of personnel required for monitor a lot of equipment.
# Vulnerability Scanners - Network Based. Software that can simulate the behavior attacker and studied until about 600 possible system weaknesses being attacked.

Managed Security Services
 
# Enterprise Security Policy Implementation. Epsi allows the security manager to mengautomasi any security measures of the center console, ranging from creating, editing, approving, publishing, distribution, education, compliance, reporting and maintenance. This tool will force socialization, understanding menchek employees, noting events, and measure compliance, which in turn will help management IT risk without giving much weight to the limited staff. # Managed Security Services. Vendors that offer managed security services assume that they will gain a few percent of the outsourced work. With this way. administrators can do other work. # Enterprise Security Administration. This tool administer security level enterprise, ensuring that all users in an enterprise to obtain the rights and The same obligation. This system is particularly useful for providing access for new users, and, most importantly, remove all access for employees who already exit. # Security Services: Policy Development. Consultants who help develop security policies quickly. They generally already have a template for security policies can be implemented quickly, sepertoi use of e-mail Good, extranet to PKI. # Trusted Operating Systems. Since all the security mechanism is highly dependent on operating systems, technology trusted O / S provides the only mechanism in O / S to defend against attacks. # Anti D.D.O.D Tools. Anti Ddos Tool will identify non beresan use in the network. If there is lack beresan, the tool will try to check the legitimacy of access and recommended several preventive measures it.

Map of Network Security Technology ( Part 1 )

Network security must become a knowledge that is owned for those who want to seriously work in the Internet. Unfortunately, technology has grown so complex that require network security professionals to learn many things to really understand the whole concept & technology network security. To facilitate the learning process, it is worth considering carefully the attached image that contains a map of network security technology. An excellent reference on this subject contained in http://www.sans.org.
In general, the topology of computer networks consist of a public Internet network that spreads throughout the world and that there is an internal Intranet network in the company / institution. In between Internet and intranet there are usually de-Militerized Zone (DMZ) is limited by the Router to the Internet filtering, and firewall to the Intranet. In De-Militerized Zone (DMZ) is usually in pairs of various servers, such as, Mail Server, FTP Server, Web Server and DNS Server.
  Based on the above network topology, we can divide the network security technology into four (4) major parts, namely: • Penetration testing • Certificate Authority / PKI • Vulnerability Testing
• Managed Security Services
  Let's look at the technology that became part of the four (4) of this section, in general,
 
 • Penetration Testing, consists of: o Active Content Monitoring / Filtering, usually put on the mail server in the DMZ. o Intrusion Detection - Host Based, usually put on servers in the Intranet and DMZ. o Firewall, intercede with the DMZ Intranet and Internet .. o Intrusion Detection - Network Based, usually used to monitor the Intranet. o Authorization, on the run in the Intranet. o Water Gap Technology, run on De-Militerized Zone (DMZ). o Network Authentication, operated on the Intranet. o Security Appliances, usually in the form of hardware firewall. o Security Services: Penetration Testing, a company outside that provide services to us. o Authentication, operated on the Intranet.
  • Certificate Authority / PKI, a supporter of other technologies and can be operated on servers in the Intranet, comprising: o Certificate Authority, on the intranet and internet.
o File and Session Encryption, operated on the Intranet o Cryptographic VPN & Communications, at the start of De-Militerized Zone and is used to penetrate to the Internet to the Intranet to another. o Secure Web Servers, operated at the De-Militerized Zone (DMZ). o Single Sign On, on the server. o Web Application Security, on the Web server.
  • Vulnerability Testing, usually performed by an auditor or security manager, among others. o Vulnerability Scanners - Host-Based, operated on Intranet server o Real-Time Security Awareness, Response & Threat Management, used by the security manager. o Vulnerability Scanners - Network Based, operated in the filtering router is connected directly to the Internet. 

Managed Security Services, is part of management (non-technical) network security. Issues that exist include:
o Enterprise Security Policy Implementation.
o Managed Security Services.
o Enterprise Security Administration.
o Security Services: Policy Development.
o Trusted Operating Systems, installed on all computers.
o Anti D.D.O.D Tools.
 

# Active Content Monitoring / Filtering. When you are connected to the Internet, you take the risk of computer viruses, java / Active-X scripts etc evil. This tool will check all content entering the network / computer, continuously update its library. # Intrusion Detection - Host Based. Host-based intrusion detection will monitor file log. He will meresponds with an alarm or a counterattack if any business user for accessing data, file or service that is not allowed. # Firewall. A firewall is a system or group of several systems implement access control policy between two networks. # Intrusion Detection - Network Based. Network-based intrusion detection will monitor the network and will meresponds with alarm at the time he identified a pattern of traffic that is not good, such as scanning, denial of business service or other attacks. # Authorization. Authentication, asked "Who are you?". Authorization, ask "Are you entitled to?". With the authorization mechanism for each user who will resource access should apply to the authorization server to obtain a permit. # Water Gap Technology. Hardware / software of this type allows the transfer of data real-time between the Internet with the back-end without opening a hole in the firewall. Sometimes Water Gap solutions require a physical connection to the network terminated outside. Water Gap sever all network protocols, limiting access to data in the application layer only, and perform content analysis. # Network Authentication. This tool uses several approaches to improve the system's ability to distinguish between eligible and not entitled to access. # Security Appliances. The combination of hardware / software that provides limited service, such as firewalls, network load management etc. Because its operating system is limited, more easily managed and not subject to hacker attacks such as the general-purpose UNIX or Windows NT. # Security Services: Penetration Testing. Consultant organization that simulate hacker attacks in the real world as well as social engineering attacks. They usually give advice how to fix the defense. Usually they using network-based vulnerability scanning tools. # Authentication. Authentication is a process that determines something or someone is who or what. The simplest way of authentication process is the logon password, unfortunately very susceptible to the stolen. Another way to overcome this is to use a token that allows more stringent authentication process again. 

 

Motivation for Hacking

Hackers with the expertise to see and fix vulnerabilities in computer software; normally then published openly on the Internet for the system to be better. Unfortunately, few people take the evil use that information to crime - they are usually called a cracker. Basically the world of hackers and crackers are no different from the art world, here we
talking art Internet network security.
 
I hope the science of network security in this paper is used for good things - be a Hacker
not a Cracker. Do not until you get karma for using science to destroy property others. Moreover, at present the need for hackers is increasing in Indonesia with dotcommers more who want to IPO in the stock market. Good name and the value of a dotcom could fall even become worthless if the dotcom collapse. In this case, the hackers expected to be a security consultant for the dotcommers it - because the HR party police and security forces in Indonesia is very very weak and pathetic in the field of technology Information & Internet. What may make cybersquad, private cyberpatrol probably need at budayakan for survival dotcommers Indonesia on the Internet.
 
Various Internet network security techniques can be easily obtained on the Internet, among others, in
http://www.sans.org, http://www.rootshell.com, http://www.linuxfirewall.org/, http://www.linuxdoc.org, http://www.cerias.purdue.edu/coast/firewalls/, http://www.redhat.com/mirrors/LDP/HOWTO/. Most of this technique in the form of books that the number of its several hundred pages that can be taken in free of charge (free). Some Frequently Asked Questions (FAQ) about network security can obtained in http://www.iss.net/vd/mail.html, http://www.v-one.com/documents/fw-faq.htm. And for
the experimenter some script / program that is so can be found among others in http://bastille-linux.sourceforge.net/, http://www.redhat.com/support/docs/tips/firewall/firewallservice.html.
 
For those readers who wish to gain knowledge about the network can be downloaded free of charge from http://pandu.dhs.org, http://www.bogor.net/idkf/, http://louis.idaman.com/idkf.
Some book-shaped softcopy can be taken free of charge to the capture of http://pandu.dhs.org/Buku-Online/. We must especially grateful to the team led by Pandu I Made Wiryana for this. At this time,  I do not know of any place of active discussion Indonesia discuss these hacking techniques - but may be partly discussed in the mailing list information such as kursus-linux@yahoogroups.com & Linux-admin@linux.or.id which are operated by the Indonesian Linux Users Group (Ltsp)
http://www.kpli.or.id.
 
The simplest way to see the weakness of the system is by way of seeking information from various vendors for example in http://www.sans.org/newlook/publications/roadmap.htm # 3b on weakness of the system they have created yourself. In addition, monitoring the various mailing lists at Internet security-related networks such as the list http://www.sans.org/newlook/publications/roadmap.htm # 3e.
 
Described by Front-line Information Security Team, "Techniques Adopted By 'System Crackers' When Attempting To Break Into Corporate or Sensitive Private Networks, "fist@ns2.co.uk http://www.ns2.co.uk.
A Cracker generally men aged 16-25 years.
Based on user statistics Internet in Indonesia, then in fact the majority of Internet users in Indonesia are children younger at this age as well. Indeed, this age is the age that is ideal in studying new including Internet knowledge, very unfortunate if we do not succeed menginternetkan to 25,000 Indonesian school s / d in 2002 - as the foundation for the future of Indonesia is in the hands of our young kids this.
 
Well, the young cracker cracking is generally done to improve the ability / use the resources on the network for its own sake.
Generally, the cracker is opportunistic.
Seeing the weakness of the system to carry out the scanner program. After gaining access root, the cracker will install a back door (backdoor) and close all general weakness there.
 
As we know, generally the various companies / dotcommers will use the Internet to (1)
Web hosting their servers, (2) e-mail communication and (3) provide access to web / internet to its employees.
Internet and Intranet network separation is generally performed using engineering / software firewall and proxy server. Seeing the conditions of use of the above, the weakness of the system generally can penetrate through the mail server for example with external / outside that is used for easy access to the mail out of the company. In addition, by using aggressive-SNMP scanner and a program that forced the SNMP community string to convert a router into bridge (bridge) which can then be used for a stepping stone to get into the network company's internal (Intranet).
 
In order for crackers protected during the attack, the technique cloacking (incognito) is done by jumping from the previous machine has been compromised (conquered) through program telnet or rsh. At an intermediary machine that uses Windows attack can be performed with Wingate jumped out of the program. In addition, the jumps can be done through a proxy device configuration is less good.
 
After a successful jump and into other systems, usually a cracker to probe against network and gather the information needed. This is done in several ways, eg (1) use nslookup to run the command 'ls <domain or network>', (2) see HTML file on your web server to identify other machines, (3) to see various documents on FTP servers, (4) connecting to the mail server and use the command 'expn <user>', and (5) her finger users on other external machines.
The next step, the cracker will identify network components that are trusted by the system what only. These network components are usually the administrator machine and the server that is usually considered most secure in the network. Start by checking access & NFS exports are critical to various directories such as / usr / bin, / etc and / home. Exploitation of the machine through the weakness of the Common Gateway Interface (CGI), with access to the file / etc / hosts.allow.

Next cracker should identify network components that are weak and can be conquered. Crackers can use the program in Linux like ADMhack,
mscan, nmap and many small scanner other. Programs such as 'ps' and 'netstat' in for a trojan (remember the Trojan horse story? in classical greek story old) to hide the scanning process. For a fairly advanced cracker can use aggressive-SNMP scanning to scan equipment with SNMP.

Once the cracker managed to identify the network components are weak and can be conquered, then cracker will run a program to conquer the weak daemon program on the server.
Program daemon is a program on a server that normally runs in the background (as daemon / demon).

The success of conquering this daemon program will allow a cracker to obtain access as 'root' (the highest administrator in the server).

To eliminate the trace, a cracker usually perform the cleaning operation 'clean-up' operation by way of cleaning the various log files. And add the program to enter from the back door 'backdooring'. Changing. Rhosts file in / usr / bin for easy access to the machine that be conquered through rsh & csh.
 
Furthermore, a cracker can use a machine that has been conquered for their interests own, such as taking sensitive information that should not be read; mengcracking machine other by jumping from the machine be conquered; install a sniffer to see / record the various traffic / communication is passed; can even turn off the system / network by running command 'rm-rf / &'.
The latter will be very fatal consequences because the system will be destroyed at all, especially if all the software in put in the hard disk. Process re-install the entire system must be done, would be a headache if it is done on machines that run mission critical.
 
Therefore all machines & routers that run mission critical should always check security & on patch by newer software. Backup is very important especially in machines that perform critical missions in order to be saved from the act of disabling cracker system with 'rm-rf / &'.
 
For those of us who wrestle daily on the Internet usually it will greatly appreciate the presence of hacker (not cracker).
Because thanks to the hackers, the Internet is there and can we enjoy such today, even kept in repair to be a better system. Various weaknesses
system be improved because of cleverness fellow hackers who often times they will be working on improvements. voluntarily because of his hobby. Moreover, often the result of his hacking distributed free of charge on the Internet for the purposes of the Internet community.
A culture of mutual help values & Noble it grows in cyberspace Internet that usually seem futuristic and far from the social sense.
 
Development of the hobbiest hackers has become critical to the sustainability / survival Internet vehicle dotcommers in Indonesia.
As one of fact, in the near future Inshallah God around mid April 2001 will be held hacking competition on the Internet to break into a server that has been determined beforehand. The hacking competition at hatched by children young people in the Indonesian Linux Users Group (Ltsp) Semarang driven by young people like Kresno Aji (masaji@telkom.net), Agus Hartanto (hartx@writeme.com) & Lekso Budi Handoko (Handoko@riset.dinus.ac.id). Like many other young children, they generally have capital tight budget - help & sponsorship would be very useful and expected by this young fellow.
 
Hopefully all this will add to the spirit of readers, especially young readers, for move in a world of exciting and challenging hackers. If Captain Jean Luc Picard said in the film Startrek Next Generation, "To boldly go Nowhere no one has gone before".
 

Minggu, 26 Desember 2010

Ranking Cirebon Blogger Competition

Assalamualaikum BC ( Blogger Cirebon ) , Bloggers Ciayumajakuning, dan lainnya. Bentar ( beberapa minggu ) lagi pengumuman Cirebon Blogger Competition nih. Saya yakin pesertanya lebih dari 1 juta orang! ( #lebayy.. bak!bik!buk!! http://warungflash.com/wp-includes/images/smilies/090_.gif) Sebelumnya saya ga nyangka kalau bisa buat blog sejauh ini berkat ikut lomba ini. Sekarang jadi giat posting, share ilmu http://warungflash.com/wp-includes/images/smilies/onion-head69.gif.

Oiya Sobat, hanya ngasih tau ajah, kalo disini juga ada forumnya. Yang mau share ilmu-ilmunya ( wuuiih.. dikira shaolin temple atau kanuragan kali ya ..? ), silahkan ramaikan forumnya di http://it-forum-speedystudent.982588.n3.nabble.com/ . Jadilah yang pertama posting new topic disitu. Postingannya boleh seputar internet, telpon, komputer, info kota masing-masing, kuliner, jual-beli, film, manga, anime, blogging, hacking, cracking, networking, dan lain-lain. http://warungflash.com/wp-includes/images/smilies/101_.gif

Baca juga

Cari Blog Ini

Sms-online gratis

Link Excharge
 
Powered by Blogger