Hack Security Systems ON THE SITE OR Web
15 Ways Hackers Penetrate A Breaking into and System Security On Site Or Web
15 Ways Hackers Penetrate A Breaking into and System Security On Site Or Web
Are you ready buddy pass today-?
Should donk .... Let all current job, yes ...
Well, this time we shared an article on 15 Ways Hackers Penetrate A Breaking into and System Security On Site Or Web, hackers typically perform an action in breaking into a site with various kahlian and creativity hackers. But what they do it-? That is the question.
Well, following 15 Ways Hackers in Membobo System on the Site or the Web:
1. IP Spoofing.
IP spoofing is also known as the Source Address Spoofing, namely forgery attacker's IP address so that the target assumes the attacker's IP address is the IP address of the host in the network instead of the outside network. Suppose the attacker has the IP address type A 66.25.xx.xx when the attacker to attack this type of network that attacked then will assume the attacker's IP is part of their network, eg 192.xx.xx.xx is IP Spoofing C.IP type occurs when an attacker 'outsmart 'packet routing to change the direction of the data or transmission to different destinations. Packet routing is usually transmitted in a transparent and clear so that makes it easy to modify the attacker with data origin or destination of the data. This technique is not only used by the attacker but also used by security professionals to download tracing the identity of the attacker.
2. FTP Attack.
One of the attacks carried out against the File Transfer Protocol is a buffer overflow attacks caused by malformed command. destination FTP server attack is the average is to get a command shell or to perform a Denial of Service. Denial Of Service attacks can eventually lead to a user or attacker to retrieve the resource in the network without authorization, while the command shell can make an attacker to gain access to the server system and data files that ultimately an attacker can make anonymous root acces a right full of the system even network diserang.Tidak never or rarely update the server version and mempatchnya are common mistakes made by an admin and this is what makes the FTP server becomes prone to be entered. An example is a popular FTP servers on UNIX family of WU-FTPD are always in the upgrade twice a day to improve the conditions that allow the FTP exploit bufferoverflow also useful to know the password contained in the system, FTP Bounce attack (using ftp server others to carry out the attack), and knowing or mensniff information in the system.
3. Finger Unix Exploits ..
In the early days of the Internet, Unix OS finger efficient utility used to download information sharing among users. Because the demand for information on this finger information not blame the rules, many system administrators leave this utility (finger) with very minimal security, even without security at all. For an attacker utility is very valuable to have information about footprinting, including login names and information contact.Utility also provides excellent information about user activity within the system, how long a user stays in the system and how far the user take care of the system. The information generated from this finger can minimize the Cracker effort to penetrate a system. Personal information about the user that is raised by the finger daemon is already enough for a atacker to perform social engineering by using social skill to utilize the user to 'tell' passwords and access codes to the system.
4. Flooding & Broadcasting.
An attacker could menguarangi speed networks and hosts that are in it significantly by continuing to perform the request / demand for the information on servers that can handle the classic attack Denial of Service (Dos), send a request to the named port of excessive flooding, sometimes it is also called spraying. When a request is sent to flood all stations in the network attacks dinamakn broadcasting. The purpose of the attack is the same that make network resources that provide information becomes weaker and finally menyerah.Serangan by means Flooding is dependent on two factors: the size and / or volume (size and / or volume). An attacker could cause a Denial of Service by throwing large capacity files or a large volume of small packets to a system. In such circumstances the network server will deal with congestion: too much information requested and not enough power to push the data to run. Basically a large package requires a capacity greater process, but it is not normal and the same small package in a large volume of resources will be spent in vain, and the resulting congestion.
5. Fragmented Packet Attacks.
Internet data is transmitted via TCP / IP can be subdivided into packets containing only the first packet of information contents of the main part (head) of the TCP. Some firewalls will allow to process part of the packages do not contain information on the packet source address first, this will result in some type of system to crash. For example, the NT server will be a crash if the packets are broken up (fragmented packet) enough to rewrite the first packet information of a protocol.
6. E-mail Exploits.
Peng-exploitasian e-mail occur in five types: mail floods, manipulation commands (command manipulation), the attack rate of transport (transport-level attack), enter the various codes (inserting malicious code) and social engineering (utilizing physical socialization). Email attack could cause the system to crash, open and rewrite even execute application files or also make access to command functions (command function).
7. DNS and BIND Vulnerabilities.
Recent news about vulnerabilities (vulnerabilities) on application Berkeley Internet Name Domain (BIND) in various versions illustrate the fragility of the Domain Name System (DNS), which is a crisis that is directed at the basic operation of the Internet (Internet basic operation).
8. Password Attacks.
Password is common when we talk about security. Sometimes a user does not care about the number of pins they have, such as online transaction in the cafe, even transact online at home is very dangerous if not equipped with security software such as SSL and PGP. Password is one procedure that is very difficult to attack, an attacker may just have a lot of tools (in engineering and in social life) just to open something that is protected by password.Ketika an attacker managed to get a password that is owned by a user, then he will have the same power to the user. Train employees / users to remain vigilant in protecting the password of social engineering can at least minimize the risk, in addition to guard against social engineering practice organization must be aware of this by technical means. Most attacks were carried out against the password is guessed (guessing), brute force, cracking and sniffing.
9.Proxy Server Attacks.
One of the functions of proxy servers is to speed up response time by bringing together the process of multiple hosts in a trusted network. In most cases, each host has the power to read and write (read / write) which means that what can I do in my system I can also do in your system and vice versa.
10. Remote Command Processing Attacks
Trusted Relationship between two or more hosts to provide facilities for exchanging information and resource sharing. Similar to a proxy server, trusted relationships give all members the same network access control in one and the other system (the network) .Attacker will attack the server that is a member of the trusted system. Just as the latency to the proxy server, when the access is received, an attacker would have the ability to execute commands and access the data available to other users.
11. Remote File System Attack
Protocols for transport of data -tulang backs of internet- is TCP level (TCPLevel) by a mechanism that has the ability to read / write (read / write) between network and host. The attacker can easily obtain the trace information of this mechanism to gain access to the file directory.
12. Selective insertions Program
Selective Program insertions are attacks carried out when the attacker put destroyer programs, such as viruses, worms and trojans (this term may already know well?) On the target system. Programs crusher is also called malware. These programs have the ability to damage the system, destruction of files, theft of passwords to open a backdoor.
13. Port Scanning
Through port scanning an attacker can see the function and how to survive a system from a variety of ports. A atacker can gain access to the system through a port that is not protected. Sebaia example, scanning can be used to determine where the default SNMP string in the open to the public, which means that information can be extracted for use in remote command attack.
14.TCP / IP Sequence Stealing,
Passive Port Listening and PacketInterception TCP / IP Sequence Stealing, Passive Port Listening and Packet Interception walk to collect sensitive information to access the network. Unlike active attacks and brute-force attacks that use this method has more stealth-like quality.
15. HTTPD Attacks
Vulnerability found in HTTPD webserver or there are five kinds: buffer overflows, httpd bypasses, cross-scripting, web code vulnerabilities, and floods.HTTPD URL Buffer Overflow can occur because the attacker adds errors on the port that is used for web traffic by entering many carackter and string to find a suitable overflow. When a place for overflow was found, an attacker would enter the string that will be a command that can be executed. Buffer-overflow can give the attacker access to the command prompt.
Many of the things we've passed but actually useful and it can change our lives, so let's start from the beginning to fix it.
Okeeh ...
So first post, may be useful.
When was kindly comment below, we are very grateful.
Hehehe ..

Comments
Post a Comment