Monday, 25 March 2013

Best Free SEO Tools and Website for 2013|| Mukesh Joon

Joon Hospital | 9:30:00 am | 4 Comments so far
Best Free SEO Tools and Website for 2013! Learn how to rank in Google Search Engine Free!
Before starting out your internet business, there are tools that you can’t do without. This SEO TOOLS are a must have for serious internet marketers. And luckly we have lots of free Seo tools available for anyone willing to make his/her online business easier.
What this tools does is, show us how to improve your Search engine ranking, and if you agree with me. If you don’t have plans for ranking your website, there is no way you can Make Money Online.
You might see lots of Websites selling different cheap backlinks services, and they have bootload of clients because, without ranking your website, nobody will see that great product of yours, nobody will read that great article of yours.
And seeing that google are always doing one update and another every single month, you need to learn how to protect your website from getting sandboxed, the best backlinks services to use that is panda and Penguin tested. Many more tips will be shared here.
This are the Free Seo tools available for anybody starting out internet marketing, learn how to use them gradually and then master them fully. This tools will show you how to improve your website ranking.
* PINGDEVICE
http://pingdevice.com I use pingdevice to automatically ping my new articles and get them index in google instantly! There are lots of different pinging services/websites, but i prefer this one, because it also ping in other ping websites like Pingomatic.
* BROWSERSHOTS
http://browsershots.org
I personally use this website for testing different browsers, which will make your google analytics look like you recieved 150 visitors that day.
* BROKEN LINK CHECKER
http://www.brokenlinkcheck.com
I use this tool once every month to check all my websites for broken links.
* SEMRUSH
www.semrush.com — Though the free searches are quite limited. It is an Easy way to find out your competitors longtail keywords and estimated organic traffic they are generating. Semrush is a good tool for evaluating CPC in a niche before getting started in it by querying the main authority site. It is a must have tool for any serious Internet guru
* Google Alerts
http://www.google.com/alerts — Lots of people don’t make use of this tool, but it is one of the great to track most recent information in your Niche, you can use it to set up an email alert everyday to tell you the most recent information on “make money online products” (assuming your niche is make money online) this will help you to write a quick fresh content and bank on it.
You can as well use google alert to see who is talking about your site, your name, your brand, all you need to do is just type in your company or site name.Example: “makemoneyonlinefreehq.com” and find out when someone talks about your site or company.
* Google Insights
http://www.google.com/insights/search/ — another best tool from google, to use this site, Just Log in and type in your niches keyword to find out the popularity overtime.
* Google Analytics
http://www.google.com/analytics/ — I personally use this tool to see who is coming to my site and where my traffic are comes from. Though there are different other use for this tool.
* Google Webmaster tools http://www.google.com/webmasters/ — This tool is use to set up sitemaps, some experts said it enable them index their site quicker, it is also use to track errors, know when you have the google penalty. etc.
* YouTube
Youtube.com — This is a great tool for creating video tutorials for your products, if don’t know how to create one, you can hire people from fiverr to do it for you. This is a very useful tool for finding help on some softwares that are broken down step by step.
* Google Adwords
https://adwords.google.co.uk — You can get free good adword vouchers in PC magazines and use them to advertise for free. You can get about £50 per voucher
* Google Keywords Tool
https://adwords.google.co.uk — A reliable tool to research Keywords, find out how valueable niches are, how many people are interested in your search, how many local search it has a month, how many global search a month, and how much is the CPC. This tool is a must have. Remember to always tick the exact box when using google keyword tool.
* KeywordSpy
www.keywordspy.com– spy on other people keywords, know what your competitors are ranking for and improved your website ranking.
* BacklinkWatch
www.Backlinkwatch.com — This will show you how many backlinks a url has, use it to analyse your competitors backlinks.
* iBackLinkPro
http://www.ibacklinkpro.com/ — iBackLinkPro will gives you 100 results per day, what i do is to use this site to review my competitor backlinks, It will help me find out the sites they are posting on and also get backlinks from there! This will allow you to see the kind of backlinks your competitors are building and know why the ranking above you, you can start taking action to beat them to their game!
* aherfs
https://ahrefs.com/ — This is almost the same as iBackLinkPro but it gives about 500 results per day. A very very useful tool for webmasters.
* MajesticSeo
https://www.majesticseo.com/ — This tool is what I use to review my backlinks and my competitor backlinks, though it required a free account, all you need do is sign up.
* OnlyWire
https://www.onlywire.com/ — This website will give you Free account which allows one to have 300 submissions per month, it might takes sometime to set up. But when it done, it allow you to add your web2.0′s, onlywire allows you to post to 46 accounts all at the same time! A superb tool to boost your online presence.
* Flickr Creative Commons
http://www.flickr.com/creativecommons/by-2.0/ — Are you looking for legal images to you use on your website? Then this tool is all you need. You are legally allowed to use the images on your sites as long as you give appropriate link back to the photographer, what you need to do is to simply save the image, post it to your website and then put a copyright under the image with the users Flickr id. Done, you won’t get any DMCA notice whatever.
* UberSuggest
http://www.ubersuggest.org — I mainly use this tool to get tons of tags to use on my new post, and it also give us broad keywords about my niche. It is also a great tool which allow you to see what normal users are searching on the different search engines around. Example of it is shown below. Putting the keyword “Make Money Online”
I get the following keywords users are using to find make money online sites
By putting this keywords into Google Keyword tool above, i will be able to see how users are searching for that particular keyword per month, and you can know your longtail keyword to target as well. The list is given from ubersuggest is pretty long. I only put a very little part here.
Go and see how to use this to earn some huge money this coming christmas! You can use it to search for shopping keywords “buying keywords” and know what to target.
I have listed THE BEST FREE SEO TOOLS FOR 2013/2014 and i expect anyone reading this, to become an expert in the nearest future.
Read more ...

Top 5 Pentration Testing Operating System’s Based On Linux|| Mukesh Joon

Joon Hospital | 4:20:00 am | Be the first to comment!
If you are in search of good  Pentration Testing operating system then you are at right place because in this post I am going to introduce you with Top 5 penetration testing Operating System’s Based On Linux. First of all i want to tell you something about Penetration Testing :
” It is that process in which an individual/professional can evaluate the security of a computer system  or network by applying the attacks. These professionals have legal rights to do this task as their purpose is only to examine the network security instead of doing any harm.”
Most of you have heard the name of Backtrack, it is one of the most popular Penetration Testing Linux based Os. But here i am going to tell you rest four penetration testing distro which i found very useful during my experiments. Backtrack is very successful Penetration Testing Os because it has all the tools which is mostly required by a Professional and it makes a revolutionary change in the field of penetration testing.
According to me right judgement of Penetration Testing Os is based on tools available in it. No matter, what the Os watch rank said about them. It depends on the user how much they get from them. Don’t go with name just evaluate the features and tools available in the distro.

List Of Top 5 Pentration Testing Operating System’s Based On Linux


1. Backtrack Or Kali Linux : 

Backtrack is most popular among professionals as well as learner. This Os has the ultimate collection of Penetration testing tools. It is based on debian linux based distribution and primarily aimed at digital forensics and penetration testing. The tools in this distribution are sub divided into modules, each modules have different types of tool but some of them have common like nmap. i have listed the modules available in backtrack in below given points :-
  • Information Gathering
  • Vulnerability assessment
  • Exploitation tools
  • Privilege Escalation
  • Maintaining access
  • Reverse Engineering
  • RFID tools
  • Stress Testing
  • Forensics
  • Reporting tools
Backtrack and Kali Linux both are available in two Desktop flavor i.e KDE and GNOME. I will recommend you to use GNOME because it is lighter than KDE environment.
  • Download Backtrack 5R3 from here HERE and Download Kali Linux from HERE

2. BackBox

Backbox is second most popular distribution for penetration testing and security assessment. It is based on Ubuntu Linux-based distribution which has set of tools required for ethical hacking and security testing. It is designed to be fast and easy to use which includes its own software repository for downloading the required packages. Like Backtrack it is also divided in to modules which helps you to choose the right tool for performing  your task. But then also it is not as powerful as Backtrack because  stress testing tools are still missing from this.
  • Download BackBox from HERE

3. Blackbuntu

Blackbuntu is developed by small team  from Thailand, India, Turkey, USA., U.K., Canada, Ireland, Saudi Arabia, Brazil, Syria, Russia. It is also a very powerful environment for penetration testing based on ubuntu. It is designed for security training  students for learning the Ethical Hacking and Information Security.
  • Download Blackbuntu from HERE

6. Knoppix (Security Tool Distribution) 

Knoppix STD (security tool distribution ) is live Linux distro which is used to penetrate the network for ethical purpose. It is designed by a community whose prime motto is to manage the security insted of hacking. This distribution is consist of mostly used open source tools which helps you to perform security assessment on network. It is specially designed to aid the network administrators and security professionals.
  • Download Knoppix STD from HERE

5.  NST (Network Security Toolkit)

Network security toolkit is also a live distribution based on fedora. Similarly like other distro it is designed for security assessment of a computer system or network. The main intent  of developing this distro is to provide the network security administrator with a set of opensource tools to penetrate the network for managing the best security of network. Top 125 security tools are included in this toolkit provided by INSURE.ORG

Download NST from HERE
Enhanced by Zemanta
Read more ...

Sunday, 24 March 2013

Installing Zemanta on Blogger - A New Way to create Blog Posts! || Mukesh Joon

Joon Hospital | 10:52:00 am | Be the first to comment!
Creating quality content is a major concern for bloggers. It is one thing to establish a good-looking and well-optimized website which is SEO friendly, and quite another to update it with fresh, regular content which is of high quality. No matter how well a site is optimized for search engines, content still remains the king, and Google regards content more highly, since it is oriented towards the users more. Creating quality content, and adding value to it isn't an easy job. But don't worry! People who use Google Blogger now have access to an amazing tool, Zemanta, which will help them create quality content, and spice it up with images, links, and more!

What makes a great blog post?

When people ask me how they can create 'quality blog posts', I usually tell them to first overview their own posts from an outsider's perspective. Forget the person who wrote the post, and become the person who'd love to find anything wrong with the post so that he could fire the guy who wrote it. This kind of self-criticism often proves to be constructive, and makes you see your posts in a better light.
Now the writing part of the blog post itself cannot be imposed on anyone, because not everybody has the knack for writing proficiently, not at the start anyway. So instead, we advise people to focus on the visuals. When you take a glance at a blog post, you generally analyze the structure of the content. One of the most important thing to consider here is visual aids. Adding images can be the key to any post's success, since they add colors and graphics which attract readers.
Besides images, there are a few more things that matter within a blog post, such as authority links, further resources, and so on. In other words, working on building trust. Well, as it turns out, this sort of work is right up Zemanta's alley.

Zemanta?

Zemanta is a free editorial service that will help you build upon your blog post, and add more value to it by helping with images, tags, links, and more. It has just been integrated with Blogger, so Blogger users can easily use this to improve the quality of their blog posts!
Zemanta can help you with;
  • Images - This is a real time-saver! While you are writing your post, you can see image suggestions appear right on your sidebar. You can choose them at any post, and insert them into your post with a single click! Additionally, you can quickly insert your Instagram and Flickr photos too.

 


  • Tags - With Zemanta, you can easily tag your posts with Labels. Zemanta will make the process much easier, and bring your site closer to search engines as well.
  • In-text links - This is another perk I was really looking forward to. Zemanta will automatically (or to quote Zemanta, "automagically") link keywords to relevant sources. This will hopefully help readers who aren't clear about a term, and want to find out more about it.
  • Related Articles - Here's another potential gold mine. You can use this tool to link to your old articles, as well as to link to articles from the blogosphere. This way, you will relate to posts from other bloggers, and other bloggers will relate to posts from you. Hence, an effective linking scheme that could benefit both parties.

How to get Zemanta?

Zemanta is pretty easy to install. And since it's free, there's no hassle about it. Best of all, it is available for most popular browsers, since it is a browser extension. You can get this plugin from its host website. Simply click on the browser icon that you use, and follow the on-screen instructions.
For example, to install to Chrome, simply follow this download link. Click on the Add to Chrome button at the top, and this extension will be installed in seconds! Similarly, for FireFox, all you need to do is go to the download site, and click on Continue to download. The extension will then take no time to download and install!
Pretty cool, huh? This plugin could really save time, and help with productivity. What do you guys think? Leave your interesting responses below. Peace :)
Read more ...

How to Make Blog Fast and Faster

Joon Hospital | 10:06:00 am | Be the first to comment!
Hi, friends! Advance, I've posted about a trick to solve How to Make Blog Fast. That's Boost Blog Speed with CSS Compressor. But, now I will discuss some problems to makeblogger faster. Who don't want their blog become light, surely all of bloggers want it because our visitors can browse our blog easier.

Based on my experience, there are some tricks to make blog fast :


  • Picture
  • Did you know, pictures with large size can make our blog become slower. So, it's better for you to decrease the use large-size picture. Both in template and also posts. You can use Photoshop Save for Web & Device trick.
  • Widget
  • Over usage widget was one of problems which makes blog become slower. Especially if the widget contains heavy scripts. It's good for you to delete some widgets which unuseful such as clock, music player, pet, games, and so on. Use useful widget such as related postmost popular article , or may be Google Friend Connect
most popular articles, or maybe Google Friend Connect.
  • CSS and Javascript
  • As we knew, CSS and javascipt can make our blog become good looking. But the side effect is it can make our blog become slowly. So you should decrease the usage or compress it for your blog. To compress Javascript, you can use Javascript Compressor.

Epilog How to Make Blog Fast and Faster: I think good blog should have a good looking and fast loading. But, don't reduce your creativity on blog. Stay blogging!
Read more ...

Sunday, 17 March 2013

Five way to create a new website || Mukesh Joon

Joon Hospital | 12:28:00 am | Be the first to comment!
Now a days making website is getting more as we all know that by website also we can earn. For this we should not have any kind of the programming knowledge nor we have to invest any thing. These all can be done for free...
There are many website that provide service to make your own free website. By using these services you can make your own website and start earning. For this there are three things are must as i know.. Domain, Quality content and Traffic.
If you have all the three thing above that you can earn a good amount. There are many of the people who are earning through the site or blogs. Blogs and site are two different and I will discuss this later on.
Here I will discuss about the website that gives you to make your free website in a simple steps.

1) DOODI.ME


Doodi.me is one of the site that helps you to make your own site in a very simply steps. The main thing of this site is that it allows the users to make the domain name of their own name. Additionally it give the facility of automatic optimization of your site for tablet or mobiles. It also provides the live preview of the site while designing the site. After this you can take a view on your site visitors. You can directly share the site on the social networks.

2) FLAVORS.Me


If you want to make your site colorful, then Flavors.me is the best option for you. Flavors.me allows anyone to create an elegant website using personal content from around the internet. It have many additional feature as like- you can change the layout of the home page. organised your own content and also add the visual effects to your own content. You can connect five social networks accounts with free account of flavors. I also have premium account, on which there are many additional features like, multiple design, unlimited services, mobile optimization services. You can also make the visitors contact forum on this.

3) FOLLR.COM


Follr.com is little bit different for the other sites. Here you can make your own virtual visiting cards. On which you can add details of the social networks, skills, work experience and also a option to add the contact details. It have the facility to get automatic update from the social networks. Additionally, it also have the mini social network site, by which you can connect the users.

4) WEEBLY.COM


weebly is another better option to make a website. Before signing up on weebly, first it will ask what you want to make. A Forum, Blog or a Portfolio site. In you can use the sub-domain provided by the weebly for you site address or buy a new one as you like(if available). There are many of the pre-installed tools to design a site. Here first you can select the theme of the site and then do further design of your site. It also have the drag and drop facility.

5) WIX.COM


If you want some creative and a rich designing site then wix.com will the better option. This is also a free site to make your own website. Here you can use website template as you want. There are many templates on its template gallery. You can also edit the template as you want. For editing there is HTML editor present on it, and to you this you don't have to learn HTML program also. After there designing of the site you can publish your site live in just a seconds. You can also make your own name sub-domain.
Read more ...

Saturday, 23 February 2013

Top 10 Programming language | Power of Linux: | Mukesh Joon

Joon Hospital | 10:17:00 am | 1 Comment so far


Top - 10 Programming language currently Used

1. Java – 35.7%
2. C, C++ – 15.3%
3. C# – 12.7% 4. Perl – 11.9%
5. JavaScript – 10.9%
6. Visual Basic .NET – 5.2%
7. PHP – 2.9%
8. Ajax – 2.7%
9. Python – 2.0% 10. Ruby – 0.7%
*********************
*********************
*********************

Power of Linux:

1. Google, Facebook, Twitter and
Amazon are all powered by Linux.
2. 850,000 Android devices are
activated every single day, all
running Linux. That means 100
Android devices have come online
since you started reading this
post, all running Linux.
3. 700,000 TVs are sold everyday
most of which are running Linux.
4. 9 out of 10 world's
supercomputers run Linux.
5. 8 out of 10 financial trades are
powered by Linux.
 
Read more ...

Friday, 25 January 2013

Ten Tips To Become A Social Media Expert || Mukesh Joon

Joon Hospital | 8:30:00 pm | Be the first to comment!

Top 10 Tips on How to Become a Social Media Expert:

  1. Peruse what the entire planet is perusing about Social Media by way of books, magazines, blogs/sites, TV and so on. 
  2. Retweet things around you and constantly answer and listen to the people.
  3. Always Join Popular Events and teach people.
  4. Study the criticalness of Social Media in the eyes of Search motors and Know How to Promote it intelligently? 
  5. Learn from your past mistakes and Never surrender. Always do new experiments and do new things.
  6. Invest the vast majority of your chance on Social Media destinations talking with associates, overhauling your particular profiles, making blanket pics, uniting groups and whatnot. 
  7. Interface with an increasing amount People making inquiries, giving unlimited giveaways and whatnot. 
  8. Compose on Social Media News, Create sites on Social media and in addition advise tips and tricks identified with it. 
  9. Make an inclination of making more Friends connected and logged off as well. Friends are the best for promotion.
  10. Revisit Press scope's and webinars.
Note: If  you newbie and don't know how to do all these things and want to do many other things that are not mention here then you can simply hire me for advice.
Read more ...

Tuesday, 13 November 2012

How to Protect Yourself while Hacking || Mukesh Joon

Joon Hospital | 10:15:00 am | 1 Comment so far

First of all lemme tell you all , that while hacking many of hackers don’t protect their privacy. By your this silly mistake. You can be put  behind the bars or Pay fine. When you login into any site , you think that you have hacked and deface it But when you logged in your IP address was stored in the logs. By the logs the admin can able to catch your ip address and give to any Cyber Security team. They will trace your location via IP address and you are BUSTED .

How to prevent your self from being Caught or How to protect yourself while hacking sites

You know that you have to be anonymous while hacking or trying to access any high profile sites. I suggest you to use TOR web browser. It’s same as fire fox but it is connected to TOR network. Which help to surf anonymously in the Internet.


It’s protects your privacy all the time when you are using it. Its is free software to protect your privacy. It has about 60+ countries ip address to choose. Very easy to use. You can choose settings like you wanted.

So here my article ended and I hope it was useful. :D

Download TOR :- Click here

SO STAY PROTECTED  AND SURF ANONYMOUSLY.

If you like the article then don’t forget to share it ;)

 
Read more ...

Saturday, 20 October 2012

Simple 5 Steps The Police Will Find "Anonymous" on FACEBOOK And Get him/her || Mukesh Joon

Joon Hospital | 8:32:00 am | 2 Comments so far

We All Know Most Of You Have Fake Accounts Pretending To Be This Weird Guy ;)


I often see these kind of messages, Someone calling you/your friends “fat” and “racist”? huh! ;)

It’s the Internet, the most public of public places. It’s completely your fault for adding some “random dude” that you don’t know.;)

This is how they will get you.

;)




1. First you got to find out the IP address of that User. So we will be using “netstat” command in windows (its been the simplest like forever). If you want to know the IP address of a specific person on facebook or orkut or any chat service, there is only one way: Just invite or ping him for a chat and while chat is ON open ‘Command Prompt‘ on your PC (Start >Run>cmd).

;)

[note: Before trying this make sure you close all the other tabs in your browser and only facebook is open. also if possible delete all the history and cache from your browser]


2. Type the following command and hit Enter after opening the cmd

netstat -an

;)

3.After typing this command above, you will get all established connections IP addresses there. Note down all the suspicious IP’s

:D

(The police are closer)


4. The Next Step is to Trace that user using his IP address. To do so we will be using IP tracer service. Go to the below address and paste the IP address in the box that says “lookup this ip or website”. and it will show you the location of the user.


http://www.ip-adress.com/ip_tracer/ :)


5. It will show you all the information about that user along with his ISP and a Location in the MAP. Now in the MAP Just click on “click for big ip address location” in the big picture you can actually zoom in. and try to recognize the area. If any serious matter just note down the ISP details in that page and contact them about the IP. they will respond you. :)



>>>The police will be at your door within no time<<<

:D

Solution: Always use private browsing option on your browser but you can still be traced when using powerful ip port scan softwares on Linux.

:D

Read more ...

Wednesday, 12 September 2012

Sixteen Ways How To Secure Your E-mail ID || Mukesh Joon

Joon Hospital | 8:36:00 am | Be the first to comment!

Hello Friends Now We Can Discuss About How To Secure Our E-mail account.........



1------ Apply Double Verification Method on your gmail account.

2------ Chose a secure security question .

3------ Choose an strong password like as Ranbir@Kapoor now we can say dat type of passwordis known as a strong password .

4------ Prevent yourcomputer from trozon and virus... trozan and virus are the malysious activity which transfer your system information to the attacker.

5------In your computer we can use idps (intrusion detection &prevention  system)& firewall &update anti-virus.

6------Prevent your yahoo account from cookie grabbing .....basically some people create FACEBOOK account from yahoo account ...&due to cookie grabbing .

7------Basically use an secure operating system like as linux is the most secure operating system so frenz use only trusted and secure operating system .for example some-times we use window addition .... the xp-addition has many big vulnerability so use only trusted computer .

8------Convert password in the encrypted form ......which provide us more security .

9------ Safe your public ip address .........&prevent your system from metasploit .

10----- Use only trusted Application :) :D

Simple to implement, these tips can be a good start to making sure your e-mail communication becomes more secure.



11.------ Understand that no e-mail communication is 100% secure. We can do our best to make the percentage close to that, but sometimes - if the information is extremely important - you should consider ditching the e-mail option and deliver it in person (if possible). Avoid sending credit card or social security numbers via e-mail. It's also a good idea not to send user names and passwords for accounts you don't want to see compromised.


12.------ The more your e-mail is present in the confines of the cyberworld, the more spam you'll be likely to receive. Unfortunately, even if you're careful with disclosing your e-mail, chances are people will include you in mass mailings and you eventually your e-mail will be out there. To counteract this, you should definitely set up filters and rules. They will not catch every unwanted e-mail, but they will reduce their number. This is not just a matter of annoyance - basic users and novices are more susceptible to spam and scams. So why give the bad guys the possibility of trying out their angle?

 

 13.------ Tied to the previous advice is this one: choose plain text over full HTML or XHTML rendition to reduce the risk of being targeted by a phishing attack.

14.----- Don't open attachments unless you know who it's coming from and you trust them.15. Use encryption. Check with your ISP to see if they encrypt the authentication process. Encrypt your email message if possible. Are you familiar with the concept of steganography? You can hide messages in images, articles, shopping lists... Ideally, you can use both - first encrypt the message, then use a steganography software to embed it in a recent photograph. There are simple tools out there.


15.------ Don't access your e-mail from an unsecured network or potentially compromised computers. Yes, that particularly includes access from an Internet cafe. There be keyloggers.


16.----- Teach everybody who wants to know about it, especially your children (AND especially if you're using the same computer). 

Be aware of both your virtual and physical surroundings when communicating via e-mail. Be careful. Trust no one that you do not absolutely have to trust, and recognize the dangers and potential consequences of that trust.


Your e-mail security does not just affect you; it affects others, as well, if your e-mail account is compromised. Even if the e-mail account itself is not compromised, your computer may be if you do not take reasonable care with how you deal with e-mails — and that, in turn, can lead to affecting both you and others adversely as well.
Don’t be a victim.

 

 

Read more ...

Friday, 7 September 2012

Mukesh Joon | Intrusion Detection FAQ: What Are The Top Selling IDS/IPS and What Differentiates Them from Each Other?

Joon Hospital | 10:03:00 am | Be the first to comment!

-------&&&&&****Intrusion Detection FAQ: What Are The Top Selling IDS/IPS and What Differentiates Them from Each Other?  :) :D :P ****-------&&&&&


Selecting an Intrusion Prevention System (IPS) can be a daunting task. While an independent assessment of available solutions is strongly recommended as a best practice before procurement and deployment, a good place to start a research effort is to look at the market leaders and to compare their offerings.
According to Infonetics Research, Cisco ranked highest among six top selling IPS solution providers -- the other five suppliers being McAfee, Juniper, IBM, Sourcefire and TippingPoint -- based on assessments performed by large organizations on eight selection criteria, ranging from value and pricing to technology and the product's roadmap for the future. These same six providers also rank highest in terms of their effectiveness on the latest Gartner report, although CIsco and IBM are considered to be challengers to the market led by the other four vendors.
As IPS systems have evolved in time and grown in maturity, several traits are shared by the various offerings, the primary one being the successful migration from passive IDS monitoring systems to active in-line/in-band IPS choke points. This type of "pre-patch shield" provided by modern IPS systems is a feature made possible from its perimeter location; the vendor's frequent database updates gives their clients network-level protection while they work out a patching and hardening strategy on their internal production nodes. Other improvements generally found in today's IPS systems include attack recognition beyond simple signature matching, dropping of malicious sessions as opposed to simple resetting of connections, and the deployment of dedicated hardware that can operate at "wire speeds".
Cisco has several IPS solution offerings, which can be implemented via its IPS Sensor Software as well as through hardware (with physical add-on modules). A component of the Cisco Self-Defending Network, the Cisco IPS 4200 Series Sensors provide protection against worms, Trojans and exploits against application & operating system vulnerabilities. The IPS 4200 series filters for over 300 signatures and has 30 detection engines, providing protection for over 30,000 known threats. On top of standard signature-base matching capabilities, a globally-managed "reputation analysis" feature can push updates to client systems in a matter of minutes. Adopting a Cisco solution would certainly be attractive to those organizations that exclusively deploy and maintain Cisco network equipment; Cisco IPS solutions can be integrated and managed using existing Cisco network management systems.
IBM, through its acquisition of IDS pioneer Internet Security Systems, inherits a robust inspection engine and deploys their Proventia IPS solution in a variety of deliverables including dedicated hardware. At the core is a "security convergence" strategy that is engineered to provide protection for the wide range of threats that exist today, from web-based attacks to insider threats to standard malware protection, through a single consolidated solution. A key feature is the IBM Protocol Analysis Module (PAM) that supports a deep packet inspection capability. A scaleable solution through its modular product architecture, additional protection modules can be introduced as new threats emerge. Their X-Force research and development team provides 24/7 monitoring of ongoing threat levels in order to provide their customers with prompt updates to their IPS solutions.
Juniper Networks also maintains a portfolio of IPS solutions, ranging from standalone systems to integrated all-in-one security solutions. The Juniper IPS is Implemented as an application that can run collocated with other perimeter functions such as firewalls and rate limiters. Strengths in this solution include a highly-granular Role Based Access Control implementation for administration, a communications protocol validation capability performed against published RFCs, and selective contextual screening of network traffic. Its evolution from Netscreen acquirer to the developer of their next-generation JUNOS platform has helped them maintain their market share in the IDS/IPS market.
McAfee's acquisition of IntruShield makes them a player in the IPS marketplace with the rebranded McAfee Network Security Platform (NSP), also offered in various packages from all-in-one to dedicated solutions. NSP is the only IPS appliance that has the NSS Group's Multi-Gigabit IPS certification, and it supports integration to the McAfee Vulnerability Manager and ePolicy Orchestrator, a management platform that pushes down policy to managed nodes and systems. Centralized management of IPS nodes and policies is implemented through the McAfee Network Security Manager system, a separate appliance that implements a scaleable and intuitive management system that can support up to 1000 sensors.
Sourcefire is perhaps best known as the commercial arm of the Snort IDS project. The product's intrusion detection and protection engine is well-known in the security community due to its maturity and its open-source accessibility to students, although the learning curve associated with this type of offering is considered to be high. The Sourcefire RNA feature recommends which rules to implement based on the type of network being protected. The Sourcefire Vulnerability Research Team (VRT) is complemented by the open source community to provide and maintain updates to the configurations of their product line, which includes hardware and software solutions built on the Snort core. Snort is a highly configurable and expandable IDS/IPS solution, with its rule set built from a library of 14,000 rules that can be readily adapted and expanded by individual security administrators.
TippingPoint, acquired by 3Com in 2005, is a major player in the IPS market, and enjoys a significant market share. Also provided in a variety of flavours, it is able to provide zero-day protection capabilities due to its relationship with an army of independent researchers. Built upon their Threat Suppression Engine (TSE) with custom ASICs at the core, the TippingPoint IPS provides a high-performance solution that can efficiently scan packets at Layers 2-7 of the OSI model. Their research team pushes out emergency updates on top of standard updates twice a week; their Digital Vaccine service delivers filters that are designed to block multiple attack types that can be associated with new exploits. The product line's default settings provide a ready-to-use policy set to greatly facilitate initial commissioning.
Resources:
NIST Special Publication 800-94: Guide to Intrusion Detection and Prevention Systems (IDPS) http://csrc.nist.gov/publications/nistpubs/800-94/SP800-94.pdf
Cisco, McAfee, Juniper top IPS vendors http://www.ciol.com/Technology/Security/News-Reports/Cisco,-McAfee,-Juniper-top-IPS-vendors/16909125093/0/
Cisco, McAfee, and Juniper top intrusion prevention vendor ratings by enterprise IPS users http://www.infonetics.com/pr/2009/User-Plans-Intrusion-Prevention-Systems-Study-Highlights.asp
Magic Quadrant for Network Intrusion Prevention System Appliances http://www.sourcefire.com/products/sfsem/gartnerMQ?semg=USGTR1
Cisco Intrusion Prevention System http://www.cisco.com/en/US/products/sw/secursw/ps2113/index.html
Cisco IPS 4200 Series Sensors http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/index.html
IBM - Proventia Network Intrusion Protection Systems (IPS) http://www-935.ibm.com/services/us/index.wss/offerfamily/iss/a1030570
IBM Proventia Network Intrusion Protection System ftp://ftp.software.ibm.com/common/ssi/pm/sp/n/sed03056usen/SED03056USEN.PDF
Juniper Networks: Intrusion Prevention System (IPS) http://www.juniper.net/us/en/products-services/software/ise-applications/ips/
McAfee Network Security Platform http://www.mcafee.com/us/enterprise/products/network_security/network_security_platform.html
Snort
Sourcefire Intrusion Prevention Systems (IPS)
Sourcefire Vulnerability Research Team (VRT)
TippingPoint Intrusion Prevention Systems
Read more ...

IDS&IPS | Mukesh Joon

Joon Hospital | 9:47:00 am | Be the first to comment!

IDS & IPS

An intrusion detection system (IDS) is software and/or hardware based system that monitors network traffic and monitors for suspicious activity and alerts the system or network administrator. In some cases the IDS may also respond to anomalous or malicious traffic by taking action such as blocking the user or source IP address from accessing the network.

Typical locations for an intrusion detection system is as shown in the following figure -

ids


Following are the types of intrusion detection systems :-

1) Host-Based Intrusion Detection System (HIDS) :- Host-based intrusion detection systems or HIDS are installed as agents on a host. These intrusion detection systems can look into system and application log files to detect any intruder activity.

2) Network-Based Intrusion Detection System (NIDS) :- These IDSs detect attacks by capturing and analyzing network packets. Listening on a network segment or switch, one network-based IDS can monitor the network traffic affecting multiple hosts that are connected to the network segment, thereby protecting those hosts. Network-based IDSs often consist of a set of single-purpose sensors or hosts placed at various points in a network. These units monitor network traffic, performing local analysis of that traffic and reporting attacks to a central management console.

Some important topics comes under intrusion detection are as follows :-

1) Signatures - Signature is the pattern that you look for inside a data packet. A signature is used to detect one or multiple types of attacks. For example, the presence of “scripts/iisadmin” in a packet going to your web server may indicate an intruder activity. Signatures may be present in different parts of a data packet depending upon the nature of the attack.

2) Alerts - Alerts are any sort of user notification of an intruder activity. When an IDS detects an intruder, it has to inform security administrator about this using alerts. Alerts may be in the form of pop-up windows, logging to a console, sending e-mail and so on. Alerts are also stored in log files or databases where they can be viewed later on by security experts.

3) Logs - The log messages are usually saved in file.Log messages can be saved either in text or binary format.

4) False Alarms - False alarms are alerts generated due to an indication that is not an intruder activity. For example, misconfigured internal hosts may sometimes broadcast messages that trigger a rule resulting in generation of a false alert. Some routers, like Linksys home routers, generate lots of UPnP related alerts. To avoid false alarms, you have to modify and tune different default rules. In some cases you may need to disable some of the rules to avoid false alarms.

5) Sensor - The machine on which an intrusion detection system is running is also called the sensor in the literature because it is used to “sense” the network.

Snort :- Snort is a very flexible network intrusion detection system that has a large set of pre-configured rules. Snort also allows you to write your own rule set. There are several mailing lists on the internet where people share new snort rules that can counter the latest attacks.

Snort is a modern security application that can perform the following three functions :

* It can serve as a packet sniffer.
* It can work as a packet logger.
* It can work as a Network-Based Intrusion Detection System (NIDS).

Further details and downloads can be obtained from it's home- http://www.snort.org
Read more ...

DOS(Deniel Of Services) Attack | Mukesh Joon

Joon Hospital | 9:37:00 am | Be the first to comment!




            

-: Denial Of Service (DoS) Attacks :-


A denial of service (DoS) attack is an attack that clogs up so much memory on the target system that it can not serve it's users, or it causes the target system to crash, reboot, or otherwise deny services to legitimate users.There are several different kinds of dos attacks as discussed below:-

1) Ping Of Death :- The ping of death attack sends oversized ICMP datagrams (encapsulated in IP packets) to the victim.The Ping command makes use of the ICMP echo request and echo reply messages and it's commonly used to determine whether the remote host is alive. In a ping of death attack, however, ping causes the remote system to hang, reboot or crash. To do so the attacker uses, the ping command in conjuction with -l argument (used to specify the size of the packet sent) to ping the target system that exceeds the maximum bytes allowed by TCP/IP (65,536).
example:- c:/>ping -l 65540 hostname
Fortunately, nearly all operating systems these days are not vulnerable to the ping of death attack.

2) Teardrop Attack :- Whenever data is sent over the internet, it is broken into fragments at the source system and reassembled at the destination system. For example you need to send 3,000 bytes of data from one system to another. Rather than sending the entire chunk in asingle packet, the data is broken down into smaller packets as given below:
* packet 1 will carry bytes 1-1000.
* packet 2 will carry bytes 1001-2000.
* packet 3 will carry bytes 2001-3000.
In teardrop attack, however, the data packets sent to the target computer contais bytes that overlaps with each other.
(bytes 1-1500) (bytes 1001-2000) (bytes 1500-2500)
When the target system receives such a series of packets, it can not reassemble the data and therefore will crash, hang, or reboot.
Old Linux systems, Windows NT/95 are vulnerable.

3) SYN - Flood Attack :- In SYN flooding attack, several SYN packets are sent to the target host, all with an invalid source IP address. When the target system receives these SYN packets, it tries to respond to each one with a SYN/ACK packet but as all the source IP addresses are invalid the target system goes into wait state for ACK message to receive from source. Eventually, due to large number of connection requests, the target systems' memory is consumed. In order to actually affect the target system, a large number of SYN packets with invalid IP addresses must be sent.

4) Land Attack :- A land attack is similar to SYN attack, the only difference being that instead of including an invalid IP address, the SYN packet include the IP address of the target sysetm itself. As a result an infinite loop is created within the target system, which ultimately hangs and crashes.Windows NT before Service Pack 4 are vulnerable to this attack.

5) Smurf Attack :- There are 3 players in the smurf attack–the attacker,the intermediary (which can also be a victim) and the victim. In most scenarios the attacker spoofs the IP source address as the IP of the intended victim to the intermediary network broadcast address. Every host on the intermediary network replies, flooding the victim and the intermediary network with network traffic.
Smurf Attack Result:- Performance may be degraded such that the victim, the victim and intermediary networks become congested and unusable, i.e. clogging the network and preventing legitimate users from obtaining network services.

6) UDP - Flood Attack :- Two UDP services: echo (which echos back any character received) and chargen (which generates character) were used in the past for network testing and are enabled by default on most systems. These services can be used to launch a DOS by connecting the chargen to echo ports on the same or another machine and generating large amounts of network traffic.  
 
 
                                                       
Read more ...

XSS(Cross Site Scripting) || Mukesh Joon

Joon Hospital | 9:15:00 am | Be the first to comment!

Basic XSS Cross Site Scripting


Allot of you guys aren't clear with xss aka cross site scripting and for that many of you were sending me mails on how to do xss attack , etc and that's why i got this video which explains some basic concepts of the Xss attack and how it can be practiced and how can we use it to hack anybody.

This video is controversial by Brial Contos, CISSP from a company named IMPERVA. it takes through each and every step involved to find a xss vulnerability in a webpage . and showcases some of the basic steps that you need to know.

What is XSS


Cross-site scripting ('XSS' or 'CSS') is an attack that takes advantage of a Web site vulnerability in which the site displays content that includes un-sanitized user-provided data. For example, an attacker might place a hyperlink with an embedded malicious script into an online discussion forum….

That purpose of the malicious script is to attack other forum users who happen to select the hyperlink. For example it could copy user cookies and then send those cookies to the attacker. The Script Injection video should be watched before this video for greater understanding.


Conclusion

Now you might be clear with xss attacks it is easy and can be used in man terms to hack anybody or anything else for fun also. Now lets take a look at some of the commonly used xss scripts and code snippets -

Assuming you can only fit in a few characters and it filters against ".js" you can rename your JavaScript file to an image as an XSS vector:

This is most simplest snippet used to find a Xss vulnerability in a webpage.

This is a normal XSS JavaScript injection, and most likely to get caught but I suggest trying it first (the quotes are not required in any modern browser so they are omitted here):

There are many more xss vulnerabilities you can use to bypass the security but they are most useful to find a xss vulnerability in webpage.
Read more ...

Friday, 31 August 2012

ThE HaCkEr NeWs || MuKeSh JoOn

Joon Hospital | 10:09:00 am | 2 Comments so far
Read more ...
Twitter Delicious Facebook Digg Stumbleupon Favorites More

Search

Recent Post

Total Pageviews

Join us on Facebook

Blogging Tips via Email

Powered by Blogger.

Translate Your Language

Entri Populer

Twitter Page URL

Facebook Page URL

Blogroll

About