Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Hacker's Guide to Secure Hacking filter_list
Author
Message
Hacker's Guide to Secure Hacking #1
Network Hacking Group fckD
Version: 0.1
October 2008


The Hacker's RFC


ABSTRACT

This document introduces best practices a computer hacker should
know about and implement for his own safety.


------[ Table of Contents

1 - Introduction

2 - Why this paper?

3 - Selecting a target

4 - Anti-forensics

4.1 - Full disk encryption
4.2 - Virtual Disk/Partition/Drive Encryption
4.3 - Cipher recommendations
4.4 - Encrypted communication
4.5 - Avoid logging
4.6 - Useful tools

5 - Notes on behavior and trust

6 - Keep yourself up to date

7 - Related reading

8 - Final words

------[ 1 - Introduction


This paper focuses on setting up a *secure* computer for real
hacking attacks.


------[ 2 - Selecting a target


When choosing where to hack for fun these are the best practices:

- blacklisting:
* avoid your own country
* avoid good friends of your own country
* avoid countries you may want to go live in
* if you are living within the european union it is preferable
not to hack into countries that are members of the union

- whitelisting:
* select somewhere far like Peru, Chili, Argentina, Aruba, Yemen,
Uruguay, Mongolia, Liberia, Korea, Cambodia, Gabon. An exaustive
list of countries can be found in.
* select countries in a cyber war like Georgia with Russia

Once you have chosen which part of the world to target you could
look at its url country code [1].


------[ 3 - Anti-forensics


This section focuses on setting up a computer *protected* against
forensics investigation(s).


---[ 4.1 - Full disk encryption

Installing a full disk encryption software to protect your files
is highly recommended. There's a list of free and open sources
tools available for you:

windows:
- Truecrypt [2]
- DiskCryptor [19]
linux:
- dm-crypt/Linux Unified Key Setup (LUKS) [3,4,5,6]
- EncFS [9]
- eCryptfs [10]
- Loop-AES [15]
bsd:
- GELI [7,8]
- CGD [16]

note: under linux or bsd remember to also encrypt the swap
partitions.


---[ 4.2 - Virtual Disk/Partition/Drive Encryption

If you need to encrypt a virtual disk a partition or a drive (e.g
usb drive), there's a list of free and open sources tools for you:

windows:
- Truecrypt [2]
- CrossCrypt [17]
- DiskCryptor [19]
- FreeOTFE [21]
linux:
- Truecrypt [2]
- Cryptoloop (Deprecated, known vulnerabilities) [18]
- FreeOTFE [21]
- eCryptfs [10]
- dm-crypt [21]
bsd:
- GBDE [20]


---[ 4.3 - Cipher recommendations

The following table is my personal recommendations when selecting a
cipher algorithm:

+----------------------------------------------------------------+
| PARAMETER | RECOMMENDATION |
+--------------------+-------------------------------------------+
| block cipher | AES, Serpent |
+--------------------+-------------------------------------------+
| symmetric key size | at least 128bits |
+--------------------+-------------------------------------------+
| hash functions [12]| SHA-2 (SHA-224, SHA-256, SHA-384, SHA-512)|
| | Whirlpool |
+--------------------+-------------------------------------------+
| key generation | follow PKCS#5 PBKDF2 [13,14] |
+--------------------+-------------------------------------------+

Cryptography for dummies:
- Ciphers: http://en.wikipedia.org/wiki/Cipher
- Block ciphers: http://en.wikipedia.org/wiki/Block_cipher
- Serpent: http://en.wikipedia.org/wiki/Serpent_%28cipher%29
- Hash function: http://en.wikipedia.org/wiki/Hash_function
- SHA: http://en.wikipedia.org/wiki/SHA_hash_functions
- Whirlpool: http://en.wikipedia.org/wiki/WHIRLPOOL
- Passphrase http://en.wikipedia.org/wiki/Passphrase
- Weak key: http://en.wikipedia.org/wiki/Weak_key
- LinuxCryptofs: http://wiki.boum.org/TechStdOut/LinuxCryptoFS

---[ 4.4 - Encrypted communication

To protect your messaging communications you can use the following
open source and free tools:

- pidgin + pidgin-encryption (pidgin-encrypt.sourceforge.net)
- pidgin + pidgin-otr (pidgin-encrypt.sourceforge.net)
- kopete + kopete-otr (kopete-otr.follefuder.org)
- irssi + irssi-otr (irssi-otr.tuxfamily.org)



---[ 4.5 - Useful tools

Passwords generator:
- makepasswd (linux, bsd)
- PWGen (windows)
- Advanced password generator (windows)
- PC Tools Password Generator (online: http://www.pctools.com/guides/password/

Anti-forensics:
- Timestomp, that allows you to modify all four NTFS timestamp
values modified, accessed, created, and entry modified.
- Slacker, tool that allows you to hide files within the slack
space of the NTFS file system.
- Sam Juicer, a Meterpreter module that dumps the hashes from the
SAM, but does it without ever hitting disk.

Secure file deletion:
- Eraser (windows)
- Evidence eliminator (windows)
- WinClear (windows)
- Window washer (windows)
- shred (linux)
- srm (bsd, linux)
- wipe (linux)


------[ 5 - Keep yourself up to date


It is important to keep yourself updated on what's going on in the
digital forensics world. I recommend following rss feeds of those
sites:
http:// http://www.forensicfocus.com
http:// http://computer.forensikblog.de
http:// http://volatilesystems.blogspot.com
http:// http://www.securiteam.com

Adapt yourself to new forensics techniques and discoveries.


------[ 6 - Related reading


-Anti-Forensics: Techniques, Detection and Countermeasures, http://www.simson.net/ref/2007/slides-ICIW.pdf
-The Computer Forensics Challenge and Anti-Forensics Techniques, http://www.h2hc.com.br/repositorio/2007/montanaro.pdf
-Anti-Forensics,
http://www.youtube.com/watchv=q9VUbiFdx7w

REFERENCES :
-Truecrypt software
http://www.truecrypt.org/
http://www.truecrypt.org/downloads.php
http://www.truecrypt.org/docs/

-Linux Unified Key Setup (LUKS)
http://luks.endorphin.org/
http://www.saout.de/tikiwiki/tiki-index.php?page=LUKS

-EncFS
http://www.arg0.net/encfs

eCryptfs
http://ecryptfs.sourceforge.net/

PKCS #5: Password-Based Cryptography Standard
http://www.rsa.com/rsalabs/node.asp?id=2127

PBKDF2 (Password-Based Key Derivation Function)
http://www.truecrypt.org/docs/pkcs5v2-0.pdf

Loop-Aes
http://loop-aes.sourceforge.net/

CGD
http://www.imrryr.org/%7Eelric/cgd/cgd.pdf

CrossCrypt
http://www.scherrer.cc/crypt/

Cryptoloop
http://www.tldp.org/HOWTO/Cryptoloop-HOWTO/

DiskCryptor
http://freed0m.org/index.php/DiskCryptor_en

dm-crypt
http://www.saout.de/misc/dm-crypt/


I'm not a h4cker :headbash:

Reply

RE: Hacker's Guide to Secure Hacking #2
I live in
Spoiler:
Spoiler:
Spoiler:
Spoiler:
Spoiler:
Cambodia
Am i safe from FBI now??
(This post was last modified: 09-14-2011, 12:50 PM by Azade.)
[Image: dd.png]

Reply

RE: Hacker's Guide to Secure Hacking #3
You are safe if u won't do anything stupid Tongue

Reply