WAZOBIA AFRICA-THE ETHICAL HACKER TRAINING CENTER:

WAZOBIA AFRICA-THE ETHICAL HACKER TRAINING CENTER:
WAZOBIA AFRICA - THE EHTICAL HACKER TRAINING CENTER™, IS A ETHICAL HACKING FIRM,WITH ACCREDITED TRAINING CENTER (ATC) DEDICATED TO IT PROFESSIONALS AND NON-IT PROFESSIONALS WHO DESIRE EDUCATION AND TRAINING REGARDING INFORMATION SECURITY AND MALICIOUS HACKERS.

HACKERS QUOTES

"The only truly secure system is one that is powered off, cast in a block of concrete and sealed in a lead-lined room with armed guards." - Gene Spafford

Social engineering bypasses all technologies, including firewalls." - Kevin Mitnick

"There is no security on this earth, There is only opportunity." - General Douglas MacArthur

ABOUT US

ABOUT US
WAZOBIA AFRICA - THE ETHICAL HACKER™, AN ETHICAL HACKING FIRM, WAS BORN OUT OF THE NEED TO HELP PROTECT OUR BUSINESSES, GOVERNMENT, HEALTHCARE, FINANCIAL AND EDUCATIONAL INSTITUTIONS AND VARIOUS ORGANIZATIONS NATIONWIDE FROM VICIOUS HACKERS. AS CERTIFIED ETHICAL HACKERS, WE EMULATE THE MINDS AND MOTIVES OF MALICIOUS ATTACKERS TO TEST THE SECURITY OF YOUR NETWORK AND YOUR PEOPLE.

BECOME A PARTNER:

(EXPAND YOUR SERVICE OFFERINGS & IMPROVE YOUR BOTTOM LINEOUR RESELLER PARTNERS ARE INCREASING LIKE WILDFIRE).


Why? Because Information Security Is Hot. Everywhere You Turn a Business Has Been Hacked And Corporations, Financial Institutions, Health Care And All Other Industries Are Concerned. Plus, They Have Compliance Auditors Knocking On Their Doors Making Sure Requirements Are Met. Well, If You’Re Secure, You’Re Compliant.
Help Your Clients With Their Security Needs By Adding Our Security Services To Your List Of Service Offerings. You’Ll Not Only Be Seen As Being Proactive About Their Well-Being But Also Set Yourself Apart From The Competition By Adding Services They Lack. Additionally, You Benefit Financially By Adding These Additional Services Without Increasing Overhead And Improving Your Overall Bottom Line.
We’d Love To Talk With You. If You’Re Interested About Partnering And Reselling Our Services, Please Contact our Customer care, or call: +2348167469997.

AYIS HOST

AYIS HOST
AYISHOST IS A UNIQUE, FULLY-AUTOMATED OF THE MOST AFFORDABLE WEB HOSTING AND DOMAIN REGISTRATION PROGRAM WITH SECURE SSL CERTIFICATES, DEVELOPED ENTIRELY BY AYIS GLOBAL LINKS. AYIS GLOBAL WAS ESTABLISHED IN 2010 IN NIGERIA BUT THE AYISHOST PROGRAM ITSELF STARTED IN 2012.

HACKERS CUSTOMER CARE HELPLINES

MANY-MORE LIMITED

MANY-MORE LIMITED
MAJOR DEALERS IN CUSTOM-MADE QUALITY FURNITURE. GET THE BEST OF WORLD-CLASS FURNITURES AT AFFORDABLE PRICE. FOR MORE INFO CALL:+2348165117144

BUYER PROTECTION

BUY AIRTIME ON FACEBOOK,

BUY AIRTIME ON FACEBOOK,
With Social Banking you can now transfer money, purchase airtime, pay bills and check your account balance on Facebook.

HACKER'S FACEBOOK PAGE

HACKERS TRAFFIC


free website counter code

SITE PROTECTION: NO VIRUSES-NO SPYWARE (100% CLEAN)

SCHOOL IN INDIA:

SCHOOL IN INDIA:
MAII IS AN EDUCATIONAL INITIATIVE OF THE MODI GROUP THAT CATAPULTS MANAGEMENT STUDENTS TO GLOBAL PLATFORMS BY OFFERING AMERICAN DEGREES IN INDIA AND TAILOR MADE PROGRAMS UNRAVELING UNIQUE BREADTH OF MANAGEMENT & LEADERSHIP EXPERTISE.
...
free web site traffic and promotion
Protected by Copyscape DMCA Takedown Notice Checker

HACKERS TIME

...

OUR PARTNERS

OUR PARTNERS
FORTINET FORTIGATE® FIREWALL INDIA.

OUR PARTNERS:

OUR PARTNERS:
MCAFEE.

OUR PARTNERS:

OUR PARTNERS:
HP ENTERPRISE SECURITY INDIA.

WAZOBIA AFRICA

WAZOBIA AFRICA
WELCOME TO WAZOBIA AFRICA - THE ETHICAL HACKER

HACKERS TRANSLATION

OUR PARTNERS:

OUR PARTNERS:
CHECKMARX INDIA.

HACKERS SEARCH

OUR PARTNERS:

OUR PARTNERS:
RSA SECURITY PRODUCTS AND SOLUTIONS INDIA.

IP SPOOFING & IP ADDRESS

-: IP Spoofing :-


The term IP (Internet Protocol) address spoofing refers to the creation of IP packets with a forged (spoofed) source IP address with the purpose of concealing the identity of the sender or impersonating another computing system.

Why it works ?
IP-Spoofing works because trusted services only rely on network address based authentication. Since IP is easily duped, address forgery is not difficult.
The main reason is security weakness in the TCP protocol known as sequence number prediction.

How it works ?
To completely understand how ip spoofing can take place, one must examine the structure of the TCP/IP protocol suite. A basic understanding of these headers and network exchanges is crucial to the process.

Internet Protocol (IP) :
It is a network protocol operating at layer 3 (network) of the OSI model. It is a connectionless model, meaning there is no information regarding transaction state, which is used to route packets on a network. Additionally, there is no method in place to ensure that a packet is properly delivered to the destination.
Examining the IP header, we can see that the first 12 bytes (or the top 3 rows of the header) contain various information about the packet. The next 8 bytes (the next 2 rows), however, contains the source and destination IP addresses. Using one of several tools, an attacker can easily modify these addresses – specifically the “source address” field.

Transmission Control Protocol (TCP) :
It is the connection-oriented, reliable transport protocol in the TCP/IP suite. Connection-oriented simply means that the two hosts participating in a discussion must first establish a connection via the 3-way handshake (SYN-SYN/ACK-ACK). Reliability is provided by data sequencing and acknowledgement. TCP assigns sequence numbers to every segment and acknowledges any and all data segments recieved from the other end.

As you can see above, the first 12 bytes of the TCP packet, which contain port and sequencing information.

TCP sequence numbers can simply be thought of as 32-bit counters. They range from 0 to 4,294,967,295. Every byte of data exchanged across a TCP connection (along with certain flags) is sequenced. The sequence number field in the TCP header will contain the sequence number of the *first* byte of data in the TCP segment. The acknowledgement number field in the TCP header holds the value of next *expected* sequence number, and also acknowledges *all* data up through this ACK number minus one.

TCP packets can be manipulated using several packet crafting softwares available on the internet.

The Attack
IP-spoofing consists of several steps. First, the target host is choosen. Next, a pattern of trust is discovered, along with a trusted host. The trusted host is then disabled, and the target's TCP sequence numbers are sampled. The trusted host is impersonated, the sequence numbers guessed, and a connection attempt is made to a service that only requires address-based authentication. If successful, the attacker executes a simple command to leave a backdoor.

Spoofing can be implemented by different ways as given below -

Non-Blind Spoofing :- This type of attack takes place when the attacker is on the same subnet as the victim. The sequence and acknowledgement numbers can be sniffed, eliminating the potential difficulty of calculating them accurately.

Blind Spoofing :- Here the sequence and acknowledgement numbers are unreachable. In order to circumvent this, several packets are sent to the target machine in order to sample sequence numbers.

Both types of spoofing are forms of a common security violation known as a Man In The Middle Attack. In these attacks, a malicious party intercepts a legitimate communication between two friendly parties. The malicious host then controls the flow of communication and can eliminate or alter the information sent by one of the original participants without the knowledge of either the original sender or the recipient. In this way, an attacker can fool a victim into disclosing confidential information by “spoofing” the identity of the original sender, who is presumably trusted by the recipient.

IP spoofing is almost always used in what is currently one of the most difficult attacks to defend against – Denial of Service attacks, or DoS.

CounterMeasures
1) Filtering at the Router :- Implementing ingress and egress filtering on your border routers is a great place to start your spoofing defense. You will need to implement an ACL (access control list)

2) Encryption and Authentication :- Implementing encryption and authentication will also reduce spoofing threats. Both of these features are included in Ipv6, which will eliminate current spoofing threats.


-: IP Address :-


Definition :-
"An Internet Protocol (IP) address is a numerical identification (logical address) that is assigned to devices participating in a computer network utilizing the Internet Protocol for communication between its nodes".   -- Wikipedia

The Internet Protocol (IP) has two versions currently in use which are IPv4 and IPv6.
This article represents to IPv4 version only.

In general, an IP address is a 32-bit decimal number that is normally written as four numbers between 1 to 255 (8 bits or 1 byte each), each seperated from the other by a decimal point. This standard is known as "Dotted Decimal Notation".
e.g.-   117.200.77.110

IP addresses are divided into number of ranges/classes as given in the table below-

Class Range
A 0.0.0.0 to 127.255.255.255
B128.0.0.0 to 191.255.255.255
C192.0.0.0 to 223.255.255.255
D224.0.0.0 to 239.255.255.255
E240.0.0.0 to 255.255.255.255

e.g.-  IP Address 192.168.24.114 belongs to Class 'C'.

How to find out IP Address of your system ?
1) Connect to the Internet.
2) Launch MS-DOS Command Prompt.
3) Type "netstat -n", Press Enter.

You will get the output similar to following-


The IP Address shown in local address field denotes IP Address of your system.
In this case it is 117.200.160.151

IP Address Formats :-
Four different formats of IP Address along with example is as given below-

1) Domain Name System (DNS) : www.insecure.in
2) DWORD Format : 2928008962
3) Octal Format : 0256.0205.0337.002
4) Dotted Decimal Format : 174.133.223.2

Converting DNS IP Address into Normal IP Address :-
You can easily get the IP Address of any domain by various methods such as WHOIS, Netstat, Ping, Traceroute, etc.
Here I have used 'Ping' to get IP Address.

1) Connect to the Internet.
2) Launch MS-DOS Command Prompt.
3) Type "ping domainname", Press Enter.

You will get the output similar to following-



Here, IP Address for Domain "www.insecure.in" is "174.133.223.2"

Thus by typing "http://www.insecure.in" OR "http://2928008962" OR "0256.0205.0337.02" OR "174.133.223.2" in your browser will take you to the same site.

Not all of these formats work in all browsers.