Publications

How xor Encryption Works

Fadıl

Key and text
Xor encryption uses a key(password) to encrypt text. Ascci
All letters/symbols/numbers are represented by a number from 0 to 256. This is called the ASCII number.
Binary
In an XOR encryption program each letter of the key and the text are converted to ASCII, then to binary (0’s and 1’s).
XORing
The 0 or 1 from the key is XORed against the 0 or 1 of the text. If the key is shorter than the text, is repeats. XORing a 0 against a 0 gives a 1. See the below truth table for all

Protecting Against SSH Brute-Force Attacks

Fadıl

Practically all UNIX-based servers run a SSH server to allow remote administration across the Internet. From time to time, you might notice a large number of failed login attempts. Often, these are brute-force attacks against your SSH server

In this hack, we’ll show you 5 tips to protect machines running SSH daemons from brute-force attacks.

Change the default port

Configure your SSH daemon to listen on a non-standard port. SSH servers have no trouble doing this. Just make sure you configure your firewalls to allow connections to the new port. For instance, to have your SSH daemon to accept connections on port 2222, edit the sshd_config file and modify the value of Port to 2222 and restart the SSH daemon.

How to Write Secure Perl Scripts

Fadıl

Perl is the main server scripting language for web servers. It is used because of its ease of use and its power, but because of the ease of use, a power perl can be exploited. This document will tell you how to secure your web server from attacks.

Perl scripts can be identified by the outside world as they normally have .pl or .cgi extensions.
Tainting
IF you have ever seen a perl script, you will have noticed that on the first line there is the path to the perl program. eg:
#!/usr/local/bin/perl -w
The -w tells perl to give warnings if there are errors in the code. The security equivalent is to disallow insecure commands from user input. The way this works is that user input cannot execute a command, but any variable created in the script can. eg;
$input= ; STDIN is from the user, so it is considered as insecure
$untainted = "hi";
To enable this secure mode (or tainting, to call it its proper name) add -t to the line, eg; #!/usr/local/bin/perl -T or #!/usr/local/bin/perl -Tw
You can untaint a variable by putting the data it contains into a variable name $number, e.g. $input = $1; The following perl script parses user input if it doesn’t contain dangerous characters tells perl it is secure:

How to Connect Mikrotik to the Internet

Fadıl

How do I connect to the Internet Mikrotik

Perhaps this question ever arises when you are new to Mikrotik. There are several ways that can be taken to connect to the Internet Mikrotik. These ways depend on the modem or the devices used to connect to the Internet.

In general, how to connect to the Internet Mikrotik is as follows:

1. First, make sure the source of an internet connection. Is it from the ADSL modem (for example Speedy) or from a USB modem?

Tunneling Remote Desktop (RDP) Over SSH

Fadıl

Windows remote desktop (RDP) is an extremely useful way to have access to your computer’s desktop from everywhere. Suppose you need to connect to your work computer through RDP but your company’s IT staff configured the firewalls to block all remote connections accept secure connections (e.g. SSH). This is just an example scenario where you need to tunnel remote desktop over SSH.

In this hack, we’ll show you how to tunnel remote desktop connections over SSH, and how to remotely connect any internal computer by tunneling remote desktop through the main gateway.