Linux Tutorial

Hacking Unix User Passwords

Hacking Unix User Passwords

Fadıl

On most Unix systems passwords are stored in the

file /etc/passwd

This means using the Unix echo out command, cat, you can see the contents of this file:

cat /etc/passwd

The passwords will be encrypted, but unfortunately quite insecurely. But the encryption has long been crackable. A tool called John has long been availble. It runs in dos, and you can crack the average unix password in a couple of hours. A password shorter then four letters takes no time at all (make sure no passwords are this long).

How Web Pages Are Hacked

Fadıl

Stopping the most common attack:

Ok well, one of the easiest ways of getting superuser access is through anonymous ftp access into a webpage. This can easily be secured against. First, you need to learn a little about the password file…

root:User:d7Bdg:1n2HG2:1127:20:Superuser 
TomJones:p5Y(h0tiC:1229:20:Tom Jones,:/usr/people/tomjones:/bin/csh 
BBob:EUyd5XAAtv2dA:1129:20:Billy Bob:/usr/people/bbob:/bin/csh

This is an example of a regular encrypted password file. The Superuser is the part that gives you root. That’s the main part of the file.

Protecting Against SSH Brute-Force Attacks

Fadıl

Practically all UNIX-based servers run a SSH server to allow remote administration across the Internet. From time to time, you might notice a large number of failed login attempts. Often, these are brute-force attacks against your SSH server

In this hack, we’ll show you 5 tips to protect machines running SSH daemons from brute-force attacks.

Change the default port

Configure your SSH daemon to listen on a non-standard port. SSH servers have no trouble doing this. Just make sure you configure your firewalls to allow connections to the new port. For instance, to have your SSH daemon to accept connections on port 2222, edit the sshd_config file and modify the value of Port to 2222 and restart the SSH daemon.

How to Write Secure Perl Scripts

Fadıl

Perl is the main server scripting language for web servers. It is used because of its ease of use and its power, but because of the ease of use, a power perl can be exploited. This document will tell you how to secure your web server from attacks.

Perl scripts can be identified by the outside world as they normally have .pl or .cgi extensions.
Tainting
IF you have ever seen a perl script, you will have noticed that on the first line there is the path to the perl program. eg:
#!/usr/local/bin/perl -w
The -w tells perl to give warnings if there are errors in the code. The security equivalent is to disallow insecure commands from user input. The way this works is that user input cannot execute a command, but any variable created in the script can. eg;
$input= ; STDIN is from the user, so it is considered as insecure
$untainted = "hi";
To enable this secure mode (or tainting, to call it its proper name) add -t to the line, eg; #!/usr/local/bin/perl -T or #!/usr/local/bin/perl -Tw
You can untaint a variable by putting the data it contains into a variable name $number, e.g. $input = $1; The following perl script parses user input if it doesn’t contain dangerous characters tells perl it is secure:

Mount Remote File Systems Over SSH with SSHFS

Fadıl

If you work on remotely connected machines, most likely you’re going to use SSH to secure your connections. But, what if you just want to work with files on a remote server, but find SSH file transfer tedious in repetition and establishing a VPN tunnel is too complicated?

What you’re looking for is a simple tool for mounting remote file systems easily, transparently and securely as if they were just another part of your local machine. In this hack, we’ll show you how to configure Fuse and SSHFS to access remote file systems securely over SSH.