Results for Privacy

What is Email Header ? View email header in Gmail.

Monday, October 28, 2019
Many people open there inbox in-order to check their email or send a email and then sign-out but what we do not know that there are indeed lot of things are carried out when we simply send or receive a email.

There is a detail report/history of all those things  that are carried out and are attached with the email.

Yes, I am talking about email headers.They are kept hidden from normal user but we can certainly view it.

These headers comes very handy when tracing email, filtering spams, recording the Ip address of the sender etc. So, let's see what email header is all about and later in the post we will see how to get email header.


What is Email Header?

It is a record/report/history of  the email which covers the path from the sender to the receiver and also contains the vital information about the email servers that it has encountered in its path.

Few emails also contain digital signature to detect the tampering of the email in the path.

What information we can get from Email headers?

As i mentioned above we can get the history of the email and the information on the path the email has traveled to reach us.Lets see what information we can get from it.....
                               
            1.When the sender has composed the message(Date,Time)
            2.When the email was sent from the sender's PC to the email server.(Date,Time)
            3.When the email was sent from the email server to the intended receiver.(Date,Time)
            4.The type of protocol used in the entire path.
            5.The PC of the sender can be identified from the Header.
            6.The IP address of the sender but not always.
            7.The type and the number of digital signatures on the email I mean the type of algorithm.
            8.What type of email-client the sender has used to send the email
            9.The ISP of the sender. 
           10.If any third party is using any tracking means.

How to view Header of an Email?

Here I have listed out not all but few of the web mail providers and email client using which you can get email header.

Web mail providers:

1.Gmail: Login in a standard version >Open email of your choice >Click the down arrow next to reply >Then select show original.

2.Yahoo: Login >Select the desired email >Click on action drop down menu >Select view full header.

3.Hotmail: Login >Select Inbox >Right click on the desired email >Select view message source.

Email Desktop Clients:

1.Outlook Express: In order to view email header in outlook Open it >Select  the desired email from Inbox >Right click on it and select Properties >Details.

2.Mozilla:Open it >Open the desired email > Click view menu >Message source.

How to read an Email Header.

Here I have taken the example of my Gmail account to explain, we will see how to view email header in gmail.

As mentioned above we first need to open up the header of  any desired email as shown below.
What is an Email Header
(Click on the image to zoom it.)
 This is what you will get in a new window as shown below.
What is an Email Header
(Click on the image to zoom it.)
As you can see i have divided the whole header into 3 sections.It is worth mentioning that a header is always analyzed in bottom to top approach.This is because most of the vital informations about the sender is there at the bottom.You can say in the above image section1 is for destination mostly and section3 is for source mostly.

Section 3:
What is an Email Header
(Click on the image to zoom it.)
MIME-Version:1.0:MIME stands for Multipurpose Internet Mail Extension. It tells about the types of attachments in the email.It allows to send sound,graphics etc.Here the Mime-Version field shows that it is currently in 1.0.

Received:by :It show the time and date the email reached the Gmail server.

In-Reply-to: and References : Both are same,as the name shows it means whether the sender has sent an reply to the past message or is a direct new message.If it is a reply message then it contains the reference of the past message.This is an unique number.

Message-ID:This show the system from which the email has originated,I mean the senders's PC.It can be changed or forged easily.This is also a unique number.

To: and From: It gives the sender's and receivers email-id.

Content type:What type of content is there in the email ie. text or image or anything else.

Section 2:
What is an Email Header
(Click on the image to zoom it.)
What is DKIM-Signature?

DKIM(DomainKeys Identified Mail) is a digital signature put on every email we send or receive through email servers.It is used because the emails cannot be tampered or altered in its path.This mechanism is also used in spam filters as spam do not have any digital signature.

In the above image there are certain values let me explain.
                  v=Version
                  a=The algorithm used by Sender or Originating Web mail provider.
                  c=canonicalization algorithm of header and body.
                  d=Sender or Originating Web mail provider.
                  s=Selector
                  h=Contains the list of all the digital signature done on this email.
                  bh=Body hash
                  b=Digital signature of header and body.

Section 1:
What is an Email Header

Delivered-To:It contains the email-id of the receiver.

Received:by : You can see there is a  2 second difference in time between the "received by:" in section 3 and section 2.It shows the time and date the email reaches the gmail server.

Return-Path: The sender's email-id.

Received :from :Specifies the Ip address of the sender generally in "[ ]" but in gmail it is masked by the gmail server address.

This video explain in detail the insights into what is Email Header using Mozilla Thunderbird client.



If you find this post worth reading then do drop a comment,it will be appreciated.
What is Email Header ? View email header in Gmail. What is Email Header ? View email header in Gmail. Reviewed by Satyajit (Admins,a.k.a Satosys) on Monday, October 28, 2019 Rating: 5

More Security for Firesheep from Mozilla | HSTS

Wednesday, February 02, 2011
Firesheep was a buzz word few months ago then came the blacksheep to counter protect users from it.
The firesheep tutorial I demonstrated in a post shows how an attacker can gain access to any account(Twitter,Facebook,Gmail etc) with out even knowing the password using Sidejacking.

Security for Firesheep

Now with the increase of threats from the tools like Firesheep Mozilla has come with a concept of "HTTP Strict-Transport-Security", that will be employed in the version 4 of it and is available in the beta versions available.

What is "HTTP Strict-Transport-Security" ?

Actually when we access any login page it is done by default with http so our initial connection is unencrypted so an attacker can plant a MITM(Man in the Middle Attack) to recieve the connection from the user and the user feels that he/she is connected to the real server.Here comes the role of "HTTP Strict-Transport-Security" in protecting the user's session.What it does is that it guides the user's session to be strictly over Https there by encrypting the user's session from the initial point and also protect the sniffing of cookies.

How to use this feature?

1.A site need to ebable the "Strict-Transport-Security HTTP header",in order to allow the user to access a https login page and the firefox 4 will take care rest of the thing.

2.If you are using Firefox 3.6 you can use an addon called "ForceTLS" to use this functionality.

3.This is built in with Firefox 4 and in the beta but you can also use additonal controls by using "STS-UI" addon.

With this feature added to Firefox 4 the online activities of users from public
Wifi hotspots can be secured to some extent... :)
More Security for Firesheep from Mozilla | HSTS More Security for Firesheep from Mozilla | HSTS Reviewed by Satyajit (Admins,a.k.a Satosys) on Wednesday, February 02, 2011 Rating: 5

How to change Mac Address manually and spoof using tool.

Wednesday, January 05, 2011
Computers talk or communicate over the network using Mac address(Media Access Control Address ) which is unique for each and every machine.Here in this post we will see how we can spoof or change the Mac Address manually and using tools.

Procedure:

Using Registry:

Step 1.
Type "Regedit" in run and press enter.In the regedit winodow follow the path
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318] as shown in the image below.
Step 2.
Check all the values under the above path to find the correct driver description(DriverDesc) as shown in the above image.For me it was "0009",Now search for "NetworkAddress" in the right side of the editor,if you find it then change the value to your desired 12 digit number(MacAddress).If you cannot find "NetworkAddress" then create a new "string value".
Step 3.
 Now rename the new string value to "NetworkAddress" and set the value to a random 12-digit number as shown below.
Step 4.
Now disable the connection and enable then open up command prompt and type the command ipconfig /all to find the change in Mac Address.

Using tools:

1.SMAC :
It is not a freeware tool to use but it is a very useful tool and widely used for spoofing MacAddress(Download)

2.Macshift:
It is an opensource tool and has a command line usage.(Download)

3.MadMACs:
If it a very user friendly tool you just need to double click on the executable thats it.(Download)

If you find this post useful and interesting then do drop your comment,it will be appreciated... :)
How to change Mac Address manually and spoof using tool. How to change Mac Address manually and spoof  using tool. Reviewed by Satyajit (Admins,a.k.a Satosys) on Wednesday, January 05, 2011 Rating: 5

Monitor Facebook activity and increase Security

Monday, January 03, 2011
Facebook is one of the most widely used social networking site these days.So,if your account get compromised in any way for example by session hijacking etc then it may result in a big headache.Here in this post i will tell you how you can monitor your account activity details like location,OS type and time of access.

Read the  post on "Facebook security and privacy tips".

Procedure:

Step 1.
Click on the "Account" on the upper right side of the your facebook page and then click on the "Account settings" as shown in the image below.

If you find this post interesting then subscribe here to get updates.

 Step 2.
Now scroll down to where you see "Account Security" and click on change option there as shown in the image below.
Step 3.
Now you can see the recent activity and other activities in the past.There also you can see the "Login Notification" option,I would recommend to set it "On" to add an extra level of security.In the next login attempt you will be asked your computer name so,provide the desirable name and click on continue.
Step 4.
If you suspect any unfamiliar device or location based on your activity history then you can click on the "End activity" option to end that activity.

Note:The information furnished in the account activity in not that detail but it can certainly add a level of security to your facebook account.
Monitor Facebook activity and increase Security Monitor Facebook activity and increase Security Reviewed by Satyajit (Admins,a.k.a Satosys) on Monday, January 03, 2011 Rating: 5

How to use John the Ripper Tutorial and Pwdump7

Wednesday, October 20, 2010
In Microsoft Windows user account password and information are stored in a file called SAM. The windows SAM file location is “%systemroot%\system32\config” and also a backup copy of the file is also stored in ”%systemroot%\repair”.Here in this post we will see how to use John the Ripper for windows to extract the information.

As part of Windows 10 Password hack, we will be using brute force password cracker that is John the Ripper and Pwdump7.In this John the Ripper tutorial we will keep things simple for understanding and keeping in mind if any beginner is following it.
SAM-Password-cracking

In Windows 10 and earlier versions till Windows SP3 the SAM file is by default locked with syskey enabled so we cannot open it as such and view its content so here in this post, I will show you how we can crack it and retrieve the hash.

You may be wondering what does SAM stand for?

It is can be expanded as Security Accounts Manager, it stores the user credentials information.

Requirements:

1. Pwdump7: (Download)

2.John the ripper Download

Procedure:

Step 1. You need to have the administrative privilege then open up command prompt window, using the command prompt go to the directory where pwdump7 is present and follow the on-screen information as shown below.
SAM-Password-cracking

Step 2. After all the hashes are being displayed on the command prompt screen right click on the title bar copy it then pastes and saves it in a text file.First right click and mark the screen before copying. Here I have saved it as pw-hash.txt
SAM-Password-cracking

Step 3.Having downloaded John the ripper for windows browse into John’s root directory and use the command as shown in the image below.
SAM-Password-cracking

Step 4.The command we have used above is “C:\JOHN\RUN>john-386 C:/pw-hash.txt –users=Administrator”, the format of the command is “john-386 [Hash file path] –users=[Username]”.Here the hash file path is “C:/pw-hash.txt” and the username is “Administrator”, by using the above command then the John will search for the password of Administrator.

You can also use “C:\JOHN\RUN>john-386 C:/pw-hash.txt” so that John will search for the password of all the usernames available.

If you have a John the ripper wordlist then you can use the wordlist mode as well.

john --wordlist=password.txt pw-hash.txt

I think from this post we were able to understand how to use John the Ripper for windows Tutorial and Pwdump7 .

If you find this post useful then do drop a comment it will be appreciated.
How to use John the Ripper Tutorial and Pwdump7 How to use John the Ripper Tutorial and Pwdump7 Reviewed by Satyajit (Admins,a.k.a Satosys) on Wednesday, October 20, 2010 Rating: 5

How to hack Facebook Account ? | Tabnabbing.

Tuesday, September 21, 2010
My intension of posting an article on such a title is not to harm anyone nor bring down the reputation of the concern services or promote black hat rather I want to aware the users of such a threat they can encounter and for educational purposes.
I recommend readers if they abide by the blog's Disclaimer then they can proceed reading this post otherwise leave this page immediately.
Facebook is one of the most hyped and widely used social networking site these days.So,attackers always look out for profiles where they can post there spam message,advertise etc.So here in this post I will use a phishing technique called as "Tabnabbing" brought out by Aza Raskin.If you are new to it you can follow my earlier post on Tabnabbing.Keeping in mind that you know what is "Phishing" and how it is done so,lets start.....

Requirements:

1.One should know how Phishing is carried out if not (Read here)
2.Should have a free hosting account(t35.com /110mb.com / yourfreehosting.com etc)
3.Need two codes of java script on Tabnabbing download (Here).

Procedure:

Step 1.I assume that you have made the fake login page of facebook and the required .php file needed for it.If you do not know how to do it (Read here).

Note:In the .php code if the redirect url is the main login page of Facebook(http://www.facebook.com) then a warning message may be flashed after logging into the fake page to reset the password.So,the attacker may have used a different link there, you can try with this "http://www.facebook.com/careers/?ref=pf" instead of "http://www.facebook.com" Look the screen shot below to get the whole idea.
(Click on the image to zoom it)
Now upload the fake page and the .php file to the free web hosting account.

Step 2.Having done with the fake page and .php file ,now use a standard webpage like "http://www.google.com" or "http://www.bing.com" save the source code of it in a text file.

Step 3.Download the code in the requirement part and open "Bgattack.js Injecting COde.txt" and copy the content.Now open the file in step 2.and find (use ctrl+f) first <style.......... > and put the copied content above it then save and upload the web page to the free web host account.
(Click on the image to zoom it)
Step 4.Now open "bgattack.js" and find(use ctrl +f)  "window.location = '<Ur Fake Page URL>' " as shown below,remove it and replace with the fake page url then save and upload the file to the free web host account.
(Click on the image to zoom it)
Step 5.See the screen shot below,your free web hosting account should look similar to this.
(Click on the image to zoom it)
Click on the url of the standard webpage and open few tabs and see the change.Now the whole process is complete..... :)

I have made a Demo you can check it (HERE).Click on it and open 3-4 tabs and see the magic.I mean you will see a facebook login page, you can enter few trail words in the login field and see those words (HERE)

If you find this post worth reading then do drop a comment,it will be appreciated.
How to hack Facebook Account ? | Tabnabbing. How to hack Facebook  Account ? | Tabnabbing. Reviewed by Satyajit (Admins,a.k.a Satosys) on Tuesday, September 21, 2010 Rating: 5

Facebook:Security and Privacy Tips

Wednesday, September 08, 2010
"Facebook" is the widely used social networking site these days,as the number of users are increasing so it is luring attackers and spammers to trick the users with social engineering so i have come up with few security and privacy tips for it by which I feel you can avoid the awkward situation.

Click on the images below to zoom them
 Security and Privacy Tips:

1.Never ever "like" any link if you are not sure about the authenticity and the source of the post because that may be a spam,if you do that then that update may get posted in your profile and the chain continues.

2.If you find any link of video with luring words like "See what i did with my girl friend"....LOL  never click on those links.It sometimes may happen that when you click on the link then it may prompt you to download a video codec(may be Adobe flash player) and when you download that you may end up making your computer a zombie so be careful.

3.Privacy for Photo Albums:
  • Click "Account" on the top left corner and select "Privacy settings" from the drop down menu then the image below will open up.Click on "Customise settings".
  •  Then from the next page click on "edit album privacy " as shown in the image below.

  • From the next page use the settings that suits you, I mean select the settings to whom you want to view your pics.
4.Photo & Video Tagging:
It can sometime create some embarrassing situation because the pics and videos you are tagged in are shared not only in your profile,in friend's but also in the profile of the people those are not in your friend list.Follow these privacy settings and take a relax nap...Lol.Choose Privacy settings-->Customise settings as show in step3.Then as shown in the image below,select the desirable settings to what extent you want to share your tagged photos and videos.
5."Search me on Facebook" Option:
This lets friends find you in Facebook,if you are visible to fewer people then you are more exposed to spammers but this may prevent you from connecting to real world.So,its on you what options you use for it.
Follow the path  Privacy settings-->Basic directory settings.
6.As in step5 you can change few other option like "send me friend request","see my current location" etc in the same page according to your wish.
7."See my friend list" Option:
Follow the path in the previous step and follow the instruction in the image below.I recommend not showing your friend list to anyone.
8.In the privacy settings page you can see down the page there are two option for viewing the applications that access your account and block list as shown below.
  • Applications and websites that have access to your can be viewed here.You can then remove the spam applications or unwanted applications.
  • Use Block list to block people as shown in the image below.
9.Hide your contact information from strangers:
As shown in step3. use Customise settings and then scroll down to "contact information" and edit it so that only you and your friends can view it.
10.Hide yourself from search engine:
This is one of the very important option because if you are visible through search engine then you are more exposed to spammers and attckers.So disable the option of being visible in search result.

If you find this post worthy enough to read and follow then do drop a comment,it will be appreciated... :)
Facebook:Security and Privacy Tips Facebook:Security  and Privacy Tips Reviewed by Satyajit (Admins,a.k.a Satosys) on Wednesday, September 08, 2010 Rating: 5
Powered by Blogger.