10 Best Hacking and Security Software Tools for Linux

Linux is a hacker’s dream computer operating system. It supports tons of tools and utilities for cracking passwords, scanning network vulnerabilities, and detecting possible intrusions. I have here a collection of 10 of the best hacking and security software tools for Linux. Please always keep in mind that these tools are not meant to harm, but to protect.

UPDATE: More hacking and security software tools that you should check out.



1. John the Ripper

John the Ripper is a free password cracking software tool initially developed for the UNIX operating system. It is one of the most popular password testing/breaking programs as it combines a number of password crackers into one package, autodetects password hash types, and includes a customizable cracker. It can be run against various encrypted password formats including several crypt password hash types most commonly found on various Unix flavors (based on DES, MD5, or Blowfish), Kerberos AFS, and Windows NT/2000/XP/2003 LM hash. Additional modules have extended its ability to include MD4-based password hashes and passwords stored in LDAP, MySQL and others.


2. Nmap

Nmap is my favorite network security scanner. It is used to discover computers and services on a computer network, thus creating a "map" of the network. Just like many simple port scanners, Nmap is capable of discovering passive services on a network despite the fact that such services aren't advertising themselves with a service discovery protocol. In addition Nmap may be able to determine various details about the remote computers. These include operating system, device type, uptime, software product used to run a service, exact version number of that product, presence of some firewall techniques and, on a local area network, even vendor of the remote network card.

Nmap runs on Linux, Microsoft Windows, Solaris, and BSD (including Mac OS X), and also on AmigaOS. Linux is the most popular nmap platform and Windows the second most popular.




3. Nessus

Nessus is a comprehensive vulnerability scanning software. Its goal is to detect potential vulnerabilities on the tested systems such as:

-Vulnerabilities that allow a remote cracker to control or access sensitive data on a system.
-Misconfiguration (e.g. open mail relay, missing patches, etc).
-Default passwords, a few common passwords, and blank/absent passwords on some system accounts. Nessus can also call Hydra (an external tool) to launch a dictionary attack.
-Denials of service against the TCP/IP stack by using mangled packets

Nessus is the world's most popular vulnerability scanner, estimated to be used by over 75,000 organizations worldwide. It took first place in the 2000, 2003, and 2006 security tools survey from SecTools.Org.



4. chkrootkit

chkrootkit (Check Rootkit) is a common Unix-based program intended to help system administrators check their system for known rootkits. It is a shell script using common UNIX/Linux tools like the strings and grep commands to search core system programs for signatures and for comparing a traversal of the /proc filesystem with the output of the ps (process status) command to look for discrepancies.

It can be used from a "rescue disc" (typically a Live CD) or it can optionally use an alternative directory from which to run all of its own commands. These techniques allow chkrootkit to trust the commands upon which it depend a bit more.

There are inherent limitations to the reliability of any program that attempts to detect compromises (such as rootkits and computer viruses). Newer rootkits may specifically attempt to detect and compromise copies of the chkrootkit programs or take other measures to evade detection by them.



5. Wireshark

Wireshark is a free packet sniffer computer application used for network troubleshooting, analysis, software and communications protocol development, and education. In June 2006, the project was renamed from Ethereal due to trademark issues.

The functionality Wireshark provides is very similar to tcpdump, but it has a GUI front-end, and many more information sorting and filtering options. It allows the user to see all traffic being passed over the network (usually an Ethernet network but support is being added for others) by putting the network interface into promiscuous mode.

Wireshark uses the cross-platform GTK+ widget toolkit, and is cross-platform, running on various computer operating systems including Linux, Mac OS X, and Microsoft Windows. Released under the terms of the GNU General Public License, Wireshark is free software.


6. netcat

netcat is a computer networking utility for reading from and writing to network connections on either TCP or UDP.

Netcat was voted the second most useful network security tool in a 2000 poll conducted by insecure.org on the nmap users mailing list. In 2003, it gained fourth place, a position it also held in the 2006 poll.

The original version of netcat is a UNIX program. Its author is known as *Hobbit*. He released version 1.1 in March of 1996.

Netcat is fully POSIX compatible and there exist several implementations, including a rewrite from scratch known as GNU netcat.



7. Kismet

Kismet is a network detector, packet sniffer, and intrusion detection system for 802.11 wireless LANs. Kismet will work with any wireless card which supports raw monitoring mode, and can sniff 802.11a, 802.11b and 802.11g traffic.

Kismet is unlike most other wireless network detectors in that it works passively. This means that without sending any loggable packets, it is able to detect the presence of both wireless access points and wireless clients, and associate them with each other.

Kismet also includes basic wireless IDS features such as detecting active wireless sniffing programs including NetStumbler, as well as a number of wireless network attacks.



8. hping

hping is a free packet generator and analyzer for the TCP/IP protocol. Hping is one of the de facto tools for security auditing and testing of firewalls and networks, and was used to exploit the idle scan scanning technique (also invented by the hping author), and now implemented in the Nmap Security Scanner. The new version of hping, hping3, is scriptable using the Tcl language and implements an engine for string based, human readable description of TCP/IP packets, so that the programmer can write scripts related to low level TCP/IP packet manipulation and analysis in very short time.

Like most tools used in computer security, hping is useful to both system administrators and crackers (or script kiddies).


9. Snort

Snort is a free and open source Network Intrusion prevention system (NIPS) and network intrusion detection (NIDS) capable of performing packet logging and real-time traffic analysis on IP networks.

Snort performs protocol analysis, content searching/matching, and is commonly used to actively block or passively detect a variety of attacks and probes, such as buffer overflows, stealth port scans, web application attacks, SMB probes, and OS fingerprinting attempts, amongst other features. The software is mostly used for intrusion prevention purposes, by dropping attacks as they are taking place. Snort can be combined with other software such as SnortSnarf, sguil, OSSIM, and the Basic Analysis and Security Engine (BASE) to provide a visual representation of intrusion data. With patches for the Snort source from Bleeding Edge Threats, support for packet stream antivirus scanning with ClamAV and network abnormality with SPADE in network layers 3 and 4 is possible with historical observation.


10. tcpdump

tcpdump is a common computer network debugging tool that runs under the command line. It allows the user to intercept and display TCP/IP and other packets being transmitted or received over a network to which the computer is attached.

In some Unix-like operating systems, a user must have superuser privileges to use tcpdump because the packet capturing mechanisms on those systems require elevated privileges. However, the -Z option may be used to drop privileges to a specific unprivileged user after capturing has been set up. In other Unix-like operating systems, the packet capturing mechanism can be configured to allow non-privileged users to use it; if that is done, superuser privileges are not required.

The user may optionally apply a BPF-based filter to limit the number of packets seen by tcpdump; this renders the output more usable on networks with a high volume of traffic.

Irc Bot


IRC Bot adalah serangkaian script atau sebuah program yang berdiri sendiri yang bertujuan untuk melaksanakan fungsi-fungsi khusus dalam Internet Relay Chat.

Pada biasanya, IRC bot dipasang sebagai program terpisah yang berjalan pada host yang stabil. IRC bot akan berdiam di IRC Channel untuk menjaga agar tetap terbuka dan menjaga user yang jahil dari pengambil alihan IRC Channel. Berdasar pada kondisi alami protokol IRC, sebuah bot akan tertampil selayaknya user biasa. IRC bot dapat diatus untuk memberikan status operator ke user yang berwenang ketika user tersebut masuk ke channel, dan juga IRC bot menyediakan daftar operator yang seragam.

Sebagian dari fasilitas ini, tentu saja memerlukan status operator channel bagi bot itu sendiri. kebanyakan IRC bot tersebut berjalan dari komputer yang memiliki waktu uptime yang sangat panjang (pada umumnya pada turunan BSD atau Linux), cepat dan memiliki koneksi internet yang stabil. Di karenakan IRC makin populer di kalangan user dial-up, layanan khusus muncul dan menawarkan akses secukupnya pada server Linux stabil. User dapat menjalankan IRC bot dari shell account ini. Layanan seprti ini sering disebut sebagai shell provider.

Bot juga dapat dimanfaatkan untuk fungsi-fungsi yang lain, seperti mencatat peristiwa pada channel IRC, memberikan informasi yang diinginkan (sangat populer di channel yang memberikan layanan kepada user), membuat statistik, melaksanakan permainan tebak-tebakan dan lain sebagainya. Fungsi-fungsi tersebut biasanya di tulis menggunakan bahasa pemograman script seperti Tcl atau Perl.

IRC Bot yang populer antara lain Eggdrop, EnergyMech, Infobot, blootbot, and Supybot.

Sumber : Wikipedia

Menghilangkan Icon Quick edit pada Blogger

Apa sih maksud dari judul posting ini, sepertinya agak aneh? begini nih teman-teman, jika kita sedang mengedit template dan melihat hasilnya maka pada sudut-sudut element akan terlihat icon bergambar obeng dan tang. berikut contoh screenshotnya :


Icon tersebut di sebut juga dengan icon Quick Edit atau dengan kata lain untuk mengedit secara cepat. Fungsinya jika kita ingin melakukan editing terhadap elemen tersebut tinggal klik saja icon nya dan kita bisa langsung mengeditnya. Icon tersebut sebenarnya hanya bisa di lihat apabila kita sedang login ke blogger saja, sedangkan pengunjung yang lain tidak bisa melihat icon tersebut.

Namun ternyata ada beberapa blogger yang tidak suka dengan kehadiran icon tersebut dan ingin menghapusnya. Apakah kita bisa menghapus icon tersebut? Jawabannya tentu saja bisa, dan sangatlah gampang karena kita hanya melakukan perintah agar icon itu tidak di munculkan dengan hanya manambahkan sedikit kode pada kode CSS template kita. Ingin tahu kodenya seperti apa, nih ini dia kodenya, coba pasang saja di Style Sheet CSS anda :


.quickedit{
display:none;
}

Mudah sekali bukan? atau masih bingung. Ok deh, ini dia cara lengkapnya :

Pertama - tama Login ke blogger dengan ID anda Masing - masing.

1. Klik Tata Letak / Desain

2. Klik tab Edit HTML.

3. Cari kode seperti ini :

]]></b:skin>

4. Copy paste kode berikut persis di atas kode yang tadi :

.quickedit{
display:none;
}

5. Klik tombol Simpan template.
6. Selesai.

Sumber. kolom tutorial

Kode-kode Ponsel NOKIA


Berikut ini adalah kunci kode tombol rahasia yang dapat anda jalankan sendiri dengan mengetiknya di keypad hp ponsel anda yang bermerek Nokia baik yang Cdma maupun yang Gsm ;



1. Melihat IMEI (International Mobile Equipment Identity)
Caranya tekan * # 0 6 #

2. Melihat versi software, tanggal pembuatan softwre dan jenis kompresi software
Caranya tekan * # 0 0 0 0 #
Jika tidak berhasil coba pencet * # 9 9 9 9 #

3. Melihat status call waiting
Caranya tekan * # 4 3 #

4. Melihat nomor / nomer private number yang menghubungi ponsel anda
Caranya tekan * # 3 0 #

5. Menampilkan nomer pengalihan telepon all calls
Caranya tekan * # 2 1 #

6. Melihat nomor penelepon pada pengalihan telepon karena tidak anda jawab (call divert on)
Caranya tekan * # 6 1 #

7. Melihat nomor penelepon pada pengalihan telepon karena di luar jangkauan (call divert on)
Caranya tekan * # 6 2 #

8. Melihat nomor penelepon pada pengalihan telepon karena sibuk (call divert on)
Caranya tekan * # 6 7 #

9. Merubah logo operator pada nokia type 3310 dan 3330
Caranya tekan * # 6 7 7 0 5 6 4 6 #

10. Menampilkan status sim clock
Caranya tekan * # 7 4 6 0 2 5 6 2 5 #

11. Berpindah ke profil profile ponsel anda
Caranya tekan tombol power off tanpa ditahan

12. Merubah seting hp nokia ke default atau pabrikan
Caranya tekan * # 7 7 8 0 #

13. Melakukan reset timer ponsel dan skor game ponsel nokia
Caranya tekan * # 7 3 #

14. Melihat status call waiting
Caranya tekan * # 4 3 #

15. Melihat kode pabrik atau factory code
Caranya tekan * # 7 7 6 0 #

16. Menampilkan serial number atau nomer seri hp, tanggal pembuatan, tanggal pembelian, tanggal servis terakhir, transfer user data. Untuk keluar ponsel harus direset kembali.
Caranya tekan * # 92702689 #

17. Melihat kode pengamanan ponsel anda
Caranya tekan * # 2 6 4 0 #

18. Melihat alamat ip perangkat keras bluetooth anda
Caranya tekan * # 2 8 2 0 #

19. Mengaktifkan EFR dengan kualitas suara terbaik namun boros energi batere. Untuk mematikan menggunakan kode yang sama.
Caranya tekan * # 3 3 7 0 #

20. Mengaktifkan EFR dengan kualitas suara terendah namun hemat energi batere. Untuk mematikan menggunakan kode yang sama.
Caranya tekan * # 4 7 2 0 #

21. Menuju isi phone book dengan cepat di handphone nokia
Caranya tekan nomer urut lalu # contoh : 150#

22. Mengalihkan panggilan ke nomor yang dituju untuk semua panggilan
Caranya tekan * * 2 1 * Nomor Tujuan #

23. Mengalihkan panggilan ke nomor yang dituju untuk panggilan yang tidak terjawab
Caranya tekan * * 6 1 * Nomor Tujuan #

24. Mengalihkan panggilan ke nomor yang dituju untuk panggilan ketika telepon hp anda sedang sibuk
Caranya tekan * * 6 7 * Nomor Tujuan #

Keterangan Tambahan :
- Kode diinput tanpa spasi
- Ada kode-kode nokia yang berlaku pada tipe tertentu saja

Bikin Blog di Microsoft Word

Microsoft Word bisa dipakai sebagai aplikasi untuk menulis di salah satu layanan blog gratis Blogger. Hanya saja, sebuah peranti lunak tambahan dibutuhkan. Peranti itu bernama Blogger for Word.

Salah satu penyedia layanan untuk membuat blog secara gratis adalah Blogger. Situs web yang telah diambil alih oleh Google ini dapat diakses di alamat www.blogger.com. Di situ, Anda tinggal mendaftar. Seselainya pendaftaran, Anda bisa langsung membuat blog, bikin tulisan, dan “menerbitkannya”.

Untuk pendaftaran, Anda memang harus online. Tapi, untuk menulis, Anda tidak perlu online supaya bisa menghemat biaya berinternet. Cara yang paling sederhana adalah dengan menulis blog dulu di penyunting teks, seperti Notepad atau Microsoft Word, secara offline. Kalau sudah, baru online, buka situs web layanan blog, login, lalu copy-paste hasil tulisan yang ada di penyunting teks.

Kita sebut cara yang barusan disebut adalah cara manual. Cara yang akan dijelaskan berikutnya kita sebut dengan cara otomatis. Tulisan tetap dibuat secara offline. Online-nya baru nanti kemudian setelah tulisan selesai dibuat.

Cara otomatis ini menggunakan Microsoft Word. Tapi, bukan sembarang Microsoft Word, melainkan Microsoft Word yang sudah dilengkapi dengan suatu add-on bernama Blogger For Word. Aplikasi tambahan gratisan itu bisa didapat dari http://buzz.blogger.com/bloggerforword.html. Ukuran paket instalasinya kecil, cuma 2MB.

Cara pemakaiannya bisa diringkas seperti ini. Setelah Blogger For Word diinstal, toolbar Blogger akan muncul pada Microsot Word. Kemudian, tuliskan isi blog seperti biasa, tapi jangan online dulu, offline saja. Kalau tulisan sudah selesai, nyalakan koneksi intenet, lalu publis deh. Nah, cara detailnya seperti berikut ini. Oh ya, PCplus pakai Word 2007 untuk artikel ini. Di versi lama mungkin berbeda, tapi sedikit saja.

1. Klik [Add-Ins] pada menu di sebelah atas. Opsi [Add-Ins] sebaris dengan [Home], [Insert], [Page Layout], dan lain-lain.

2. Klik [Blogger Settings], kemudian pada kotak yang muncul, masukkan username dan password untuk masuk ke Blogger. Klik [OK].

3. Ketikkan isi blog di dalam Word. Kalau sudah selesai, online-lah. Kemudian, klik [Publish].

4. Masukkan judul blog dan pilih blog yang akan berisi tulisan itu. Klik [Send].

5. Selesai.


sumber.pcplus