Archive for July, 2006

Now the DemocraKey is Free

If you’ve been looking for a way to protect your identity on the net, look no further. Now Traveling Forever is giving away the ebook on how to build the DemocraKey.

So what is the DemocraKey?

The DemocraKey is free software on a USB Key that makes your actions on the internet completely anonymous. It makes it so no government entity can track the sites you visit, and so all your communications are untracable. Just unplug the DemocraKey, and your actions are traceable again.

There’s no fee, no mailing list to sign up for, and everyone’s free to share the book with whoever they feel. We’re that serious about the need for true anonyminity and freedom of speech on the internet.

With the latest uncertainties in the middle east, and the increasing desire of the eastern and western powers to regulate everything on the internet, we feel it’s our duty to do everything we can to spread the word about how to circumvent government regulation on the net.

So spread the word, and tell all your friends. The DemocraKey is now free.

You can download the ebook here.
If you’re interested in buying a DemocraKey kit, you can do so here.

How to Check Your Webhost’s Security

It only took a week before Traveling Forever was seeing hack attempts. They were thankfully only automated script kiddie attacks, but they were still annoying. For any webmaster, system security is an integral part of being able to sleep at night. But just setting up mod_security on Apache and leaving your machine to the elements isn’t nearly enough.

You’ve got to Pen-Test your own machine. Depending on your webhost, they might not like a simulation attack, so be sure to ask first, and let them know what’s going on. Remember, nothing you do now is any worse than what already happens in the wild.

That being said, lets get started and download our tools for our hack test of our web server. For this guide we’ll be using my favorite Pen-Test Linux LiveCD, BackTrack.

Once you’ve downloaded BackTrack, burn it to a CD, then restart your computer with the CD in your computer. You should automatically start booting into Linux. The default username and password are: “root” and “toor”.

There are three parts to your basic Pen-Test. Here we’ll just go over the following tests:

Nitko

Nitko is an automated web vulnerability scanner. Using Nitko is painless and quite easy. This is one of the best tests available for web software vulnerabilites. Use Nitko from the command line, and you’ll see all your vulnerabilities that are in its database. The report isn’t nearly as robust as Nessus’.

Nessus

Nessus is an automated scanner. It’ll scan and see what services are running on your server and check their version against an extremely large database of vulnerabilites. This is one of the most powerful scanners in the world, and it’s open source and free. Its report system is robust and powerful, with a complete breakdown of vulnerabilities or possible misconfigurations broken down by port.

THC-Hydra

THC-Hydra is an automated password cracker. You should always test your web server against a dictionary attack. This is the easiest way to do so, and make sure no script kiddie is going to 0wn your webserver with a lame dictionary attack.

Between these three tests you’ll be off to a good start in making sure your web host has a basic level of security. Of course, every server has its flaw, and there is no such thing as unbreakable. But by doing the most basic attacks, you ensure security from the most common attacks.

You can get BackTrack here.

Close
E-mail It